log in
metasiberia logo

Privacy Policy / Политика конфиденциальности

1. General Provisions

“Metasiberia” (Metasiberia), hereinafter referred to as the “Service”, is a software platform for creating and managing interactive 3D spaces and digital twins.

This Policy explains processing of personal and technical data by the Service.

Russian personal-data law applies within its scope; GDPR (General Data Protection Regulation — the European Union General Data Protection Regulation) applies only where its territorial and material conditions are met.

2. Personal Data Operator

The operator is Denis Vladimirovich Shipilov, an individual registered as a payer of NPD (professional income tax).

Contact email: mail@metasiberia.com. No additional legal details are stated here without confirmation.

3. Terms and Definitions

TermDefinition
UserA person using the Service.
Personal DataInformation relating directly or indirectly to an identified or identifiable person.
Data SubjectThe person to whom personal data relates.
OperatorThe person determining purposes and scope of processing.
ProcessingAny operation with data, including collection, storage, use, transfer and erasure.
StorageKeeping data in service state, logs or backups.
ErasureDeletion or other removal under applicable procedures.
AnonymizationMaking identification impossible without additional information.
CookieA browser identifier stored separately from localStorage.
Technical DataData generated by network and service operation.
IP AddressA network address available to infrastructure.
Authentication DataPassword-derived verification data and session identifiers.
SessionA period of authenticated access.
UsernameAn account identifier used for login.
EmailAn address used for the account and recovery.
PasswordA secret supplied by the User; plaintext is not stored.
Password HashA cryptographic representation stored instead of plaintext.
SaltA random value used when computing the hash.
Password Reset TokenA temporary recovery credential.
ConsentSpecific, informed and unambiguous permission expressed by a separate action.
Terms of UseRules accepted separately from data consent.
Privacy PolicyThis document describing processing.
Third PartyA person other than the User, Operator or instructed processor.
ConfidentialityA protection duty or regime, not an independent personal-data category.
Special Categories of Personal DataCategories defined by applicable law, such as health or biometric data.

4. Data Processed

CategoryDataPurpose
AccountUsername, email, creation timestampAccount operation
CredentialsPassword hash, salt, sessions, reset dataAuthentication and recovery
SettingsAccount, avatar and language settingsRequested personalization
TechnicalNetwork data, IP available to infrastructure, logsDelivery, security and diagnostics

The plaintext password is not stored.

5. Purposes and Legal Bases of Processing

PurposeDataBasis
Registration and loginAccount and credentialsRequested service and applicable law
RecoveryEmail and reset dataRequested recovery and consent where required
World operationAccount, avatar and session settingsService performance
Security and supportTechnical data and logsLegal duties and lawful security grounds

Russian legal grounds and GDPR bases are not interchangeable.

6. Registration, Authentication and Security

Registration uses username, email and password, two separate checkboxes for Terms of Use and personal-data consent, and server-side validation of both.

Use of the Service is governed by the Terms of Use.

The disabled submit button is only an interface aid. Password hashing, random salt, sessions and reset tokens protect authentication; their secrets must not be disclosed.

7. Cookies and Technical Data

MechanismPurposeStorage
site-bAuthentication and sessionCookie; Max-Age 90 days, HttpOnly, SameSite=Lax, Secure over TLS
msb-cookie-consent-v1Cookie-banner decisionBrowser localStorage, not a cookie
msb-site-langInterface languageBrowser localStorage

8. Storage and Retention

Account/world state, operational logs and recovery backups are kept under production controls for operation, security and continuity. No universal fixed retention period is promised. Removing data from production does not necessarily remove it immediately from backups or immutable logs.

9. Data Security and Technical Infrastructure

Hashing, salt, HttpOnly, SameSite, TLS, restricted production access, reverse proxy, technical logs and security diagnostics are used as appropriate. No measure guarantees absolute security.

10. Third-Party Services and Data Sharing

Password recovery uses configured SMTP. Hosting and reverse-proxy infrastructure handles traffic; the server may use upstream map services. Personal data is not sold or rented and may be processed by providers only as necessary for operation, security, maintenance, recovery, requested functions or legal requirements.

11. User Rights

RightDescription
AccessRequest information about processing
CorrectionRequest correction of inaccurate data
Deletion or restrictionRequest where provided by applicable law
ComplaintContact a competent authority where applicable

Requests: mail@metasiberia.com

12. Consent Withdrawal and Account Deletion

12.1 Withdrawal of Consent

Consent may be withdrawn by email. Withdrawal does not make prior lawful processing unlawful and does not stop processing required by law or security where another basis exists.

12.2 Account and Data Deletion

Send a request to mail@metasiberia.com; identification may be required. Data subject to deletion is removed where required, while legally required records, backups and immutable logs may follow their lifecycle.

13. Minors and International Transfers

13.1 Minors

The Service does not automatically verify age. Where required by law, a representative’s consent must be obtained; parents or legal representatives may contact the Operator.

13.2 International Transfers

Hosting, SMTP and upstream services may process data in different jurisdictions depending on configuration. No specific country is asserted without confirmation.

14. Changes to this Privacy Policy

This Policy may change when the Service, law or security practices change. The current version is published at /privacy.

15. Applicable Law

Russian personal-data legislation applies within its scope. GDPR applies only where its territorial and material criteria are met.

16. Official Legal Sources

Legal actSubjectSource
Federal Law No. 152-FZPersonal-data definitions, principles, consent, rights and securityConsultant.ru
Federal Law No. 156-FZAmendments concerning consentConsultant.ru
GDPR, Regulation (EU) 2016/679Data protection where applicableEUR-Lex