Personal Data Processing Policy
This Policy describes what data the NeznakovBoost service collects, for what purposes, with whom it shares it, how long it stores it and how it protects it. The document has been drawn up in view of the requirements of Federal Law No. 152-FZ "On Personal Data" (Russian Federation) and the Law of the Kyrgyz Republic "On Personal Data".
Revision of 3 September 2026
1. General Provisions
1.1. This Personal Data Processing Policy (hereinafter the "Policy") governs the collection, storage, use and other processing of the personal data of users of the neznakov.ru website and its related services (the Personal Account, support chat, Telegram bot, monitoring, etc.).
1.2. Use of the site, placing an order, paying for a service, registering in the Personal Account and/or any other interaction with the Service constitutes the User's full and unconditional consent to this Policy and to the terms of processing of their personal data.
1.3. If the User does not agree with the terms of the Policy, they must immediately cease using the site and not transfer any personal data to the Operator.
1.4. The Operator is entitled to amend the Policy unilaterally in accordance with Section 22 of this Policy. The current revision is always posted at neznakov.ru/privacy. Use of the Service after a new revision is published constitutes the User's consent to its terms.
1.5. The Policy supplements the Service's Public Offer; in the event of a conflict between the documents regarding data processing, this Policy prevails, and on other matters the Offer prevails.
2. Terms and Definitions
- Operator — Alliance Torg Company LLC, which organises the operation of the NeznakovBoost Service (see Section 23).
- Service / Site — the neznakov.ru information resource and its related services.
- User / Data Subject — any natural person who uses the Service or transfers their data to the Operator.
- Personal Data — any information relating directly or indirectly to an identified or identifiable User.
- Processing — any action or set of actions performed on personal data: collection, recording, organisation, accumulation, storage, rectification, use, transfer, anonymisation, blocking, deletion, destruction.
- Biometric Personal Data — information characterising a person's physiological and biological features (fingerprints, a facial image for identification, voice prints, DNA).
- Special Categories of Data — information about racial or ethnic origin, political opinions, religious and philosophical beliefs, health, sex life or criminal record.
- Engaged Contractor — an independent person (booster, coach, support operator) engaged by the Operator to actually render the service.
- Authorised Authority — the state body that supervises personal data protection: for the Russian Federation — Roskomnadzor; for the Kyrgyz Republic — the State Agency for Personal Data Protection under the Cabinet of Ministers of the KR (or its legal successor).
- Incident — an event resulting in a breach of the confidentiality, integrity or availability of personal data, including leakage, unauthorised access, loss, destruction, or unlawful or accidental transfer.
3. Operator Details
3.1. The personal data operator within the meaning of the applicable law is:
Alliance Torg Company LLC, Kyrgyz Republic, Bishkek, Oktyabrsky District, 7th microdistrict, Bezymyannaya St., 37/2; OGRN 310076-3301-OOO; INN 9909710244; website neznakov.ru.
3.2. The Operator is a foreign legal entity in relation to the Russian Federation. When processing the personal data of citizens of the Russian Federation, the Operator observes the requirements of Federal Law No. 152-FZ.
3.3. The person responsible for organising the processing of personal data (within the meaning of Art. 22.1 of Federal Law No. 152-FZ): the head of the support and compliance department of the NeznakovBoost Service. The responsible person may be contacted via the contacts page marked "For the person responsible for PD processing" or through the official support channels.
3.4. Notification of the authorised authority. The Operator, as a foreign legal entity collecting the personal data of citizens of the Russian Federation using the "Internet" information and telecommunications network, files a notification of its intention to process personal data with Roskomnadzor under Parts 1 and 2.1 of Art. 22 of Federal Law No. 152-FZ. Information about the Operator is entered, in the established manner, into the Register of operators processing personal data.
