Загрузка...
Загрузка...
Found a bug, outage, or unexpected behavior in reChecker? Send us a message and we will check and fix it.
Version dated August 24, 2026
This Policy describes how personal data is processed when a person visits rechecker.ru, creates an account, uses reChecker tools, submits an application or brief, pays for services, contacts support, or connects an integration.
The Controller complies with the Constitution of the Russian Federation, Federal Law No. 152-FZ on Personal Data, Federal Law No. 149-FZ, Federal Law No. 38-FZ on Advertising, and other applicable Russian law.
Processing is limited to stated and lawful purposes. Data that is excessive in relation to those purposes is not intentionally requested.
Sole Proprietor Dobrynina Ekaterina Vladimirovna
TIN: 482425719598 · OGRNIP: 326480000011329
Registered address: 398059, Lipetsk, Nedelina St., 4A
Email: info@rechecker.ru
Requests concerning personal data, consent withdrawal, correction, blocking, or deletion should be sent to this email. The Controller may request information necessary to identify the requester and confirm their authority.
The Controller does not intentionally collect special-category or biometric personal data and asks users not to include such data, third-party secrets, or unrelated third-party personal data in URLs, messages, files, or tool inputs.
| Purpose | Legal basis | Retention |
|---|---|---|
| Registration, authentication, account and team management | Steps requested before a contract and performance of the contract | While the account is active; after closure, deletion or blocking with only legally required exceptions |
| Checks, audits, monitoring, reports, AI tools and integrations requested by the user | Performance of the contract; consent where a particular integration requires it | Until deletion by the user or while the account is active; after closure, deletion or blocking with legally required exceptions |
| Temporary guest express-audit report | Steps requested before a contract and performance of the requested service | Available for 7 days unless the guest adds it to an account; it is then deleted by the next scheduled cleanup, normally within the following day. After adding it, the ordinary account-report period applies |
| Payments, subscriptions, receipts, refunds and accounting | Performance of the contract and legal obligations | For the period required by accounting and tax law, generally at least 5 years |
| Applications, briefs, feedback, support and pre-contract communication | Requested pre-contract steps, performance of the contract, or separate consent shown with the form | Until handling is completed and for 1 year afterwards; an unresolved submission for no longer than 3 years |
| Security, abuse prevention, diagnostics and incident investigation | Legal obligations and the Controller’s legitimate interest, provided that subject rights are not violated | Technical logs for up to 90 days; incident materials until the investigation and applicable limitation periods end |
| Maintaining an anonymized public technical domain index | The Controller’s legitimate interest in maintaining a public technical index based on publicly accessible website information, subject to data-subject rights | Until the summary is updated by a new check, the index is discontinued, or a justified removal request is granted |
| Email or phone verification and recovery | Requested pre-contract steps, performance of the contract, and security | Verification codes and related records for no longer than 7 days after expiration |
| Optional audience measurement and advertising technologies | Cookie consent | Until consent withdrawal or the period stated in the Cookie Policy |
| reChecker promotional communications | Separate prior marketing consent | Until withdrawal, but no longer than 3 years without renewed confirmation |
| Proof of consent, refusal, withdrawal, or unsubscribe | Legal obligations and the Controller’s legitimate interest in proving compliance | A minimized record for 3 years after withdrawal or the end of consent |
Consent is not used where processing is necessary for a contract or required by law. Withdrawal of consent does not invalidate prior lawful processing and does not require deletion of data that must be retained on another legal basis.
The Controller may collect, record, systematize, accumulate, store, clarify, retrieve, use, transfer to an authorized processor, provide access, block, delete, and destroy data by automated or mixed processing, including transmission over the Internet.
Data is obtained from the subject, their device, an organization they represent, payment and authentication providers, a connected integration, or public website resources that the user asks reChecker to analyze. A person submitting third-party data must have a lawful basis to do so.
Automated checks may generate technical scores and recommendations, but reChecker does not make solely automated decisions that produce legal consequences for a person or otherwise significantly affect their rights. A user may ask support to explain a result.
When collecting personal data of Russian citizens, the Controller records, systematizes, accumulates, stores, updates, and retrieves it using databases located in the Russian Federation. The actual hosting and database infrastructure is maintained in Russia; the Controller does not publish technical addresses for security reasons.
