GerwinGerwin AI

Personal Data Processing Policy

· Version 2.1

1. General provisions

This Policy explains how Individual Entrepreneur Ksenia Andreevna Khramtsova (Taxpayer No. 560705615950, Primary State Registration No. 322565800038690; Operator, Gerwin AI, we) processes and protects personal data.

It applies to gerwin.ai and its subdomains, the journal, help center, and the Gerwin AI software service (together, the Resources). A notice displayed for a particular feature supplements this Policy.

We process personal data under the Constitution of the Russian Federation, Federal Law No. 152-FZ On Personal Data, Federal Law No. 149-FZ On Information, Information Technologies and Information Protection, and other applicable mandatory requirements.

The terms used in this Policy have the meanings given by applicable law. Processing includes collection, recording, organization, accumulation, storage, updating, retrieval, use, transfer, provision, blocking, deletion, and destruction. Cross-border transfer means a transfer of personal data to the territory of a foreign state, to a foreign public authority, individual, or legal entity.

2. Operator details

The personal data operator is Individual Entrepreneur Ksenia Andreevna Khramtsova, Taxpayer No. 560705615950, Primary State Registration No. 322565800038690. Send privacy questions and requests to team@gerwin.ai.

3. Persons covered by this Policy

This Policy applies to:

  • visitors to the corporate site, journal, and help center;
  • registered and prospective users of the service;
  • payers, business customers, and their representatives;
  • people who contact support, submit feedback, requests, or claims;
  • recipients of product or promotional messages who provided separate consent;
  • contractor representatives and other people interacting with Gerwin AI.

The Resources are not intended for independent use by persons under 18. A legal representative who believes that a minor has submitted data without a proper legal basis may request its deletion.

4. Data we process

The categories depend on how the Resources are used.

4.1. Visitor data

  • IP address and request date and time;
  • browser, operating system, language, time zone, and device type;
  • requested page, referral source, technical events, and errors;
  • cookies, local identifiers, and saved preferences;
  • aggregated page interaction data in the cookie scenarios described below.

4.2. Account data

  • name or alias, email address, telephone number, and profile image;
  • user identifier and account status;
  • password hash, session tokens, sign-in and security history;
  • the identifier and profile fields released by a login provider selected by the user, such as Yandex or Telegram, within the scope shown during authorization;
  • company, role, and business details when the user acts for a legal entity or individual entrepreneur.

We do not store passwords in plain text.

4.3. User content

  • prompts, instructions, text, images, files, and other material submitted by the user;
  • outputs generated by the service;
  • operation history, selected model, generation settings, ratings, and feedback;
  • personal data included by the user in a prompt or file.

Do not submit special-category or biometric data, state secrets, medical records, payment credentials, or third-party data unless strictly necessary and supported by a lawful basis. Gerwin AI does not request this information for ordinary service use.

4.4. Payment and contract data

  • plan, amount, currency, date, payment status, and transaction identifier;
  • masked payment instrument data and receipt details returned by a payment partner;
  • taxpayer number, legal name, address, bank, and other details required for a contract, invoice, or closing documents;
  • subscription, accrual, refund, and payment support history.

Full bank-card details are normally entered on a payment partner's secured page and are not received by Gerwin AI. The relevant partner is identified in the checkout interface.

4.5. Communications

  • emails, chats, support requests, reviews, and claims;
  • name, contact details, attachments, and technical context required for a response;
  • records of consents, withdrawals, contractual acceptances, and legally significant notices.

4.6. Security data

  • signs of automated activity, unauthorized access attempts, and violations;
  • technical identifiers, audit logs, restrictions, and complaints;
  • other information objectively required to protect the Resources, users, and third parties.

We process only data necessary for a specified purpose.

PurposeMain dataLegal basis
Delivering pages and storing essential settingstechnical data and essential cookiesactions requested by the user; exercise of the Operator's rights and legitimate interests in operating and securing the Resources, provided the individual's rights and freedoms are not infringed
Registration, identification, and account administrationcontact, profile, and authentication dataentering into and performing the contract; separate consent where required
Responding to prompts and providing AI featuresuser content, settings, and technical eventsperforming the contract and actions requested by the user
Payments, receipts, accounting, and taxpayment, contract, and accounting datacontract performance and legal obligations
Support and handling requests or claimscontacts, communications, and account datacontract performance, legal duties, and exercise and protection of the Operator's rights and legitimate interests
Fraud and abuse preventionlogs, IP address, and security eventsperformance of security duties; exercise of the Operator's rights and legitimate interests, provided the individual's rights and freedoms are not infringed
Product analytics and improvementusage events and pseudonymous identifiersprior consent for non-essential analytics
Product news and promotionsname, email, and preferencesseparate prior marketing and data-processing consent
Publishing a review, case study, name, or imagepublication materialsseparate consent, including dissemination consent where required
Protecting rights and complying with authoritiesnecessary records and evidencelegal obligations and protection of legal rights

Where consent is required, it must be specific, informed, conscious, unambiguous, and separately documented where Russian law requires separation. Refusal of optional processing does not prevent access to features that do not require it.