4. Categories of Processed Data
The Operator collects and processes the following categories of personal data:
| Category | Data composition | Purpose of processing |
|---|---|---|
| Identification | Nickname/name, country, time zone, and — where verification is required — a photo of an ID document and/or a selfie | Identifying the User, countering fraud and fraudulent chargebacks |
| Contact | Telegram, VKontakte, Discord, e-mail, phone number | Contacting the User, order status notifications, support |
| Steam account data | Steam login, password, Steam Guard codes, SteamID, linked e-mail/phone addresses | Rendering services that require access: boosting, calibration, MMR recovery, behaviour recovery, Battle Cup, account rental |
| Game statistics | MMR, Behavior Score, medals, match history, rank, hero and role statistics | Calculating the cost of a service, showing progress in the Personal Account and in the "Monitoring" section |
| Order data | Order number, service type, cost, date, status, selected parameters | Recording and fulfilling the order, resolving disputes |
| Payment information | Payment method, amount, provider, transaction status, masked details (last 4 digits of the card) | Recording payments, protection against chargebacks; the Operator does not receive or store full card details |
| Technical | IP address, browser and device type, OS version, screen resolution, session identifiers, fingerprint, referral source (referrer, ?ref) | Ensuring the site works, analytics, protection against automated attacks, anti-fraud |
| Behavioural | Action logs in the Personal Account, pages visited, session duration, clicks performed | Analytics, interface improvement, incident investigation |
| Communications | Correspondence in the Personal Account, messengers (Telegram), e-mail, voice and text messages, and — where necessary — call recordings | Support, quality control, evidentiary basis in disputes with the User, banks and payment providers |
| Referral | Referral code, history of invitees, referral account balance | Administering the referral programme, protection against abuse |
4.1. The Operator does not process biometric personal data or special categories of personal data (information about racial or ethnic origin, political opinions, religious and philosophical beliefs, health, sex life or criminal record). If such information accidentally comes into the Operator's possession (for example, when the User uploads documents), it is subject to deletion at the earliest opportunity.
4.2. Documents uploaded during verification (KYC) are used solely for the purpose of identifying the User in cases of suspected fraud and are deleted within the periods specified in Section 9 of this Policy.
5. Purposes of Processing
5.1. Personal data is processed solely for the following purposes:
- Concluding and performing the contract (the Public Offer) — rendering the services paid for by the User;
- Identifying the User and verifying their authority, including in cases of suspected fraud;
- Communicating with the User: order status notifications, support, informational messages;
- Calculating the cost of services, maintaining the Personal Account, showing progress and order history;
- Ensuring the operability and security of the site, protection against attacks, fraud and unauthorised access;
- Providing an evidentiary basis for claims, chargebacks, court and other disputes;
- Administering the referral programme and rewards;
- Using anonymised game statistics (MMR, win rate, screenshots without identifying features) for marketing purposes — the "Reviews", "Monitoring" and "Match history" sections and the Service's social media;
- Analysing site traffic and on-site behaviour, improving the user experience;
- Complying with the requirements of applicable law and responding to lawful requests from government authorities.
5.2. The Operator does not use personal data for purposes not specified in this section and does not transfer it to third parties beyond the cases expressly provided for by the Policy.
5.3. Use of data for training artificial intelligence models. The Operator does not transfer Users' personal data to third parties for training publicly available artificial intelligence models (LLM, ML, generative models) and does not use it to train external models for commercial purposes. Internal use of anonymised and aggregated data for the Operator's own analytical, anti-fraud and predictive models is permitted without an identifying link to a specific User.
6. Legal Grounds for Processing
6.1. The Operator processes personal data on the following grounds:
- The User's consent — expressed by starting to use the site, placing an order, paying for services, registering in the Personal Account and/or otherwise interacting with the Service;
- Performance of the contract with the User (the Public Offer) — data processing is necessary to render the paid service;
- Protection of the rights and legitimate interests of the Operator and third parties — countering fraud, defending in disputes, ensuring the security of the service;
- Compliance with the requirements of applicable law and responding to lawful requests from authorised government bodies.
7. Principles of Personal Data Processing
7.1. The Operator processes personal data on the basis of the following principles (Art. 5 of Federal Law No. 152-FZ, Art. 5 of Regulation (EU) 2016/679):
- Lawfulness, fairness and transparency — processing is carried out on the legal grounds specified in Section 6 and in accordance with this Policy, which is made publicly available;
- Purpose limitation — data is collected for specific, predefined and lawful purposes (Section 5) and is not used for other purposes incompatible with those declared;
- Data minimisation — only the data necessary to achieve the relevant purposes is processed; excessive data is neither requested nor stored;
- Accuracy — the Operator takes reasonable measures to keep data accurate and up to date; inaccurate data is subject to rectification, correction or deletion at the User's request (Section 19);
- Storage limitation — data is stored no longer than the periods established by Section 9 of this Policy and applicable law;
- Integrity and confidentiality — data is protected by technical and organisational measures against unauthorised access, loss, alteration and destruction (Section 18);
- Operator accountability — the Operator is obliged to comply with the established processing principles and is able to demonstrate such compliance to the authorised authority and to data subjects.
