Terms of Service (Public Offer)
Version dated 23 August 2026
These Terms of Service constitute a public offer and govern access to the Norm CRM service. Appendix No. 1 — Personal Data Processing Instructions forms an integral part of these Terms.
This English translation is provided for convenience. In the event of any discrepancy, the Russian version shall prevail unless otherwise required by mandatory law.
1. Parties and general provisions
The Provider is Individual Entrepreneur Egor Vladimirovich Kamelev, Primary State Registration Number of the Individual Entrepreneur (OGRNIP) 311784724500633, Taxpayer Identification Number (INN) 781429913000, registered address: Apt. 62, 21 Granichnaya St., St Petersburg, 197229, Russian Federation. Legally significant communications shall be sent to ekamelev@yandex.ru.
The User is a legally capable individual who has created an account. The Service is primarily intended for independent professional activity, including use by individual entrepreneurs and professional-income taxpayers. If the User purchases access exclusively for personal, family or household purposes, mandatory consumer-protection rules apply to the relationship.
These Terms form a mixed contract covering the right to use software via the internet, information and technical support, and related services included in the selected plan.
2. Contract formation and electronic acceptance
Before registration, the User is provided with permanent links to the exact versions of these Terms, Appendix No. 1 and the Personal Data Processing Policy. The Policy is provided for information and does not itself constitute consent to personal data processing. The User confirms having reviewed it by selecting a separate required checkbox on the registration form.
The User accepts these Terms and Appendix No. 1 by selecting the required checkbox and submitting the registration form. The Provider records the accepted document version, date and time, account identifier, IP address, a limited User-Agent string, request identifier and document checksum.
The email address, password and verified authenticated session constitute the User’s simple electronic signature in dealings with the Provider. Actions performed after successful authentication are deemed to have been performed by the User until the User reports compromised access. The User must keep the password confidential, must not disclose the primary password to third parties, and must promptly terminate unknown sessions or contact the Provider.
3. Scope and functionality of the Service
The Provider grants remote access to Norm CRM at normcrm.ru. The Service is designed to manage clients, projects, tasks, meetings, documents, financial records, files, notifications, public forms and websites, as well as other available functions.
The specific set of functions is determined by the interface, plan description and technical readiness of individual modules. The Provider may develop the interface and architecture, correct errors and replace technical solutions. Such changes must not deprive the User of core access already paid for without a lawful basis, an equivalent replacement or a proportionate adjustment.
Exclusive rights to the software code, design and system documentation belong to the Provider or the relevant right holders. For the duration of access, the User receives a limited, non-exclusive and non-transferable right to use the Service for its intended purpose through its interface.
4. Account and administrators
- A valid email address and password are required for registration; the email address is verified using a link sent by email.
- The User is responsible for the accuracy of registration details and for keeping the contact address current.
- The User may create administrator accounts available under the applicable functionality and independently determines their permissions.
- The User is responsible for actions performed by invited administrators as for the User’s own actions.
- The Provider may temporarily restrict access in the event of a security threat or a breach of law or these Terms, notifying the User where legally permitted and reasonably practicable.
5. Plans, payment, cancellation and refunds
Registration alone does not create a free trial. Full access to the private CRM is enabled after payment is confirmed unless the Provider grants other access individually. The price, duration and contents of the plan are shown before the User proceeds to payment.
- Payment is made by an individual on a cashless basis through Robokassa.
- There is no automatic renewal or automatic charge.
- Bank card details are entered on the payment provider’s side; Norm CRM neither receives nor stores them.
- Receipts are generated and delivered through Robokassa’s payment and fiscal infrastructure.
- A new price applies only to future payments and does not change an already paid period.
5.1. Cancellation of future use
The User may terminate further performance of the contract at any time. As there is no automatic renewal, the User may decline the next period simply by making no new payment. The User may also send a notice to ekamelev@yandex.ru. Unless the User requests early termination of access or a refund, paid access remains available until the end of the paid period.
5.2. Grounds and amount of a refund
The User may request a refund, including where:
- payment was completed but paid access was not activated due to a cause attributable to the Provider or its payment provider;
- the Service was materially unavailable for a prolonged period due to a confirmed failure attributable to the Provider;
- the User did not use paid functionality and submitted a request within 7 calendar days after payment.
In the first two cases, the Provider refunds the value of the part of the service not provided or improperly provided, or, by agreement, grants a proportionate extension of access. In the third case, the Provider grants an additional contractual right to a full refund.
