PERSONAL DATA PROCESSING POLICY

Effective date: September 10, 2026

1. General Provisions
1.1. This Personal Data Processing Policy (the “Policy”) defines the procedure for processing personal data and the measures taken to ensure its security by the operator — Pavel V. Golovin (the “Operator”).
1.2. This Policy is drafted in accordance with:
  • Federal Law No. 152‑FZ of 27.07.2006 “On Personal Data”;
  • Federal Law No. 149‑FZ of 27.07.2006 “On Information, Information Technologies and Information Protection”;
  • Decree of the Government of the Russian Federation No. 687 of 15.09.2008 “On Approving the Regulation on Specifics of Personal Data Processing Without Using Automation Tools”;
  • other regulatory legal acts of the Russian Federation.
1.3. This Policy applies to all personal data that the Operator receives from users of the website https://golovinarchive.com/ (the “Site”).
1.4. Key definitions used in this Policy:
  • Personal data — any information relating directly or indirectly to an identified or identifiable natural person (data subject).
  • Operator — a natural person who, alone or jointly with others, organizes and/or carries out the processing of personal data.
  • Personal data processing — any action (operation) or set of actions performed with personal data, including collection, recording, systematization, accumulation, storage, updating, extraction, use, transfer, anonymization, blocking, deletion, and destruction.
  • Data subject — a user of the Site.
  • Anonymization — actions as a result of which it is impossible to determine the ownership of personal data to a specific subject.

2. Legal Grounds for Personal Data Processing
2.1. The legal grounds for personal data processing are:
  • consent of the data subject to the processing of their personal data (Article 6 of Federal Law No. 152‑FZ);
  • the Operator’s legitimate interest in ensuring the functioning and security of the Site;
  • compliance with the requirements of the legislation of the Russian Federation.
2.2. Consent to personal data processing is provided by the data subject through conclusive actions (continued use of the Site, sending a message to the Operator’s email address).

3. Purposes of Personal Data Processing
3.1. The Operator processes personal data solely for the following purposes:

Purpose of processing

Categories of subjects

Categories of data

Processing period

Ensuring the functioning of the Site

Site visitors

IP address, cookies, technical data

Until the purpose is achieved

Analyzing traffic and improving the Site

Site visitors

Anonymized statistical data

Until the purpose is achieved

Feedback and responding to inquiries

Users who submitted an inquiry

Email address, message content

Until correspondence is completed

Ensuring security and preventing misuse

Site visitors

IP address, log files

Until the purpose is achieved

3.2. The Operator does not process personal data for purposes incompatible with those specified above.

4. Scope and Categories of Personal Data Processed
4.1. The Operator does not intentionally collect personal data that directly identifies a user (full name, phone number, residential address) unless such data is provided voluntarily by the user.
4.2. Automatically processed technical data:
  • IP address (anonymized);
  • cookies;
  • browser and device information;
  • date and time of visit;
  • referral source (referer);
  • page view statistics.
4.3. Data provided voluntarily by the user:
  • email address;
  • message content (when contacting mr.pavelgolovin@inbox.ru).
4.4. The Operator does not process special categories of personal data (race, nationality, political views, religious beliefs, health status, intimate life) or biometric personal data.

5. Procedure and Conditions for Personal Data Processing
5.1. Personal data is processed in the following ways:
  • automated processing using computer technology;
  • non-automated processing (when handling user inquiries).
5.2. Actions performed with personal data: collection, recording, systematization, accumulation, storage, updating (renewal, modification), extraction, use, anonymization, blocking, deletion, and destruction.
5.3. Personal data processing is carried out in compliance with the principles of:
  • lawfulness of the purposes and methods of processing;
  • correspondence of processing purposes to the purposes previously defined and stated;
  • correspondence of the scope and nature of the processed data to the stated purposes;
  • accuracy and sufficiency of the data;
  • storage of data no longer than required by the purposes of processing.
5.4. The Operator ceases personal data processing in the following cases:
  • achievement of the processing purposes;
  • withdrawal of consent by the data subject;
  • detection of unlawful processing;
  • liquidation or reorganization of the Operator;
  • the subject’s request to cease processing.

6. Transfer of Personal Data to Third Parties
6.1. The Operator does not transfer personal data to third parties, except in cases:
  • expressly provided for by the legislation of the Russian Federation;
  • where it is necessary to ensure the operation of the Site (e.g., a hosting provider), subject to compliance with personal data protection requirements.
6.2. Cross-border transfer of personal data is not carried out.
6.3. When transferring personal data to third parties, the Operator ensures that such parties undertake obligations to maintain confidentiality and use the data solely for the purposes for which it was transferred.

7. Measures to Ensure Personal Data Security
7.1. The Operator takes the necessary legal, organizational, and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, dissemination, and other unlawful actions.
7.2. Measures to ensure personal data security include:
  • appointment of a person responsible for organizing personal data processing;
  • restricting access to personal data;
  • use of information protection tools (TLS encryption of the data transmission channel);
  • regular data backups;
  • accounting of personal data carriers;
  • monitoring of the measures taken to ensure security.
7.3. All information on the transfer of personal data to third parties is recorded to monitor the lawfulness of the use of such information by the recipients.

8. Storage of Personal Data
8.1. Personal data is stored no longer than required by the purposes of its processing.
8.2. Storage periods:
  • technical data (cookies, log files) — up to 12 months from the date of collection;
  • inquiry data — until correspondence is completed, but no more than 3 years from the date of the last inquiry.
8.3. Upon expiration of the storage periods, personal data shall be destroyed or anonymized.

9. Rights of the Data Subject
9.1. The data subject has the right to:
  • obtain information concerning the processing of their personal data (Article 14 of Federal Law No. 152‑FZ);
  • request the updating, blocking, or destruction of their personal data in case of its incompleteness, inaccuracy, or unlawful processing;
  • withdraw consent to personal data processing;
  • appeal the actions or inaction of the Operator to the authorized body for the protection of the rights of data subjects (Roskomnadzor) or in court.
9.2. To exercise their rights, the subject shall send a request to the Operator’s email address: mr.pavelgolovin@inbox.ru.
9.3. The Operator reviews requests from data subjects within 30 days from the date of receipt of the request.

10. Amendments to the Policy
10.1. The Operator has the right to amend this Policy.
10.2. The current version of the Policy is published on the Site in open access.
10.3. Continued use of the Site after amendments are made constitutes the user’s consent to the new version of the Policy.

11. Operator’s Contacts
For all matters related to personal data processing:
Pavel V. Golovin
Email: mr.pavelgolovin@inbox.ru