8. Consent to Processing and Its Withdrawal
8.1. Consent to the processing of personal data is given by the User freely, voluntarily, by their own will and in their own interest. Consent is given with respect to the composition, purposes and periods of processing specified in this Policy.
8.2. Consent may be expressed in any of the following ways:
- continued use of the Site after the informational cookie banner has been shown, or pressing «Accept» in it (see section 12);
- acceptance of the Public Offer in the manner provided for by the Offer;
- placing and/or paying for an order on the Site;
- registering and/or logging in to the Personal Account;
- sending a message to any of the official support channels (Telegram, Discord, e-mail, feedback forms);
- ticking a dedicated checkbox in a form on the Site, where one is provided;
- any other implied action that clearly indicates an intention to use the Service.
8.3. Consent remains in force until withdrawn by the User or until the periods established by applicable law expire, whichever occurs later.
8.4. Withdrawal of consent: the User has the right to withdraw their consent to the processing of personal data by sending a written request via the contacts page or the Service's official support channels. When withdrawing consent, the User must confirm their identity in the manner described in Section 19 of this Policy.
8.5. Consequences of withdrawal: withdrawal of consent entails the inability to further use the Service. At the same time, the Operator is entitled to continue processing personal data without the User's consent to the extent necessary for:
- performing services already paid for by the User;
- protecting the rights and legitimate interests of the Operator in disputes with the User, banks and payment providers (including chargebacks and court proceedings);
- complying with the requirements of applicable law, including tax and accounting law;
- storing information for the periods established by Section 9 of this Policy.
8.6. The Operator ceases processing personal data upon a request to withdraw consent within 30 (thirty) calendar days of receiving the relevant request, except in the cases specified in clause 8.5.
9. Methods and Periods of Processing
9.1. Processing is carried out both with and without the use of automation tools (mixed processing).
9.2. Localisation of storage of the data of Russian Federation citizens. When collecting the personal data of citizens of the Russian Federation, the Operator ensures the recording, organisation, accumulation, storage, rectification (updating, modification) and retrieval of data using databases physically located on the territory of the Russian Federation, in compliance with the requirements of Part 5 of Art. 18 of Federal Law No. 152-FZ. Any subsequent cross-border transfer of data is carried out in accordance with Section 11 of this Policy.
9.3. Retention periods for individual categories of data:
| Category | Retention period |
|---|---|
| Steam account authorisation data (password, Steam Guard codes) | For the duration of the service; deleted within 72 hours of its completion |
| Identification and contact data | 3 years from the last interaction with the Service |
| Order data, transaction statuses | 3 years (for accounting, anti-fraud and dispute-defence purposes) |
| Verification documents (KYC: ID photo, selfie) obtained during a fraud investigation | Up to 1 year from completion of the check, then destroyed |
| Correspondence and communication records | 3 years from creation (for evidentiary purposes) |
| Technical data (IP, fingerprint, session logs) | Up to 12 months |
| Cookies and browser local-storage entries | According to the period specified when the cookie is set (up to 12 months); the nb_client_ref referral code — 30 days |
| Anonymised game statistics | Indefinitely, for marketing and analytical purposes |
9.4. Upon expiry of the periods, data is subject to deletion or anonymisation, except where a longer retention period is required by applicable law or is necessary to protect the Operator's rights in pending disputes.
