LeingeLeinge
Back to siteEN

Leinge Privacy Policy

1. General provisions

1.1. This Personal Data Processing Policy (the Policy) sets out how personal data is processed and protected when using https://leinge.com, its pages and forms (the Website).

1.2. Leinge is the name of the project and website administered by Individual Entrepreneur Igor Evgenyevich Lebezov.

1.3. The personal data controller (the Controller) is:

Individual Entrepreneur Igor Evgenyevich Lebezov, using the special tax regime "Tax on Professional Income". Taxpayer Identification Number (INN): 503625389485; Primary State Registration Number of an Individual Entrepreneur (OGRNIP): 326508100101236. Address: 25/13 Panfilova Street, Podolsk, Moscow Region, 142103, Russia. Email: support@leinge.com.

1.4. This Policy applies to Website visitors, people joining the waitlist, applicants for a pilot or cooperation, email subscribers and people contacting the Controller.

1.5. The Website is technically accessible over the Internet without territorial restrictions. The current processing configuration uses Russian infrastructure and does not involve transfers of personal data to foreign public authorities, foreign individuals or foreign legal entities. Before introducing such transfers, the Controller will update the documents and meet the applicable requirements of Russian law.

1.6. This Policy does not govern independent processing by external websites that users visit through links. The Controller does not embed external widgets, social plugins, maps, video players or other integrations that transmit visitor data to third parties unless they are expressly described in this Policy and the Cookie Policy.

2. Processing principles

The Controller:

  • processes data lawfully, fairly and only for predefined purposes;
  • does not collect excessive data;
  • keeps processing purposes and separate consents distinct;
  • retains data no longer than the specified periods;
  • restricts access to data;
  • does not disclose personal data to an unrestricted audience;
  • does not make decisions producing legal effects for users solely on the basis of automated processing;
  • does not use visitor, applicant or customer data to train artificial intelligence models;
  • does not carry out behavioural profiling, advertising retargeting or transfers to advertising networks at the initial stage of the Website's operation.

3. Data subjects and categories of data

3.1. Website visitors

Opening and using the Website may involve processing:

  • IP address;
  • request date and time;
  • requested page address and referral source;
  • browser type and version, operating system, device type and language;
  • technical HTTP headers;
  • session information, security events and the results of automated-request protection;
  • the identifier and settings of the user's cookie choice;
  • with separate analytics consent, visited pages, referral source, session duration and Website actions listed in the Cookie Policy.

3.2. Waitlist

The waitlist form must contain only the following fields:

  • email address, required;
  • name, optional;
  • area of interest in Leinge, optional;
  • a separate optional checkbox for marketing and news emails.

The Controller also records the request identifier, submission date and time, consent version, the fact that the checkbox was selected, IP address and browser information to the extent needed to demonstrate consent and maintain security.

3.3. Pilot or cooperation requests

Email address and name are required fields. Organization name, the selected area of interest and a comment are optional and are processed only when provided. The request identifier, submission date and time, consent version, the fact that the checkbox was selected, IP address and browser information are also recorded to the extent needed to demonstrate consent and protect the form.

3.4. Email subscribers

With separate optional consent, the following data is processed:

  • email address;
  • name, if provided;
  • subscription source, date and time;
  • marketing consent version;
  • subscription confirmation and unsubscribe status;
  • selected email topics, if this option becomes available on the Website.

Email-open and link-click tracking in UniSender is not used. An address is added to the active mailing list only after double opt-in confirmation by following the link in the confirmation email.

3.5. Personal data enquiries

The Controller processes the person's name, contact details, enquiry contents and information needed to verify identity and fulfil the request. Passport details and copies of documents are requested only where identity and authority cannot reasonably be verified in a less risky way.

3.6. Data not collected at the current stage

At the current stage, the Website does not provide for:

  • creating user accounts;
  • accepting payments;
  • uploading files, DWG projects or other documentation;
  • collecting payment details;
  • collecting special categories of personal data or biometric personal data;
  • collecting third-party data through forms;
  • integrations with Telegram, Google, Microsoft, Autodesk or other external platforms;
  • using data to train artificial intelligence;
  • automated profiling.

Before enabling accounts, payments, file uploads or new integrations, this Policy, the consents and the notification to Roskomnadzor must be updated.

