Legal documents
B2B SaaS offer and data processing instructions
This offer sets out unified terms for providing LARNES as SaaS to owners of networks, schools, and education centres. Appendix 1, containing processing instructions under Article 6(3) of Russian Federal Law No. 152-FZ, is an integral part of the offer.
- Status
- Effective · interface acceptance unavailable
- Provider
- Индивидуальный предприниматель Бояркин Алексей Станиславович
- Who it applies to
- Legal entities and individual entrepreneurs operating a network, school, or education centre, acting through an authorised representative. The offer does not apply to independent teachers using a personal tutor workspace or to consumers.
Status and scope
Provider means the LARNES platform owner identified on the Company details and contacts page. Customer means a legal entity or individual entrepreneur operating a network, school, or education centre and entering into the agreement for business or professional purposes.
This offer governs only B2B access to a LARNES organisation workspace. It does not cover independent teachers using personal tutor workspaces, consumer family access, educational services supplied by the Provider, data-subject consents, marketing consent, or consumer payment rules.
Where the Customer's procurement requires a separate agreement, tender, Russian unified procurement system, electronic document exchange, qualified electronic signature, or special terms under Laws No. 44-FZ or No. 223-FZ, the parties execute a separate document. This offer does not replace a mandatory procurement procedure.
Definitions
Platform means the LARNES website, software, APIs, and role-based workspaces. Organisation workspace means the Customer's isolated area containing branches, users, and data. Order means a document or record agreed by the parties specifying the plan, term, price, modules, and access start date.
Customer Administrator means a Customer-designated user managing the organisation workspace, staff, branches, roles, and enabled functionality. Customer Users means representatives, staff, and contractors to whom the Customer lawfully grants work access.
Customer Data means information and materials created, uploaded, imported, or received by the Customer or its Users in the organisation workspace, including personal data processed under Appendix 1.
Agreement formation and authority
This offer is effective. Verifiable online acceptance in the LARNES interface is not yet available; until it is enabled, the contract is concluded through a separate agreement or order. Viewing this page, registering, signing in, testing, uploading data, corresponding, or paying does not by itself constitute acceptance.
Until online acceptance is enabled, an agreement is formed only by signing a separate agreement or Order that expressly incorporates this offer and Appendix 1. The Customer must not upload third-party personal data before that formation.
The pre-connection online flow identifies the Customer, authorised representative, position and authority, document version, plan, and acceptance time. Silence, a pre-selected checkbox, and action by an unauthorised user are not acceptance.
The signatory warrants sufficient authority. Before activating the organisation workspace, the Provider may request Russian corporate or entrepreneur register details, a power of attorney, a machine-readable power of attorney, or subsequent approval by the chief executive.
SaaS scope and functionality
The Provider grants remote access to available LARNES modules, and the Customer uses them for its own learning and operational processes. Scope, limits, and term are set by the Order and the selected plan's current capabilities.
An organisation workspace may include:
- branches, staff, teachers, children, families, groups, directions, schedules, lessons, attendance, and grades;
- homework, learning programmes, progress, and classroom/QR flows;
- CRM, leads, tasks, contract templates, and contract instances;
- internal accrual, payment, and balance records, spreadsheets, and analytics views;
- integrations and other modules expressly enabled by the Order or Customer settings.
LARNES is a software tool and does not become a party to the Customer's agreements with students, parents, staff, or teachers. Internal payment records are not bank transfers, fiscal receipts, or receipt of money by the Provider.
SaaS, CRM, and analytics access is not an educational service supplied by the Provider. The Customer remains responsible for its education content and legality, licences, staff qualifications, family agreements, and mandatory notices.
Access, implementation, and support
Access uses individual accounts. The Customer appoints administrators, grants least-privilege roles, promptly disables dismissed or suspended users, and prevents shared use of passwords and verification codes.
The Provider may update interfaces, correct defects, and develop functionality without impairing the paid service's core purpose. Material discontinuation of a paid module requires advance notice and a proportionate solution for unused access.
