Доктор Строй

Courtesy English translation. The Russian version prevails in case of any discrepancy.

PRIVACY POLICY

Personal Data Processing Policy

of the Doctor Stroy digital platform

Effective from 15 May 2026

Permanent address of this document: doctorstroy.ru/legal/privacy

This is a courtesy English translation. The original Russian version of this Privacy Policy prevails in case of any discrepancy and governs the processing of personal data. The English translation is provided for the convenience of non-Russian-speaking Users and for review by foreign application stores (App Store, Google Play, RuStore).

1. GENERAL PROVISIONS

1.1. This Personal Data Processing Policy (the «Policy») is developed in accordance with clause 2 of part 1 of Article 18.1 of Federal Law No. 152-FZ of 27 July 2006 «On Personal Data» (the «Law No. 152-FZ») and sets out the procedure for the processing of personal data and the measures to ensure their security taken by the Operator.

1.2. Personal data operator: Individual Entrepreneur Malshaev Baatr Anatolyevich, OGRNIP 321080000003188, INN 081400461200, address for correspondence: 358014, Republic of Kalmykia, Elista, Citi-3 microdistrict, building 34, email: malshaev@yandex.ru, phone: +7 909 399-93-42 (the «Operator»).

1.3. The Policy applies to all personal data processed by the Operator in connection with the operation of the Doctor Stroy digital platform, available via the website doctorstroy.ru and the mobile applications for iOS and Android (collectively, the «Platform»).

1.4. The Policy is publicly available and is published in free access on the Operator's Website. The current version of the Policy is permanently available at the address set out in the preamble, without registration and without any action by the user.

1.5. Defined terms «personal data», «processing of personal data», «operator», «subject of personal data», «cross-border transfer», «distribution», «provision», «blocking» and «destruction» are used in the meanings established by Article 3 of Law No. 152-FZ. Other terms («Platform», «User», «Customer», «Service Provider», «Partner», «Account» and the like) are used in the meanings established by the Terms of Use at doctorstroy.ru/legal/offer.

1.6. The processing of personal data is carried out by the Operator on a lawful and fair basis, is limited to the achievement of specific, predetermined and lawful purposes and is not carried out in a volume excessive in relation to such purposes. The Operator does not combine databases the processing of which is carried out for incompatible purposes.

1.7. Database localisation. The recording, systematisation, accumulation, storage, refinement (update, modification) and extraction of personal data of Russian citizens are carried out by the Operator using databases located on the territory of the Russian Federation (part 5 of Article 18 of Law No. 152-FZ).

2. CATEGORIES OF SUBJECTS OF PERSONAL DATA

2.1. The Operator processes personal data of the following categories of subjects:

  • Customers — natural persons who have registered an Account on the Platform or who have submitted a request via feedback forms to search for and obtain goods, services and rentals of equipment;
  • Applicants — natural persons who have submitted a request for a service, a call-back request, a request for an on-site visit or any other request without registering an Account;
  • Service Providers — natural persons, including those applying the special tax regime «Tax on Professional Income» (self-employed), and individual entrepreneurs going through verification to render services through the Platform;
  • Other natural persons whose personal data may be transferred to the Operator by Users (for example, persons mentioned in comments to requests, depicted in photographs of objects or works, or mentioned in the texts of reviews and messages).

2.2. This Policy applies to the processing of personal data of natural persons. Information about organisations and individual entrepreneurs is processed by the Operator to the extent it relates to the personal data of the natural persons representing them.

The relations with franchisee partners and stores are governed by separate agreements outside the Platform; the processing of personal data within these relations is governed by the relevant agreements and, where necessary, by separate consents.

3. PERSONAL DATA PROCESSED

3.1. The Operator processes the following categories of personal data.

3.2. General personal data (for all categories of subjects)

  • surname, first name, patronymic (or the name indicated by the subject);
  • date of birth;
  • mobile phone number;
  • email address;
  • postal address and/or address of the place of provision of services (city, street, building number, block, floor, apartment number);
  • information on the selected city of residence or city of service provision;
  • image of the subject (profile photograph, avatar);
  • information on preferences and convenient time for contact;
  • free-form text information provided by the subject themselves (comments, descriptions of requests, chat messages, reviews).

3.3. Identification data of Service Providers (in addition to clause 3.2)

  • series and number of the identity document; photo- and scan-copies of such document;
  • taxpayer identification number (INN);
  • information on the form of employment (natural person, self-employed, individual entrepreneur);
  • professional information: specialisation, experience, description of services, portfolio of works (photographs);
  • information on tariffs and availability schedule;
  • bank details — if settlements need to be performed.

3.4. Account and authentication data

  • Account identifier; information on confirmation of phone and email address;
  • timestamps of acceptance of the Terms of Use, of the Policy and of consents;
  • timestamps of login; information on the blocking of the Account and its reasons;
  • technical session identifiers (secure cookies and tokens).

