PRIVACY POLICY

Legion Laboratory website — https://legionlaboratory.ru/
Version 1.0 dated 10 August 2026

This Privacy Policy sets out the procedure for processing and protecting personal data by Individual Entrepreneur Mikhail Mikhailovich Milovanov (the “Controller”) when the Legion Laboratory website is used, including its Russian and English versions, contact forms, and related communications.

1. GENERAL PROVISIONS

Website: https://legionlaboratory.ru/, including the /en page and the legal pages /privacy, /consent, /en/privacy and /en/consent.

Controller: Individual Entrepreneur Mikhail Mikhailovich Milovanov, OGRNIP 325547600019233, INN 540438208403.

Data protection contact details: kerkeen@mail.ru; telephone +7 (995) 011-97-21; Telegram: https://t.me/legion_laboratory.

This Policy has been prepared in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and other applicable legal requirements. For visitors located in the European Economic Area, the United Kingdom or Switzerland, mandatory provisions of the applicable data protection laws also apply.

The current version is available at https://legionlaboratory.ru/en/privacy. If the categories of data, purposes or connected services materially change, this Policy will be updated before the new processing begins.

2. KEY DEFINITIONS

Personal data means any information relating directly or indirectly to an identified or identifiable individual.

Processing means any operation or set of operations performed on personal data, including collection, recording, organisation, accumulation, storage, updating, retrieval, use, transfer, anonymisation, restriction, deletion and destruction.

Cookies and other browser data are small records stored in a browser or other local storage on a device that enable the website to operate, remember the user’s choices and, where consent has been given, generate website usage statistics.

3. PROCESSING PRINCIPLES

Processing is carried out lawfully, fairly and only for specified purposes. The data collected is limited to what is necessary for the relevant purpose. Data is not combined with databases created for incompatible purposes. Inaccurate data is corrected, and data that is no longer required for the purpose of processing is deleted or anonymised. Confidentiality and data security are ensured through organisational and technical measures.

4. PURPOSES, CATEGORIES OF DATA AND LEGAL BASES

4.1. Website operation and information security

Data subjects: all website visitors.

Data: IP address; date and time of access; address of the requested page; referral source; browser and device information; language; technical identifiers; essential cookies; the user’s recorded cookie preferences; and security logs.

Purposes: displaying pages, maintaining sessions, protecting against DDoS attacks and abuse, diagnosing errors and remembering the user’s cookie choices.

Legal bases: the need to provide the website requested by the user, compliance with the Controller’s legal obligations, and pursuit of the Controller’s rights and legitimate interests where the user’s rights and freedoms are not overridden.

4.2. Handling enquiries and preparing proposals

Data subjects: users who submit an enquiry through a form on the Russian or English version of the website or initiate subsequent correspondence.

Data: name; telephone number and/or Telegram username; project description; other information voluntarily provided by the user; date, time and page from which the form was submitted; and the technical identifier of the enquiry.

Purposes: receiving and reviewing the enquiry, contacting the user, clarifying the project, preparing a preliminary proposal, timeline and next step, and, where both parties are interested, preparing to enter into a contract.

Legal bases: the user’s separate consent given through a mandatory, initially unticked checkbox below the form; and steps taken at the user’s request before entering into a contract.

The form is not intended for health information, biometric data, criminal-record information, information about sexual life, political, religious or philosophical beliefs, or personal data relating to third parties without an appropriate legal basis.

4.3. Entering into and performing a contract

Data subjects: customers, customer representatives and other individuals involved in agreeing and carrying out a project.

Data: full name, contact details, position and organisation, contracting-party details, delivery or installation address, project information, and other data necessary to enter into and perform the contract. Passport details and other identity data are not collected through the public website form and are requested separately only where necessary and legally justified.

Purposes: preparing, entering into and performing a contract; producing, delivering and installing an object; payments; accounting and tax records; and handling claims.

Legal bases: entering into and performing a contract, legal requirements and, where required, the data subject’s separate consent.

4.4. Website analytics

Data subjects: visitors who have allowed analytics cookies through the separate cookie settings banner.

Data: online identifiers and cookies; IP address used to determine approximate location; browser and operating-system type and version; device type and screen resolution; language; referral source; pages viewed; clicks, scrolling and other interaction events; and the fact that a form was successfully submitted, without sending the user’s name, telephone number, Telegram username or project description as analytics parameters.

Purposes: measuring website traffic, traffic sources and usability; checking the operation of the Russian and English versions; measuring form submissions; diagnosing errors; and improving the website structure.

Services: Yandex Metrica, counter 111424482; Google Analytics 4, measurement ID G-N24SVJYLQ5.

Legal basis: the user’s separate consent to analytics cookies. Until the user makes a choice, or where the user refuses, Tilda must not initialise the Yandex Metrica and Google Analytics codes connected through the website settings.

5. PROCESSING METHODS AND RETENTION PERIODS

Processing is performed by automated and non-automated means. The Controller may collect, record, organise, accumulate, store, update, retrieve, use, transfer data to authorised processors, anonymise, restrict, delete and destroy data.

Technical data and security logs are retained only for as long as necessary to operate and protect the website, generally no longer than 12 months unless a longer period is needed to investigate an incident or comply with the law.

