PERSONAL DATA PROCESSING POLICY
Version dated 20 August 2026
1. GENERAL PROVISIONS1.1. This Personal Data Processing Policy (the “Policy”) has been drawn up in accordance with the Constitution of the Russian Federation, Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”, Federal Law No. 38-FZ of 13 March 2006 “On Advertising”, other laws and regulations of the Russian Federation governing the processing and protection of personal data, and with due regard to the requirements of the applicable laws of other countries to the extent that such laws apply to the activities of the Controller.
1.2. The personal data controller is:
Individual Entrepreneur Valeria Olegovna Shalimova
Taxpayer Identification Number (INN): 711709760432
Primary State Registration Number of the Individual Entrepreneur (OGRNIP): 319715400062002
Email address for enquiries concerning the processing of personal data:
lera_shali@mail.ruhereinafter referred to as the “Controller”.
1.3. This Policy sets out the procedure and conditions for processing the personal data of individuals who:
- visit the Controller’s website;
- complete forms, questionnaires and applications;
- submit a pre-enrolment or consultation request;
- purchase the Controller’s online courses and other services;
- obtain access to a Personal Account;
- take part in training and submit materials in order to receive feedback;
- contact the Controller by email or through messaging services;
- subscribe to advertising and informational communications.
1.4. This Policy applies to the website
https://valeriashali.com/, its pages and subdomains, data collection forms, payment pages, Personal Accounts and other digital services used by the Controller to provide services (the “Website”).
1.5. This Policy is an informational document and does not constitute consent to the processing of personal data. Where the law requires consent, such consent is requested separately from the Data Subject.
1.6. Acceptance of the terms of the public offer, consent to the processing of personal data and consent to receive advertising communications are obtained separately from one another.
1.7. The use of the Prodamus payment service to accept payments made with foreign bank cards does not change the identity of the service provider and seller: payment for the services is received by the Russian individual entrepreneur Valeria Olegovna Shalimova.
2. KEY TERMS2.1. Personal Data means any information relating directly or indirectly to an identified or identifiable individual.
2.2. Processing of Personal Data means any operation or set of operations performed on Personal Data, including collection, recording, organisation, accumulation, storage, clarification, updating, alteration, retrieval, use, transfer, provision, access, anonymisation, restriction, erasure and destruction.
2.3. Automated Processing of Personal Data means the processing of Personal Data by means of computer technology.
2.4. Data Subject means the individual to whom the Personal Data being processed relates.
2.5. User means any individual who visits the Website or uses its functions.
2.6. Client means a person who has entered into, or intends to enter into, an agreement with the Controller for the purchase of an online course, consultation or other service.
2.7. Student means a Client or another person who has been granted access to the Controller’s educational and informational materials.
2.8. Personal Account means a restricted-access section of the Website created on the Tilda platform and intended to provide the User with access to purchased materials and services.
2.9. Cookies means small pieces of data stored on the User’s device and used to operate the Website, save settings, ensure security and perform analytics.
2.10. Dissemination of Personal Data means the disclosure of Personal Data to an indefinite number of persons, including the publication online of reviews, photographs, videos, training results and other materials.
3. PRINCIPLES AND LEGAL BASES OF PROCESSING3.1. The Controller processes Personal Data lawfully, fairly and only to the extent necessary to achieve specific, predetermined purposes.
3.2. The Controller does not process Personal Data in a manner incompatible with the purposes for which it was collected and does not request data that is not required to provide the services.
3.3. The legal bases for processing Personal Data are:
- the Data Subject’s consent;
- the need to enter into and perform an agreement at the Data Subject’s request;
- the need to comply with legal obligations imposed on the Controller;
- the exercise of the rights and legitimate interests of the Controller or third parties, provided that this does not infringe the rights and freedoms of the Data Subject;
- other grounds provided for by applicable law.
3.4. Personal Data is processed for the purpose of sending advertising communications only where the User has given separate prior consent.