In all other cases, the refund is calculated in accordance with mandatory law, taking into account the part of access actually provided and the Provider’s documented expenses. The contractual seven-day option does not limit the User’s statutory rights in respect of service defects or any other rights granted by law.
5.3. How to request a refund
The request shall be sent to ekamelev@yandex.ru from the account email address or by another method that allows the applicant to be verified. The request should include:
- the name and account email address;
- the payment date and amount;
- the reason for the request;
- the payment identifier or payment document, if available.
Full bank card details are not required. The Provider may request only the information necessary to identify the payment and applicant and to verify the grounds for the refund.
5.4. Review of the request
The request is reviewed within 5 business days after sufficient information is received. If information is missing, the Provider requests clarification. This provision does not extend any mandatory deadline established by law for satisfying the User’s particular claim.
5.5. Refund method and timing
Once approved, funds are returned through Robokassa using the same payment method, generally within 5–7 business days. The actual crediting time may depend on the bank and other payment-system participants. The Provider will notify the User of any known delay.
5.6. Limitations
A fully used paid period is not in itself refundable, except where the service was not provided, was improperly provided, or another mandatory legal ground applies. A breach of these Terms or an account suspension does not automatically deprive the User of mandatory rights: the refund amount and other consequences are determined in view of the part of access actually provided, documented expenses, the nature of the breach and the requirements of law.
6. User Data and materials
Rights to data, text, files, images, code and other materials uploaded by the User remain with the User or the relevant right holders. The User grants the Provider only the technically necessary right to store, copy, transform, display, transmit upon the User’s instruction, back up, export and delete the materials for operation of the Service.
The User independently determines the purposes and lawful grounds for processing information about the User’s clients, representatives, contractors and website visitors. In relation to such personal data, the User is the data controller and the Provider acts on the User’s instructions in accordance with Appendix No. 1.
Free-text fields and files may technically contain any information. The Provider does not review them in advance to determine their legal category. The User undertakes not to upload special categories of personal data, biometric data, criminal-record information, passport details or minors’ data unless the User has a proper legal ground, the necessary documents and safeguards, and Norm CRM functionality is expressly intended for that mode.
7. Notifications and external integrations
The User independently connects Telegram, email, Google Calendar and other available integrations, selects recipients and determines field contents. A meeting, task, project or other object title may be included in a message. By enabling a channel, the User instructs the Provider to generate and transmit the notification to the selected recipient through the relevant provider.
The User must minimise notification contents and must not include information whose transmission through the selected channel is unlawful or creates an unjustified risk. Neutral default values do not relieve the User of responsibility for text modified by the User.
If the User independently gives a third-party AI agent access to a browser session, screen or credentials, the User independently selects the data recipient and is responsible for the lawfulness of that access. Disclosing the primary account password to AI or any other third party is prohibited. Any integrations built into Norm CRM in the future will be governed by a separate description and instruction.
8. Public forms, websites and User JavaScript
Where the relevant functionality is available, the User may publish websites and connect custom domains, forms, payment widgets, external services and User JavaScript within applicable technical limits. Public websites operate in a web environment separate from the private CRM.
The User independently:
- determines website content and holds all necessary rights to the materials;
- acts as the controller of visitor data and determines processing purposes, fields, retention periods, recipients and lawful grounds;
- publishes the User’s own policy, obtains required consents and complies with requirements concerning cookies, advertising, payments and cross-border transfers;
- reviews connected code and providers and is responsible for the consequences of their operation;
- handles visitor requests and claims relating to the User’s website.
The Provider does not continuously pre-moderate websites but may suspend publication upon a substantiated complaint, a security threat, signs of malicious code or a request from a competent authority. The User must assist in reviewing the matter and remedy the violation.
9. Acceptable use
The following is prohibited:
- violating law, third-party rights, confidentiality of communications, intellectual-property rights or confidentiality obligations;
- distributing malware, phishing, spam or knowingly unlawful content;
- circumventing access restrictions, exploring other accounts or creating excessive automated load;
- impersonating another person or using another person’s payment or contact details without authority;
- using the Service for decisions directly affecting human life, health or safety without independent verification and specialised tools.
10. Availability, security and backups
The Provider implements reasonable legal, organisational and technical safeguards, remedies identified vulnerabilities and performs backups. Unless a plan expressly includes an SLA, uninterrupted and error-free operation at all times is not guaranteed. Maintenance, updates and failures of communications, providers or equipment may occur.
