Privacy Policy
Last updated 2026-10-06
Draft pending legal review. Text in square brackets is to be completed before publication.
1. Who we are
1.1. This Privacy Policy explains how SOFTARTEL LIMITED, D-U-N-S Number 534494520, registered office Pandoras 21, Hadjimattheo Yiannouri Court, 2nd Floor, Office 10, 6042 Larnaca, Cyprus (“we”, “us”) processes personal data of users of Kosmodrom (the “Service”) — the task and team management system available at https://web.kosmodrom.ai, in the Service’s apps, through the API and through the MCP server at https://mcp.kosmodrom.ai.
1.2. Contact for privacy questions and requests: info@soft-artel.com.
1.3. The Service is developed and operated for us by [ООО «СОФТ-АРТЕЛЬ», Russia — role to be confirmed: processor / service provider]. Users in the Russian Federation are served under the Russian-language Политика конфиденциальности with ООО «СОФТ-АРТЕЛЬ» as the operator.
2. Our role
2.1. Controller. We are the controller of the data we need to run your account: sign-in methods and contacts, profile, sessions and security data.
2.2. Processor. Workspace content and employee data that a company (our customer) places in the Service — tasks, chats, files, worklogs, HR records and documents — are processed on that company’s behalf and under its instructions. The company is the controller of that data; requests about it go to the company, and we help the company fulfil them.
3. Data we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Phone number, email, confirmation marks, linked sign-in methods, one-time sign-in codes | registration, sign-in, account recovery, avoiding duplicate accounts | performance of the contract |
| Profile: name, gender, date of birth, avatar, time zone, position, address, contact details, Zoom email | showing you to colleagues, assigning work, meeting invitations | performance of the contract; consent for data received from VK ID and Yandex ID |
| Employment data placed by your company: roles, rates, payments, time off, employee documents | the company’s HR, time and payroll records | processing on the company’s behalf (2.2) |
| Content: tasks, specifications, messages, files, worklogs, meetings, transcripts; data from connected GitLab, GitHub, Figma and Zoom | providing the Service | performance of the contract |
| Technical data: IP address and the country, city and time zone derived from it on our servers, device and browser details, session times, push subscription, activity log, AI usage log (function, model, volume — not the request text) | security, session and device list, rate limiting, incident investigation, notifications, AI cost accounting | legitimate interests in securing the Service; performance of the contract |
We do not use third-party analytics or advertising trackers, do not sell personal data and do not make decisions with legal effects based solely on automated processing.
4. AI features and AI apps you connect
4.1. AI features of the Service (drafting texts, task estimates, summaries, meeting transcripts) send the text needed for a specific request to the model provider listed in section 5. Results are generated automatically and may be inaccurate.
4.2. When you connect an AI app or agent to the Service (for example ChatGPT, Claude or Cursor) through the MCP server or a personal token, that app reads and changes Service data on your behalf, within your permissions and the access you granted. What the app does with the data it receives is governed by the app provider’s terms and privacy policy. You can revoke the access at any time in your profile, Sessions and access tab.
5. Recipients and processors
| Recipient | Purpose | Data |
|---|---|---|
| Users of the same company | collaboration | profile, content; employment data only to users with rights to it |
| Yandex Cloud (Russia) | hosting: servers, database, file storage, monitoring and logs; document recognition (OCR) and YandexGPT | all Service data; document images for passport recognition; content for AI features |
| DeepSeek (China) | AI features | content needed for the specific request |
| SMS Aero (Russia), CheckMobi | sign-in codes via Telegram and SMS, meeting invitations by SMS | phone number, code or invitation text |
| REG.RU (Russia), email hosting | sign-in codes by email; timesheets and orders to the company’s accountant if the company enables it | email, code; names and amounts |
| Dadata (Russia) | filling in company details by tax ID and bank code | tax ID, company name and address; for sole proprietors — their name and tax ID |
| Browser push services (Google, Mozilla, Apple) | push notifications | notification text, name and avatar of the actor |
| VK and Yandex | sign-in with VK ID and Yandex ID | data needed to exchange the authorization code |
| Zoom, Figma, GitLab, GitHub — when connected by the company | company integrations | meeting, design and repository data |
| AI apps you connect (section 4.2) | working with the Service on your behalf | data the app requests within your access |
| Public authorities | legal obligations | on lawful request only |
6. International transfers
The Service is hosted in the Russian Federation, and AI requests may be processed in China. [Transfer mechanism for users in the EEA, the UK and other jurisdictions — to be completed after legal review.]
7. Retention
- Account, profile, sessions and devices — while the account exists.
- Employee data placed by a company — while the company has access to it, for the periods the company sets.
- Data from VK ID and Yandex ID — while the sign-in method is linked.
- One-time sign-in codes — 5 minutes; notifications — 30 days.
- Content — until the user or the company deletes it; archived items are deleted after 7 days, chats after 60 days.
- Database backups — 14 days.
You can request deletion of your account at the contact in 1.2; we delete the data within 30 days, except data a company must keep by law and content that belongs to the company.
8. Cookies and local storage
We use only technically necessary cookies: fsid — an HttpOnly session cookie for file downloads, valid up to
30 days after the last activity; mcp_oauth_sid — the session of connecting an AI app. The web client keeps
session data and a cache in the browser’s local storage; clearing the site data removes it.
9. Your rights
You may request access to your personal data, its correction, deletion or restriction, object to processing based on legitimate interests, receive your data in a portable form and withdraw consent at any time. Many details you can change yourself in your profile. Send requests to the contact in 1.2 from the email of your account; we reply within one month. You may also lodge a complaint with a supervisory authority, in Cyprus — the Commissioner for Personal Data Protection.
10. Security
HTTPS for all connections; sign-in only with one-time codes or VK ID and Yandex ID, no passwords stored; rate limits on codes and requests; personal tokens stored as irreversible hashes; you see and revoke your sessions, app connections and tokens; staff access limited by roles; company data access governed by the rights company administrators grant.
11. Children
The Service is intended for work teams and is not directed at children under 16.
12. Changes
We publish a new version of this Policy at the same address with its date. If a change extends the data we process based on consent, we ask for consent again.