1. Controller and scope
The controller is Individual Entrepreneur Grishechko Aleksei Sergeevich, trading as TUNDRÄ. Registration and contact details are in the Seller Information. Privacy requests may be sent to support@tundraa.dev.
This Notice applies to tundraa.dev, lead and booking forms, demo and client accounts, the client and team portals, communications, free tests and paid services. Lava.top separately controls personal data it collects for checkout, identity, tax, fraud prevention and payment processing under its privacy policy.
When a Business Customer determines why and how personal data in its website, database or task materials is processed and TUNDRÄ handles it only to perform the Customer’s instructions, the Customer is controller and TUNDRÄ is processor under the Data Processing Addendum.
2. Personal data we collect
Information you provide
- identity and contact data: name, email, telephone, company and role;
- account data: password hash, workspace, authorised users and preferences;
- project data: task briefs, URLs, comments, approvals, status history, attachments and deliverables;
- secure access data: key names and encrypted values you deliberately save in the portal Secrets area;
- billing data: plan, billing country, business and tax details, invoice and payment status, Lava.top order identifiers;
- communications: support, complaint, privacy, security and sales correspondence; and
- any other data you choose to include, subject to the Acceptable Use Policy.
Information collected automatically
- IP address, timestamp, user agent, approximate country, referrer and requested page;
- session, authentication, rate-limit, security and audit events;
- UTM parameters and advertising click identifiers included in a landing URL;
- cookie and consent choices; and
- optional analytics data after consent, including anonymous visitor and visit identifiers, page views, headline experiment assignments, device/browser information and interaction events.
Information from others
We may receive payment and subscription status from Lava.top, account invitations from your organisation, information from a person who refers or authorises you, and technical information from a Customer-selected platform needed to complete a task.
3. Why we process data and legal bases
| Purpose | Typical data | Legal basis where GDPR/UK GDPR applies |
|---|---|---|
| Respond to enquiries and create an account | Contact, company, project and technical data | Steps requested before contract; legitimate interests |
| Provide the trial and paid Service | Account, tasks, files, encrypted Secrets, communications, billing status | Performance of contract |
| Authenticate and secure the Service | Session, IP, device, rate-limit and audit events | Contract; legitimate interests in security and fraud prevention |
| Process payments and keep records | Plan, transaction ID, invoice, tax and payment status | Contract; legal obligations; legitimate interests |
| Send transactional messages | Name, email, account and service events | Contract; legitimate interests |
| Measure website use | Consent choice, analytics identifiers and events | Consent where required |
| Send marketing | Contact details and communication preferences | Consent, or legitimate interests where law permits |
| Handle claims and comply with law | Relevant account, payment, audit and correspondence data | Legal obligation; legitimate interests in legal rights |
Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact on individuals. You may request information about that assessment. Where processing is based on consent, you may withdraw it without affecting earlier lawful use.
4. Payments
Complete card data is entered into Lava.top or its payment partner and is not stored by TUNDRÄ. We receive limited information such as Customer identity, plan, amount, currency, order/subscription identifier, payment status, refund and chargeback status. Lava.top may independently collect identity, address, tax and fraud-prevention information.
5. Cookies and local storage
We use a strictly necessary session cookie for signed-in accounts, local storage for consent, attribution and draft task information, and browser IndexedDB to hold selected draft attachments before registration. Google Analytics loads only after the visitor allows analytics. Details and controls are in the Cookie Notice.
6. Recipients and subprocessors
We disclose data only as reasonably necessary to:
- hosting, email, payment, analytics and communication providers that support the Service;
- authorised TUNDRÄ personnel and contractors bound by confidentiality;
- Customer administrators and authorised workspace members;
- professional advisers, insurers, auditors and accountants under duties of confidence;
- a successor in a genuine restructuring or sale, subject to lawful safeguards; and
- courts, regulators, tax authorities, law enforcement or other recipients where disclosure is legally required or necessary to protect rights and safety.
We do not sell personal data for money. We do not share personal data for cross-context behavioural advertising. We do not permit third parties to use Customer task data for their own advertising.
7. International processing
TUNDRÄ is operated by an individual entrepreneur registered in Russia. Primary web infrastructure may be hosted in another country, and providers may process data in Russia, the EEA, United States, United Arab Emirates, British Virgin Islands and other locations. Your data may therefore be processed outside your country.
Where a restricted international transfer occurs, we use an available lawful mechanism such as an adequacy regulation, approved contractual clauses, a transfer addendum or a specific statutory derogation, and assess supplementary safeguards where required. A Business Customer must not upload regulated EEA/UK customer data until the transfer mechanism required by its DPA has been completed.
8. Retention
| Data | Default retention |
|---|---|
| Unconverted enquiries and booking requests | Up to 24 months after the last meaningful interaction |
| Account and workspace profile | For the account term and up to 24 months after closure |
| Tasks, comments and ordinary attachments | For delivery and up to 24 months after closure, unless an Order Form requires earlier deletion |
| Values stored in Secrets | Until you delete them or the workspace is closed; isolated backup copies expire on their normal cycle |
| Session records | Active sessions expire after 30 days; expired records are removed operationally |
| Security and server logs | Normally up to 90 days; longer if needed for an incident |
| Audit and acceptance evidence | Up to 3 years after the relevant account or order |
| Contracts, invoices, fiscal and tax records | At least the period required by applicable accounting, tax and limitation laws, commonly 5 years or longer where required |
| Analytics | According to the configured analytics retention period and consent status |
We may retain a limited record longer where needed for an active claim, legal hold, fraud prevention or mandatory law. We may delete data earlier when it is no longer needed. Backup copies, where available, are isolated from ordinary use and expire on their cycle.
9. Your rights
Depending on applicable law, you may have rights to:
- obtain confirmation, access and a copy of personal data;
- correct inaccurate or incomplete data;
- request deletion, restriction or objection;
- receive portable data in a structured format;
- withdraw consent and opt out of marketing;
- appeal a refusal where local law provides an appeal; and
- complain to the data-protection authority in your residence, workplace or place of alleged infringement.
Submit a request to support@tundraa.dev. We may verify identity and authority, particularly for account, billing and file requests. We respond within the period required by applicable law, normally one month for GDPR/UK GDPR requests. Some data may be retained or withheld where a lawful exemption applies.
10. California disclosures
California residents may use the rights channel above. During the preceding 12 months, the categories collected are the identifiers, commercial, internet/network, professional and user-provided content described in section 2; they are used and disclosed for the purposes and recipients in sections 3 and 6. We do not sell or share these categories for cross-context behavioural advertising and do not have actual knowledge of selling or sharing data of persons under 16. TUNDRÄ may not meet the statutory thresholds for all obligations under the California Consumer Privacy Act, but this Notice is intended to satisfy applicable online-privacy disclosures.
Browser “Do Not Track” signals are not standardised and do not change essential processing. Because optional analytics requires affirmative consent, it remains off unless enabled. Where legally required and technically received, recognised opt-out preference signals will be honoured for processing to which they apply.
11. Children
The Service is for persons aged 18 or older and is not directed to children. We do not knowingly collect personal data from a child through an account. Contact us if you believe a child supplied data without valid authorisation so we can investigate and delete it.
12. Security
We use technical and organisational measures described in the Security Overview. No online service is risk-free. You must use unique credentials, minimise uploaded data and notify us promptly of suspected compromise.
13. Changes and contact
We may update this Notice to reflect law, providers or processing. Material changes will be highlighted on the website or notified to account holders where appropriate. The effective date above identifies the current version. Questions and requests may be sent to support@tundraa.dev or the business address in the Seller Information.