Privacy and personal data processing policy for this website.
Version: [1.0]
Effective date: [DD.MM.YYYY]
1.1. This Privacy Policy (the Policy) describes how personal data is processed when you use the website [domain] (the Website) in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (the Personal Data Law) and other applicable laws of the Russian Federation.
1.2. The data controller is [specify: individual — full name / sole proprietor — full business name / legal entity — full legal name], [TIN; OGRN or OGRNIP if applicable], [registered address / legal address], [contact email for personal data requests], [phone — if applicable] (the Controller).
1.3. This Policy applies to personal data processing carried out by the Controller in connection with use of the Website, including when you fill in forms, subscribe to newsletters [if applicable — describe], contact support [if applicable — describe], and perform other actions available on the Website.
1.4. By using the Website, including submitting data through forms [and ticking consent boxes where required], you confirm that you have read this Policy and accept its terms, except where mandatory legal requirements provide otherwise.
1.5. If you do not agree with this Policy, do not use the Website or submit personal data through its forms.
2.1. Personal data is processed in line with the principles set out in Article 5 of the Personal Data Law, including lawfulness and fairness, purpose limitation, adequacy of the data to the stated purposes, and minimisation of processing.
2.2. The Controller does not process special categories of personal data or biometric personal data unless expressly permitted by separate consent and law.
2.3. Processing of minors’ personal data is carried out where required by law, including consent of a legal representative where applicable. The Website is [not aimed / aimed] at children under [14 / 18]; [if needed — describe age limits and how parental consent is obtained].
3.1. Depending on the features you use, the following categories may be processed:
3.2. The Controller does not perform profiling or solely automated decision-making that produces legal effects concerning you or similarly significantly affects you, unless expressly stated in a separate notice or required by law.
Personal data is processed for the following purposes:
5.1. Processing is based on:
5.2. Certain processing [e.g. newsletters, third-party analytics] is carried out only with separate consent [and/or] other applicable bases as explained in the relevant forms or interfaces.
6.1. The Controller may perform collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data — only to the extent necessary for the purposes in Section 4.
6.2. Processing may involve automated and non-automated means, depending on the operation.
7.1. The Controller does not sell personal data or disclose it to the general public.
7.2. Personal data may be disclosed where required by law and may be processed on the Controller’s behalf by processors under a contract, including:
7.3. Processors must comply with applicable data protection requirements. The Controller remains responsible within the limits set by law.
8.1. [If servers or vendors are outside the Russian Federation — describe countries, legal basis, and safeguards under Article 12 of the Personal Data Law.]
8.2. [If no cross-border transfers: State explicitly that no cross-border transfer occurs / that transfers occur only as described in this section.]**
9.1. Personal data is kept no longer than necessary for the purposes, unless a longer period is required by contract or law.
9.2. Data from contact forms is retained [specify period, e.g. for the duration of handling the request and [N] months after the conversation ends, unless longer retention is needed for claims].
9.3. Technical logs [specify retention aligned with security and legal requirements].
9.4. When purposes are achieved, consent is withdrawn (where applicable), or other legal grounds apply, data is deleted or anonymised, unless law requires otherwise.
10.1. The Controller implements appropriate legal, organisational and technical measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, in accordance with the Personal Data Law and internal policies [if any — reference].
11.1. You have the right to:
11.2. To exercise your rights, email [email] with the subject line “Personal data request” / “152-FZ”. Please include your full name, contact details for the reply, and a clear description of your request. The Controller will respond within statutory time limits.
11.3. The Controller may refuse a request in full or in part where permitted by the Personal Data Law [e.g. inability to identify you, processing required by law — refine with counsel].
12.1. The Website may use cookies and similar technologies for:
12.2. Strictly necessary cookies may rely on legitimate interests / performance of your request to use the Website [choose and justify with counsel]. Other cookies [only with consent via banner/settings — describe your implementation].
12.3. You can restrict or disable cookies in your browser; some features may not work or may work incorrectly.
13.1. The Controller may update this Policy. The current version is always available at [URL of this policy page].
13.2. For material changes, the Controller [recommended: notify users via banner / email where lawfully possible]. Continued use after the new version takes effect may constitute acceptance only where permitted by law; otherwise, statutory rules apply.
14.1. This Policy remains in force until replaced by a new version.
14.2. Matters not covered here are governed by the laws of the Russian Federation.
14.3. Informational nature of content. Information on the Website is for general information only and does not constitute a public offer within the meaning of paragraph 2 of Article 437 of the Civil Code of the Russian Federation unless expressly stated on a specific page.