Privacy Policy
POLICY ON THE PROCESSING AND PROTECTION OF PERSONAL DATA
Version 1.5 dated 31 August 2026
1. General provisions and scope
1.1. This Policy describes how Victoria Viktorovna Safonova (the Controller) processes and protects personal data in connection with the digital business card website at https://victoriasafonova.ru/, its pages and the protected administration panel at https://admin.victoriasafonova.ru/ (together, the Site). The partnership form and private Partner Room are disabled as of this version and do not accept personal data.
1.2. The Policy has been prepared under the Constitution of the Russian Federation, Federal Law No. 152-FZ of 27 July 2006 On Personal Data and other applicable laws of the Russian Federation.
1.3. The Controller processes personal data lawfully and fairly, only for predetermined purposes, in the amount necessary for those purposes and no longer than required by the purpose or an applicable legal basis.
1.4. The public partnership form is intended for adults. Acceptance of new enquiries through the form has been temporarily suspended since 23 August 2026 until the organisational and technical measures required for resuming processing have been completed.
1.5. PROFILE 360 is a separate service operated by the same Controller and is not a third-party resource. Public access and acceptance of new questionnaires are closed. Processing of PROFILE 360 questionnaires and reports is outside the scope of this digital business card Policy; separate policies and consents have been prepared for that service. The adult route may resume only after a separate decision and technical verification. Routes for persons under 18 remain blocked until a verified legal-representative process and a separate decision are in place. The Site's partnership form does not send data to PROFILE 360.
1.6. The Russian version is the governing version of this Policy. The English version is a translation; the Russian version prevails in the event of a discrepancy.
1.7. Processing of personal data in connection with the project actually began on 17 August 2026. This date does not give this version retroactive effect: version 1.5 applies only from its publication date.
2. Controller details
2.1. Controller: Victoria Viktorovna Safonova, an individual applying the special Professional Income Tax regime (self-employed), without the status of an individual entrepreneur.
2.2. Controller's registered address: Apt. 42, 11 Zoi i Aleksandra Kosmodemyanskikh Street, Moscow 125130, Russian Federation.
2.3. Postal address for data-subject requests: 31 Klary Tsetkin Street, Moscow 125130, Russian Federation.
2.4. Telephone: +7 985 908-80-06.
2.5. The active address for personal-data requests, demands and consent withdrawals is privacy@victoriasafonova.ru. General enquiries are accepted at hello@victoriasafonova.ru. Delivery to both addresses has been verified. A request may also be sent to the postal address in clause 2.3 and marked “Personal Data”.
3. Purposes, data, legal bases, methods and retention
3.1. Page delivery, operation and security. Data subjects: Site visitors. Purposes: delivering pages and files, routing requests, maintaining availability, preventing attacks and abuse, and diagnosing errors. Data: IP address; request date and time; requested page or file; query parameters if sent by the browser; referring page; HTTP headers; browser, device, operating-system and connection information; approximate location inferred from the IP address; and technical diagnostic and security logs. Legal basis: the Controller's rights and legitimate interests in maintaining availability and security, provided the visitor's rights and freedoms are not infringed. Operations and method: automated collection, entry in technical logs, use, access by infrastructure providers, restriction, deletion and destruction. Retention: logs controlled directly by the Controller are to be deleted or anonymised within 90 days unless needed to investigate a specific incident or comply with law. Infrastructure providers retain their own logs under their terms and settings; the Controller must clarify and minimise such periods when selecting infrastructure.
3.2. Partnership enquiries. Data subjects: adult visitors, prospective clients, partners and representatives of organisations. Acceptance of new enquiries is paused as of this version. Purposes after the form resumes: receiving and reviewing an enquiry, contacting the person, discussing a project or cooperation, and taking steps at the person's request before a possible contract. Data: name; reply email; organisation or project if provided; selected enquiry category; message; interface language; submission page; submission date and time. Legal basis: separate consent. Where the enquiry is directly aimed at entering into a contract, taking pre-contractual steps at the person's request is an additional basis. Operations and method: automated collection, recording, organisation, accumulation, storage and retrieval; human review and use; correction, restriction, deletion and destruction. Retention: no more than 180 days after receipt unless the purpose is achieved or consent is withdrawn earlier, or another independent lawful basis arises. Data needed for an agreement or a substantiated claim is then processed separately within the scope and period of that basis.
3.3. Evidence of consent. Data subjects: persons submitting the form after it resumes. Purpose: proving the fact, time, method and terms of consent and protecting the rights of the person and the Controller. Data: enquiry identifier; server date and time; Policy and Consent versions; form language; separate-checkbox method; SHA-256 digest of the exact Consent version; submission page. Legal basis: the Controller's obligation to prove consent and legitimate interest in demonstrating lawful processing, provided the person's rights and freedoms are not infringed. Operations and method: automated recording, storage, retrieval, use, restriction, deletion and destruction. Retention: with the enquiry for no more than 180 days; if a dispute arises, the minimum evidence necessary may be retained for the applicable period for protecting legal rights.
