Privacy Policy
Last updated: August 27, 20261. General Provisions
1.1. This Privacy Policy (hereinafter — the "Policy") defines the procedures for collecting, processing, storing, using, transferring, protecting, and destroying personal data of users of the LALAPAM platform (hereinafter — the "Platform"), located at lalapam.ru.
1.2. The Policy has been developed and operates in accordance with Federal Law No. 152-FZ dated July 27, 2006 "On Personal Data" (hereinafter — FZ-152), Decree of the Government of the Russian Federation No. 1119 dated November 1, 2012 "On Approval of Requirements for the Protection of Personal Data During Their Processing in Personal Data Information Systems," and other regulatory legal acts of the Russian Federation in the field of personal data.
1.3. The Policy applies to all personal data that the Operator may receive from Users, Users' Clients, and other personal data subjects in the course of using the Platform.
1.4. By registering on the Platform, transmitting personal data, and/or using the Platform's functionality, the User expresses consent to the terms of this Policy. If the User disagrees with the terms of the Policy, the User must cease using the Platform.
1.5. The Operator does not control and is not responsible for third-party websites that the User may access via links posted on the Platform.
2. Personal Data Operator
2.1. The personal data operator is:
- Name: Individual Entrepreneur Denis Nikolaevich Filipkin
- TIN (INN): 731201040405
- Address: 6 Kirova St., Apt. 225, Ulyanovsk, 432048, Russian Federation
- Email: support@lalapam.ru
2.2. The Operator appoints a person responsible for organizing the processing of personal data in accordance with Article 22.1 of FZ-152.
3. Definitions
3.1. The following terms are used in this Policy:
- Personal Data — any information relating directly or indirectly to an identified or identifiable natural person (personal data subject) (Article 3 of FZ-152).
- Processing of Personal Data — any action (operation) or set of actions (operations) performed with or without automated means on personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data.
- Operator — Individual Entrepreneur Denis Nikolaevich Filipkin, who independently or jointly with other persons organizes and/or carries out the processing of personal data, and also determines the purposes of processing personal data, the composition of personal data subject to processing, and actions (operations) performed on personal data.
- Personal Data Subject — a natural person to whom the processed personal data directly or indirectly relates.
- Processor — a person who processes personal data on behalf of the Operator on the basis of a concluded agreement (processing instruction).
- User — a natural or legal person (individual entrepreneur, self-employed) registered on the Platform and using its functionality to organize the sale of their services, goods, and bookings.
- User's Client — a natural person who interacts with the User through the Platform as a consumer of services, goods, or bookings.
- Platform — the LALAPAM software suite, including the website, web applications (PWA), Telegram Mini App, MAX Mini App, and associated application programming interfaces (API).
- AI Features — Platform functionality that uses artificial intelligence technologies (large language models) of third-party providers, including the AI assistant and the AI agent for automated communication with Users' Clients.
- Direct Channels — functionality for sending and receiving messages through Users' own accounts in third-party messengers, connected by Users to the Platform.
4. Categories of Personal Data
4.1. The Operator processes the following categories of personal data:
| Category | Data Composition | Purpose of Processing |
|---|---|---|
| Identification Data | First name, last name, email address, phone number, profile photo | Registration, user identification, personal account management |
| Authorization Data | Telegram ID, VK ID, Yandex ID, MAX messenger ID, OAuth provider access tokens | Authorization and authentication through third-party providers (OAuth 2.0) |
| Technical Data | IP address, browser user-agent, session data (session identifier, creation time, expiration time) | Security, fraud prevention, technical support |
| Transactional Data | Order information (service/product name, amounts, dates, statuses), payment data (payment status, transaction identifier) | Contract performance, transaction accounting, reporting |
| Communication Data | Content of messages sent and received through the Platform's communication channels (including messengers and Direct Channels), history of dialogs with the AI agent, message delivery information | Messaging between the User and their Clients, operation of AI Features, confirmation of the fact and content of communication |
| Preference Data | Brief information about a User's Client's preferences and service history (facts and summaries generated from dialogs and orders), the User's notes about the Client | Personalization of Client service within the respective User's organization |
| Fiscal Data | Self-employed person's TIN (INN), Federal Tax Service receipt data (service name, amount, date) | Fiscal receipt generation via the "My Tax" API, compliance with Russian tax legislation |
| Analytics Data | Platform interaction events (order creation, payment, registration, notification sending, etc.) | Service quality improvement, platform usage analysis, technical issue identification |
4.2. The Operator does not request and does not purposefully process special categories of personal data relating to race, ethnicity, political views, religious or philosophical beliefs, health status, or intimate life. The Platform's free-form text fields and dialog channels are not intended for the transmission of such information; if a data subject, at their own initiative, communicates such information in correspondence (for example, individual contraindications when booking a service), it is processed exclusively as the content of the respective communication for the purpose of serving the subject and is not used by the Operator for any other purposes.