10. Transfer of Data to Third Parties
10.1. The Operator does not sell, rent out or transfer Users' personal data to third parties, except in the cases listed below and only to the extent necessary to achieve the relevant purpose:
- Engaged contractors (boosters, coaches, operators) — receive account authorisation data, contact details and order parameters to the extent necessary to render the service; they undertake to keep the transferred information confidential;
- Payment providers and acquiring banks — process the User's payments; card details and other payment data are transferred directly from the User's device to the payment page of a provider certified to the PCI DSS standard; the Operator has no access to full card data, CVV codes, PIN codes, or bank and app passwords; the Operator is given only the transaction status, the operation identifier and masked details (last 4 digits of the card);
- Infrastructure providers — hosting, CDN, mail servers, push-notification and analytics providers (process data as technical contractors on the basis of processing agreements);
- Anti-fraud services — to prevent fraud, fraudulent chargebacks and unauthorised access;
- Government authorities — upon receipt of a lawful written request, in the manner and within the limits provided for by applicable law;
- Payment providers and banks within a payment dispute (chargeback) procedure — to rebut bad-faith disputes, the Operator is entitled to transfer any available evidence that the service was rendered: Personal Account logs, correspondence, screenshots of game activity, IP addresses, metadata.
10.2. Reorganisation, sale of the business, bankruptcy, succession. In the event of the Operator's reorganisation (merger, accession, division, spin-off, transformation), the sale of the business or part of it, the transfer of assets in discharge of obligations, bankruptcy, liquidation or other succession, the Operator is entitled to transfer Users' personal data to the successor in full without obtaining separate consent from Users. In doing so, the successor assumes all obligations established by this Policy and by applicable personal data protection law. The User is notified of the change of Operator via the neznakov.ru site or by another available means within a reasonable time.
10.3. The transfer of data under clauses 10.1–10.2 of this Policy is carried out on the basis of concluded agreements obliging recipients to observe confidentiality and applicable personal data protection law.
11. Cross-Border Data Transfer
11.1. Given that the Operator is a legal entity of the Kyrgyz Republic, while the Service's infrastructure may be hosted across several jurisdictions, the User confirms their consent to the cross-border transfer of their personal data to the Kyrgyz Republic, the Russian Federation and other countries in which the Operator's technical contractors are located.
11.2. The Operator takes reasonable measures to ensure adequate protection of the transferred data, including by concluding agreements with contractors obliging them to observe confidentiality.
11.3. When transferring the data of citizens of the Russian Federation across borders, the Operator complies with the procedure established by Art. 12 of Federal Law No. 152-FZ, including the requirements for prior notification of the authorised authority in the cases provided for by law.
12. Cookies, Local Storage and Third-Party Services
12.1. The Site uses cookies, browser local storage (localStorage, sessionStorage), pixels and other tracking technologies, which are classified as follows:
| Type | Purpose | Consent |
|---|---|---|
| Technical (necessary) | Sessions, Personal Account login, CSRF protection, basic site operability | Not required (mandatory for the service to work) |
| Functional | Remembering the language, theme, recently viewed services and the referral code (nb_client_ref) | Implied — given by continuing to use the site |
| Audience counter | The Operator's own anonymised count of concurrent visitors and page views, not shared with third parties. The visit identifier is kept in sessionStorage (nb_sid) and is discarded when the tab is closed | Not required (necessary for the operation and protection of the Service; does not allow the User to be recognised on a later visit) |
| Analytical | Yandex Metrica (including Webvisor) and Google Analytics 4: visit statistics, on-site behaviour, traffic sources. Persistent visitor identifier nb_vid with a 12-month lifetime | Implied — the counters run from the moment the site is opened, which the banner states. Pressing «Decline» switches them off and deletes the identifiers already stored |
| Advertising attribution | The source of a paid click (utm_*, yclid, gclid) stored under the nb_attr key | Implied — together with the analytical category |
| Anti-fraud | Device identification (fingerprint), protection against automated attacks and fraud | Not required (protection of the Operator's rights and legitimate interests) |
| Push notifications | Delivery of order status notifications (see Section 13) | Explicit — via the browser dialog |
12.2. Third-party services and embedded content. Individual pages of the Service may load resources and widgets from third-party providers: Telegram (chat widgets, login), VK ID, YouTube, Steam Login, and the iframe payment forms of YooMoney, Antilopay and other payment providers. These services may set cookies of their own and collect data in accordance with their own personal data processing policies, over which the Operator has no influence. The User's use of such services implies their consent to those policies.
