"English version" section below
ПОЛИТИКА КОНФИДЕНЦИАЛЬНОСТИ
сервиса «Метафикс»
г. Москва
Редакция от «23» июня 2026 года
Настоящая Политика конфиденциальности (далее — «Политика») разработана Обществом с ограниченной ответственностью «Агентство цифрового технологического сопровождения» (ООО «АЦТС») и определяет порядок обращения с информацией, в том числе с персональными данными, получаемой в связи с использованием сервиса «Метафикс» (далее — «Сервис»), а также меры, направленные на обеспечение её конфиденциальности и безопасности.PRIVACY POLICY
of the “Metafix” Service
Moscow Edition dated June 23, 2026
This Privacy Policy (hereinafter referred to as the “Policy”) has been developed by Limited Liability Company “Agency of Digital Technological Support” (LLC “ACTS”) and defines the procedure for handling information, including personal data, obtained in connection with the use of the “Metafix” service (hereinafter referred to as the “Service”), as well as measures aimed at ensuring its confidentiality and security.
This Policy is an integral part of the User Agreement of the “Metafix” service, available at https://ацтс.рф, and applies together with the Personal Data Processing Policy of LLC “ACTS”.
By starting to use the Service, including completing Registration or performing other actions constituting acceptance of the User Agreement, the User confirms that they have read this Policy, understand its provisions, and accept them. If the User does not agree with the terms of this Policy, they must refrain from using the Service.
Contents
1. General Provisions
2. Terms and Definitions
3. Information Collected by the Administration
4. Purposes of Collection and Use of Information
5. Legal Grounds for Processing Personal Data
6. Cookies and Similar Technologies
7. Confidentiality of User Content
8. AI Modules and Anonymized Data
9. Disclosure and Transfer of Information to Third Parties
10. Storage of Information, Localization, and Retention Periods
11. Measures to Ensure Information Security
12. User Rights and Procedure for Their Exercise
13. User Consents
14. Specifics of Processing for Certain Categories of Users
15. Notifications and Communications
16. Minors
17. Changes to the Policy
18. Contact Information
19. Final Provisions
1. General Provisions
1.1. This Policy has been developed in accordance with the requirements of the legislation of the Russian Federation, including:
— the Constitution of the Russian Federation (Articles 23, 24);
— the Civil Code of the Russian Federation (Part Four, Articles 1225, 1235, 1286);
— Federal Law No. 152-FZ of July 27, 2006 “On Personal Data” (hereinafter — “152-FZ”);
— Federal Law No. 149-FZ of July 27, 2006 “On Information, Information Technologies and Protection of Information”;
— Federal Law No. 38-FZ of March 13, 2006 “On Advertising”;
— Federal Law No. 233-FZ of August 8, 2024 (regarding the processing of anonymized personal data);
— Federal Law No. 23-FZ of February 28, 2025 (regarding the localization of personal data storage);
— Federal Law No. 156-FZ of June 24, 2025 (regarding requirements for the formalization of consent to the processing of personal data);
— Resolution of the Government of the Russian Federation No. 1119 of November 1, 2012 and Resolution of the Government of the Russian Federation No. 687 of September 15, 2008;
— Order of the FSTEC of Russia No. 21 of February 18, 2013;
— Order of Roskomnadzor No. 140 of June 19, 2025 (regarding requirements and methods for anonymization of personal data);
— other regulatory legal acts of the Russian Federation in the field of processing and protection of information.
1.2. The Administration is Limited Liability Company “Agency of Digital Technological Support” (LLC “ACTS”, TIN 9722002596, OGRN 1217700256179, address: 111123, Moscow, 2nd Vladimirskaya St., 12, bldg. 3, premises 1/1). When processing Users’ personal data, the Administration acts as a personal data operator within the meaning of Article 3 of 152-FZ.
1.3. Relationship of this Policy with other documents of the Administration:
— Personal Data Processing Policy — published in accordance with Part 2 of Article 18.1 of 152-FZ and defines the general principles, purposes, legal grounds, categories, and conditions for the processing of personal data by the Operator;
— this Privacy Policy — is a contractual document (part of the User Agreement) and defines the procedure for handling User information in relation to the use of the “Metafix” Service, including personal data, Content, technical data, and cookies, as well as measures to ensure their confidentiality;
— the “Cookies and Analytics” document — defines the composition, purposes, and retention periods for the use of cookies and similar technologies, as well as the procedure for obtaining and withdrawing User consent in the relevant part;
— Consents to the processing of personal data — are formalized as standalone documents in relation to specific processing purposes (analytics, improvement of AI modules, advertising communications).
