Policy on the Processing of Personal Data
Version of 15 September 2026.
This is an unofficial translation of the Russian original, provided for information only. The Russian text published at denizsincar.ru/privacy is the legally binding version; in case of any discrepancy, the Russian text prevails.
1. General provisions
1.1. This Policy defines which personal data are processed on the websites and services listed in Section 2 (the “Services”), for what purposes, on what legal basis, for how long and by what measures they are protected.
1.2. The operator of personal data is Deniz Sincar (Синджар Дениз), a natural person. Address for enquiries: e-mail deniz.sincar@mail.ru (the “Operator”).
1.3. The Policy is drawn up in pursuance of clause 2 of part 1 of article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (the “Law”) and is published for public access at https://denizsincar.ru/privacy.
1.4. The terms “personal data”, “operator”, “data subject”, “processing of personal data”, “depersonalisation”, “destruction of personal data” and others are used in the meanings defined by article 3 of the Law.
1.5. The Operator processes personal data on a lawful and fair basis, only for the purposes named in Section 4 and only to the extent necessary for those purposes. Data going beyond the stated purposes are not processed.
2. Services covered by the Policy
2.1. The Policy applies to the following Services of the Operator:
- document cloud — https://mdcloud.denizsincar.ru;
- forms and surveys service — https://forms.denizsincar.ru;
- voice server registration system — https://tt.denizsincar.ru;
- source code repository — https://gitea.denizsincar.ru;
- other Services of the Operator on denizsincar.ru subdomains, where their use requires creating an account or entering information about a person. Services that do not collect information about people do not process personal data and are not covered by this Policy.
2.2. Where a service processes data on the instructions of another person, that person is the operator of the personal data and their own policy applies.
3. Categories of data subjects
3.1. Data subjects are:
- users of the Services who have created an account;
- persons who have filled in a form or a survey;
- persons who have left a comment on a document;
- persons who have contacted the Operator.
4. Purposes of personal data processing
4.1. Maintaining accounts: registration, sign-in, access recovery, separation of rights.
4.2. Working with documents: storage, display, granting access to another user at the document owner's choice, comments.
4.3. Conducting surveys and receiving answers: storing completed forms and providing their results to the person who published the form.
4.4. Operating the voice server: creating and maintaining accounts, issuing connection data.
4.5. Operating the source code repository: accounts, access to repositories.
4.6. Responding to user enquiries.
4.7. Protecting the Services from automated attacks and spam.
4.8. Performing the duties imposed on the Operator by the legislation of the Russian Federation.
4.9. Personal data are not used for advertising, are not transferred to third parties for marketing purposes, are not used for profiling and are not sold.
5. Composition of the personal data processed
5.1. The following data are processed for each service.
5.2. Document cloud (mdcloud.denizsincar.ru):
- login — the account name the user chooses;
- password — stored as an irreversible hash; the original password is not available to the Operator;
- e-mail address — if the user has provided one;
- display name — if the user has provided one;
- the content of documents, comments and document access settings;
- technical data: session identifier in a cookie, irreversible hash of the IP address, date and time of actions.
5.3. Forms and surveys service (forms.denizsincar.ru):
- the information the user enters in the form, to the extent determined by the form itself;
- the user name given when filling in the form;
- technical data: session identifier in a cookie, date and time of completion.
5.4. Voice server registration system (tt.denizsincar.ru):
- login;
- password — stored as an irreversible hash;
- information about the access granted to the voice server;
- technical data: date and time of the request.
5.5. Source code repository (gitea.denizsincar.ru):
- account login and e-mail address;
- password — stored as an irreversible hash;
- actions in the repository necessary for its operation.
5.6. Special categories of personal data (concerning health, nationality, political views, religious beliefs) and biometric personal data are not processed by the Operator.
5.7. Raw IP addresses are not stored in the databases. To protect against spam, a hash of the IP address computed with a secret salt may be stored; the original address cannot be recovered from it.
5.8. The Operator does not verify the accuracy of the data provided by the user. The user is responsible for what information, including data about third parties, they place in documents, forms and comments.
6. Legal grounds for processing
6.1. Processing is carried out on the basis of:
- the consent of the data subject (clause 1 of part 1 of article 6 of the Law), given when an account is created or a form is submitted;
- the requirements of the Law and of the normative legal acts adopted in accordance with it that are binding on the Operator.
6.2. Consent is given once and covers the data listed in Section 5. The subject may withdraw consent at any time by sending a request to the address given in clause 1.2.
7. Procedure and conditions of processing
7.1. Processing is carried out with the use of automation tools.
7.2. Actions performed with the data: collection, recording, systematisation, accumulation, storage, clarification (updating, change), extraction, use, blocking, deletion, destruction.
7.3. The databases and the equipment on which the Services run are located in the territory of the Russian Federation. No cross-border transfer of personal data is carried out.
7.4. Retention periods:
- account data — until the account is deleted;
- documents — until the owner deletes the document; a document created for a limited period is deleted automatically when that period expires, together with its comments;
- comments — until the comment, the document or the account is deleted;
- answers to forms and surveys — until the form is deleted by the person who published it;
- session — until it expires (no more than 30 days) or until the user signs out;
- IP address hash — until the corresponding record is deleted.
7.5. Personal data are provided to third parties only on requests provided for by the legislation of the Russian Federation.
7.6. The technical hosting of the Services is provided by the hosting provider Phoenix901 (formerly Loveprod-Host), whose servers are located in the Russian Federation.
7.7. The Services use one mandatory cookie — the session identifier. It is needed to sign in to an account, is marked httpOnly and Secure and is not used for analytics, advertising or tracking. No third-party analytics or advertising systems are installed on the Services.
8. Security measures
8.1. The Operator is responsible for organising the processing of personal data.
8.2. The security of processing is ensured in accordance with the Law, Decree of the Government of the Russian Federation No. 1119 of 1 November 2012 and Order of the FSTEC of Russia No. 21 of 18 February 2013.
8.3. The following measures are applied:
- the connection to the Services is protected by HTTPS, HSTS is enabled;
- passwords are stored as a hash produced by the bcrypt algorithm;
- the session cookie is marked httpOnly, Secure and SameSite=Lax, and its value is stored in the database as a hash;
- the number of requests to the Services is limited, which makes password guessing and mass submission of data harder;
- access to documents is separated: a private document is not given to anyone except the owner and the person to whom the owner has sent it;
- only the Operator has access to the servers and databases;
- no log of requests to the Services is kept in persistent storage.
8.4. The Operator has assessed the harm that may be caused to data subjects (clause 8 of part 2 of article 18.1 of the Law).
9. Rights of the data subject
9.1. The subject has the right to:
- receive information about the processing of their personal data;
- demand clarification, blocking or destruction of the data if they are incomplete, outdated, inaccurate, obtained unlawfully or not needed for the stated purpose;
- withdraw consent to processing;
- appeal against the Operator's actions to Roskomnadzor or to a court.
9.2. A request is sent to the e-mail address given in clause 1.2 and must contain information allowing the applicant to be identified (login) and the substance of the demand.
9.3. The Operator considers a request within the following periods:
- a notice that personal data exist — no later than ten working days from the date the request is received;
- clarification, blocking or destruction of data, as well as termination of processing upon withdrawal of consent — no later than thirty days.
9.4. An account is deleted at the request of the subject. The documents and comments associated with the account are deleted together with it.
10. Final provisions
10.1. The Policy is valid indefinitely until replaced by a new version.
10.2. The Operator may amend the Policy. The new version is published at the address given in clause 1.3, stating the date.
10.3. The Operator monitors compliance with the Policy.