12.3. The User is entitled to disable cookies and clear local storage in their browser settings. In this case, some site functions (the Personal Account, referral credits, saving order progress) may work incorrectly or be unavailable.
12.4. On the first visit the Service shows a banner stating which technologies are used and why. Continued use of the site after the banner has been shown constitutes the User's consent to all technologies listed in the table above, except those for which a separate permission is expressly stated (push notifications are requested through the browser dialog). The User may refuse analytics and advertising attribution — see clause 12.5.
12.5. How to refuse and how to withdraw consent. The banner has two buttons — «Accept» and «Decline». Yandex Metrica, Google Analytics and the nb_vid and nb_attr identifiers work from the moment the site is opened; pressing «Decline» switches them off immediately, without a reload, and deletes the identifiers already stored (nb_vid, _ym_*, _ga*, nb_attr). After a refusal the Service shows a window explaining why it cannot work without cookies and stays unavailable until «Accept and continue» is pressed; the alternative is to close the page. The choice is stored for 12 months and is then requested again. Consent may be withdrawn at any time: clear the site's storage in browser settings (the analytics identifiers are deleted and the banner asks again) or contact the Operator using the details in section 23.
13. Push Notifications and Service Worker
13.1. To send order status notifications, the site uses Service Worker and web-push technology (sw.js). With the User's consent, a unique subscription token is stored in the browser and transmitted to the Operator.
13.2. The User is entitled at any time to withdraw consent to push notifications via the browser settings or the Personal Account.
14. Logging of Correspondence and Recordings
14.1. The Operator maintains automatic and/or manual logging and audio, video and text recording of all interactions with the User: correspondence in the Personal Account, messengers (Telegram, etc.), voice channels and by e-mail, as well as all actions in the system, IP addresses, login times and other technical data.
14.2. Such recordings and logs are used by the Operator as evidence in any disputes with the User, banks, payment providers and other third parties. By continuing to interact with the Service, the User consents to such recording and fixation.
14.3. The retention period for recordings and logs is set out in Section 9 of this Policy.
14.4. When rendering the «E-Girl in party» service, the Operator records voice channels and correspondence in full. In addition to the purposes of Section 14.2, such recording is used to confirm the fact and time of the start of the session, the fact and time of an offer of a replacement contractor, and the content of the User's requests, and constitutes evidence in the consideration of claims and refund demands.
14.5. Upon transfer of an account to the User, the Operator records the composition of the account's stated characteristics, the date and time of transfer and the technical data of the transfer session. Such records are used to establish the state of the account at the moment of transfer and to distinguish circumstances that arose after transfer and are beyond the Operator's control, including regional restrictions of the Steam platform applied by its rightsholder based on the IP address of the person actually using the account.
15. Automated Processing and Anti-Fraud
15.1. The Operator applies automated processing of personal data for the purposes of anti-fraud protection, transaction risk assessment, and the detection and prevention of fraud and unauthorised access.
15.2. The following signals are used in automated processing: the IP address and its reputation, the device and browser fingerprint, the history of interaction with the Service, behavioural data, the geography of the payment, the reputation of the payment method, and flags from external anti-fraud providers.
15.3. Based on the results of automated processing, the Operator may decide to:
- refuse to place or pay for the order;
- require additional verification of the User (KYC) before or during the rendering of the service;
- suspend the rendering of the service pending clarification of the circumstances;
- transfer information to the bank and/or payment provider within a chargeback procedure.
15.4. The User is entitled to request an explanation of a decision taken as a result of automated processing and to demand its review by an authorised employee of the Operator, by sending a request in the manner described in Section 19 of this Policy.
16. Content Uploaded by the User
16.1. The User may upload or transfer to the Operator the following content: screenshots, match replays, verification documents (KYC), correspondence files, scanned copies of payment confirmations and other materials necessary to render the service or resolve a dispute.
16.2. By transferring such content, the User confirms that they hold all the rights necessary to transfer it and grants the Operator an irrevocable, non-exclusive, royalty-free licence to use the content for the purposes specified in this Policy and the Public Offer, including:
- rendering the service and related operations;
- protecting the Operator's rights in disputes, chargebacks and court proceedings;
- training employees and engaged contractors;
- using anonymised materials for marketing and analytical purposes.