Scheduled work and emergency maintenance may temporarily limit access. The Provider takes reasonable recovery steps and informs the Customer through an available channel where an outage materially affects operation.
Support is provided through the channels and during the hours published on the Company details page unless the Order includes an enhanced service level.
Price, payment, and tax
The Order or separate agreement states price, access period, payment terms, limits, and enabled modules. No paid access arises under this offer unless those terms are agreed.
Invoices, acceptance certificates, and other accounting documents follow the parties' agreed process. The Provider's tax treatment and VAT status follow applicable law and its details at the calculation date.
Late payment may result in suspension of paid functionality after notice and a reasonable cure period. Suspension does not cancel confidentiality, data return, or payment duties for the period already supplied.
Customer duties
The Customer must:
- provide accurate details about itself, representatives, administrators, and authority;
- use the Platform lawfully, solely for its own activities, and within the Order;
- hold lawful grounds for student, child, parent, lead, staff, and teacher data;
- give mandatory privacy information, obtain required consents, and handle subject requests as controller;
- avoid excessive, special-category, or biometric data unless separately agreed in writing and legally safeguarded;
- control roles, invitations, integrations, exports, and Customer User actions;
- promptly report account compromise, mistaken access, and suspected incidents.
The Customer is responsible for its instructions, materials, and Customer User activity. Technical ability to enter information is not Provider confirmation of legality, consent validity, or authority.
When a contact is entered manually or received from a connected form, the Customer confirms that an applicable lawful ground exists and supplies an available notice or supporting-document reference. LARNES retains the Customer's assertion with minimal technical source and receipt-time evidence; it does not attest that the data subject consented or verify consent validity. The Customer remains responsible for informing data subjects and obtaining consent where required by law.
Provider duties
The Provider supplies agreed access, maintains role and tenant isolation, corrects confirmed material defects within a reasonable period, and gives notice of important service changes.
The Provider does not use Customer Data for its own advertising, data sales, training public models, or activity incompatible with the instructions. Anonymised technical statistics may be used for security and service improvement where re-identification is prevented.
The Provider may temporarily restrict a dangerous operation or access where necessary to comply with law, prevent an incident, protect other customers, or stop a material breach. Where possible, it explains the reason and restoration conditions.
Intellectual property and data
Rights in LARNES code, interfaces, design, marks, and proprietary materials remain with their owners. During the agreement the Customer receives a limited, non-exclusive, non-transferable right to use the Platform through its intended interface.
Rights in Customer Data and materials remain with the Customer or relevant rights holder. The Customer grants only the technical right to store, reproduce, transform, transfer, and display them as needed to provide the service and perform the instructions.
Resale, extraction of a substantial part of LARNES databases, circumvention, decompilation outside statutory exceptions, and copying protected elements to build a competing service are prohibited.
Confidentiality
Each party protects the other's non-public business, technical, and contractual information at least as carefully as comparable information of its own and discloses it only to personnel and contractors who need access and are bound by confidentiality.
The duty does not cover public information, information lawfully obtained from a third party, independently developed information, or mandatory legal disclosure. Unless prohibited, the receiving party gives advance notice and limits disclosure to the required scope.
Confidentiality lasts during the agreement and for five years afterwards; for personal data and legally protected secrets it lasts while the relevant legal regime continues.
Liability
The parties are liable for proven breach under Russian law. A breaching party compensates documented direct loss causally linked to its breach; lost profits and indirect loss are excluded to the extent permitted by law.
The Provider is not liable for unlawful Customer instructions, inaccurate data, Customer role assignments, Customer agreements and materials, third-party systems connected by the Customer, or Customer-side connectivity.
Liability limitations do not apply to wilful breach, payment obligations, unlawful intellectual-property use, confidentiality breach, or liability that law expressly prohibits limiting.
An ordinary software defect is not force majeure by itself. Force majeure excuses liability only where extraordinary, unavoidable, causally relevant, and promptly notified.
Term and termination
The agreement begins on the date stated in the signed Order or separate agreement and lasts for the agreed period. Renewal occurs only by the agreed method; continued viewing of a public page does not renew it.
