Skip to main content

Privacy Policy

Revision of: 13 August 2026

1. General Provisions

1.1. This Policy defines how personal data is processed by Individual Entrepreneur Lev Aleksandrovich Aminov, taxpayer identification number (ՀՎՀՀ/TIN): 71062923, Republic of Armenia (hereinafter — the "Operator", "we").

1.2. The Policy is drawn up in accordance with the Law of the Republic of Armenia "On Protection of Personal Data" (ՀՕ-49-Ն of 18 May 2015). For individuals located in the European Economic Area, the provisions of the General Data Protection Regulation of the European Union (GDPR, Regulation (EU) 2016/679) additionally apply. In GDPR terms, the Operator acts as a data controller to the extent set out in Section 3.

1.3. The Policy covers the processing of data of:

1.4. Use of the website, the personal account and the platform services means that you have reviewed this Policy. The terms of use of the services are defined by the Terms of Service.

1.5. The current revision of the Policy is published at /policy/.

2. Definitions

2.1. Personal data — any information relating directly or indirectly to an identified or identifiable individual.

2.2. Processing — any operation with personal data: collection, recording, storage, use, transfer, deletion and other operations.

2.3. User — a visitor to the website or a user of the personal account, the API or the client software.

2.4. Customer — a person who has concluded the Terms of Service and uses the services of the Tuna platform.

2.5. Customer Data — data that the Customer and its users transmit, place or route through the platform services.

3. Allocation of Roles

3.1. With respect to account data, payment data, technical logs, support requests and website visitor data, the Operator acts as an independent operator (controller). The procedure for such processing is described in this Policy.

3.2. With respect to personal data contained in Customer Data, the Customer itself acts as the operator (controller): it determines the purposes and means of processing, while the Operator acts as a processor on its instructions. The terms of such processing are set out in the Customer Data Processing Terms.

3.3. Traffic transmitted through tunnels and gateways is handled in transit. The Operator does not analyse its contents, except for technically necessary processing for routing, for applying traffic policies configured by the Customer, for security purposes and for handling abuse reports.

3.4. The password manager is built on a zero-knowledge model: decryption keys are generated on the user's side and are not transmitted to the Operator. The Operator has no technical access to the contents of the password vault.

3.5. Certain services by their nature involve storing data contents on the Operator's infrastructure (webhooks, reports, secrets, meeting and board materials). The composition of such data is determined by the Customer; the restrictions are set out in Sections 13 and 14 of the Terms of Service.

4. Categories of Data Processed

4.1. Website and documentation visitors

  • IP address, browser and operating system type and version, language, screen resolution;
  • referral source, pages visited, time and duration of the visit;
  • search queries in the documentation;
  • cookie identifiers.

4.2. Personal account users

  • email address;
  • name, if provided by the User;
  • password hash or the account identifier at the OpenID/SSO provider, if sign-in is performed through one;
  • WebAuthn credential data (public key and credential identifier), if the User has enabled this sign-in method;
  • data on purchased subscriptions, plans and additional licenses;
  • payment details: amount, currency, date, status, transaction identifier, masked payment method details (card type and last four digits), token of the saved payment method;
  • details required to issue invoices and closing documents, if payment is made by invoice;
  • IP address, date and time of sign-in, activity logs in the personal account and organization audit events.

Full bank card numbers, CVV codes and other complete payment details are not transmitted to or stored by the Operator — they are processed by payment providers (clause 7.1).

4.3. Users of the client software and the API

When the client software connects and when requests are made to the API, the following data is processed:

  • account identifier and access token used;
  • connection IP address;
  • client software version, operating system type and version, architecture;
  • parameters of created resources: tunnel addresses and names, connection region, session start and end times, volume of transmitted traffic.

Some of this data, primarily IP addresses, constitutes personal data, and this Policy therefore applies to it. In addresses of tunnels with dynamically assigned names, the source IP address is used as part of the domain name — this is an anti-fraud measure described in the Abuse section; it can be hidden in the organization settings.

4.4. Technical support requests and abuse reports

  • email address and the contents of the correspondence;
  • username and message contents when contacting the Telegram chat;
  • information voluntarily provided for diagnostics: client software logs, configurations, screenshots;
  • information contained in an abuse report, including the reporter's data.

Users should remove from the materials they send any information not related to the issue being resolved.

DataPurposeLegal basis
Personal account recordRegistration, provision of access to the services, subscription managementPerformance of the contract
Payment dataAccepting payment, subscription renewal, refundsPerformance of the contract
Details and payment documentsAccounting and tax recordsCompliance with legal requirements
Technical connection data (clause 4.3)Provision of the services, billing and limit enforcement, diagnosticsPerformance of the contract
Access logs and security eventsProtection against unauthorized access, countering abuse, handling reportsLegitimate interest of the Operator and third parties
Depersonalized and aggregated derivatives of technical logsStatistics, capacity planning, improvement and development of the services, training machine learning models for these purposes (clause 13.8 of the Terms of Service)Processing of depersonalized data; no personal data is used for these purposes
Support requestsProvision of technical supportPerformance of the contract; legitimate interest
Web analytics data and cookiesTraffic analysis, website improvementUser consent
Email address for mailingsInformation about products, updates and offersUser consent
Service notifications (upcoming charges, changes to terms, incidents)Performance of contractual obligationsPerformance of the contract

5.1. Service notifications are sent regardless of consent to marketing mailings, as they are necessary for the performance of the contract. It is not possible to opt out of them while continuing to use the services.

