Publication date: 11 August 2026

This Privacy Policy (the "Policy") describes how personal data is processed and protected in connection with the Turbotables service (the "Service"), available at https://turbotabl.es and on connected domains.

This Policy is intended for an international audience and is designed to provide transparency consistent with widely recognized data-protection principles, including those reflected in the EU General Data Protection Regulation (GDPR) and similar laws. Where local law imposes stricter or additional requirements, those requirements prevail.

1. Definitions

Personal data means any information relating to an identified or identifiable natural person (a "data subject").

Controller (also referred to below as the "Operator" for consistency with our Russian documentation) means Grigory Petrovich Dmitrenko, sole proprietor, who alone or jointly with others determines the purposes and means of processing personal data.

Processing means any operation performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, use, disclosure by transmission, dissemination or otherwise making available, restriction, erasure, or destruction.

User means a natural person who registers for or uses an account in the Service, including a person who creates an account for sole personal use.

Customer means a User, company, sole proprietor, or other person that creates a workspace (account) in the Service and uses the Service for its own purposes, alone or by inviting others. Use of the Service is based on a contract formed by accepting the public offer upon registration, together with consent to personal-data processing.

Offer means the Turbotables Terms of Service / Offer Agreement published at /legal/offer on the Service website (Russian-language version is authoritative; an English version adapted for international / EU readers may also be available).

Consent means the Consent to personal data processing published at /legal/agreement on the Service website (Russian-language version is authoritative for Russian law purposes).

End User means a natural person whose personal data is processed in a Customer’s system deployed using the Service (including on the Customer’s own domain), including a person invited by the Customer to register in the Customer’s account.

Cookies means small pieces of data stored in a user’s browser when visiting the Service.

Other terms have the meanings commonly assigned under applicable data-protection law (including GDPR terminology such as “processor”, “controller”, and “personal data”).

2. Who we are (Controller)

Controller / Operator:

  • Grigory Petrovich Dmitrenko, sole proprietor;
  • Primary state registration number (OGRNIP): 324237500322572;
  • Tax ID (INN): 541077263701;
  • Registered address: Sochi, Troitskaya St. 31/2, Russian Federation;
  • Service website: https://turbotabl.es;
  • Email for privacy requests: info@turbotabl.es.

We do not provide a telephone number for privacy requests. Please contact us by email at the address above.

3. Scope and roles

3.1. The Service as a SaaS platform

The Service is software-as-a-service (SaaS) that allows Customers to:

  • create and administer their own information systems;
  • use the Service alone, without inviting others;
  • invite others to register and work in their account;
  • connect a custom domain;
  • register and manage their own users (End Users);
  • process data needed for the Customer’s activities, including integrations with government or industry systems (for example, product-marking systems such as Russia’s “Chestny Znak”), where the Customer enables such functionality.

Registration in the Service is completed through the registration form by checking a single box, by which the data subject simultaneously: (1) accepts the Offer and enters into a contract with the Controller; and (2) consents to personal-data processing under the Consent and this Policy. A separate written contract before registration is not required. Paid-use terms may be agreed individually (including by invoice or contract sent by email).

All Customer data is stored in a shared database of the Service (multi-tenant architecture) with logical access separation between accounts.

3.2. When we act as a controller

We act as a controller in relation to:

  1. visitors to the Service website;
  2. Users who register via the registration form (including those creating an account for sole use);
  3. persons invited by a Customer to work in the Customer’s account, with respect to account data needed to provide access to the Service;
  4. representatives of Customers (companies and sole proprietors);
  5. persons who provide identification, invoicing, integration, or contact details to us;
  6. persons who send us inquiries.

3.3. When we act as a processor (End User data)

Regarding personal data of End Users that a Customer enters, uploads, invites to register, or otherwise processes using the Service:

  1. the Customer is the controller of such personal data (if the Customer is an individual using the Service alone and processing only their own data, no separate processing of third-party data arises);
  2. if the Customer involves others (invites users, maintains End User records, etc.), we process their personal data as a processor on the Customer’s instructions under the Offer / agreement with the Customer;
  3. the Customer determines the purposes, legal bases, categories of End User data, retention periods, and how data-subject rights are handled;
  4. we process such data only as needed to provide, operate, secure, and support the Service, and we do not use it for our own marketing.

