Skip to content
Delivery across RussiaAll products manufactured in Germany
+7 495 227-81-24Discuss your project
HomePersonal data processing policy

Personal data processing policy

Data controller: [Наименование оператора — заполнить в настройках]. Tax ID: [Заполнить]. Controller address: [Заполнить]. Data enquiries: [Email для обращений — заполнить].

1. Purpose and legal basis

The purpose is to consider the visitor’s enquiry, select a structure, prepare a proposal and respond. The legal basis for processing form data is the visitor’s separate consent under Russian Federal Law No. 152-FZ. Advertising mailings are not a purpose of this form.

2. Data processed

A phone number is required; name, model, dimensions and comments are optional. Shop enquiries save the selected product and its parameters. Submission time, the page URL without query parameters, and the consent version and text are also saved. Do not provide special categories of data, health information or third-party data.

Spam protection uses temporary HMAC values derived from the IP address and phone number, retained for up to one hour and one minute respectively. The plugin does not record the original IP address in the enquiry. Hosting server logs are governed by the controller’s hosting settings and agreement; their content, access and retention must be reviewed separately.

3. Processing and storage

Collection, recording, organisation, accumulation, storage, correction, use and deletion take place automatically in the WordPress database. The database containing Russian citizens’ personal data, backups and associated processes must comply with Russian localisation requirements. In the supplied configuration, access to enquiries is restricted to website administrators.

Enquiries are retained until the purpose is fulfilled, consent is withdrawn or 180 days after submission, whichever comes first. After an enquiry is marked Completed, it is deleted within 30 days and within the overall retention limit. A daily task deletes these enquiries; the controller ensures regular execution and extends deletion to copies and logs. Contract and statutory accounting data are outside this form and require separate legal bases and retention periods.

4. Access and transfers

Visitor data is not transferred for advertising. Email notifications contain only the enquiry number and a link to the protected administration area. Telegram is disabled by default; if explicitly enabled, only the enquiry number is sent. These notifications reduce the amount of information transferred but still require the controller’s assessment, including cross-border transfers. The controller must establish legal bases, review contractors and complete required notifications before enabling external services.

Yandex Map is available on the contacts page and loads only after the visitor clicks. No connection to Yandex is made beforehand. On loading, the service receives the IP address and technical browser information and may use its own cookies. Enquiry form data is not sent to the map. You can use the page without loading it. Service terms: Yandex privacy policy.

The header provides external WhatsApp and Telegram links. They open only when the visitor chooses to follow them; the website does not load messenger widgets beforehand. After following a link, data processing is governed by the relevant service’s terms.

5. Your rights

You may request information about processing, correction, restriction or deletion of data, or withdraw consent: [Email для обращений — заполнить]. Provide the enquiry number and information needed to locate it. The controller verifies the requester’s authority and responds within statutory time limits. Processing may continue within legal limits where another legal basis applies. You may also contact Roskomnadzor or a court.

6. Security measures

The kit provides a private enquiry section, permission checks, server-side form validation, rate limits, protection against product substitution and consent records. The controller supplements these with HTTPS, updates, backups, access management, internal policies, threat assessment and required information-system security measures.

7. Policy changes

The controller updates this document when purposes, data or services change. New consent versions apply to new submissions; the version and text previously accepted remain saved with each enquiry.

Separate consent → · Cookies and external services →

↑
Get advice and a quoteCall us