Academy CanLup · Legal information
Personal data policy
The data Academy needs, why it is used and how to contact the operator.
Operator and scope
Personal data operator: Баца Алла Антоновна. Russian taxpayer identification number: 890603453994. A self-employed professional income tax payer, without individual entrepreneur status, in the Russian Federation. Personal data enquiries: batsaaleksey@gmail.com.
This policy covers academy.canlup.com, Academy accounts and the features used. The service is intended for adults in Russia. The policy provides information; it does not itself constitute consent. Access requests have a separate consent document.
Data processed
People concerned include site visitors, applicants, account users, customer representatives, invited participants and people contacting support. Sources are the individual, their device and service activity, and authorised customers for invitations and corporate materials. Data obtained from someone else requires a lawful basis and any information to the individual required by law.
Software processes data, with authorised people involved when a request or enquiry needs review. Operations include collection, recording, organisation, accumulation, storage, correction, retrieval, use, authorised access, blocking, deletion and destruction within the relevant purpose.
- Requests: email, selected use case and industry; in the extended form, name, job title, organisation, team size, needs, optional contact and comment. The consent edition, timestamp and request status are recorded.
- Accounts: name, email, profile image and settings, identifiers, roles and sessions. Passwords are stored as cryptographic hashes. Passkeys use public keys and technical records; device biometrics are not received.
- Selected features: uploaded materials, messages, support enquiries, assignments and results, personal notes, AI requests, supplied context and outputs. Other people’s data requires appropriate authority and a lawful basis.
- Technical records: IP address or protective derivatives, request time, browser/device details, authentication, error and security events.
Purposes and legal bases
- Applicants: email, the selected form’s details and confirmation records are used to review the request, verify contact details and send access-related service messages. Basis: separate consent under Article 6(1)(1) of Russian Law No. 152-FZ. Retention ends upon completion of the purpose, withdrawal or 180 days, whichever occurs first.
- Account users: profile and authentication details, selected materials and outputs support the requested account, features and related support. Basis: entering into a contract at the individual’s initiative and performing it under Article 6(1)(5). Retention follows the requested functions and the end of the relevant basis.
- Corporate participants: work contacts, roles, materials and results support the functions instructed by the customer, within the agreed scope and period. The customer establishes the basis for participant data; provider obligations follow Article 6(3) and the specific instructions. Company membership does not itself expose personal account materials to a manager.
- Visitors and users: necessary network, session and technical records support authentication, service protection, error investigation and abuse prevention. Bases: necessary contractual activity and legitimate interests respecting individual rights under Article 6(1)(5) and (7). Retention is limited to the relevant protection or diagnostic purpose.
- Enquirers and customer representatives: contact details, enquiry content and necessary account or order details support replies, contractual performance and statutory requests. Article 6(1)(2), (5) or (7) applies according to the request. Records subject to a statutory retention period are kept for that period and scope; the grounds are available on request.
- Advertising and public dissemination are outside access-request consent. Advertising requires separate prior consent; personal data dissemination requires its own basis and separate consent where Article 10.1 requires it. A closed workspace does not make a person’s materials public.
Retention and deletion
An access request is processed until its purpose is achieved, consent is withdrawn or 180 days expire, whichever happens first. Access records may then be retained under a separate account-related basis.
Account and feature data is kept while needed to provide them. Enquiries and technical records are kept for their purpose; mandatory records and evidence for a substantiated dispute are retained under the applicable basis. Losing company access does not automatically delete a personal account.
Completion of the purpose or withdrawal requires processing to stop and data to be destroyed within no more than 30 days unless the law permits continued processing. A demand to cease processing has a separate deadline: no more than 10 working days, with a reasoned extension of up to 5 working days where permitted. The general request-retention period does not replace these deadlines.
Backups are included in deletion handling. If destruction within the required period is impossible, Article 21(6) requires blocking followed by destruction within no more than six months unless federal law provides otherwise. Restoration must not resume processing without a lawful basis. Destruction is documented as required.
Cookies and device storage
Essential cookies, local storage and cache support sign-in, request protection, account selection and settings. Removing them may end a session or reset settings; it does not delete server-side account data.
Optional analytics and advertising tracking are not covered by request consent. Where consent is required, they are enabled only after a separate choice. Reading legal pages also sends ordinary network information to the server.
Access, technical services and location
The operator and authorised persons receive access only for their tasks. Hosting, transactional email, diagnostics and AI may involve technical service providers, receiving only information needed for the operation. AI may receive the submitted request, selected context and files. Access request consent does not authorise public dissemination.
Academy’s primary server is in Russia. Collection of Russian citizens’ data is subject to localisation requirements. A Russian primary server does not mean all additional processing occurs exclusively in Russia. Cross-border transfers require compliance with Article 12 of Law No. 152-FZ. Information about processing and recipients that a user is entitled to receive is available by contacting the operator.
Rights, contact and protection
For access to processing information, correction, withdrawal or cessation, email batsaaleksey@gmail.com with the account/request email and the issue. Sign-in is not required. Do not send passwords or one-time codes. Proportionate verification of authority may be requested.
Processing information or a reasoned response is provided within 10 working days of the enquiry or request. A legally permitted extension of up to 5 working days requires a reasoned notice. Confirmed inaccurate data is corrected within 7 working days. Identified unlawful processing stops within 3 working days; if it cannot be made lawful, the data is destroyed within 10 working days of identifying the violation.
Withdrawal does not end processing with an independent lawful basis. The response explains that basis and the necessary scope of retention. Users may contact Roskomnadzor or a court. A service enquiry does not require agreement to advertising or a purchase.
Access controls, session checks, encrypted connections and abuse prevention support protection. Ordinary service forms should not be used for special categories of personal data or biometric identification data.
Updates and additional features
The edition and date are shown on this page. Updates do not retroactively change consent; new purposes require any necessary separate consent. File, microphone, screen and desktop-action permissions are handled in the relevant feature.