With regard to the processing of personal data, this Policy applies subject to the Personal Data Processing Policy, individual User consents, and the requirements of 152-FZ. In the event of discrepancies on issues of personal data processing, the provisions of 152-FZ and the Personal Data Processing Policy as a mandatory publicly available document of the Operator shall prevail.
1.4. This Policy applies to the processing of information carried out when using the Service (web application, mobile application for iOS and Android operating systems, Open API integration gateways), when visiting the Website, as well as when the User interacts with the Administration by other means (inquiries, correspondence).
1.5. This Policy is a publicly available document and is posted on the Website at https://ацтс.рф/privacy-policy. The Administration ensures unrestricted access to this Policy.
1.6. The actions (acceptance) performed by the User when accepting the User Agreement form the legal basis for the processing of personal data necessary for the performance of the contract (Clause 5 of Part 1 of Article 6 of 152-FZ). The processing of personal data for additional purposes (analytics, improvement of AI modules, advertising communications) is carried out on the basis of separate consents formalized as standalone documents.
2. Terms and Definitions
2.1. The following terms are used in this Policy:
Service (“Metafix”, Program) — a computer program “Digital Tracker of Construction Processes Metafix”, including a web application, mobile application (client part), artificial intelligence modules (AI modules), Open API integration gateways, and User documentation. The exclusive right to the Program belongs to the Administration.
Website — the Administration’s Internet website available at https://ацтс.рф/, as well as its subdomains.
Administration (Rights Holder, Operator) — LLC “ACTS”.
User — a fully capable individual who has completed Registration and uses the Functionality of the Service on their own behalf and (or) in the interests of the Licensee.
Licensee — a legal entity or individual entrepreneur that has entered into a license agreement with the Administration for the right to use the Program.
Account — a set of data created upon Registration and used to identify and authenticate the User when accessing the Service.
Registration — the procedure for creating an Account in the Service. Registration is voluntary.
Personal Data (PD) — any information relating directly or indirectly to a specific or identifiable individual (personal data subject).
Processing of Personal Data — any action (operation) or set of actions (operations) with personal data performed with or without the use of automation tools.
Content — any information, data, documents, photographs, files, and other materials uploaded, created, or posted by the User in the Service.
AI Module — a functional component of the Service that uses artificial intelligence technologies (machine learning, computer vision, neural networks).
Cookies — small text files stored on the User’s device when using the Website and the Service.
Anonymization of Personal Data — actions as a result of which it becomes impossible without the use of additional information to determine the ownership of personal data by a specific personal data subject.
2.2. Other terms are used in the meanings defined by the User Agreement, the Personal Data Processing Policy, and 152-FZ.
3. Information Collected by the Administration
3.1. Data provided by the User
upon Registration and use of the Service: last name, first name, patronymic; email address; phone number; position; name of the organization (Licensee).
3.2. Account data: login, password hash, User role (category) in the Service, authorization history, access settings.
3.3. Content uploaded by the User: photographic materials of construction sites (which may contain incidental images of faces), documents, comments, conclusions and data on classified defects, geolocation data of objects, and other information about construction sites.
3.4. Technical data collected automatically: IP address, device model and type, operating system, application version, device identifiers, data on events and actions in the Service, cookies and similar technologies.
3.5. Interaction data: content of requests to technical support, correspondence with the Administration, information about applications.
3.6. The Administration does not collect or process special categories of personal data (racial or ethnic origin, political opinions, religious or philosophical beliefs, health status, intimate life) or biometric personal data. Incidental images of faces in photographic materials are not used for the purposeful identification of individuals, are not matched with other data to establish identity, and are not processed as biometric personal data within the meaning of Article 11 of 152-FZ. Where technically feasible, the Administration applies measures to minimize such images (access restriction, cropping, or blurring), provided this does not impede the achievement of the purposes of processing photographic materials.
