AI Business Partner ← Home

Personal Data Processing Policy

This document sets out how personal data is processed and protected on aibp.ai: what is collected, for what purposes, on what legal grounds, where it is stored, who it is shared with and how to have it deleted. The full text below is given in Russian, as the Policy is governed by Russian law and the Russian version prevails.

Version of 4 August 2026. Effective from the date of publication on the website.

1. General provisions

This Policy on the processing of personal data (hereinafter — the Policy) has been drawn up pursuant to the requirements of clause 2 of part 1 of Article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (hereinafter — the Law) and sets out the Operator's policy on the processing of personal data, together with information on the protection requirements it applies.

The Policy applies to all personal data of data subjects that the Operator receives through the aibp.ai website, including all of its sections and language versions, and through the communication channels linked to the website that are listed in section 3.

The Policy applies to personal data processed by the Operator both on its own and with the involvement of third parties acting on its instructions under part 3 of Article 6 of the Law.

The current version of the Policy is freely available at aibp.ai/privacy and is accessible to anyone without restriction.

2. Terms and definitions

Terms are used with the meanings established by Article 3 of the Law. The principal ones are set out below.

3. Information about the Operator

OperatorAI Business Partner (AIBP)
Taxpayer number (INN)
Registration number (OGRN / OGRNIP)
Address
Websiteaibp.ai
Additional communication channelTelegram: @AIBusinessPartner_bot

The Operator's registration details will be completed once state registration is finished. Until then, enquiries concerning the processing of personal data are accepted at the email address and communication channel given above.

4. Principles of personal data processing

The Operator follows the principles established by Article 5 of the Law:

5. Categories of data subjects and composition of the data processed

The Operator processes the personal data of the following categories of data subjects. Personal data are provided by the data subject themselves. The Operator does not buy databases, does not obtain personal data from external sources and does not collect them covertly.

Category of data subjectsComposition of personal data
Website visitors who have submitted the form Name (or other form of address given); telephone number; the service selected; the date and time the enquiry was sent
Persons taking the AI audit of a sales department Name; contact details; answers to the audit questions containing information about activities and business processes; where taken through Telegram — the Telegram username and identifier
Persons who have contacted the Operator's Telegram bot Telegram username and identifier; the text of messages sent by the data subject
Website visitors (technical statistics) The IP address of the connection and the country derived from it; information about the pages viewed and the actions taken on the site; a random browser identifier not linked to any individual
Counterparties and their representatives Surname, first name and patronymic; position; contact details; information required to conclude and perform a contract

Operator does not process special categories of personal data (race, ethnicity, political opinions, religious and philosophical beliefs, state of health, sex life), nor biometric personal data.

The Operator does not process personal data authorised by the data subject for dissemination within the meaning of Article 10.1 of the Law.

6. Purposes of the processing

Each purpose of the processing is matched with the data involved, the legal basis and the retention period.

PurposeLegal basisProcessing period
Contacting the data subject about the enquiry submitted, providing a consultation, preparing a commercial proposal Consent of the data subject — clause 1 of part 1 of Article 6 of the Law Until the purpose is achieved, but no longer than 3 years from the date of the last contact; where consent is withdrawn — until such withdrawal
Preparing and delivering to the data subject the result of the AI audit of the sales department Consent of the data subject — clause 1 of part 1 of Article 6 of the Law Until the purpose is achieved, but no longer than 3 years; where consent is withdrawn — until such withdrawal
Replying to messages from the data subject in the Telegram bot and other communication channels Consent of the data subject — clause 1 of part 1 of Article 6 of the Law Until the purpose is achieved, but no longer than 3 years; where consent is withdrawn — until such withdrawal
Conclusion, performance and termination of a contract with the data subject or with the person they represent Performance of a contract — clause 5 of part 1 of Article 6 of the Law For the term of the contract and 5 years after its termination, unless another period is established by law
Fulfilment of obligations imposed on the Operator by law (accounting and tax records, responses to requests from authorised bodies) Fulfilment of obligations imposed by law — clause 2 of part 1 of Article 6 of the Law For the periods established by the relevant legislation
Ensuring the operation and security of the website and analysing section traffic in anonymised form Pursuit of the Operator's legitimate interests, provided the rights and freedoms of the data subject are not infringed — clause 7 of part 1 of Article 6 of the Law No more than 12 months; records are overwritten as new ones arrive

Processing of personal data for the purposes of advertising, promotion of goods and services and the sending of advertising messages is carried out solely with the separate prior consent of the data subject in the manner set out in Article 18 of Federal Law No. 38-FZ of 13 March 2006 “On Advertising”. The absence of such consent does not prevent the data subject from receiving a consultation or the result of the audit.

7. Legal bases of the processing

The legal bases for the processing of personal data are:

8. List of operations with personal data and methods of processing

The Operator performs the following operations on personal data: collection, recording, systematisation, accumulation, storage, updating (renewal, alteration), retrieval, use, transfer (provision, access) to the extent and in the manner set out in sections 11 and 12 of this Policy, anonymisation, blocking, deletion and destruction.

Processing is carried out by mixed means: with and without the use of automation. Personal data are transmitted over the Operator's internal network and over the Internet through secure channels.

Operator does not take decisions producing legal effects concerning the data subject or otherwise affecting their rights and legitimate interests based solely on the automated processing of personal data. The language models used by the Operator serve to prepare materials and draft replies; the final decision is taken by an employee of the Operator.

9. Procedure for collection, storage and destruction

Collection. Personal data are collected directly from the data subject when the form on the website is completed, when the AI audit is taken and when the Telegram bot is contacted. The fields that are mandatory are marked in the form. Providing personal data is voluntary; if they are not provided, the Operator has no technical means of contacting the data subject and delivering the requested service.

