CHIFAT®
We publish the list of third parties to which the personal data of CHIFAT® clients and visitors is transferred: the registry supplements section 9 of the Privacy Policy and is published together with it as part of the documents setting out the operator's policy on personal data processing (Art. 18.1(2) of RF Federal Law 152-FZ of 27 July 2006 “On Personal Data”); for data subjects to whom the GDPR applies, it gives the information on recipients (GDPR Art. 13(1)(e)). Personal data of RU citizens is primarily stored within the territory of Russia (Art. 18(5) of 152-FZ); part of the data is nevertheless transferred to recipients outside Russia. The “Country and address” column names the country and address of a recipient where they are stated; a dash in that column means the country is not stated, not that the recipient is in Russia. Section 10 of the Privacy Policy sets out the legal grounds of the cross-border transfer for the recipients it names: the Sentry error-report ingest (the operator's legitimate interest), the analytics tools loaded only with consent, and the storage of data of subjects who are not RU citizens at Hetzner. The “Processing terms / DPA” column distinguishes a data processing agreement from the recipient's privacy notice — the latter is not an agreement.
The registry is published: (a) under 152-FZ Art. 18.1(2) — as part of the documents setting out the operator's policy on personal data processing, to which the operator must provide unrestricted access; (b) under GDPR Art. 13(1)(e) — as the information on the recipients of personal data for data subjects to whom the Regulation applies; (c) under PIPL Art. 23 — for PRC subjects. The registry names third parties — recipients of personal data; the operator does not entrust processing to every one of them. To a recipient entrusted with processing (a processor), data is transferred under a contract with it (152-FZ Art. 6(3)).
| Name | Purpose | Data categories | Country and address | Processing terms / DPA |
|---|---|---|---|---|
| Cloud.ru (ООО «Облачные технологии») | Hosting of the site and databases; storage of RU citizens’ personal data within Russia (Art. 18(5) of 152-FZ). | Email, password stored as a hash, full name, phone, IP, user agent, activity logs, sessions. | Russia, 28 2-ya Zvenigorodskaya St., Moscow 123100 | Recipient's legal documents (not a DPA) ↗ |
| Yandex Cloud (ООО «Яндекс.Облако») | The Yandex Cloud Postbox service — sending the site’s service e-mails (for example, e-mail address confirmation and password recovery). | The recipient’s e-mail address, the text of the message (including links and one-time codes). | Russia, 16 Lva Tolstogo St., premises 528, Moscow 119021 | Recipient's legal documents (not a DPA) ↗ |
| Hetzner Online GmbH | Hosting of the server infrastructure, including the Plausible web analytics loaded only with consent; storage of the personal data of subjects who are not RU citizens. | Personal data of subjects who are not RU citizens: email, full name, IP, user agent, history. RU citizens’ personal data is not stored here — it is stored in Russia (the Cloud.ru row, Art. 18(5) of 152-FZ). ⚠️ A connection from a visitor in Russia to a Hetzner server does occur nonetheless: the Plausible web analytics is loaded in the browser with consent, and the server sees the connection’s IP address and request headers. Plausible counts aggregated page views and referrers, uses no cookies and does not store the IP address (only a hash for counting daily unique visitors). |
For questions about the recipients of personal data, contact [email protected].
Last updated: 9/25/2026
| Germany (processing in Finland, EU); Industriestr. 25, 91710 Gunzenhausen, Germany |
| DPA ↗ |
| Cloudflare, Inc. | Reverse proxy for all of the site’s traffic: content delivery network (CDN), DNS, protection against attacks. Second leg — the Cloudflare Turnstile anti-bot check on the login, signup, password-recovery, contact, checkout and data-subject-request forms: when the form opens, the browser loads the Cloudflare challenge script; on submit, the server verifies the result with Cloudflare. Loaded without consent — protection of forms against automated submissions; the ground is the operator’s legitimate interest in securing the service (152-FZ Art. 6(1)(7)), as for Sentry. | The visitor’s connection to the site, including form submissions, terminates at a Cloudflare edge node and is passed on to our server through it, so everything that passes through the site during a visit is available to the node: the visitor’s IP address, user agent, HTTP headers (cookies included), the content of requests and responses, including data entered into forms (name, email, message, order details). This applies to visitors who are RU citizens as well. Turnstile: when the challenge script loads and the challenge runs, Cloudflare receives the visitor’s IP address, user agent, request headers and browser details; on form submit, the server passes the challenge result and the visitor’s IP address to Cloudflare. The Turnstile check itself does not pass the form content — that content goes through Cloudflare as part of the site’s traffic. Cloudflare nodes are located worldwide. | USA, 101 Townsend Street, San Francisco, CA 94107; edge nodes worldwide | DPA ↗ |
| VK (ООО «ВК Цифровые Технологии») | Mail service for the [email protected] mailbox — receiving and sending business correspondence with clients. | Sender/recipient email address, message content. | Russia, 39 Leningradsky Ave., bldg. 79, Moscow 125167 | No DPA concluded / not found |
