Privacy Policy


This Privacy Policy explains how AFFStudio (“we”, “us”, “our”) collects and processes personal data when you use affstudio.org (the “Website”).

1) Who we are (Controller)

Data Controller: AFFStudio (Website operator)
Country of establishment: [Insert country] (outside the Russian Federation)
Contact email (privacy): [Insert privacy email, e.g., privacy@affstudio.org]
Postal address (optional): [Insert address]

If required by applicable law (e.g., GDPR), we may appoint an EU/UK representative and/or a Data Protection Officer (DPO). If appointed, their contact details will be published here.

2) Scope

This Policy applies to personal data processed through the Website, including:

  • data you provide voluntarily (e.g., when leaving comments);
  • technical data collected automatically (e.g., log data, cookies).

3) What personal data we collect

Because the Website is informational, we generally collect minimal data:

A. Data you provide

  • Comments (if enabled): name, email address, website URL, comment text, and any other information you choose to include in the comment.
  • Messages/contact requests (if you contact us): name, email, and the content of your message.

B. Data collected automatically

  • Technical and usage data: IP address, device type, browser type, operating system, referring URLs, pages visited, timestamps, and similar log data.
  • Cookies / similar technologies: may be used for basic Website functionality, security, analytics, and preference storage. Where required, we will request consent for non-essential cookies.

4) Purposes of processing

We process personal data for the following purposes:

  1. To operate and maintain the Website (display content, ensure core functionality).
  2. To enable user interactions (e.g., publishing and moderating comments).
  3. To ensure security and prevent abuse (spam prevention, fraud detection, incident investigation).
  4. To analyze and improve the Website (aggregated statistics, performance measurement).
  5. To respond to requests you send us (support, questions, feedback).

5) Legal bases (where GDPR applies)

Depending on your location and applicable law, we rely on one or more of the following bases:

  • Consent (e.g., optional cookies/analytics, and certain optional features).
  • Legitimate interests (e.g., Website security, basic analytics, improving content and user experience), provided your rights do not override these interests.
  • Legal obligation (when we must comply with applicable laws or lawful requests).

6) Cookies and similar technologies

We may use cookies and similar technologies:

  • Essential cookies — required for core functionality and security.
  • Analytics cookies — help us understand Website usage and improve content.

Where required by law (EU/EEA/UK in many cases), we will ask for your consent before placing non-essential cookies and provide a way to change your preferences.

7) Sharing and disclosure of personal data

We do not sell personal data.

We may share data only when necessary:

  • Service providers (processors): hosting, security, analytics, anti-spam tools—only to the extent needed to provide their services and under contractual safeguards.
  • Legal compliance: when required by law, court order, or lawful request by authorities.
  • Protection of rights: when needed to protect the Website, our users, and our rights (e.g., preventing fraud or abuse).

8) International data transfers

Because the Website is operated outside Russia and may use international service providers, personal data may be transferred and processed in countries other than your own.

Where GDPR applies and transfers go outside the EEA/UK, we use appropriate safeguards (for example, Standard Contractual Clauses and/or other lawful transfer mechanisms, as applicable).

9) Data retention

We keep personal data only as long as necessary for the purposes described above:

  • Comments: stored while the related content remains published, unless you request deletion (subject to legal/legitimate exceptions).
  • Contact messages: kept as long as needed to resolve your request and for reasonable record-keeping.
  • Logs/security records: kept for a limited period appropriate for security and troubleshooting.

We may retain certain data longer if required by law or for establishing, exercising, or defending legal claims.

10) Security measures

We implement reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction (e.g., access controls, least-privilege, backups, security monitoring). No method of transmission or storage is 100% secure.

11) Children’s privacy

The Website is not intended for children. If you believe a child has provided us personal data, please contact us so we can take appropriate steps.

12) Your rights

Depending on your jurisdiction (and in particular if GDPR applies), you may have rights to:

  • be informed about processing;
  • access your personal data;
  • correct inaccurate data;
  • delete data (“right to erasure”);
  • restrict processing;
  • object to processing;
  • data portability (in certain cases);
  • withdraw consent (where processing is based on consent).

You also have the right to lodge a complaint with your local data protection authority (where applicable).

13) Third-party links

The Website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies separately.

14) Changes to this Policy

We may update this Policy from time to time. The updated version becomes effective when published on the Website with a new “Effective date”.

RECENTS POSTS

ALL TAGS