PRIVACY POLICYVersion dated March 27, 2026
Data Controller | Individual Entrepreneur Kamilla Andreevna Yakimova |
Taxpayer Identification Number (TIN) | 761107434063 |
Primary State Registration Number of Individual Entrepreneur (OGRNIP) | 325762700036670 |
Email | kamillamengel@gmail.com |
Telegram | @KamillaMengel |
What Is This Privacy Policy About?This Privacy Policy explains how the Data Controller processes your Personal Data and ensures its security and confidentiality.
In accordance with
Part 2 of Article 18.1 of the Federal Law of the Russian Federation “On Personal Data,” this Privacy Policy is published in the public domain on the Data Controller’s Resources.
Resources mean the Data Controller’s electronic resources, including, without limitation, social media accounts, online services, platforms, messaging applications, communication channels, and the Website registered in the Data Controller’s name.
This Privacy Policy explains what Personal Data the Data Controller collects and how the Data Controller uses such Personal Data.
What Is Personal Data?Personal Data means any information relating to an identified or identifiable individual (
Data Subject).
The Data Controller processes only those categories of Personal Data specified in this Privacy Policy that identify you as a user of the Resources.
You may provide your consent to the processing of Personal Data when using the Resources, completing feedback or contact forms available through the Resources or by any other means provided for in this Privacy Policy.
On What Legal Grounds Does the Data Controller Process Personal Data?The Data Controller processes Personal Data on the following legal grounds:
1. Consent of the Data Subject (Clause 1, Article 6 of the Federal Law “On Personal Data”) – applies to the processing of Personal Data provided when using the Resources, completing feedback forms, subscribing to newsletters, publishing reviews, using cookies, and in other similar cases.
2. Performance of a Contract (Clause 5, Article 6 of the Federal Law “On Personal Data”) – applies to the processing of Personal Data necessary for the preparation, conclusion, and performance of contracts, as well as for the provision of services requested by the user.
3. Compliance with Obligations Imposed by the Legislation of the Russian Federation (Clause 2, Article 6 of the Federal Law “On Personal Data”) – applies to the processing of Personal Data necessary to comply with legal requirements, including tax accounting, accounting records, and compliance with orders and requirements issued by state authorities.
4. Pursuit of the Data Controller’s Legitimate Interests (Clause 7, Article 6 of the Federal Law “On Personal Data”) – applies to the processing of Personal Data for the purpose of ensuring the security of the Website, preventing fraud, protecting the Data Controller’s rights in the event of disputes, and transferring Personal Data to third parties where necessary for the provision of services (for example, payment service providers).
What Rights Do You Have?At any time while the Data Controller processes your Personal Data, you may exercise the following rights:
Right | Description |
Right of Access | You have the right to request a copy of the Personal Data held by the Data Controller. |
Right to Rectification | You may request that the Data Controller correct inaccurate or incomplete Personal Data. |
Right to Blocking and Erasure of Personal Data | You may request the deletion of the Personal Data held by the Data Controller about you, except where the Data Controller is required by law to retain such Personal Data. |
Right to Appeal the Actions or Inaction of the Data Controller | If you believe that the Data Controller processes your Personal Data in violation of the applicable legislation or otherwise infringes your rights, you have the right to appeal the actions or inaction of the Data Controller to Roskomnadzor. |
Right to Appeal Decisions Based Solely on Automated Processing of Personal Data | You have the right to object to decisions based solely on the automated processing of your Personal Data. |
Right to Withdraw Consent | You may withdraw your consent to the processing of your Personal Data at any time. |
You may contact the Data Controller if you wish to clarify the procedure for exercising any other rights provided for by the Federal Law “On Personal Data.”
How Does the Data Controller Process Personal Data?The Data Controller processes Personal Data both in digital form (by automated means) and manually (without the use of automation tools). In doing so, the Data Controller performs only the following processing operations:
- collection;
- recording;
- systematization;
- accumulation;
- storage;
- updating (modification);
- retrieval;
- use;
- transfer (provision, access);
- depersonalization;
- blocking;
- deletion;
- destruction of Personal Data.
For What Purposes Does the Data Controller Process Your Personal Data?Purpose | Personal Data | Category | Processing Period | Method of Destruction |
Processing a request for Services and providing the Services | Full name, email address, mobile phone number, Telegram ID, bank account details | General | Until the purpose of processing is achieved or consent to processing is withdrawn | Deletion from the Data Controller’s database |
Preparation, conclusion, and performance of a contract | Full name, email address, mobile phone number, Telegram ID, bank account details, passport details, date of birth, registered address | General | Until the purpose of processing is achieved or consent to processing is withdrawn | Deletion from the Data Controller’s database |
Distribution of marketing and informational communications | Full name, email address, mobile phone number, Telegram ID | General | Until the purpose of processing is achieved or consent to processing is withdrawn | Deletion from the Data Controller’s database |
Publication of reviews | Full name, email address, Telegram ID, voice data, photo and video image of the individual, Instagram username | General | Until the purpose of processing is achieved or consent to processing is withdrawn | Deletion from the Data Controller’s database |
What Are Cookies?The Website uses
cookies, which are small text files stored in the user’s browser when visiting the Website. Cookies enable the Website to recognize the user’s device, ensure the proper functioning of the Website, and improve the functionality of its services.