The User should use export functionality to retain an independent copy of critical information. The Provider’s backups are intended primarily for disaster recovery of the overall environment and do not replace the User’s archive of individual records.
11. End of paid access, archive and deletion
When the paid period ends, ordinary use of the private CRM is suspended. The account and working data enter a free archive mode for 36 months. During the archive period, the User must retain access to payment renewal, security functions, export of the User’s data and an account-deletion request without being required to purchase a new plan.
Early deletion starts in Account and data after two consecutive warnings, renewed authentication with the password and, where enabled, a one-time code, and confirmation through a link sent to the account email address. Opening the link does not itself delete anything. After the final button is pressed, access stops immediately, all sessions end, and websites, forms, public links and integrations are disabled. Working data enters a fully blocked seven-calendar-day security quarantine solely for manual recovery following a verified account compromise; ordinary cancellation of deletion is not available. Irreversible deletion of the working copy begins after that period.
The email address remains reserved during the security quarantine. Once it ends, a new and independent account may be registered with the same address, but previous data, settings, subscription and trial eligibility are not transferred.
The Provider sends notices to the account email address 60 and 30 days before scheduled permanent deletion. The User may request earlier deletion at any time. Information that the Provider must retain by law or for an existing dispute is separated, access-restricted and deleted when the relevant ground ends. Further details on procedure and timing are set out in the Policy.
12. Liability
Each party is liable for a culpable breach of its obligations within the limits established by law. The User is responsible for the lawfulness of uploaded data, websites, code, selected recipients and instructions, and shall compensate the Provider for documented losses resulting from an established breach by the User.
The Provider is liable for its own culpable breach, including obligations as a person processing personal data on instructions. The Provider is not liable for independent services connected by the User outside Norm CRM mechanisms or for consequences of the User granting access to third parties.
For a User acquiring the Service for business or other professional purposes, the Provider’s liability for ordinary proven direct losses is limited to the amount paid during the three months preceding the event. The limitation does not apply to wilful misconduct, breaches of confidentiality or personal data, harm to life or health, or any other case in which limitation is prohibited by law. This clause does not reduce consumer rights.
13. Term, termination and amendments
These Terms apply from registration until the account is deleted and any mandatory retention of separate information is completed. The User may terminate the contract by requesting deletion. The Provider may terminate the contract for a material or repeated breach after notice and a reasonable cure period, except where immediate suspension is required.
Each new edition is published as a separate version. Active Users are notified of material changes by email or within the Service, generally at least 10 calendar days in advance. Where the nature of the change or law requires new acceptance, the Service requests it separately. Silence does not constitute consent where law requires an express declaration of intent.
14. Notices, requests and disputes
The Provider sends legally significant notices to the account email address or displays them in the authenticated interface. The User sends notices from the account email address to ekamelev@yandex.ru. The parties will seek to resolve disputes through negotiation and exchange of documents.
The laws of the Russian Federation apply. A consumer may use all remedies and jurisdiction rules available under law. In all other cases, the dispute shall be heard by a competent court under the laws of the Russian Federation after compliance with any mandatory pre-action claim procedure required by law.
Appendix No. 1. Personal Data Processing Instructions
This Appendix has the same version as the Terms of Service.
1. Roles and scope of the instructions
The User is the personal data controller in respect of the User’s clients, counterparties, representatives, contractors, project participants, website visitors and other persons whose data the User places in Norm CRM. The User instructs the Provider to process that data solely to provide and technically support the Service. The Provider is a person processing personal data on the controller’s instructions within the meaning of Part 3 of Article 6 of Federal Law No. 152-FZ.
2. Term and documented instructions
These instructions apply from acceptance of the Terms until the relevant data is deleted at the end of the contract, the archive period or pursuant to a lawful request. Documented User instructions include this Appendix, account settings, actions in the authenticated interface and support requests that reliably identify the User and the instruction.
3. Data subjects and categories of data
These instructions may cover:
- the User’s clients and prospective clients;
- counterparties, their representatives and contact persons;
- project participants, contractors and team members;
- visitors to public websites and persons submitting forms;
- other persons whose data the User has lawfully entered into the Service.
Categories of data include: names and other identifiers; contact details; company and professional-role information; projects, tasks, meetings and communications; contractual, commercial and financial records excluding bank card details; form responses; files; User notes and other free-field content. Special categories of personal data, biometric data, criminal-record information, passport details and minors’ data are outside the ordinary scope of these instructions unless a separate written data-handling regime is agreed.