16.3. It is prohibited to transfer to the Operator content that:
- contains the personal data of third parties without their consent;
- infringes the copyright, related or other rights of third parties;
- contains unlawful, offensive, extremist or other illegal information;
- contains malicious code, viruses or scripts.
16.4. The Operator is entitled to unilaterally delete received content, refuse to process it and/or cease rendering services without a refund if the content violates the terms of this section.
16.5. Screenshots that contain no identifying features (nickname, SteamID, avatar, chat) may be used by the Operator in marketing materials — in the "Monitoring" and "Reviews" sections, on social media and in other publications.
17. Marketing Communications
17.1. The Operator is entitled to send the User promotional and informational messages (promotions, discounts, Service news, referral reminders) using the contact details provided: e-mail, Telegram, push notifications, SMS.
17.2. Consent to receive marketing communications is deemed given at the moment the User provides the relevant contact details and confirms acceptance of the Public Offer or otherwise interacts with the Service.
17.3. Opting out of marketing mailings:
- by e-mail — via the "Unsubscribe" link in the message or by contacting us through the contacts page;
- on Telegram — by sending the "STOP" command or blocking the bot/manager;
- push notifications — by disabling them in the browser settings or the Personal Account;
- SMS — by sending a reply message "STOP" or contacting support.
17.4. Opting out of marketing communications does not entail the cessation of service notifications: order statuses, Personal Account login alerts, security warnings and service-completion notifications are delivered to the User regardless of their marketing settings.
18. Data Protection and Incident Response
18.1. The Operator takes reasonable organisational and technical measures (Technical and Organizational Measures, TOMs) to protect personal data against unauthorised access, loss, alteration, dissemination or destruction:
- Encryption in transit: data is transmitted between the User and the server over the secure TLS 1.2 or TLS 1.3 protocol (the version is chosen by the User's browser) with support for modern cryptographic algorithms; legacy versions of the protocol (TLS 1.0 and TLS 1.1) are disabled, and requests over unencrypted HTTP are redirected to HTTPS (HSTS policy);
- Encryption at rest: game account authorisation data, access tokens and other critical data are stored in encrypted form using modern algorithms (AES-256 or equivalent);
- Role-based access control (RBAC): access to personal data is granted only to authorised employees and engaged contractors, to the minimum extent necessary to perform their duties (the principle of least privilege);
- Two-factor authentication (2FA): access to all administrative interfaces and systems containing Users' personal data is protected by two-factor authentication;
- Password policies: requirements for the complexity, rotation and storage of employee and contractor passwords; passwords are stored as cryptographic hashes (bcrypt/argon2);
- Access logging: logs are kept of access to personal data, administrator actions and privileged operations; logs are regularly analysed for anomalies;
- Security testing: internal security audits, vulnerability scans and penetration tests (pentests) are conducted periodically; identified vulnerabilities are remediated within a reasonable time;
- Software updates: regular updates of operating systems, libraries and other software, including the installation of critical security patches;
- Monitoring and WAF: continuous monitoring of suspicious activity, use of attack-detection tools (IDS/IPS), application-level firewalls (WAF) and anti-fraud control systems;
- NDAs and confidentiality obligations: employees and engaged contractors sign non-disclosure agreements (NDAs) and assume confidentiality obligations for the entire period of cooperation and after its termination;
- Staff training: employees and engaged contractors undergo mandatory training on the security of personal data processing and protection against social engineering and phishing;
- Backup encryption: data backups are stored in encrypted form with separate storage of the encryption keys.
18.2. Despite the measures taken, the Operator cannot guarantee absolute security of data during its transmission over the internet and is not liable for incidents resulting from the actions of third parties, phishing attacks directed against the User, the actions of hosting providers, force majeure or other circumstances beyond the Operator's reasonable control.
18.3. The User is obliged to independently ensure the security of their devices, passwords, and access to e-mail and messengers, to use two-factor authentication and not to transfer authorisation data to third parties.
