Legal
Personal Data Processing Policy
Personal Data Processing Policy
Controller: Individual Entrepreneur Ruslan Alikovich Beriev
Effective date: 4 August 2026
Published at: https://alania-drive.ru/en/privacy
1. General provisions
1.1. This Personal Data Processing Policy sets out how Individual Entrepreneur Ruslan Alikovich Beriev, hereinafter the “Controller,” processes and protects personal data.
1.2. The Policy has been prepared in accordance with the laws of the Russian Federation, including Federal Law No. 152-FZ of 27 July 2006 “On Personal Data.”
1.3. This Policy applies to personal data obtained:
- through https://alania-drive.ru;
- through booking and contact forms;
- when arranging vehicle rental;
- when ordering a transfer, tour or another service;
- by telephone;
- by email;
- through Telegram and WhatsApp;
- during in-person communication;
- when entering into and performing contracts;
- automatically when the website is used.
1.4. This Policy is publicly available on the Controller’s website.
2. Controller information
Full name: Individual Entrepreneur Ruslan Alikovich Beriev
Short name: IE Ruslan Beriev
Russian Taxpayer Identification Number, INN: 151500962010
Primary State Registration Number, OGRNIP: 321151300017276
Registered address: 9 Borodinskaya Street, Vladikavkaz, Republic of North Ossetia–Alania, Russian Federation
Postal address: 9 Borodinskaya Street, Vladikavkaz, Republic of North Ossetia–Alania, Russian Federation
Telephone: +7 (928) 480-29-99
Privacy email: —
Requests concerning personal data, data-subject rights or withdrawal of consent may be sent to the postal address above or communicated by telephone.
3. Processing principles
The Controller processes personal data in accordance with the principles of:
- lawfulness and fairness;
- processing for specific and predetermined purposes;
- no processing incompatible with the original purpose;
- data minimisation;
- accuracy, sufficiency and relevance;
- retention only for as long as required by the purpose or applicable law;
- deletion or anonymisation after the purpose has been achieved, unless another lawful ground requires continued retention;
- confidentiality and security.
4. Categories of data subjects
The Controller may process personal data relating to:
- website visitors;
- persons submitting vehicle rental requests;
- customers ordering transfers, tours or other services;
- prospective and existing customers;
- customer representatives;
- passengers where their details are required to provide a service;
- persons submitting questions, reviews, complaints or other communications;
- contractors and their representatives;
- users communicating through Telegram, WhatsApp, email or telephone.
5. Categories of personal data
5.1. Contact information
The Controller may process:
- first name;
- surname and patronymic, where provided;
- telephone number;
- email address;
- preferred language;
- messenger username or identifier.
5.2. Booking and travel information
The Controller may process:
- selected vehicle, tour, transfer or other service;
- requested dates and time;
- vehicle delivery and return location;
- point of departure and destination;
- route;
- number of passengers;
- luggage information;
- requests and comments;
- message content;
- request status and processing history.
5.3. Contractual information
When entering into and performing a contract, the Controller may request additional information that is objectively required to:
- identify the customer;
- arrange the vehicle or service;
- enter into and perform the contract;
- comply with applicable statutory obligations.
The amount of data requested must not exceed what is necessary for the relevant purpose.
5.4. Technical information
The following information may be processed automatically:
- IP address;
- date and time of access;
- browser type and version;
- device type;
- operating system;
- user-agent;
- referrer;
- visited pages;
- technical identifiers;
- cookies;
- UTM parameters;
- security and diagnostic logs.
5.5. Consent information
The Controller may retain:
- whether consent was given or withdrawn;
- date and time;
- source and form;
- interface language;
- consent type;
- legal-document identifier and version;
- document content hash;
- the wording applicable when consent was provided.
6. Sensitive and biometric data
6.1. The Controller does not request sensitive personal data relating to health, political opinions, religious beliefs, private life or similar categories.
6.2. The Controller does not process biometric personal data for identification.
6.3. Users should not provide such information through website forms, email or messengers.
6.4. Excessive or sensitive information submitted without necessity may be deleted by the Controller.
7. Purposes and legal grounds
7.1. Processing service requests
Personal data is processed to:
- receive and process requests;
- contact users;
- clarify travel requirements;
- select a vehicle or service;
- calculate costs;
- prepare an offer;
- agree booking details.
The legal grounds are the user’s consent and taking steps at the user’s request before entering into a contract.
7.2. Entering into and performing contracts
Personal data is processed to:
- arrange bookings;
- enter into and perform contracts;
- provide vehicles;
- organise transfers and tours;
- communicate regarding the service;
- handle claims;
- comply with legal obligations.
7.3. Communications
Personal data is used to handle questions, reviews, claims and other requests, and to prepare responses.
7.4. Website operation and security
Technical data may be used to:
- maintain website functionality;
- save language preferences;
- diagnose errors;
- prevent misuse;
- protect the website, databases and server infrastructure;
- investigate security incidents.
7.5. Marketing communications
Advertising, news and special offers may be sent only where the user has provided separate consent.
Marketing consent:
- is not required to submit a service request;
- is not pre-selected;
- is given separately;
- may be withdrawn at any time.
Where marketing communications are not used, personal data is not processed for this purpose.
8. Sources of personal data
Personal data may be obtained:
- directly from the user;
- from the user’s lawful representative;
- through website forms;
- by telephone;
- by email;
- through Telegram and WhatsApp;
- during contract conclusion and performance;
- automatically through technical interaction between the browser and the website;
- from contractors where the transfer is lawful.
Users must provide accurate information and must not provide another person’s data without a lawful basis.
9. Processing operations
The Controller may perform:
- collection;
- recording;
- organisation;
- accumulation;
- storage;
- correction;
- updating;
- retrieval;
- use;
- access by authorised persons;
- disclosure to processors and service providers where legally permitted;
- anonymisation;
- restriction;
- deletion;
- destruction.