3.4. Partner Room. Data subjects: persons issued an access code and persons attempting access. Purposes: verifying access rights, protecting private materials, limiting attempts and investigating abuse. Data: the code at the moment of verification; the code label, which may contain a name or other recipient designation; creation, expiry and last-use dates; attempt result and time; hashed IP address. The application database does not store the access code in plain text. Legal basis: the legitimate interests of the Controller and authorised users in protecting private materials. Operations and method: automated recording, comparison, storage, use, restriction, deletion and destruction. Retention: successful and unsuccessful attempt records for no more than 90 days; the label and technical code metadata until revocation or expiry and no more than 30 days thereafter, unless longer retention is required for a specific incident or by law.
3.5. Previously collected minimised analytics. Since 23 August 2026 the Site's own code has not sent analytics events. Before suspension, records may have included event type, date and time, page path without query parameters, reduced referrer, language, the opened section or asset identifier and the category of a successfully submitted enquiry. Name, email, message text and raw IP address were not included in the events table. The purpose of retaining earlier records is aggregated evaluation of Site sections. The basis is the Controller's legitimate interest in developing the Site using minimised data while respecting visitor rights. Earlier records are to be deleted or irreversibly anonymised within 90 days of the event. Analytics may resume only after a new assessment of the data, legal basis and infrastructure, and an update of this Policy where required.
3.6. Email correspondence. Active domain mail is provided through Yandex 360. The sender and recipient addresses, technical headers, subject, content and attachments voluntarily supplied by the person are processed to answer the enquiry, conduct business correspondence and take steps at the person's initiative before a contract. Retention is until the enquiry is closed and no longer than one year thereafter unless law, a contract or a substantiated dispute requires otherwise. Gmail is not published or used as a working channel; the five identified project threads were transferred to a Russian Yandex 360 archive and permanently deleted from Gmail.
3.7. Data restrictions. The Controller does not intend to collect through the form special-category data, biometric data, passport details, banking details, passwords, information about minors or third-party personal data. The form Consent does not cover such data. Accidentally received excessive data is restricted and deleted without use unless another lawful basis exists.
3.8. Protected administration. Data subject: the Controller as the Admin Panel 6.0 user. Purposes: authentication, content management, protection of administrative access, password-guessing limits, and viewing or changing the status of previously stored enquiries. Data: administrative username; password salt and hash (the password is not stored in plain text); session-token hash; session creation and expiry; login result and time; technical hash of the browser key; and actions changing an enquiry status. Legal basis: the Controller's legitimate interests in managing and protecting their own information system and compliance with personal-data security obligations. A session lasts no more than four hours and ends on logout or password change; login-attempt records controlled directly by the Controller are to be deleted or anonymised within 90 days except records of a specific incident; credentials are retained while administrative access is active and deleted within 30 days after its permanent closure.
4. General processing conditions
4.1. Data is received from the person, their browser, an authorised representative or the infrastructure used to operate the Site.
4.2. The Controller may collect, record, organise, accumulate, store, correct, retrieve, use, transfer by providing or granting access to the parties in section 5, anonymise, restrict, delete and destroy personal data.
4.3. Processing is automated and mixed. The main Site does not make decisions based solely on automated processing that produce legal effects or otherwise significantly affect a person.
4.4. The Controller does not sell personal data, provide it for third-party advertising, disclose it to an indefinite audience or use form data for advertising mailings.
5. Infrastructure providers and recipients
5.1. Yandex.Cloud LLC, TIN 7704458262, PSRN 1187746678580, Room 528, 16 Leo Tolstoy Street, Moscow 119021, Russian Federation. The Russian Yandex Cloud region ru-central1 and Object Storage, Cloud DNS, Certificate Manager, API Gateway, Cloud Functions and YDB are used to host, deliver and securely administer the Site. Public content is loaded from a static file in the same bucket; an ordinary visitor’s browser does not call Cloud Functions or YDB to display pages. The public form and Partner Room are disabled. The protected Admin Panel 6.0 is available at admin.victoriasafonova.ru and uses API Gateway, Cloud Functions and YDB in ru-central1 to authenticate the Controller, manage content and securely access previously stored enquiries. The provider processes data on the Controller’s instructions in accordance with Article 6(3) of Federal Law No. 152-FZ. Terms: https://yandex.ru/legal/cloud_dpa/ru/.
5.2. Yandex LLC, TIN 7736207543, PSRN 1027700229193, 16 Leo Tolstoy Street, Moscow 119021, Russian Federation, provides Yandex 360 for domain mail. The Site does not use Vercel or Gmail for page delivery, analytics, form submission or forwarding of form content. All identified Vercel projects have been deleted and the checked legacy addresses return `404: NOT_FOUND`; project Gmail messages were moved to the Russian archive and permanently deleted from Gmail. Personal Gmail is not a Controller channel.
5.5. Public authorities and other parties receive data only where and to the extent required by law or another applicable legal basis.