The Customer must ensure it has a valid legal basis to share End User personal data with us and to process it using the Service, and must inform data subjects where required by law.

Where required, Customers may request a Data Processing Agreement (DPA) by contacting info@turbotabl.es.

3.4. Consent at registration and invitation

When registering independently, a data subject:

  1. provides an email address;
  2. checks a single box in the registration form, thereby simultaneously:
    • accepting the Offer (entering into a contract to use the Service);
    • consenting to processing of personal data under the Consent and this Policy.

Without checking that box, registration and account creation are not possible. No additional separate consents are requested at registration. We do not send advertising or marketing emails.

A person invited by a Customer follows the invitation link and independently checks a single box in the relevant form, confirming acceptance of the Offer (to the extent applicable to use of the Service) and consent to personal-data processing under the Consent and this Policy. Without checking the box, invitation-based registration is not possible.

Consent to personal-data processing is voluntary, specific, informed, and unambiguous. A data subject may withdraw consent as described in Section 13; withdrawal may make further use of the Service impossible.

4. Principles of processing

We process personal data in accordance with the following principles:

  1. lawfulness, fairness, and transparency;
  2. purpose limitation — processing is limited to specified, explicit, and legitimate purposes;
  3. data minimization — we process only what is adequate, relevant, and necessary;
  4. accuracy — we take reasonable steps to keep personal data accurate and up to date;
  5. storage limitation — we keep personal data no longer than necessary for the purposes, unless a longer period is required by law or contract;
  6. integrity and confidentiality — we apply appropriate security measures;
  7. accountability — we are responsible for demonstrating compliance with these principles.

5. Purposes of processing

We process personal data for the following purposes:

  1. providing access to the Service, registration, and authentication;
  2. entering into, performing, and terminating contracts with Customers, including identifying the contracting party;
  3. operating the multi-tenant architecture of the Service, including on subdomains and Customer custom domains;
  4. handling inquiries, requests, and messages from data subjects and Customers;
  5. invoicing, accepting payments (including online payment / fiscalization tools where enabled), and accounting / tax compliance;
  6. enabling integrations used by the Customer (including product-marking or similar systems) and processing company / sole-proprietor details needed for such purposes;
  7. sending service (transactional) notices related to use of the Service (invitations, registration confirmation, access recovery, security notices, and material changes to terms);
  8. ensuring information security, preventing fraud and abuse;
  9. improving the Service and analyzing usage statistics (including via Yandex Metrica) — subject to cookie consent where required;
  10. complying with legal obligations applicable to us;
  11. handling claims and protecting our rights before courts and authorities;
  12. providing technical support, including Operator staff access to Customer account data to the extent needed for support and Service continuity.

We do not send advertising (marketing) emails.

6. Categories of data subjects

We may process personal data of:

  1. visitors to the Service website;
  2. Users who register independently;
  3. Users who register via a Customer invitation;
  4. Customers who are natural persons, sole proprietors, and representatives of legal entities;
  5. persons who contact us;
  6. End Users of Customer systems — to the extent needed to provide the Service as a processor (see Section 3.3).

7. Categories of personal data

Depending on the purpose and role, we may process the following personal data.

7.1. Data required for registration

To create an account, a data subject provides:

  • email address;
  • consent to personal-data processing and acceptance of the Offer (fact and time of checking the box at registration / invitation acceptance).

7.2. Data that may be provided later (profile, billing, integrations)

As the Service is used, a User / Customer may voluntarily provide, or may need to provide for certain features (invoicing, integrations, counterparty identification, etc.):

  • full name;
  • phone number;
  • tax identification numbers and business registration numbers applicable in the relevant jurisdiction (for example, INN / OGRNIP / OGRN in Russia);
  • organization name;
  • registered / postal address;
  • bank account details;
  • national identifiers required for documents or legal compliance in the relevant jurisdiction;
  • other details needed for invoicing and integrations.

