Support
Describe your question and we'll help solve the problem.
Before sending a request, please check the FAQ section.
Frequent questions
View allCreate a request
PRIVACY POLICY
and personal data processing policy for chessbase.am
Effective date: «05» june 2026.
1. General provisions
1. This Privacy Policy (the “Policy”) sets out how personal data is processed and protected and has been prepared in accordance with the legislation of the Republic of Armenia, including the Law of the Republic of Armenia “On Protection of Personal Data” (the “Data Protection Law”), the Civil Code of the Republic of Armenia and the Law of the Republic of Armenia “On Protection of Consumer Rights”.
2. The data controller is CHESSBASE C.I.S LLC (trademark “ChessBase C.I.S.”), operating the website https://chessbase.am/ (the “Website”).
3. The Policy applies to all information about users and customers that the Controller may obtain in connection with the use of the Website and the purchase of software and cloud-service subscriptions.
4. Use of the Website by itself does not constitute consent to the processing of personal data. Consent is given separately, in written or electronic form (a separate checkbox upon form submission), as set out in this Policy and in the separate “Consent to the processing of personal data” document.
5. The Controller may amend the Policy; the current version is published on the Website.
2. Controller details
Name: CHESSBASE C.I.S LLC / ChessBase C.I.S.
Registration number: 999.110.1559887 dated 13.02.2026
TIN: 02941235
Address: Armenia, Yerevan, 0010, M. Khorenatsi str., 26a, office 210
Email: info@chessbase.am
Website: https://chessbase.am/
3. Key definitions
6. Personal data — any information relating directly or indirectly to an identified or identifiable natural person (data subject).
7. Processing — any operation with personal data (collection, recording, storage, use, transfer, depersonalisation, destruction, etc.), with or without automated means.
8. Controller (processor) — the person that determines the purposes and scope of processing and organises it.
9. Data subject — a user of the Website, a purchaser of software or a subscription.
10. Authorised body — the Personal Data Protection Agency under the Ministry of Justice of the Republic of Armenia (the “Agency”).
4. Categories of personal data processed
11. Upon registration, ordering and payment the Controller processes: first and last name; email address; phone number; data required for invoicing and document execution; information about purchased software products and subscriptions.
12. For card payments via acquiring, bank-card data is processed by the acquiring bank and payment systems; the Controller does not receive or store card data.
13. When using the Website, technical data is processed automatically: IP address, device and browser information, date and time of access, pages and actions on the Website, referral source, cookies.
14. The Controller does not process special categories of data or biometric data. Should such processing become necessary, it will be carried out with written consent and with notification to the Agency in the cases prescribed by law.
15. Since the Controller does not process biometric or special-category data, prior notification to the Agency is not mandatory for the Controller (Article 23 of the Data Protection Law); such notification is submitted at the Agency’s request. The Controller may notify the Agency of its intention to process voluntarily.
5. Purposes and legal grounds
16. Conclusion and performance of the contract (provision of software and subscription) — ground: processing necessary for the performance of a contract to which the data subject is a party.
17. Invoicing, accounting and tax records — ground: compliance with obligations imposed on the Controller by the legislation of the Republic of Armenia.
18. Handling enquiries and technical support — ground: performance of the contract and the Controller’s legitimate interests.
19. Sending informational and marketing messages — ground: the data subject’s consent (given separately and not a condition of purchase).
20. Collection of anonymised statistics and improvement of the Website — ground: legitimate interests and consent to analytical cookies.
6. Data subject’s consent
21. Consent is informed and specific: prior to giving it, the data subject is notified of the purpose, scope and duration of processing and of the persons to whom the data may be transferred.
22. Consent is given in written or electronic form (including by a separate checkbox upon form submission; where prescribed by law — validated by electronic digital signature) and may be withdrawn at any time.
23. Consent is deemed given, in particular, where personal data is set out in a document addressed to the Controller and signed by the data subject, or obtained on the basis of a contract with the data subject and used for the purposes of that contract (Article 9 of the Data Protection Law).
24. For a minor under 16, as well as for a person declared incapable or with limited capacity, consent is given by the legal representative.
25. Upon withdrawal of consent, the Controller terminates processing and destroys the data within ten (10) working days of receiving the withdrawal, unless otherwise agreed or provided by law and unless other legal grounds for continued processing exist under the Data Protection Law.
7. Transfer to third parties
26. The Controller transfers personal data to third parties only to the extent necessary to perform the contract and operate the Website: to the acquiring bank and payment systems (for settlements); to the cloud-infrastructure and hosting provider (for the subscription and Website operation); to the web-analytics provider (in anonymised form); to authorised bodies in the cases prescribed by the legislation of the Republic of Armenia.
27. Third parties process the data subject to confidentiality and security obligations.
8. Cross-border transfer
28. Personal data is transferred to other countries with the data subject’s consent or where necessary to achieve the purposes of processing (in particular, when using cloud infrastructure located outside the Republic of Armenia).
29. Transfers to countries ensuring an adequate level of protection (under international treaties or under the official list published by the Agency) are made without the Agency’s prior permission.
30. Transfers to countries not ensuring an adequate level of protection are made only after obtaining the Agency’s prior permission and with contractual safeguards (Article 27 of the Data Protection Law).
