Back Русская версия
Document version: 2026-08-22

Personal Data Processing Policy

*Courtesy English translation. The Russian text (PRIVACY_POLICY.ru.md, «Политика обработки персональных данных») is the binding version.*

Operator: [not set — Settings → Operator], INN/OGRN [not set — Settings → Operator], address: [not set — Settings → Operator], e-mail: [not set — Settings → Operator], phone: [not set — Settings → Operator] (the "Operator").

Platform: "Iterum School" — https://www.lms.iterum.school (the "Platform").

Person responsible for organising personal-data processing: [not set — Settings → Operator], [not set — Settings → Operator].

Document version: 2026-08-22. Published without restriction under art. 18.1(2) of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data".


1. General

  1. This Policy sets out how the Operator processes and protects the personal data ("PD") of Platform users: students, their parents (legal representatives), teachers and administrators.
  2. It is based on the Constitution of the Russian Federation, Federal Laws No. 152-FZ "On Personal Data", No. 149-FZ "On Information", No. 273-FZ "On Education", No. 38-FZ "On Advertising" and other Russian legislation.
  3. Using the Platform means you agree with this Policy. Consent to PD processing is given as a separate document at first sign-in (152-FZ art. 9). Refusing consent makes it impossible to use the Platform.

2. Data subjects and data collected

SubjectPersonal data
All usersfull name, e-mail, phone number, role and account status, password (stored only as a bcrypt hash), interface language, photo (avatar, if uploaded), Telegram ID (if provided)
Studentsdate of birth (to decide whether a representative's consent is required); enrolment and course/module/lesson access; progress (lesson completion, quiz results, time spent); homework with attached files, text and voice notes; group and timetable; attendance; parent / legal-representative details (name, phone, e-mail)
Parents / legal representativesrelationship; if they have an account — name, e-mail, phone, password; read-only access to their children's data
Teachersassigned courses/modules/groups; grades and feedback given; remuneration records (visible only to administrators with the Finance right)
All (communications)internal chat messages; records of information mailings and their status
All (finance)invoices, amounts, payment status and method, fiscal receipt number. Full card details are never stored on the Platform
All (technical)IP address, browser details, sign-in date and time, session identifier (cookie), consent records (date, time, IP, document version)

Special categories of PD (health, ethnicity etc.) and biometric data are not processed.

3. Purposes and legal bases

PurposeLegal basis
Provision of educational services, organisation of learning, attendance and progress recordspaid educational services agreement (152-FZ art. 6(1)(5)); consent of the subject / legal representative
Communication with the student and representatives about learning (timetable, assignments)agreement; consent
Invoicing, payment records, accountingagreement; Federal Law No. 402-FZ "On Accounting"; Tax Code
Information and promotional messagesseparate consent (38-FZ art. 18, 152-FZ art. 15); may be withdrawn at any time
Platform security, protection against unauthorised accessOperator's legitimate interest; 152-FZ art. 19
Compliance with law, responses to authorised bodieslaw

No decisions with legal consequences are taken solely on the basis of automated processing. PD is not used for profiling or third-party advertising and is never sold.

4. How data is processed

  1. Processing is automated: collection, recording, systematisation, accumulation, storage, updating, extraction, use, transfer (access) within section 4.2, depersonalisation, blocking, deletion, destruction.
  2. Only the Operator's staff and teachers who need PD for their duties have access, limited by their role in the Platform (permissions matrix). A teacher sees only their own students; a parent only their own children.
  3. Localisation. Recording, systematisation, accumulation, storage, updating and extraction of Russian citizens' PD is carried out in databases located in the Russian Federation: [not set — Settings → Operator] (152-FZ art. 18(5)). No cross-border transfer takes place.
  4. PD is not shared with third parties except: the hosting provider (under contract, storage on servers in Russia only); telecom / mailing providers — only with separate marketing consent and only contact data; state bodies on lawful request.
  5. Lesson videos are hosted on Russian video platforms or the Operator's own servers. No third-party analytics or trackers are embedded.
  6. Cookies. Only strictly necessary cookies are used: the session ID (PHPSESSID, deleted when the browser closes) and the sign-in page language (login_lang). No tracking or advertising cookies.

5. Retention and destruction

DataPeriod
Account and learning dataperiod of study + 3 years (or as set in the agreement), then anonymisation
Financial documents (invoices, payments)5 years (402-FZ art. 29) — kept in anonymised form after the account is anonymised
Security log (sign-ins, actions), technical data1 year
Chat messages1 year
Consent recordswhole processing period + 3 years (proof of consent)

On withdrawal of consent the Operator stops processing and destroys (anonymises) the PD within 30 days (152-FZ art. 21(5)), except data that must be kept by law. Destruction is automatic (account anonymisation: name, contacts, date of birth, files, messages and learning history are removed) and is logged.

6. Your rights

A data subject (or, for a minor, their legal representative) may (152-FZ art. 14):

7. Minors

Consent for a student under 18 is given by a parent or other legal representative (Civil Code art. 26, 28). If no date of birth is on file the student is treated as a minor. The representative's consent is recorded on the Platform from the parent account or on paper (the administrator then marks it in the system). A parent sees their child's data in the parent portal.

8. Security measures

Legal, organisational and technical measures under 152-FZ art. 18.1 and 19: an appointed responsible person; this Policy and internal regulations; role-based access; bcrypt password hashes; CSRF, SQL-injection and session-fixation protection; sign-in throttling; HTTPS; uploaded files are never executed; a log of actions with PD; regular backups inside Russia.

Incidents. If an unlawful transfer (leak) of PD is detected, the Operator notifies Roskomnadzor within 24 hours, submits the internal investigation results within 72 hours (152-FZ art. 21(3.1)) and informs affected subjects.

9. Operator details

10. Changes

The Operator may amend this Policy. The new version is published on this page with its version number; after material changes users re-confirm consent at next sign-in.