Personal Data Processing Policy
The rules, purposes and safeguards governing personal data processing on this website.
1. Controller and scope
ФГБОУ ВО «Санкт-Петербургский государственный архитектурно-строительный университет», 190005, Россия, г. Санкт-Петербург, 2-я Красноармейская ул., д. 4, acts as the data controller. This Policy applies to the public website, its question and membership forms and the administrative workspace.
2. Principles and legal grounds
Processing is lawful, fair, purpose-limited, proportionate and no longer than necessary. The grounds are the data subject’s specific, informed and unambiguous consent, steps taken at the subject’s request before an agreement and legal obligations where applicable.
3. Data, subjects and purposes
- Website visitors: language and cookie choice, security request data.
- People asking a question: name, organisation, position, email, phone or messenger, subject and message.
- Membership contacts: organisation type and city, contact person, position, contact details, comment and optional PDF/DOCX attachment.
The purposes are responding, considering consortium participation, communication, information security and evidencing lawful processing.
4. Operations and methods
The controller may collect, record, organise, store, update, retrieve, use, provide to authorised processors, restrict, delete and destroy data using automated and non-automated methods. No solely automated decision with legal or similarly significant effect is made.
5. Recipients and infrastructure
Access is limited to authorised consortium staff and contracted hosting, email or technical-support providers only where required for the stated purposes and subject to confidentiality and security obligations. Data is not made public or sold. Primary collection and storage for data subjects in Russia must use databases located in the Russian Federation; cross-border transfer is not planned and requires a separate assessment before activation.
6. Retention and deletion
Form records are retained while the request is handled and for up to three years after the last substantive interaction to resolve follow-up questions and evidence lawful processing, unless a shorter period is requested or a longer period is required by law. Attachments are removed when no longer needed. Security rate-limit records expire automatically. After the purpose is achieved or consent is withdrawn, data is deleted or anonymised within the period required by law unless another lawful ground applies.
7. Security
Measures include access control, Argon2id administrator authentication, hashed session tokens, strict cookies, encryption in transit, CSP and security headers, server-side validation, request throttling, restricted file types, isolated storage, logging and backups appropriate to the deployed environment.
8. Rights and requests
You may ask what data is processed, request a copy, correction, restriction or deletion, object where applicable and withdraw consent by emailing privacy@example.ru. Please provide enough information to identify the relevant request without sending unnecessary identity documents.
9. Updates
The current version is always published at this address. Material changes are dated and, where required, renewed consent is requested.
