Privacy Policy

1. About us
This Service is provided by Ivan Makarov, individual entrepreneur, registered in the Russian Federation (TIN 774324436493, OGRNIP 318774600073866), registered address: 125475, Moscow, Dybenko str. 6, bldg. 1, apt. 352 ("Roydis", "we", "us").
For any privacy-related question, write to info@roydis.ru.
2. Scope
This policy explains how we handle personal data in two situations: when you use our website, and when you use a Roydis widget inside your CRM account. Our role differs between the two.
3. Our website
When you contact us or submit a form on roydis.ru, we act as a data controller. We process your name, email address, phone number, and, where you provide them, your company name, job title and location.
We use this data to answer your enquiry and to conclude and perform our agreement (Art. 6(1)(b) GDPR), to meet accounting and tax obligations (Art. 6(1)(c)), to operate and secure the Service (Art. 6(1)(f)), and - only if you have opted in - to send you product news and offers (Art. 6(1)(a)). You can withdraw marketing consent at any time.
Our website uses cookies for analytics. You can accept or refuse them in your browser settings.
4. Widgets in your CRM account
Personal data stored in your Kommo or amoCRM account - contacts, companies and leads - belongs to you. You remain the data controller for it. We act as a data processor and handle that data only to run the widget functionality you have enabled.
In practice this means: we retrieve data from your account at the moment a specific widget operation requires it, use it for that operation, and pass it on where completing the operation requires it. We do not build our own databases of your contacts, and we do not use that data for any other purpose - including our own purposes, marketing, or training machine learning models.
If you obtained the widget through a partner, the partner may act as processor and Roydis as sub-processor. In that case our obligations are set out in the agreement with your partner and are no less protective than those the partner owes you.
From your account we do store one item: the OAuth access token issued when the integration is connected. It is kept in encrypted form for as long as the integration is active, and is revoked and deleted when the widget is disabled.
Some widgets query external enrichment services using an API key you provide in the widget settings. The relationship with such a service is between you and its provider; we do not use our own credentials for your data.
5. Where data is processed
Our servers are located in the Russian Federation, and personal data is processed there. Where personal data is transferred from the EEA or the United Kingdom, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses.
6. How long we keep data
  • enquiries from website forms - up to 3 years from your last contact, or until consent is withdrawn;
  • customer records under a concluded agreement - for the term of the agreement and 5 years afterwards, as required by accounting and tax law;
  • CRM access tokens - for the duration of the integration;
  • technical logs, which contain no personal data - up to 10 days;
  • analytics data - as set by the analytics provider.
If you withdraw consent, we stop processing and erase the data within 30 days, unless the law requires us to keep it.
7. Who else sees the data
We do not sell or trade personal data. We share it only with our hosting provider, payment providers and banks where a payment is involved, email delivery and analytics providers, and public authorities where the law requires it. All of them are bound by confidentiality obligations. A current list of sub-processors is available on request.
8. Security
Access to our systems is limited to authorised personnel. Data in transit is encrypted, access tokens are stored in encrypted form, technical logs contain no personal data, and the software we operate is kept patched and reviewed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a personal data breach affects data we process on your behalf, we will notify you without undue delay and within 24 hours of becoming aware of it, and share the results of our investigation within 48 hours.
9. Your rights
You have the right to access, correct, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. Write to info@roydis.ru to exercise them. You may also lodge a complaint with the supervisory authority in your country.
If your request concerns data held in a customer's CRM account, please contact that customer, who is the controller; we will assist them in responding.
10. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children under 16.
11. Changes
We may update this policy from time to time. The current version is always published at https://roydis.ru/privacy_policy.
12. Contact
Ivan Makarov, individual entrepreneur
125475, Moscow, Dybenko str. 6, bldg. 1, apt. 352, Russian Federation
info@roydis.ru · +7 995 896-64-98

Have more questions?

Fill out the form and we will contact you and help.

Ivan Makarov

Founder of Roydis & Kommo guru

I worked at Kommo back in the days when there were only 10 people there. In addition, I worked as a manager in the TOP 3 among Kommo partners.
This allows us to know a little more than others.
«
»
2018-2024