Legal

Privacy Policy

Effective Date: July 12, 2026

1. General Provisions

This Privacy Policy describes how Individual Entrepreneur Alexey Sharapov processes and protects personal data in connection with the use of the agentbouncer.io website, the AgentBouncer service, its API, SDK, dashboard, and related features.

This Policy has been prepared in accordance with the Constitution of the Russian Federation, Federal Law No. 152-FZ of July 27, 2006, “On Personal Data,” and other applicable laws and regulations.

This Policy applies to personal data relating to website visitors, registered users, clients and their representatives, individuals who contact support, and personal data that clients may transmit when using the AgentBouncer API and analytics features.

Use of the Service does not constitute blanket or automatic consent to all forms of personal data processing. Where consent is required for a particular processing activity, it will be requested separately from acceptance of the User Agreement or other documents.

2. Personal Data Operator

The personal data operator is Individual Entrepreneur Alexey Sharapov, Primary State Registration Number of Individual Entrepreneur (OGRNIP) 325774600322644, Taxpayer Identification Number (INN) 773001860255.

For questions or requests relating to the processing of personal data, please contact us at hello@agentbouncer.io.

3. Categories of Data Subjects

Visitors to the agentbouncer.io website and users of publicly available documentation.

Registered users, clients, individual entrepreneurs, and representatives and employees of organizations that use the Service.

Individuals who submit support requests, apply to participate in beta testing, request consultations, or otherwise communicate with us.

4. Categories of Personal Data We Process

Account and contact information: email address, name, organization name, user role, account identifier, and profile settings.

Project information: domains, project names, endpoints, integration settings, access policies, rules, and API key identifiers. Depending on the implementation, the secret value of an API key may be stored in a protected or hashed form.

Verification event data: date and time, IP address, URL or endpoint, HTTP method, user-agent, Signature, Signature-Input, Signature-Agent, keyid, information about the presumed agent or provider, the requested action or tool, verification outcome, matched rule, and risk level.

Technical information: IP address, cookies, session identifiers, browser and device information, language settings, authentication logs, errors, performance metrics, and information security events.

Communications data: the content of inquiries and other communications, email addresses, attachments, and any other information voluntarily provided by the user.

We do not request special categories of personal data, biometric data, passwords for third-party services, or full payment card details. Users must not submit such information through the Service, its API, or its forms.

5. Purposes of Processing

To register and authenticate users, manage accounts, and provide access to the Service.

To verify signed requests, enforce access policies, generate technical decisions, and provide analytics.

To maintain information security, detect abuse, mitigate malicious traffic, and investigate security incidents.

To process inquiries, provide technical support, and communicate with users.

To analyze, maintain, and improve the Service, troubleshoot errors, and develop new features.

To comply with contractual and legal obligations, protect our rights and legitimate interests, and resolve disputes.

6. Legal Bases for Processing

We may process personal data where processing is necessary to enter into or perform the User Agreement or another contract to which the data subject is a party or beneficiary.

We may process personal data on the basis of the data subject's consent where consent is required under applicable law.

Certain personal data may be processed where necessary to comply with obligations imposed on the operator by the laws of the Russian Federation.

Personal data may also be processed on other legal grounds expressly provided for by Article 6 of Federal Law No. 152-FZ and other applicable laws and regulations.

7. How We Process Personal Data

Personal data may be processed using automated means and, in certain cases, without the use of automated means.

Processing activities may include the collection, recording, organization, accumulation, storage, updating, retrieval, use, transfer to authorized processors, anonymization, restriction, deletion, and destruction of personal data.

Access to personal data is limited to individuals and information systems that require such access for legitimate operational purposes.

We do not make personal data publicly available or provide unrestricted access to personal data without a lawful basis.

8. Data Transmitted by Clients Through the API

Clients must transmit through the API only the data that is necessary to verify requests and apply configured policies.

Each Client is responsible for determining the appropriate legal basis for processing personal data relating to its users, visitors, employees, and counterparties and for ensuring that any transfer of such data to AgentBouncer is lawful.

Clients must not transmit request content, authorization tokens, payment information, passwords, special categories of personal data, or other sensitive information unless such transmission is necessary and has been separately agreed upon.

Where we process personal data on behalf of a Client, the specific terms and instructions governing such processing may be set out in a separate data processing agreement or other written arrangement.

9. Sharing Personal Data with Third Parties

We may share personal data with service providers that support the operation of the Service, including providers of infrastructure, hosting, databases, monitoring, analytics, authentication, communications, payment processing, and accounting services, to the extent necessary for them to provide the relevant services.

The Service may use third-party artificial intelligence models or API providers for website analysis, recommendation generation, or file preparation. Where such services are used, data may be transmitted to those providers only to the extent necessary to perform the relevant function.

Where a Client requests additional consulting services or integrations, personal data may be processed by contractors or specialists engaged to perform the relevant work, subject to appropriate confidentiality obligations.

We may disclose personal data where required by a lawful request from a court, government authority, regulatory body, or other competent authority, or where disclosure is otherwise required by applicable law.

