This is a translation. In case of any discrepancy, the Russian version of the document prevails.
1. Who processes your data
The data controller is the administration of the “the iVy Studio” project (the “controller”), the owner and administrator of the service, independently determining the purposes and means of processing. “the iVy Studio” is the name of a project, not a separate legal entity. Details of the person acting as the controller are provided on request to the address below and will be published once the corresponding status is registered.
Data protection requests: legal@theivy.ru.
This Policy is written for people and explains the processing in plain language. The formal document required by clause 2 part 1 article 18.1 of Russian Federal Law No. 152-FZ is the Personal Data Processing Policy; in case of discrepancy it prevails.
2. Legal grounds
- your consent — given with a tick during registration; the date, the time and the version of the accepted documents are stored along with it;
- performance of a contract and pre-contractual steps — handling your request and discussing the work;
- legitimate interest — protecting the Service from password guessing, spam and abuse, and keeping technical logs;
- legal obligations — retention required by law.
Consent can be withdrawn. Since the client area cannot work without processing, withdrawing consent means deleting the account — see section 7.
3. What data is processed
3.1. Account data
- e-mail address, which is also the login;
- the name you provided;
- country and interface language;
- role in the system (client, specialist, manager, administrator);
- password — only an irreversible hash is stored, the password cannot be recovered from it;
- profile picture, if you uploaded one;
- personal backup e-mail address, if provided, and whether it is confirmed;
- dates of acceptance and the version of the accepted document set.
3.2. Request data
Task description, budget range and currency, desired timeline, status, work stage, assigned manager, deadline and price where set. A separate event feed records creation, status and stage changes, manager assignment, price and deadline changes and archiving — with the author and the timestamp.
3.3. Messages and files
Messages in the request chat, replies, reactions and uploaded images and video. Files are stored on the server disk; the database keeps the link, the type and the size.
3.4. Technical data
- IP address and browser details — used for rate limiting, incident analysis and the block list;
- device identifier from a cookie — it distinguishes the devices of one account and lets a block target a single device instead of a whole network;
- session records: issue and expiry times and a revocation mark; the renewal token itself is stored only as a hash;
- technical logs of the web server and the application containing the request path, the response code, the time and the IP address.
3.5. Public team cards
Staff members fill in their own cards: name, position, description, links, projects, photo and Discord identifiers. These details are published on the website by the staff member’s own decision and are visible to everyone.
3.6. Analytics on the public website
The public website (theivy.ru and theivy.dev) uses Yandex.Metrica and Google Analytics. They load only after you agree in the cookie banner; before that no analytics script is fetched at all. Your answer is stored in the browser and never reaches our server. To opt out, clear the site data in your browser. What these services collect is listed in the Cookie Policy.
4. Why the data is processed
- to give you access to the client area and recognise you at sign-in;
- to receive a request, discuss it and work on it;
- to send service e-mails: password, recovery, address confirmation;
- to protect the Service from password guessing, spam and abuse;
- to see which pages of the website are used — with your consent;
- to comply with the law.
We do not sell data, do not share it with advertising networks and do not make decisions with legal effect solely by automated means.
5. Where the data is stored
The database, the files and the mail server run on a server rented from Hetzner Online GmbH in Finland (European Union). Finland is a party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, that is, a country providing adequate protection of data subjects’ rights.
This means a cross-border transfer: by sending data to the Service you are aware that it is processed in the European Union. Please note that part 5 of article 18 of Russian Federal Law No. 152-FZ requires the recording, systematisation, accumulation, storage, amendment and retrieval of personal data of Russian citizens to use databases located in Russia. The controller discloses the actual state of affairs openly and plans to move the primary database to Russia; until then you decide whether to provide data with this in mind.
6. Who else receives the data
- Hetzner Online GmbH — hosting of the server that runs the application, the database and the mail service; it is given no access to the content, yet the data physically resides on its hardware;
- Yandex LLC and Google LLC — website visit data, only after consent to analytics cookies;
- Lanyard (a public Discord status service) — receives only the Discord identifiers that staff members put in their own cards; client data never goes there, and the request is made by our server rather than your browser;
- competent authorities — upon a duly issued demand, within the scope required by law.
Studio staff see data only as far as their work requires: a manager sees requests and their chats, an administrator sees accounts and roles.
7. Retention and deletion
- account data, requests and chats — while the account exists;
- when an account is deleted it is first marked as deleted and hidden, and after seven days it is erased together with requests, messages and files; during that window the deletion can be undone;
- sessions: the renewal token lives up to 90 days, the access token one hour; revoked sessions remain as a revocation record;
- one-time links from e-mails: password recovery 30 minutes, backup address confirmation 24 hours; they are kept in Redis as a hash and are burned on first use;
- device identifier — up to one year from issue;
- technical logs — up to 30 days unless a longer period is needed to investigate an incident;
- consent records — while the account exists; they prove which version of the documents you accepted.
8. How the data is protected
- connections to the website, the client area and the API use TLS;
- passwords are stored as an irreversible hash;
- functional cookies carry the HttpOnly and Secure flags, so page scripts cannot read them;
- state-changing requests are protected by an anti-CSRF token;
- request rates are limited; suspicious activity triggers blocks by address, subnet or device;
- staff access is separated by roles; actions on requests are recorded in the event feed.
9. Your rights
9.1. Under Russian law
You may obtain information about the processing of your data, demand its correction, blocking or destruction if it is incomplete, outdated, inaccurate or unlawfully obtained, and withdraw your consent. Write to legal@theivy.ru; the answer follows within the statutory period of no more than 30 days. You may also complain to Roskomnadzor or go to court.
9.2. If you are in the European Union
In addition to the above you have the rights granted by Regulation (EU) 2016/679 (GDPR): access, rectification, erasure, restriction of processing, portability (in a machine-readable form), objection to processing based on legitimate interest, and the right to lodge a complaint with your national supervisory authority. A message to legal@theivy.ru is enough to exercise any of them.
10. Cookies
What exactly is stored in your browser and why is listed in the Cookie Policy, together with the analytics scripts and the way to refuse them.
11. Children
The client area is intended for people over 18; we do not knowingly collect children’s data. If such data reached us by mistake, write to legal@theivy.ru and we will delete it.
12. Changes to this Policy
The Policy changes along with the Service. The document set carries a version — the date at the top of the page; earlier versions are kept in the Legal documents section. We announce material changes by e-mail or with a notice in the client area.
13. Contacts
Questions about data processing: legal@theivy.ru. Technical support: support@theivy.ru.