Processing may be automated, non-automated or mixed.
The Controller does not make decisions producing legal effects solely through automated processing.
10. Retention
10.1. Personal data is retained only for as long as required for the relevant purpose, unless a longer period is required by law or contract.
10.2. Request information is retained for the time required to:
- contact the user;
- prepare an offer;
- perform the booking;
- handle possible communications and claims.
10.3. Contractual, accounting, tax and other legally significant records are retained for the periods required by Russian law.
10.4. Consent records are retained for the duration of consent and for the period required to demonstrate lawful processing.
10.5. Once the purpose has been achieved, the retention period has expired or consent has been withdrawn, personal data is deleted or anonymised unless another lawful basis applies.
10.6. Specific retention periods are established in the Controller’s internal documents.
11. Storage and localisation
11.1. Primary recording, organisation, accumulation, storage, correction and retrieval of personal data relating to citizens of the Russian Federation are performed using databases located within the Russian Federation.
11.2. The website, principal database, file storage and related components are hosted on a REG.RU cloud server.
11.3. Infrastructure region: Moscow, Russian Federation.
11.4. The main application database uses PostgreSQL.
11.5. Files and images may be stored in MinIO object storage.
11.6. Backups are stored within REG.RU infrastructure in Moscow, Russian Federation.
11.7. The alania-drive.ru domain is managed through REG.RU.
12. Processors and recipients
12.1. The Controller does not disclose personal data without a lawful basis.
12.2. Access may be provided to:
- the Controller’s authorised staff and representatives;
- REG.RU, for domain registration, cloud-server services, network and server infrastructure, and backup storage;
- email, telephony and communications providers;
- persons and organisations directly involved in providing the requested transfer, tour or other service;
- accounting, legal and technical contractors;
- public authorities where required by law.
12.3. Only the amount of data necessary for the relevant purpose is disclosed.
12.4. Processors acting on the Controller’s instructions must maintain confidentiality and implement appropriate security measures.
13. Telegram and WhatsApp
13.1. Users may contact the Controller through Telegram or WhatsApp.
13.2. When a messenger is used, personal data is also processed by the owner of that service under its own terms and privacy documents.
13.3. The Controller does not control the messenger provider’s infrastructure, retention periods or further use of personal data.
13.4. Users should not send through messengers:
- passport details;
- banking information;
- health information;
- sensitive personal data;
- confidential information not required for the request.
13.5. Users may request an alternative communication method by calling +7 (928) 480-29-99.
14. Cross-border transfers
14.1. The principal database and backups are located within the Russian Federation.
14.2. The use of Telegram, WhatsApp or other foreign services may result in processing or access outside the Russian Federation.
14.3. Before initiating a cross-border transfer, the Controller complies with applicable Russian legal requirements, establishes a lawful basis and completes any required notification procedure.
14.4. Where the necessary requirements have not been met, personal data must not be transferred through the relevant foreign service.
15. Cookies and local storage
15.1. The website uses cookies and browser local storage.
15.2. Essential cookies may be used to:
- save language preferences;
- maintain security;
- support technical sessions;
- save user preferences;
- ensure correct website operation.
15.3. Non-essential analytics, functional and marketing technologies are used only in accordance with the user’s choice.
15.4. Users may accept, reject or modify non-essential cookie settings through the website interface.
15.5. Further information is available in the Cookie Policy:
https://alania-drive.ru/en/cookies
16. Security measures
The Controller applies legal, organisational and technical safeguards, including:
- access restrictions;
- individual user accounts;
- passwords and authentication;
- HTTPS connections;
- role-based administrative access;
- logging of significant actions;
- backups;
- software updates;
- server infrastructure protection;
- database and file-storage access controls;
- data recovery;
- detection of unauthorised access;
- incident response;
- deletion or anonymisation after lawful grounds expire.
17. Data-subject rights
Users may:
- obtain information about the processing of their personal data;
- request correction of inaccurate or incomplete data;
- request restriction or deletion of unlawfully processed data;
- withdraw consent;
- opt out of marketing communications;
- request cessation of processing where no other lawful ground applies;
- lodge a complaint with Roskomnadzor or a court;
- exercise other rights provided by Russian law.
18. Requests and withdrawal of consent
18.1. Requests or withdrawals may be submitted:
By post: 9 Borodinskaya Street, Vladikavkaz, Republic of North Ossetia–Alania, Russian Federation
By telephone: +7 (928) 480-29-99
By email: —
18.2. A request must contain sufficient information to identify the applicant and describe the requested action.
18.3. The Controller may request information required to verify the applicant’s identity.
18.4. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal was received.
18.5. After withdrawal, the Controller stops processing based solely on consent unless another lawful basis permits or requires continued processing.
19. Security incidents
Where unlawful access, disclosure, loss or dissemination of personal data is identified, the Controller:
- takes steps to contain the incident;
- investigates the causes;
- remedies identified violations;
- records relevant information;
- complies with statutory notification obligations;
- takes steps to prevent recurrence.
20. Amendments
20.1. The Controller may update this Policy where laws, services, processing activities or information systems change.
20.2. The current version is published at:
https://alania-drive.ru/en/privacy
20.3. The page displays the effective date and the last-updated date.
20.4. A new version applies from the date of publication unless another effective date is stated.
21. Controller details
Individual Entrepreneur Ruslan Alikovich Beriev
INN: 151500962010
OGRNIP: 321151300017276
Registered and postal address: 9 Borodinskaya Street, Vladikavkaz, Republic of North Ossetia–Alania, Russian Federation
Telephone: +7 (928) 480-29-99
Privacy email: — hello@alania-drive.ru