3.5. Data on interaction with the Platform

  • history of requests, orders, rentals and their statuses;
  • history of correspondence in the chat with other Users, Partners and the support service, including the text of messages and attached files;
  • history of notifications sent to the subject (SMS, push, email, in-app);
  • texts of published reviews and ratings.

3.6. Technical data and information on devices

  • device network address (IP address); browser type and operating system, User-Agent header;
  • mobile device token for sending push notifications; information on the device platform (iOS / Android / web);
  • information on the selected city and user settings stored in the local storage of the browser or of the mobile application on the subject's device (including session identifiers and other technical markers of the application);
  • diagnostic information on crashes and stability of the mobile application (crash stack, version of the application and operating system, device model, anonymised installation identifier), used exclusively for error diagnostics and improvement of the application's quality.

3.7. Geolocation data

Geographic coordinates of the device are processed exclusively upon the subject's request at the time of determination of the city or selection of the address of service, are not stored in unchanged form, and are used only for address normalisation and determination of the administrative-territorial unit.

3.8. Audit and security log data

Information on the subject's actions in the Personal Account and in administrative interfaces: date and time of the action, type of action, IP address, device header, session identifier, action metadata (without the content of user data).

3.9. Categories of data NOT processed by the Operator

The Operator does not process special categories of personal data (information on racial and ethnic affiliation, political, religious and philosophical beliefs, state of health, intimate life, criminal record) or biometric personal data within the meaning of part 1 of Article 11 of Law No. 152-FZ. The Platform is intended only for persons who have reached the age of 18; personal data of minors are not processed.

4. PURPOSES OF PROCESSING AND LEGAL GROUNDS

4.1. The Operator processes personal data for the purposes listed below. For each purpose, the data used and the legal ground are stated.

4.2. Consent to the processing of personal data, to the cross-border transfer, to the processing of data permitted for distribution and to the receipt of marketing communications is provided as separate documents in accordance with the requirements of Article 9 of Law No. 152-FZ and is not included in this Policy or in the Terms of Use.

5. METHODS OF PROCESSING

5.1. The Operator processes personal data by mixed methods — using means of automation and without using such means.

5.2. The Operator carries out the following actions (operations) with personal data: collection, recording, systematisation, accumulation, storage, refinement (update, modification), extraction, use, transfer (provision, access), anonymisation, blocking, deletion and destruction.

5.3. The Operator does not take decisions on the basis solely of automated processing of personal data that produce legal effects in relation to the subject or otherwise affect their rights and legitimate interests.

6. TRANSFER OF PERSONAL DATA TO THIRD PARTIES

6.1. To ensure the operation of the Platform, the Operator entrusts the processing of personal data to third parties under part 3 of Article 6 of Law No. 152-FZ. With each such party, the Operator concludes an agreement providing for the obligations of confidentiality and security of personal data. The list of parties to whom processing is entrusted:

6.2. In addition to the parties listed in clause 6.1, personal data may be transferred to the Operator's franchisee Partners to the extent necessary for the performance of the Customer's request (for example, name, contact phone and address of visit are transferred to the Partner for performance of the request in their city). The specific legal construction of interaction with Partners (entrusted processing or transfer to a separate operator) is determined by the agreement with the Partner.

6.3. Personal data may be provided to state authorities, local authorities and other persons in the cases and in the manner expressly provided by the legislation of the Russian Federation.

6.4. The Operator does not sell personal data and does not transfer them to third parties for purposes not provided for in this Policy and in the consents of the subjects.

7. CROSS-BORDER TRANSFER OF PERSONAL DATA

7.1. The Operator carries out cross-border transfer of part of personal data to Google LLC (United States of America) for the operation of the Platform's mobile application in two directions:

  • Firebase Cloud Messaging — for delivery of push notifications to Users' devices. The following data are transferred: the device token issued by the service upon the subscription of the device to push notifications, and the header and text of the push notification (which may contain the subject's name, the request or order number and other information from the context of the notification);
  • Firebase Crashlytics — for diagnostics of crashes and for ensuring the stability of the mobile application. The following data are transferred: crash stack, version of the mobile application and operating system, device model, anonymised installation identifier. Substantive personal data of the subject are not transferred in crash reports.

7.2. The United States of America is not included in the list of foreign states providing adequate protection of rights of personal data subjects. The cross-border transfer in both directions is carried out by the Operator on condition of submission to the authorised body for the protection of rights of subjects of personal data (Roskomnadzor) of a notification of the intention to carry out cross-border transfer of personal data (Article 12 of Law No. 152-FZ) and on the basis of a separate consent of the subject to such transfer.

7.3. The Operator does not carry out any other cross-border transfers of personal data. All principal databases of the Operator are located on the territory of the Russian Federation.

