This is an unofficial translation for informational purposes. The Russian version is legally binding.
Personal data processing policy
Effective from: May 10, 2026
1. General provisions
1.1 This Personal Data Processing Policy (the "Policy") defines the procedure and conditions for processing personal data by Самозанятый Кулаков Кирилл Дмитриевич (address: 300034, г. Тула, ул. Дм. Ульянова, д. 2, кв. 246) in respect of users of the website https://diarynchy.com and *.diarynchy.com subdomains.
1.2 Terms are used in the meaning established by the legislation of the Russian Federation on personal data.
1.3 The Operator processes personal data on the principles of lawfulness, fairness, minimization, and limiting processing to achieving specific, predetermined, and lawful purposes.
1.4 The Operator ensures confidentiality of personal data (Art. 7 of the Personal Data Law) and takes necessary measures to fulfill obligations established by Part 2 of Article 18.1 and Part 1 of Article 19 of that law (organizational and technical protection measures).
1.5 Contacts for personal data subject inquiries: e-mail: k.kulakov@diarynchy.com; phone: +7 (910) 701-86-99; postal address: 300034, г. Тула, ул. Дм. Ульянова, д. 2, кв. 246. The Policy is effective from 2026-05-10 and is freely available on the website https://diarynchy.com.
2. Basic concepts used in the Policy
2.1 Automated processing of personal data — processing of personal data using computer technology.
2.2 Blocking of personal data — temporary cessation of personal data processing (except where processing is necessary to clarify personal data).
2.3 Website — a set of graphic and informational materials, as well as computer programs and databases ensuring their availability on the Internet at https://diarynchy.com and *.diarynchy.com subdomains.
2.4 Personal data information system — a set of personal data contained in databases and information technologies and technical means ensuring their processing.
2.5 Depersonalization of personal data — actions as a result of which it is impossible to determine, without additional information, which User or other personal data subject the personal data relates to.
2.6 Processing of personal data — any action (operation) or set of actions (operations) performed with or without automation tools on personal data, including collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data.
2.7 Operator — a state body, municipal body, legal entity, or individual that independently or jointly with others organizes and/or carries out personal data processing and determines the purposes of processing, the composition of personal data to be processed, and actions (operations) performed with personal data.
2.8 Personal data — any information relating directly or indirectly to a defined or definable User of the website https://diarynchy.com and *.diarynchy.com subdomains.
2.9 Personal data permitted by the data subject for distribution — personal data to which unlimited access has been granted by the data subject through consent to processing of personal data permitted for distribution in the manner provided by the Personal Data Law (hereinafter — personal data permitted for distribution).
2.10 User — any visitor to the website https://diarynchy.com and *.diarynchy.com subdomains.
2.11 Provision of personal data — actions aimed at disclosure of personal data to a specific person or specific group of persons.
2.12 Distribution of personal data — any actions aimed at disclosure of personal data to an indefinite number of persons (transfer of personal data) or familiarization with personal data by an unlimited number of persons, including publication in mass media, placement in information and telecommunications networks, or provision of access to personal data in any other way.
2.13 Cross-border transfer of personal data — transfer of personal data to the territory of a foreign state to an authority of a foreign state, a foreign individual, or a foreign legal entity.
2.14 Destruction of personal data — any actions as a result of which personal data are irreversibly destroyed with no possibility of further restoration of personal data content in the personal data information system and/or material carriers of personal data are destroyed.
3. Basic rights and obligations of the Operator
3.1 3.1 The Operator has the right to:
- —receive from the personal data subject reliable information and/or documents containing personal data;
- —if the personal data subject withdraws consent to processing or sends a request to cease processing, continue processing without consent where grounds specified in the Personal Data Law exist;
- —independently determine the composition and list of measures necessary and sufficient to fulfill obligations under the Personal Data Law and regulatory legal acts adopted in accordance with it, unless otherwise provided by the Personal Data Law or other federal laws.
