TRUSTCORE
Connect
Legal information

PRIVACY POLICYAND PROCESSING OF TRUSTCORE USERS' PERSONAL DATA

Last updated: July 20, 2026

1. GENERAL PROVISIONS

1.1. This Privacy Policy and Policy on the Processing of Personal Data of TRUSTCORE Users (hereinafter, the “Policy”) establishes the procedure for obtaining, using, storing, transferring, and protecting the personal data of users of the TRUSTCORE website and related services.

1.2. The Policy has been developed in accordance with the Constitution of the Russian Federation, Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data,” Federal Law No. 149-FZ dated July 27, 2006 “On Information, Information Technologies and Information Protection,” Federal Law No. 38-FZ dated March 13, 2006 “On Advertising,” and other applicable regulatory legal acts of the Russian Federation.

1.3. TRUSTCORE is an information technology service in the field of payment solutions intended to advise businesses, support connection to payment services, organize technical integration, and facilitate interaction with independent banks, acquirers, payment providers, and other technology partners.

1.4. TRUSTCORE is not a bank, credit institution, or payment system operator. Payments, payouts, transfers, identification, and other regulated operations may be carried out directly by independent payment partners in accordance with their own terms, rules, and legal requirements.

1.5. The personal data operator under this Policy is the TRUSTCORE Administration, which organizes the operation of the website, processes user requests, and provides technical support for the service (hereinafter, the “Operator”).

1.6. The Policy applies to information obtained:

  • when visiting the TRUSTCORE website;
  • when completing and submitting an application form;
  • when contacting TRUSTCORE by email;
  • when contacting TRUSTCORE via Telegram;
  • during consultations;
  • when discussing connection terms and technical integration;
  • during subsequent business and technical interaction with the User.

1.7. By using the website, completing an application form, or sending a request to TRUSTCORE, the User confirms that they have reviewed this Policy.

1.8. Where the User's consent is required by law, personal data is processed after obtaining specific, substantive, informed, conscious, and unambiguous consent.

2. TERMS AND DEFINITIONS

2.1. Personal data means any information relating to an identified or identifiable individual, directly or indirectly.

2.2. User means an individual who visits the TRUSTCORE website or contacts TRUSTCORE independently or as a representative of a project, company, organization, or individual entrepreneur.

2.3. Operator means the TRUSTCORE Administration, which independently determines the purposes of personal data processing, the scope of personal data processed, and the actions performed with such data.

2.4. Processing of personal data means any action or set of actions performed with personal data, including collection, recording, systematization, accumulation, storage, clarification, updating, modification, retrieval, use, transfer, granting access, anonymization, blocking, deletion, and destruction.

2.5. Confidentiality of personal data means the mandatory requirement not to disclose or distribute personal data without the User's consent or another lawful basis.

2.6. Website means the TRUSTCORE online resource through which the User receives information about the service, submits an application, or requests a consultation.

2.7. Payment partners means independent banks, acquirers, payment providers, operators of payment and identification solutions, and providers of anti-fraud, KYC/AML, and other technology services.

3. CATEGORIES OF PERSONAL DATA PROCESSED

3.1. When completing an application form or contacting TRUSTCORE, the User may voluntarily provide:

  • name;
  • project, company, or brand name;
  • email address;
  • Telegram username, profile link, or other Telegram contact;
  • language of communication;
  • message text;
  • other information independently provided by the User in the request.

3.2. During subsequent business interaction, the following may additionally be processed:

  • the representative's surname, first name, and patronymic;
  • position and place of work;
  • business contact details;
  • information about the project, field of activity, and proposed operating model;
  • information required for a preliminary connection assessment;
  • technical information related to integration;
  • the content of correspondence, consultations, and support requests.

3.3. When visiting the website, the following technical information may be processed automatically:

  • IP address;
  • device type;
  • operating system;
  • browser type and version;
  • date and time of the visit;
  • address of the page visited;
  • referral source;
  • selected website language;
  • information about technical errors;
  • other technical data automatically transmitted by the User's browser.

3.4. The website language selected by the User may be stored in the browser's local storage to display the Russian or English version of the website correctly.

3.5. The public section of the TRUSTCORE website is not intended for entering or transmitting:

  • full bank card number;
  • bank card expiration date;
  • PIN;
  • CVV/CVC code;
  • passwords for banking applications and personal accounts;
  • one-time verification codes;
  • private keys and other confidential payment data.

3.6. The User must not transmit the information listed in clause 3.5 through the website form, email, or Telegram.

3.7. When the User follows a link to the website of a bank, acquirer, payment provider, or another partner, information is processed by the owner of the relevant resource under its own privacy policy and security rules.

3.8. TRUSTCORE does not intentionally collect special categories of personal data or biometric personal data. The User should not send such information through publicly available forms or communication channels.