4.3. The Operator does not process biometric personal data.
5. Purposes of Data Processing
5.1. The Operator processes personal data exclusively for the following purposes:
- Contract Performance — providing Platform functionality under the Terms of Service, including account creation and management, order processing, and personal account access.
- Authorization and Authentication — user identification upon logging into the Platform, including through third-party providers (Telegram, MAX, VK ID, Yandex ID, email).
- Sending Notifications and Messaging — informing users about order statuses, reminders, and service messages, as well as messaging between Users and their Clients through channels: Telegram, MAX messenger (VK), email, browser push notifications, and Direct Channels — messenger accounts connected by Users (including MAX and, as the functionality becomes available, Telegram, WhatsApp, and others).
- Fiscal Receipt Generation — automatic receipt creation through the Federal Tax Service "My Tax" API for self-employed users in accordance with the Russian Tax Code.
- AI Features — processing text queries and correspondence using artificial intelligence technologies: generating recommendations, automatic business process configuration, automated dialog with the User's Clients (AI agent), generating brief dialog summaries and preference information for service personalization.
- Analytics and Platform Improvement — collecting and analyzing depersonalized and aggregated data on Platform interactions to improve service quality, identify and resolve technical issues.
- Development and Improvement of Artificial Intelligence Models — maintaining a technical log of AI agent interactions (the request to the model, the context of the interaction, tool calls and their results, the model's response) and using such information to assess quality, debug, and further train the models used in the Platform. Phone numbers and email addresses are removed from the log before it is used for further training.
- Security — preventing unauthorized access, fraud, DDoS attacks, and other information security threats.
5.2. Processing of personal data incompatible with the stated purposes is not permitted.
6. Legal Basis for Processing
6.1. Personal data processing is carried out on the following legal grounds:
- Consent of the personal data subject (Article 6, Part 1, Clause 1 of FZ-152) — upon registration on the Platform, when connecting additional communication channels, and when using AI Features. Consent is given by a separate expression of the subject's will (checking a box in the interface, submitting a form, continuing a dialog after receiving a notice with a link to the consent text) and is recorded by the Operator in a consent log with the date, method, and document version.
- Contract performance (Article 6, Part 1, Clause 5 of FZ-152) — processing of data necessary for the performance of the Terms of Service to which the personal data subject is a party, as well as for concluding a contract at the subject's initiative.
- Legitimate interest of the operator (Article 6, Part 1, Clause 7 of FZ-152) — processing of data necessary to ensure Platform security, prevent fraud, conduct internal analytics, and improve service quality, provided that such processing does not violate the rights and freedoms of the personal data subject.
- Compliance with legal obligations (Article 6, Part 1, Clause 2 of FZ-152) — processing of fiscal data in accordance with the requirements of the Russian Tax Code.
6.2. Consent to the processing of personal data may be withdrawn by the subject in the manner prescribed in Section 10 of this Policy. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
7. Transfer of Data to Third Parties
7.1. The Operator is entitled to transfer personal data to third parties exclusively in cases provided for by this Policy and applicable legislation of the Russian Federation.
