Privacy Policy

Last updated: 11 August 2026

This Privacy Policy (the "Policy") describes how INCRAM LLC (ООО «Инкрам», the "Company") processes and protects personal data received through the website https://incram.com (the "Site").

1General provisions

1.1This Policy forms an integral part of the Terms of Use and of any other agreement concluded with the User in the course of using the Site, where those agreements expressly say so.

1.2This Policy applies to all personal data the Company may receive from the User during use of the Site.

1.3The Company does not control and is not responsible for third-party websites the User may reach through links published on the Site. Those websites operate their own privacy policies and may collect or request data on their own terms.

1.4For specific services the Company may publish additional terms that supplement this Policy.

2Data processed and the purposes of processing

2.1By submitting the contact form or otherwise contacting the Company through the Site, the User freely, by their own will and in their own interest, provides their personal data to the Company for processing.

2.2Processing means the actions set out in Federal Law No. 152-FZ of 27 July 2006 "On Personal Data", performed with or without automation, including collection, recording, systematisation, accumulation, storage, clarification, retrieval, use, transfer, blocking, deletion and destruction of personal data.

2.3The Company processes the following categories of data, submitted voluntarily through the contact form:

  • full name
  • company name and position
  • email address
  • Telegram handle, where provided
  • the content of the message sent to the Company

2.4The purposes of processing are limited to the following:

  • responding to the enquiry submitted and conducting the ensuing correspondence
  • preparing a commercial proposal at the User's request
  • concluding and performing an agreement where the enquiry leads to an engagement
  • fulfilling obligations imposed on the Company by the legislation of the Russian Federation, including accounting and anti-money-laundering requirements
  • responding to lawful requests from state authorities

2.5The Company does not process special categories of personal data, biometric personal data, or data of persons under the age of majority through the Site.

2.6The Company does not use personal data collected through the Site for automated decision-making that produces legal effects for the User.

2.7Personal data is processed for the period necessary to achieve the purposes set out above, and thereafter for the period during which the Company is required to retain it under the legislation of the Russian Federation. Enquiries that do not lead to an engagement are destroyed within twelve months.

3Principles and methods of processing

3.1In processing personal data the Company follows these principles:

  • the purposes and methods of processing are lawful
  • processing is confined to the purposes stated at the point of collection
  • the volume and nature of the data processed correspond to those purposes
  • no data is collected in excess of the stated purposes
  • the accuracy of the data processed is maintained
  • data collected for incompatible purposes is held separately

3.2Processing is carried out both with and without the use of automation.

4Rules of processing

4.1Personal data is obtained directly from Users in the course of their use of the Site, save where this Policy provides otherwise.

4.2Collection of personal data is carried out using databases located in the territory of the Russian Federation.

4.3Personal data may be transferred to third parties only with the User's consent, or in the cases provided for by the legislation of the Russian Federation and on the basis of the requirements of federal law. Where the Company engages a processor to act on its instructions, that processor is bound by equivalent confidentiality and security obligations.

4.4Where an engagement requires work to be performed by a licensed partner, personal data necessary for that work is transferred only to the extent required and only after the User has been informed.

5Security of personal data

5.1The Company takes the protective measures required by the legislation of the Russian Federation to ensure the confidentiality and security of personal data, including:

  • a person responsible for the security of personal data has been appointed
  • current threats to the security of personal data have been identified
  • a set of protective measures neutralising those threats has been designed and implemented
  • rules for securing personal data during processing have been established
  • the effectiveness of the measures taken is reviewed periodically

6Rights of the User

6.1Under Federal Law No. 152-FZ of 27 July 2006 "On Personal Data", Users have the right to request information about the personal data the Company processes about them, including:

  • confirmation that processing is taking place
  • the legal grounds and purposes of processing
  • the methods of processing applied
  • the full name and location of the Company, and details of third parties with access to the data
  • the categories of data processed and their source
  • the periods of processing and storage
  • the procedure for exercising the rights of a data subject
  • information about any cross-border transfer of data, actual or intended
  • the name and address of any processor acting on the Company's instructions

6.2Users further have the right to require access to the data processed; to require correction of data that is incomplete, out of date or inaccurate; to require blocking of such data or of data processed unlawfully; and to require destruction of data obtained unlawfully or no longer necessary for the stated purpose.

6.3Users have the right to require that the Company notify all persons to whom incorrect or incomplete data was previously disclosed of every correction, exclusion or addition made.

6.4Users have the right to appeal unlawful acts or omissions of the Company to the authorised body for the protection of the rights of data subjects, or before the courts.

7Correction and destruction of personal data

7.1Personal data processed by the Company is destroyed in the following cases:

  • on achievement of the purposes of processing, or on loss of the need to achieve them, within thirty days
  • on discovery of unlawful processing, within ten working days of discovery
  • on withdrawal of consent, where retention is no longer required for the purposes of processing, within thirty days of receipt of the withdrawal
  • on expiry of the retention period determined under the legislation of the Russian Federation
  • on the order of the authorised body for the protection of the rights of data subjects, of the Prosecutor's Office, or by decision of a court

7.2Consent to the processing of personal data may be withdrawn at any time. To exercise this right, the User sends the corresponding request to info@incram.com.

7.3Withdrawal of consent does not by itself terminate processing where the Company has grounds under clauses 2, 7 and 10 of part 1 of article 6 of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data".

8Contact

8.1Questions regarding this Policy, and requests to exercise the rights described in section 6, are sent to info@incram.com.

8.2The Company may amend this Policy. The current version is always published on this page, and the date of the last revision is shown above.

Questions about this document: info@incram.com