This Policy has been developed in accordance with Federal Law of 27.07.2006 No. 152-FZ “On Personal Data”.
1. General Provisions
1.1. Data Controller — LLC “AELITA PRODUCTION” (TIN 4000027320, OGRN 1254000006644).
1.2. This Policy defines the procedure for processing personal data that the Data Controller receives through the Website and Telegram bot, as well as through video surveillance at the venue where events are held (Section 3).
1.3. Use of the Website or Bot constitutes agreement to the terms of this Policy. If you do not agree, please refrain from using them.
1.4. This Policy may be amended unilaterally. We recommend checking the current version regularly.
1.5. The Operator also owns the website koroche-dance.ru (KOROCHE DANCE COMPANY). This Policy applies to the Site aelita-production.ru and the Operator's Telegram bot; the processing of personal data on koroche-dance.ru is governed by a separate Policy published on that resource. Both resources belong to the same operator and are listed as resources of the same operator in the notification submitted to Roskomnadzor.
2. Purposes of Personal Data Processing
Conclusion and performance of contracts with customers (provision of services, sale of tickets to entertainment events); registration for the Operator's free events (open meetings, workshops and other events with free admission) and admission to them; maintaining the user's personal account on the Site and purchase history; performance of the AELITA COMMUNITY subscription contract, including automatic monthly charges from the saved payment method and notifications about them; feedback from users — handling enquiries, applications and ticket refund requests; handling a ticket refund request on the grounds of “illness” or “death of a family member or close relative”; collection and publication of audience reviews of events; improving the quality of services and analytics, including the recording of on-page actions via Yandex.Metrica Session Replay (for details, see the Cookie Agreement); sending informational messages (with consent); ensuring the safety of visitors and staff and protecting property at the event venue (video surveillance); conclusion and performance of contracts with artists, authors, contractors and partners, as well as accounting and tax records; compliance with the requirements of the legislation of the Russian Federation.
3. Categories of Data Processed
Surname, first name, patronymic; phone number; email address; Telegram ID and username; the content of messages, photographs and documents (when voluntarily provided); Website account data — name, email address, password hash (the password itself is not stored in any form) and purchase history (service name, amount, date, payment identifier — without payment card details, which never pass through the Data Controller); for a ticket purchase to a live event — additionally, name, email address, selected seat (row and seat, or a note that seating is unassigned), ticket number and series, ticket redemption status (redeemed/valid); when a ticket is transferred to another person via the personal account — the recipient’s name and email address, provided by the transferring buyer; for registration for a free event — name, email address, registration identifier, date and time of registration and attendance status; video recordings of visitors and staff obtained through video surveillance at the venue where events are held; when submitting a ticket refund request on the grounds of “illness” or “death of a family member or close relative” — medical documents and death certificates attached to the request (a special category of personal data, article 10 of Federal Law 152-FZ; processed solely to review the request, stored separately from the rest of the order data with restricted access, and deleted after the period specified in clause 5.4); other data necessary for the provision of services.
4. Legal Basis for Processing
Consent of the personal data subject; performance of a contract to which the subject is a party (including maintaining an account and purchase history at the subject's own initiative); exercise of the Data Controller's rights and legitimate interests in connection with ensuring the safety of visitors and staff and protecting property (clause 7, part 1, article 6 of Federal Law No. 152-FZ of 27.07.2006 “On Personal Data”) — with respect to video surveillance at the venue where events are held; with respect to medical documents and death certificates attached to a ticket refund request — processing is carried out on the basis of the written consent of the personal data subject (part 1, article 10 of 152-FZ), which is deemed to have been given when the corresponding documents are voluntarily attached to the request; performance of obligations established by Russian law.
5. Processing Procedure and Conditions
5.1. Processing is carried out using both automated and non-automated means.
5.2. The Operator takes the necessary organisational and technical measures to protect personal data from unauthorized access, destruction, modification, blocking, copying, and distribution. The personal account password is stored in an irreversibly hashed form (scrypt) — the Operator never knows the password itself and it cannot be recovered, only reset.
5.3. Transfer of personal data to third parties is carried out only with the data subject's consent or in cases provided for by law. To process payments, the Operator transfers the necessary data (amount, purpose of payment, contact) to the payment service YooKassa (operator — NKO YuMoney LLC, OGRN 1127711000031, INN 7750005725) — the Customer's bank card details are not transferred to the Operator and are not processed by it. When a ticket to an entertainment event is purchased, the name and the selected seat become available to the Operator's staff at the entrance (an internal ticket control system, not a third party) — solely to verify the ticket and grant admission to the event; the electronic ticket contains a QR code with a signed identifier of the order and the seat, and verification is performed against it. When registering for a free event, the participant's name and email address are sent to the event organiser — a member of the Operator's staff, including as a notification in the Operator's internal Telegram chat; the participant is sent an electronic ticket with a QR code containing a signed registration identifier, which is presented at the entrance. For certain free events, registration is handled through the Timepad service (TimePad Ltd) — in that case the participant's surname, first name, phone number and email address are processed by that service on the Operator's instructions and become available to the Operator as the organiser of the event. When a subscription with automatic payments is set up, the bank card details are kept by the YooKassa payment service; the Operator keeps only the identifier of the saved payment method and its label (card type, the last four digits of the number and the card expiry date).
