← Home

Privacy Policy

Version: 2026-07-22 — Effective date: 2026-07-22

1. Introduction

1.1. This Privacy Policy (the "Policy") defines what personal data is collected, how it is processed and protected when using the SmartSplitAI Contract Review service (the "Service").

1.1.A. The Service is oriented toward the B2B sector: individual entrepreneurs, legal entities, their employees, representatives, and other users acting in a professional, entrepreneurial, or contractual context. The Service is not intended for processing personal data of individuals for personal, family, household, or other purposes unrelated to entrepreneurial or professional activity.

1.2. This Policy has been developed taking into account the requirements of:

  • Federal Law of the Russian Federation No. 152-FZ "On Personal Data" (for users from the Russian Federation);
  • Regulation (EU) 2016/679 (GDPR) — for users from the European Economic Area;
  • California Consumer Privacy Act (CCPA/CPRA) — as a reference for user rights.

1.3. The Service does not guarantee full compliance with the requirements of all jurisdictions. Users from countries with special data protection requirements should take this into account when using the Service.

2. Who is the Data Operator (Controller)

2.1. The person responsible for the storage and processing of personal data within the SmartSplitAI service — Sergei V. Stepanov.

2.2. Contact email for all matters related to personal data processing: info@smartsplitai.net.

2.A. Categories of Personal Data Subjects

The Service may process personal data of the following persons:

  • Registered users — persons who have created an account in the Service;
  • Organization members — users invited by the organization owner or administrator;
  • Approvers (customer) — persons designated by the customer as report recipients or approvers;
  • Payers — persons whose data is indicated in payment documents;
  • Unregistered visitors — persons visiting public pages of the Service.

3. What Data is Collected

3.1. During registration: email, name.

3.2. During use of the Service:

  • organization and profile information;
  • uploaded documents (contracts, appendices, other materials);
  • AI Analysis results and reports;
  • user role in the organization.

3.3. Technical data collected automatically:

  • IP address and country of access (optional, via GeoIP);
  • browser type and operating system (User-Agent, when logging acceptances);
  • cookies for session maintenance and language preference storage (see Cookie Policy);
  • access and error logs.

4. Purposes of Processing

4.1. Personal data processing is carried out for the following purposes:

  • providing access to the Service and its functionality;
  • uploading documents and performing AI Analysis;
  • displaying review history and analysis results;
  • sending email notifications about analysis completion;
  • sending notifications about registration, invitations, password reset, and email verification;
  • ensuring Service security and preventing unauthorized access;
  • complying with applicable legal requirements;
  • preparing payment documents and accounting support.

5. Legal Basis for Processing

5.1. Processing is carried out on the following legal bases:

  • performance of the contract with the User (Terms of Use);
  • the User's consent (during registration and acceptance of agreements);
  • legitimate interest of the Service (security, fraud prevention, functionality improvement);
  • compliance with applicable legal requirements.

6. Data Storage and Deletion

6.1. Personal data is stored for the duration of the User's account and for the necessary period after its closure for financial, tax, and contractual accounting, security, and dispute resolution purposes in accordance with applicable law.

6.2. A data deletion request should be sent to info@smartsplitai.net. Before executing deletion, the Service administration is entitled to verify the identity of the requester. Data will be deleted or anonymized within a reasonable period, except where retention is required by applicable law.

6.3. Documents, reports, and technical copies are processed in accordance with the Service's retention policy. Data required for financial, tax, and contractual accounting, security, and dispute resolution may be retained within the mandatory period. Until precise retention periods are established, a specific deadline for physical deletion cannot be promised.

7. Transfer of Data to Third Parties

7.1. The Service may transfer data to the following categories of recipients:

  • Category: AI providers — text or fragments of uploaded documents are transmitted for analysis. Changing the model or AI provider does not require changes to this Policy if the purposes, data categories, and processing conditions remain unchanged. A third-party contractor shall not use documents for independent purposes unless separately disclosed and permitted by applicable terms;
  • Category: infrastructure contractors — for hosting, sending email notifications, and ensuring Service operation;
  • Category: payment infrastructure — to the extent necessary for processing and executing payments;
  • as required by applicable law or a competent authority;
  • with the User's consent — to other recipients.

7.2. The Service does not sell personal data to third parties and does not transfer data to AI providers for independent use outside the provision of the service, except where required by the selected technical integration and disclosed in the terms of the relevant provider.

8. Cross-Border Transfer

8.1. When using certain technical services and infrastructure, personal data may be processed using infrastructure and technology providers located in various countries, provided there are legal grounds and taking into account the applicable requirements of personal data legislation.

8.2. To perform document analysis, the Service may transfer text or fragments of documents to external AI/technical providers. Such transfer is carried out only to the extent necessary to provide the service. The Service selects providers taking into account available confidentiality and data processing terms. The Service does not transfer data to AI providers for independent use outside the provision of the service, except where required by the selected technical integration and disclosed in the terms of the relevant provider. The User understands that data processing by an AI provider is also governed by the terms of that provider.

9. User Rights

9.1. The User has the following rights regarding their personal data:

  • Right of access — request information about what data is being processed;
  • Right to rectification — request correction of inaccurate data;
  • Right to erasure — request data deletion ("right to be forgotten"), where applicable;
  • Right to restriction of processing — in cases provided for by law;
  • Right to data portability — receive data in a machine-readable format;
  • Right to object — object to processing in certain cases.

9.2. The User may contact the competent supervisory authority if such a right is provided by applicable law.

9.3. To exercise these rights, a request must be sent to info@smartsplitai.net. Requests are processed within a reasonable period.

10. Security Measures

10.1. The Service takes reasonable technical and organizational measures to protect personal data:

  • passwords are stored in hashed form (bcrypt);
  • data access is limited by user and administrator roles;
  • data transmission between the User and the Service is performed over HTTPS;
  • regular updating of dependencies to eliminate vulnerabilities.

10.2. Despite the measures taken, the Service cannot guarantee absolute data security when transmitted over the Internet.

11. Changes to the Policy

11.1. The Service reserves the right to amend this Policy. The new version takes effect upon publication.

11.2. In the event of material changes to the Policy, Users may be notified by email or through the Service interface.