Last updated: 12.09.2026
This Policy describes the actual operation of the informational website starcodepr.com. Website operator — Sole Proprietor Arashov Artem Kamaludinovich.
The website does not have general registration, personal accounts, public comments, or user file uploads.
On the legislative compliance audit pages, there is a form for a voluntary express audit request. The processing of the applicant's personal data is carried out by the Operator based on informed and substantive consent (Art. 9 of Federal Law No. 152-FZ), as well as within the framework of considering a request at the initiative of the personal data subject (Clause 5 of Part 1 of Art. 6 152-FZ).
Composition of processed data: the address of the website being checked, the contact provided by the user, the name or position of the contact person (if provided), as well as the source IP address and browser User-Agent string determined by the server. The form does not request information about patients, health status, or medical care provided; screen size, time zone, and additional digital fingerprint attributes are not collected.
Purposes and methods of processing: data is processed exclusively for the purpose of conducting an expert express audit of the website, preparing a list of recommendations, and sending the results to the applicant. Processing is carried out in compliance with the principles of legality and minimization (Part 2 of Art. 5 152-FZ).
Primary recording and localization of databases (Part 5 of Article 18 of 152-FZ): collection, recording, systematization, accumulation, and storage of personal data of citizens of the Russian Federation are carried out using databases located on the territory of the Russian Federation. The browser transmits form data directly via the secure HTTPS protocol to the server (IP address: 159.194.229.120, located in the Russian Federation. The web page delivery infrastructure does not accept, process, or relay the content of requests. Request fields, the source IP address, and User-Agent are encrypted before being saved in the database. Only after a persistent primary record is created in the Russian Federation does a separate delivery queue decrypt the data to send a notification to the Operator via Telegram.
Transmission via external communication service: after primary recording in the Russian Federation, a notification with the request number and time, form fields, source IP address, and User-Agent is automatically transmitted to the Operator via Telegram Bot API. Telegram is an external service whose infrastructure may process data outside the Russian Federation. By submitting the form after reviewing this Policy and Consent, the user agrees to such transfer for prompt review of the request. The terms of processing by the Telegram service are published in its privacy policy.
Recipients: the Operator receives access to the request; technical notification transmission is performed via Telegram Bot API to the Operator's private chat. Request data is not shared with web analytics systems, advertising networks, or data brokers. To contact the applicant, the Operator uses the contact information voluntarily provided in the form.
Direct contact buttons open Telegram, WhatsApp, VK, MAX, an email client, or a phone dialer. Additional data transmission via such buttons occurs only after the user navigates independently to the chosen external service and is governed by that service's policies.
The server that serves the website pages technically receives the IP address, date and time of the request, the address of the requested page, browser headers, and the response code. The content of the form is not sent to this server. The Russian-based receiver uses the IP address for request rate limiting, and also stores the source IP address and User-Agent inside the encrypted request for request review and protection against abuse. Screen size, time zone, and additional browser fingerprinting parameters are not collected.
The access log for the Russian form route is disabled. Technical logs of the main site, if maintained by the infrastructure, are used only for security, diagnostics, and availability and do not contain request fields.
The Russian receiver records only anonymized operational events in the local system log: time, request number, result code, service and tariff identifier, and after successful recording, the request number. The contact, name, address of the audited site, form body, source IP address, and User-Agent are not recorded in this log.
In case of internal infrastructure errors and failures, a separate isolated monitor may send an anonymized alert to the Operator via Telegram Bot API: the Russian node identifier, time, aggregated type and number of errors, or the name of the faulty service and certificate expiration date. The request number, fields, and content of the request are not included in such notifications; the detailed technical log remains on the Russian server.
Without sending to the server, the website can store in the browser:
starcodeConsent — the version, date, and selected analytics setting;session_start_time — start time of the current visit;Session values are deleted by the browser after closing the tab or session. Analytics settings are stored until changed by the user, a new edition of the consent mechanism is released, or site data is cleared in the browser. These values do not contain contact details and are not transmitted to the Operator via a separate request.
Yandex Metrica loads only after clicking the "Allow Analytics" button. Prior to consent, the website does not load the Metrica code and does not send events to it. Session Replay is disabled.
After consent, Metrika may receive technical information about the visit in accordance with its terms. The site transmits conversion goals to phone and external communication services only after 60 seconds on the page, only upon an actual user click, and no more than once per session for each type of conversion.
You can change your choice via the "Cookie Settings" link at the bottom of the page. Upon refusal, further collection is disabled, and the page reloads if Metrika was already running.
The Yandex rating widget and official Google Partner status images are also loaded only after analytics permission. Prior to consent, the browser does not access the addresses of these resources.
A standard click on an external link takes the user to the website of the corresponding service. The Operator does not control data processing on the external website.
Technical connection data is used to provide the website, protect infrastructure, and diagnose errors. Analytical data and conversions are processed only based on the user's choice in the banner — to assess traffic, material demand, and website usability.
Data retention and destruction periods: Applications are stored in the production database for no more than 30 calendar days from the moment of receipt, after which they are automatically and permanently deleted. Encrypted backups are stored for no more than 30 days from the moment of creation, after which they are overwritten during the rotation process. The destruction of personal data is carried out using software methods (deletion of records from the database) in accordance with the requirements of Roskomnadzor Order No. 179 dated 28.10.2022, with the fact of deletion recorded in the system log. If a request leads to the conclusion of a contract, the processing of contractual and primary accounting documents is carried out separately in accordance with the requirements of the legislation of the Russian Federation (Tax Code of the Russian Federation, Federal Law 402-FZ) with a storage period of up to 5 years.
The subject of personal data has the right to receive information about the processing of their data, the right to demand its clarification, blocking, or destruction, as well as the right to withdraw this consent to processing at any time. Requests and requirements of personal data subjects are processed by the Operator within a period not exceeding 10 (ten) working days from the moment of receipt of the request (Part 1 of Article 20 of 152-FZ).
The user can also disable analytics through the site settings ("Cookie Settings" at the bottom of the page) and clear local storage and cookies in the browser.
Requests or withdrawals of consent can be sent to starcode.in@gmail.com with the subject "Personal Data".
If the user contacts the Operator on their own via email or an external messenger, further correspondence and the information provided by the user are processed outside the website to respond to the inquiry and for potential performance of an agreement. This version specifically describes the technical flows of the public website and does not replace the Operator's internal documents regarding client data processing.
The policy is updated when site functions or the composition of connected services change. The current version is published at starcodepr.com/policy.
Operator: Sole Proprietor Arashov Artem Kamaludinovich
The person responsible for organizing the processing of personal data: Arashov A. K.
INN: 550116040054
OGRNIP: 318554300108266
Location: Russia, Republic of Crimea, Simferopol
Contact email: starcode.in@gmail.com
Telegram: @tema_37
WhatsApp: +7 (913) 635-32-86
This section contains the full text of the Consent to the processing of personal data provided by the personal data subject when filling out and submitting interactive forms on the website starcodepr.com in accordance with the requirements of Article 9 of Federal Law No. 152-FZ (as amended by Federal Law No. 156-FZ).