31. Armenian law does not impose mandatory localisation of personal data within the Republic of Armenia; data may be hosted on cloud infrastructure abroad subject to the rules of this section.
9. Retention periods
32. Personal data is stored no longer than necessary for the purposes of processing, or for the period established by the legislation of the Republic of Armenia (including for accounting and tax purposes).
33. Upon achievement of the purposes or withdrawal of consent (absent other grounds), the data is destroyed or anonymised.
10. Data subject’s rights
34. The data subject has the right to: obtain information about the processing of their data; require rectification, blocking or destruction of data that is incomplete, inaccurate, outdated, unlawfully obtained or unnecessary for the purpose; withdraw consent; appeal the Controller’s actions to the Agency or in court.
35. To exercise their rights, the data subject sends a request to info@chessbase.am. The Controller provides the information or access within five (5) working days of receiving the written request (Article 20 of the Data Protection Law).
11. Security measures
36. The Controller takes legal, organisational and technical measures to protect data against unlawful or accidental access, destruction, alteration, blocking, copying and dissemination, including encryption of data transmission (SSL/TLS), access control and processing oversight.
37. In the event of a personal-data leak from electronic systems, the Controller immediately publishes an announcement and reports the leak to the Police of the Republic of Armenia and to the Agency (Article 21 of the Data Protection Law).
12. Cookies and web analytics
38. The Website uses mandatory (technical) and analytical cookies. Analytical cookies (including web-analytics services) are used with the user’s consent given via the cookie banner.
39. Cookie terms are set out in a separate Cookie Notice on the Website. Users may manage cookies in their browser settings.
13. Provisions for data subjects in the European Union (GDPR)
This section applies to data subjects located in the EU where the Controller offers them goods or services and falls within the scope of the EU General Data Protection Regulation (GDPR).
40. Legal bases: performance of a contract (Article 6(1)(b) GDPR); compliance with legal obligations (Article 6(1)(c)); the Controller’s legitimate interests (Article 6(1)(f)); consent (Article 6(1)(a)) — for marketing and analytical cookies.
41. EU data subjects additionally have the rights of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability and objection, as well as the right to lodge a complaint with their national supervisory authority.
42. Cross-border transfers of EU data subjects’ data are carried out with appropriate safeguards (standard contractual clauses or other mechanisms provided by the GDPR).
43. The Controller does not carry out automated decision-making producing legal effects for the data subject without a separate legal basis.
44. Requests from EU data subjects are sent to info@chessbase.am and handled within the GDPR time limits (generally one month).
14. Final provisions
45. This Policy is a public document and is published on the Website.
46. The law of the Republic of Armenia applies to relations connected with the processing of personal data, unless otherwise required by applicable data-protection rules for subjects from other jurisdictions.
47. Essential consumer information is provided in Armenian; Russian and English versions are published additionally.
48. Questions regarding this Policy are sent to info@chessbase.am.
CONSENT
to the processing of personal data
This Consent is given in accordance with the Law of the Republic of Armenia “On Protection of Personal Data” and is an informed, specific and unambiguous expression of the data subject’s will. It is executed separately from other documents.
1. Data subject
First and last name: ______________________________________________;
Email address: ____________________________________;
Phone number (if any): _______________________________.
2. Controller
Name: CHESSBASE C.I.S LLC / ChessBase C.I.S.
Registration number: 999.110.1559887 dated 13.02.2026
Address: Armenia, Yerevan, 0010, M. Khorenatsi str., 26a, office 210
Email: info@chessbase.am
Website: https://chessbase.am/
3. Categories of data
— first and last name;
— email address;
— phone number (if provided);
— data for invoicing and document execution;
— information about purchased products and subscriptions;
— technical data when using the Website (IP address, cookies, device and browser information, actions on the Website).
1. The Controller does not request processing of special categories of data or biometric data.
4. Purposes
— conclusion and performance of the contract (provision of software and subscription);
— invoicing, accounting and tax records;
— handling enquiries and technical support;
— informing about order status.
5. Term and scope
2. Consent is given for the period necessary to achieve the purposes or for the period established by the legislation of the Republic of Armenia.
3. Processing includes collection, recording, storage, use, transfer (to the extent necessary for performing the contract), depersonalisation and destruction, with or without automated means.
6. Transfer and cross-border transfer
4. The data subject consents to transfer of data to the acquiring bank and payment systems (for settlements), the cloud-infrastructure and hosting provider, and the web-analytics provider (in anonymised form).
5. The data subject is informed that data may be transferred to other countries when using cloud infrastructure; such transfer is carried out in accordance with the Law “On Protection of Personal Data” (to adequate-protection countries — without the Agency’s permission; to others — with the Agency’s permission and with contractual safeguards).
7. Withdrawal
6. Consent may be withdrawn at any time by sending a request to info@chessbase.am. Upon withdrawal, the Controller terminates processing and destroys the data within ten (10) working days, unless other legal grounds for continued processing exist under the Law “On Protection of Personal Data”.
8. Confirmations
— consent is given freely, by the subject’s own will and in their interest;
— the subject has reviewed the Controller’s Privacy Policy;
— the data provided is accurate.
Consent to receive marketing and informational messages is given separately and is not a condition of purchase.
Date: «____» __________ 20___. Signature: ___________ / ______________ /