3.2 3.2 The Operator must:
- —provide the personal data subject, upon request, with information regarding processing of their personal data;
- —organize processing of personal data in the manner established by applicable legislation of the Russian Federation;
- —respond to inquiries and requests from personal data subjects and their legal representatives in accordance with the Personal Data Law;
- —report to the authorized body for protection of personal data subjects' rights, upon request of that body, the necessary information within 10 days of receiving such request;
- —publish or otherwise ensure unrestricted access to this Personal Data Processing Policy;
- —take legal, organizational, and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution, and other unlawful actions;
- —cease transfer (distribution, provision, access) of personal data, cease processing, and destroy personal data in the manner and cases provided by the Personal Data Law;
- —fulfill other obligations provided by the Personal Data Law.
4. Basic rights and obligations of personal data subjects
4.1 4.1 Personal data subjects have the right to:
- —receive information regarding processing of their personal data, except in cases provided by federal laws. Information is provided by the Operator in an accessible form and must not contain personal data relating to other data subjects, except where there are lawful grounds for disclosure. The list of information and procedure for obtaining it are established by the Personal Data Law;
- —require the operator to clarify, block, or destroy their personal data if the data are incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated processing purpose, and take lawful measures to protect their rights;
- —set a condition of prior consent for processing personal data for promoting goods, works, and services on the market;
- —withdraw consent to processing of personal data and send a request to cease processing;
- —appeal to the authorized body for protection of personal data subjects' rights or to court against unlawful actions or inaction of the Operator in processing their personal data;
- —exercise other rights provided by the legislation of the Russian Federation.
4.2 4.2 Personal data subjects must:
- —provide the Operator with accurate data about themselves;
- —inform the Operator of clarification (update, change) of their personal data.
4.3 Persons who provided the Operator with inaccurate information about themselves, or information about another personal data subject without the latter's consent, bear liability in accordance with the legislation of the Russian Federation.
5. Purposes of collecting and processing personal data
5.1 User support and handling of inquiries.
5.2 Ensuring operation and security of the website/application.
5.3 Statistical accounting.
5.4 Promotion of goods, works, and services on the market.
5.5 Conducting events, webinars, and mailings.
5.6 Recruitment (candidates) for vacant positions.
5.7 Registration and authentication of website/application users.
5.8 Ensuring operation and security of the website/application.
5.9 User support and handling of inquiries.
5.10 Conducting events, webinars, and mailings.
5.11 Loyalty program, bonuses, and referral programs.
5.12 E-commerce: order placement, delivery, returns, and claims.
5.13 Payment operations and billing.
5.14 Personnel and accounting records.
5.15 Compliance with labor legislation of the Russian Federation.
5.16 Compliance with tax legislation of the Russian Federation.
5.17 Compliance with security legislation of the Russian Federation.
5.18 Preparation, conclusion, and performance of civil law contracts.
5.19 Conducting research work.
5.20 Statistical accounting.
5.21 Promotion of goods, works, and services on the market.
5.22 Recruitment (candidates) for vacant positions.
6. Legal bases for processing personal data
6.1 For the purpose "User support and handling of inquiries", legal bases are: contract/offer; Federal Law 126-FZ (call recording when informing); consent (if required).
6.2 For the purpose "Ensuring operation and security of the website/application", legal bases are: legitimate interest of the operator (ensuring operability and security); Federal Law 149-FZ; local regulations; consent (for cookies/analytics if necessary).
6.3 For the purpose "Statistical accounting", legal bases are: Federal Law 282-FZ; depersonalization.
6.4 For the purpose "Promotion of goods, works, and services on the market", legal bases are: data subject consent to marketing; Federal Law 38-FZ "On Advertising"; Federal Law 126-FZ "On Communications".
6.5 For the purpose "Conducting events, webinars, and mailings", legal bases are: contract (offer to participate); consent to mailing/advertising; Federal Law 38-FZ "On Advertising"; Federal Law 126-FZ "On Communications".
6.6 For the purpose "Recruitment (candidates) for vacant positions", legal bases are: Labor Code of the Russian Federation; applicant consent; contract (offer on processing/consent).
6.7 For the purpose "Registration and authentication of website/application users", legal bases are: contract (offer/user agreement); Federal Law 126-FZ "On Communications" (notifications); consent (if necessary).
