Prod.by_Лазарев — to home
  • Cases
  • Studio
  • Telegram
  • Instagram*
  • MAX
  • RUРусский
  • ENEnglish

Privacy Notice

Version
09 September 2026
Last updated
9 September 2026
Effective from
9 September 2026

This notice explains how personal data is handled on lazarewww.ru (the “Site”). It is written to meet the transparency requirements of Articles 12–14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the UK GDPR, and it applies to everyone who visits the Site or contacts us through it — wherever they are located.

A separate document, published in Russian, governs processing under Russian Federal Law No. 152-FZ “On Personal Data”. Where the two documents differ, the Russian version prevails for data subjects located in the Russian Federation, and this version prevails for data subjects located in the EEA, the United Kingdom and Switzerland.

Contents
  • 1. Who we are
  • 2. Scope — when this notice applies
  • 3. What personal data we process
  • 4. Why we process it, and on what legal basis
  • 5. Cookies and similar technologies
  • 6. Who your data is shared with
  • 7. International transfers
  • 8. Your rights
  • 9. How long we keep it
  • 10. Security
  • 11. Automated decision-making and profiling
  • 12. Changes to this notice
  • 13. Contact

1. Who we are

We act as the data controller for the personal data described below.

Item Detail
Controller Pavel Sergeevich Lazarev, sole trader (individual entrepreneur registered in the Russian Federation)
Tax ID (INN) 424607307354
Registration number (OGRNIP) 324547600034301 (registered 28 Feb 2024)
Registered address Kamenka village, Novosibirsk District, Novosibirsk Region, Russia. The full registered address is held in the Russian state register of sole proprietors (EGRIP) and is provided on written request
Place of business Novosibirsk, Russia
Email for privacy matters webkuzndets@yandex.ru
Other contact channels Telegram @lazarevpl, MAX, Instagram lazarewww.ru

We have not appointed a Data Protection Officer. Under Article 37 GDPR an appointment is not required here: our core activities do not consist of large-scale regular and systematic monitoring of individuals, nor of large-scale processing of special categories of data.

EU representative (Article 27 GDPR). We rely on the exemption in Article 27(2)(a): the processing described in this notice is occasional, does not include special categories of data or criminal-offence data on a large scale, and is unlikely to result in a risk to the rights and freedoms of individuals. If the nature of our processing changes, we will appoint a representative in the Union and update this notice.

2. Scope — when this notice applies

The Site is a personal portfolio. It presents project case studies and information about how we work. It does not sell anything, does not host user accounts, does not run a store, and does not offer a subscription.

This notice covers:

  • browsing the Site;
  • sending a message through the contact form;
  • contacting us through the messengers and social accounts listed above;
  • any subsequent correspondence about a possible engagement.

A note on territorial scope. We are established in Russia, not in the EEA. The GDPR applies to us under Article 3(2) to the extent that we offer services to, or monitor the behaviour of, individuals in the EEA. We have chosen to apply this notice to all visitors regardless of location, so that the same standard applies to everyone.

3. What personal data we process

3.1. Data you give us

When you use the contact form or write to us directly:

  • your name, or whatever you would like to be called;
  • your email address;
  • your phone number, if you choose to provide one;
  • the content of your message and anything you include in it;
  • the date and time you sent it.

Providing this data is voluntary. There is no statutory or contractual obligation to give it — but without an email address or another way to reach you, we cannot reply.

3.2. Data collected automatically

When a page is requested, our server records:

  • your IP address;
  • your browser and operating system string (User-Agent);
  • the date, time and address of the page requested;
  • the referring page, if your browser sends one;
  • the cookie identifiers listed in Section 5.

3.3. What we do not process

We do not process:

  • special categories of data (Article 9 GDPR) — health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation;
  • criminal-offence data (Article 10 GDPR);
  • payment card or bank details — no payments are taken on the Site;
  • data about children. The Site is not directed at anyone under 16 and we do not knowingly collect their data.

We do not buy contact lists, scrape data, or enrich what you tell us with data from brokers.

