LEGAL INFORMATION
PROF.MIR Privacy Policy
This Policy explains what data the PROF.MIR operator processes, why it is needed, who receives it and how users exercise their rights.
1. Controller
The data controller is RAMKHAT PROF KADRY LLC. This Policy applies to prof.mir.express, user accounts, support requests and related platform workflows.
2. Data categories
Data depends on the selected function and legal status. The operator applies data minimisation and does not request information unnecessary for the stated purpose.
- account and contact data, language, country and security settings;
- professional profile, experience, portfolio and availability;
- identity, tax, registration and authority data needed to verify a party;
- listings, messages, contracts, signatures, milestones, files, payment statuses and evidence;
- security events, IP address, device, browser, cookies, access logs and checksums.
3. Purposes and legal bases
Data is processed to create and protect accounts, perform the Terms, publish information chosen by the user, support negotiations and deals, verify status and authority, sign documents, provide support, prevent fraud, comply with law and defend legal claims.
The legal bases include consent, taking steps to enter into and perform a contract, compliance with legal duties and legitimate security or legal-protection interests where those interests do not override individual rights.
4. Sources and recipients
Data may come from the user, their organisation, a counterparty, ESIA, public registers and approved providers only as required for the selected function.
Recipients may include a deal counterparty, infrastructure processor, bank or payment partner, signature service, public authority or another legally authorised recipient. Access is limited by purpose, contract and permissions.
5. ESIA and electronic signatures
When Gosuslugi is linked, the operator receives only authorised identifiers and verified attributes, never the user’s Gosuslugi password. A private signature key is not transferred to PROF.MIR and remains in the owner’s signature tool or with an approved provider.
6. Retention and security
Data is retained only as long as required for the purpose, contract, mandatory records, security and dispute resolution, then deleted or anonymised unless the law requires continued retention.
Controls include access restriction, encrypted transport, MFA, audit logs, backups, integrity checks, malware scanning and incident response. No security measure eliminates every risk.
7. International transfers
An international transfer occurs only after applicable legal requirements, safeguards and any notification or authorisation have been checked. Selecting a foreign counterparty does not permit unnecessary data disclosure.
8. Individual rights
A user may request information, correction, restriction or deletion, withdraw consent and lodge a complaint. Withdrawal does not stop processing supported by another lawful basis, including retention of transaction evidence.
Requests are sent to the operator email. Identity and authority may be verified before personal data is disclosed or changed.
9. Cookies and updates
Essential cookies support sessions, security and preferences. Optional analytics or advertising requires an appropriate legal basis and consent controls.
Each revision has a separate version and date. A function remains unavailable until renewed consent where an update legally requires it.
