1. Scope
This Privacy Notice explains how personal data of visitors to smolserver.com, customer representatives and people who contact the controller are handled. It reflects Russian Federal Law No. 152-FZ on Personal Data and, where applicable, Regulation (EU) 2016/679 (GDPR).
2. Controller and contact details
Controller/operator: Smol Server («Смол Сервер»).
Website: https://smolserver.com
General contact: info@smolserver.com
Privacy enquiries and rights requests: privacy@smolserver.com or https://smolserver.com/privacy-request/
No data protection officer or EU representative has been appointed. If an appointment becomes legally required, the details will be published before the relevant processing begins.
3. People covered
This Notice covers website visitors, prospective and current customers, their personnel and representatives, and people making a data rights request. The website is not intended to knowingly collect children's data.
4. Data processed
An enquiry may include an optional name or organisation, an email address, phone number, messenger username or another contact detail, the enquiry text, selected language, and submission timestamps.
For form security and abuse prevention, the application creates a non-reversible source pseudonym from an IP address using a secret key; the raw IP address is not stored in the enquiry record. Infrastructure may briefly process network information, a request identifier, timestamps and response status for security and troubleshooting.
A rights request may include a reply contact, request type, explanation, selected jurisdiction, proportionate identity-verification information, workflow status and outcome. Do not submit passwords, access keys, special-category data or information unrelated to the request.
5. Purposes and legal bases
Enquiry data is used to reply, clarify requirements, prepare an estimate and take steps requested before entering a contract. For people in the EU/EEA, the primary basis is Article 6(1)(b) GDPR and, where required, consent under Article 6(1)(a). Security, abuse prevention and legal-claim protection rely on the controller's legitimate interests under Article 6(1)(f), subject to a balancing assessment. Compliance with mandatory law relies on Article 6(1)(c).
For Russian data subjects, processing relies on consent, entering or performing a contract, compliance with operator duties, or another basis under Article 6 of Law No. 152-FZ. The enquiry consent does not cover advertising or marketing messages.
Rights requests are processed to comply with legal obligations and protect the requester. The controller does not use profiling or solely automated decisions producing legal or similarly significant effects.
6. Processing and required information
Operations may include collection, recording, organisation, storage, updating, retrieval, use, disclosure to authorised processors, restriction, anonymisation and deletion, primarily by automated means. Required form fields are necessary to respond; without a contact and a description, the enquiry cannot be handled. Providing a name or organisation is optional.
7. Recipients and processors
Access is limited to people who need it to handle the enquiry or operate and secure the systems. Hosting and data-centre providers, email providers, technical support providers and contracted specialists bound by confidentiality may process data as necessary. Data may be disclosed to public authorities where the law requires it. Personal data is not sold or shared for independent advertising.
8. Location and international transfers
Processing locations and providers are selected subject to applicable law. Where Russian localisation rules apply, the controller undertakes to organise the relevant initial collection and storage using databases in Russia. A transfer from the EU/EEA to a country without an adequacy decision will use an applicable Chapter V GDPR mechanism, such as Standard Contractual Clauses, or a valid Article 49 derogation. Details of the actual safeguard are available on request when such a transfer occurs.
9. Retention
Enquiries are normally retained for up to 180 days. Data-rights requests and evidence of their resolution are retained for up to 1,095 days after closure. Administrative audit records are retained for up to 1,095 days. A period may be shortened following withdrawal or a valid request, or extended where mandatory law, a contract, an incident investigation or a legal claim requires it. Data is then deleted or anonymised unless a lawful basis requires continued storage.
10. Cookies and local storage
Necessary technologies are used for form and administrative-session security and local language and theme preferences. Optional analytics may load only after a separate opt-in. No external analytics provider is configured in the current version. The Cookie Notice explains durations and how to change the choice. Advertising and cross-site trackers are not used.
11. Security
Measures include access controls, encrypted transport, strong password hashing, administrative audit trails, backups, request throttling, log minimisation, deletion schedules and confidentiality duties. No security measure removes all risk; controls are reviewed according to the data and threats involved.
12. Your rights
Depending on applicable law, you may request information and access, rectification, erasure, restriction, object to processing, receive portable data, withdraw consent without affecting earlier lawful processing, and complain to a supervisory authority. EU/EEA rights are described in Articles 12–22 GDPR; Russian rights are governed by Law No. 152-FZ.
Submit a request to privacy@smolserver.com or https://smolserver.com/privacy-request/. Only proportionate identity evidence may be requested to protect your data. Requests are handled within the applicable statutory period. In Russia, the supervisory authority is Roskomnadzor; in the EU/EEA, you may contact the authority for your habitual residence, workplace or the alleged infringement.
13. Changes
This Notice is effective from 25 August 2026. A revised notice will be published here with a new version and date. Material changes will not be applied to existing data incompatibly with the original purpose and legal basis.