Privacy and Personal Data Processing Policy of the “Mary” Service
Last updated: August 28, 2026
This is an English translation provided for convenience. In case of any discrepancy, the Russian version prevails.
1. General Provisions
1.1. This privacy policy (the “Policy”) governs the processing and protection of personal data that Maryrose LLC (ООО «Мэрироуз») (“we”, the “Operator”) receives when you use the “Mary” Service and in the course of any other interaction you have with us.
1.2. Personal data is processed by Maryrose LLC, Republic of Belarus, UNP (taxpayer ID) 193889413.
1.3. This Policy has been prepared in accordance with Law of the Republic of Belarus No. 99-Z of May 7, 2021 “On Personal Data Protection” and other legislative acts of the Republic of Belarus. With respect to users from other countries, we additionally take into account the requirements of the personal data legislation applicable to them.
1.4. This Policy sets out: what personal data we process; the purposes, legal grounds and procedure for processing it; retention periods; protective measures; and your rights and how to exercise them.
1.5. This Policy applies to all persons whose personal data we process: users of the Service, our employees and contractors, and any other persons who interact with us.
1.6. We do not verify the accuracy of the personal data you provide. You are responsible for its accuracy.
1.7. We proceed on the basis that you provide personal data voluntarily, of your own free will and in your own interest, and that you knowingly configure the settings of the software and devices you use.
2. Definitions
2.1. Personal data means any information relating to an identified or identifiable natural person, whether directly or indirectly.
2.2. Processing of personal data means any action or set of actions performed with personal data, including collection, systematization, storage, modification, use, depersonalization, blocking, dissemination, provision and deletion.
2.3. Service means the “Mary” platform designed to automate business processes: building and launching processes and AI agents, connecting external services, receiving and handling requests, and maintaining customer data, including the Service website maryrose.by.
2.4. User means a natural person or legal entity that obtains access to the Service.
2.5. User’s Customer Data means personal data of third parties (customers, employees and counterparties of the User) received by the Service from the User or through external services connected by the User.
2.6. Agent means a software module of the Service based on artificial intelligence technologies that performs actions within a process configured by the User.
2.7. Account means the User’s personal account in the Service.
3. Two Roles: Your Data and Your Customers’ Data
3.1. The Service works with two fundamentally different categories of personal data, and our role differs with respect to each of them.
3.2. Your data as a User means your account data, payment data, support requests and information about your use of the Service. With respect to this data we act as the operator: we determine the purposes of processing and are responsible for it. Its processing is described in Sections 4–6 of this Policy.
3.3. Your customers’ data means correspondence, requests, bookings and other information that enters the Service through integrations you connect or that you upload. With respect to this data, you determine the purposes and content of processing, and we process it solely on your instructions and to the extent necessary for the Service to operate. Its processing is described in Section 7 of this Policy.
3.4. We do not use your customers’ data for our own purposes: we do not build profiles based on it, do not transfer it to third parties other than for the operation of the Service, and do not offer advertising based on it.
4. What Data About You We Process
4.1. You provide us with personal data when you register an account, use the Service, make payments, subscribe to mailings, fill in feedback forms and whenever you contact us.
4.2. We process the following personal data about you:
- email address;
- first and last name, if you provide them;
- phone number, if you provide it;
- if you register via external authentication (for example, Google): the email address, name and profile picture link from the relevant service;
- information about your organization and your role in the workspace;
- cookies and similar technologies (see Section 12);
- automatically collected usage data: IP address, device type and identifiers, referral source, operating system, approximate geographic location, browser type and version, language settings, pages visited, navigation paths, and the date, time and duration of visits;
- information about connected integrations: the name of the external service, the identifier of the connected account, and the date and status of the connection (we do not receive or store the passwords to external services themselves);
- the content of your support requests;
- payment information: plan, amounts, dates and statuses of payments.
4.3. We do not receive or store the full details of your payment cards. Payments are handled by a payment provider that processes card details on its side; we receive only the result of the payment and masked information about it.
4.4. Website request form. When you submit the form, we process: your name; a contact of your choice — phone number, email address or Telegram username; your company name, if provided; the areas of work you selected; the description of your task; and the date and time of submission. The form collects no other information: it contains no hidden fields that insert your data.
4.5. We do not process biometric personal data.
4.6. We do not knowingly process personal data of minors. If we become aware that we have received such data without the consent of their legal representatives, it will be deleted as soon as possible.