7.3. Data collected automatically

  • IP address;
  • cookie and similar technology data;
  • device, browser, and Service activity data as needed for security, operation, and (with consent) analytics.

7.4. End User data

The categories of End User personal data are determined by the Customer. We may access such data in connection with providing Service infrastructure, support, and security, and we process it as a processor on the Customer’s instructions.

7.5. Data we do not request

We do not require uploading of photographs, passport copies, or other identity documents as a mandatory or standard Service feature.

We do not process biometric data and do not intentionally process special categories of personal data under Article 9 GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health, or sex life), except where such data is placed in the Service by a Customer on its own initiative. In that case the Customer warrants that it has a valid legal basis for such processing (including an Article 9 condition where required) and shall indemnify the Controller against all losses arising from claims by data subjects and/or supervisory authorities in connection with such placement, to the extent permitted by mandatory law.

8. Legal bases for processing

Depending on applicable law, our legal bases include:

  1. Consent of the data subject — including at registration and for non-essential cookies;
  2. Performance of a contract with the data subject, or steps taken at the data subject’s request before entering into a contract — where such relations arise;
  3. Compliance with a legal obligation applicable to us;
  4. Legitimate interests — for example, securing the Service, preventing abuse, improving reliability, and defending legal claims, provided such interests are not overridden by the data subject’s interests or fundamental rights;
  5. for End User data — processing as a processor on the Customer’s documented instructions, provided the Customer has its own legal basis for that processing.

Consent is given electronically by checking a box at registration and invitation acceptance (the same box also means acceptance of the Offer), accepting cookies, or another clear affirmative action.

9. How we process personal data

  1. Processing may be automated and/or non-automated.
  2. We may collect, record, organize, store, update, retrieve, use, disclose (provide access), restrict, erase, and destroy personal data.
  3. Personal data is obtained directly from the data subject or from the Customer (for data the Customer submits for processing via the Service).
  4. We do not disclose personal data to third parties or make it public without the data subject’s consent, except where required by law or where we engage processors / service providers (see Section 9.1).
  5. Disclosure to public authorities is made only where required by applicable law.
  6. The database containing personal data collected via the Internet is hosted in the Russian Federation (Timeweb hosting).
  7. If you access the Service from outside the Russian Federation, your personal data is transferred to and processed in the Russian Federation. See Section 15.

9.1. Processors and service providers

To operate the Service, we engage the following processors / contractors (under contracts or their service terms):

Purpose Provider / service Data that may be shared
Hosting and database storage Timeweb (Timeweb LLC / related companies), Russian Federation data stored in the Service
Email delivery smtp.bz email address and contents of service emails
Web analytics Yandex Metrica cookies, IP address, visit data — only after cookie consent
Online payments / fiscalization payment providers (if/when enabled) data needed for payment and fiscalization

We may update this list while maintaining an appropriate level of protection and updating this Policy for material changes.

9.2. Operator staff access to Customer data

Because of the shared architecture of the Service, our staff (administrator, support) may access Customer account data to the extent needed to:

  • provide technical support at the Customer’s request;
  • ensure Service availability, security, and recovery;
  • investigate incidents and comply with legal requirements.

Such access is confidential and is not used for purposes incompatible with this Policy.

10. Retention

Personal data is processed and stored:

  1. for the life of the User account / Customer workspace;
  2. after account deletion — for the time needed to complete deletion, manage backups, and meet legal obligations (including accounting / tax and evidence related to disputes);
  3. until consent is withdrawn — where processing is based on consent and no other legal basis applies;
  4. for End User data — for periods determined by the Customer, or until the Customer deletes the data / the account is deleted.

When retention ends, personal data is deleted or anonymized, unless law requires otherwise.

11. Cookies and similar technologies

The Service uses cookies and similar technologies to:

  • ensure Service functionality and security (necessary cookies);
  • store the User’s cookie-consent choice;
  • perform analytics via Yandex Metricaonly after the User consents via the cookie banner.

If the User rejects non-essential cookies, analytics scripts are not activated.

