Privacy Policy

Effective date: August 11, 2026

1. General provisions

1.1. This Privacy Policy (hereinafter — “Policy”) defines the procedure for processing and protecting the personal data (hereinafter — “PD”) of users of the online service “DynapiCMS”, accessible at dynapi.ru (hereinafter — “Service”).

1.2. The data controller is Individual Entrepreneur SOLOMANIDIN EVGENIY VLADIMIROVICH, OGRNIP 326619600175766, INN 616899285500 (hereinafter — “Controller”).

1.3. Controller’s address: 344049, Rostov region, Rostov-on-Don, 4th Glazurny lane, 3. Contact email for PD-related requests: support@dynapi.ru.

1.4. The Policy is developed in accordance with the Russian Federal Law No. 152-FZ of July 27, 2006, “On Personal Data” (hereinafter — “152-FZ”), taking into account the requirements of Articles 18.1 and 19 of 152-FZ.

1.5. Use of the Service constitutes the user’s unconditional consent to the terms of this Policy. If a user disagrees with any provision, they must refrain from using the Service.

1.6. The Controller may amend the Policy. The current version is posted on this page. Users are advised to periodically review the current version.

2. Purposes of personal data processing

2.1. PD is processed for the following purposes:

  • providing the user with access to the Service, identification and authentication;
  • performance of the service agreement concluded between the Controller and the user (hereinafter — “Agreement”);
  • technical support, notification of changes in the Service;
  • billing and settlements (for paid plans);
  • ensuring Service security, investigating incidents;
  • analyzing marketing website traffic to improve the Service (using Yandex.Metrica).

3. Categories of personal data processed

3.1. The Controller processes the following categories of user PD:

  • surname, first name (provided by the user at registration);
  • email address;
  • login session (cookies used for authentication);
  • IP address;
  • browser and device information (User-Agent, transmitted automatically);
  • technical access data (date, time, session duration).

3.2. The Controller does not process special categories of PD (racial or ethnic origin, political opinions, religious beliefs, health, intimate life) or biometric PD.

3.3. The Controller does not request passport, SNILS, INN, bank card data or other PD beyond those listed in 3.1. Payments for paid plans (if applicable) are processed through a third-party payment provider — card data is not transmitted to the Controller.

4. Categories of data subjects

4.1. The subjects of processed PD are:

  • Service clients — registered users using the Service under an Agreement;
  • marketing website visitors — persons visiting public pages of dynapi.ru without registration.

5.1. PD processing is based on the following legal grounds:

  • clause 1 part 1 article 6 of 152-FZ — the data subject’s consent. Applies to website visitors (consent via cookie banner for Yandex.Metrica use);
  • clause 5 part 1 article 6 of 152-FZ — performance of a contract to which the data subject is a party. Applies to Service clients (Agreement for SaaS platform use).

6. List of operations with personal data

6.1. The following operations are performed with PD: collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (provision, access) to third parties in accordance with this Policy, deletion, destruction.

6.2. PD is processed automatically using computing equipment in the personal data information system “DynapiCMS”.

7. Personal data retention period

7.1. PD is retained for the duration of the Agreement with the user. After termination of the Agreement, PD is retained for 3 (three) years to comply with Russian Federation legal requirements (statute of limitations under the Civil Code + tax period), unless otherwise provided by law.

7.2. When a subject withdraws consent to PD processing (for visitor data via cookie banner or written request), the Controller ceases processing and immediately deletes the corresponding PD, except in cases provided by Russian law.

7.3. Audit logs are retained indefinitely as a security measure in accordance with Article 19 of 152-FZ.

8. Transfer of personal data to third parties

8.1. The Controller uses the third-party web analytics service Yandex.Metrica on the marketing website dynapi.ru (operator: Yandex, Moscow). The service collects visit statistics: traffic sources, page views, devices, on-site behaviour. Yandex is an independent controller of the data it collects; the visitor’s consent to the use of Yandex.Metrica is obtained via the cookie banner (see Section 13) and may be withdrawn at any time.

8.2. The platform is deployed on leased server infrastructure located in the Russian Federation (Moscow). The infrastructure provider has no logical access to the Controller’s databases and is not a processor of PD within the meaning of clause 3 article 6 of 152-FZ. Other technical services (DNS hosting, TLS certificate issuance via Let’s Encrypt) also do not process personal data of the Service users.