10. Localization of Personal Data of Russian Federation Citizens

When collecting personal data of citizens of the Russian Federation through the Internet, we ensure that the recording, systematization, accumulation, storage, updating, and retrieval of such personal data are carried out using databases located within the territory of the Russian Federation, except where otherwise permitted by law.

The architecture of the Service and the service providers we use are selected with due regard to the requirements of Russian personal data localization laws.

Any subsequent transfer of personal data to recipients located outside the Russian Federation is carried out only where there is an appropriate legal basis and the applicable requirements governing cross-border transfers have been satisfied.

11. Cross-Border Transfers of Personal Data

Where the operation of the Service requires personal data to be transferred to a recipient located outside the Russian Federation, we complete the procedures required by Russian law before initiating such transfer.

Before carrying out a cross-border transfer, we assess the categories of personal data involved, the purpose of the transfer, the foreign recipient, and the safeguards and data protection measures implemented by that recipient.

Cross-border transfers are carried out only where an appropriate legal basis exists and, where required by law, after the necessary notification has been submitted to the competent authority.

12. Data Retention

Account data is retained for as long as the account remains active and for up to 30 days after the account is deleted, unless a longer retention period is required by law, necessary for security purposes, or reasonably required to establish, exercise, or defend legal claims.

API events, verification logs, and technical analytics are retained for the period specified in the interface for the applicable plan or project. During the free beta period, the standard retention period is determined by the operator based on technical necessity and the principle of data minimization.

Security logs may be retained for as long as reasonably necessary to detect abuse, investigate incidents, prevent fraud or misuse, and protect the Service.

Communications and legally significant records may be retained for applicable limitation periods and for any mandatory retention periods required by law.

13. Termination of Processing and Data Destruction

When the purpose of processing has been fulfilled, the applicable legal basis no longer exists, or we receive a valid request requiring us to cease processing, we will stop processing the relevant personal data and delete, destroy, or anonymize it within the time limits required by applicable law.

Where personal data is processed solely on the basis of consent, withdrawal of that consent will result in the deletion or destruction of the relevant data within no more than 30 days, unless we are entitled or required to continue processing it on another legal basis.

Personal data is destroyed by deleting it from information systems and, subject to applicable backup retention cycles, from backup copies, or by using another method that prevents the data from being restored using means reasonably available to the operator.

14. Data Security

We implement reasonable and appropriate technical and organizational measures designed to protect personal data, including access controls, privilege restrictions, monitoring, secure communications, and other security safeguards.

We seek to minimize the amount of personal data we process and restrict access to personal data to individuals and systems that require such access for legitimate purposes.

No method of transmitting or storing data over the Internet can be guaranteed to be completely secure. Users and Clients are also responsible for maintaining the security of their accounts, websites, hosting environments, content management systems, DNS configurations, and integrations.

15. Cookies and Similar Technologies

We may use cookies, localStorage, and similar technologies for authentication, session management, security, remembering user preferences, analyzing the operation of the interface, and diagnosing errors.

Some cookies and similar technologies are strictly necessary for the operation of the Service. Others may be used for analytics or product improvement where permitted by applicable law.

If a Client integrates scripts, widgets, or analytics provided by agentbouncer.io into its own website, the Client is responsible for providing any required cookie notices and obtaining any necessary consent from its visitors where required by applicable law.

16. Rights of Data Subjects

Data subjects have the right to obtain information about the processing of their personal data and to request that their personal data be corrected, restricted, blocked, or deleted where the data is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary for the stated purpose of processing.

Where processing is based on consent, the data subject has the right to withdraw that consent.

Requests may be submitted to hello@agentbouncer.io or sent to the operator's address. A request must contain sufficient information to verify the identity of the applicant and, where applicable, the applicant's relationship with the operator.

We will respond within the time limits established by applicable law. Where necessary, we may request additional information to verify the applicant's identity or authority to act on behalf of another person.

Data subjects may challenge the operator's actions or omissions by submitting a complaint to Roskomnadzor or by seeking judicial remedies in accordance with applicable law.

17. Children's Privacy

The Service is primarily intended for website owners, businesses, entrepreneurs, and professionals working in marketing, SEO, software development, and AI optimization. It is not specifically directed to children.

We do not knowingly seek to collect personal data from children. If you believe that a child's personal data has been provided to us unlawfully, please contact us at hello@agentbouncer.io.

18. Automated Processing

The Service may use automated algorithms and artificial intelligence models to analyze websites, classify files, identify errors, generate recommendations, and prepare technical files.

Such processing is not intended to produce decisions that have legal or similarly significant effects on Users or visitors to a Client's website.

Outputs generated through automated processing may be incomplete or inaccurate and should be reviewed by the User before being relied upon or used.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our data processing practices, or applicable legal requirements.

The current version of this Privacy Policy will be published on agentbouncer.io. The effective date of the current version is stated at the beginning of this document.

Where changes are material, we will take reasonable steps to notify users where required by applicable law or appropriate in light of the nature of the changes.

20. Contact Information

If you have any questions, requests, or concerns regarding privacy or the processing of personal data, please contact us at hello@agentbouncer.io.