3.7. Sources of information are: information provided by the User directly; information generated automatically when using the Service; information entered by the Licensee in relation to its employees and employees of contracting organizations.
4. Purposes of Collection and Use of Information
4.1. The Administration processes information for the following purposes:
— providing access to the Service and ensuring its Functionality; managing Accounts; identifying and authenticating Users; sending service notifications;
— performance of the User Agreement and the license agreement;
— processing personal data of Licensee employees entered into the Service for the purposes of access management and record-keeping (on behalf of the Licensee);
— ensuring the security of the Service: preventing unauthorized access, detecting and preventing fraud, detecting information security incidents;
— technical support and consideration of User requests;
— conducting analytical research, improving the user interface, and optimizing Functionality (on the basis of separate User consent);
— using anonymized data for training and improving AI modules (on the basis of separate User consent);
— sending advertising, informational, and marketing materials (on the basis of separate User consent);
— compliance with the requirements of the legislation of the Russian Federation and responding to requests from authorized state bodies.
4.2. The processing of information is limited to the achievement of specific, predetermined, and legitimate purposes. Processing incompatible with the purposes of collection of information, as well as the merging of databases processed for incompatible purposes, is not permitted.
5. Legal Grounds for Processing Personal Data
5.1. The Administration processes personal data on the legal grounds specified in the table below:
Legal Ground Norm of 152-FZ Processing Purposes
Performance of a contract to which the PD subject is a party Clause 5 of Part 1 of Article 6 Providing access to the Service, identification and authentication, ensuring Functionality, service notifications, technical support
Operator’s instruction (on behalf of another operator) Part 3 of Article 6 Processing of data of Licensee employees entered into the Service
Consent of the PD subject Clause 1 of Part 1 of Article 6, Article 9 Analytics and improvement of the Service, improvement of AI modules, advertising communications
Legitimate interests of the Administration Clause 7 of Part 1 of Article 6 Ensuring security, preventing fraud
Performance of an obligation provided by law Clause 2 of Part 1 of Article 6 Responding to requests from authorized state bodies
5.2. For purposes directly related to the performance of the User Agreement, separate consent of the User to the processing of personal data is not required (Clause 5 of Part 1 of Article 6 of 152-FZ).
5.3. The processing of personal data for additional purposes (analytics and improvement of the Service, improvement of AI modules, advertising communications) is carried out on the basis of separate User consent. Consent is formalized as a standalone electronic document, separate from other documents that the personal data subject confirms and (or) signs (Part 1 of Article 9 of 152-FZ as amended by Federal Law No. 156-FZ of June 24, 2025), and contains the mandatory details provided for by Part 4 of Article 9 of 152-FZ.
5.4. The User has the right not to provide consent to processing for additional purposes or to withdraw it at any time. Withdrawal of such consent does not entail termination of access to the Service and does not affect the processing of personal data carried out on other legal grounds.
6. Cookies and Similar Technologies
6.1. When using the Website and the Service, the Administration uses cookies and similar technologies to ensure the operation of the Service, save user settings, maintain an authentication session, as well as for analytics subject to User consent.
6.2. The Administration uses the following categories of cookies:
— strictly necessary (technical) — ensure the functioning of the Service, authentication, and security; their use is a mandatory condition for the operation of the Service;
— analytical — allow assessment of how the Service is used in order to improve its operation; are set and used only after obtaining User consent.
6.3. Strictly necessary (technical) cookies are used without separate User consent to the extent necessary for the functioning of the Website and the Service. Analytical cookies and similar technologies are not set until prior consent of the User is obtained via a banner, Website, or Service interface. The User has the right to refuse analytical cookies without termination of access to the Service.
6.4. The User may manage cookies through the consent interface on the Website or in the Service, as well as through the settings of their browser or device, including limiting or prohibiting their use and deleting previously stored cookies. Disabling strictly necessary cookies may result in the unavailability of certain Service functions.
6.5. The procedure for processing data collected using cookies is additionally determined by the “Cookies and Analytics” document posted on the Website, and the Consent to the processing of personal data for analytics purposes.
7. Confidentiality of User Content
7.1. Rights to Content uploaded by the User to the Service, including rights to protected results of intellectual activity, remain with the User, the Licensee, or another rights holder. Uploading Content to the Service does not entail the transfer of exclusive rights to such Content to the Administration. The Administration is entitled to use Content solely to the extent necessary to ensure the operation of the Service, performance of the User Agreement, the license agreement, and other purposes expressly provided for by this Policy.