18.4. Incident response. If an incident is identified that has resulted in, or could result in, the unlawful or accidental transfer of personal data, the Operator:
- within 24 (twenty-four) hours of detection, notifies the authorised authority of the incident (for citizens of the Russian Federation — Roskomnadzor under Part 3.1 of Art. 21 of Federal Law No. 152-FZ; for citizens of the Kyrgyz Republic — the authorised authority of the KR);
- within 72 (seventy-two) hours, sends the authorised authority information on the results of the internal investigation of the incident;
- takes reasonable measures to contain the incident, minimise the consequences and remediate the vulnerabilities;
- where there is a significant risk to the rights and freedoms of data subjects, informs the affected Users within a reasonable time using the contact details they provided.
18.5. Backups and archives. The Operator creates regular backups of the Service's databases and storage to ensure continuity of operation and the recovery of data in the event of a failure. After a User's personal data is deleted from the Operator's main systems, fragments of such data may be retained in archived copies for the duration of the backup rotation period — up to 90 (ninety) calendar days — after which they are deleted automatically when the cycle is overwritten. Until that period expires, archived copies are held in encrypted form with restricted technical access and are not used by the Operator for active processing, except in cases of data recovery after a failure or compliance with the requirements of authorised authorities.
19. Rights of the Data Subject
19.1. The User has the right to:
- Request information about the composition and periods of processing of their personal data;
- Obtain a copy of their personal data in a structured, machine-readable format (CSV, JSON or similar) — to the extent of the data actually held by the Operator, and without disclosing the data of third parties, legally protected secrets or information constituting the Operator's trade secret;
- Demand the rectification, correction or supplementation of inaccurate or incomplete data;
- Withdraw consent to the processing of personal data — subject to the limitations specified in Section 8 of this Policy;
- Demand the deletion of personal data, except where its retention is necessary to perform the contract, protect the Operator's rights or comply with the requirements of the law;
- Object to processing carried out on the basis of protecting the Operator's rights and legitimate interests;
- Demand a review of decisions taken as a result of automated processing (see Section 15);
- Appeal the actions or inaction of the Operator to the personal data protection authorities, including: Roskomnadzor (RF; pd.rkn.gov.ru), the State Agency for Personal Data Protection under the Cabinet of Ministers of the KR (or its legal successor) — for citizens of the KR; the national supervisory authority of the country of residence — for users from the EU, the UK and other jurisdictions.
19.2. Submitting a request. The request is sent by the User via the contacts page or an official support channel of the Service. The request must contain:
- the User's surname, first name and/or nickname;
- identifying information (order number, registration date, linked e-mail/Telegram);
- the subject of the request and the desired outcome.
19.3. Identification of the applicant. To protect the User from phishing, social engineering and bad-faith third parties, the Operator is obliged to verify the applicant's identity. A match of at least two of the following indicators is deemed sufficient confirmation:
- sending the request from an e-mail or Telegram account linked to the Personal Account;
- specifying the order number and its parameters (amount, date, status);
- logging in to the Personal Account and sending the request from it;
- providing a copy of an identity document, if identification by other means is impossible.
19.4. If reliable identification of the applicant is impossible, the Operator is entitled to refuse to fulfil the request, stating the reasons for refusal.
19.5. Review period. The request is reviewed within 30 (thirty) calendar days of its receipt. In the case of a particularly complex request or a large volume of data, the period may be extended, of which the User is notified separately.
19.6. The Operator is entitled to refuse to fulfil a request in whole or in part if doing so would violate the rights and legitimate interests of the Operator or third parties, require the disclosure of a legally protected secret, or result in a breach of applicable law.
20. Specifics for Users from the EU and the UK (GDPR / UK GDPR)
20.1. If the User is a resident of the European Economic Area (EU/EEA) or the United Kingdom, Regulation (EU) 2016/679 (GDPR) and the Data Protection Act 2018 / UK GDPR respectively apply to the processing of their personal data.
20.2. In addition to the rights listed in Section 19, such Users have the following additional rights:
- The right to data portability — to receive their data in a structured, machine-readable format;
- The right to restriction of processing;
- The right to object to processing based on the Operator's legitimate interests;
- The right to lodge a complaint with the national supervisory authority of the country of residence (Data Protection Authority).
20.3. The legal basis for the cross-border transfer of personal data outside the EEA is the Standard Contractual Clauses approved by the European Commission and/or the User's explicit consent.
