PERSONAL DATA CONTROLLER:
IE Panova Elvira Viktorovna (Individual Entrepreneur)
TIN (INN): 631938286341 · OGRNIP: 312631925500061
Address: Samara, Russia
Email: aidesignspace.pro@gmail.com · Support: aidesignspace.pro@gmail.com
This Privacy Policy (hereinafter — the "Policy") defines the procedures for processing and protecting personal data of users (hereinafter — "Data Subjects" or "Users") of the AI Design Space online platform (hereinafter — the "Platform"), located at https://aidesignspace.pro, including the Telegram bot @aidesignspace_bot (hereinafter — the "Bot").
The personal data controller is IE Panova Elvira Viktorovna (hereinafter — the "Controller").
By using the Platform, you confirm your consent to the processing of personal data in accordance with this Policy.
1. General Provisions
1.1. Legal Framework
1.1.1. This Policy has been developed in accordance with:
- Federal Law No. 152-FZ dated July 27, 2006 "On Personal Data" (hereinafter — 152-FZ);
- Federal Law No. 149-FZ dated July 27, 2006 "On Information, Information Technologies and Information Protection";
- Government Decree No. 1119 dated November 1, 2012;
- Orders and guidelines of Roskomnadzor (Russian Federal Service for Supervision of Communications);
- General Data Protection Regulation (GDPR) of the EU — to the extent applicable to Russian controllers.
1.2. Terms and Definitions
Personal Data — any information relating directly or indirectly to an identified or identifiable individual.
Personal Data Processing — any action (operation) or set of actions performed on personal data.
Controller — a person organizing and/or carrying out the processing of personal data.
Data Subject — an individual to whom personal data relates.
Cookies — small text files placed on the User's device when visiting a website.
Data Anonymization — actions that make it impossible to determine the attribution of data to a specific individual.
1.3. Processing Principles
1.3.1. Processing on a lawful and fair basis.
1.3.2. Processing is limited to specific, predetermined, and legitimate purposes.
1.3.3. Data is not excessive in relation to the stated purposes.
1.3.4. The Controller takes measures to ensure accuracy and currency of data.
1.3.5. Storage — no longer than required by the processing purposes.
2. Data We Collect
2.1. Registration Data
| Registration Method | Data Collected |
|---|---|
| Google OAuth | Email, first and last name, Google ID, avatar URL, email verification status |
| Telegram | Telegram ID, username, first and last name, interface language |
| Email + code | Email, name (optional), verification code (temporary) |
2.2. Automatically Collected Data
- IP Address — security, fraud prevention;
- User-Agent — browser, OS, and device information;
- Cookies and Sessions — authentication and personalization;
- Visit Data — login time, pages visited, referrer;
- Interaction Logs — clicks, generations, downloads, errors.
2.3. Service Usage Data
- Prompts — text queries for AI generations;
- Uploaded Files (Assets) — images, video, audio;
- Generated Content — results of AI generations;
- Project Metadata — names, generation settings;
- Generation History — log of all generations with timestamps.
2.4. Financial Data
- Transaction data (amount, date, plan);
- Anonymized card token, payment status (the Controller does not store full card details);
- Invoices and receipts; for legal entities — organization details.
2.4.2. Bank Card Data
When saving a bank card for automatic payments, data is transmitted directly to the payment provider and processed in accordance with PCI DSS Level 1 standards.
Data stored on the Platform:
- Unique card token (cannot be used to make payments outside the Platform);
- Last 4 digits of the card number;
- Payment system brand (Visa, Mastercard, MIR);
- Card expiration date;
- Binding status (active / unlinked).
Data the Controller does NOT store:
- Full card number;
- CVV/CVC code;
- PIN code;
- Any other data that would allow a payment without the payment provider.
Legal basis: consent of the data subject (Art. 6(1)(a) of Federal Law No. 152-FZ), explicitly given when saving the card.
Retention periods:
- Card token — until the User revokes consent or deletes their account;
- Transaction data — 3 (three) years from the date of the transaction (as required by accounting regulations);
- Consent for card storage (fact, date, IP address) — for the entire subscription period + 1 year.
Security measures:
- Encryption of tokens at rest;
- Card data access restricted to the certified payment provider;
- Regular security audits;
- Immediate token deletion upon consent revocation.
User rights:
- View the list of saved cards in "Account → Payments";
- Delete any saved card;
- Revoke consent for card storage (all tokens are deleted immediately);
- Request information about card data processing.