4. PURPOSES OF PERSONAL DATA PROCESSING

4.1. The User's personal data is processed for the following purposes:

4.1.1. Receiving, registering, and processing applications and requests.

4.1.2. Communicating with the User by email, Telegram, or another method specified by the User.

4.1.3. Providing information about TRUSTCORE's capabilities, services, and operating procedures.

4.1.4. Providing consultations on payment solutions and technical integration.

4.1.5. Conducting a preliminary assessment of the project, its needs, and technical requirements.

4.1.6. Selecting potential payment and technology solutions.

4.1.7. Organizing the User's interaction with independent payment and technology partners.

4.1.8. Supporting connection and integration.

4.1.9. Providing technical and informational support.

4.1.10. Ensuring stable, correct, and secure operation of the website.

4.1.11. Detecting and preventing fraud, abuse, spam, technical attacks, and other violations.

4.1.12. Protecting the rights and legitimate interests of Users and TRUSTCORE.

4.1.13. Complying with the laws of the Russian Federation and lawful requests from authorized public authorities.

4.1.14. Sending informational and advertising messages where the User's required prior consent has been obtained.

4.2. Personal data is not processed for purposes incompatible with the purposes for which it was originally collected.

5. LEGAL BASES FOR PROCESSING

5.1. The legal bases for processing personal data are:

  • the User's consent to the processing of personal data;
  • the need to process a request or application submitted by the User;
  • the need to take action at the User's initiative before entering into a contract;
  • the need to perform an agreement or contract, where such a contract has been concluded;
  • performance of obligations established by the laws of the Russian Federation;
  • exercise of the rights and legitimate interests of TRUSTCORE or third parties, provided that the User's rights and freedoms are not violated;
  • other grounds provided for by Federal Law No. 152-FZ.

5.2. The User's consent must be voluntary, specific, substantive, informed, conscious, and unambiguous.

5.3. The Operator is responsible for confirming the existence of consent or another lawful basis for processing personal data.

5.4. Personal data is processed for the direct promotion of goods, work, or services using communication tools only with the User's prior consent.

6. PRINCIPLES OF PERSONAL DATA PROCESSING

6.1. Personal data is processed lawfully and fairly.

6.2. Processing is limited to achieving specific, predetermined, and lawful purposes.

6.3. Personal data may not be processed in a manner incompatible with the purposes for which it was collected.

6.4. Only personal data that corresponds to the stated processing purposes is processed.

6.5. The content and volume of personal data processed correspond to the stated purposes. Excessive processing is not permitted.

6.6. The accuracy, sufficiency, and, where necessary, relevance of personal data are ensured during processing.

6.7. Where incomplete or inaccurate data is identified, reasonable measures are taken to clarify or delete it.

6.8. Personal data is stored no longer than required for the processing purposes unless another retention period is established by law or an applicable agreement.

7. PROCEDURE AND METHODS OF PROCESSING

7.1. Personal data may be processed using automated means or without using automated means.

7.2. The Operator may perform the following actions with personal data:

  • collection;
  • recording;
  • systematization;
  • accumulation;
  • storage;
  • clarification;
  • updating;
  • modification;
  • retrieval;
  • use;
  • transfer;
  • granting access;
  • anonymization;
  • blocking;
  • deletion;
  • destruction.

7.3. Access to personal data is granted only to persons who require it to process a request, provide technical support for the website, or provide a service requested by the User.

7.4. The Operator does not sell Users' personal data or transfer it to third parties for their independent use for advertising purposes without the User's consent or another lawful basis.

8. TRANSFER OF PERSONAL DATA TO THIRD PARTIES

8.1. Personal data may be transferred to third parties only to the extent necessary to achieve the stated processing purposes.

8.2. Recipients of personal data may include:

  • banks, acquirers, and payment providers;
  • providers of identification, KYC/AML, and anti-fraud solutions;
  • hosting providers;
  • developers and technical specialists;
  • business communication services;
  • professional advisers;
  • public authorities and courts in cases provided for by law;
  • other persons where the User has provided consent or another lawful basis exists.

8.3. Applications submitted through the website form may be transferred to TRUSTCORE's work channel via the Telegram Bot API.

8.4. An application transferred via Telegram may include:

  • name;
  • project, company, or brand name;
  • email address;
  • Telegram contact;
  • selected website language;
  • message text.

8.5. The use of Telegram and certain foreign technology services may involve cross-border transfers of personal data. Such transfers are permitted only where the required legal basis exists and the requirements of the laws of the Russian Federation are observed.

8.6. When personal data of citizens of the Russian Federation is collected via the Internet, the initial recording, systematization, accumulation, storage, clarification, and retrieval of such data must be carried out using databases located in the Russian Federation, except in cases provided for by law.