7.2. List of third parties to whom personal data may be transferred:
| Service | Purpose | Data Transferred | Jurisdiction |
|---|---|---|---|
| Resend | Email notification delivery | Email address, message content | USA |
| Telegram Bot API | Telegram messenger notifications | Chat ID, message text | UAE |
| MAX (VK) | Notifications and messages in the MAX messenger, including delivery through accounts connected by Users (Direct Channels) | User ID, recipient's phone number (to determine the delivery addressee), message text | Russian Federation |
| Operators of other connectable messengers (as Direct Channels functionality becomes available: Telegram — UAE, WhatsApp — USA, etc.) | Message delivery through accounts connected by Users (Direct Channels) | Recipient's phone number (to determine the delivery addressee), messenger identifier, message text | According to the operator of the respective messenger |
| Messenger integration infrastructure providers (when Direct Channels are used; the current list is available upon request) | Technical support for sending and receiving messages | Recipient's phone number, messenger identifier, message text | Russian Federation (unless otherwise indicated when the feature is connected) |
| OpenAI | AI Features (processing of text queries and correspondence by artificial intelligence models) | Text of queries and messages, context necessary to generate a response (without excessive identification data where possible) | USA |
| DeepSeek | AI Features (processing of text queries and correspondence by artificial intelligence models) | Text of queries and messages, context necessary to generate a response (without excessive identification data where possible) | People's Republic of China |
| Providers of Russian AI models (including GigaChat, Sberbank PJSC — as the corresponding functionality becomes available) | AI Features (processing of text queries and correspondence by artificial intelligence models) | Text of queries and messages, context necessary to generate a response | Russian Federation |
| YooKassa (NBCO YooMoney LLC) | Payment acceptance | Payment amount and purpose, order identifier, payer's email/phone (for the fiscal receipt) | Russian Federation |
| VK ID | OAuth authorization | Access token, profile data (name, photo) | Russian Federation |
| Yandex ID | OAuth authorization | Access token, profile data (name, email, photo) | Russian Federation |
| Federal Tax Service ("My Tax" API) | Fiscal receipt generation | Self-employed person's TIN, transaction amount, service name | Russian Federation |
| Web Push (browser) | Browser push notifications | Subscription endpoint, encryption keys | Depends on browser push service provider |
7.3. Data is transferred to third parties exclusively in the volume necessary to achieve the stated processing purposes. Only content necessary to generate a response is transferred to AI model providers; the Operator does not transfer to them credentials, payment details, or data unrelated to the processed request.
7.4. The Operator obligates third parties to maintain the confidentiality of personal data and ensure their security during processing, and to not use personal data for purposes not provided for by this Policy. Processing of data by third-party providers is carried out in accordance with their own terms and policies, which the Operator takes into account when selecting providers.
7.5. The list of third parties may change as the Platform develops. The current version of the list is published in this Policy; changes take effect in the manner provided by Section 15 of this Policy.
8. Cross-Border Data Transfer
8.1. The Operator carries out cross-border transfer of personal data to the following countries:
- USA — OpenAI (AI Feature query processing), Resend (email delivery); when WhatsApp Direct Channels are used (as the functionality becomes available) — WhatsApp LLC (message delivery).
- People's Republic of China — DeepSeek (AI Feature query processing).
- UAE — Telegram (delivery of notifications and messages).
8.2. Cross-border transfer is carried out in compliance with the requirements of Article 12 of FZ-152, including notifying the authorized body (Roskomnadzor) of the intention to carry out cross-border transfer of personal data before it begins. Transfer to countries that do not provide adequate protection of the rights of personal data subjects is carried out only on the grounds provided by Part 8 of Article 12 of FZ-152, including: the data subject's consent to cross-border transfer and/or the necessity of performing a contract to which the data subject is a party.
8.3. Protective measures for cross-border transfer:
- Data encryption during transmission using TLS 1.2 protocol or higher.
- Data minimization — only data strictly necessary for the provision of the respective services is transferred.
- Minimization of identification data when transferring to AI model providers — direct identification data is excluded from queries where technically feasible.
- Risk assessment and verification of the level of protection in the receiving country in accordance with the requirements of Article 12 of FZ-152.
8.4. Databases containing personal data of citizens of the Russian Federation are, at the time of collection, located on servers within the territory of the Russian Federation (Part 5, Article 18 of FZ-152). Cross-border transfer of certain data to the third parties listed in Section 7 is carried out for purposes other than the initial collection and storage of databases.
9. Data Retention Periods
9.1. The Operator retains personal data for no longer than required by the purposes of processing, unless a different retention period is established by federal law or contract.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data (identification, authorization) | Until account deletion by the user or upon subject's request | Contract performance |
| Authorization sessions | 30 days from creation | Security |
| Order data (transactional) | 3 years from order creation date | Contract performance, legitimate interests of the operator |
| Communication content (messages, dialog history) | For the period the messaging functionality is provided, no longer than the account lifetime; technical data of completed AI agent dialog sessions — up to 7 days after session completion | Contract performance, operation of AI Features |
| Preference information (AI agent memory, notes) | Until deleted upon the subject's request, consent withdrawal, deletion by the User, or account deletion | Subject's consent, User's instruction |
| Technical log of AI agent interactions (requests to the model, tool calls, responses) | Until the purposes of development and improvement of the models are achieved; reviewed by the Operator at least once a year | Legitimate interests of the operator |
| Consent log | 3 years from the withdrawal of the respective consent or account deletion | Confirmation of the lawfulness of processing (legitimate interest of the operator) |
| Fiscal data | 4 years from the end of the tax period | Article 23 of the Russian Tax Code |
| Analytics events | 3 years from event registration | Legitimate interests of the operator (service improvement) |
| Message queue data (notifications) | 30 days after sending | Technical delivery assurance |
9.2. Upon expiration of the retention period, personal data shall be destroyed or depersonalized within no more than 30 days, unless otherwise provided by applicable legislation.
