“Metasiberia” (Metasiberia), hereinafter referred to as the “Service”, is a software platform for creating and managing interactive 3D spaces and digital twins.
This Policy explains processing of personal and technical data by the Service.
Russian personal-data law applies within its scope; GDPR (General Data Protection Regulation — the European Union General Data Protection Regulation) applies only where its territorial and material conditions are met.
The operator is Denis Vladimirovich Shipilov, an individual registered as a payer of NPD (professional income tax).
Contact email: mail@metasiberia.com. No additional legal details are stated here without confirmation.
| Term | Definition |
|---|---|
| User | A person using the Service. |
| Personal Data | Information relating directly or indirectly to an identified or identifiable person. |
| Data Subject | The person to whom personal data relates. |
| Operator | The person determining purposes and scope of processing. |
| Processing | Any operation with data, including collection, storage, use, transfer and erasure. |
| Storage | Keeping data in service state, logs or backups. |
| Erasure | Deletion or other removal under applicable procedures. |
| Anonymization | Making identification impossible without additional information. |
| Cookie | A browser identifier stored separately from localStorage. |
| Technical Data | Data generated by network and service operation. |
| IP Address | A network address available to infrastructure. |
| Authentication Data | Password-derived verification data and session identifiers. |
| Session | A period of authenticated access. |
| Username | An account identifier used for login. |
| An address used for the account and recovery. | |
| Password | A secret supplied by the User; plaintext is not stored. |
| Password Hash | A cryptographic representation stored instead of plaintext. |
| Salt | A random value used when computing the hash. |
| Password Reset Token | A temporary recovery credential. |
| Consent | Specific, informed and unambiguous permission expressed by a separate action. |
| Terms of Use | Rules accepted separately from data consent. |
| Privacy Policy | This document describing processing. |
| Third Party | A person other than the User, Operator or instructed processor. |
| Confidentiality | A protection duty or regime, not an independent personal-data category. |
| Special Categories of Personal Data | Categories defined by applicable law, such as health or biometric data. |
| Category | Data | Purpose |
|---|---|---|
| Account | Username, email, creation timestamp | Account operation |
| Credentials | Password hash, salt, sessions, reset data | Authentication and recovery |
| Settings | Account, avatar and language settings | Requested personalization |
| Technical | Network data, IP available to infrastructure, logs | Delivery, security and diagnostics |
The plaintext password is not stored.
| Purpose | Data | Basis |
|---|---|---|
| Registration and login | Account and credentials | Requested service and applicable law |
| Recovery | Email and reset data | Requested recovery and consent where required |
| World operation | Account, avatar and session settings | Service performance |
| Security and support | Technical data and logs | Legal duties and lawful security grounds |
Russian legal grounds and GDPR bases are not interchangeable.
Registration uses username, email and password, two separate checkboxes for Terms of Use and personal-data consent, and server-side validation of both.
Use of the Service is governed by the Terms of Use.
The disabled submit button is only an interface aid. Password hashing, random salt, sessions and reset tokens protect authentication; their secrets must not be disclosed.
| Mechanism | Purpose | Storage |
|---|---|---|
| site-b | Authentication and session | Cookie; Max-Age 90 days, HttpOnly, SameSite=Lax, Secure over TLS |
| msb-cookie-consent-v1 | Cookie-banner decision | Browser localStorage, not a cookie |
| msb-site-lang | Interface language | Browser localStorage |
Account/world state, operational logs and recovery backups are kept under production controls for operation, security and continuity. No universal fixed retention period is promised. Removing data from production does not necessarily remove it immediately from backups or immutable logs.
Hashing, salt, HttpOnly, SameSite, TLS, restricted production access, reverse proxy, technical logs and security diagnostics are used as appropriate. No measure guarantees absolute security.
Password recovery uses configured SMTP. Hosting and reverse-proxy infrastructure handles traffic; the server may use upstream map services. Personal data is not sold or rented and may be processed by providers only as necessary for operation, security, maintenance, recovery, requested functions or legal requirements.
| Right | Description |
|---|---|
| Access | Request information about processing |
| Correction | Request correction of inaccurate data |
| Deletion or restriction | Request where provided by applicable law |
| Complaint | Contact a competent authority where applicable |
Requests: mail@metasiberia.com
Consent may be withdrawn by email. Withdrawal does not make prior lawful processing unlawful and does not stop processing required by law or security where another basis exists.
Send a request to mail@metasiberia.com; identification may be required. Data subject to deletion is removed where required, while legally required records, backups and immutable logs may follow their lifecycle.
The Service does not automatically verify age. Where required by law, a representative’s consent must be obtained; parents or legal representatives may contact the Operator.
Hosting, SMTP and upstream services may process data in different jurisdictions depending on configuration. No specific country is asserted without confirmation.
This Policy may change when the Service, law or security practices change. The current version is published at /privacy.
Russian personal-data legislation applies within its scope. GDPR applies only where its territorial and material criteria are met.
| Legal act | Subject | Source |
|---|---|---|
| Federal Law No. 152-FZ | Personal-data definitions, principles, consent, rights and security | Consultant.ru |
| Federal Law No. 156-FZ | Amendments concerning consent | Consultant.ru |
| GDPR, Regulation (EU) 2016/679 | Data protection where applicable | EUR-Lex |