This is a translation. In case of any discrepancy, the Russian version of the document prevails.
This document is adopted by the controller in accordance with clause 2 part 1 article 18.1 of Russian Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 and sets out the policy on processing personal data together with the protection measures applied. It is published with unrestricted access.
1. General provisions
1.1. The controller is the administration of the “the iVy Studio” project, the owner and administrator of the service, independently determining the purposes and means of processing. Details of the person acting as the controller are provided on request to the address below and will be published once the corresponding status is registered. Address for requests: legal@theivy.ru.
1.2. Processing takes place in the controller’s information systems available at theivy.ru, app.theivy.ru, api.theivy.ru, theivy.dev, app.theivy.dev and api.theivy.dev. They are all served by one and the same Service: the .ru and .dev domain zones work with shared data.
1.3. The duties of the person responsible for organising the processing of personal data rest with the person acting as the controller; their details are provided on request.
1.4. A plain-language explanation for users is given in the Privacy Policy; in case of discrepancy this document prevails.
2. Legal grounds for processing
- the Constitution of the Russian Federation;
- Federal Law No. 152-FZ “On Personal Data” of 27 July 2006;
- Federal Law No. 149-FZ “On Information, Information Technologies and Information Protection” of 27 July 2006;
- Federal Law No. 126-FZ “On Communications” of 7 July 2003 — as regards retention obligations of information distribution organisers, should such an obligation arise;
- the Civil Code of the Russian Federation;
- the consent of the data subject;
- a contract to which the data subject is a party and steps taken at the subject’s request before entering into it.
3. Purposes of processing
- providing access to the client area and identifying the subject;
- receiving and handling development requests and related messages;
- sending service messages (password, access recovery, e-mail address confirmation);
- keeping the information systems operational and secure;
- complying with obligations imposed on the controller by law;
- measuring public website traffic — where consent is given.
4. Categories of subjects and data
4.1. Users of the client area
E-mail address; name; country; interface language; role; password hash; profile picture; additional e-mail address and its confirmation mark; consent records (date, time, version); request and message content; uploaded files; session records; IP address; browser details; device identifier.
4.2. Staff of the controller
The data listed in 4.1, plus what a staff member publishes about themselves in a team card: name, position, description, links to external resources, list of projects, photo, Discord identifiers.
4.3. Visitors of the public website
Data collected by web analytics where consent is given: a pseudonymous visitor identifier, device and browser details, viewed pages, referral source.
Special categories of personal data and biometric personal data are not processed. Processing does not involve decisions with legal effect taken solely by automated means.
5. Manner and methods of processing
5.1. Processing is mixed — automated and non-automated — and includes collection, recording, systematisation, accumulation, storage, amendment, retrieval, use, transfer (provision, access), blocking, deletion and destruction.
5.2. Processing is limited to the purposes in section 3. Processing incompatible with those purposes is not allowed, nor is merging databases processed for incompatible purposes.
5.3. The controller does not place personal data in publicly available sources, except for the details a staff member publishes about themselves in a team card.
6. Cross-border transfer and place of processing
6.1. The technical facilities of the information systems are hosted on hardware of Hetzner Online GmbH in the Republic of Finland — a country party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data and providing adequate protection of data subjects’ rights.
6.2. The controller notifies subjects that, as of this version, the requirement of part 5 article 18 of Federal Law No. 152-FZ to keep databases of Russian citizens in Russia is not met, and plans to move the primary database to the Russian Federation. Compliance will be reflected in the next version of this document.
7. Retention periods and destruction
7.1. Data is processed while the account exists. When processing ends, the data is destroyed.
7.2. Upon a deletion request the account is marked as deleted and removed from operation; the data is actually destroyed after seven calendar days — a window that allows an accidental deletion to be undone.
7.3. Consent records are kept while the account exists and are destroyed with it.
7.4. Technical logs are kept for no more than 30 days unless a longer period is needed to investigate a security incident.
8. Security measures
- appointing a person responsible for organising the processing;
- limiting who has access and separating rights by role;
- encrypting the communication channel (TLS);
- storing passwords as an irreversible hash;
- protecting sessions: functional cookies with HttpOnly and Secure flags, anti-CSRF protection, request rate limiting;
- keeping logs of actions on requests and accounts;
- backups and key-based access control to the server;
- assessing the harm that may be caused to subjects and matching the measures to that assessment.
9. Rights of the data subject
A subject may obtain information about the processing of their data, demand its correction, blocking or destruction, withdraw consent, and appeal the controller’s actions to the supervisory authority or in court. Requests go to legal@theivy.ru and must contain details identifying the subject. The answer follows within 30 days of receipt.
10. Final provisions
This document is amended when the law or the set of processed data changes. The current and earlier versions are published in the Legal documents section.