5.4. Retention periods are determined by the purposes of processing and legal requirements. Once the purposes have been achieved or consent is withdrawn, the data is destroyed. Specific retention periods by category:
- Account data — until the account is deleted at the subject's request via aelita.production@yandex.ru.
- Data on the purchase of a ticket or other service (including name, contact details, amount, date, payment identifier, ticket number and series) — for the periods established by accounting and tax legislation, but not less than 5 years from the date of the transaction. This data cannot be deleted at the subject's request before the expiry of this period, since its retention is an obligation of the Data Controller.
- Data of the recipient of a transferred ticket (name, email address) — under the rules established for ticket purchase data, as part of which they are stored; used only to send the ticket to the recipient and to notify them of the postponement or cancellation of the event and of the ticket refund.
- Data on an unfinished order (checkout started but not paid: the step at which checkout stopped, the selected seats or service, the amount, name, email address, phone number, and the reason given by the payment service for declining) — no more than 30 days from the last action on the order, after which they are deleted automatically. They are used to handle enquiries about a failed purchase, to find faults in the checkout process and to send the buyer one service email saying that the order has not been paid, with a link to complete the checkout; no advertising messages are sent using this data.
- AELITA COMMUNITY subscription data (plan, name, email address, phone, payment method identifier and label, card expiry date, dates and amounts of charges and refunds, record of the consent to automatic charges and of its withdrawal) — for as long as the subscription is in effect and thereafter as established for purchase data; when the personal account is deleted, the subscription record is deleted with it, while information on payments made is kept as part of the purchase data.
- Data for paying for the subscription by invoice from an organisation (name, TIN, KPP and address of the organisation, accounting email address, name and contact details of the participant, invoice and act numbers) — for as long as the subscription is in effect and thereafter as established for purchase data and accounting documents.
- Data on registration for a free event, and enquiries submitted through feedback forms and the Telegram bot — for 5 years from the date of the event or the date of the last message, respectively. This period is set based on the need to confirm the circumstances of the event and to consider possible enquiries and claims within the limitation periods established by civil law.
- Video recordings obtained through video surveillance — no more than 30 days from the date of recording, unless a longer period is required to investigate a specific incident or is established by an agreement with the organisation maintaining the video surveillance system.
- Medical documents and death certificates attached to a ticket refund request — until the request has been reviewed, plus 3 years (the general limitation period under article 196 of the Civil Code), after which they are automatically deleted. The refund request itself (without the documents) is retained under the general procedure established for ticket purchase data.
5.5. Personal data processed in connection with the personal account, with ticket purchases and with registration for free events is stored on infrastructure physically located within the territory of the Russian Federation, in accordance with Part 5 of Article 18 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”.
6. Consents and dissemination of personal data
6.1. Consents to the processing of personal data, to receiving information messages and to the dissemination of personal data when a review is published are drawn up as self-contained documents, the texts of which are published on the page “Consents to the processing of personal data”. Each consent is given by a separate action; consent boxes are not pre-ticked.
6.2. Publishing a review together with the author's name or pseudonym constitutes dissemination of personal data and is carried out on the basis of a separate consent in accordance with article 10.1 of Federal Law No. 152-FZ. The list of data permitted for dissemination is given in section 3 of the consent texts; the conditions for publishing the name and any prohibition on using the review outside the site are set by the subject personally in the review form, and any prohibition set is published together with the review. Silence or inaction on the part of the subject does not constitute consent.
6.3. Other data provided by the author of a review (email address, telephone number) is not permitted for dissemination and is not published.
7. Action in the event of personal data incidents
7.1. On discovering an unlawful or accidental transfer of personal data resulting in a loss of confidentiality, the Operator notifies the authority responsible for protecting the rights of personal data subjects within 24 hours of discovering the incident and submits the results of its internal investigation within 72 hours, in accordance with part 3.1 of article 21 of Federal Law No. 152-FZ.
7.2. If an incident creates a risk of harm to personal data subjects, the Operator notifies them, stating which data is affected and what measures should be taken.
7.3. The internal procedure for such incidents is set out in a separate internal regulation of the Operator.
8. Rights of personal data subjects
8.1. The User is entitled to: receive information about the processing of their data; demand rectification, blocking or destruction of the data; withdraw consent to processing (the Operator then ceases processing and destroys the data, except in cases provided for by law).
8.2. A request to exercise the rights set out in clause 8.1 is sent to aelita.production@yandex.ru and must include the surname and first name, the email address used when registering the personal account, purchasing a ticket, or registering for an event, and, where applicable, the order or registration number to which the request relates, together with a description of the request. The Data Controller may ask for additional information needed to confirm that the request comes from the data subject themselves.
8.3. The Operator considers the request and sends a reply within 30 days of receipt, unless a different period is established by the legislation of the Russian Federation. If the request does not contain the information set out in clause 8.2, or if it is impossible to confirm that the request comes from the personal data subject, the Operator may ask for clarification or refuse to act on the request, stating the reason for refusal.
9. Liability
9.1. The Data Controller is liable for breaches of personal data processing procedures in accordance with Russian Federation law.
9.2. The User is responsible for the accuracy of the data provided.
10. Contact information
TIN 4000027320 · KPP 400001001 · OGRN 1254000006644
248016, Russia, Kaluga region, Kaluga, Lenin St., 51
See also: Information on the personal data protection measures implemented · Cookie Policy · Public offer agreement · All documents
← Back to home