Personal data
Personal data policy
This policy explains how personal data may be processed when using vlasovlab.ru, contacting VlasovLab, preparing or performing agreements, and publishing approved project materials.
Revision date: July 19, 2026.
The English text is provided for convenience. The Russian version applies to processing governed by Russian law.
1. General provisions
This policy describes the purposes, scope and procedures used by the operator when processing personal data with and without automated tools.
The website does not use request forms, personal accounts, online payments, advertising pixels or newsletter subscriptions. A visitor may contact the operator voluntarily by email. The Russian version of the website also provides a telephone number.
2. Operator
The personal data operator is individual entrepreneur Yaroslav Vlasov, Russian taxpayer ID 771371517514, who administers VlasovLab.
Contact address: 3 Einstein Boulevard, Moscow.
For personal data questions, contact info@vlasovlab.ru.
3. Data that may be processed
3.1. Website use
Technical data may be processed: IP address, access date and time, requested page address, HTTP headers and User-Agent, browser, operating system and device type, server log entries, technical security event identifiers, and values stored in technical cookies or local browser storage.
The self-hosted Matomo Analytics installation processes a shortened IP address, visit date and time, page address, referral source, browser, operating system and device type, and technical event identifiers to produce anonymized technical visit statistics without identifying individual visitors.
3.2. Enquiries and agreements
Data voluntarily provided by a person or required to prepare and perform an agreement may be processed: name, email address, telephone number, organization and position, business registration and tax details where applicable, postal address where required, bank details and account number, enquiry and correspondence content, project information and attachments, agreement, statement of work, acceptance certificate and power-of-attorney details, and signatures in contractual documents.
The operator does not request information about gender or place of birth, social-security identifiers, foreign passport data, payment card details, private-life information, special categories of personal data or biometric personal data. Identity document details are requested only where genuinely required by law or for a specific agreement with an individual.
3.3. Tax and accounting obligations
Agreements, invoices, acceptance certificates, payment documents, primary accounting records and electronic document-management records may contain data of clients, counterparties, individual entrepreneurs, their representatives and signatories.
3.4. Publication of project and professional materials
With separate consent, the operator may process and publish a person's name, position, project role, professional information, photograph or video image, authorship and an approved link to a public professional profile. Photographs and videos are not used for biometric identification.
4. Processing purposes
- Preparing, entering into and performing civil-law agreements, including handling incoming enquiries and discussing technical tasks.
- Operating and securing the website.
- Statistical accounting through anonymized technical visit statistics without advertising profiling.
- Compliance with Russian tax and accounting requirements.
- Promotion of goods, work and services, including publication of approved information about projects, authors, specialists and professional activities.
5. Legal grounds
Depending on the purpose, processing is based on the data subject's consent; steps taken at the data subject's request before entering into an agreement; performance of an agreement; compliance with Russian legal obligations; or the operator's legitimate interests where the data subject's rights and freedoms are not violated.
Personal data is published only with separate consent to dissemination and, where applicable, consent to the use of the person's image.
6. Cookies, local browser storage and Matomo
The website uses the technical cookie vl_site_policy_consent to remember acknowledgement of the policy banner and the technical cookie vl_site_language to remember the selected website language. Local browser storage is used to remember the selected theme and may duplicate the policy-banner acknowledgement. These technologies are not used for advertising or behavioral profiling.
Matomo Analytics is installed on the same Russian hosting account as the website. Matomo tracking cookies are disabled, IP addresses are masked, User ID is disabled, browser Do Not Track signals are respected, and logged-in WordPress administrators are excluded from tracking. Raw Matomo visit logs are scheduled for deletion after 180 days.
The website does not use Yandex Metrica, Google Analytics, advertising pixels or third-party data collection forms.
7. Service providers and data transfers
To the extent required for their functions, data may be available to the Russian hosting provider, the Russian email and cloud-storage provider, Bank Tochka and its accounting service, Kontur.Diadoc electronic document management, authorized technical contractors, and public authorities where required by law.
Data is not transferred to third parties for sale, advertising or advertising profiling. External links do not transmit contact or contractual data from the website; after following such a link, the destination website's rules apply.
The website, Matomo, business email and the primary databases used to collect and store personal data of Russian citizens are located in Russia. Cross-border transfer of personal data is not performed under the current processing arrangements. Before such transfers are introduced, the operator must complete the applicable legal and organizational steps and update this policy where required.
8. Storage periods
- technical cookies are stored for up to one year;
- local browser preferences remain until the user changes or deletes them or the browser clears its storage;
- server logs are stored within the hosting provider's rotation period, and longer only when required to investigate an incident, protect legal rights or comply with law;
- raw Matomo visit logs are stored for up to 180 days;
- an enquiry that does not lead to an agreement is stored for up to one year after the last substantive correspondence;
- contractual, accounting and tax records are stored for at least five years after the relevant reporting year or longer where required by law;
- published materials are used until the purpose is achieved, publication ends or consent is withdrawn, unless another legal ground applies.
After the applicable period, data is deleted, destroyed or anonymized unless continued storage is required by law.
9. Enquiries that do not lead to an agreement
A person may voluntarily include a name, telephone number, email address or other contact details in an email. The operator uses this information to reply, discuss the matter and, where appropriate, prepare a proposal or agreement.
If no agreement is entered into and there is no separate legal ground for retaining a professional contact, the correspondence is deleted no later than one year after the last substantive interaction.
10. Data subject rights
A data subject may request information about processing, request correction, restriction or deletion of data, withdraw consent where processing is based on consent, and lodge a complaint with the Russian data protection authority or a court.
To make a request, write to info@vlasovlab.ru and identify the data, enquiry or published material to be checked.
11. Security
The operator applies legal, organizational and technical measures to protect personal data from unauthorized access, modification, disclosure, copying, blocking, deletion, destruction and other unlawful actions. Access is limited to persons who require it for a specific function.
The measures include access control and password protection, anti-malware protection, hosting-provider network controls, protected TLS/HTTPS connections, backups, qualified electronic signatures for electronic document management, software updates and internal review of data handling practices.
12. Policy changes
This policy is updated when processing purposes, data categories, storage periods, service providers or legal requirements change. The current version is published on this page.