5.2. The Operator does not process special categories of personal data for its own purposes and does not take decisions based solely on automated processing that produce legal effects for the User. Automatic restrictions applied when limits are exceeded or abuse is detected may be appealed in accordance with clause 12.8 of the Terms of Service.

6. Cookies and Web Analytics

6.1. The website uses the following categories of cookies:

  • Essential — enable the website and the personal account to work: session, authentication, selected language and theme, storing the cookie choice. They are set without consent, since the service does not work without them.
  • Analytics — used by the Yandex.Metrica service to collect anonymized traffic statistics. They are set only after the User's consent has been obtained.

6.2. In the documentation, the User is asked on the first visit to accept or decline analytics cookies. Web analytics scripts are not loaded until consent is given. You can change or withdraw your decision at any time here:

No choice has been made yet.

6.3. The Yandex.Metrica service is provided by Yandex LLC and involves the transfer of data to servers located in the Russian Federation. The terms of data processing by the service are available in the Yandex privacy policy. The same counter is shared by the website, the documentation and the personal account, which allows the Operator to see the User's path between them.

6.4. In the documentation, the session recording feature ("Webvisor") is not used.

On the website and in the personal account such recording is used — it is needed to diagnose interface problems and to investigate support requests. Input fields and data classified as sensitive are masked and do not appear in the recording. If you object to your actions being recorded, write to info@tuna.am and we will exclude you from the collection.

6.5. The website embeds the script of the Operator's own Reports service. It collects technical session details, on-page actions and a screenshot, and transmits them to the Operator when an error report is created. Sensitive fields are masked as described in the service documentation. The data is processed by the Operator and is not transferred to third parties.

6.6. Documentation search is powered by the Algolia DocSearch service: search queries and technical request parameters are transmitted to the service to perform the search. Certain website resources (fonts, styles, terminal recording player scripts) are loaded from the public jsDelivr content delivery network, which learns the User's IP address when they are loaded.

6.7. Declining analytics cookies does not restrict access to the website, the documentation or the personal account.

7. Transfer of Data to Third Parties

7.1. To provide the services, the Operator engages the following categories of data recipients:

Category of recipientData transferredPurpose
PayPro Global (PayPro Global Inc. and its affiliates; Canada, USA, European Union)Name, email address, payment details, payer's country, amount and payment parametersAccepting payment in US dollars, issuing invoices, calculating and remitting taxes, processing refunds and automatic renewals. Acts as an authorized reseller (merchant of record) and is an independent controller of the data it collects
YuMoney NBCO LLC (YooKassa service, Russian Federation)Email address, payment details, amount and payment parametersAccepting bank card payments in roubles
Payment collection agent (clause 10.3 of the Terms of Service, Russian Federation)Payer's name and details, email address, amount and payment parametersIssuing invoices and accepting payments from legal entities and individual entrepreneurs in the Russian Federation
Hosting and network infrastructure providers (Russian Federation, Germany, the Netherlands and other countries listed in the Regions section)Data placed on the Operator's serversHosting and operation of the platform, tunnel and monitoring nodes, personal account and databases
Functional Software, Inc. (Sentry service, USA)Technical error details, IP address, user identifier, request contextDetecting and fixing malfunctions
Email delivery providerEmail address, name, message contents and delivery statusSending service notifications and mailings
Yandex LLC (Yandex.Metrica, Russian Federation)Data specified in clause 4.1Website traffic analysis, only after consent
Algolia (DocSearch service)Search query, IP address, technical request parametersDocumentation search
Telegram messengerData voluntarily sent by the User to the support chatProvision of technical support

7.2. All engaged recipients process data solely to the extent necessary for the stated purposes and are bound by confidentiality obligations.

7.3. The Operator does not sell personal data, does not transfer it for third-party advertising purposes and does not disclose it to anyone other than the recipients listed in this Section.

7.4. When handling an abuse report, the Operator may disclose to the affected party, an Internet service provider or another competent person the minimum necessary technical information (in particular, the IP address and session times) without disclosing the Customer's personal data, except in cases provided for by law.

7.5. Data is disclosed to authorities only on the basis of their official request made in accordance with the law, and only to the extent necessary to comply with legal requirements.

7.6. In the event of reorganization of the Operator's business or transfer of rights to the Tuna platform, data may be transferred to the successor while preserving the terms of this Policy; Users are notified of this in advance.