6.8 For the purpose "Ensuring operation and security of the website/application", legal bases are: legitimate interest of the operator (ensuring operability and security); Federal Law 149-FZ; local regulations; consent (for cookies/analytics if necessary).
6.9 For the purpose "User support and handling of inquiries", legal bases are: contract/offer; Federal Law 126-FZ (call recording when informing); consent (if required).
6.10 For the purpose "Conducting events, webinars, and mailings", legal bases are: contract (offer to participate); consent to mailing/advertising; Federal Law 38-FZ "On Advertising"; Federal Law 126-FZ "On Communications".
6.11 For the purpose "Loyalty program, bonuses, and referral programs", legal bases are: contract (adherence to program rules); consent (to marketing/profiling — if necessary).
6.12 For the purpose "E-commerce: order placement, delivery, returns, and claims", legal bases are: Civil Code of the Russian Federation; Law 2300-1 "On Protection of Consumer Rights"; Federal Law 54-FZ (online cash registers); sale contract/offer.
6.13 For the purpose "Payment operations and billing", legal bases are: Federal Law 161-FZ "On the National Payment System" (through payment providers); Federal Law 54-FZ; contract; consent (if necessary).
6.14 For the purpose "Personnel and accounting records", legal bases are: Labor Code of the Russian Federation; Federal Law 402-FZ "On Accounting"; Tax Code of the Russian Federation; Federal Law 27-FZ; Federal Law 167-FZ; local regulations; contract (employment/civil law).
6.15 For the purpose "Compliance with labor legislation of the Russian Federation", legal bases are: Labor Code of the Russian Federation; local regulations; contract (employment/civil law).
6.16 For the purpose "Compliance with tax legislation of the Russian Federation", legal bases are: Tax Code of the Russian Federation; Federal Law 402-FZ; contract with the subject (if any).
6.17 For the purpose "Compliance with security legislation of the Russian Federation", legal bases are: Federal Law 390-FZ; local regulations; contract/access control; consent (if required).
6.18 For the purpose "Preparation, conclusion, and performance of civil law contracts", legal bases are: Civil Code of the Russian Federation; contract.
6.19 For the purpose "Conducting research work", legal bases are: contract/research assignment; consent (if required); depersonalization.
6.20 For the purpose "Statistical accounting", legal bases are: Federal Law 282-FZ; depersonalization.
6.21 For the purpose "Promotion of goods, works, and services on the market", legal bases are: data subject consent to marketing; Federal Law 38-FZ "On Advertising"; Federal Law 126-FZ "On Communications".
6.22 For the purpose "Recruitment (candidates) for vacant positions", legal bases are: Labor Code of the Russian Federation; applicant consent; contract (offer on processing/consent).
6.23 Legal bases may also include the operator's constituent documents, local regulations, and contracts concluded with subjects and/or consents issued by them (in cases provided by law).
Note: Federal Law No. 152-FZ "On Personal Data" establishes general requirements for personal data processing and is not itself a legal basis for processing.
7. Scope and categories of processed personal data; categories of subjects
7.1 For the purpose "User support and handling of inquiries", the following categories may be processed: full name, contacts, content of inquiries/calls/chats, call recordings, ticket metadata, payment/order data if necessary.
7.2 For the purpose "Ensuring operation and security of the website/application", the following categories may be processed: IP addresses, date/time, URL, headers and technical identifiers, cookies/SDK, device data, error and access logs.
7.3 For the purpose "Statistical accounting", the following categories may be processed: depersonalized and aggregated data; if necessary — minimally required personal data with subsequent depersonalization.
7.4 For the purpose "Promotion of goods, works, and services on the market", the following categories may be processed: full name, contacts (phone/e-mail/messengers), order/interaction history, cookies and behavioral data (with consent).
7.5 For the purpose "Conducting events, webinars, and mailings", the following categories may be processed: full name, contacts, position/organization (if provided), registration forms, attendance, preferences, survey results.
7.6 For the purpose "Recruitment (candidates) for vacant positions", the following categories may be processed: full name, contacts, résumé, education, experience, qualifications, interview/test results, portfolio, references.