5. Purposes of Processing Your Personal Data
| Purpose of processing | Category of data subjects | List of personal data |
|---|---|---|
| 1. Identification and operation of your account (conclusion and performance of the agreement on the use of the Service) | User registering an account | Email address; name; when signing in via external authentication — email, name and profile picture link; cookies; usage data |
| 2. Provision of the Service’s functionality: operation of processes, agents and integrations | Any user of the Service | Account data; workspace and role information; information about connected integrations; usage data |
| 3. Accepting payments and fulfilling tax obligations | User paying for a subscription | Name; email address; organization details; plan, amounts, dates and statuses of payments |
| 4. Technical support and handling of requests | User who has contacted us | Email address; name; content of the request; technical information needed to investigate the issue |
| 5. Ensuring the security of the Service, preventing abuse and investigating incidents | Any user of the Service | IP address; device and session identifiers; sign-in and activity logs in the Service |
| 6. Improvement and development of the Service, usage analytics | Any user of the Service | Depersonalized and aggregated usage data; cookies |
| 7. Informational and promotional mailings — subject to your consent | User who has consented to mailings | Email address; name; information about interaction with mailings |
| 8. Handling a website request: contacting you and discussing your task (steps taken at your request prior to entering into an agreement) | Person who submitted the request form | Name; contact — phone, email address or Telegram username; company name; selected areas of work; task description; date and time of submission |
| 9. Web analytics: understanding how visitors use the website and improving it — only with consent to non-essential cookies | Website visitor who has given consent | Cookies and session identifiers; usage data (see clause 4.2); session recordings of on-page actions — cursor movements, clicks, scrolling, filling in form fields without their content; events of opening and submitting the request form |
5.2. Processing is carried out by automated, non-automated and mixed means, with or without the transmission of information over information and telecommunication networks.
6. Legal Grounds for Processing
6.1. We process your personal data:
- on the basis of your consent;
- to conclude and perform the agreement on the use of the Service to which you are a party;
- to fulfil obligations imposed on us by law.
6.2. You give your consent when registering an account by ticking the box next to the link to this Policy.
6.3. You may withdraw your consent at any time in the manner set out in Section 11. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal and may make further use of the Service impossible.
6.4. If you do not agree with the terms of this Policy, you should stop using the Service.
7. Your Customers’ Data: Processing on Your Instructions
7.1. By uploading data to the Service and connecting external services, you instruct us to process the personal data of your customers, employees and counterparties to the extent necessary for the operation of the processes you have configured.
7.2. We process such data only on your instructions and do not independently determine the purposes of its processing.
7.3. You are responsible for having legal grounds for transferring your customers’ data to us and for its automated processing, including obtaining the necessary consents and notifying data subjects in the manner prescribed by the legislation applicable to you.
7.4. You independently determine what data enters the Service, which agents and processes work with it and what actions they are permitted to perform.
7.5. We ensure the confidentiality of your customers’ data, restrict access to it and apply the protective measures described in Section 10.
7.6. At your request, we provide information about the composition of the data processed on your instructions and delete it in accordance with Section 9.
8. Artificial Intelligence and Transfer of Data to Models
8.1. The Service is based on artificial intelligence technologies, including models provided by third parties. To perform your tasks, the content of requests, documents and other materials may be transferred to the providers of such models to the extent necessary to obtain the result.
8.2. The list of model providers used in the Service is given in clause 13.3 of this Policy. Such transfer may be cross-border — see Section 9.
8.3. We take reasonable measures to ensure that model providers are bound by confidentiality obligations and do not use the data transferred to them to train their models. The terms of individual providers may vary.
8.4. We do not use the content of your data or your customers’ data to train our own models without your separate consent.
8.5. We recommend that you do not upload to the Service any information whose transfer to third parties is unacceptable to you, including legally protected secrets that you have no legal grounds to disclose.
9. Where and How Long Data Is Stored. Cross-Border Transfer
9.1. Personal data is stored on the servers of the hosting provider hoster.by (Nadezhnye Programmy LLC, Minsk, Republic of Belarus). Backups are stored there as well. Certain categories of data are processed by the services listed in clause 13.3 on their own infrastructure.
9.2. Your account data is stored for as long as the account exists and is deleted within the periods specified in clause 9.7. If the purpose of processing is achieved earlier, processing ceases once it has been achieved.
9.3. Your customers’ data is stored for as long as necessary for the operation of the processes you have configured and is deleted on your instructions or upon termination of access to the Service.
9.4. Cross-border transfer. Since the Service is available to users from different countries and part of the processing is performed by providers located outside the Republic of Belarus, processing may involve cross-border data transfer. A User who is subject to the requirements of the legislation of their country on the localization of personal data databases or on a special procedure for cross-border transfer independently assesses whether use of the Service is permissible and, if necessary, requests information from us on the location of the infrastructure before uploading any data.