3.5. Reviews, photographs, videos, training results, names, social media accounts and other Personal Data are disseminated only where the Data Subject has separately consented to the processing of Personal Data authorised for dissemination.
3.6. The Controller does not deliberately collect special categories of Personal Data, including information concerning health, political opinions, religious beliefs, private life or criminal convictions.
3.7. The Controller does not process images, voice recordings or video recordings for identification purposes and does not create biometric databases.
4. CATEGORIES OF DATA SUBJECTS AND PERSONAL DATA PROCESSED4.1. The Controller may process the Personal Data of the following categories of individuals:
- Website visitors;
- persons who have submitted an application, questionnaire or pre-enrolment request;
- Clients and Students;
- recipients of consultations;
- subscribers to advertising and informational communications;
- persons who have contacted the Controller;
- payers, where payment is made by someone other than the Student.
4.2. Depending on the nature of the interaction, the Controller may process:
- surname, first name and patronymic, if provided;
- email address;
- telephone number;
- country, city and selected language of instruction;
- username or a link to an account on Instagram, Telegram, WhatsApp or another communication service;
- the contents of an application, questionnaire, brief, message or enquiry;
- information about the selected course, plan or service;
- information about the order, price, currency, promotional code and payment status;
- payment or transaction identifier;
- information required to process a refund;
- data required to create and use a Personal Account;
- information about access granted and course progress;
- completed assignments, comments, reviews and correspondence;
- photographs, videos, audio recordings and other materials voluntarily submitted by the User for review, feedback or consultation;
- information required to issue a certificate;
- details of a legal entity or individual entrepreneur where the Client requests business documentation;
- records of consents provided, including the date, time, IP address and version of the consent wording.
4.3. When the Website is visited, the following data may be processed automatically:
- IP address;
- cookies;
- date and time of the visit;
- address of the page visited;
- address of the page from which the User accessed the Website;
- information about the browser, operating system, language and device type;
- approximate location determined from the IP address;
- the User’s actions on the Website;
- technical information about errors and Website operation.
4.4. The Controller does not receive or store the full bank card number, its expiry date, the CVC/CVV code or any other data that would allow a payment to be made without the cardholder’s involvement. The User enters this information directly on the secure page of the payment service or bank.
5. PURPOSES, SCOPE AND RETENTION PERIODS OF PROCESSING5.1. Website operation and securityData processed: IP address, technical data, device and browser information, essential cookies, date and time of the visit, and technical logs.
Purposes: displaying the Website, authentication, protection against fraud and unauthorised access, identifying technical errors and ensuring stable operation.
Legal basis: the Controller’s legitimate interests and the need to provide the digital service requested by the User.
Retention period: no more than 24 months, unless a shorter period is specified in the settings of the relevant cookie or technical log.
5.2. Processing applications, questionnaires and pre-enrolment requestsData processed: first name, surname, telephone number, email address, country, language, social media or messaging account, contents of the application and questionnaire responses.
Purposes: processing the request, providing information, booking a consultation, adding the User to a pre-enrolment list, preparing an offer and entering into an agreement at the User’s request.
Legal basis: steps taken at the User’s request prior to entering into an agreement and, where necessary, the User’s separate consent.
Retention period: until an agreement is entered into, or no more than 12 months from the date of the last interaction if no agreement is entered into.
5.3. Entering into and performing an agreementData processed: surname, first name, contact details, information about the selected service, order, plan, payment, Personal Account and access granted.
Purposes: processing the order, entering into an agreement, providing access to a course or service, identifying the Client, performing the Controller’s obligations and sending organisational notices.
Legal basis: entering into and performing an agreement to which the Data Subject is a party or beneficiary.
Retention period: for the duration of the agreement and the period of access to the service, and thereafter for three years following termination of the agreement, unless a longer retention period is required by law.
5.4. Creating and maintaining a Personal AccountData processed: first name, surname, email address, telephone number, login credentials, information about purchased products, access rights and training progress.
Purposes: registering the User, providing access to materials, restoring access, providing technical support and recording course progress.