A party may terminate for material breach not cured within 15 calendar days after written notice, except where law or security requires immediate restriction.
After termination, new data entry is blocked, the Customer receives agreed export access, and data is returned or deleted under Appendix 1. Payment, intellectual property, confidentiality, liability, and dispute terms survive as needed.
Versions, notices, and precedence
The Provider publishes a new version in advance and notifies material changes through an available verified channel. A new version does not alter an existing agreement until properly incorporated or newly accepted where required.
Notices may be sent through the interface, verified email, electronic document exchange, or party details. Legally significant notices to the Provider are accepted through the Company details and contacts page.
In case of conflict, precedence is: separate signed agreement, Order, this offer body, Appendix 1 for instructed processing, and Terms of use for general interface rules. Appendix 1 controls within its specific subject.
Governing law and disputes
Russian law governs. A party first sends a written claim and allows 15 business days for response unless law sets another mandatory period.
An unresolved dispute is heard by the competent Russian commercial court under applicable procedural law. This does not alter exclusive jurisdiction or public-authority powers.
If the Russian and English versions differ, the Russian version is legally controlling.
Appendix 1. Personal data processing instructions
This Appendix is an integral part of the B2B SaaS offer and constitutes processing instructions under Article 6(3) of Russian Federal Law No. 152-FZ. It operates only with a concluded agreement and within the Customer's active organisation workspace.
The Customer instructs the Provider to process the personal data described below only on documented Customer instructions, this Appendix, authorised Administrator settings, and mandatory law.
These instructions do not replace parent, staff, client, or other data-subject consent, do not authorise dissemination, and do not include marketing processing. The Customer remains responsible for legal grounds and controller duties toward subjects.
Appendix 1. Roles and limits
The Customer is controller of its students, children, parents and representatives, leads and clients, staff, teachers, payers, and other persons entered into its workspace. It determines purposes, grounds, data scope, users, and periods within law.
The Provider is the person processing that data on the Customer's instructions. It does not change the instructed purposes or independently determine use of Customer Data.
The Provider remains an independent controller for its own representatives and users where needed for agreement formation, authentication, account management, security, support, billing, legal claims, and statutory duties. That processing follows the LARNES Personal data processing policy.
Where several organisations participate in one process, the Customer determines their roles and lawful exchange before transfer. These instructions do not automatically make the Provider a joint controller.
Appendix 1. Subjects and data categories
Instructions may cover:
- Customer representatives, administrators, staff, and teachers;
- current and prospective clients, leads, parents, guardians, and other representatives;
- children and adult students;
- payers, counterparties, and contacts in Customer contracts;
- invitees and persons named in Customer User work materials.
Data categories include:
- name, date of birth, gender, contact details, and family or representative relationship;
- organisation, branch, position, role, work permissions, access status, and change history;
- enquiry, lead source, assignee, notes, CRM history, and communications;
- enrolment, group, direction, programme, schedule, homework, progress, attendance, grade, and timestamps;
- contract templates and instances, accruals, payments, corrections, balances, and internal records;
- account, invitation, session, classroom/QR device, and security-event identifiers;
- text, links, images, and other information entered into CRM, tasks, spreadsheets, rich text, DOCX, and other free fields.
These instructions do not authorise biometric identification data, health data, intimate-life data, racial or ethnic origin, political, religious or philosophical beliefs, or other special-category data. Such processing requires separate written instructions, legal-ground review, and safeguards; current LARNES functionality is not intended for it.
Appendix 1. Purposes, operations, and methods
Processing is limited to:
- supplying and administering the organisation workspace, branches, roles, and access;
- operating CRM, enquiries, contracts, groups, schedules, lessons, attendance, grades, and homework;
- displaying learning programmes, progress, and classroom/QR flows;
- internal accrual, payment, and balance records without the Provider processing bank payments;
- available Customer reports, spreadsheets, and analytics views;
- import, export, backup, restoration, support, diagnostics, and security for these functions.
Permitted operations are collection through Customer interfaces, recording, organisation, accumulation, storage, correction, retrieval, use, matching within a stated purpose, role-based access, transfer to an approved subprocessor, blocking, anonymisation, deletion, and destruction.