7.2. The Administration ensures the confidentiality of Content and does not disclose it to third parties, except in cases provided for by this Policy, the User Agreement, and the legislation of the Russian Federation.
7.3. The Administration does not participate in the formation of the content of Content, does not verify its content, and is not responsible for its accuracy, completeness, and compliance with legislation.
7.4. Photographic materials uploaded to the Service are processed by AI modules solely for the purpose of detecting and classifying construction defects. AI modules do not use facial recognition technologies, do not identify individuals from images, and do not process biometric personal data.
7.5. Access to Content is provided in accordance with the User category, role model, and access settings established by the Licensee.
8. AI Modules and Anonymized Data
8.1. The results of the operation of AI modules are of an informational and advisory (recommendatory) nature and do not constitute decisions giving rise to legal consequences in relation to the personal data subject. The Administration does not make decisions in relation to the User that give rise to legal consequences based solely on automated processing of personal data, except in cases provided for by 152-FZ.
8.2. For the purposes of training and improving AI modules, the Administration uses anonymized data. Before using data for training, the Administration anonymizes it in accordance with Articles 3 and 13.1 of 152-FZ, as well as taking into account the requirements and methods for anonymization of personal data approved by Order of Roskomnadzor No. 140 of June 19, 2025. The methods applied and the result of anonymization are recorded by the Administration’s internal organizational and (or) technical means.
8.3. Anonymized data in respect of which it is impossible without the use of additional information to establish ownership by a specific personal data subject may be stored and used for statistical purposes and improvement of the Service without time limitation. If it subsequently becomes possible to determine the ownership of such data by a specific personal data subject, their processing is carried out as the processing of personal data.
8.4. The processing of data for the purpose of improving AI modules is carried out on the basis of separate User consent.
9. Disclosure and Transfer of Information to Third Parties
9.1. The Administration does not sell personal data and does not disclose it to third parties, except in cases provided for by this Policy and the legislation of the Russian Federation. A mandatory condition for transfer is that the recipient complies with confidentiality and ensures the security of personal data.
9.2. Transfer of information to third parties is possible in the following cases:
— the transfer is necessary for the performance of a contract with the User or to ensure the functioning of the Service, including to a cloud infrastructure provider or hosting provider engaged in processing on behalf of the Administration;
— the User has expressed consent to the transfer;
— transfer to the Licensee — in relation to data of Users engaged by such Licensee, to the extent necessary for the purposes of the license agreement;
— the transfer is provided for by the legislation of the Russian Federation (upon request of authorized state bodies).
9.3. Categories of recipients of information:
— cloud infrastructure provider — ensures storage and processing of data on servers located in the territory of the Russian Federation, on behalf of the Administration and on the basis of a contract containing conditions for the processing of personal data;
— Licensees — to the extent of data relating to their Users.
9.4. Upon a reasoned request, personal data may be transferred to judicial authorities, prosecutor’s offices, state security authorities, internal affairs authorities, and investigative authorities — in cases established by the legislation of the Russian Federation.
9.5. In accordance with Article 13.1 of 152-FZ, the Administration is obliged, upon the request of the authorized federal executive body, to provide personal data in anonymized form for inclusion in a state information system in the prescribed manner. Biometric personal data and special categories of personal data are not subject to transfer.
9.6. When instructing a third party to process personal data, the Administration ensures that the contract or instruction includes the conditions provided for by Part 3 of Article 6 of 152-FZ, including a list of actions with personal data, the purposes of processing, the obligation to maintain confidentiality, and requirements for the protection of personal data. The Administration remains responsible to the personal data subject for the actions of the person processing personal data on its behalf.
10. Storage of Information, Localization, and Retention Periods
10.1. The Administration stores and processes personal data on servers located in the territory of the Russian Federation (Part 5 of Article 18 of 152-FZ). Processing and storage of personal data of citizens of the Russian Federation using databases located outside the Russian Federation is not permitted.
10.2. Cross-border transfer of personal data by the Administration is not carried out. In the event of the need for such transfer, the Administration will ensure compliance with the requirements of Article 12 of 152-FZ and notify the authorized body in the prescribed manner.