9.5. Website request data. A request is saved in a Google Sheets spreadsheet (Google LLC, USA) and duplicated as a message in an internal Telegram chat (Telegram FZ-LLC, UAE). Only our employees responsible for handling requests have access to the spreadsheet and the chat. Requests are stored for no longer than 3 years from the date of the request or until you request their deletion; if an agreement is concluded as a result of the request, for the period established by law for the relevant documents.
9.6. Upon expiry of the retention periods, personal data is deleted from our servers.
9.7. We cease processing personal data if: the purpose of processing has been achieved; unlawful processing has been identified — within 3 business days of its identification; the consent has expired or been withdrawn and storage of the data is no longer required.
10. Protection of Personal Data
10.1. We apply legal, organizational and technical protective measures: access rights management, encryption of data transmission channels, activity logging, regular updating of components and oversight of contractors.
10.2. Only employees whose job duties include the processing of personal data are permitted to process it, and only to the extent necessary to perform a specific task.
10.3. In most cases, processing is performed automatically, without employees having access to the content of your data or your customers’ data. Access to the content is granted to an employee only when necessary — for example, when investigating your support request.
10.4. We do not guarantee absolute security of information transmitted over the Internet and recommend that you do not disclose your account access credentials.
11. Your Rights
11.1. You have the right to:
- receive information about the processing of your personal data;
- withdraw your consent to processing at any time by sending a notice to ceo@maryrose.by with the subject line “Withdrawal of consent to the processing of personal data”;
- demand that your personal data be amended if it is incomplete, outdated or inaccurate;
- demand the cessation of processing and deletion of personal data if it was obtained unlawfully or is not necessary for the stated purpose of processing;
- receive information about the provision of your personal data to third parties;
- appeal against our actions to the authorized body for the protection of the rights of personal data subjects of the Republic of Belarus or in court;
- exercise other rights provided for by law.
11.2. Please send requests concerning the processing of personal data to ceo@maryrose.by. We consider them within the period established by law — as a rule, within 15 calendar days of receipt of the request.
11.3. We notify you of the outcome of our consideration of the request at the email address from which the request was received.
11.4. If your request concerns data that we process on the instructions of another User (for example, you are a customer of a company that uses Mary), we will forward the request to that User, since it is that User who determines the purposes of processing such data.
12. Cookies
12.1. Cookies are small text files that are stored on your device when you use the Service.
12.2. We use cookies and similar technologies (including the browser’s local storage) of two categories:
- Essential — authorization and session handling, security, remembering your settings and your choice on this banner. They are set without consent, because the Service cannot work without them;
- Analytics — understanding how visitors use the website. They are set only after you click “Accept all”.
12.3. For web analytics we use Yandex.Metrica (Yandex LLC, Russian Federation). Metrica collects depersonalized information about visits: pages, referral source, device, browser, approximate location based on IP address, as well as session recordings of on-page actions — cursor movements, clicks, scrolling and the fact that form fields were filled in (the content of the fields is not saved in the recording). The terms of data processing by Metrica are set out in the document “Yandex.Metrica Terms of Use”; you can opt out of collection by not consenting to non-essential cookies or by installing a Metrica blocker.
12.4. We additionally use Google Analytics 4 (Google LLC, USA). It collects depersonalized information about visits: pages viewed, referral source, device and browser type, approximate location based on IP address, as well as events — opening the request form and submitting it (the content of the form fields is not transmitted). Google Analytics does not record on-page actions. Processing is governed by the “Google Analytics Terms of Service” and the “Google Analytics Data Processing Terms”; you can opt out of collection by not consenting to non-essential cookies or by installing Google’s official Analytics opt-out browser add-on.
12.5. You can change your choice by category at any time — in the cookie settings or via the “Cookie settings” button in the website footer.
12.6. Below is a list of exactly what is stored on your device. Entries in the “essential” group appear immediately; everything else appears only after you click “Accept all”. Third-party services may change their sets of entries: the list reflects the state as of the date of this version.