4. Why we process it, and on what legal basis

Purpose Data Legal basis (Article 6 GDPR)
Reading your message and replying to it Section 3.1 Art. 6(1)(b) — steps taken at your request prior to entering into a contract; where no contract is in prospect, Art. 6(1)(f) — our legitimate interest in responding to people who contact us
Negotiating, concluding and performing a service agreement Section 3.1 Art. 6(1)(b) — performance of a contract
Keeping the Site available, secure and free of abuse; investigating faults and attacks Section 3.2 Art. 6(1)(f) — our legitimate interest in operating a secure service
Remembering your interface preference (light or dark theme) lazarewww-theme cookie Art. 6(1)(a) — consent, where required for storage on your device; otherwise Art. 6(1)(f)
Keeping records required by Russian tax and accounting law Section 3.1 Art. 6(1)(c) — legal obligation to which we are subject
Establishing, exercising or defending legal claims Section 3.1 Art. 6(1)(f) — our legitimate interest

Our legitimate interests, balanced. Where we rely on Article 6(1)(f), we have considered whether our interest is overridden by your rights. The data involved is minimal, it is not combined into a profile, it is not shared for marketing, and you can object at any time (Section 8). We consider the balance to favour processing; if you disagree in your particular case, tell us and we will re-run the assessment.

We do not use your data for marketing. No newsletters, no advertising, no profiling, no lookalike audiences.

5. Cookies and similar technologies

5.1. Cookies we set

Name Purpose Category Lifetime
cookiebar Records that you dismissed the cookie notice, so it is not shown again Strictly necessary 12 days
lazarewww-theme Stores your choice of light or dark colour theme Functional / preference 1 year
wordpress_logged_in_*, wp-settings-*, wp-settings-time-* Session and preference cookies of the content management system. Set only when signing into the admin area; ordinary visitors never receive them Strictly necessary up to 14 days

5.2. No analytics, no advertising trackers

The Site runs no web analytics and no advertising trackers. As at the version date above, there is no Google Analytics, no Google Tag Manager, no Meta Pixel, no Yandex Metrica, no Microsoft Clarity, no heatmap tool and no A/B testing script. Consequently we set no analytics or advertising cookies, build no behavioural profiles, and share no browsing data with adtech vendors.

If this ever changes, we will update this notice and obtain consent through a banner that offers a genuine “Reject” option before any non-essential script loads.

5.3. Embedded video

Some pages embed video hosted by YouTube (Google Ireland Limited / Google LLC). When such a page loads the player, your browser connects to Google’s servers. Google then receives your IP address and technical request data and may set its own cookies under its own privacy policy — we have no access to those cookies and no control over their contents.

You can prevent this by not playing the embedded video and by blocking third-party cookies in your browser. Google’s privacy policy: https://policies.google.com/privacy.

5.4. Managing cookies

You can delete stored cookies and block new ones through your browser settings. Blocking strictly necessary cookies may break parts of the Site. Blocking the preference cookie simply means your theme choice will not be remembered between visits.

We do not use local storage, browser fingerprinting, pixel tags, or device-identification techniques for tracking purposes.

6. Who your data is shared with

We do not sell, rent or trade personal data. It is disclosed only to:

Recipient category Role Why
Hosting provider for the Site infrastructure Processor (Art. 28 GDPR) Storing Site files and the database
Email service provider used to deliver contact-form messages Processor (Art. 28 GDPR) Transmitting and storing correspondence
Messaging and social platforms you choose to contact us through Independent controllers They operate the channel you selected; their own privacy terms apply
Public authorities, courts, law enforcement Independent controllers Only where we are legally compelled, and only to the extent required
Professional advisers (accountant, legal counsel) Processors or independent controllers Only where necessary to run the business or defend a claim

Named recipients: Yandex LLC (email delivery service used for messages sent from the site).

Every processor we engage is bound by a written agreement meeting Article 28(3) GDPR, or by the equivalent obligation under applicable local law.

7. International transfers

This section matters, so it is stated plainly.

We are located in Russia. The European Commission has not issued an adequacy decision for the Russian Federation. If you are in the EEA, the UK or Switzerland and you send us a message, your personal data is transferred to, and stored in, Russia.

Where such a transfer takes place, we rely on the derogations in Article 49(1) GDPR:

  • Article 49(1)(b) — the transfer is necessary for the performance of a contract between you and us, or to take pre-contractual steps at your request; and/or
  • Article 49(1)(a) — your explicit consent, given after being informed of the possible risks of a transfer to a country without an adequacy decision and without appropriate safeguards under Article 46.

