Personal Data Processing Policy
Version dated 13 September 2026
This Personal Data Processing Policy explains how Norm CRM processes data of Users, website visitors and other data subjects for the Controller’s own purposes. This Policy is an information document and does not constitute consent to personal data processing.
This English translation is provided for convenience. In the event of any discrepancy, the Russian version shall prevail unless otherwise required by mandatory law.
1. Controller and scope
The Controller is Individual Entrepreneur Egor Vladimirovich Kamelev, Primary State Registration Number of the Individual Entrepreneur (OGRNIP) 311784724500633, Taxpayer Identification Number (INN) 781429913000, registered address: Apt. 62, 21 Granichnaya St., St Petersburg, 197229, Russian Federation. Personal-data requests shall be sent to ekamelev@yandex.ru.
This Policy applies to normcrm.ru, registration, payment, the private CRM, support, service notifications, analytics and platform security.
In relation to information about clients, counterparties, project participants and website visitors uploaded by a User for the User’s own purposes, the User is the controller and Norm CRM processes the data on the User’s instructions. The terms of such processing are set out in Appendix No. 1 to the Terms of Service. This Policy does not replace the User’s own policy for the User’s clients and visitors.
2. Processing principles
The Controller observes the following principles:
- processing data lawfully, fairly and only for purposes determined in advance;
- not collecting excessive information or combining incompatible purposes;
- maintaining accuracy and providing a means of correction;
- retaining identifiable data no longer than the established period;
- maintaining the confidentiality, availability and integrity of data;
- not using User content for undisclosed advertising or the sale of databases.
3. Data subjects and categories of data
The Controller may process data relating to:
- visitors to marketing and registration pages;
- registered and former Users;
- payers and refund applicants;
- persons contacting support or making legal enquiries;
- the User’s administrators and representatives.
Depending on the scenario, the following data may be processed:
- email address, name or display name, language and account settings;
- password hash, activation data, session information and security settings;
- IP address, limited User-Agent, date and time, request ID, login events and security actions;
- registration source: limited UTM tags or the origin of an external referrer without the full path or query string;
- plan, period, amount, internal payment number and status, promo code and related evidence; Norm CRM does not receive bank card details;
- Telegram identifiers, delivery settings, service tokens and Google Calendar information where voluntarily connected;
- subject and contents of an enquiry, attachments and support response history;
- cookies, identifiers and usage statistics for the website and Service;
- the version of accepted Terms and the Policy whose review the User confirmed, date, IP address, User-Agent, request ID and SHA-256 hash of the text.
A password is not stored in plain text or in reversibly encrypted form. Norm CRM stores a cryptographic hash used to verify the entered value.
4. Data sources
Data is obtained:
- directly from the data subject during registration, payment, configuration or an enquiry;
- automatically from the browser, server and security tools when the Service is used;
- from Robokassa regarding the result of a payment initiated by the User;
- from integrations connected by the User within the permissions granted;
- from a data-subject representative or a competent authority in cases provided by law.
5. Purposes, lawful grounds and retention periods
| Purpose | Data and lawful ground | Primary retention period |
|---|---|---|
| Registration, account and provision of the Service | Email address, settings, password hash and session data; entering into and performance of the contract | For the term of the contract and up to 36 months of archive mode after paid access ends |
| Payments, receipts, refunds and accounting | Amount, plan, identifiers and status; performance of the contract and compliance with legal obligations | For mandatory tax, accounting and limitation periods, separately from CRM data that is subject to deletion |
| Authentication, abuse prevention and incident investigation | IP address, User-Agent, request ID and events; performance of the contract, security obligations and the Controller’s legitimate interests without infringing the data subject’s rights | Ordinary security events: up to 180 days; confirmed incident materials: until closure and expiry of the applicable protection period |
| Service notifications and support | Email address, recipients, message or enquiry contents and history; performance of the contract and the User’s initiative | Delivery queue contents: generally up to 90 days; closed enquiries: up to 3 years unless a longer period is required for a dispute |
| Analytics and interface improvement | Cookies, identifiers, visits and events; consent where required, or legitimate interest while respecting the data subject’s rights | According to the relevant analytics counter settings and until the analytics purpose is achieved |
| Evidence of contract formation and completion of data-subject requests | Document versions, actions and correspondence; performance of the contract, compliance with law and protection of rights | For the contract term and at least 3 years after termination unless a longer period is required by law or a dispute |
When paid access ends, working data is retained in free archive mode for up to 36 months so that the User can return, export or delete it. Notices of scheduled permanent deletion are sent 60 and 30 days in advance. The User may request earlier deletion.
6. Processing operations and methods
The Controller performs collection, recording, organisation, accumulation, storage, correction, retrieval, use, transfer to specified recipients, provision of access, anonymisation, blocking, backup, deletion and destruction. Processing is predominantly automated and involves transmission over information and telecommunications networks; certain enquiries and documents may be processed without automation.
