PRIVACY POLICY AND PERSONAL DATA PROCESSING
Effective date: July 9, 2026
This Privacy Policy and Personal Data Processing Policy defines the procedure for processing personal data on the website grapelab.ru (hereinafter — the “Website”).
1. Data Controller Information
The data controller is:
- Individual Entrepreneur Gilka Vadim Viktorovich (ИП Гилка Вадим Викторович)
- TIN:
344411774883 - OGRNIP:
326344300012089 - Legal address:
400065, Russia, Volgograd Region, Volgograd, Ul. Opolchenskaya, d. 49, kv. 64 - Email:
grapelaboratory@gmail.com
2. Purposes of Personal Data Processing
Personal data on the Website is processed for the following purposes:
- ensuring the correct operation of the Website;
- ensuring the security of the Website;
- publishing information about GrapeLab team members;
- presenting the GrapeLab team, its competencies and areas of activity;
- providing translated review content in different languages;
- providing access to the Website’s administrative panel;
- maintaining security logs and auditing actions in the administrative panel;
- restricting unauthorized access attempts to the administrative panel.
3. Legal Basis for Personal Data Processing
The legal bases for personal data processing are:
- the legitimate interest of the data controller in ensuring the correct operation and security of the Website with respect to technical data automatically transmitted when visiting the Website (Article 6, Part 1, Paragraph 5 of Federal Law No. 152-FZ);
- written consent of the personal data subject to the processing of information about team members published on the Website (Article 9 of Federal Law No. 152-FZ);
- written consent of the personal data subject to the processing of personal data contained in published reviews, if such data is present in the review text (Article 9 of Federal Law No. 152-FZ);
- the legitimate interest of the data controller in providing access to the administrative panel, protecting the administrative part of the Website, logging security events, and preventing unauthorized access (Article 6, Part 1, Paragraph 5 of Federal Law No. 152-FZ).
4. Categories of Personal Data Subjects
The controller processes personal data of the following categories of subjects:
- Website visitors;
- GrapeLab team members;
- persons who have left reviews published on the Website;
- users of the Website’s administrative panel.
5. List of Processed Personal Data
The following data may be processed as part of the Website’s operation:
5.1. Website Visitor Data
- IP address;
- browser and device information;
- date and time of access;
- addresses of visited pages.
5.2. GrapeLab Team Member Data
- first name;
- last name;
- photograph;
- description of professional activity;
- work directions in the form of tags and hashtags.
5.3. Data Contained in Reviews
- review text;
- first and last name of the review author;
- position or other description of the review author’s role, if such information is provided.
5.4. Administrative Panel User Data
- name or other designation of the administrative panel user;
- email address;
- password hash;
- technical data related to authorization and ensuring the security of the administrative panel, including IP address (or other network identifier of the request source), date and time of the event, information about login attempts and actions in the administrative panel.
6. Methods of Personal Data Processing
Personal data is processed in the following ways:
- receiving and processing server requests as part of the Website’s standard operation;
- storing and displaying information about team members on the Website pages;
- displaying reviews on the Website pages;
- automated translation of review texts and related text fields to provide localized content;
- providing access to the administrative panel;
- logging authorization events and actions in the administrative panel;
- applying technical restrictions to protect the administrative panel from repeated failed login attempts;
- using an embedded third-party mapping service iframe on the “Contacts” page.
7. Terms of Personal Data Processing and Storage
Personal data is processed and stored for the following periods:
- technical data of Website visitors is not stored separately as an independent array of personal data and is processed at the time of access to the Website;
- team member data is stored until the corresponding record is deleted by the Operator;
- data contained in reviews is stored until the corresponding review is deleted by the Operator;
- the automatic review translation cache is stored for the entire period of placement of the corresponding reviews on the Website;
- administrative panel user data is stored for the duration of the corresponding access and thereafter to the extent necessary to comply with security requirements and internal accounting;
- administrative panel audit logs are stored for up to 180 days;
- data used to restrict repeated failed login attempts to the administrative panel is stored for the period necessary for the operation of the corresponding security mechanisms;
- in case of information removal from the Website, the corresponding personal data must be deleted within 30 days, unless a different period is required by law.
8. Transfer of Personal Data to Third Parties
The controller does not transfer personal data to third parties, except in the following cases:
- when such transfer is necessary for the operation of individual Website functions;
- when the transfer is caused by the use of embedded third-party services;
- when the obligation to transfer is provided for by the legislation of the Russian Federation.
The Website uses an embedded Yandex.Maps service, when loading which certain technical data of the user may be transferred to the corresponding service.
9. Personal Data Security Measures
The controller takes the necessary organizational and technical measures to protect personal data from:
- unauthorized access;
- modification;
- disclosure;
- destruction;
- other unlawful actions.
Such measures include:
- storing passwords in hashed form (bcrypt);
- limiting the session lifetime of the administrative panel (JWT, no more than 8 hours);
- restricting the number of failed login attempts to the administrative panel with progressive blocking;
- logging authorization events and actions in the administrative panel;
- configuring HTTP security header policies (Content-Security-Policy, X-Frame-Options, Referrer-Policy, etc.);
- restricting access to the administrative panel to authorized users only.
10. Cross-Border Transfer of Personal Data
Cross-border transfer of personal data may occur on the Website in the following case:
- when using an external translation service for localization of reviews.
If personal data is contained in review texts, such data may be transferred to the servers of the external translation service provider for the purpose of translation.
11. Contacts of the Person Responsible for Personal Data Processing
For questions regarding personal data processing, you can contact:
- Full name: Gilka Vadim Viktorovich
- Email:
grapelaboratory@gmail.com
12. Procedure for Responding to Requests of Personal Data Subjects
A personal data subject has the right to submit a request regarding:
- clarification of personal data;
- modification of personal data;
- deletion of personal data;
- withdrawal of consent to personal data processing, if the processing is based on consent.
In addition, a personal data subject has the right to:
- request information about the processing of their personal data, including the purposes, methods, and storage periods of processing (Article 14 of Federal Law No. 152-FZ);
- receive information about the fact of transfer of their personal data to third parties, as well as the scope and purposes of such transfer;
- challenge the actions or inaction of the Operator with the Authorized Body for the Protection of the Rights of Personal Data Subjects (Roskomnadzor) or in court.
Contact details of Roskomnadzor:
- website: https://pd.rkn.gov.ru;
- email: list@pd.rkn.gov.ru.
Requests are accepted by email:
- Email:
grapelaboratory@gmail.com
Requests are processed by the Operator manually. For each request, the Operator takes the necessary actions (clarification, modification, deletion of personal data) within its technical and organizational capabilities.
The response time to a request is up to 30 calendar days from the moment of its receipt.
13. Procedure for Destruction of Personal Data
Destruction of personal data is carried out by deleting the relevant data from the information systems and database of the Website used.
The period for destruction of personal data is no more than 30 days from the moment of:
- achievement of the processing purpose;
- cessation of placement of the relevant data on the Website;
- receipt of a proper request from the personal data subject, if there are no other legal grounds for further processing.
14. Effective Date
The current version of this Policy is effective from July 9, 2026.
15. Procedure for Amending the Policy
The controller reserves the right to make changes to this Policy.
The current version of the Policy is always posted on the Website.
16. Personal Data Anonymization
Personal data anonymization is not carried out on the Website.
17. Automated Processing of Personal Data
Automated processing of personal data is permitted to the extent necessary for the functioning of the Website and the provision of its content.
Automated decision-making based solely on automated processing of personal data that produces legal effects is not carried out.