4. Purposes, methods and operations
The purpose of processing is to enable the User to operate the CRM, public forms and websites, including storage, search, organisation, collaboration, notifications, integrations, export, backup, restoration, security and deletion of data. Processing is predominantly automated and includes transmission over communications networks.
Permitted operations include receipt and collection through forms, recording, organisation, accumulation, storage, correction, retrieval, use for display and Service functions, granting access to persons designated by the User, transfer to recipients selected by the User, anonymisation, blocking, backup, deletion and destruction.
5. Provider’s obligations
The Provider undertakes to:
- process data only within the User’s documented instructions and the requirements of law;
- comply with processing principles and rules, maintain personal-data confidentiality and ensure that authorised persons do the same;
- implement the necessary legal, organisational and technical measures under Articles 18.1 and 19 of Federal Law No. 152-FZ;
- upon a substantiated request, provide documents and information evidencing compliance with these instructions without disclosing secrets or other Users’ data;
- assist the User in handling data-subject requests and incident obligations to the extent of the information available to the Provider;
- notify the User of a confirmed incident affecting instructed data without undue delay and, where possible, within 24 hours after confirmation;
- when the processing grounds end, return data through export and delete it under the established procedure, except for information retained on a separate lawful ground.
6. User-controller’s obligations
The User undertakes to:
- have lawful purposes and grounds for processing, provide required information to data subjects and obtain required consents;
- not instruct any operation that conflicts with law or this Appendix;
- ensure accuracy, minimisation, appropriate retention periods and timely deletion;
- respond independently to data subjects and competent authorities as the data controller;
- configure administrator permissions, notification recipients, forms, websites, scripts and integrations consistently with the User’s own documents;
- promptly report account compromise and not include in messages any data that must not be transmitted through the selected channel.
7. Engaged parties and transfer channels
The User authorises the Provider to engage infrastructure and service providers to the extent necessary for selected functions. Current categories include Russian hosting provider Hostland, SMTP.BZ email delivery, Robokassa’s payment infrastructure for the User’s own data, Yandex Metrica, Google reCAPTCHA and, where connected by the User, Telegram and Google Calendar. Current roles and categories of transferred information are disclosed in the Policy.
The Provider’s external availability monitoring is not an ordinary recipient of instructed data: it may only check a public technical status without URLs containing identifiers, application logs, error bodies or CRM content.
User JavaScript, a payment widget or another service independently added by the User to the User’s website is a recipient selected by the User and is not a processor engaged by the Provider. The User instructs the Provider to technically enable that transfer and independently verifies its lawfulness.
8. Localisation and cross-border operations
Primary storage of the production database and User files is organised in the Russian Federation. Certain optional channels and foreign providers, including Google and Telegram, may involve cross-border transfer. The User selects such functions voluntarily and fulfils the User’s own controller obligations; the Provider fulfils the obligations relating to its role and providers selected by it.
9. Access, control and audit
Access to instructed data is granted only to persons who require it for technical support, security, restoration or compliance with a lawful request. Instead of granting the User direct infrastructure access, the Provider may supply descriptions of safeguards, logs relating to a specific incident, review results and other sufficient evidence. An audit must not compromise Service security, other Users’ rights or confidentiality obligations.
10. Retention, return and deletion
While the contract and paid access remain in effect, data is processed for operation of the Service. When paid access ends, data is retained in archive mode for up to 36 months unless the User requests earlier deletion. Export is available during the archive period. The working copy is deleted after a verified request within the time necessary to verify the applicant and safely perform the operation; backups are overwritten according to the backup cycle. Following restoration, the Provider must reapply records of previously completed deletions.
A deletion request confirmed through the interface and email constitutes the User’s documented instruction to cease processing instructed data. The Provider immediately closes user and public access, then keeps the working copy for no more than seven calendar days in a security quarantine solely for a verified account-compromise recovery and thereafter starts irreversible deletion. Data that the Provider must retain on an independent lawful ground is separated from the instructed working database.
11. Liability and precedence of law
The User is responsible to data subjects for the purposes, lawful grounds, scope of data and instructions given. The Provider is responsible to the User for a culpable breach of these instructions. This allocation of responsibility does not limit data subjects’ mandatory rights or the powers of state authorities.
Version: 2026-08-23.2 · 2026-08-24