Legal information
Personal data processing policy
How Wicsora LLC (convenience translation) processes data for digitalrur.ru and requested subscriptions.
Effective: 6 August 2026
Version: 2026-08-06
Last review: 6 August 2026
1. General provisions
This policy of ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ВИКСОРА" describes personal-data processing on digitalrur.ru, requested subscriptions, and voluntary email enquiries. Effective date: 6 August 2026. Version: 2026-08-06.
2. Operator
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ВИКСОРА" (Wicsora LLC (convenience translation)), OGRN 1262300031773, INN 2373029310, KPP 237301001. Registered locality: Plastunovskaya, Dinskoy Municipal District, Krasnodar Krai, Russian Federation. Contact: privacy@wicsora.ru.
3. Definitions
Personal data means information relating to an identified or identifiable person; processing means operations performed on it; the operator determines purposes, data, and operations.
4. Data-subject categories
- website visitors;
- people requesting and confirming a subscription;
- people requesting free test access;
- people managing preferences or unsubscribing;
- senders of voluntary email enquiries;
- authorised administration users.
5. Data categories
- email, language, and selected topics;
- for a trial request: name, role, optional organisation, use case, and interests;
- consent status, versions, time, and source;
- route and form type;
- keyed IP and user-agent hashes for protection;
- technical logs, delivery, and unsubscribe events;
- voluntary enquiry content.
6. Purposes
- confirm and deliver selected updates;
- receive, confirm, manually review, and manage a trial application;
- manage preferences and unsubscribe;
- evidence consent;
- prevent abuse;
- maintain availability and investigate incidents;
- review and answer enquiries.
7. Legal bases
The operator relies, as applicable, on the person’s explicit request and consent, steps needed to supply the requested service, legal obligations, and legitimate security interests. Advertising requires a separate basis.
8. Operations
Collection, recording, organisation, storage, correction, retrieval, use, authorised processor access, restriction, erasure, and destruction. Public dissemination is not a purpose.
9. Collection sources
Data comes directly from the person through a form or email; technical data comes from the browser, network connection, and server components during service use.
10. Processing methods
Processing is mainly automated, with staff involvement for administration, support, security, and enquiries. No decision with legal effects is based solely on automated processing.
11. Website forms
The subscription form collects email, language, topics, and separate consents. The free-trial form collects name, email, role, optional organisation, use case, and interests. Required processing consent is separate from optional marketing consent; the site does not request payment-card data, identity documents, or sensitive information.
12. Email communications
Voluntary enquiries go to contact@wicsora.ru. Do not send passwords, payment information, documents, or unnecessary sensitive data. Content is used to route and answer the enquiry.
13. Subscriptions and alerts
Double opt-in is used. Before confirmation, only the user-initiated confirmation message is sent. Topics can be changed and optional mail stops through the unsubscribe link.
14. Technical logs
Server logs may record time, route, outcome, minimised technical identifiers, and error information. Secrets, full tokens, and email content must not appear in ordinary logs.
15. Cookies and analytics
The site uses no third-party analytics, advertising cookies, session replay, or marketing pixels. Optional first-party analytics may run only after separate affirmative consent and operator enablement. It uses a random pseudonymous browser identifier, page/interaction events, normalized path, language, acquisition source, coarse device category, and active time; it does not retain IP, full user agent/referrer, query/fragment, form values, or email and is not linked to a subscriber/account. Before consent and after withdrawal there is no analytics request or identifier. The cookies policy explains the controls.
16. Hosting and infrastructure
The actual production VM, database, object storage, backups, logs, and SMTP must be verified through the deployment checklist before collection is enabled. This policy does not replace that check.
17. Processors
Access may be granted only to approved hosting, infrastructure, backup, and email providers under documented instructions and to the necessary extent. Unverified providers are not approved for production processing.
18. Cross-border transfers
A cross-border transfer is not stated as necessary for subscription operation. Before adding a foreign recipient, the operator must establish a legal basis, complete applicable notices, and update the processor register and this policy.
19. Russian localization
Where Russian law requires it, the recording, organisation, accumulation, storage, correction, and retrieval of Russian citizens’ personal data collected online must initially use databases located in the Russian Federation.
20. Retention
- unconfirmed encrypted email: until the 24-hour link expires and cleanup runs;
- active subscription: until withdrawal or service termination;
- address after unsubscribe: erased while a minimum suppression hash remains;
- pseudonymous analytics events: proposed 90 days; non-identifying aggregates: proposed 730 days; final periods require approval before production collection;
- consent, delivery, security, log, and enquiry records: under the approved schedule, which is a production gate.
21. Erasure and anonymisation
When a purpose is achieved, consent is withdrawn, or a term ends, data is erased, destroyed, or anonymised except for minimum information lawfully retained for suppression, security, and legal protection.
22. Rights
- obtain information about processing;
- request correction, restriction, or erasure where applicable;
- object to or restrict processing where provided by law;
- complain to the operator, competent authority, or a court.
23. Withdrawal
Unsubscribe without signing in through the unique email link; withdraw other consent by contacting privacy@wicsora.ru. Withdrawal does not invalidate earlier lawful processing.
24. Requests and complaints
State the subject, subscribed email, and enough information to verify authority. Do not send unnecessary documents. Proportionate identity verification may be requested before data is disclosed or changed.
Requests are accepted at privacy@wicsora.ru. Identify the subject and a reply address; do not send unnecessary documents or sensitive information.
25. Security measures
- role-based access;
- email and secret encryption;
- keyed identifier hashes and high-entropy tokens;
- CSRF/origin controls and rate limiting;
- auditable consent events;
- backups, restoration, logging, and updates.
26. Policy changes
The document is reviewed before a material change in purposes, data, recipients, or technology. A new version is dated and does not retroactively authorise an incompatible purpose.
27. Contact and language
Requests are accepted at privacy@wicsora.ru. Identify the subject and a reply address; do not send unnecessary documents or sensitive information.
For relationships governed in the Russian Federation, the Russian text controls. This English version is supplied for convenience.
Wicsora LLC (convenience translation) is the DigitalRUR operator and publisher. DigitalRUR is not a Bank of Russia or government website.
Document and privacy enquiries: privacy@wicsora.ru.