Users may manage cookies via the Service banner and browser settings. Disabling certain cookies may limit some Service features.

12. Security measures

We implement appropriate legal, organizational, and technical measures to protect personal data against unauthorized or accidental access, destruction, alteration, blocking, copying, disclosure, and other unlawful actions, including:

  1. hosting infrastructure in the Russian Federation with access controls;
  2. encrypted transmission (including HTTPS);
  3. access segregation for Users and Customers according to their permissions;
  4. limiting and monitoring Operator staff access to Customer data;
  5. detecting unauthorized access and responding to incidents;
  6. backups and recovery;
  7. other measures proportionate to the nature and volume of processing.

13. Your rights

Depending on your location and applicable law (including GDPR / UK GDPR where they apply), you may have the right to:

  1. obtain information about the processing of your personal data;
  2. access your personal data;
  3. request rectification of inaccurate or incomplete data;
  4. request erasure (“right to be forgotten”) where applicable;
  5. request restriction of processing;
  6. object to processing based on legitimate interests;
  7. receive your data in a portable format (data portability), where applicable;
  8. withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
  9. lodge a complaint with a competent supervisory authority in your country or region;
  10. seek judicial protection of your rights, including compensation where provided by law.

Send requests to: info@turbotabl.es.

Where the GDPR / UK GDPR applies, we respond without undue delay and in any event within one month of receiving the request. Where necessary, taking into account the complexity and number of requests, that period may be extended by up to two further months, in which case we will inform you of the extension and the reasons for the delay within one month of receipt. Where Russian law applies to the request, we respond within 10 business days, with a possible extension of up to 5 business days with a reasoned notice to the data subject.

Important: if your request concerns End User personal data processed by a Customer using the Service, please contact the Customer first as the controller of that data. We will assist the Customer in fulfilling data-subject rights within the technical capabilities of the Service.

14. Account deletion and destruction of personal data

  1. A User may delete their account:
    • using the corresponding function (button) in the Service interface; and/or
    • by emailing a deletion request to info@turbotabl.es.
  2. After account deletion, we stop processing the User’s personal data for providing the Service and delete or anonymize it, except for information we must retain by law and data remaining in backups for a limited technical period.
  3. Deleting a Customer account may delete or make unavailable End User data stored in that account; the Customer is responsible for notifying End Users where required.
  4. If personal data is confirmed to be inaccurate, we update it.
  5. Users may update some of their data themselves in the Service interface where that function is available.

15. International transfers

The Service infrastructure and primary database are located in the Russian Federation.

If you are located outside the Russian Federation (including in the EEA, UK, Switzerland, or elsewhere), using the Service involves transfer of your personal data to the Russian Federation for hosting, storage, and processing.

We engage the subprocessors listed in Section 9.1. We do not currently use additional foreign hosting providers for primary storage of Service personal data.

Where required by applicable law (for example, GDPR Chapter V), international transfers are carried out on the basis of:

  • your consent (including as part of registration / acceptance of this Policy where that is a valid ground); and/or
  • contractual necessity to provide the Service you request; and/or
  • appropriate safeguards agreed with Customers (such as a DPA with transfer clauses), where applicable.

If this approach changes, we will update this Policy and take steps required under applicable law.

16. Changes to this Policy

We may update this Policy. The new version takes effect when published on the Service website, unless the new version states otherwise. The current version is available at https://turbotabl.es/legal/privacy (and/or in the Service’s legal documents section).

If changes affect processing based on consent and require new consent, we will request it separately.

17. Final provisions

  1. This Policy is governed by the laws of the Russian Federation, without prejudice to mandatory protections that apply to you under the law of your country of residence (including GDPR / UK GDPR where applicable).
  2. Disputes are resolved under the laws of the Russian Federation at the Operator’s place of business, unless mandatory rules of another jurisdiction provide otherwise.
  3. If any provision of this Policy is held invalid, the remaining provisions remain in effect.
  4. Matters not covered by this Policy are governed by applicable data-protection and other relevant laws.

For privacy questions, contact: info@turbotabl.es.