Mockarty Cloud Privacy Policy

Version v1 · Effective from 4 September 2026

This Privacy Policy explains what personal data Artem Orlovich (the "Operator", "we") processes when you use Mockarty Cloud at https://mockarty.ru and the services managed through it (the "Service"), why, for how long, and what rights you have. It is part of the Terms of Service at https://mockarty.ru/legal/terms.

This Policy covers data about you and your team members as users of the Service. Data that you place inside the Service yourself — mocks, recordings, test data, files, prompts ("Customer Content") — is processed on your instructions, and you are responsible for it as its controller (Section 5 of the Terms).

1. Who is responsible

The controller of your personal data as a user of the Service is Artem Orlovich. Contact for privacy matters: i@aorlovich.ru.

2. What we process and why

The Privacy center in your account lists every processing purpose, its legal basis, the retention period, the region where the data is kept, and whether it needs your consent. The purposes currently in use are:

Purpose Data Legal basis Consent
Account and service delivery name, email, password hash, second-factor secrets, language and theme, Space membership and roles, sessions performance of the contract (the Terms) not required
Security and audit sign-in events, IP address, browser identification, actions taken in the Service, Terms acceptance records legal obligation and our legitimate interest in protecting the Service not required
Billing and accounting billing details you enter, invoices, payments, refunds, wallet transactions, seller and tax data legal obligation (accounting and tax law) and the contract not required
Support the content of your support requests and their attachments, your account identifiers, correspondence performance of the contract not required
Product analytics anonymised usage events: which features are used and how often, performance measurements your consent, given and withdrawn in the Privacy center required
Crash diagnostics error reports and technical context when the Service or a desktop application fails your consent, given and withdrawn in the Privacy center required

We do not process special categories of personal data and do not perform decisions based solely on automated processing that have legal effects on you.

3. Where the data comes from

We collect data that you enter (registration, profile, billing, support requests), data produced by your use of the Service (sessions, actions, technical logs), data received from identity providers you choose to sign in with (name and email), and data from payment providers about the outcome of a payment. We do not buy personal data from third parties.

4. Cookies and local storage

The Service uses a session cookie to keep you signed in, a short-lived cookie to protect sign-in through identity providers, and a cookie that remembers your interface language. Your theme choice is kept in the browser's local storage. These are strictly necessary for the Service and need no consent. We do not use advertising or cross-site tracking cookies.

5. Who receives the data

We share personal data only with parties needed to run the Service, and only what they need:

The list of processors and the region for each purpose is shown in the Privacy center. Where data leaves the home region, we rely on the safeguards required by applicable law.

6. How long we keep the data

Each purpose has its own retention period and deletion mode, shown in the Privacy center. At the time of this version: account data is anonymised ten years after the account is closed; security and audit records are kept for six years and billing records for five years because the law requires it; support cases are anonymised after three years; product analytics events are anonymised after one year; crash reports are erased after ninety days. Backups are deleted on their own rotation, after which residual copies no longer exist.

7. Your rights

Through the Privacy center you can, without contacting support:

You also have the right to object to processing based on our legitimate interest, to restrict processing, and to lodge a complaint with the supervisory authority for personal data in your country. To exercise a right that is not available in the Privacy center, write to i@aorlovich.ru; we may need to verify your identity first. We answer within the period the law sets and no later than 30 days.

Deleting your account removes your access immediately. Data that we must keep by law (billing, audit) stays for its retention period and is then deleted or anonymised; it is not used for any other purpose meanwhile.

8. Security

We protect personal data with technical and organisational measures appropriate to the risk: isolation between Spaces, encryption in transit, encryption of sensitive fields at rest where configured, access control by role, second-factor authentication, and audit logging of administrative actions. If a breach affects your data, we will inform you and, where required, the supervisory authority without undue delay.

9. Children

The Service is intended for professional use by adults. We do not knowingly process data of persons under 18. If you believe a minor has created an account, tell us at i@aorlovich.ru and we will remove it.

10. Changes to this Policy

We may update this Policy. A new version is published at https://mockarty.ru/legal/privacy with a new version number and effective date, and material changes are announced in the Service or by email before they take effect. Optional purposes that are added later require a fresh consent in the Privacy center.

11. Contact

Artem Orlovich · i@aorlovich.ru · https://mockarty.ru

This Policy is published in English and in Russian. In case of a conflict between the versions, the Russian version prevails.