9.3. In the event of consent withdrawal by the personal data subject, the Operator shall cease processing and destroy personal data within no more than 30 days from the date of receiving the withdrawal, except in cases where processing may be continued on another legal basis (Section 6.1 of this Policy).
10. Rights of Personal Data Subjects
10.1. The personal data subject has the following rights in accordance with FZ-152:
- Right to information (Article 14 of FZ-152) — the subject has the right to receive information regarding the processing of their personal data, including: confirmation of processing, legal grounds and purposes, processing methods, operator's name and address, composition of processed data, processing and storage periods.
- Right of access to personal data — the subject has the right to request and receive a copy of their personal data processed by the Operator.
- Right to rectification (Article 14, Part 1 of FZ-152) — the subject has the right to demand clarification, updating, or correction of inaccurate or incomplete personal data.
- Right to erasure (Article 14, Part 1 of FZ-152, Article 21 of FZ-152) — the subject has the right to demand destruction of personal data if the data is incomplete, outdated, unlawfully obtained, or unnecessary for the stated purpose of processing. This right also applies to preference information (AI agent memory) generated from the subject's dialogs.
- Right to withdraw consent (Article 9, Part 2 of FZ-152) — the subject has the right to withdraw previously given consent to the processing of personal data at any time.
- Right to restriction of processing — the subject has the right to demand restriction of processing of their personal data in cases provided by law.
- Right to data portability — the subject has the right to request their personal data in a structured, commonly used, and machine-readable format (JSON).
- Right to opt out of messages — the subject has the right to opt out of receiving messages in dialog channels at any time by sending a reply message demanding that sending be stopped (stop word); the opt-out is recorded automatically.
- Right to appeal (Article 17 of FZ-152) — the subject has the right to appeal the actions or inaction of the Operator to the authorized body for the protection of personal data subjects' rights (Roskomnadzor) or through judicial proceedings.
10.2. To exercise their rights, the personal data subject shall send a written request to the Operator's email address: support@lalapam.ru.
10.3. The request must contain:
- Last name, first name, and patronymic (if available) of the subject.
- Email address registered on the Platform (or another identifier for verification).
- Description of the request (the specific right the subject wishes to exercise).
10.4. The Operator shall review the request and provide a response within 10 business days from the date of receiving the request or the subject's appeal (Article 20 of FZ-152). If additional verification is required, the period may be extended, and the subject shall be notified accordingly.
10.5. The Operator may refuse to fulfill the request in cases provided by the legislation of the Russian Federation, including when identification of the subject is not possible.
11. Cookies and Local Storage
11.1. The Platform uses browser local storage technologies (localStorage) to ensure service functionality.
| Identifier | Type | Purpose | Retention Period |
|---|---|---|---|
| session_token | localStorage | User authorization (session identifier storage) | Until logout |
| Theme preference | localStorage | Saving user interface settings (light/dark theme) | Indefinite (until cleared by user) |
11.2. The Platform does not use third-party advertising or analytics cookies.
11.3. All data in localStorage is stored exclusively on the user's device and is not transmitted to third parties.
12. Security Measures
12.1. The Operator takes necessary and sufficient organizational and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, distribution, and other unlawful actions by third parties, in accordance with Article 19 of FZ-152 and Government Decree No. 1119.
12.2. Technical security measures:
- Data encryption in transit — all connections to the Platform are protected by TLS 1.2 protocol or higher (HTTPS).
- Encryption of sensitive data in the database — API keys, access tokens, credentials of connected messenger accounts, and other secret data are stored in encrypted form.
- Access control — role-based access model with permission segregation (User, Administrator, Staff). Each user has access only to their own data and their organization's data; organizations' data is isolated from one another.
- Session authentication — cryptographically strong session identifiers with limited validity period (30 days) are used.
- Regular backups — automatic database backups with encryption and storage in secure object storage.
- Activity logging — security event logging for incident detection and investigation.
12.3. Organizational security measures:
- Limiting the circle of persons who have access to personal data.
- Controlling access to server equipment and software.
- Regular auditing of security measures and software updates.