| Telegram Messenger Inc. | Telegram messenger — delivery of the one-time two-factor authentication code when the user has chosen Telegram as the way to receive it. | The user’s Telegram chat identifier, the one-time code. | British Virgin Islands, Commerce House, Wickhams Cay 1, Road Town, Tortola | Privacy notice (not a DPA) ↗ |
| Google LLC | Embedding of catalogue product videos from YouTube (privacy-enhanced mode: no tracking cookies are set before playback). The player loads only with consent to the “Marketing” category or when the visitor clicks the “Load video” placeholder — until then no connection to Google is made. | When the player loads, Google receives the visitor’s IP address, request headers (user agent, referrer limited to strict-origin-when-cross-origin) and device details; on playback — player data under YouTube’s terms. | USA, 1600 Amphitheatre Parkway, Mountain View, CA 94043 | DPA ↗ |
| Vimeo.com, Inc. | Embedding of catalogue product videos hosted on Vimeo (the embedded Vimeo video player). The player loads only with consent to the “Marketing” category or when the visitor clicks the “Load video” placeholder — until then no connection to Vimeo is made. | When the player loads, Vimeo receives the visitor’s IP address, request headers (user agent, referrer limited to strict-origin-when-cross-origin) and device details; on playback — player data and cookies under Vimeo’s policy. Account personal data is NOT transferred. | USA, 330 West 34th Street, 10th Floor, New York, NY 10001 | Privacy notice (not a DPA) ↗ |
| Yandex.Metrika (ООО «Яндекс») | Web analytics of chifat.ru traffic: traffic sources, visitor behaviour; Webvisor — recording of visitor sessions to analyse the usability of the site. Loaded only with the user’s consent (via the cookie consent banner). | IP address, user agent, navigation history (page URLs, referrers), device/screen parameters, cookies. Webvisor session recordings on open pages: pointer movements, clicks, scrolling and page content. Excluded from recording: the personal account, the cart, checkout, all forms and input fields (catalogue search, enquiry, request, sign-in, sign-up, password recovery, passwords and two-factor authentication codes, data subject request) except the product quantity field, the e-mail address in the account menu, revealed supplier contacts — in the recording, text is replaced with random characters of the same length and fields with asterisks. The counter loads only if the page path is a site section with its variable part in its own form (a brand, supplier or product address, an order number), the rest of the address carries nothing but a list page number, the site’s service parameters (each in its own form) and advertising and search tags (utm, yclid, gclid, ysclid, yrclid), and the previous page address — on this or another site — carries no other query parameters; an address with other data (an e-mail address in the path, a search query, a return path after sign-in, a value outside its form, anything after “#” except the site’s links to the contacts section and to sections of its legal documents) is not passed to the counter. Clicks on a supplier’s e-mail and phone links are not reported. Metrika form analytics is switched off. Recordings are kept by Yandex for 15 days. | Russia, 16 Lva Tolstogo St., Moscow 119021 | Privacy notice (not a DPA) ↗ |
| PostHog, Inc. | Product event analytics — user journeys, A/B tests, funnels. Loaded ONLY with the user’s consent (152-FZ Art. 9 / GDPR Art. 6(1)(a) / PIPL Art. 13). Data is stored in the EU (Germany) under the DPA with PostHog Inc. | Pseudonymised visitor identifier, events (event name, properties), IP (anonymised — last octet zeroed), user agent. Account personal data of RU citizens is NOT transferred. | USA, 2261 Market Street #4008, San Francisco, CA 94114; data storage in Germany (EU) | DPA ↗ |
| Functional Software, Inc. (Sentry) | Site error and performance monitoring (the report ingest is located in Germany). Cross-border transfer — see section 10 of the Privacy Policy. Loaded without consent — the legal ground is legitimate interest (152-FZ Art. 6(1)(7) / GDPR Art. 6(1)(f)) to secure and keep the service operational. Part of the personal data is removed from the report before sending; the report is not anonymous nonetheless — see the data categories. | Stack traces, release version, navigation breadcrumbs, page URLs after scrubbing. Session Replay recordings and report attachments are not transferred to the ingest. Removed from the report: of the account details — the e-mail address, username and IP address (the account’s internal record number and its role are kept); request content; cookies; the header describing the browser (user-agent); values from the page address (search and filter parameters, variable path segments). ⚠️ Scrubbing the report does not make it anonymous: everything outside the scrubbed details or not recognised by the scrubbing remains available to the recipient. In particular: the sender’s IP address is visible to the ingest when connecting — removing the field from the report body does not change that, and the ingest is located in Germany; browser and device details other than the removed user-agent header are available to the recipient; stack frames (file paths and lines of our own source code) are transferred unscrubbed; a first or last name written into free-form error message text is not recognised by the scrubbing. | USA, 45 Fremont Street, 8th Floor, San Francisco, CA 94105; report ingest in Germany (EU) | DPA ↗ |