Within the stated purposes and under contracts or statutory obligations, data may be entrusted or provided to: Russian hosting, database, backup, email, and infrastructure providers; YooKassa for payments, recurring payment identifiers, receipts, and refunds; Yandex services for a user-requested SEO check or connected Webmaster integration, and Yandex.Metrica only after optional analytics consent; public authorities under a lawful request; and other persons directly named in the relevant interface or consent.
Some selected or activated reChecker functions actually use foreign services and may involve cross-border transfer. Such transfer occurs when the user requests the relevant function, connects an integration or communication channel, or enables a service whose operation requires that provider. Closed technical notifications about a completed registration are generated automatically for authorized administration of the service and do not depend on the user selecting Telegram as a communication channel.
Except for the closed registration-administration notification described above, these integrations are used only for a function requested, connected, or enabled by the user, or for delivery selected in the account. The product sends the minimum data required for that action and may temporarily disable a provider if safe processing cannot be ensured. A deliberate external link opened by the user is not an automatic website transfer.
Only data necessary for the selected action or authorized administration is sent: for example, an OAuth token and connected-resource identifier; a Telegram identifier, username, event, or message; for an email registration, its source, account username, email, and the manually entered contact phone and/or unverified Telegram username in a single closed technical topic visible only to authorized administrators; for a Telegram registration, its source and public Telegram username if one is present; a submitted URL or search query; a prompt, text, image, audio, or other file; and technical request metadata necessarily received by the provider. Registration notifications are not delivered through legacy fallback recipients. Passwords, internal account identifiers, and numeric Telegram identifiers are not included. The interface should not be used to submit secrets, special-category data, or unrelated third-party personal data.
The legal basis depends on the function: performance of a contract or steps requested by the data subject, a separate specific consent where consent is required, or a statutory obligation. Advertising through Telegram or another channel additionally requires separate prior advertising consent. Before a cross-border transfer, the Controller must assess the recipient and destination country, safeguards and termination conditions; comply with Article 12 of Federal Law No. 152-FZ; submit the separate cross-border-transfer notification to Roskomnadzor required by that Article; and comply with any prohibition or restriction imposed by the authority.
The Russian localization requirement remains in force: initial collection, recording, systematization, accumulation, storage, clarification, and retrieval of Russian citizens’ personal data are performed using databases in Russia before any lawful subsequent transfer required for a selected action. If no exception under Article 22 applies, the Controller must also file and keep current the general personal-data-processing notification. Publication of this Policy does not represent that either notification has already been filed; filing and registry status must be confirmed separately.
The current legal recipient, destination country, and transfer details for a particular function are available from the Controller. Personal data is not sold or provided to unrelated third parties for their own advertising.
The automatic public technical index contains only a registrable domain/origin, overall score, bounded numeric coverage, check statuses, run count, and update date. Server-side filtering removes paths, queries, page content, error text, full audit details, account data, contact data, and internal identifiers before storage. Registration never unlocks the full result of another person’s run.
Ordinary processing consent is not consent to make personal data publicly available. A full or private report, branded case, or status page is made public only after a separate deliberate sharing action by an authorized user; the user must verify that the publication has a lawful basis and may disable sharing.
Strictly necessary technologies support security, authentication, language selection, load control, and recording the cookie choice. Optional analytics and advertising technologies are enabled only after consent and may be disabled without losing the core service.
The Controller applies legal, organizational, and technical measures appropriate to identified threats, including access restriction, authentication, role separation, encrypted transport, password hashing, encryption of integration tokens, logging, backups, updates, vulnerability response, and incident procedures. Employees and contractors receive access only to the extent needed for their duties and are bound by confidentiality.
After the purpose or retention period ends, data is deleted, destroyed, or anonymized unless another legal basis requires retention. Paper records are shredded; electronic records are deleted from active systems and then overwritten with the normal backup cycle. Destruction may be documented where required.
A data subject may:
The Controller responds within 10 business days after receiving a request. This period may be extended by no more than 5 business days upon a reasoned notice. Direct marketing is stopped immediately upon request.
Consent documents: personal data consent · marketing consent
reChecker is intended for adults and representatives of businesses. A minor must not provide personal data without a legal representative. If such data is discovered without a lawful basis, the Controller will delete it.
The Controller may update this Policy when processing or law changes. The effective version and its date are always published on this page. Material changes affecting an existing legal basis or consent are communicated before the new processing begins, where required.