Enquiries that do not result in a contract are retained until communication is complete or consent is withdrawn, but no longer than 12 months after the last substantive contact. A copy of an enquiry in the Tilda submissions section is retained for the platform’s configured period, which is 30 days by default.

Contractual and accounting data is processed for the duration of the contract and, after termination, for the periods required by law for accounting documents, tax supervision, protection of rights and handling claims.

Analytics data is processed until consent is withdrawn, cookies are deleted or the retention period configured for the relevant service expires. Anonymised and aggregated reports may be retained for longer where they cannot be used to identify a user.

Evidence of consent is retained for the processing period and for a reasonable period afterwards as necessary for the Controller to demonstrate compliance with legal requirements.

When a purpose has been achieved, consent has been withdrawn, unlawful processing has been identified or the relevant activity ends, the data is deleted or destroyed within the periods required by law unless another lawful basis exists for further processing.

6. COOKIES AND ANALYTICS SETTINGS

The website uses essential storage technologies required for Tilda security and operation. Analytics technologies are enabled only after separate consent in the T972 block. No advertising or other non-essential services are connected as of the date of this version; the Policy must be updated before any such services are connected.

Essential cookies used by Tilda and infrastructure security services support website operation, DDoS protection and storage of consent settings; their approximate lifetime is the session or up to one year, depending on the technology.

Yandex Metrica analytics cookies, including _ym_uid and _ym_d, are used for statistics, traffic sources and interactions and are generally retained for up to one year.

Google Analytics 4 analytics cookies, including _ga and _ga_N24SVJYLQ5, are used to distinguish users and sessions and generate statistics and are retained for up to two years unless the browser limits them earlier.

A user may accept all cookies, reject non-essential categories or select categories separately. Cookie choices can be changed again through the “Cookie Settings” widget on the website. Cookies can also be deleted in the browser settings.

7. PARTIES INVOLVED IN PROCESSING

The Controller does not sell personal data or disclose it to an indefinite group of persons.

Tilda Publishing JSC (Tilda) provides the website platform, form submissions and storage of enquiries on the Controller’s behalf; its infrastructure partners are Selectel JSC and Yandex.Cloud LLC.

VK LLC / Mail.ru is used to deliver form notifications and store business correspondence.

YANDEX LLC / Yandex Metrica processes technical and analytics data after the user has given consent.

Google Ireland Limited and Google affiliates / Google Analytics 4 process technical and analytics data after the user has given consent; processing and storage outside the Russian Federation may occur.

Data may also be disclosed to public authorities where and as required by law, or to contractors involved in performing a specific contract, in the minimum necessary amount and on an appropriate legal basis.

8. CROSS-BORDER TRANSFERS

Where Google Analytics 4 is used after consent to analytics cookies, technical and analytics data may be transferred to Google Ireland Limited and Google affiliates outside the Russian Federation. Such transfers are carried out in compliance with Article 12 of Federal Law No. 152-FZ, including prior notification of Roskomnadzor where required. Refusing analytics cookies prevents this counter from being initialised through Tilda’s standard settings.

Routine processing of enquiries through Tilda and Mail.ru does not involve a cross-border transfer provided that “Russia” is selected as the country in the Tilda profile, the project is not transferred to a foreign account and access is not granted to users abroad.

9. USER RIGHTS

A user may obtain information about processing; request correction of incomplete, outdated or inaccurate data; request restriction or destruction of data where provided by law; withdraw consent in whole or in part; object to processing based on legitimate interests where applicable law provides this right; and complain about the Controller’s actions or omissions to Roskomnadzor or a court.

To exercise these rights, email kerkeen@mail.ru. State your full name, contact details for the reply, information sufficient to confirm your interaction with the Controller, and the substance of your request. The Controller may request reasonably necessary additional information to identify the applicant without requiring excessive data.

10. SECURITY AND INCIDENTS

The Controller applies necessary organisational and technical measures, including access controls, strong passwords and secure connections, backups, monitoring of connected services, software updates, records of data-subject requests, and deletion of data after the applicable retention periods.

If an incident affecting data subjects’ rights is identified, the Controller takes steps to contain it and remedy its consequences and notifies Roskomnadzor within the periods required by law, including an initial notification within 24 hours and a report on the internal investigation within 72 hours.

11. ADDITIONAL INFORMATION FOR INTERNATIONAL VISITORS

Where the GDPR, UK GDPR or similar legislation applies, a user may also have rights to restriction of processing, data portability, objection to processing and lodging a complaint with the competent supervisory authority. Analytics is based on consent; responding to an enquiry and preparing a contract are based on steps taken at the user’s request; and website security is based on the Controller’s legitimate interests. The Controller does not make decisions based solely on automated processing that produce legal or similarly significant effects for a user.

12. FINAL PROVISIONS

This Policy applies from 10 August 2026 until replaced by a new version. The Russian-language version is the controlling version. This English translation is provided for users’ convenience; users’ mandatory rights are determined by applicable law regardless of the language of this text.

Controller details: Individual Entrepreneur Mikhail Mikhailovich Milovanov; OGRNIP 325547600019233; INN 540438208403; telephone +7 (995) 011-97-21; Telegram: https://t.me/legion_laboratory; e-mail: kerkeen@mail.ru.
Made on
Tilda