Legal information
Data processing
Detailed description of SKYTAL data categories, processing purposes, retention periods, recipients, and security measures. Supplements the Privacy Policy.
1. Processing operator
Operator: Obedinennaia Kazanskaia Biznes Gruppa LLC (ООО «Объединенная Казанская Бизнес Группа») (INN 1656055260, OGRN 1101690032982), 8 Lushnikova St., office 29, Kazan 420034, Russia.
Data processing inquiries: info@skytal.ru.
This document describes processing when using skytal.ru, the SKYTAL mobile application, and related infrastructure.
2. Data categories processed
- Account, profile, and device identifiers (internal IDs, public identifier, display name, activation status)
- Message delivery metadata: routing, send and delivery times, statuses, chat and group participation
- Encrypted message and attachment content (the server does not decrypt message text)
- WebRTC call signaling and media data, including TURN use when necessary
- Push notification tokens and identifiers
- Invitation data: code, status, expiry, issuance source (without identity verification)
- Email and order data when payment is enabled for agreed access orders (via supported payment providers, including YooKassa and PLATIMA)
- Support requests and correspondence with the operator
- Technical logs: IP address, user-agent, request time, response codes, diagnostic events
3. Purposes and legal bases
Legal bases depend on data category and jurisdiction: contract performance, legitimate interests of the operator, user consent where required, and compliance with legal obligations.
- Providing invitation-based access and performing the Terms of Use
- Delivering messages, files, call signaling, and push notifications
- Security, abuse prevention, and incident investigation
- Technical support and handling user requests
- Payment processing when payment is enabled for agreed orders (via supported providers)
- Compliance with applicable legal requirements
4. Recipients and processors
Sharing is limited to what is necessary for the relevant purpose. Contracts or other safeguards under applicable law are used with third parties.
- Hosting providers and cloud infrastructure — server hosting and backup
- Push notification providers (FCM and equivalents) — delivery of notifications to devices
- Payment providers (YooKassa, PLATIMA, etc.) — payment processing when payment is enabled for agreed orders
- Technical support and monitoring contractors — under processing agreements and confidentiality obligations
5. Retention periods
Retention periods are refined following technical and organizational review and may be updated in new document versions.
- Profile and device data — for the active account period and a reasonable period after deletion to complete operations and resolve disputes
- Delivery metadata — for periods necessary for service operation, diagnostics, and security; intervals may vary by event type
- Encrypted message packets — in a temporary delivery queue until ack and automatic cleanup (default: up to 1 hour after ack or up to 24 hours queue TTL); no persistent server chat history
- Encrypted attachments — until media layer TTL expires (default up to 7 days after upload) or sender deletion
- Infrastructure logs — limited rotation periods; immediate removal from all backups and logs is not guaranteed
- Support data — until the request is closed and within internal policy limits
6. Cross-border transfers
Some processors (hosting, push, infrastructure analytics) may be located outside your country of residence.
Cross-border transfers are carried out where legal grounds and applicable safeguards exist under Russian personal data law. Specific contractual mechanisms are refined as infrastructure evolves and require separate organizational review.
7. Security measures
Absolute protection against all threats is not guaranteed. Users must also secure their own devices.
- Channel encryption (TLS) and E2EE for message content
- Access controls to server infrastructure and logging of administrative actions
- Regular component updates and incident monitoring
- Data minimization within the service architecture
8. Data subject rights
Depending on applicable law, you may request access, correction, deletion, restriction of processing, objection to processing, or data portability.
Send requests to info@skytal.ru or use the Profile and data removal page. Response timelines depend on legal requirements and request complexity.