10.3. Retention periods for information are determined depending on the purposes and grounds for processing:
Category / Ground Retention Period
User data (performance of contract) For the entire period of use of the Service and for 30 calendar days after termination of access (to ensure data export)
Licensee employee data (on behalf of the Licensee) Until a request for deletion is received from the Licensee; after termination of the license agreement — 30 calendar days
Technical data (cookies, logs) No more than 1 (one) year from the moment of collection
Data for analytics and AI (based on consent) Personal data processed for analytics and improvement of AI modules on the basis of consent — until the consent is withdrawn by the personal data subject; after withdrawal of consent, processing ceases, and personal data are destroyed or anonymized within a period not exceeding 30 calendar days, unless their further storage is required on another legal ground. Anonymized data formed before the withdrawal of consent and not allowing determination of ownership by a specific personal data subject without the use of additional information may be stored and used without time limitation.
Data for advertising communications (based on consent) Until consent is withdrawn by the subject; after withdrawal — cessation of mailings within 3 business days
Requests and correspondence 3 years from the moment the request is closed
Anonymized data Without time limitation
10.4. Upon achievement of the purposes of processing or upon expiration of the retention periods, personal data are destroyed or anonymized within a period not exceeding 30 (thirty) calendar days, in the manner established by the legislation of the Russian Federation. The destruction of personal data is confirmed by an act, an extract from the event log, or another documented method applicable to the relevant information system.
11. Measures to Ensure Information Security
11.1. The Administration takes necessary and sufficient legal, organizational, and technical measures to protect information from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution, as well as from other unlawful actions (Articles 18.1 and 19 of 152-FZ).
11.2. Organizational measures include: appointment of a person responsible for organizing the processing of personal data; issuance of local acts on issues of processing and protection of personal data; familiarization of employees with the requirements of legislation; internal control; assessment of the harm that may be caused to personal data subjects.
11.3. Technical measures include: encryption of data during transmission over information and telecommunication networks (SSL/TLS); access differentiation and control, password protection; registration and accounting of actions with personal data; detection of unauthorized access and response to it; data backup; use of information protection tools that have undergone a conformity assessment procedure.
11.4. The User is obliged to ensure the confidentiality of their Account data (login and password) and not to transfer them to third parties. All actions performed using the User’s Account are considered to have been performed by the User themselves. The User is obliged to immediately notify the Administration of any facts of unauthorized access to the Account at info@cts.company.
11.5. In the event of detection of unlawful (unauthorized) access to personal data, the Administration takes measures to eliminate the consequences of the incident and notifies the authorized body (Roskomnadzor) within 24 (twenty-four) hours from the moment of detection of the incident, and within 72 (seventy-two) hours submits the results of the internal investigation in the manner established by Part 3.1 of Article 21 of 152-FZ.
12. User Rights and Procedure for Their Exercise
12.1. The User (personal data subject) has the right to:
— receive information relating to the processing of their personal data (Article 14 of 152-FZ);
— request clarification, blocking, or destruction of personal data if they are incomplete, outdated, inaccurate, unlawfully obtained, or are not necessary for the stated purpose of processing;
— withdraw consent to the processing of personal data;
— withdraw consent to receive advertising materials independently of other consents;
— object to a decision made solely on the basis of automated processing of personal data;
— appeal the actions or inaction of the Administration to the authorized body for the protection of the rights of personal data subjects (Roskomnadzor) or in court;
— protect their rights and legitimate interests, including the recovery of damages and compensation for moral harm.
12.2. To exercise their rights, the User sends a request (inquiry) to the Administration by email to info@cts.company or by postal mail to the address: 111123, Moscow, 2nd Vladimirskaya St., 12, bldg. 3, premises 1/1.
12.3. The request must contain: the number of the main identity document of the User or their representative, information about the date of issue and the issuing authority; information confirming the User’s participation in relations with the Administration (contract number, date of registration in the Service, email address specified upon Registration, or other information); the content of the demand. The request may be sent in the form of an electronic document signed with an electronic signature in accordance with the legislation of the Russian Federation.
