Skip to content
vb.tech
case studiesexpertiseapproachaboutdiscuss a project
RU / EN
Draft. This document is not in force. No effective date. Submission is disabled.

VBT-PD-01

Personal Data Processing Policy — Draft

This draft describes only the intended processing of a visitor's data when that visitor chooses to send a future v-b.tech project enquiry.

Code
VBT-PD-01
Identity
VBT-PD-01/DRAFT
Status
draft

1. Controller and scope

Intended controller: Богатырев Владислав Сергеевич; postal address: 353745, Краснодарский край, Ленинградский район, ст. Ленинградская, ул. Грузская, д. 26; email: hello@v-b.tech; phone: +7 934 355-14-90; site: https://v-b.tech.

The policy is limited to v-b.tech and its future project enquiry form. Data subjects are visitors who choose to send an enquiry. This document is a draft, is not in force, and does not itself permit enquiries to be accepted.

2. Definitions, principles, and applicable rights

Personal data
information relating directly or indirectly to an identified or identifiable natural person.
Processing
an operation or set of operations on personal data, with or without automated means.
Restriction
temporary suspension of processing except where processing is needed to correct the data.
Destruction
operations after which data cannot be restored in the information system.

Processing must be lawful, fair, limited to stated purposes and the minimum necessary data, accurate, time-bounded, and protective of the data subject's rights under applicable requirements.

3. Data subjects and visitor-provided data

A visitor will be able to provide only a name of no more than 100 characters, a contact value as email or @telegram of no more than 254 characters, and a message of no more than 4,000 characters. Attachments are not accepted.

Visitors should not send passwords, payment details, legally protected secrets, special-category personal data, or other unnecessary confidential information.

4. Bounded operational data

  • the enquiry UUID, locale, and source path from a closed allow-list;
  • the consent identity and submission and delivery timestamps;
  • the captcha verification outcome and a short-lived keyed HMAC digest of the bounded network source for a fixed rate-limit window;
  • delivery state and bounded provider message identifiers.

The raw IP address must not be persisted in the application database. During verification SmartCaptcha may receive only the verification token and the minimum network context required; no name, contact, or message is sent to it.

The enquiry UUID is used only as a bounded correlation identifier. For the intended flow, application telemetry and logs must be limited to event kind, enquiry UUID, stage, status, and latency; they must exclude the user-provided fields — name, contact, and message — and any other personal body data, captcha token, and secrets. No hidden enrichment is intended, and arbitrary referrers and marketing parameters must not be retained.

5. Purposes and explicit exclusions

  • replying to the enquiry and clarifying it;
  • conducting directly related business correspondence;
  • sending a transactional receipt only when the contact is email;
  • preventing automated abuse;
  • securing and diagnosing the service.

This release provides no advertising, newsletter, analytics, profiling, lead enrichment, data sale, CRM transfer, or unrelated reuse.

6. Grounds and separate-consent boundary

Processing for the form does not begin until the form is enabled in the future. A voluntarily sent enquiry is intended to rely on a separate active revision of consent VBT-PD-02. VBT-PD-02/DRAFT is not active and cannot be accepted by a visitor.

After correspondence begins, a specific operation may have another applicable ground only if it actually exists and is documented; this draft does not claim such a ground in advance.

7. Operations and processing methods

Intended operations are collection, recording, organization, accumulation, storage, correction, retrieval, use, necessary transfer to engaged processors, restriction, erasure, and destruction. Processing is mixed: automated and, for correspondence, without automated means.

8. Retention, restriction, erasure, and destruction

The enquiry and related business correspondence are intended to be retained for no more than one year after the last substantive contact unless another documented ground applies. Substantiated subject requests for restriction, erasure, or destruction are handled separately.

The encrypted delivery payload must be erased on a short schedule after a terminal outcome. Bounded technical delivery history is retained only for an operational term and does not replace separate correspondence management.

9. Providers and intended roles

Yandex Cloud
hosting, function, database, and secret infrastructure acting on the controller's instructions.
Postbox
transactional message delivery to the necessary extent.
SmartCaptcha
automated-abuse protection only when online submission is enabled.
The controller's mailbox provider
receipt and storage of directly related business correspondence.

The exact contracting entities, roles, processing regions, and current terms for every provider must be reverified before activation. This list does not confirm that any particular agreement exists or what it contains.

10. Russian localization and cross-border transfer

For the future configuration, primary collection, recording, organization, accumulation, storage, correction, and retrieval of Russian citizens' data must use databases located in the Russian Federation.

No cross-border transfer is intended. It cannot be enabled without a separate review of recipients, grounds, procedures, and updated documents before such transfer begins.

11. Security and incidents

Intended measures include access controls, data isolation, secret protection, encryption of delivery payloads, change controls, backups, bounded logging, and retention limits proportionate to the data and current threats, without publishing details that could weaken defenses.

For a confirmed incident, the controller must contain consequences, preserve necessary evidence, make applicable notifications, and correct the cause.

12. Access, correction, restriction, erasure, and withdrawal

A request for access, correction, restriction, erasure, destruction, or consent withdrawal may be sent to hello@v-b.tech or the controller's postal address. To protect data, the controller may request enough information to verify identity and locate the enquiry.

Withdrawal does not invalidate processing performed before receipt. Limited continuation is possible only under another applicable ground and is explained for the specific request.

13. Browser storage, logs, and captcha

The strictly necessary vbtech-theme-v1 local record stores the theme choice. The site uses no analytics or advertising cookies. The enquiry UUID is used only as a bounded correlation identifier. Server and application telemetry and logs must be limited to event kind, enquiry UUID, stage, status, and latency and must exclude the user-provided fields — name, contact, and message — and any other personal body data, captcha token, and secrets.

SmartCaptcha and its resources may load only when online submission is enabled; during verification it may receive the verification token and the minimum network context required, but no name, contact, or message is sent to it. Before submission is enabled, captcha is inactive and receives no data.

14. Revisions, language, and draft status

Document code: VBT-PD-01. Candidate identity: VBT-PD-01/DRAFT. No public revision has been assigned and no effective date exists. This document is a draft, is not in force, and does not establish legal approval.

After activation, the Russian text of a specific published revision will be authoritative. This English text is an informational translation of the matching Russian text. A replacement revision is published as a separate identity after renewed review.

Back to legal register

vb.tech

Products that keep working when conditions stop being ideal.

Legal registerPrivacy policyPersonal data consent
RU / EN

GitHubEmail