4. Purposes, legal grounds and retention periods

4.1. Visitor technical data, security logs, protection tokens and cookie choices are processed to operate and secure the Website, protect forms and prevent abuse. Processing is based on the Controller's legitimate interest in ensuring Website security and operation, and on separate consent for actions that require consent. Security logs are retained for no more than 90 calendar days. Technical tokens are retained for the session or the period stated in the Cookie Policy.

4.2. To save cookie settings and demonstrate the user's choice, the record identifier, categories, text version, date and time, and technical browser and request information are processed. The preference cookie is stored for 1 year; the server-side record is retained for 3 years after the choice expires, is replaced or is withdrawn.

4.3. Visitor analytics is used only after separate consent. When enabled, visited pages, referral source, session duration, actions and technical characteristics may be processed for the periods stated in the Cookie Policy or until earlier withdrawal of consent.

4.4. Waitlist data is processed on the basis of separate consent for 3 months from the request date or until earlier withdrawal.

4.5. Pilot or cooperation request data is processed on the basis of separate consent and steps taken at the user's initiative before entering into a contract. If no contract is concluded, the retention period is 3 months from the last substantive interaction. If a contract is concluded, data is processed for the contract term and mandatory document-retention periods.

4.6. An email address is used for marketing and news emails only after separate prior consent and subscription confirmation. The period runs until unsubscribing or withdrawal, but for no more than 24 months from the latest confirmation.

4.7. The consent identifier, contact details, text version, date and time, selected settings and withdrawal record may be retained for 3 years after processing for the relevant purpose ends, to demonstrate compliance with obligations and protect lawful rights.

4.8. Data relating to enquiries from users or supervisory authorities is processed under Russian law for the period of consideration and the time needed to demonstrate fulfilment of the relevant obligation.

Once a purpose is fulfilled, a retention period expires or consent is withdrawn, data is deleted or destroyed unless an independent lawful ground for further processing exists.

5. Processing operations

The Controller may collect, record, organize, accumulate, store, update, retrieve and use personal data; grant access to persons acting on the Controller's instructions; and block, delete or destroy data. Processing is automated or combines automated and manual methods, with transmission over the Internet.

The Controller does not sell or publish data or provide it to independent advertising platforms.

6. Infrastructure and parties involved in processing

The frontend, backend, primary request database, consent log and server logs are hosted on a Russian server provided by Individual Entrepreneur Gleb Aleksandrovich Artamanov (SkyStark), INN 500717486839, OGRNIP 312500724100057. The server is physically located at the RU-MSK-UGR data centre (Moscow VDC), Building 147, 2 Ugreshskaya Street, Pechatniki Municipal District, Moscow, 115088, Russia. Requests submitted through Website forms are stored directly in Leinge's database and are accessible to the Controller through the administration panel. Web request contents are not automatically duplicated by email.

The domain and DNS are serviced by REG.RU Domain Names Registrar LLC in the Russian Federation. This provider may receive technical DNS request data and information needed to service the domain; it does not receive request contents.

The frontend, backend, primary database, consent log and server logs are serviced by Individual Entrepreneur Gleb Aleksandrovich Artamanov (SkyStark), INN 500717486839, OGRNIP 312500724100057. Processing takes place at the RU-MSK-UGR data centre at the Moscow address above, to the extent needed to provide infrastructure and technical maintenance.

Corporate email at support@leinge.com is serviced by VK Digital Technologies LLC, VK WorkSpace, in the Russian Federation. The mailbox contains only information users independently send to the Controller and subsequent correspondence; web requests are not automatically duplicated there.

Email campaigns following separate confirmed consent are serviced by UniSender Smart LLC, UniSender, in the Russian Federation. The data provided consists of email addresses, names if available, and subscription, confirmation and unsubscribe information.

Following separate cookie consent, Leinge's own analytics is used within its primary Russian database. Data is not passed to an external analytics provider. Raw IP addresses, full User-Agent strings, precise locations, contact details and form contents are not recorded in the analytics database. Yandex Metrica is disabled.

Yandex SmartCaptcha, provided by Yandex.Cloud LLC, protects forms against bots. The service receives the IP address, HTTP headers, form address, technical request parameters and verification token. It does not receive form field contents.