| Name | Set by | Category | Retention period | Purpose |
|---|---|---|---|---|
mary-cookie-consent |
us | essential | until the browser is cleared | Stores your choice on this banner. Without it, the banner would be shown on every page and a refusal could not be remembered. Technically this is not a cookie but an entry in the browser’s local storage: it is not sent to the server |
mary-lang |
us | essential | until the browser is cleared | The selected page language, Russian or English. Also local storage; not transmitted to the server |
_ym_uid |
Yandex.Metrica | analytics | 1 year | Depersonalized browser identifier. It is used to count how many distinct visitors there were, rather than just visits |
_ym_d |
Yandex.Metrica | analytics | 1 year | Date of the first visit — to distinguish new visitors from returning ones |
_ym_isad |
Yandex.Metrica | analytics | 2 days | Indicates whether an ad blocker is installed in the browser. Affects only the accuracy of counting |
_ym_visorc |
Yandex.Metrica | analytics | 30 minutes | Service entry for Webvisor — session recordings of on-page actions. The content of form fields is not included in the recording |
_ga |
Google Analytics | analytics | 2 years | Depersonalized browser identifier; same purpose as
_ym_uid |
_ga_4Q6GN6ZZW6 |
Google Analytics | analytics | 2 years | State of the current session for our counter: when the session started and how many sessions there have been |
12.6. Until consent is given, the page makes no requests to analytics services: the counter code is not loaded, and no entries from the “analytics” group appear on your device.
12.7. Withdrawal of consent. Withdrawing consent is as easy as giving it: the “Cookie settings” link in the bottom bar of the website erases your choice and brings the banner back, after which the counters stop loading. In addition, you may at any time delete stored cookies using your browser or change its settings.
13. Whom We Share Data With
13.1. We may transfer personal data to third parties or engage them to process it where this is necessary to provide the functionality of the Service or to achieve the other purposes set out in Section 5.
13.2. In such cases, we ensure that the recipients are bound by confidentiality obligations and comply with the requirements for the processing of personal data.
13.3. Categories of recipients and specific services:
- web analytics services — Yandex.Metrica, Yandex LLC (Russian Federation) and Google Analytics, Google LLC (USA);
- storage of website requests — Google Sheets and Google Apps Script, Google LLC (USA);
- internal notifications about requests — Telegram, Telegram FZ-LLC (UAE);
- website hosting and Service infrastructure — hoster.by, Nadezhnye Programmy LLC (Republic of Belarus);
- artificial intelligence model providers — OpenAI, OpenAI L.L.C. (USA) and Anthropic, Anthropic PBC (USA);
- corporate email — Mail.ru for Business, VK LLC (Russian Federation).
As of the date of the last update of this Policy, payments are not accepted through the website and bulk mailings are not carried out; therefore, payment services and mailing services do not receive personal data from us. If this changes, the list above will be supplemented before launch.
13.4. We also transfer personal data to external services that you have connected yourself, to the extent necessary for the operation of the processes you have configured. The processing of data on the side of such services is governed by their own policies.
13.5. We disclose personal data to government authorities and courts in the cases and to the extent provided for by law.
14. Rectification, Blocking and Deletion of Data
14.1. If inaccurate personal data is identified, we block it for the duration of the verification and rectify it within the period established by law, after which the block is lifted.
14.2. If unlawful processing is identified, we block the relevant data from the moment of identification and remedy the violation or delete the data.
14.3. If an unlawful or accidental transfer of personal data is identified that has resulted in a violation of the data subject’s rights, we notify the authorized body in the manner and within the time limits established by law and take measures to eliminate the consequences of the incident.
14.4. Personal data is deleted: when the purpose of processing has been achieved or the need to achieve it no longer exists; when the retention periods expire; when it is confirmed that the data was obtained unlawfully or is not necessary for the stated purpose; when consent is withdrawn, if storage of the data is no longer required.
15. Liability
15.1. If we breach the requirements of personal data legislation, we bear the liability provided for by law.
15.2. We are not liable for damage arising from: technical failures in equipment and networks beyond our control; use of the Service other than for its intended purpose; your failure to keep your account data confidential; unlawful actions of third parties to gain access to your account.
15.3. We are not liable for the processing of personal data of third parties that the User has provided as their own or uploaded to the Service without proper legal grounds.
16. Links to Other Websites
16.1. The Service may contain links to websites and services that are not operated by us. We do not control and are not responsible for the processing of your personal data by such websites and services, and we recommend that you review their policies separately.
17. Dispute Resolution
17.1. Before going to court, please send us a request at ceo@maryrose.by or to our registered address.
17.2. This Policy and relations concerning the processing of personal data are governed by the legislation of the Republic of Belarus, unless otherwise mandatorily established by the legislation of the country in which you are located.
18. Miscellaneous
18.1. We may amend this Policy. Amendments take effect upon publication of the updated version in the Service. The date of the current version is indicated at the beginning of this Policy.
18.2. If the amendments result in an additional restriction of your rights, we will notify you in the Service or through available communication channels.
18.3. Please send suggestions and comments on this Policy to ceo@maryrose.by.
19. Our Details
Maryrose Limited Liability Company Republic of Belarus UNP (taxpayer ID): 193889413 Registered address: 3 Chapaeva St, office 213, Minsk, Republic of Belarus Email: ceo@maryrose.by Phone: +375 29 189-85-01