Information on cross-border transfer is current as of the revision date of the Policy. If the Operator switches from Firebase services to Russian channels of notification delivery and crash diagnostics, the cross-border transfer will be terminated, and the Policy will be amended accordingly.

8. PROCESSING AND STORAGE PERIODS

8.1. The Operator processes personal data no longer than the purposes of processing require, unless a different period is established by law or by the subject's consent. Storage periods by types of data:

8.2. The processing of personal data terminates upon the occurrence of any of the following events: achievement of the purposes of processing; withdrawal by the subject of consent (where processing was carried out on the basis of consent and there are no other legal grounds); expiry of the storage period; detection of unlawful processing; termination of the Operator's activity. Upon achievement of the purposes of processing or in other cases established by law, personal data are destroyed or anonymised within the periods set by Law No. 152-FZ.

9. MEASURES TO ENSURE SECURITY OF PERSONAL DATA

9.1. The Operator takes the necessary legal, organisational and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution and other unlawful actions (Articles 18.1 and 19 of Law No. 152-FZ; Decree of the Government of the Russian Federation No. 1119 of 1 November 2012; Order of FSTEC No. 21 of 18 February 2013).

9.2. Technical measures

  • use of strong encryption algorithms (AES-256) to store the most sensitive personal data (passport details, INN, contact details, addresses, free-form text);
  • storage of user passwords solely in the form of a cryptographic hash;
  • encryption of the data transmission channel (HTTPS / TLS 1.2 and above);
  • differentiation of access between internal components and verification of internal requests;
  • session protection: access tokens with short lifetime, separate refresh tokens, CSRF protection, storage of session identifiers in HttpOnly, Secure and SameSite cookies;
  • rate limiting and protection against automated brute-force attempts;
  • differentiation of access at the database level;
  • audit logs of user actions;
  • regular data backup and key/secret management via a dedicated secure service.

9.3. Organisational measures

  • appointment of a person responsible for the organisation of personal data processing;
  • approval and application of this Policy and other internal documents governing the processing and protection of personal data;
  • approval of the list of persons having access to personal data and restriction of such access;
  • familiarisation of persons processing personal data with the relevant legislation and local acts, signing of confidentiality undertakings;
  • conclusion of agreements on entrusted processing of personal data with engaged third parties;
  • regulation of the procedure for responding to requests of subjects and to incidents concerning personal data, including the duty to notify the authorised body within 24 hours of detection of an incident and to send the results of the internal investigation within 72 hours;
  • regulation of the destruction of personal data upon expiry of processing periods and internal compliance checks.

10. RIGHTS OF SUBJECTS OF PERSONAL DATA

10.1. A subject of personal data has the right to:

  • receive information concerning the processing of their personal data to the extent provided for in part 7 of Article 14 of Law No. 152-FZ (about the operator, the purposes and methods of processing, periods, persons to whom data are transferred and so on);
  • require clarification of their personal data, their blocking or destruction if they are incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the declared purpose;
  • withdraw consent to the processing of personal data at any time;
  • object to processing and appeal against actions or omissions of the Operator to the authorised body for the protection of rights of subjects of personal data (Roskomnadzor) or in court;
  • protect their rights and legitimate interests, including by way of judicial recovery of damages and compensation for non-pecuniary harm.

10.2. To exercise their rights, the subject sends to the Operator a request at the address 358014, Republic of Kalmykia, Elista, Citi-3 microdistrict, building 34 or by email at malshaev@yandex.ru. The request shall contain information allowing the subject to be identified and information confirming their participation in relations with the Operator, or details of a document confirming such participation.

10.3. Time limits for the Operator's response: to a request for information on processing — within 10 business days (with possible extension by no more than 5 business days); to a request for clarification, blocking or destruction — within 7 business days; upon withdrawal of consent, processing is terminated and personal data are destroyed within no more than 30 days, unless otherwise provided by law or by other legal grounds for processing.

10.4. Deletion of the Account and related personal data is initiated by the subject by one of the following methods: (a) directly in the mobile application of the Platform — section «Profile» → «Delete account»; (b) on the public page doctorstroy.ru/legal/delete-account, accessible without authentication; (c) by sending a request to the Operator at malshaev@yandex.ru indicating the phone number used at registration. After confirmation, the Account and profile data are deleted within no more than 30 days. Information that the Operator is obliged to retain under the law continues to be stored for the periods established by law (Section 8), and is destroyed thereafter. Detailed information is set out in the Account Deletion Notice at doctorstroy.ru/legal/delete-account.

11. PERSON RESPONSIBLE FOR THE ORGANISATION OF PERSONAL DATA PROCESSING

11.1. The person responsible for the organisation of personal data processing by the Operator: Individual Entrepreneur Malshaev Baatr Anatolyevich.