The Controller accepts providers' terms and uses services only in configurations consistent with this Policy. Only the Controller has direct user access to requests and the Leinge administration panel.

A private GitHub repository is used solely for source code. Real requests, personal data, production logs, database dumps, backups, cookie consents and access secrets must not be placed in it. Subject to this restriction, GitHub is not a recipient of Website visitors' personal data.

No CRM is currently used.

7. Data localization and cross-border transfers

7.1. The initial recording, organization, accumulation, storage, updating and retrieval of Russian citizens' personal data use databases located in the Russian Federation.

7.2. In the current configuration, no cross-border transfers of personal data take place. The primary database and consent log are located in Moscow; web requests are not duplicated to foreign services; only the Controller has access to production data; and only source code without personal data is sent to GitHub.

7.3. Email, mailing, analytics and protection services are used only in Russian configurations that do not transfer personal data to foreign recipients. If a foreign recipient, administrative access from abroad or foreign infrastructure is introduced in the future, the Controller will update the documents and meet applicable requirements before the transfer begins, including submitting a separate cross-border transfer notification where required by law.

8. Cookies

Necessary technologies and Leinge's own analytics are described in the Cookie Policy. Analytics is enabled only after separate consent. Detailed events are retained for no more than 90 days; daily aggregate metrics and pseudonymized identifiers for no more than 12 months. Yandex Metrica, marketing cookies, advertising pixels and retargeting are disabled.

Details of the data, retention periods and management procedures are set out in:

  • the Cookie Policy;
  • the Cookie and Analytics Consent.

9. Data protection

The Controller implements or ensures the implementation of measures appropriate to the nature and extent of processing, including:

  • access limited to the Controller and technically necessary access for contracted providers;
  • use of TLS;
  • keeping secrets outside the repository;
  • restricting network access to the database;
  • updating software;
  • logging administrative actions;
  • backups on the same Russian server; the documents are updated if backup-storage arrangements change;
  • protecting forms against forged requests and automated submissions;
  • deleting data when retention periods expire and following consent withdrawal;
  • regularly checking actual processing against the documents and the notification to Roskomnadzor.

Specific information whose disclosure could reduce system security is not published.

10. User rights

Users may:

  • obtain information about the processing of their data;
  • request the correction, blocking or destruction of inaccurate, unlawfully obtained or excessive data;
  • withdraw consent;
  • request that processing stop where no other lawful ground exists;
  • opt out of marketing emails;
  • change or withdraw cookie consent through the "Cookie settings" link in the Website footer;
  • challenge the Controller's actions before Roskomnadzor or a court.

11. Enquiries and withdrawal of consent

Enquiries may be sent:

  • by email to support@leinge.com;
  • by post to 25/13 Panfilova Street, Podolsk, Moscow Region, 142103, Russia.

We recommend using "Personal data" as the email subject. The enquiry should identify the contact used on the Website and explain the request. The Controller may ask for reasonable proof of identity without collecting excessive data.

Following consent withdrawal, the Controller stops processing and deletes the data within the period required by law, unless another ground for continued processing exists. A minimal consent, withdrawal or unsubscribe record may be retained for 3 years to demonstrate fulfilment of the request and prevent repeat mailings.

12. Users without full legal capacity

The Website is not specifically intended for children, but does not impose a formal age restriction. A person who cannot independently give valid consent under applicable law must use the Website with the involvement of a legal representative. The Controller may delete a request where there are reasonable grounds to believe that consent was not properly obtained.

13. Changes to this Policy

This Policy is reviewed when forms, purposes, data categories, providers, retention periods, storage locations, analytics, CAPTCHA, access arrangements or cross-border transfers change, and before accounts, payments or file uploads are introduced.

A new version is published on the Website with its version number and date. Where a change requires new consent, the relevant processing does not start until that consent has been obtained.

14. Contact details

Individual Entrepreneur Igor Evgenyevich Lebezov
INN 503625389485, OGRNIP 326508100101236
Address: 25/13 Panfilova Street, Podolsk, Moscow Region, 142103, Russia
Email: support@leinge.com

Leinge, 2026
Privacy policyCookie policy
Privacy policy | Leinge