Processing is mainly automated. Manual activity is permitted for support, authority checks, document import, subject requests, audit, or incident response.
The Provider promptly informs the Customer if an instruction reasonably appears to violate data law and suspends the disputed operation until clarified, except where a competent authority mandates it.
Appendix 1. Localisation and subprocessors
When Russian citizen data is collected online, recording, organisation, accumulation, storage, correction, and retrieval use databases located in Russia as required by Article 18(5) of Law No. 152-FZ. The Provider does not activate third-party data intake under these instructions until that production infrastructure is confirmed.
Cross-border transfer is excluded by default. It requires documented Customer instruction, compliance with Article 12, mandatory notices, recipient assessment, and advance Customer notice.
The Provider uses a hosting provider and other subprocessors only for necessary functionality and under agreements imposing duties no weaker than this Appendix. The Provider remains responsible to the Customer for their instructed performance.
Before processing activation, the Provider discloses the current subprocessors, functions, processing locations, and data categories. It gives at least 10 business days' notice of planned additions or replacements; the Customer may raise a reasoned data-protection objection. Disabled integrations are not engaged subprocessors.
Appendix 1. Confidentiality and safeguards
The Provider ensures confidentiality and permits access only to persons who need it, understand the safeguards, and are bound by non-disclosure. Access ends when the service need ends.
Taking Articles 18.1 and 19 of Law No. 152-FZ into account, safeguards include:
- local policies, assigned data-protection functions, harm assessment, threat assessment, and protection-level determination;
- tenant and role isolation, least privilege, individual authentication, and session revocation;
- password and one-time-code hashing, secret management, and protected data transfer;
- security event records, rate limiting, vulnerability controls, and updates;
- backups, restoration testing, availability controls, and an incident plan;
- unauthorised-access detection, affected-processing blocking, investigation, and remediation;
- regular internal review, authorised-person training, and documented deletion.
Controls are proportionate to current threats, data, and mandatory requirements. On request, the Provider supplies a sufficient description without exposing secrets, keys, vulnerabilities, or other customers' data.
Appendix 1. Subject requests and incidents
The Customer decides subject requests as controller. If the Provider receives a Customer Data request, it forwards it without undue delay, normally within one business day, and does not answer substantively without instruction except for its own controller role or a legal duty.
Within available functionality, the Provider helps locate, export, correct, block, stop, delete, or document destruction. The Customer sends a verified instruction allowing statutory deadlines; the Provider reports completion or a technical obstacle without undue delay.
The Provider gives initial notice of a discovered Customer Data security breach within 12 hours through the agreed channel. It includes known facts, affected subject and data categories, likely effects, measures, and a contact; missing information follows as investigation proceeds.
The Provider preserves relevant evidence, contains and remediates the incident, and assists the Customer with Roskomnadzor and subject notifications. The Customer remains responsible for its controller notice, while the Provider separately performs duties arising from its own controller role.
Appendix 1. Retention, return, deletion, and review
Data is processed during the agreement and periods in lawful Customer instructions. The Customer defines its retention schedule; the Provider does not extend storage arbitrarily and may require clarification of conflicting periods.
After termination, the Customer may request an available standard export for 30 calendar days. The Provider then deletes or anonymises working copies within 30 calendar days unless law or a documented legal hold requires a limited set.
Backups leave circulation through overwrite no later than 14 days after working-data deletion. Until then they are isolated from ordinary access and used only for disaster recovery; restored data again follows the current deletion request.
On written request, the Provider supplies evidence reasonably needed to verify these instructions, including safeguards, subprocessors, deletion outcome, available logs, and a justified questionnaire response, normally within 10 business days.
No more than annually, the Customer may conduct a scoped remote review on agreed timing. Additional review is available after a confirmed incident or regulator requirement. It must protect other customers, security secrets, and service continuity; the Customer bears cost unless a material Provider breach is found.
If mandatory law prevents return or deletion, the Provider informs the Customer, identifies the ground, and limits further processing to protected retention until the duty ends.