1-LVL · Legal
Privacy Policy
This Policy explains what 1-LVL processes, why it does so, where primary databases are located, and how users may exercise their rights.
1. Controller and scope
The personal data controller is Sannikov Denis, a natural person. Privacy contact: info@1-lvl.ru.
This Policy applies to the 1-LVL public website, accounts, 1-LVL Operator, plugins, modules, APIs, support, and related services when they refer to this Policy.
2. Data categories
- account information: name, email, password hash, roles, and permissions;
- license, plan, access, and application information;
- technical logs, IP address, browser and device information, sessions, and security events;
- API and support data, messages, and attachments knowingly submitted by the user;
- project or job parameters if the user explicitly sends them to the server;
- payment and billing information once paid services exist; a payment provider may process card details instead of 1-LVL;
- separate records of marketing consent and industry analytics consent.
3. Purposes and legal bases
- creating and servicing accounts, authentication, and security;
- providing licenses, services, support, and performing contracts;
- diagnosing errors, preventing abuse, and protecting infrastructure;
- complying with law and protecting legal rights;
- marketing communications only with separate consent or another applicable basis;
- industry analytics on a basis applicable to the particular data and use, including separate consent where required.
4. Russia and primary database location
The primary 1-LVL personal data databases are located in the Russian Federation.
When personal data of Russian citizens are collected, recording, systematization, accumulation, storage, updating, and retrieval use databases located in the Russian Federation to the extent required by applicable law.
This does not claim that every technical datum can never leave Russia under any circumstances. Any lawful cross-border transfer, if needed, requires an applicable basis, safeguards, and notices.
5. Service and marketing communications
Service communications are required for operation and security: email verification, password reset, security, license, and mandatory contractual notices. Opting out of advertising does not disable service communications.
Marketing communications contain news, updates, and offers. Consent is separate and voluntary and may be withdrawn at any time without ending the core service.
6. Anonymous and Aggregated Analytics Data
1-LVL may produce Anonymous and Aggregated Analytics Data from technical metrics under the separate Analytics Terms. These results may support statistics, research, benchmarks, reports, dashboards, APIs, datasets, and product improvement, and may be provided to third parties for free or for a fee.
Anonymization must prevent reasonable identification of a natural person, account, specific company, customer, project, or source file. Replacing a user_id with a random identifier is not enough. Pseudonymized data that can be linked back to a user remains personal data where applicable law so requires.
7. Source projects
Without a separate legal basis or consent, analytics partners do not receive source SketchUp, Tekla, CAD, or BIM files, full drawings, project names, customer details, emails, names, account IDs, IP addresses, payment data, or user source documents.
Individual technical features may be extracted from projects for later anonymous or aggregated statistics only where an applicable legal basis exists.
9. User rights and security
Depending on applicable law, a user may request information, access, correction, deletion, restriction, portability, objection, or withdrawal of consent, and may complain to a supervisory authority or court. Withdrawal does not affect processing lawfully performed beforehand.
1-LVL applies proportionate technical and organizational safeguards. No transmission or storage method is absolutely secure; material incidents are reported where and when law requires.
10. Requests and changes
Send requests to info@1-lvl.ru. Reasonable identity verification may be required to protect data. A revised Policy will be posted here with an updated effective date.