Legal basis: entering into and performing an agreement.
Retention period: for the duration of access to the Personal Account and for three years after the end of the most recently granted access period, unless the data must be deleted earlier.
5.5. Feedback and review of assignmentsData processed: first name, contact details, correspondence, photographs, videos, audio recordings, completed assignments, comments and other voluntarily provided materials.
Purposes: providing training, reviewing assignments, providing recommendations, feedback and support.
Legal basis: performance of the agreement and, where necessary, the Data Subject’s consent.
Retention period: for the duration of the feedback period and for no more than one year after it ends, unless longer retention is required to consider an enquiry or protect the Controller’s legitimate interests.
5.6. Accepting payments, issuing refunds and maintaining accounting recordsData processed: surname, first name, telephone number, email address, information about the order, amount, currency, payment method and status, transaction identifier and refund details.
Purposes: accepting and identifying payments, issuing receipts, refunding payments, maintaining accounting and tax records and confirming performance of the agreement.
Legal basis: performance of the agreement and compliance with the requirements of Russian law.
Retention period: for the period required by accounting and tax laws, generally at least five years after the end of the relevant reporting period.
5.7. Issuing certificatesData processed: surname, first name, course title, training completion date and other information required to issue a certificate.
Purposes: preparing and issuing an electronic certificate and confirming completion of the training.
Legal basis: performance of the agreement.
Retention period: for the duration of the agreement and for up to five years after its termination in order to confirm that the certificate was issued.
5.8. Informational and advertising communicationsData processed: first name, email address, telephone number, messaging service identifier, information about products of interest and consent provided.
Purposes: sending information about new courses, products, events, special offers and promotions.
Legal basis: the User’s separate prior consent to receive advertising and to the processing of Personal Data for the stated purposes.
Retention period: until consent is withdrawn, the User unsubscribes or the consent expires.
The minimum information required to demonstrate that consent was given and withdrawn may be retained for three years after communications cease in order to demonstrate compliance with legal requirements.
5.9. Publishing reviews and training resultsData processed: name, photograph, video recording, voice recording, social media account, text of the review, work results and other information specified in a separate consent.
Purposes: publishing reviews, case studies and training results on the Website, on social media and in the Controller’s advertising materials.
Legal basis: separate consent to the processing of Personal Data that the Data Subject has authorised for dissemination.
Retention period: for the period specified in the relevant consent or until it is withdrawn.
6. PROCESSING PROCEDURE AND METHODS6.1. The Controller processes Personal Data by automated and non-automated means.
6.2. The Controller may perform the following operations: collection, recording, organisation, accumulation, storage, clarification, updating, alteration, retrieval, use, granting access, transfer, anonymisation, restriction, erasure and destruction of Personal Data.
6.3. Personal Data may be obtained:
- directly from the User;
- automatically when the Website is used;
- from payment organisations, to the extent necessary to confirm payment;
- from a person who has paid for a service for the benefit of the User;
- from other sources where a lawful basis exists.
6.4. Access to Personal Data is granted only to the Controller, authorised employees, course supervisors, contractors and technical service providers, to the extent necessary for them to perform their duties.
6.5. Persons granted access to Personal Data must maintain its confidentiality and comply with security requirements.
6.6. The Controller does not sell Personal Data or disclose it to third parties for their independent use for advertising purposes.
7. DATA STORAGE AND DESTRUCTION7.1. The initial recording, organisation, accumulation, storage, clarification and retrieval of the Personal Data of citizens of the Russian Federation are carried out using databases located within the Russian Federation.
7.2. The Tilda platform is used to host the Website, forms and Personal Accounts and to store data. When “Russia” is selected as the country in the Tilda profile, Personal Data is stored on Russian servers operated by the platform’s partners, Selectel JSC and Yandex.Cloud LLC.
7.3. The primary database containing Website User, application, order and Personal Account data is stored within Tilda’s infrastructure.
7.4. The Controller takes reasonable measures to keep data up to date and deletes or rectifies incomplete, outdated or inaccurate information.