8. Storage Location and Cross-Border Transfer

8.1. Data is hosted on the servers of the Operator and of the infrastructure providers it engages, in the Russian Federation, Germany and the Netherlands. The list of countries changes as new regions are introduced; the current list of regions available for tunnels and monitoring checks is published in the Regions section. The User selects the region itself.

8.2. The use of the services listed in Section 7 entails the transfer of certain categories of data outside the Republic of Armenia, including:

  • to the Russian Federation — the infrastructure of the regions located in that country, the YooKassa service for rouble card payments, the payment collection agent for invoice payments, and the Yandex.Metrica web analytics service;
  • to Germany and the Netherlands — the infrastructure of the regions located in those countries;
  • to the United States, Canada and the European Union — PayPro Global for payments in US dollars;
  • to the United States — the Sentry error monitoring service and the Algolia documentation search service.

8.3. The legal bases for such transfers are:

  • the User's consent — for web analytics data;
  • the necessity of performing a contract to which the User is a party — for payment data and data hosted on the servers of infrastructure providers.

8.4. For data subjects located in the European Economic Area, transfers to countries not recognized by the European Commission as providing an adequate level of protection are carried out on the basis of standard contractual clauses or the data subject's explicit consent.

9. Retention Periods

DataRetention period
Personal account recordFor the entire existence of the account; after its deletion — up to 30 days in backups
Customer Data placed in the servicesFor the term of the contract; after its termination — up to 30 calendar days (Section 8 of the Customer Data Processing Terms)
Payment data and closing documentsFor the period established by the accounting and tax legislation of the Republic of Armenia
Technical connection logs and security events90 days
Depersonalized and aggregated derivatives of technical logsIndefinitely; not personal data
Organization audit events displayed in the personal accountFor as long as the organization exists
Technical support requests3 years from the date of the last message
Abuse report materials3 years from the date of review
Web analytics dataIn accordance with the Yandex.Metrica service policy
Email address in the mailing listUntil consent is withdrawn

9.1. Upon expiry of the retention period, data is deleted or anonymized. If data is needed to protect the Operator's rights in a declared or potential dispute, it is retained until the expiry of the corresponding limitation period.

10. User Rights

10.1. The User has the right to:

  • obtain confirmation that their data is being processed and a copy of the data processed;
  • request clarification or correction of inaccurate or incomplete data;
  • request deletion of data if there are no lawful grounds for its further processing;
  • request restriction of processing;
  • object to processing carried out on the basis of legitimate interest, as well as to receiving marketing messages;
  • receive their data in a structured, machine-readable format and request its transfer to another operator (right to data portability);
  • withdraw previously given consent — withdrawal does not affect the lawfulness of processing carried out before it was received;
  • lodge a complaint against the Operator's actions with a supervisory authority or a court.

10.2. To exercise any of these rights, it is sufficient to send a message to info@tuna.am from the email address specified in the personal account. No special subject line is required. The Operator responds within no more than 30 calendar days and may request additional information to verify the applicant's identity.

10.3. If a request concerns data processed by the Operator on a Customer's instructions (clause 3.2), the Operator forwards it to the relevant Customer, who acts as the operator of such data.

10.4. You can also unsubscribe from marketing mailings using the unsubscribe link in any email.

10.5. Deletion of an account terminates access to the services and results in the deletion of the data placed in them within the periods specified in Section 9. Data that must be retained under legal requirements is kept for the established periods.

10.6. The supervisory authority is the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia. Users located in the European Economic Area may also contact the supervisory authority at their place of residence.

11. Security

11.1. The Operator implements organizational and technical data protection measures, including traffic encryption (TLS), storage of passwords solely as irreversible hashes, encryption of sensitive data at rest, the zero-knowledge model in the password manager, access segregation, access logging and backups.

11.2. Absolute security of data transmission and storage on the Internet cannot be guaranteed. The User must maintain the confidentiality of their password, password manager master key and access tokens. The allocation of responsibility in respect of sensitive data is set out in Section 14 of the Terms of Service.

11.3. Upon detecting a security breach that creates a high risk to the rights and freedoms of data subjects, the Operator notifies the affected Users and the competent authority within the periods established by applicable law.

12. Minors

12.1. The website, the personal account and the Tuna platform services are not intended for persons under 16 years of age. The Operator does not deliberately collect the data of such persons. If the registration of a person under 16 is discovered, the corresponding data is subject to deletion.

13. Changes to the Policy

13.1. The Operator may amend this Policy. The current revision, with the date indicated, is published at /policy/.

13.2. Registered Users are notified of material changes affecting the purposes of processing or the composition of data transferred to third parties by email or through the personal account at least 7 calendar days before the changes take effect.

14. Contacts

For any questions related to the processing of personal data, and to exercise the rights provided for in Section 10:

Individual Entrepreneur Lev Aleksandrovich Aminov
Address: 3901, Republic of Armenia, Tavush Province, Dilijan
Taxpayer identification number (ՀՎՀՀ/TIN): 71062923
Email: info@tuna.am