5.6. A visitor follows links to social networks, messaging services and other external resources by their own action. The relevant owner then processes data under its own terms. PROFILE 360 remains a service of the Controller and is governed by clause 1.5 of this Policy.
6. Localisation and cross-border transfers
6.1. The form is disabled as of this version and does not collect new data. Before the form resumes, the Controller must verify that initial recording takes place in YDB in the Russian ru-central1 region through Yandex Cloud Functions and that form content is not sent to Gmail, Vercel or PROFILE 360.
6.2. Domain mail at `@victoriasafonova.ru` is active in Yandex 360; delivery to `hello@`, `privacy@`, `profile360@` and `dmarc@` has been verified. Personal-data requests use `privacy@victoriasafonova.ru`.
6.3. Site pages are hosted in Yandex Cloud and do not automatically load Vercel or Google resources. The Controller's current application processes do not provide for cross-border transfers. A person's independent navigation to a third-party external resource is not a transfer of form content by this Site and is governed by that resource's rules.
6.4. This Policy neither replaces a notice of intended cross-border transfer nor confirms compliance with Article 12 of Federal Law No. 152-FZ. Before a relevant transfer begins, the Controller must obtain the information required by law, file a separate notice with Roskomnadzor and comply with its decision.
6.5. Migration of the public Site and domain mail to Russian infrastructure is complete; the Vercel/Gmail foreign legacy environment has been closed. PROFILE 360 is hosted in a closed Russian environment and is not publicly available. A new cross-border transfer may begin only after a separate assessment and compliance with Article 12 of Federal Law No. 152-FZ.
7. Cookies and browser storage
7.1. The Site's own code does not set advertising or marketing cookies or create a persistent identifier to track a visitor across sessions.
7.2. A visitor's localStorage may contain a technical copy of public Site content and its save time. Form fields and message text are not stored there. In the administration panel, localStorage holds a random browser key used to derive a technical login-protection hash, and sessionStorage holds the administrative session token for no more than four hours. These entries can be removed using browser controls.
7.3. Infrastructure providers may independently use technical network identifiers and logs under their terms. Any new analytics, advertising or device-storage technology requires a prior assessment, an update of the Policy and, where required by law, separate consent.
8. Data-subject rights
8.1. A person may obtain information about processing; request correction, restriction or deletion; withdraw consent; demand the end of processing where provided by law; complain to Roskomnadzor or a court; and exercise other rights provided by law.
8.2. A request may be sent to privacy@victoriasafonova.ru or to the postal address in clause 2.3 and marked “Personal Data”. It should state the person's name, information sufficient to verify the relationship with the Controller and locate the record, the substance of the request and an address for the reply. A passport copy should not be sent unless separately and reasonably requested by the Controller.
8.3. Information or a reasoned refusal is provided within 10 business days, with a reasoned extension of no more than 5 business days. Confirmed inaccurate data is corrected, and unlawfully obtained or unnecessary data is destroyed, within 7 business days. After the purpose is achieved or consent is withdrawn, processing ceases and the data is destroyed within 30 days where no other ground exists. Withdrawal does not affect the lawfulness of earlier processing.
9. Personal-data security
9.1. The Controller applies proportionate legal, organisational and technical safeguards: data minimisation; access controls; HTTPS; request-source restrictions and content-security policies; IAM and service accounts; hashing of access codes and tokens where applicable; login-attempt limits; consent-version records; component updates; security monitoring and incident response.
9.2. Access is limited to the Controller and providers that need it for a stated purpose.
9.3. If an incident results in unlawful or accidental transfer, provision, dissemination of or access to personal data, the Controller sends an initial notice to Roskomnadzor within 24 hours of detection and the internal investigation results within 72 hours.
10. End of processing and destruction
10.1. Processing ends when a purpose is achieved, a retention period expires, a legal basis ends, consent is withdrawn and no other basis remains, unlawful processing is identified or a lawful demand is received.
10.2. Electronic records are removed from working systems automatically or under a documented procedure. If immediate deletion from a backup is technically impossible, the data is restricted, not used and permanently removed during the normal backup replacement cycle. Destruction is evidenced in the manner prescribed by Roskomnadzor.
10.3. The periods in section 3 are obligations of the Controller. Until automatic TTL is enabled, they are enforced by scheduled review and deletion; this Policy does not claim that TTL is already active.
11. Versions and publication
11.1. The current Russian version is published at https://victoriasafonova.ru/privacy/ and this English translation at https://victoriasafonova.ru/en/privacy/. An exact text copy is available at https://victoriasafonova.ru/legal/privacy-en-2026-08-31-v1.5.txt.
11.2. Version 1.5 takes effect on 31 August 2026 when published on the Site. It clarifies the description of the already active protected administration environment and does not retroactively alter an earlier consent. Processing that began on 17 August 2026 remains linked to the documents and conditions actually in effect on the relevant date.
11.3. Version identifier: PRIVACY-2026-08-31-v1.5.
11.4. The Controller publishes a new version when the domain, infrastructure, purposes, data or applicable law changes. Where a change requires new consent, that consent must be obtained before processing under the new terms.