Privacy Notice
1. Who processes your data
Operator and data controller: Balancier (the "Provider")
Email for privacy requests: support@balancier.pro
The Provider is established in the Russian Federation and acts as an operator of personal data under Federal Law No. 152-FZ "On Personal Data". The Service is offered to business users and is not directed at individuals in the European Economic Area or the United Kingdom.
2. What personal data is processed
- account data: email address, name and workspace name, where you provide them;
- authentication data: password hash, session records, user-agent string and a hash of your IP address;
- technical data required to operate and protect the website and the application, including error reports;
- project data: schedules, resources, files and other content you upload to or create in the Service, which may contain personal data of third parties;
- correspondence you send to support.
The Provider does not seek to process special categories of personal data or biometric data. You should not upload such data to the Service.
3. Why the data is processed and on what basis
- to register your account, authenticate you and provide the functions of the Service - performance of the agreement between you and the Provider;
- to store and process the projects you create - performance of that agreement;
- to keep the Service secure, prevent abuse and diagnose errors - the Provider's legitimate interest in the security and reliability of the Service;
- to answer your requests and inform you about the operation of the Service - performance of the agreement and the Provider's legitimate interest;
- to comply with obligations under applicable law, including Russian law applicable to the Provider.
Where Russian law requires consent for the processing of account data, that consent is given separately at registration and is set out in the Consent to the Processing of Personal Data. Withdrawing consent is described in clause 9.
Your personal data is not used for advertising, is not sold or otherwise made available to third parties for their own purposes, and is not used to train machine-learning models.
4. Where your data is stored
The Service runs on servers located in the Russian Federation. If you use the Service from another country, your personal data and your project data are transferred to and stored in the Russian Federation, where they are subject to Russian law, including lawful access requests by Russian public authorities. By using the Service you acknowledge this transfer. If your organisation requires data to be stored in a particular jurisdiction, this must be agreed in a separate written agreement, including an on-premises deployment.
5. Cookies
The Service uses two cookies, both strictly necessary for the functions you request:
balancier_session- keeps you signed in; standard lifetime up to 14 days;locale- remembers the interface language you selected; lifetime up to 12 months.
No analytics, advertising or third-party tracking cookies are used, and no third-party scripts are loaded by the application. Disabling cookies may make signing in impossible.
6. How long data is kept
Personal data is kept no longer than the purposes of processing or the law require. After those purposes are achieved, after consent is withdrawn where no other lawful basis applies, or if the Service is discontinued, the data is deleted or destroyed.
For data processed to keep the Service secure and to diagnose errors, the following retention periods apply, after which the records are deleted automatically:
- detailed technical error reports (page address, technical information about the failure, user identifier) - 180 days;
- minimised aggregated technical information about errors and the history of their handling - 730 days from the last occurrence;
- the log of administrative and protective actions - 365 days.
Following an account deletion request, account and project data is deleted within 30 days, after which residual copies are removed from backups in the ordinary backup rotation.
7. Who else has access
The Provider may engage infrastructure and service providers necessary to operate the Service - currently a hosting provider for the servers described in clause 4 and an email delivery provider for account and support messages - on condition that they maintain confidentiality and comply with the law. Access within the Service is granted only to the extent required to operate and support it. Data may also be disclosed where the law or a competent authority requires it.
8. Security
The Provider applies organisational and technical measures appropriate to the risk to protect data against unauthorised access, alteration, disclosure, blocking and deletion. These include encrypted transport (HTTPS), password hashing, server-side sessions with HttpOnly cookies, access control by workspace, and a restricted administrative surface with an audit log. No service can be guaranteed to be completely secure, and you are responsible for the security of your own credentials and devices.
9. Your rights
You may request confirmation of whether your data is processed and access to it, ask for it to be corrected, blocked or deleted, and withdraw the consent referred to in clause 3. Send requests to the email address in clause 1. The Provider may ask for information needed to verify your identity, and will normally respond within 30 days.
Withdrawing consent or requesting deletion may make further use of the Service impossible, as the account cannot be operated without the data described in clause 2.
10. Children
The Service is intended for business use and is not directed at children. Accounts may only be created by persons aged 18 or over.
11. Changes to this Notice
This Notice may be updated when the Service or the applicable requirements change. The current version is always available at /en/privacy.html. Where changes are material, notice will be given by email or in the application.