Information

Политика конфиденциальности

Public legal and informational pages should feel clear and lightweight, not like another landing-page hero.

Page content

his Privacy Policy (the “Policy”) sets out how personal data of users of the “AI SMM” online service, available at https://ai-smm.com (the “Service”), is processed and protected.

The operator of personal data (for the purposes of Russian law) and the data controller (for the purposes of the GDPR) is Individual Entrepreneur Vladislav Nikolaevich Aksenov, Krasnodar, Russia (the “Company”, “we”). By using the Service, you confirm that you have read this Policy and, where required by law, consent to the processing of your personal data on the terms set out below.

1. General provisions

1.1. This Policy has been prepared primarily in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), which applies to users located in the European Economic Area (EEA) and other international users, and, as the Company is established in Russia, also in accordance with Russian Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (“152-FZ”).

1.2. This Policy applies to all personal data that the Company receives from users while they use the Service, including the website, personal account, mobile and desktop applications, and related features and interfaces.

1.3. Using the Service constitutes the user’s acceptance of this Policy. If the user does not agree with this Policy, they must stop using the Service.

2. Definitions

  • Personal data — any information relating to a directly or indirectly identified or identifiable natural person (the data subject).

  • Processing — any operation or set of operations performed on personal data (collection, recording, organisation, storage, use, transfer, anonymisation, deletion, etc.).

  • User — a natural person using the Service.

  • Consent — a freely given, specific, informed and unambiguous indication of the user’s agreement to the processing of their personal data.

  • AI processing — processing of data entered by the user using machine-learning algorithms and neural-network models to produce the output of the Service.

3. Categories of personal data processed

3.1. When you register for and use the Service, we may process the following data:

  • Identification and contact data: name, username, email address, phone number;

  • Account data: password (in encrypted form), profile settings, subscription status;

  • Payment data: information about payments made and the selected plan (card details are processed by the payment provider and are not disclosed to the Company in full);

  • User content: prompts, files, images and other data that the user submits to the Service for processing by neural-network models;

  • Technical data: IP address, browser and device type and version, operating system, session data, cookies, activity logs;

  • Usage data: query history and statistics on the use of Service features.

3.2. The Company does not intentionally request, and asks users not to submit through the Service, special categories of data (concerning health, racial or ethnic origin, political, religious beliefs, etc.), nor third-party personal data without a proper legal basis.

4. Purposes of processing

Personal data is processed for the following purposes:

  • registering and identifying the user and providing access to the personal account;

  • providing the functionality of the Service, including AI processing of requests and generation of output;

  • accepting and processing payments, arranging and renewing subscriptions;

  • technical support and responding to user requests;

  • improving the quality and security of the Service, usage analytics, and preventing fraud and abuse;

  • sending service messages and, subject to consent, marketing communications;

  • complying with applicable legal requirements.

5. Legal bases for processing

5.1. Under Russian law (152-FZ), processing is carried out on the basis of the data subject’s consent, as well as where processing is necessary to perform a contract to which the user is a party, or to achieve purposes provided for by law.

5.2. Under the GDPR, the legal bases for processing are:

  • performance of a contract with the user (Art. 6(1)(b) GDPR);

  • the data subject’s consent (Art. 6(1)(a) GDPR) — e.g. for marketing communications and certain cookies;

  • the Company’s legitimate interests (Art. 6(1)(f) GDPR) — ensuring security, preventing abuse, and improving the Service;

  • compliance with a legal obligation of the Company (Art. 6(1)(c) GDPR).

6. AI-specific processing

6.1. The Service uses neural-network models to process data entered by the user (prompts, files, images) and to generate output. Such data is processed to the extent and for the time necessary to provide the service.

6.2. The Company does NOT use user content (prompts, files, images) to train or fine-tune its neural-network models. User content is processed solely to generate output as part of providing the service.

6.3. Requests are processed on the Company’s own infrastructure; user content is not transferred to third-party AI-model providers. The only exceptions are payment data processed by the payment service (Section 8) and data whose disclosure is required by law.

6.4. AI outputs are probabilistic in nature and may contain inaccuracies; the Company does not guarantee their completeness or accuracy and does not make decisions producing legal effects for the user based solely on automated processing without the right to human review.

7. Cookies and tracking technologies

7.1. The Service uses cookies and similar technologies to ensure functionality, remember settings, perform analytics and, subject to consent, marketing.

7.2. The user may manage cookies through browser settings and the consent banner on the Service. Disabling certain categories of cookies may limit the functionality of the Service.

8. Data sharing and international transfers

8.1. The Company does not sell personal data and does not transfer user content to third-party AI providers. Data may be shared with the following recipients solely for the purposes set out in Section 4:

  • the payment service Stripe (Stripe, Inc.) — to accept and process payments;

  • government authorities — in cases provided for by law.

8.2. Payments are processed through Stripe; card details are entered on Stripe’s side and are not disclosed to the Company in full. Stripe’s processing of data is governed by its own privacy policy.

8.3. The Company is established in Russia, and the Service may be used by users located in other countries. For cross-border transfers of personal data (including payment data transferred to Stripe), the Company uses appropriate safeguards for the purposes of the GDPR (including Standard Contractual Clauses or transfers to countries with an adequate level of protection) and complies with applicable Russian law.

9. Data retention

9.1. In line with the data-minimisation principle (GDPR), personal data is stored no longer than necessary for the purposes of processing. Account data is stored for the duration of the account.

9.2. After account deletion, personal data is deleted within 30 (thirty) days, and from backups within 90 (ninety) days. Longer retention applies only to the extent and for the period expressly required by applicable law (e.g. for accounting and tax purposes).

9.3. Upon expiry of the retention periods, or upon withdrawal of consent where no other legal basis exists, data is deleted or anonymised.

10. Data subject rights

10.1. The user has the right to:

  • obtain information about, and access to, their data;

  • request rectification, restriction or erasure of data that is incomplete, outdated, inaccurate or processed unlawfully;

  • withdraw previously given consent;

  • data portability, restriction of processing and objection to processing (for EEA users — to the extent provided by the GDPR);

  • lodge a complaint with a supervisory authority — Roskomnadzor (Russia) or the data-protection authority in their country of residence (EEA).

10.2. To exercise these rights, the user may send a request to info@ai-smm.com. The Company will respond within the timeframes set by applicable law.

11. Data security

11.1. The Company implements the necessary legal, organisational and technical measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including encryption, access control, backups and security monitoring.

11.2. In the event of a data breach posing a high risk to users’ rights, the Company will notify the competent authority and affected users within the timeframes set by law.

12. Children’s data

The Service is not intended for persons under the age of 16. The Company does not knowingly collect data of minors without the consent of their legal guardians. Any such data identified will be deleted.

13. Changes to this Policy

The Company may amend this Policy. The current version is published on the Service with the effective date indicated. Material changes are additionally communicated to users by available means.

14. Contact information


Website: https://ai-smm.com

Data-protection email: info@ai-smm.com