szpakedstudio
SZPAKED STUDIO / DOCUMENTS

Personal data processing policy

1. General provisions and information about the Controller

1.1. This Policy sets out how the personal data of visitors to https://szpaked.com and individuals submitting enquiries through its form is processed and protected. It has been prepared in accordance with Federal Law No. 152-FZ of 27 July 2006, On Personal Data. It does not govern data processing by the standalone products and services presented in the website's portfolio.

1.2. The Controller is Sole Proprietor Vitaliy Yuryevich Lakshin, Tax ID (INN) 601501194203, sole proprietor registration number (OGRNIP) 326600000009002 (the Controller). Enquiries concerning personal data processing can be sent to vylakshin@gmail.com.

2. Purposes and legal bases for processing

2.1. The Controller processes applicants' data to review enquiries about design and software development, clarify requirements, prepare proposals and communicate with applicants. Processing is based on the applicant's separate consent under Article 6, Part 1, Clause 1 of Federal Law No. 152-FZ.

2.2. When entering into and performing a contract, the grounds in Article 6, Part 1, Clause 5 also apply. When fulfilling statutory duties, the applicable statutory grounds apply.

2.3. Technical data is processed to maintain the website's functionality and security where the grounds in Article 6, Part 1, Clause 7 apply, provided the data subject's rights and legitimate interests are respected.

2.4. Enquiry data is not used for advertising mailings and is not intended for disclosure to an unrestricted audience.

3. Categories of data subjects and data collected

3.1. Data subjects are website visitors and individuals submitting enquiries, including representatives of potential clients.

3.2. Enquiry data includes the applicant's name; their chosen contact details, either a Telegram username or link, or an email address; information voluntarily included in the task description; approximate budget; chosen service package; and expected completion date. The enquiry date and reference number, consent details, submission and initial visit page addresses, and referral tags, where present, are also processed.

3.3. To operate and protect the website, the Controller may process IP addresses, access dates and times, requested resources and technical browser information to the extent necessary for the relevant purpose.

3.4. The Controller does not request special categories of personal data or biometric personal data. Applicants should not include such information, copies of documents or third parties' personal data without an appropriate legal basis.

4. Processing procedures and data disclosure

4.1. Processing is carried out with and without automated tools and includes collection, recording, organisation, accumulation, storage, updating, retrieval, use, disclosure, restriction, deletion and destruction. Enquiries are initially recorded on a server located in the Russian Federation.

4.2. The Controller maintains the confidentiality of personal data. Access is limited to persons who need it to review the enquiry.

4.3. Gmail is used for correspondence sent to the Controller's email address.

4.4. Where external services involve cross-border transfers of personal data, the requirements of Article 12 of Federal Law No. 152-FZ are observed.

4.5. Data may be disclosed at the request of an authorised authority where required by law. Processing may be entrusted to another person where there is an appropriate legal basis and conditions meeting Article 6, Part 3 of the same law.

5. Retention periods and termination of processing

5.1. Enquiry data is processed until the purpose is achieved, but for no longer than 180 calendar days after submission if no contract is concluded and no other lawful basis exists. This is the Controller's maximum retention period for enquiries, not a mandatory statutory period.

5.2. If the purpose is achieved earlier or consent is withdrawn, processing stops and data is destroyed in accordance with Article 21 of Federal Law No. 152-FZ, including within 30 days where that statutory period applies. An independent lawful basis may require continued processing of necessary data.

5.3. Retention periods for contractual and mandatory accounting records are determined separately under applicable law.

5.4. Termination covers records, message copies and backups under the Controller's control. If destruction within the required period is not possible, the Controller restricts processing and subsequently destroys the data within the period allowed by law.

6. Session storage and external resources

6.1. Information entered in the form is held only in the state of the open page. The website does not save form fields to the browser's session or persistent storage. Refreshing or closing the page resets an incomplete form. The consent checkbox is not selected automatically.

6.2. The initial visit page and referral tags may be saved in session storage.

6.3. No external analytics trackers are connected as of this version's date.

6.4. When loading fonts used by the website, the browser contacts Google Fonts, which receives technical connection data.

7. Data subject rights and requests

7.1. A data subject may obtain information about the processing of their data, request its correction, restriction or destruction where statutory grounds exist, withdraw consent, and complain to Roskomnadzor or a court.

7.2. Requests should be sent to vylakshin@gmail.com. To identify an enquiry, we recommend including its reference number and the contact details used when submitting it. A request for processing information must meet Article 14 of Federal Law No. 152-FZ. The Controller may request proportionate information needed to verify the applicant's identity or a representative's authority.

7.3. Consent may be withdrawn by sending an email with the subject Withdrawal of consent to personal data processing. Withdrawal does not affect the lawfulness of earlier processing or prevent processing on another statutory basis.

7.4. Requests are reviewed within the periods specified in Articles 20 and 21 of the same law.

8. Security measures

8.1. The Controller takes necessary legal, organisational and technical measures to protect data against unlawful or accidental access, alteration, destruction, restriction, copying and dissemination. In particular, access to the enquiry log is restricted; the log is stored outside publicly accessible website files; incoming data is validated; and request rates are limited. Access management, secure transmission, backups and compliance with retention periods are maintained during operation.

8.2. In the event of an incident, the Controller acts in accordance with the law, including notifying the authorised authority where required.

9. Publication and amendments to the Policy

9.1. The Policy is available at https://szpaked.com/privacy.

9.2. Changes to external services and processing purposes are reflected in a new version before the relevant processing begins. A new version does not automatically entitle the Controller to extend the processing authorised by previously obtained consent.