Current version · Personal data processing policy
How MobiProxyDesk processes and protects data
The controller is sole proprietor Alexander Viktorovich Laponkin. Full provider details, address, business hours, and contacts are published in the operator profile on this page. This policy applies to site visitors, registered customers, company representatives, and people contacting support.
- Version
- 2026-08-16-privacy-2
- Effective from
- August 16, 2026
- SHA-256
- 0c603d691be0e6c128455864418d58d862e91ed8346949bc8807dd3f1ac1580e
Provider and company details: view company details
Registration and contract performance
Subjects: customers and representatives of companies or sole proprietors. Data: name, email, optional phone, account type, organization name and INN where applicable, account ID, accepted document versions, orders, rentals, and requests. Purposes: creating the portal account, entering into and performing the contract, delivering and supporting proxies, confirming actions, and handling claims. Operations: collection, recording, organization, storage, updating, use, restriction, and deletion. Grounds: contract formation and performance and compliance with legal duties.
Sign-in, security, and audit
Subjects: visitors, users, and administrators. Data: IP address, sign-in time and result, user agent, session, technical request ID, security events, and portal actions; passwords are stored only as irreversible hashes. Purposes: authentication, password-guessing and abuse prevention, incident investigation, and proof of significant operations. Grounds: contract performance, the controller's data-security duties, and a legitimate security interest that respects the subject's rights.
Support and documents
Subjects: customers, their representatives, applicants, and persons covered by an official request. Data: contacts, messages, attachments, the related operation and evidence, and after payments launch, payment and fiscal-document details without bank-card secrets. Purposes: answering requests, correcting errors, handling claims, and meeting applicable accounting, tax, and other legal duties. Operations include receipt, registration, verification, storage, use, lawful disclosure to an authorized recipient, restriction, and destruction.
Cookies, language, and optional analytics
Strictly necessary session and cookie-choice data supports sign-in, security, and remembering the choice. Language is retained between visits only after a voluntary Functional choice. Yandex Metrica is a separate optional category: its code is not loaded and no data is sent until the visitor selects Accept analytics + functional. Refusal does not restrict browsing, registration, the portal, or purchasing. The purposes are aggregate measurement of visits and routes, successful registration and purchase-start events, and interface improvement. The legal basis for this optional processing is the visitor's separate consent; advertising and marketing profiling are not performed.
Data sent to Yandex Metrica
Only after separate consent does the browser contact the Yandex Metrica provider. The provider sees the network request's technical IP address and may receive event time, browser and device characteristics, technical analytics-storage identifiers, and a sanitized page path. Before sending, the site removes the query string, hash fragment, and dynamic identifiers from the path and supplies an empty referrer. Goals contain only the fixed names registration_success and purchase_start with no parameters. The site does not send a name, email, phone number, INN, raw user ID, account, order, or payment ID, proxy credentials, form or page contents, UTM tags, query string, or hash fragment.
Recipients and processors
Access to the primary system is limited to the controller and authorized administrators within their roles. Avguro Technologies LLC (Jino, INN 7706641390) operates the Moscow hosting infrastructure as a technical processor under contract and is not permitted to use customer data for its own purposes. After separate consent, technical analytics data is received by YANDEX LLC (16 Leo Tolstoy Street, Moscow) as the Yandex Metrica provider under the then-current service terms. Data is disclosed to public authorities only in response to a verified lawful demand. Customer data is not sold, disclosed for advertising, or made public.
Disabled analytics features
Webvisor, session and form recording, click maps, link tracking, ecommerce, content analytics, and tag manager are disabled. The service does not call setUserID, send user parameters, or create an account mapping for cross-device tracking. Analytics goals contain no parameters, free text, or personal data.
Localization, route, and cross-border transfer
Recording, organization, accumulation, storage, updating, and retrieval in the primary MobiProxyDesk system are performed in the Russian Federation; operational logs and service backups are also kept there. For a user in the Russian Federation, the contractual Metrica provider is YANDEX LLC in Moscow. The site does not independently send analytics data to any other foreign recipient. If the contractual recipient, the actual processing arrangement, or applicable requirements change so that a cross-border-transfer notice or another mandatory procedure is required, the controller suspends new transmissions until the requirement is satisfied and publishes updated information.
Retention, withdrawal, and destruction
A session lasts no more than 30 days; password-guessing protection records are kept 30 days after the last event; completed Telegram updates and flows are kept 30 days. Sign-in, security, and administrator-access logs are kept up to 3 years. Contract operations, financial evidence, requests, and documents are kept up to 5 years after the relationship ends, or longer only when directly required by law or a documented legal hold. The cookie choice is kept for up to one year. Technical Yandex Metrica identifier periods follow the provider's current documentation: most analytics identifiers last up to one year, certain technical cookies last up to two years, and yandexuid may last longer than one year in some countries. The counter interface provides no single operator-controlled retention period for all provider data, so the controller does not promise an arbitrarily shorter provider period. After withdrawal, future transmissions stop, the in-browser counter instance is destroyed, and first-party _ym-prefixed cookies and storage accessible to the site are removed. Data already sent to the provider is processed and deleted under Yandex's then-current terms and documentation, or earlier when an applicable verified request requires it. Other data is deleted or anonymized after its period; backups are isolated from routine use and overwritten within their rotation cycle.
Data-subject rights and requests
A subject may obtain information and an accessible copy, request correction, restriction, or destruction of unlawfully obtained, inaccurate, or unnecessary data, withdraw a separate consent, and challenge the controller's actions. Send the request from the public email to the support address in the operator profile or through a protected portal request, identifying the account or other facts needed to verify identity and the relationship safely. A response is provided within 10 business days and may be extended by no more than 5 business days after a reasoned notice.