We do not make decisions based solely on automated processing that produce legal effects or otherwise significantly affect a user.

6. Sources of data

We receive data:

  • directly from the user during visits, registration, payment, service use, or communications;
  • automatically from a browser or device;
  • from a login provider selected by the user;
  • from a payment partner regarding transaction status;
  • from a company or representative that grants a user access;
  • from public sources or a counterparty where receipt and further processing are lawful.

A person submitting another individual's data confirms that a proper basis exists and that the individual has received the required information. This does not release Gerwin AI from its own duties.

7. User content and third-party data

The user controls the contents of prompts and files. Where they contain third-party personal data, the user must have a valid basis for processing and disclosure to Gerwin AI, apply data minimization, and respect the original collection purpose.

Depending on the operation, Gerwin AI may act as a personal data operator/controller or as a processor acting on the user's instructions. Corporate processing terms may be agreed separately. Users must not submit data that cannot lawfully be entrusted to Gerwin AI or the selected model provider.

User content is transmitted to a selected model provider only to the extent required to fulfill the prompt. Gerwin AI does not use private prompts and files to train its own generally available models or for advertising without a separate express legal basis. Information about the specific provider and material processing terms must be available in the interface, documentation, or a specific notice before a prompt is sent.

8. Cookies and analytics

Essential cookies support sessions, security, load balancing, language, and consent preferences and are used to provide requested functionality.

Non-essential analytics, including Yandex Metrica, is enabled only after a user consents through the banner or preference center. The relevant code is not loaded before consent. Consent may be withdrawn at any time through “Cookie settings” in the footer.

Categories, retention periods, and controls are described in the Cookie Policy.

9. Recipients

We do not sell personal data. Access is limited to what is necessary and may be provided to:

  • employees and contractors bound by confidentiality;
  • hosting, storage, message delivery, monitoring, and security providers, subject to applicable localization and transfer requirements;
  • payment organizations, banks, and fiscal data operators;
  • login providers selected by the user;
  • AI model providers selected to fulfill a user prompt;
  • Yandex for analytics only after consent;
  • auditors, counsel, and professional advisers with an appropriate basis and confidentiality;
  • courts and public authorities where required by law;
  • a legal successor in a reorganization or business transfer, subject to continuing obligations.

The specific model provider available in the interface may change as the model catalog changes. Before user content is transferred, information about the relevant recipient and material processing features is provided in the interface, documentation, or a specific notice. We use appropriate agreements, define the permitted purposes and processing operations, and assess whether processors provide adequate safeguards.

10. Russian localization and international transfers

When personal data of Russian citizens is collected, including online, the Operator does not record, organize, accumulate, store, update, or retrieve that data using databases located outside the Russian Federation, except where Russian law expressly provides otherwise. Initial collection and the listed operations are organized using databases located in the Russian Federation.

Some features may involve a subsequent cross-border transfer of part of the user content to a foreign provider of the selected model. Before beginning such activity, the Operator:

  • identifies the legal basis, purpose, data, categories of individuals, recipient, and destination state;
  • obtains the information required by law from the foreign recipient concerning its identity, safeguards, and termination of processing and, where required, the law of the relevant state;
  • assesses the recipient's confidentiality and data-security arrangements;
  • sends Roskomnadzor a notice of intended cross-border transfer separately from the general processing notice;
  • for a state that does not provide adequate protection, does not begin the transfer before the statutory ten-business-day notice-review period expires, and observes any Roskomnadzor restriction or prohibition.

If the mandatory conditions have not been met, or the transfer is prohibited or restricted, the relevant feature must not transfer personal data to the foreign recipient. Consent, selection of a foreign model, or a user's instruction does not by itself displace localization, notice, or recipient-assessment requirements.