7.7 For the purpose "Registration and authentication of website/application users", the following categories may be processed: full name, login, e-mail, phone, account identifiers, passwords/hashes, 2FA codes, IP addresses, session cookies/tokens.
7.8 For the purpose "Ensuring operation and security of the website/application", the following categories may be processed: IP addresses, date/time, URL, headers and technical identifiers, cookies/SDK, device data, error and access logs.
7.9 For the purpose "User support and handling of inquiries", the following categories may be processed: full name, contacts, content of inquiries/calls/chats, call recordings, ticket metadata, payment/order data if necessary.
7.10 For the purpose "Conducting events, webinars, and mailings", the following categories may be processed: full name, contacts, position/organization (if provided), registration forms, attendance, preferences, survey results.
7.11 For the purpose "Loyalty program, bonuses, and referral programs", the following categories may be processed: full name, contacts, participant identifiers, purchase/accrual/redemption history, referral links.
7.12 For the purpose "E-commerce: order placement, delivery, returns, and claims", the following categories may be processed: full name, delivery address, contacts, order contents, purchase history, refund details, acts/claims.
7.13 For the purpose "Payment operations and billing", the following categories may be processed: full name, contacts, partially masked payment details, payment amounts and statuses, receipts, antifraud identifiers.
7.14 For the purpose "Personnel and accounting records", the following categories may be processed: full name, date of birth, passport data, SNILS, TIN (INN), address, contacts, employment and salary information, timesheets, accrual and deduction data, bank details, signatures.
7.15 For the purpose "Compliance with labor legislation of the Russian Federation", the following categories may be processed: full name, passport data, address, contacts, job function, qualifications, education, experience, schedule and discipline, occupational safety documents.
7.16 For the purpose "Compliance with tax legislation of the Russian Federation", the following categories may be processed: full name, TIN (INN), income and payments, details for tax and contribution payments, tax deduction and status information.
7.17 For the purpose "Compliance with security legislation of the Russian Federation", the following categories may be processed: full name, access pass data, inspection results, video surveillance data, network identifiers (IP/logs), biometrics if necessary.
7.18 For the purpose "Preparation, conclusion, and performance of civil law contracts", the following categories may be processed: full name/legal name, passport/registration data, address, contacts, payment details, transaction and settlement history.
7.19 For the purpose "Conducting research work", the following categories may be processed: survey/questionnaire data, full name (if not depersonalized), contacts, survey/trial results, technical identifiers.
7.20 For the purpose "Statistical accounting", the following categories may be processed: depersonalized and aggregated data; if necessary — minimally required personal data with subsequent depersonalization.
7.21 For the purpose "Promotion of goods, works, and services on the market", the following categories may be processed: full name, contacts (phone/e-mail/messengers), order/interaction history, cookies and behavioral data (with consent).
7.22 For the purpose "Recruitment (candidates) for vacant positions", the following categories may be processed: full name, contacts, résumé, education, experience, qualifications, interview/test results, portfolio, references.
7.23 Personal data subjects may include, depending on purposes, website visitors/service users, clients, counterparties (individuals), representatives of counterparties (legal entities), employees, job candidates, and other persons.
8. Procedure and conditions for processing personal data
8.1 Personal data processing is carried out on the basis of the User's consent to processing of their personal data, unless otherwise provided by the legislation of the Russian Federation.
8.2 Consent is expressed by the User performing actions clearly aimed at providing their personal data: completing form fields on the Website, submitting an application (message), and confirming agreement with the Policy by checking the corresponding box next to the form (if such field is provided).
8.3 The User may withdraw consent to processing of personal data at any time by sending a request to k.kulakov@diarynchy.com. After withdrawal, the Operator ceases processing, except where processing is permitted without the subject's consent by law or other legal bases.
