{
    "status": "ok",
    "document": {
        "doc": "privacy",
        "label": "Privacy Notice / Политика обработки персональных данных",
        "requested_language": "en",
        "source_language": "en",
        "source_file": "privacy_v4.php",
        "version": "4",
        "effective_date": "2026-09-03",
        "html_url": "https://voscom.online/legal/en/privacy_v4.php",
        "text_url": "https://voscom.online/legal_text.php?lang=en&doc=privacy",
        "json_url": "https://voscom.online/legal_text.php?lang=en&doc=privacy&format=json",
        "sha256_text": "ec4a7ac7715b4c4d052599e57a8601b7199226e72c4804249f2dc8810b424abd",
        "sha256_source_file": "67315ab2de7c9c534855962c3fbf1a9f1999129f180803df452a4753ec5746d3",
        "last_modified": "2026-09-03T15:56:43+00:00",
        "text": "VOSCOM.ONLINEAll documentsVersion historyMy consents\n\n# Privacy Policy\n\nVersion: 4\nEffective date: 2026-09-03\n\nEnglish translation. The Russian edition is authoritative in the event of a discrepancy to the extent permitted by applicable law.\n\nTXT · JSON\n\n## 1. Scope\n\nThis Policy describes personal-data processing by the unified Russian-operated VOSCOM.ONLINE / VOSCOM AI FORGE service: site, IDE, AI, projects, builds, news, market, task board, support and communications. It is based on 152-FZ and other applicable Russian law. Reading this notice does not replace separate consent.\n\n## 2. Operator\n\nVOSCOM-ONLINE LLC (ООО «ВОСКОМ-ОНЛАЙН»), Russian Federation; OGRN 1217700640189, INN 9719021912, KPP 771901001. Registered address: 105484, Moscow, municipal district Vostochnoye Izmaylovo, Sirenevy Boulevard, building 50, apartment 72.\n\nData and security: admin@voscom.online. Support and contracts: support@voscom.online.\n\n## 3. Definitions\n\nPersonal data identifies or relates to an identifiable individual. Processing includes collection, recording, storage, use, provision, dissemination, restriction and erasure. Dissemination makes information available to an indefinite audience; a private message is not the same as public publication.\n\n## 4. Principles\n\nProcessing must be lawful, purpose-limited, proportionate and accurate, with retention limited to its purpose and applicable legal obligations. Incompatible purposes must not be combined without a lawful basis.\n\n## 5. Data subjects\n\nVisitors, registered users, organisation representatives, support applicants, project and publication authors, customers and counterparties where a relevant service is used. Account access follows the platform’s 18+ policy.\n\n## 6. Data categories\n\nAccount details include username, email, password hash, language, role, consent history and security metadata. Optional profile data includes avatar, description and skills. Requested functions may involve projects, source files, build logs, AI questions and answers, conversation context, community and private messages, support enquiries, balance operations and order information.\n\nSpecial-category data, biometric identification and children’s data are not requested for normal account creation. Do not place such data or third-party secrets in uploaded materials without a separate lawful basis.\n\n## 7. Purposes, data, grounds and duration\n\nAccounts and requested functions. Visitors, users and organisation representatives: username, email, password hash, role, language, account ID, projects, settings, operation history and internal balance. Basis: contract performance or requested pre-contract steps, and separate consent where applicable. Duration: until the relationship or purpose ends, then only on a separate lawful basis.\n\nSecurity and evidence. Visitors and users: IP, limited user agent, timestamps, login/error events and accepted document versions. Basis: protection of legitimate interests while respecting subjects’ rights and compliance with mandatory duties. Duration: as necessary for security, incident handling or rights protection, not indefinitely without purpose.\n\nSupport, projects and AI. Users and applicants: enquiry content, contact, requested files, questions, answers and sent context. Basis: handling the request/contract and separate consent where applicable. Duration: until the enquiry and related obligations end or materials are deleted, with limited necessary retention for disputes or law.\n\nAuthor-name publication. Authors of public materials: only the selected username. Basis: separate dissemination consent. Duration: until withdrawal or change. Registration does not grant this permission.\n\nOptional analytics. Visitors: random identifier, pages, tabs, durations and browser metadata. Basis: separate analytics choice. Duration: as necessary for the stated analytics purpose; future sending stops upon refusal and the choice is stored for up to 180 days.\n\nBilling and mandatory records. Customers or representatives: order ID, amount, balance operations and contact/contract details relevant to the transaction. Basis: contract and statutory recordkeeping. Duration: the legally applicable period for the record type; this does not justify keeping an entire AI conversation with an invoice.\n\n## 8. Legal grounds\n\nThe basis is determined for each purpose: consent, contract/request performance, a legal duty or lawful legitimate-interest protection. Consent does not authorise all processing. Advertising messages and public dissemination are not included in registration.\n\n## 9. Processing operations\n\nProcessing may be automated or involve authorised staff: collection, recording, organisation, storage, correction, retrieval, use, necessary provision to recipients, restriction, erasure and anonymisation. Public dissemination requires its separate legal basis.