Cartelta policy for business requests, demos, cookies, analytics, and communications about client-side security and PCI DSS.
This English page is provided for information only. The Russian version remains authoritative where that position applies to the company.
In this Policy, Cartelta means the Cartelta JSIR service and brand used to process business requests, organize demonstrations, and communicate about client-side security, PCI DSS, and payment page protection on https://cartelta.com and the Russian version at https://cartelta.com/ru.
Contractor details, legal requisites and applicable contractual terms are provided before placing an order, making a payment or entering into an agreement for the relevant service.
Personal data, operator, processing, data subject, disclosure, restriction, deletion, and related terms are used in the sense of applicable personal data laws and the Russian source document.
Cookies and similar technologies mean small data fragments or web storage keys that the site or a connected service may store in the user's browser.
Cartelta JSIR — Cartelta JSIR is a client-side security service for script inventory, integrity control and payment page change detection in the PCI DSS 4.0.1 context.
Contractor details, legal requisites and applicable contractual terms are provided before placing an order, making a payment or entering into an agreement for the relevant service.
Commercial terms, service scope, access procedure, party liability, and other material terms are documented in an agreement, order form, invoice, or another applicable document before services begin.
Email for personal data requests: support@cartelta.ru. Support email: support@cartelta.ru.
Person responsible for personal data processing: responsible Cartelta representative for request handling and communication. Primary data collection database location: infrastructure location and applicable providers are specified in contractual, technical, or compliance documents for the relevant service.
Cartelta may collect, record, organize, accumulate, store, update, retrieve, use, transfer where legally permitted, anonymize, restrict, delete, and destroy personal data.
Current configuration flags: Yandex Metrica is disabled, Google Analytics is disabled. Loading happens only after consent.
Google Analytics may involve processing or transferring technical data outside the Russian Federation. This is noted here and must be reviewed before Google Analytics is enabled.
Before Google Analytics is enabled, Cartelta reviews regulatory notification requirements, data scope, destination country, recipient, contractual basis, and Google Analytics settings.
Primary collection, recording, organization, accumulation, storage, update, and retrieval of Russian citizens' personal data must use databases located in the Russian Federation where that rule applies.
infrastructure location and applicable providers are specified in contractual, technical, or compliance documents for the relevant service.
Requests may be sent to support@cartelta.ru. Cartelta may request information needed to confirm the identity of the requester or the authority of a representative.
For cookie categories, consent settings, Yandex Metrica, Google Analytics, and the cookie table, see the Cookie Policy.
The current version is published on the site and is available without registration. The document is updated when processing operations, service providers, or legal requirements change.
Version: 2026-05-09.1. Revision date: 2026-05-09.
© 2026 Cartelta. All rights reserved.
Send request