13. Processing of Users' Client Data
13.1. With respect to the personal data of Users' Clients, the roles are distributed as follows:
- With respect to the Client's unified account on the Platform (registration and authorization, profile, consent log, security, cross-organization Platform functions), LALAPAM acts as an independent data controller (operator).
- With respect to data processed within the Client's interaction with a specific User (appointments and orders, correspondence — including dialogs with the User's organization's AI agent, preference information and notes), LALAPAM acts as a processor on behalf of the User, who is an independent operator of the personal data of their Clients.
13.2. The User, by using the Platform to interact with their Clients, is obligated to:
- Independently determine the legal basis for processing the personal data of their Clients.
- Obtain proper consent from Clients for the processing of their personal data, if required under FZ-152, and — for messages of an advertising nature — the recipient's prior consent in accordance with applicable advertising legislation.
- Inform Clients that their personal data is processed using the LALAPAM Platform.
- Ensure the exercise of rights of their Clients as personal data subjects.
13.3. The procedure for processing Users' Client data is governed by the Data Processing Agreement (DPA), which is an integral part of the Terms of Service.
13.4. LALAPAM processes Users' Client data exclusively within the scope of the User's instruction and for purposes determined by the User. LALAPAM does not use Users' Client data for its own purposes not provided for by the instruction.
13.5. By enabling AI Features and/or Direct Channels, the User gives the Operator a documented instruction for the corresponding processing of their Clients' data, including the transfer of correspondence content to AI model providers and the transfer of contact data to messenger operators for message delivery (including cross-border transfer — Section 8).
13.6. Users' Clients who interact with the Platform through dialog channels (messengers) are informed about personal data processing and this Policy upon first interaction — by a notice in the dialog with links to the consent text and this Policy.
13.7. In the event of receiving requests from Users' Clients regarding their personal data, LALAPAM notifies the respective User and assists in fulfilling the request.
14. Use of Artificial Intelligence Technologies
14.1. Certain Platform features use large language models of third-party providers (see the list in Section 7). When such features are used, the content of the corresponding queries and correspondence is transferred to the model provider to generate a response.
14.2. AI Feature responses are generated automatically. In dialog channels where a User's Client interacts with the AI agent, responses are generated by software without human participation in each specific response; the User (organization) controls the AI agent's settings and may intervene in a dialog or disable the AI agent.
14.3. The Platform does not make decisions that produce legal consequences for a personal data subject or otherwise significantly affect their rights and legitimate interests based solely on automated processing of personal data (Article 16 of FZ-152): legally significant actions (creation, modification, cancellation of an appointment or order) are performed on the basis of the subject's will expressed in the dialog or interface and/or are subject to the User's control.
14.4. Based on dialogs and service history, the Platform may generate brief information about a Client's preferences (AI agent memory) for the purpose of personalizing service within the respective User's organization. Such information: is available to the User for review, correction, and deletion; is not shared with other organizations; may be deleted upon the subject's request (Section 10).
14.5. The Operator minimizes the volume of data transferred to AI model providers (Sections 7.3, 8.3) and does not transfer data to them for purposes other than generating a response to a specific request. Data processing by model providers is governed by their own terms; the Operator takes these terms into account when selecting providers.
14.6. The Operator does not transfer subjects' personal data to AI model providers for the training of those providers' models. To assess quality, debug, and further train the Operator's own models, the Operator uses information from the technical log of AI agent interactions (Section 5.1), from which phone numbers and email addresses are removed before use.
15. Changes to the Policy
15.1. The Operator reserves the right to amend this Privacy Policy.
15.2. The Operator shall notify users of changes no less than 30 (thirty) calendar days before the changes take effect by publishing the updated version of the Policy on the Platform and/or sending a notification through available communication channels (email, push notification, messenger message).
15.3. Continued use of the Platform after the changes take effect constitutes the user's acceptance of the updated Policy.
15.4. If the user disagrees with the changes, the user has the right to cease using the Platform and delete their account.
15.5. The current version of the Policy is always available at: lalapam.ru/en/privacy.
16. Contact Information
16.1. For any questions related to the processing of personal data, the personal data subject may contact the Operator:
- Operator: Individual Entrepreneur Denis Nikolaevich Filipkin
- TIN (INN): 731201040405
- Address: 6 Kirova St., Apt. 225, Ulyanovsk, 432048, Russian Federation
- Email: support@lalapam.ru
16.2. The authorized body for the protection of personal data subjects' rights is the Federal Service for Supervision of Communications, Information Technology, and Mass Media (Roskomnadzor): rkn.gov.ru.