Categories of Cookies Used:(1) Functional Cookies – are necessary for the basic operation of the Website, including user authentication, saving user preferences, operation of the shopping cart, and the User Account.
(2) Analytical Cookies – are used to collect statistical information and analyze user behavior on the Website. This helps improve the structure and content of the Website. Web analytics systems with localized data storage (for example, Yandex Metrica) are used.
(3) Marketing Cookies – are used to personalize content and display advertisements on third-party platforms (where applicable). Marketing Cookies are used only where the user has provided separate consent.
Legal Basis for Cookie ProcessingFunctional Cookies are processed on the basis of the Data Controller’s legitimate interests for the purpose of ensuring the technical operation of the Website.
Analytical Cookies and Marketing Cookies are processed on the basis of the Data Subject’s consent, expressed by selecting the appropriate checkbox or by continuing to use the Website after activating the cookie banner.
Managing CookiesThe user has the right to disable Cookies through the browser settings. Disabling Cookies may affect the proper display of certain elements of the Website and limit access to the functionality of the User Account.
You can read more about managing Cookies by following the links below:
- Yandex Browser
- Safari
- Google Chrome
Does the Data Controller Transfer Your Personal Data to Third Parties?The Data Controller may transfer Personal Data to third parties to the extent necessary to achieve the purposes specified in this Privacy Policy. Such transfer shall be carried out only in cases provided for by law or where it is necessary for the provision of services to the user.
The Data Controller uses the services of third parties that process Personal Data on its behalf under confidentiality agreements and personal data processing agreements. This is permitted provided that such persons:
- ensure an adequate level of protection of Personal Data;
- do not use Personal Data for their own purposes;
- act strictly within the scope of the instructions given by the Data Controller.
Such recipients may include:
- payment solution providers — for processing payments;
- providers of CRM systems and email and push notification platforms;
- hosting providers and persons providing technical support for the Website and applications;
- contractors involved in the delivery of services, processing refunds, and other operations related to orders;
- persons providing access to the Resources or supporting the user interface;
- persons providing legal protection of the rights of the Data Controller or third parties in the event of violation or threatened violation of their rights, including violations of laws or regulatory requirements;
- persons providing users with access to the Resources.
Cross-Border Transfer of Personal DataThe Data Controller does not transfer Personal Data across borders to foreign countries that do not provide an adequate level of protection for the rights of Data Subjects. Should such a transfer become necessary (for example, when using foreign hosting providers or analytics services), the transfer shall be carried out only upon obtaining the Data Subject’s written consent or in other cases expressly provided for by the federal legislation of the Russian Federation.
How Does the Data Controller Ensure the Security of Personal Data?The Data Controller protects the Personal Data in its possession against disclosure, complete or partial loss, and unauthorized access by third parties.
The security of Personal Data is ensured through the implementation of legal, organizational, and technical measures corresponding to the risks associated with Personal Data processing, in accordance with the legislation of the Russian Federation.
Personal Data is stored and made available exclusively within the territory of the Russian Federation in compliance with applicable information security requirements and only to the extent necessary for the Data Controller to fulfill its obligations to public authorities.
Organizational measures include:
- appointment of a person responsible for organizing the processing of Personal Data;
- familiarization of employees directly involved in the processing of Personal Data with the legislation of the Russian Federation on Personal Data and regular training on Personal Data protection;
- monitoring compliance with the measures implemented to ensure the security of Personal Data.
Technical measures include:
- the use of information security tools (including firewalls, intrusion detection systems, and antivirus protection) that have undergone conformity assessment in accordance with the requirements of applicable legislation;
- the use of encryption mechanisms (HTTPS/SSL) for data transmission between the user and the Website;
- regular updating of the software used in order to eliminate known vulnerabilities.
If a Personal Data breach occurs, the Data Controller shall:
- notify Roskomnadzor within 24 hours;
- conduct its own investigation within 72 hours and notify Roskomnadzor of the results of such investigation.
What Does the Data Controller Not Verify?The Data Controller is unable to verify, and therefore relies on your confirmation that you:
- possess full legal capacity;
- have provided your own accurate Personal Data.
How to Contact the Data ControllerIf you have any questions regarding the processing of Personal Data, you may contact the Data Controller by email at
kamillamengel@gmail.com or through other available communication channels.
When submitting a request, please specify your name and contact details for correspondence.
The Data Controller shall respond to your request no later than
10 business days from the date of its receipt.
Changes to this Privacy PolicyThe Data Controller may update this Privacy Policy on the basis of:
- changes in legislation;
- introduction of new technologies or methods of processing Personal Data;
- changes in the Data Controller’s organizational structure or business processes;
- introduction of new products or services requiring updates to the approach to Personal Data processing;
- user feedback or changes to the privacy policies of the Data Controller’s partners.
The Data Controller shall notify users of amendments to this Privacy Policy where such amendments are material, using available means of communication.