8.3. PD transfer to other parties occurs only when there is a legal basis (e.g., pursuant to a request from a state authority in cases provided by law).

9. Cross-border transfer of personal data

9.1. No cross-border transfer of PD is performed. All processors listed in Section 8 are located in the Russian Federation. PD is not transferred outside the Russian Federation.

10. Personal data security measures

10.1. In accordance with Article 19 of 152-FZ, the Controller applies the following PD protection measures:

  • organizational: designation of a person responsible for organizing PD processing; issuance of internal regulations; restricting employee access to PD on a least-privilege basis;
  • technical:
    • encryption of data transmission channels between the user and the service;
    • irreversible hashing of user passwords;
    • token-based authentication with a limited validity period for credentials;
    • encryption of sensitive data at rest;
    • logging of security and access events;
    • regular backups;
    • physical access control to server equipment by the hosting provider.

11. Database location

11.1. The database containing personal data of Russian Federation citizens is physically located in the Russian Federation: Russian Federation, Moscow. The requirement of clause 5 article 18 of 152-FZ regarding primary collection of Russian citizens’ PD in databases located in the Russian Federation is satisfied.

12. Processing of client personal data (multi-tenant model)

12.1. The Service is a multi-tenant platform: each client (“Tenant”) uses an isolated workspace to build their own website or application.

12.2. With respect to personal data that the Tenant collects through their own website or application hosted on the platform, the parties agree on the following roles:

  • The Tenant is the controller of such PD. The Tenant independently determines the purposes and means of processing, obtains data subjects' consent, and is responsible to the data subjects and to Roskomnadzor;
  • The Controller (dynapi.ru) is the processor of such PD on behalf of the Tenant, in accordance with clause 3 article 6 of 152-FZ. The Controller processes PD exclusively on the basis of the Tenant’s instructions (expressed through the Service’s functionality) and does not use it for its own purposes.

12.3. The Tenant must independently notify Roskomnadzor of PD processing carried out through their website, in accordance with Article 22 of 152-FZ. The Controller is not responsible for the Tenant’s failure to fulfill this obligation.

12.4. The Tenant undertakes not to use the Service for processing special categories of PD (health, ethnicity, religion, etc.) or biometric PD. Violation of this obligation is grounds for immediate suspension of the Tenant’s access to the Service.

12.5. Prohibitions on Tenant content: it is forbidden to use the Service for posting materials that violate the legislation of the Russian Federation, including extremist, pornographic, copyright-infringing materials, as well as materials that unlawfully collect third-party PD.

13. Cookies

13.1. The Service and the marketing website use the following categories of cookies:

Necessary cookies (the Service cannot operate without them):

  • Session authentication cookies. Set upon user login to the Service, maintain the session between requests. Retained for a limited time; cleared on logout or upon expiration.

Analytical cookies (third-party, require consent):

  • Yandex.Metrica service cookies. Set by Yandex on the marketing site pages to identify the visitor and collect visit statistics. May be retained for up to 1 year. Loaded only after the visitor grants consent via the cookie banner.

13.2. The user may grant or withdraw consent to analytical cookies through the corresponding banner on first visit to the website. Withdrawal of consent does not affect the operation of the Service itself.

13.3. The user may delete cookies at any time via browser settings. This will require re-authentication in the Service.

14. Data subject rights

14.1. In accordance with Articles 14–17 of 152-FZ, the data subject has the right to:

  • receive information about the processing of their PD;
  • demand clarification, blocking, or destruction of their PD;
  • withdraw consent to PD processing;
  • appeal the Controller’s actions to the authorized body for the protection of data subjects’ rights (Roskomnadzor) or in court.

14.2. To exercise their rights, the data subject sends a request to support@dynapi.ru. The Controller reviews the request within 30 days of receipt.

15. Contact information

15.1. Person responsible for organizing PD processing in the Service:

  • Name: Individual Entrepreneur SOLOMANIDIN EVGENIY VLADIMIROVICH
  • Position: Individual entrepreneur
  • Email: support@dynapi.ru

15.2. For any questions related to PD processing, please contact the above email.