9. RETENTION PERIODS AND DESTRUCTION OF PERSONAL DATA

9.1. Application data, requests, and business correspondence may be stored for three years from the date of the last interaction with the User.

9.2. Technical website logs may be stored for twelve months.

9.3. Data may be stored for longer where necessary:

  • to perform existing obligations;
  • to review claims and resolve disputes;
  • to protect rights and legitimate interests;
  • to comply with legal requirements;
  • until the applicable limitation period expires.

9.4. Once the processing purposes have been achieved, the retention period has expired, consent has been withdrawn, or a lawful request has been received, personal data is deleted, destroyed, or anonymized unless its continued processing is required on another lawful basis.

10. PERSONAL DATA PROTECTION

10.1. The Operator takes necessary and sufficient legal, organizational, and technical measures to protect personal data against unlawful or accidental access, modification, blocking, copying, provision, distribution, deletion, destruction, and other unlawful actions.

10.2. Depending on the nature of processing, the following measures may be applied:

  • restricting and separating access;
  • using passwords and authentication tools;
  • protecting administrative panels and work channels;
  • using secure communication channels;
  • creating backups;
  • regularly updating software;
  • identifying technical vulnerabilities;
  • controlling contractor access;
  • deleting data when its processing is no longer necessary;
  • restoring access to data after technical failures where possible.

10.3. No method of transmitting or storing information guarantees absolute security. The User must also take reasonable precautions and must not transmit confidential payment or authentication data through unsecured channels.

11. USER RIGHTS

11.1. The User has the right to:

  • receive information concerning the processing of their personal data;
  • request clarification of incomplete, outdated, or inaccurate data;
  • request the blocking or deletion of data processed without a lawful basis;
  • withdraw consent to the processing of personal data;
  • request that processing be terminated where there are no grounds for its continuation;
  • opt out of advertising and marketing messages;
  • receive information about intended or completed cross-border transfers;
  • challenge the Operator's actions or omissions before an authorized authority or a court;
  • exercise other rights provided for by the laws of the Russian Federation.

11.2. To exercise their rights, the User may send a request to Support@trust-core.cc.

11.3. It is recommended to use “Personal Data” as the email subject.

11.4. The request must describe the requirement and include information sufficient to determine the data and actions to which the request relates.

11.5. To prevent unlawful access to another person's data, the Operator may request reasonable proof of the applicant's identity.

11.6. Withdrawal of consent does not affect the lawfulness of processing performed before the withdrawal was received and does not prevent further processing where another lawful basis exists.

12. USER OBLIGATIONS

12.1. The User must provide accurate and up-to-date information.

12.2. The User must promptly notify TRUSTCORE of changes to previously provided data where further interaction requires that data to remain current.

12.3. The User must not transfer third parties' personal data without their consent or another lawful basis.

12.4. The User is responsible for the content of information voluntarily submitted through the website form, email, or Telegram.

13. INFORMATIONAL AND ADVERTISING MESSAGES

13.1. TRUSTCORE may send the User service messages related to application processing, consultations, connection, integration, technical support, and security.

13.2. Advertising and marketing messages are sent only with the User's prior consent where such consent is required by law.

13.3. The User may unsubscribe from advertising messages using the method specified in the message or by sending a request to Support@trust-core.cc.

13.4. Messages required to process a request, fulfill the User's request, or ensure security are not advertising messages.

14. THIRD-PARTY RESOURCES

14.1. The TRUSTCORE website may contain links to Telegram, websites of banks, acquirers, payment providers, and other third-party resources.

14.2. This Policy does not govern the processing of personal data on third-party resources.

14.3. TRUSTCORE is not responsible for the content, security, or data processing procedures of resources that are not under TRUSTCORE's control.

14.4. Before using a third-party resource, the User is advised to review its privacy policy and terms of use.

15. MINORS' DATA

15.1. The TRUSTCORE website and services are intended primarily for adult business representatives.

15.2. TRUSTCORE does not intentionally collect minors' personal data.

15.3. If TRUSTCORE becomes aware that a minor's data was provided without an appropriate lawful basis, such data will be deleted unless its continued storage is required by law.

16. FINAL PROVISIONS

16.1. This Policy is made publicly available on the TRUSTCORE website.

16.2. The Policy remains in effect indefinitely until it is replaced by a new version.

16.3. TRUSTCORE may amend the Policy when legislation, website functionality, technologies used, services used, or personal data processing procedures change.

16.4. A new version takes effect upon publication on the website unless another effective date is specified in it.

16.5. The date of the latest update is stated at the beginning of the document.

16.6. Continued use of the website after publication of a new version means that the User has been given an opportunity to review the amendments.

17. CONTACT INFORMATION

Service: TRUSTCORE

Email for personal data matters: Support@trust-core.cc

Telegram for general inquiries: @Manager_TrustCore