TUNDRÄ
Login Start for free

Legal

Privacy notice

This Notice describes TUNDRÄ’s processing as controller of website, account, billing and relationship data. Customer-controlled data handled while performing development work is governed by the Data Processing Addendum.

Effective July 13, 2026 · Version 2026-07-13

Legal documents
Terms of serviceService scopeBilling & subscriptionsCancellation & refundsAcceptable usePrivacy noticeCookie noticeData processing addendumSeller informationSecurity

1. Controller and scope

The controller is Individual Entrepreneur Grishechko Aleksei Sergeevich, trading as TUNDRÄ. Registration and contact details are in the Seller Information. Privacy requests may be sent to support@tundraa.dev.

This Notice applies to tundraa.dev, lead and booking forms, demo and client accounts, the client and team portals, communications, free tests and paid services. Lava.top separately controls personal data it collects for checkout, identity, tax, fraud prevention and payment processing under its privacy policy.

When a Business Customer determines why and how personal data in its website, database or task materials is processed and TUNDRÄ handles it only to perform the Customer’s instructions, the Customer is controller and TUNDRÄ is processor under the Data Processing Addendum.

2. Personal data we collect

Information you provide

  • identity and contact data: name, email, telephone, company and role;
  • account data: password hash, workspace, authorised users and preferences;
  • project data: task briefs, URLs, comments, approvals, status history, attachments and deliverables;
  • secure access data: key names and encrypted values you deliberately save in the portal Secrets area;
  • billing data: plan, billing country, business and tax details, invoice and payment status, Lava.top order identifiers;
  • communications: support, complaint, privacy, security and sales correspondence; and
  • any other data you choose to include, subject to the Acceptable Use Policy.

Information collected automatically

  • IP address, timestamp, user agent, approximate country, referrer and requested page;
  • session, authentication, rate-limit, security and audit events;
  • UTM parameters and advertising click identifiers included in a landing URL;
  • cookie and consent choices; and
  • optional analytics data after consent, including anonymous visitor and visit identifiers, page views, headline experiment assignments, device/browser information and interaction events.

Information from others

We may receive payment and subscription status from Lava.top, account invitations from your organisation, information from a person who refers or authorises you, and technical information from a Customer-selected platform needed to complete a task.

3. Why we process data and legal bases

PurposeTypical dataLegal basis where GDPR/UK GDPR applies
Respond to enquiries and create an accountContact, company, project and technical dataSteps requested before contract; legitimate interests
Provide the trial and paid ServiceAccount, tasks, files, encrypted Secrets, communications, billing statusPerformance of contract
Authenticate and secure the ServiceSession, IP, device, rate-limit and audit eventsContract; legitimate interests in security and fraud prevention
Process payments and keep recordsPlan, transaction ID, invoice, tax and payment statusContract; legal obligations; legitimate interests
Send transactional messagesName, email, account and service eventsContract; legitimate interests
Measure website useConsent choice, analytics identifiers and eventsConsent where required
Send marketingContact details and communication preferencesConsent, or legitimate interests where law permits
Handle claims and comply with lawRelevant account, payment, audit and correspondence dataLegal obligation; legitimate interests in legal rights

Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact on individuals. You may request information about that assessment. Where processing is based on consent, you may withdraw it without affecting earlier lawful use.

4. Payments

Complete card data is entered into Lava.top or its payment partner and is not stored by TUNDRÄ. We receive limited information such as Customer identity, plan, amount, currency, order/subscription identifier, payment status, refund and chargeback status. Lava.top may independently collect identity, address, tax and fraud-prevention information.

5. Cookies and local storage

We use a strictly necessary session cookie for signed-in accounts, local storage for consent, attribution and draft task information, and browser IndexedDB to hold selected draft attachments before registration. Google Analytics loads only after the visitor allows analytics. Details and controls are in the Cookie Notice.