\n\n## 10. Storage and localisation\n\nThe production service’s primary database is in the Russian Federation. Russian citizens’ data collection is subject to statutory localisation requirements for the specified operations. This is not a claim that every backup, email-processing operation or external AI provider is exclusively in Russia. Internal infrastructure addresses and secrets are not published.\n\n## 11. Recipients and processors\n\nAuthorised staff and hosting, mail delivery, support and selected AI suppliers may access data as necessary. Integrations include Reg.cloud, browser-based Qwen and users’ own API providers; the route depends on the selected mode. Optional analytics uses a first-party tracker and Yandex Metrica when enabled.\n\nProcessing arrangements must define purposes, data, actions, confidentiality and security. Lawful authority requests are handled through the prescribed process. No unverified regulatory filing or registration status is asserted.\n\n## 12. External and cross-border processing\n\nMail and AI integrations may involve external suppliers, including outside Russia. Separate statutory transfer requirements apply; a general checkbox does not replace them. Ask admin@voscom.online about recipients, purposes and legal grounds for a particular transfer. Do not send third-party personal data or secrets to optional AI functions without an appropriate basis.\n\n## 13. AI, projects and communications\n\nWhen connecting a personal API key or third-party AI service, users choose the provider and must consider its terms and data practices. Do not supply materials or third-party data without the required rights and legal basis. The platform sends the selected model the request and necessary context, including conversation history and requested project excerpts. This does not remove the Operator’s own data-protection duties; consent does not replace specific cross-border transfer requirements.\n\nAI questions, answers, session context, messages and logs are stored for continuity, support and diagnostics. When service notifications are enabled, enquiries and AI answers may be emailed to the administrator. An AI request is therefore not a secret channel accessible only to the model.\n\nPrivate projects are not automatically published. Community messages are visible to channel participants; private messages to their participants, with authorised staff technical access for maintenance and violation investigation. Public-name consent concerns open pages, not name visibility within private messaging.\n\n## 14. Cookies\n\nNecessary cookies and settings support sessions and requested functions. Analytics requires a separate choice. See the Cookie Notice.\n\n## 15. Ending processing and retention\n\nPurpose-specific criteria are set out in section 7. Once a purpose ends or consent is withdrawn, processing on that basis stops and data must be erased, destroyed or anonymised as required by law unless another basis applies. Limited retention for a specific dispute or mandatory records does not permit continued publication.\n\nDeleting a project in the interface may hide and mark it for recovery rather than physically destroy every file. Send final personal-data erasure requests to admin@voscom.online. This Policy does not claim a universal automatic deletion job already enforces all retention periods.\n\n## 16. Rights and withdrawal\n\nYou may request processing information, access, correction, restriction or erasure, withdraw consent, restrict dissemination and contact Roskomnadzor or a court. Use admin@voscom.online or consent settings. Specify the account and request; do not send passwords or private keys. Proportionate identity checks may be needed.\n\nWithdrawal does not invalidate earlier lawful processing or remove independent contractual or statutory grounds. Loss of an optional function after refusal does not remove complaint or legal-protection rights.\n\n## 17. User responsibilities\n\nProvide accurate account information, protect credentials and do not upload other persons’ data without rights and lawful grounds. These responsibilities do not remove the Operator’s own duties.\n\n## 18. Security measures\n\nThe code uses password hashing, sessions, access and CSRF checks, request limits and audit. Security also requires organisational measures, access review, updates and retention management. Individual controls do not guarantee incident-free operation or prove every organisational procedure is in place.\n\n## 19. Incidents\n\nReport incidents to admin@voscom.online without publishing secrets or other persons’ data. The Operator must follow applicable incident law, including required notifications and periods; this document does not claim a previous notification was filed.\n\n## 20. Changes\n\nNew editions are published with a version and effective date; earlier editions remain in the history. Material changes are notified in the interface. Separate consent is requested where necessary; using the site does not itself provide personal-data or public-disclosure consent. Changes do not impair accrued mandatory rights or alter an agreed paid price or term without a lawful basis.\n\n## 21. Contacts\n\nVOSCOM-ONLINE LLC (ООО «ВОСКОМ-ОНЛАЙН»), Russian Federation; OGRN 1217700640189, INN 9719021912, KPP 771901001. Registered address: 105484, Moscow, municipal district Vostochnoye Izmaylovo, Sirenevy Boulevard, building 50, apartment 72.\n\nadmin@voscom.online for data and security; support@voscom.online for support."
    }
}