LEGIXSTORE / DOCUMENTS

Personal data policy

Information used by the store, its purposes and your data rights.

Edition dated

1. Controller and scope

This policy covers LegixStore visitors, buyers and people contacting support. The controller is the person determining the purposes and means of the store’s data processing.

2. Information processed

Order information includes email, order number and contents, products, quantities, amounts, settlement currency and network, timestamps, statuses, invoice identifiers and transaction details. The secret order link is associated with access to the product.

Support information includes email, topic, message, an optional order number, request reference and submission time. Infrastructure also receives IP addresses, HTTP request details, timestamps, browser information and technical errors to the extent necessary to operate and protect the service.

Do not include other people’s data, health details, identity documents, passwords or payment secrets in free-text fields. The store does not request biometric identification or use a form for special categories of personal data.

3. Purposes and legal grounds

Order data supports checkout, calculation, payment confirmation, delivery, status checks and claims. Processing necessary for the contract or steps requested before it relies on contractual necessity, including Article 6(1)(5) of Russian Federal Law 152-FZ where applicable.

Support data is used to address the specific question and protect the parties’ rights; technical logs support diagnostics, abuse prevention and access protection. Each purpose requires an appropriate legal ground and processing is limited to what it needs.

Orders and support requests do not constitute consent to advertising, third-party marketing or publication of correspondence. Where consent is necessary for a separate purpose, it must be requested separately from the terms and this policy. Continued browsing is not blanket consent.

4. Processing operations

Operations include collection, recording, organisation, storage, correction, retrieval, use, disclosure where lawfully justified, restriction, erasure and destruction. Some operations are automated; authorised staff handle others when reviewing orders and requests.

Prices and order statuses are calculated automatically. You may request human review of a disputed automated outcome. An incompatible new purpose requires its own lawful basis.

5. Service providers and recipients

The store uses website hosting, payment processing and order fulfilment services. Invoice creation sends the payment service the amount, chosen payment instrument and technical identifier. Order fulfilment services receive only information necessary to deliver the selected product. These disclosures do not authorise use of buyer data for other purposes.

An external payment form may process technical and payment information under its provider’s own terms. External image hosts receive technical request information when their images load. Consider those services alongside this policy.

Contractors may receive information only on an appropriate legal basis and subject to defined obligations. Authorities receive information where required or permitted by law. Email and correspondence are not intended for public disclosure.

6. Location and international transfers

The store’s deployment configuration specifies Render and a database in Frankfurt, Germany. This policy therefore does not claim that all data is processed in Russia or that no foreign access occurs.

Where Article 18(5) of Russian Federal Law 152-FZ applies, collection of Russian citizens’ data must meet its localisation requirements. Cross-border transfers require a separate assessment of legal grounds and applicable procedures, including regulator notification where required. Consent does not replace compliance with localisation rules.

7. Retention and ending processing

Order data is needed for fulfilment and related claims, then only for mandatory records retention and lawful protection of rights. Support data is used until the request is resolved and, for a dispute, for the period needed to resolve it. Technical records must not outlast their security and diagnostic purpose.

The specific period depends on the purpose, record category and applicable retention duty. Data must be erased or anonymised when its purpose or basis ends unless law requires continued retention. Clearing browser storage does not erase server orders. This policy does not promise automatic erasure of all order history when a page closes or after a fixed number of days.

8. Security and confidentiality

Access is limited to work-related purposes. The project provides secret-link order pages, encryption of stored issued codes, access controls and additional operator login verification. These measures are not an absolute guarantee against incidents.

Protect your order link and device. On a shared computer, remove store data and browsing history containing the secret link after first saving it securely elsewhere.

9. Your rights and requests

You may request information about processing and its grounds, correction, restriction or erasure of unlawfully processed information, withdraw separately given consent and challenge the controller’s actions. Withdrawal does not end processing supported by an independent lawful ground.

For a request through Help, identify the data concerned and provide a reply email. The controller may make a proportionate identity check without requesting excessive information. Applicable legal response periods apply; any necessary continued retention should be explained with its grounds and period.

10. Browser data and updates

The cart, display currency, recent order links and language setting are described in Cookies and browser storage. Accepting the terms does not enable advertising analytics.

The edition date appears at the top. Updates do not retroactively authorise new processing purposes or replace consent where it is needed.