Back to home

Legal information

Personal data processing policy

Version dated

How Tygy processes visitor, user and customer-conversation data, who receives it and how to make a data request. The Russian text prevails; this translation is provided for convenience.

1. Controller and scope

Sole proprietor Dmitry Vladimirovich Ivanochek, INN 690891251788, OGRNIP 318500700030165, controls data needed for Tygy accounts, billing and support. Business details and the enquiry contact appear below. This policy covers tygy.ru and app.tygy.ru.

For customer and employee data entering user projects, the relevant Customer determines processing purposes and grounds. Tygy processes that data on the Customer’s instructions described in the user agreement. Visiting the site, accepting a contract or reading this policy does not replace separate consent where required.

2. Data and purposes

Accounts and access: name, email, phone, account and linked Telegram profile identifiers, authentication data, membership and permissions support registration, login, invitations, security and access.

Support work: contacts and client identifiers, messages and conversation history, attachments, customer and company records, assignments, notes, reviews and operational events enable receiving and answering requests, routing and reporting. Knowledge articles support storage, search and Customer-selected publication. Audio and transcripts are processed when those features are enabled.

Payments: customer and payer details, plan, seats, access periods, amounts, payment documents and statuses support billing and accounting. If an external checkout is used, card details are entered with its identified provider.

Support and security: enquiry content, reply contact, IP address, browser and device information, request times, errors and technical events help resolve issues, operate the website and prevent abuse. Processing is limited to information needed for the relevant purpose.

3. Grounds, operations and safeguards

Processing may rely on a contract with the data subject, legal duties, lawful Customer instructions or separate consent where required. Optional advertising and analytics are not a condition of basic access.

Operations include receipt, recording, organization, storage, correction, retrieval, use, authorized disclosure, restriction and deletion. Authorized persons receive access within their duties and configured permissions. The Provider must maintain confidentiality, access controls and legally required safeguards.

The service is not intended for biometric identification or dedicated processing of sensitive data categories. Customers must not provide excessive data or information for which they lack necessary grounds and safeguards.

4. Customer projects and public content

The Customer controls membership, permissions, channels and project data access. The Customer ensures grounds and notices for processing client and employee information, including call recording and AI use.

Telegram Desk forwards conversation content and attachments to a selected Telegram group. Connected CRMs and webhooks may receive data according to configuration. Group members, external systems and public knowledge-base visitors gain access within the Customer’s chosen scope. Verify that disclosure is lawful before publishing articles or sharing public links.

If your data belongs to the project of an organization using Tygy, contact that organization or use the contact below. Identifying the project and verifying the requester’s authority may be necessary without disclosing other people’s information.

5. Infrastructure and providers

Core servers and object storage are hosted with Beget in Russia. This does not mean all processing stays in Russia when external integrations are enabled. Messengers, mail servers and CRMs process disclosed data under their own terms and connected functionality.

Service email uses a configured SMTP server or Resend. Mail transport receives the recipient address and message content, including invitations, notifications and login or recovery links. Customer email channels use their connected IMAP/SMTP servers.

Platform AI uses DeepSeek for generation and text processing, and OpenAI for text embeddings used in search. Requests may contain conversations, instructions, prompts and relevant knowledge excerpts. Customer-provided keys also support OpenAI, Anthropic, YandexGPT, Gemini and Qwen. Choosing a custom model does not automatically disable OpenAI embeddings; unavailable customer configuration may fall back to platform DeepSeek.

Initial audio recognition runs on the self-hosted whisper.cpp service. Transcript text may be sent to DeepSeek for editing. Neither this policy nor the agreement authorizes use of Customer content for training external models.

Cross-border transfers require applicable grounds and advance procedures under Article 12 of Federal Law No. 152-FZ. Enabling a feature or accepting this policy does not replace those procedures. Changes to providers, purposes or data scope are disclosed before new processing; fresh consent is requested where required.

6. Retention, restriction and deletion

Retention depends on the purpose, contract and legal duties. Account data supports access and related obligations, enquiries support issue resolution, and payment documents support billing and mandatory accounting. Data must not be kept longer than necessary on a lawful basis.

A company that loses full access follows the user agreement’s process: deletion status after six calendar months, a further 30-day support-assisted restoration window, then permanent deletion. The owner receives advance notices. Support can provide an export while access is restricted. Backups are handled separately with access and use restrictions.

Deleting a contact or organization card does not erase all conversation history. History can remain, and a contact can reappear after a new message. Use the contact below for a complete personal-data deletion request.

When a purpose ends, unlawful processing is identified or a justified request is received, processing stops and data is corrected, restricted or deleted within statutory deadlines. Longer retention requires another lawful basis; ordinary project retention does not override these requirements.

When the owner deletes a project, the 30-day restoration period starts immediately; the six-month waiting period does not apply.

7. Rights and enquiries

You may request information about processing, correction, restriction or deletion where applicable, and withdraw prior consent. Email hello@tygy.ru with information sufficient to locate the account or data. Proportionate evidence of identity or authority may be requested; do not send a passport copy without a justified need.

Withdrawing consent does not end processing supported by another lawful ground. Enquiries are handled within Russian statutory deadlines. You may complain to Roskomnadzor or seek judicial protection. New policy versions carry a date; material changes requiring separate consent are not automatically accepted on your behalf.

8. Cookies and browser storage

Tygy.ru and app.tygy.ru use Yandex Metrica (counter 112459823). Analytics starts automatically when pages open, independently of dismissing the notice. The cookie banner is informational. Got it and the close button only hide it; tygy_cookie_notice remembers dismissal for up to 12 months across both sites.

Metrica receives technical browser and device data, visits, registration and payment events, payment amount and currency, and project ID and name. The Metrica visitor ID links these events to visits. The landing uses click maps and session replay. The application disables session replay, click maps and link tracking; reported URLs omit project names, conversation IDs, parameters and tokens. Conversation text is not sent.

Yandex uses its own analytics cookies, including _ym_uid, with retention set by Yandex. Application technical cookies support authentication and the interface. The button below displays the informational notice again.

Business details and contacts

Provider and personal data controller
Sole proprietor Dmitry Vladimirovich Ivanochek
Taxpayer number (INN)
690891251788
Sole proprietor registration number (OGRNIP)
318500700030165
Registration date
Registered locality
141580, Russia, Moscow Region, Khimki, Pikino village
Service and personal data enquiries
hello@tygy.ru

The invoice contains the recipient’s bank details. Check the recipient, amount and access period before payment.