20.4. To exercise these rights, the User sends a request via the contacts page marked "GDPR Request" or "UK GDPR Request". Identification of the applicant and review periods are governed by the rules of Section 19.
21. Data of Minors
21.1. The Service is intended solely for legally capable persons who have reached the age of 18 (eighteen). The Operator does not knowingly collect the personal data of minors. The age restriction is due to:
- the requirements of the Steam Subscriber Agreement and Valve Corporation policy, which restrict commercial operations involving an account;
- the financial nature of the operations (online payments, chargebacks, obligations under the Offer), which requires full civil legal capacity;
- the requirements of child-protection law (for the Kyrgyz Republic — the KR Code "On Children"; for the Russian Federation — the Federal Law "On Protecting Children from Information Harmful to Their Health and Development").
21.2. If the Operator reliably learns that data was provided by a person under 18 without the consent of their legal representatives, such data is subject to deletion, and the rendering of services ceases without a refund of the amounts paid, in the manner provided for by the Public Offer.
21.3. Responsibility for the accuracy of the information about age lies with the User and their legal representatives.
22. Changes to the Policy and Applicable Law
22.1. The Operator is entitled to make changes to this Policy unilaterally without prior notice to the User, except in the case provided for by clause 22.3.
22.2. The current revision is always posted at neznakov.ru/privacy. The revision date is indicated at the top of the document. Use of the Service after a new revision is published constitutes the User's consent to its terms.
22.3. Material changes. When making changes that materially expand the categories of processed data, the purposes of processing, the list of data recipients or the retention periods, or that otherwise materially worsen the User's position compared with the previous revision, the Operator notifies Users at least 30 (thirty) calendar days before the changes take effect — by placing a banner on the neznakov.ru site, sending a notification to the linked e-mail and/or a message in the Personal Account. If the User does not agree with such changes, they are entitled to withdraw consent to processing in the manner provided for by Section 8 of this Policy; continued use of the Service after the changes take effect constitutes acceptance of them.
22.4. Applicable law and jurisdiction. This Policy, its interpretation and performance are governed by the law of the Kyrgyz Republic. With respect to the processing of the personal data of citizens of the Russian Federation, the Operator complies with the requirements of Federal Law No. 152-FZ "On Personal Data" and other regulatory legal acts of the Russian Federation applicable to foreign operators processing the data of Russian citizens. With respect to the processing of the personal data of EU/EEA and UK residents, the requirements of the GDPR and UK GDPR respectively apply. All disputes related to the processing of personal data and not resolved through negotiations are subject to resolution at the Operator's location in the Kyrgyz Republic, unless otherwise established by the mandatory rules of applicable law on consumer protection or personal data protection.
22.5. The Russian-language revision is recognised as the original and official version of the Policy. Where translations into other languages exist, the Russian revision prevails.
23. Operator Contacts and Details
23.1. For all questions related to the processing of personal data, the withdrawal of consent, the exercise of data subject rights or any other matters covered by this Policy, the User may get in touch via the contacts page or contact a manager through the Service's official channels (Telegram, e-mail).
23.2. The response time for an enquiry is up to 30 calendar days from receipt.
23.3. Operator details:
Full name: Alliance Torg Company LLC
Company address: Kyrgyz Republic, Bishkek, Oktyabrsky District, 7th microdistrict, Bezymyannaya St., 37/2
OGRN: 310076-3301-OOO
INN: 9909710244
Website: neznakov.ru
What data. A contact of your choice (Telegram, e-mail, phone), the contents and circumstances of the order together with the correspondence about it, payment details to the extent passed on by the payment provider, technical data about the visit (IP address, browser and device, pages viewed, referral source) and analytics identifiers —
nb_vid, nb_attr, Yandex Metrica and Google Analytics cookies.
Why. To fulfil and support the order, accept payment and refund it where necessary, answer enquiries, protect the Service and its Users against fraud, and measure traffic and advertising. For the latter Yandex Metrica (including Webvisor) and Google Analytics 4 are used: they receive information about the visit and on-page behaviour.
How to withdraw. Press «Decline» in the banner, clear the site's storage in browser settings, or contact the Operator using the details in section 23. Withdrawing consent to analytics does not affect an order that has already been placed; the procedure and its consequences are in section 8, the composition of cookies in section 12.