12.4. The Administration considers requests and provides a response within the time limits established by 152-FZ, including providing information on the existence and processing of personal data within 10 (ten) business days from the date of receipt of the request (with the possibility of extension in cases established by law). An objection to a decision made solely on the basis of automated processing is considered within 30 (thirty) days.
12.5. In the event of withdrawal of consent, the Administration ceases processing and, if the retention of personal data is no longer required for the purposes of processing, destroys them within a period not exceeding 30 (thirty) days, unless otherwise provided by the legislation of the Russian Federation or the contract, with documentary confirmation of destruction in the manner provided for by Clause 10.4 of this Policy.
13. User Consents
13.1. In relation to specific processing purposes, the Administration obtains User consents formalized as standalone documents:
— consent to the processing of personal data for the purposes of analytics and improvement of the Service;
— consent to the processing of personal data for the purposes of improving AI modules;
— consent to receive advertising and informational materials.
13.2. The fact of providing consent is recorded by the Administration’s information system with the preservation of the date and time, IP address, Account identifier, and version of the consent text.
13.3. The User has the right to withdraw any of the consents in the manner specified in the relevant consent and in Section 12 of this Policy.
14. Specifics of Processing for Certain Categories of Users
14.1. If the User independently provides their data upon Registration in the Service without the participation of a Licensee (including Users of the “Specialist” category), the Administration acts as an independent personal data operator, and processing is governed by this Policy, the Personal Data Processing Policy, and the User Agreement.
14.2. In relation to personal data entered by the Licensee into the Service (information about Licensee employees, employees of contracting organizations), the Administration acts as a person processing personal data on behalf of the Licensee (Part 3 of Article 6 of 152-FZ). The terms of such processing are determined by the Instruction for the Processing of Personal Data (an annex to the license agreement).
14.3. The Licensee, acting as an operator in relation to the personal data of its employees and other persons whose data are entered into the Service or may be contained in materials uploaded by the Licensee, is obliged to independently ensure the existence of a legal basis for the processing of such data, including obtaining properly formalized consents if such consents are required in accordance with legislation.
15. Notifications and Communications
15.1. Notifications related to the use of the Service (service notifications) are sent by the Administration via the email specified upon Registration, push notifications in the mobile application, and (or) through the Service interface.
15.2. Advertising and informational materials are sent exclusively subject to User consent and may be disabled by the User at any time (including via the “Unsubscribe” link in the advertising message).
15.3. A message is considered received by the User on the next business day after its dispatch.
16. Minors
16.1. The Service is intended for use by fully capable individuals. The Administration does not purposefully collect personal data of minors.
16.2. If the Administration becomes aware that personal data of a minor have been provided in violation of the requirements of legislation, the Administration will take measures to cease processing and destroy such data.
17. Changes to the Policy
17.1. The Administration has the right to make changes to this Policy. The new edition of the Policy is posted on the Website and enters into force no earlier than 10 (ten) calendar days from the date of posting, unless a later date is provided by the new edition. Changes driven by mandatory requirements of legislation or aimed solely at improving the position of Users may enter into force from the date of posting.
17.2. The Administration notifies Users of changes via the Service, email, and (or) by posting a notice on the Website. Continued use of the Service after the new edition of the Policy enters into force means acceptance by the User of the relevant changes to the extent that does not require separate consent.
17.3. In the event of a material change in the conditions for processing personal data, the Administration notifies Users before such changes enter into force. If the change involves the processing of personal data for a new purpose or on the basis of separate consent, such processing begins only after obtaining the relevant User consent.
18. Contact Information
18.1. All suggestions, questions, and requests related to the processing of information and ensuring confidentiality are sent to the Administration:
— by email: info@cts.company;
— by postal address: 111123, Moscow, 2nd Vladimirskaya St., 12, bldg. 3, premises 1/1;
— by phone: +7 985 484-80-08.
18.2. Requests to the person responsible for organizing the processing of personal data are sent to the email address: info@cts.company.
19. Final Provisions
19.1. The legislation of the Russian Federation applies to this Policy.
19.2. This Policy is an integral part of the User Agreement of the “Metafix” service. By acceding to the User Agreement, the User accedes to this Policy in full.
19.3. Recognition by a court of any provision of this Policy as invalid does not entail the invalidity of its other provisions.
19.4. The current edition of this Policy is posted on the Website at https://ацтс.рф/privacy-policy.