After receiving the necessary information and providing any required consent, the user instructs Gerwin AI to send only the content required to fulfill the prompt. Users must not include data that law, contract, or confidentiality restrictions prohibit from being sent to that recipient or outside the Russian Federation.

11. Retention

Data is kept no longer than required by its purpose, contract, or law. Our general reference periods are:

  • account data — for the account term and then for settlement and claims, generally no more than three years;
  • accounting, tax, and payment documents — for the mandatory statutory period;
  • security and technical logs — generally up to 12 months unless a longer investigation requires them;
  • support communications and claims — up to three years after closure, or until a dispute is finally resolved;
  • evidence of consent and acceptance — for the related processing and applicable claims period;
  • user content — while available in the account or until deletion or contract termination; backups expire through the technical rotation cycle;
  • analytics identifiers — as stated in the Cookie Policy.

When a purpose is achieved or consent is withdrawn, processing stops and the data is destroyed within 30 days unless a contract or law permits continued processing without consent. Following an individual's demand, processing stops within 10 business days; this period may be extended by no more than 5 business days with a reasoned notice where continued processing is not permitted by law.

If destruction within the applicable period is technically impossible, the data is blocked and destroyed within no more than 6 months unless federal law sets another period. Destruction is evidenced in the manner prescribed by Roskomnadzor. Limited records may be retained longer only to meet a specific legal or contractual duty, prevent repeated abuse, or protect rights, and only to the necessary extent.

12. Security

We apply legal, organizational, and technical measures proportionate to the data and current threats, including:

  • access controls and least-privilege permissions;
  • protected transfer, secret management, and password hashing;
  • audit logging, backups, and recovery processes;
  • vulnerability management, component updates, and abuse protection;
  • confidentiality commitments;
  • provider assessment and incident response;
  • internal policies, training, and compliance controls.

No storage or transmission method is absolutely secure. Users must protect sign-in credentials, use a strong password, and report suspicious activity promptly.

If unlawful or accidental transfer, provision, dissemination of, or access to personal data infringes individuals' rights, we act to stop the violation and reduce its effects. Roskomnadzor is notified within 24 hours after discovery, and the results of the internal investigation are submitted within 72 hours. Affected individuals are notified where and in the manner required by law or necessary to reduce a material risk.

13. Individual rights

An individual may:

  • obtain information about processing;
  • require correction, blocking, or deletion of incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary data;
  • withdraw consent and unsubscribe from advertising;
  • object to legitimate-interest processing where applicable law provides that right;
  • complain to Roskomnadzor or a competent court;
  • demand termination of processing where statutory conditions are met;
  • exercise other rights granted by mandatory law.

Send a request to team@gerwin.ai. Include your name, response contact, request, and information confirming your relationship with the Operator or the fact that your data is processed. For a statutory access request under Article 14 of Law No. 152-FZ, Russian law also requires identity-document details and a signature; an electronic request must be signed with an electronic signature. Do not send a passport copy unless it is specifically requested and necessary for verification.

Processing information is provided within 10 business days; this period may be extended by no more than 5 business days with a reasoned notice. Confirmed inaccurate data is corrected within 7 business days. Unlawful processing stops within no more than 3 business days after discovery; if it cannot be made lawful, the data is destroyed within no more than 10 business days. A demand to stop processing is fulfilled within 10 business days, subject to a possible extension of no more than 5 business days in the manner allowed by law.

If a request cannot be fully granted, we provide a reasoned refusal citing the applicable law. Withdrawal does not affect earlier lawful processing and does not stop processing supported by an independent legal basis.

14. Marketing

Marketing messages are sent only with separate prior consent where required. Security, billing, material contract changes, and other service communications are not marketing.

Users may unsubscribe through the message link, account settings, or team@gerwin.ai. The request is processed without undue delay.

15. Public materials

Reviews, names, images, case studies, and other personal data are made publicly available only with the separately documented dissemination consent required by law or another valid basis. Users may specify permitted conditions and restrictions within applicable law.

Do not post personal data in public comments or materials unless you intend other people to see it.

16. Foreign mandatory laws

Access to the Resources from another country does not by itself constitute a targeted offering in every foreign jurisdiction. If another country's mandatory law applies to a particular operation, Gerwin AI complies to the required extent and may publish a jurisdiction-specific supplement.

17. Changes

We review this Policy when the Resources, recipients, or law change. A new version applies from its stated publication date. We provide appropriate notice of material changes affecting an earlier consent or contract and request renewed consent where required.

18. Contact

Send privacy questions and requests to the Operator by email at team@gerwin.ai.