2.5. Referral/Partner Program Data
- Referral links, referral statistics;
- Payout details (card, wallet, bank account);
- Partner documents (sole proprietor/company details, acceptance certificates).
⚠️ Important: The Controller does not collect special categories of personal data (biometric, racial, political, religious, medical), except where such data is contained in files uploaded by the User.
3. Purposes of Personal Data Processing
| Processing Purpose | Description |
|---|---|
| Platform Access | Registration, authentication, account management |
| AI Generations | Transmitting prompts and references to AI providers |
| Asset Storage | Storing files in Cloudflare R2 |
| Payment Processing | Billing, invoices, receipts, subscriptions |
| Technical Support | Responding to inquiries, resolving issues |
| Marketing | Newsletters and offers (with consent) |
| Referral Program | Tracking referrals, accruing rewards |
| Security | Fraud prevention, detecting violations |
| Analytics | Behavior analysis, interface optimization |
| Legal Compliance | Fulfilling government authority requirements |
3.2. Additional Purposes (with Separate Consent)
- Using generation examples in marketing;
- Training AI models (anonymized data);
- Email promotional mailings (with unsubscribe option).
4. Legal Basis for Processing
4.1. Data Subject Consent
The primary legal basis is data subject consent (Article 6, Part 1 of 152-FZ). Provided upon registration (acceptance of the offer), by consent checkbox, and through continued use.
4.2. Contract Performance
Processing for contract performance (Article 6, Part 1, Clause 5 of 152-FZ).
4.3. Legitimate Interests of the Controller
Fraud prevention, security assurance, intellectual property protection (Article 6, Part 1, Clause 7 of 152-FZ).
4.4. Legal Obligations
Providing data upon government authority requests, retaining data for tax reporting (Article 6, Part 1, Clause 2 of 152-FZ).
5. Storage and Protection of Personal Data
5.1. Retention Periods
| Data Type | Retention Period |
|---|---|
| Account Data | Until account deletion + 30 days |
| Assets (Files) | According to plan (from 30 days to indefinite) |
| Generation History | 12 months + manual deletion |
| Access Logs (IP, User-Agent) | 6 months (Federal Law No. 97-FZ) |
| Financial Documents | 5 years (Tax Code of the Russian Federation) |
| Cookies and Sessions | From several hours to 12 months |
| Referral Program Data | 24 months |
Upon expiration of retention periods, data is destroyed or anonymized.
5.2. Security Measures
Organizational: appointment of responsible officer, internal regulatory acts, access rights segregation, data carrier tracking.
Technical:
- HTTPS (TLS 1.2+) for all connections;
- Password encryption (bcrypt), session encryption (JWT), encryption of sensitive fields;
- OAuth 2.0, Telegram Auth, MFA (optional);
- Monitoring and logging of data operations;
- Daily encrypted database backups;
- WAF, Cloudflare DDoS protection, regular software updates;
- SSH keys, VPN, password-based access prohibited.
5.3. Storage Location
- PostgreSQL — Render (Oregon, USA);
- Cloudflare R2 — distributed global infrastructure;
- Logs and Backups — secured servers with restricted access.
All providers comply with ISO 27001, SOC 2.
6. Cross-Border Transfer of Personal Data
| Service | Country | Purpose |
|---|---|---|
| Render | USA | Account and generation data storage |
| Cloudflare R2 | Global CDN | Asset storage |
| OpenAI | USA | AI content generation |
| Minimax | China | Video and image generation |
| USA, EU | Authentication, analytics | |
| Telegram | Germany, UAE | Authentication, bot operation |
Safeguards: data subject consent, contracts with providers, data anonymization for analytics transfers.
The User has the right to withdraw consent for cross-border transfer (aidesignspace.pro@gmail.com), which may limit functionality.
7. Cookies and Tracking Technologies
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication (aidc_sid), sessions, language | Up to 12 months |
| Functional | User preferences (theme, font) | Up to 12 months |
| Analytical | Traffic statistics (GA, Yandex.Metrica) | Up to 24 months |
| Marketing | Advertising effectiveness, referral links | Up to 12 months |
Cookie management — through browser settings. Blocking may result in Platform malfunction.
Analytics services: Google Analytics, Yandex.Metrica. Opt-out — via browser extensions (GA Opt-out, etc.).