7.5. Once the purpose of processing has been achieved, the applicable retention period has expired, consent has been withdrawn or a request to cease processing has been received, the data is erased or destroyed within the period prescribed by law, unless the Controller has another lawful basis for continuing to retain it.
7.6. Where data must be retained in order to perform an agreement, comply with accounting or tax requirements, consider claims or protect the Controller’s rights, the relevant data is retained until the applicable period expires.
7.7. Data may be deleted from backups during the standard technical backup rotation cycle, provided that access is restricted and the data cannot be used for other purposes.
7.8. Anonymised analytical and statistical information that does not allow the User to be identified may be retained indefinitely.
8. DATA DISCLOSURE AND THIRD-PARTY SERVICES8.1. The Controller may engage third parties to process Personal Data and grant them access to the extent necessary to operate the Website, accept payments, provide access to courses, send messages, support Users and comply with legal requirements.
8.2. The Tilda platform, provided by Tilda Publishing JSC, is used to host the Website and operate its forms and Personal Accounts.
8.3. Servers operated by Selectel JSC and Yandex.Cloud LLC and located within the Russian Federation may be used to store data within Tilda’s infrastructure.
8.4. The Prodamus service is used to accept payments, including payments made with bank cards issued by foreign banks:
Prodamus LLC
Taxpayer Identification Number (INN): 1215156909
Primary State Registration Number (OGRN): 1111215003460.
Prodamus LLC, acquiring banks and payment systems independently process the information required to complete a payment in accordance with their own documents and applicable legal requirements.
The Controller receives only the information necessary to identify the order, confirm payment, issue a receipt and perform the agreement.
8.5. When the payment methods available on the Website are used, data may also be disclosed to T-Bank JSC, partner banks and operators of instalment-payment or pay-in-parts services, to the extent necessary for the payment transaction selected by the User.
8.6. The Yandex Metrica service, provided by Yandex LLC, may be used to analyse Website traffic and performance. The service may receive the technical information listed in Clause 4.3 of this Policy.
8.7. Email, Telegram, WhatsApp, Instagram and other means of communication selected by the User may be used for communications and support. The operators of these platforms independently process data in accordance with their own terms and policies.
8.8. Data may be disclosed to the Controller’s accountant, course supervisor, technical specialist or other contractor where such access is necessary to perform the agreement and the relevant person has undertaken to maintain confidentiality.
8.9. The Controller may disclose data to public authorities, courts and other authorised persons in the cases and according to the procedures provided for by law.
9. CROSS-BORDER DATA TRANSFERS9.1. The primary Website Personal Data database is stored within the Russian Federation.
9.2. When the User uses foreign bank cards, foreign payment partners, messaging services, social media or other foreign services, certain data may be processed outside the Russian Federation.
9.3. Before commencing a cross-border transfer, the Controller complies with the requirements of Article 12 of Federal Law No. 152-FZ “On Personal Data”, including carrying out the required assessment and notifying Roskomnadzor where such notification is mandatory.
9.4. A User located outside the Russian Federation is informed that the data they provide will be transferred to the Russian Federation and processed by the Controller for the purposes of considering the application and entering into and performing the agreement.
9.5. If the law of the User’s country imposes additional requirements on transfers of data to the Russian Federation, the Controller applies the relevant lawful bases and safeguards to the extent that such requirements apply to the Controller’s activities.
10. COOKIES AND ANALYTICS10.1. The Website uses essential technical cookies required for pages to function properly, for authentication, to ensure security and to protect against attacks.
10.2. Essential technical cookies cannot be disabled through the Website because certain functions may not work correctly without them.
10.3. Additional analytics cookies, including cookies used by the Yandex Metrica service, are used only after the User’s consent has been obtained, where such consent is required by applicable law.
10.4. The User may accept, reject or customise the use of additional cookies through the banner on the Website and may also change their browser settings.