Storage. Personal data are stored in a form permitting identification of the data subject for no longer than the purposes of the processing require. The storage conditions preclude unauthorised access.

Destruction. Once the purposes of the processing have been achieved, where the need to achieve them has ceased, where consent is withdrawn or at the data subject's request, personal data are to be destroyed. Destruction is carried out by a method that precludes any further processing, with a record drawn up in the cases provided for by law. If destruction is not possible within the prescribed period, the Operator blocks the personal data and ensures their destruction within no more than six months.

10. Location of the databases

In accordance with part 5 of Article 18 of the Law, the recording, systematisation, accumulation, storage, rectification and retrieval of the personal data of citizens of the Russian Federation are carried out using databases located in the territory of the Russian Federation.

The server hosting the Operator's databases is located in Moscow; hosting services are provided by a Russian hosting provider. Access to the server is restricted and is granted by cryptographic key.

11. Cookies and visit statistics

Website does not set cookies to track user behaviour and does not use external web analytics systems: Yandex.Metrica, Google Analytics and similar counters are not installed on the site.

Visit statistics are kept by the Operator's own means. The following are recorded: the address of the page requested, the date and time of the request, the IP address of the connection and the country derived from it, and a random browser identifier that does not allow the visitor to be identified. This information is used solely in anonymised form to assess which sections of the site are in demand and to ensure its security; it is stored on a server in the Russian Federation and is not passed to third parties.

Technical files that keep the site working (including remembering the language selected) contain no personal data and are not used for profiling.

12. Transfer of personal data to third parties

The Operator does not sell personal data and does not pass them to advertising networks, data brokers or any other parties not named in this section.

The list of parties to whom personal data are transferred, or who may technically have access to them, is closed:

PartyWhat is transferredFor what purpose
Telegram Messenger (messaging service) Name, telephone number, the content of the enquiry and of the correspondence Receiving notifications of enquiries, conducting correspondence with the data subject in the bot
Anthropic PBC (the Claude language model) The text of the data subject's enquiry, answers to the audit questions Preparing draft replies and audit results
Hosting provider (Russian Federation) Technical access to the server hosting the databases Hosting the website and the databases

Transfers are made to the minimum extent necessary. Processing of personal data by those parties on the Operator's instructions is carried out in accordance with part 3 of Article 6 of the Law; such parties are obliged to maintain confidentiality and to ensure the security of personal data.

Personal data may be provided to public authorities in the cases and in the manner established by the legislation of the Russian Federation.

13. Cross-border transfer of personal data

The services listed in rows 1 and 2 of the table in section 12 are located outside the Russian Federation. The transfer of personal data to such parties is a cross-border transfer within the meaning of Article 12 of the Law.

Cross-border transfer is carried out with the consent of the data subject, given in the manner provided for by part 4 of Article 12 of the Law. Consent to cross-border transfer is a separate element of the document “Consent to the processing of personal data” and may be withdrawn by the data subject independently of the other consents.

Before beginning any cross-border transfer, the Operator notifies the authority responsible for the protection of the rights of data subjects of its intention to carry out such a transfer, in the manner set out in part 3 of Article 12 of the Law.

The scope of cross-border transfer is limited to the information needed to contact the data subject and prepare the result they have requested. Information about health, financial position and other sensitive data is not transferred.

14. Confidentiality

The Operator and any other parties who have obtained access to personal data are obliged not to disclose them to third parties and not to distribute them without the consent of the data subject, unless federal law provides otherwise. The duty of confidentiality continues after the end of any employment or civil-law relationship with the Operator.

15. Measures to ensure the security of personal data

In fulfilment of Articles 18.1 and 19 of the Law, the Operator takes the legal, organisational and technical measures necessary and sufficient to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, distribution and other unlawful acts.

Legal and organisational measures:

Technical measures:

16. Rights of the data subject

In accordance with Articles 14 and 20 of the Law, the data subject has the right:

17. Procedure for enquiries from data subjects

A request is to be sent to the email address given in section 3 or through the Operator's Telegram bot. The request must contain information allowing the data subject to be identified and their connection with the data processed to be confirmed: surname, first name and patronymic, the telephone number given at the time of contact, or other information confirming the fact of interaction with the Operator, together with the signature of the data subject or their representative (for requests made in writing).

Time limits for handling enquiries:

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. After withdrawal, the Operator may continue processing without the data subject's consent where another legal basis provided for by parts 1 and 2 of Article 6 of the Law exists — in particular, to perform a concluded contract or obligations imposed by law.

18. Minors

The site is addressed to business audiences and is not intended for persons under 18. The Operator does not knowingly collect the personal data of minors. Should the Operator become aware that the personal data of a minor have been obtained without the consent of their legal representative, such data are to be destroyed.

19. Liability

Persons guilty of breaching the requirements of the legislation of the Russian Federation on personal data bear the liability provided for by law. The Operator is not liable for information placed in the public domain by the data subject themselves, nor for the acts of third parties who obtained access to personal data through the fault of the data subject.

20. Final provisions

The Operator may amend this Policy. A new version takes effect from the moment it is published at aibp.ai/privacy, unless the version itself provides otherwise. The date of the version is stated at the beginning of the document.

Data subjects are advised to review the current version of the Policy from time to time. Continued use of the site after a new version has been published constitutes agreement with its terms in the part that does not require separate consent from the data subject.

This Policy has been drawn up in Russian. Translations of the Policy into other languages are published for ease of reference; in the event of any discrepancy, the Russian text prevails.

For all matters relating to the processing of personal data, please use the contact details given in section 3.

Free

Let's audit your business

Leave a request and on a free consultation we'll find where customers are being lost, suggest which service to start with and price it around your goal.

What should we call you?
Please enter a valid number
We cannot accept your request without consent