6. Recipients and subprocessors

We disclose data only as reasonably necessary to:

  • hosting, email, payment, analytics and communication providers that support the Service;
  • authorised TUNDRÄ personnel and contractors bound by confidentiality;
  • Customer administrators and authorised workspace members;
  • professional advisers, insurers, auditors and accountants under duties of confidence;
  • a successor in a genuine restructuring or sale, subject to lawful safeguards; and
  • courts, regulators, tax authorities, law enforcement or other recipients where disclosure is legally required or necessary to protect rights and safety.

We do not sell personal data for money. We do not share personal data for cross-context behavioural advertising. We do not permit third parties to use Customer task data for their own advertising.

7. International processing

TUNDRÄ is operated by an individual entrepreneur registered in Russia. Primary web infrastructure may be hosted in another country, and providers may process data in Russia, the EEA, United States, United Arab Emirates, British Virgin Islands and other locations. Your data may therefore be processed outside your country.

Where a restricted international transfer occurs, we use an available lawful mechanism such as an adequacy regulation, approved contractual clauses, a transfer addendum or a specific statutory derogation, and assess supplementary safeguards where required. A Business Customer must not upload regulated EEA/UK customer data until the transfer mechanism required by its DPA has been completed.

8. Retention

DataDefault retention
Unconverted enquiries and booking requestsUp to 24 months after the last meaningful interaction
Account and workspace profileFor the account term and up to 24 months after closure
Tasks, comments and ordinary attachmentsFor delivery and up to 24 months after closure, unless an Order Form requires earlier deletion
Values stored in SecretsUntil you delete them or the workspace is closed; isolated backup copies expire on their normal cycle
Session recordsActive sessions expire after 30 days; expired records are removed operationally
Security and server logsNormally up to 90 days; longer if needed for an incident
Audit and acceptance evidenceUp to 3 years after the relevant account or order
Contracts, invoices, fiscal and tax recordsAt least the period required by applicable accounting, tax and limitation laws, commonly 5 years or longer where required
AnalyticsAccording to the configured analytics retention period and consent status

We may retain a limited record longer where needed for an active claim, legal hold, fraud prevention or mandatory law. We may delete data earlier when it is no longer needed. Backup copies, where available, are isolated from ordinary use and expire on their cycle.

9. Your rights

Depending on applicable law, you may have rights to:

  • obtain confirmation, access and a copy of personal data;
  • correct inaccurate or incomplete data;
  • request deletion, restriction or objection;
  • receive portable data in a structured format;
  • withdraw consent and opt out of marketing;
  • appeal a refusal where local law provides an appeal; and
  • complain to the data-protection authority in your residence, workplace or place of alleged infringement.

Submit a request to support@tundraa.dev. We may verify identity and authority, particularly for account, billing and file requests. We respond within the period required by applicable law, normally one month for GDPR/UK GDPR requests. Some data may be retained or withheld where a lawful exemption applies.

10. California disclosures

California residents may use the rights channel above. During the preceding 12 months, the categories collected are the identifiers, commercial, internet/network, professional and user-provided content described in section 2; they are used and disclosed for the purposes and recipients in sections 3 and 6. We do not sell or share these categories for cross-context behavioural advertising and do not have actual knowledge of selling or sharing data of persons under 16. TUNDRÄ may not meet the statutory thresholds for all obligations under the California Consumer Privacy Act, but this Notice is intended to satisfy applicable online-privacy disclosures.

Browser “Do Not Track” signals are not standardised and do not change essential processing. Because optional analytics requires affirmative consent, it remains off unless enabled. Where legally required and technically received, recognised opt-out preference signals will be honoured for processing to which they apply.

11. Children

The Service is for persons aged 18 or older and is not directed to children. We do not knowingly collect personal data from a child through an account. Contact us if you believe a child supplied data without valid authorisation so we can investigate and delete it.

12. Security

We use technical and organisational measures described in the Security Overview. No online service is risk-free. You must use unique credentials, minimise uploaded data and notify us promptly of suspected compromise.

13. Changes and contact

We may update this Notice to reflect law, providers or processing. Material changes will be highlighted on the website or notified to account holders where appropriate. The effective date above identifies the current version. Questions and requests may be sent to support@tundraa.dev or the business address in the Seller Information.

TUNDRÄ © 2026
Terms Privacy Security Cookies Refunds Legal notice