10.5. Refusal of non-essential cookies must not restrict access to the Website’s core functions, but may affect the retention of personal settings and the quality of analytics.
10.6. The cookie retention period depends on the type of cookie and the settings of the relevant service, but must not exceed the period necessary for the stated purpose.
11. DATA SUBJECT RIGHTS11.1. The Data Subject has the right to:
- obtain information about the processing of their data;
- request that data be clarified, updated or rectified;
- request the restriction or destruction of data where it is processed unlawfully, is inaccurate or is not required for the stated purpose;
- withdraw previously given consent;
- request that the processing of Personal Data cease;
- opt out of advertising communications;
- lodge a complaint concerning the Controller’s acts or omissions with Roskomnadzor or a court;
- exercise other rights provided for by applicable law.
11.2. Withdrawal of consent does not affect the lawfulness of processing carried out before the Controller receives the withdrawal.
11.3. After consent has been withdrawn, the Controller may continue to process the data where another lawful basis exists, in particular for the performance of an agreement, accounting, consideration of claims or compliance with legal requirements.
11.4. To exercise their rights, the User may send a request to:
lera_shali@mail.ruRecommended email subject line: “Personal Data”.
11.5. The request must contain information enabling the applicant and their relationship with the Controller to be identified, a description of the request and contact details for the response.
11.6. If the Controller has reasonable doubts concerning the applicant’s identity, the Controller may request additional information necessary to verify their identity and prevent unauthorised access to another person’s data.
11.7. The Controller considers requests within the time limits prescribed by applicable law.
11.8. Requests to unsubscribe from advertising communications are fulfilled as quickly as possible. The User may also use an unsubscribe link where one is included in the communication.
12. USERS FROM OTHER COUNTRIES12.1. Where the laws of the European Union, the European Economic Area, the United Kingdom or another country apply to the processing of a particular User’s data, that User may have additional rights, including:
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on a legitimate interest;
- the right to lodge a complaint with the competent supervisory authority in the place where the User is located;
- the right not to be subject to a decision based solely on automated processing that produces significant legal effects for the User.
12.2. The Controller does not make decisions that produce legal or other significant effects for the User solely on the basis of automated processing of Personal Data.
12.3. A User from another country may exercise their rights by sending a request to
lera_shali@mail.ru.
13. PERSONAL DATA SECURITY13.1. The Controller takes the necessary legal, organisational and technical measures to protect Personal Data against unlawful or accidental access, erasure, alteration, restriction, copying, disclosure, dissemination and other unlawful acts.
13.2. These measures include:
- restricting access to Personal Data;
- using passwords and authentication tools;
- granting access only to authorised persons;
- using secure connections when data is transmitted;
- monitoring the actions of persons who have access to the data;
- regularly updating software;
- backing up and restoring data;
- adopting internal documents governing the processing and protection of Personal Data;
- responding to identified incidents.
13.3. In the event of an incident resulting in the unlawful disclosure of or access to Personal Data, the Controller takes the measures required by law and notifies the competent authority in the cases and within the time limits prescribed by law.
13.4. No method of storing or transmitting information can guarantee absolute security. The Controller takes protective measures appropriate to the nature of the data, the purposes of processing and the existing risks.
14. FINAL PROVISIONS14.1. This Policy takes effect upon its publication on the Website.
14.2. The Controller may amend this Policy where there are changes in the law, the services used, the methods of processing Personal Data or the Controller’s activities.
14.3. A new version of the Policy takes effect upon publication unless a different effective date is specified in the new version itself.
14.4. The current version of the Policy is publicly available at:
https://valeriashali.com/personal-data-policy-en14.5. A link to the Policy must be placed on every page of the Website where Personal Data is collected.
14.6. For all matters relating to this Policy and the processing of Personal Data, please contact the Controller:
Individual Entrepreneur Valeria Olegovna Shalimova
Taxpayer Identification Number (INN): 711709760432
Primary State Registration Number of the Individual Entrepreneur (OGRNIP): 319715400062002
Email:
lera_shali@mail.ru