← На главнуюBack home

Юридический документ Legal document

Personal Data Processing Policy (152-FZ)

ОбновленоUpdated  06/12/2026

Last updated: 2026-06-12 · Effective: 2026-06-07 · Version: 1.1

This is an English translation of the Personal Data Processing Policy required by Russian Federal Law No. 152-FZ of 27.07.2006 “On Personal Data”. The legally binding version is the Russian original; this translation is provided for convenience. The Policy covers all products of the operator, including the scheda.me website and the scheda.me mobile application.

Operator

Name: Индивидуальный предприниматель Алёхин Роман Сергеевич (sole proprietor Roman Sergeevich Alekhin)
ИНН (INN): 713005978740
ОГРНИП (OGRNIP): 326710000026194
Registered address: 301114, Tulskaya oblast, Tula, Leninsky rayon, rp. Plekhanovo, Zavodskaya ulitsa, 9, kv. 92
Email: roman@alekhin-dev.com
Roskomnadzor operator registry record: TODO: the registry number will be added after the notification is filed at pd.rkn.gov.ru.

Terms

  • Personal data — any information relating to a directly or indirectly identified or identifiable natural person (personal data subject).
  • Personal data processing — any operation or set of operations performed on personal data.
  • Personal data subject — a natural person using the operator’s products.
  • The subject’s consent to personal data processing (Art. 6 of 152-FZ).
  • Performance of a contract to which the subject is a party (user agreement).
  • Compliance with obligations imposed by the legislation of the Russian Federation.

Categories of subjects and data processed

The operator processes the following categories of personal data:

  • Users of the operator’s products: last and first name (if provided by the user), email address, password (encrypted), business name (if provided), device information (model, OS, app version), technical data (IP address, request timestamps), crash and diagnostic data.
  • Correspondents contacting support: email address and the content of the inquiry.
  • Users’ clients (entered by the user as controller): names, contact details, appointment and service data. The operator processes this data solely on the user’s instructions, as a processor.

The operator does not process special categories of personal data or biometric personal data.

Purposes of processing

  • User registration and authentication.
  • Providing the functionality of the operator’s products.
  • Synchronizing the user’s data between devices.
  • Providing technical support.
  • Ensuring information security and preventing abuse.
  • Complying with the requirements of RF legislation.

TODO: when paid subscriptions launch, add the purpose “Settlements under the service agreement”.

Processing methods

Personal data is processed both with and without automation tools. Operations include: collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.

Transfer of personal data to third parties

The operator transfers personal data to the following processors on the basis of processing agreements:

  • Self-hosted Supabase platform on a dedicated server located in the Russian Federation — account data storage and backups.
  • Sentry — crash and error diagnostics.
  • ЮKassa (YooMoney) — subscription settlements (for RF users, once paid tiers launch).
  • TODO: email service provider (Yandex 360 or Cloudflare) — account emails.

The operator does not transfer personal data to any other third parties, except in cases provided by RF legislation (at the request of authorized state bodies).

Localization and cross-border transfer

The operator’s servers used for the collection, recording, systematization, accumulation, storage, clarification, and extraction of personal data of citizens of the Russian Federation are located on the territory of the Russian Federation (in accordance with Part 5, Art. 18 of 152-FZ). Cross-border transfer of personal data is not performed.

Retention periods

Personal data is retained for the lifetime of the user’s account. After account deletion, data is deleted or anonymized within 30 calendar days, except where longer retention is required by RF legislation (e.g. tax documents — 4 years).

Rights of the personal data subject

The subject has the right to:

  • Receive information about the processing of their personal data, including the list of data, its source, and the purposes and methods of processing.
  • Demand clarification, blocking, or destruction of the data.
  • Withdraw consent to personal data processing.
  • Appeal the operator’s actions or inaction to Roskomnadzor or in court.

Requests are sent to roman@alekhin-dev.com. The operator responds within 30 days. Account deletion instructions: Account deletion.

Protection measures

  • Data transfer over secure channels (HTTPS / TLS).
  • Passwords stored as hashes.
  • Access control and separation of privileges.
  • Backups and data integrity monitoring.
  • Access logging.

TODO: after the ИСПДн (personal data information system) class is determined and the measures under FSTEC Order No. 21 are implemented — specify the class and the applied measures.

Changes to this Policy

The operator may amend this Policy. A new version takes effect from the moment it is published at alekhin-dev.com/legal/personal-data-ru (Russian original), unless the new version provides otherwise.

By using the operator’s sites and products and by providing personal data to the operator, the subject confirms their agreement with the terms of this Policy. Consent may be withdrawn at any time by sending a request to roman@alekhin-dev.com.