The risks you should be aware of: Russian law does not provide the same level of data protection as EU law; you may have fewer or no effective administrative and judicial remedies in Russia; and Russian public authorities may be able to access data held in the country under national legislation, including security and telecommunications legislation.

If you do not want your data transferred on this basis, please do not use the contact form. There is no other way for us to receive and answer your enquiry.

We do not make onward transfers of your data to any other third country.

8. Your rights

Under the GDPR and the UK GDPR you have the right to:

Right What it means Article
Access Get confirmation of whether we process your data, a copy of it, and the information in this notice Art. 15
Rectification Have inaccurate data corrected and incomplete data completed Art. 16
Erasure (“right to be forgotten”) Have your data deleted where one of the grounds in Article 17 applies Art. 17
Restriction Have processing limited while a dispute about accuracy or lawfulness is resolved Art. 18
Data portability Receive data you provided, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is carried out by automated means Art. 20
Objection Object at any time to processing based on legitimate interests, on grounds relating to your particular situation Art. 21
Withdraw consent Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal Art. 7(3)
Not be subject to automated decisions We make no decisions producing legal or similarly significant effects based solely on automated processing, and we do no profiling Art. 22
Complain Lodge a complaint with a supervisory authority Art. 77

How to exercise them. Email webkuzndets@yandex.ru. Tell us which right you want to exercise and give us enough information to find your data — typically the email address you used to write to us. We may ask for further details if we cannot identify you from what you send; we will not ask for identity documents unless we have a genuine doubt.

Our response time. Within one month of receiving your request. If the request is complex or you have made several, we may extend this by up to two further months and will tell you within the first month, with reasons. Requests are handled free of charge; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive (Article 12(5) GDPR), and we will explain why.

Where to complain. You may complain to the supervisory authority in the EEA member state of your habitual residence, place of work, or the place of the alleged infringement — the list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, the Information Commissioner’s Office, https://ico.org.uk. You may also seek a judicial remedy.

9. How long we keep it

Data Retention
Enquiries that did not lead to a contract 1 year from the last exchange
Data relating to a concluded contract For the term of the contract plus 5 years, limited to what tax and accounting law requires
Messenger and social-media correspondence Until deleted, and no longer than 1 year from the last message
Server logs (Section 3.2) 90 days
Records of consent and of rights requests 3 years, as evidence of compliance
Cookies The lifetimes listed in Section 5.1

When a retention period ends, data is deleted or irreversibly anonymised. Backups are overwritten on their own cycle; data in a backup is not restored into active use after the retention period has expired.

10. Security

We apply measures appropriate to the risk (Article 32 GDPR):

  • TLS/HTTPS encryption for all traffic between your browser and the Site;
  • access to the administrative interface limited to the controller, with strong, uniquely-generated credentials and hashed password storage;
  • the Site is placed behind an authentication layer for non-public environments;
  • software and components kept up to date;
  • regular encrypted backups with integrity verification;
  • data minimisation — we ask for the least we need, and no more.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where Article 33 applies, and notify you directly without undue delay where Article 34 applies.

11. Automated decision-making and profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile visitors. No AI system is used to evaluate you or to make decisions about you.

12. Changes to this notice

We may update this notice. The current version is always available at https://lazarewww.ru/en/privacy-policy/, and the version date is shown at the top. Where a change materially affects your rights, we will make it clear on the page, and — if we hold your contact details and the change is significant — tell you directly. Changes take effect no earlier than 10 days after publication.

13. Contact

For anything to do with your personal data, including exercising your rights:

  • Email: webkuzndets@yandex.ru
  • Telegram: @lazarevpl
  • MAX: https://max.ru/u/f9LHodD0cOLhXrA6rVM5rHv7x3z75fp9WpGPzeG-hHhzofklyqNhKW5exb0
  • Instagram: lazarewww.ru
  • Post: Kamenka village, Novosibirsk District, Novosibirsk Region, Russia (full address on written request)

We aim to resolve concerns directly. If we cannot, your right to complain to a supervisory authority is unaffected.

Pavel Lazarev Full-stack developer

  • Telegram
  • Instagram*
  • MAX
© 2026 All rights reserved Copying of materials is prohibited Privacy Policy Back to top

* Instagram is owned by Meta, an organisation recognised as extremist in Russia and banned on Russian territory.

We use cookies to make the site work better. Nothing scary.