11.2. Contact details for inquiries about personal data processing: email malshaev@yandex.ru, phone +7 909 399-93-42, postal address 358014, Republic of Kalmykia, Elista, Citi-3 microdistrict, building 34.

12. USE OF COOKIES, LOCAL STORAGE AND SIMILAR TECHNOLOGIES

12.1. The Platform uses cookies and similar technologies (browser local storage, mobile application local storage, session identifiers, technical installation identifiers of the application). Cookies are small files stored in the browser of the subject's device; similar technologies in mobile applications provide equivalent functionality by means of the operating system.

12.2. The Operator uses the following categories of such technologies: strictly necessary (ensure authentication, security and basic operation of the Platform — without them the Platform cannot function); functional (remember the chosen city and user settings, including in the mobile application's local storage). Third-party analytics and advertising cookies are not used by the Operator as of the revision date of the Policy; if they are introduced, this Policy will be amended and an informational banner will be displayed on the Platform. The mobile application uses an anonymised installation identifier for crash diagnostics (Firebase Crashlytics, see Sections 6 and 7).

12.3. The storage period of cookies and local storage data is set out in Section 8 of the Policy. The subject may at any time delete stored cookies and/or restrict their use in the settings of their browser; mobile application local storage data are deleted upon removal of the application from the device or via the system settings of the application. Disabling strictly necessary cookies and session identifiers may result in the unavailability of certain functions of the Platform.

13. DATA PROCESSING WHEN USING THE «AI DESIGNER» FEATURE

13.1. Description. The Platform provides an optional «AI Designer» feature which engages an external generative-model provider (the «AI Service») to produce a draft room visualisation and an indicative cost calculation.

13.2. Legal basis. Processing under this feature is carried out solely on the basis of the User's separate, explicit and informed consent (clause 1 of part 1 of Article 6 of Federal Law No. 152-FZ of 27 July 2006 «On Personal Data»), requested in the Platform interface immediately before the request is formed. Without that consent no data is transmitted to the AI Service. Withholding or withdrawing consent does not restrict access to the rest of the Platform.

13.3. Data transmitted. The following is transmitted to the AI Service:

  • a photograph of the room — only where the User has attached it to the request themselves; if no photograph is attached, no images are transmitted;
  • de-identified project parameters entered by the User: room type and area, style, budget, material and finishing preferences;
  • an irreversible technical identifier derived using a keyed cryptographic hash function. It does not allow the AI Service to identify the User and is used exclusively for abuse prevention.

13.4. Data that is not transmitted. The following is not transmitted to the AI Service: full name, telephone number, email address, postal address, payment and banking details, account identifiers, document details, and information about the User's orders, requests, reviews and correspondence.

13.5. Automatic de-identification. Free text entered by the User (design preferences) is automatically processed before transfer: telephone numbers, email addresses, postal addresses, payment card numbers and internal identifiers are removed, and the text length is capped. The AI Service has no access to the Operator's information systems or databases and cannot obtain any other information about the User on its own.

13.6. Purpose of transfer. Data is transmitted to the AI Service solely to fulfil the User's specific request. The Operator does not transfer User data to the AI Service for the purpose of training models, nor for advertising, marketing or any other purpose.

13.7. Cross-border transfer. The request is processed on the AI Service's technical facilities, which may be located outside the territory of the Russian Federation. Transfer takes place only with the User's consent and strictly within the scope set out in clause 13.3. General conditions of cross-border transfer and the User's rights are set out in Section 7 of this Policy.

13.8. Images of people. The feature is not intended for processing images of people and is not used for biometric identification or facial recognition. The Operator recommends that the User does not upload photographs depicting people, documents or other personal data of third parties. By uploading a photograph, the User confirms that they have a legal basis for its processing.

13.9. Retention. The uploaded photograph and the generated result are stored in the User's project on the Platform and are deleted when the corresponding project or the Account is deleted, within the periods set out in Section 8 of this Policy.

13.10. Automated decision-making. The feature's output is informational and is not used to take decisions producing legal effects for the User, or otherwise significantly affecting the User's rights and legitimate interests, solely on the basis of automated processing of personal data.

13.11. Withdrawal of consent and deletion. The User may stop using the feature at any time and may contact the Operator using the contact details in Section 1 of this Policy to request deletion of uploaded images and generated results.

14. FINAL PROVISIONS

14.1. The Operator may amend this Policy. The current version of the Policy is posted on the Website at the address set out in the preamble, indicating the effective date.

14.2. Material amendments to the Policy are communicated to subjects by posting the new version on the Website and, where necessary, also via the Personal Account or email.

14.3. For any issues not regulated by this Policy, the Operator and subjects are governed by the legislation of the Russian Federation.

14.4. This Policy is publicly available and permanently posted on the Internet at doctorstroy.ru/legal/privacy. In case of any discrepancy between the Russian text and any translation, the Russian text prevails.