8. Data Subject Rights
8.1. Right of Access
Request to aidesignspace.pro@gmail.com. Response — within 30 calendar days.
8.2. Right to Rectification
Through the interface (Settings → Profile) or via support.
8.3. Right to Erasure (Right to Be Forgotten)
Account deletion through the interface or request to aidesignspace.pro@gmail.com. Data is deleted within 30 days. Assets — immediately. Exception: data required by law.
8.4. Right to Restriction of Processing
Request to aidesignspace.pro@gmail.com stating the reason.
8.5. Right to Data Portability
Data copy in JSON/CSV format. Processing — 14 calendar days.
8.6. Right to Withdraw Consent
Written statement to aidesignspace.pro@gmail.com. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. May result in inability to use the Platform.
8.7. Right to Object
Unsubscribe from mailings — "Unsubscribe" link in emails or Platform settings.
8.8. Right to Lodge a Complaint
- To the Controller: aidesignspace.pro@gmail.com;
- To Roskomnadzor: rkn.gov.ru;
- To Court: at the place of residence or the Controller's location (Samara, Russia).
9. Disclosure of Data to Third Parties
| Third Party | Purpose of Transfer |
|---|---|
| AI Providers | Performing generations based on prompts |
| Payment Systems | Payment processing, invoicing |
| Hosting Providers | Data and asset storage |
| Government Authorities | Upon official requests (Article 13 of 152-FZ) |
| Referral Program Partners | Reward accrual, statistics |
All third parties are obligated to: maintain confidentiality, not use data beyond agreed purposes, comply with 152-FZ, and notify of incidents.
In case of a change in Platform ownership — 30 days' notice. The new owner must comply with this Policy or obtain new consent.
10. Data Security for Minors
10.1. The Platform is not intended for individuals under 18 years of age (except with parental consent).
10.2. The Controller does not intentionally collect data from minors.
10.3. Data of a minor collected without parental consent is deleted within 3 business days.
10.4. Deletion request — to aidesignspace.pro@gmail.com with a document confirming the parental relationship.
11. Security Incident Notification
11.1. In case of a data breach or unauthorized access, the Controller shall:
- Immediately take remedial measures;
- Notify Roskomnadzor within 24 hours;
- Notify affected Users within 72 hours;
- Publish information about the incident on the Platform.
11.2. The notification shall contain: incident description, categories of affected data, consequences, measures taken, and recommendations.
12. Privacy Policy Amendments
12.1. The Controller reserves the right to make changes at any time.
12.2. Material changes — email notification 14 days in advance, pop-up notification, publication on the homepage.
12.3. Continued use = consent to the new version.
12.4. If you disagree — delete your account before changes take effect.
13. Contact Information
Address: Samara, Russia · IE Panova Elvira Viktorovna
Email (privacy): aidesignspace.pro@gmail.com
Technical Support: aidesignspace.pro@gmail.com
Telegram Bot: @aidesignspace_bot
Responsible Person: Panova Elvira Viktorovna
Inquiry Response Times:
- Data access requests — up to 30 calendar days;
- Deletion/rectification — up to 10 business days;
- Complaints and claims — up to 10 business days;
- Technical questions — up to 3 business days.
14. Final Provisions
14.1. This Policy is an integral part of the Service Agreement (Public Offer).
14.2. Disputes are resolved under the laws of the Russian Federation.
14.3. In case of conflict with other Platform documents, this Policy shall prevail.
14.4. Invalidity of individual provisions does not invalidate the Policy as a whole.
This English version is provided for informational purposes only. In case of discrepancies, the Russian version shall prevail.
📌 Important: By accepting the terms of this Policy, you confirm that:
- You have reviewed the purposes and methods of personal data processing;
- You consent to processing, including cross-border transfer;
- You understand your rights as a data subject;
- You are at least 18 years of age (or have obtained consent from a legal representative).
PERSONAL DATA CONTROLLER DETAILS
IE Panova Elvira Viktorovna · TIN (INN): 631938286341 · OGRNIP: 312631925500061
Address: Samara, Russia
Bank: Branch "CENTRAL" of VTB Bank (PJSC), Moscow
Acct.: 40802810706180000159 · Corr. acct.: 30101810145250000411 · BIC: 044525411
Email: aidesignspace.pro@gmail.com · Website: https://aidesignspace.pro
Publication Date: February 19, 2026 · Version 1.0