8.4 For the purpose "User support and handling of inquiries", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.5 For the purpose "Ensuring operation and security of the website/application", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.6 For the purpose "Statistical accounting", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.7 For the purpose "Promotion of goods, works, and services on the market", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.8 For the purpose "Conducting events, webinars, and mailings", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.9 For the purpose "Recruitment (candidates) for vacant positions", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.10 For the purpose "Registration and authentication of website/application users", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.11 For the purpose "Ensuring operation and security of the website/application", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.12 For the purpose "User support and handling of inquiries", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.13 For the purpose "Conducting events, webinars, and mailings", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.14 For the purpose "Loyalty program, bonuses, and referral programs", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.15 For the purpose "E-commerce: order placement, delivery, returns, and claims", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.16 For the purpose "Payment operations and billing", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.17 For the purpose "Personnel and accounting records", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.18 For the purpose "Compliance with labor legislation of the Russian Federation", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.19 For the purpose "Compliance with tax legislation of the Russian Federation", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.20 For the purpose "Compliance with security legislation of the Russian Federation", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.21 For the purpose "Preparation, conclusion, and performance of civil law contracts", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.22 For the purpose "Conducting research work", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.23 For the purpose "Statistical accounting", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.24 For the purpose "Promotion of goods, works, and services on the market", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.25 For the purpose "Recruitment (candidates) for vacant positions", the following actions (operations) are performed with personal data: collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (provision, access), depersonalization, blocking, deletion, and destruction.
8.26 Processing may be carried out with or without automation tools.
8.27 Transfer of personal data to third parties: Yandex, UniSender (on the basis of processing agreements and/or other contracts; with compliance with personal data protection requirements).
8.28 When storing personal data, the operator uses databases located in the territory of the Russian Federation (Part 5 of Article 18 of the Personal Data Law).
8.29 Retention periods: logs 1 month, inquiries 3 years.
8.30 Cookie files may be used on the website to ensure correct operation of services and improve user experience.
8.31 Visit analytics may be conducted (including counters/pixels/SDK), processing minimally necessary data. Use of marketing identifiers requires consent where provided by law.
8.32 In certain cases, cross-border transfer of personal data is possible with compliance with legal requirements, including where the recipient country provides adequate protection or the data subject has given consent.
8.33 The Operator may transfer personal data to authorized bodies on grounds provided by the legislation of the Russian Federation.
9. Measures to ensure protection of personal data
9.1 The Operator takes necessary legal, organizational, and technical measures to protect Users' personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution, and other unlawful actions.
9.2 9.2 Such measures include, in particular:
- —appointment of persons responsible for organizing processing and ensuring security of personal data;
- —adoption of local acts on personal data processing and protection;
- —limiting the circle of employees with access to personal data and establishing access procedures;
- —use of antivirus tools, firewalls, and other technical information protection means;
- —storage of personal data in conditions ensuring their integrity and excluding unauthorized access;
- —conduct of internal control and audit of compliance with requirements of the legislation of the Russian Federation on personal data and this Policy;
- —familiarization of employees directly processing personal data with provisions of the legislation of the Russian Federation and local acts of the Operator.
10. Updating, correction, deletion and destruction of personal data; responses to subject requests
10.1 Upon confirmation of inaccurate personal data or unlawful processing, the operator updates data and/or ceases processing.
10.2 Personal data are subject to destruction upon achievement of processing purposes, upon withdrawal of consent by the subject (if processing was based on consent), upon expiry of retention periods, or upon detection of unlawful processing, unless otherwise provided by law or contract.
10.3 The personal data subject may send a request for information on processing of their personal data and/or statements for clarification, blocking, or deletion. A request may be sent to k.kulakov@diarynchy.com or to the postal address: 300034, г. Тула, ул. Дм. Ульянова, д. 2, кв. 246.
10.4 The operator's response period to a subject request is no more than 30 calendar days from receipt of the inquiry.
10.5 Conditions for ceasing processing: achievement of processing purposes; withdrawal of consent; detection of unlawful processing; other grounds provided by law.
11. Policy updates
11.1 This Policy is subject to review and update in case of changes in the legislation of the Russian Federation, applicable regulations, or by decision of the Operator.
11.2 The current version of the Policy is always available on the Operator's website https://diarynchy.com.
11.3 A new version takes effect upon publication on the website, unless otherwise stated in the version itself.