The Controller does not make decisions producing legal effects for a data subject solely on the basis of automated profiling.
7. Recipients and providers
| Recipient | Purpose and possible data | Condition |
|---|---|---|
| Hostland | Russian hosting, production database, files and backups | Required for operation of the Service |
| SMTP.BZ | Email address, recipient, subject, message body and service delivery information | Current temporary email delivery provider |
| Robokassa and participants in its fiscal infrastructure | Amount, internal payment number, plan and fiscal item; bank details are entered on the provider’s side | Only for payment or refund |
| Yandex Metrica | Cookies, IP address and page-usage information; Webvisor session replay is used only in environments authorised by the Controller | Marketing and behavioural analytics |
| Telegram | Chat identifier and notification generated by the User | Only after voluntary connection |
| Google Calendar | Calendar data and service tokens within the selected synchronisation | Only after voluntary connection |
| The Controller’s own availability monitoring in Amsterdam | Public technical status or keyword without CRM content, User identifiers or error bodies | Must not use URLs containing personal data or receive application logs |
Data may also be disclosed to a competent authority upon a lawful request, or to a professional adviser or contractor bound by confidentiality, in the minimum necessary scope. The Controller does not sell personal data.
8. Localisation and cross-border transfer
When personal data of citizens of the Russian Federation is collected, its initial recording, organisation, accumulation, storage, correction and retrieval are performed using databases located in the Russian Federation, except in cases expressly provided by law.
Google Calendar, Telegram and other foreign or distributed services may process data outside the Russian Federation. A transfer may occur, in particular, where the User voluntarily connects the relevant integration. The Controller must separately comply with applicable cross-border transfer requirements; disclosure in this Policy does not replace those obligations.
9. Cookies and analytics
Essential cookies are used for sessions, security, selected language, theme and saved settings. Disabling them may make authentication and certain functions unavailable.
Yandex Metrica is used for statistics and behavioural analysis. Webvisor must not be used in the private CRM; it may be used on marketing pages and in specifically designated demo accounts. Real, payment, confidential or other sensitive data should not be entered in a demo. The User may restrict cookies and third-party requests using browser controls. Where applicable law or the nature of the technology requires consent, optional analytics must be enabled on that basis.
10. Security and access
The Controller uses HTTPS, password hashing, access controls, backups, abuse protection, software updates, restricted logging and other measures in view of the nature and risks of processing. Access to content is granted only for support, security, restoration or compliance with a lawful request and only to the extent necessary. The hosting provider’s technical access is governed by the infrastructure contract.
Registration and password reset forms use the Service’s own server-side technical measures against automated submissions, including request rate limits and checks for signs of automated form filling. These measures do not require an external CAPTCHA service and do not guarantee detection of every automated submission.
Absolute protection against every threat is impossible. In the event of a confirmed incident, the Controller performs containment, investigation and mandatory notifications within the periods established by law.
11. Data-subject rights
A data subject has the right to:
- obtain information about processing and access to the data;
- request correction, blocking or destruction of incomplete, inaccurate, unlawfully obtained or unnecessary data;
- withdraw previously given consent without affecting processing based on other lawful grounds;
- object to processing in cases provided by law;
- challenge the Controller’s actions before Roskomnadzor or a court.
Requests shall be sent to ekamelev@yandex.ru. To protect data, the Controller may request information sufficient to verify identity and the link to the account. Responses and required actions are completed within the periods established by Federal Law No. 152-FZ.
12. Deletion and backups
Upon a verified request, the Controller blocks unnecessary processing and deletes the working copy within the period required by law and technical procedure. Data in backups becomes unavailable for ordinary operations and is deleted when the backup cycle is overwritten. If a backup is restored after a failure, the Controller reapplies records of previously completed deletions.
Account deletion is confirmed in the authenticated interface with the password, a one-time code where enabled, a link sent to the account email address and a separate final button. Opening the link does not itself delete anything. Following final confirmation, sign-in and public access stop immediately. The working copy remains in a fully blocked seven-calendar-day security quarantine solely for manual recovery following a verified account compromise, after which irreversible deletion begins. Self-service cancellation is not available. The email address is reserved during the quarantine; once it ends, a new account unrelated to the former account may be created with the same address.
Payment, tax, contractual and incident evidence may be retained separately after account deletion while an independent legal obligation or right of defence remains. Access is restricted to the corresponding purpose.
13. Minors and sensitive data
Norm CRM is not intended for independent registration by minors. The Controller does not ask the User to provide special categories of personal data, biometric data or criminal-record information for registration or payment. If such information is accidentally submitted to support or found during an incident, access is restricted and the matter is handled in view of applicable law and the purpose of the enquiry.
14. Changes to the Policy
Each edition has a date and permanent address. The current version is published on the website. Registered Users are notified of material changes by email or within the Service. If a new purpose requires separate consent, it is requested separately from contract acceptance and acknowledgement of this Policy.
Version: 2026-09-13.1 · 2026-09-13