Personal Data Processing Policy

Effective date: 27 July 2026

This Personal Data Processing Policy (the "Policy") describes how personal data of natural persons is collected, used, disclosed, retained, and protected when you interact with the website jemio.ru or communicate with us by email or messenger.

The Policy is drafted in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), Russian Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" ("152-FZ"), and Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), as applicable to the data subject's jurisdiction.

Related documents: Consent to Personal Data Processing, Terms of Use, Cookie Policy, Public Offer Agreement.


1. Data Controller

Legal form: Individual Entrepreneur Khamzin Artem Maratovich (IE Khamzin A.M.)

TIN (INN): 166019255124

Registration number (OGRNIP): 325169000153195

Registered address: 420075, Kazan, Republic of Tatarstan, 3rd Klenovaya str., 100, Russian Federation

Contact for personal data requests: hello@jemio.ru (subject: "Personal data")

General contact: hello@jemio.ru · Studio: studio@jemio.ru · Telegram: https://t.me/ahamzin

The controller processes personal data independently. Processing by third parties acting as processors on the controller's behalf takes place only in the cases and to the extent expressly set out in Section 5 of this Policy, under terms ensuring confidentiality and compliance with Art. 28 GDPR and Art. 6(3) of 152-FZ.


2. Scope and Applicable Law

This Policy applies to:

  • Visitors of jemio.ru located anywhere in the world;
  • Individuals whose personal data is submitted through website forms, email, or messengers.

The service is intended exclusively for individuals of legal age (18+) acting in a business capacity (B2B: employees, authorized representatives of legal entities, sole proprietors, self-employed professionals).

Applicable regimes:

  • EU / EEA residents: GDPR
  • Russian residents: 152-FZ
  • Turkish residents: KVKK No. 6698
  • Other jurisdictions: applicable local law without prejudice to the above

3. Categories of Personal Data

Depending on the interaction, we may process:

  • Identification data: first name, last name, patronymic (if applicable), organization name, job title;
  • Contact data: email, phone number, Telegram username;
  • Enquiry data: task description, briefing, shoot parameters, preferences;
  • Source materials: product images or files provided by the subject for service delivery (may contain trademarks, logos, or images of natural persons as part of the product);
  • Technical and analytical data: IP address, browser type, operating system, referrer URL, UTM parameters, cookie data (see Cookie Policy);
  • Payment data: for direct bank transfers — organizational bank details; for card payments — card data is not stored by the controller and is handled exclusively by the payment acquirer.

We do not process special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, criminal convictions).


4. Purposes and Legal Basis of Processing

PurposeLegal basis (GDPR)Legal basis (152-FZ / KVKK)
Processing enquiries, preparing commercial proposalsArt. 6(1)(b) — pre-contractual measures152-FZ Art. 6(1)(5) / KVKK Art. 5(2)(c)
Concluding and performing the service agreementArt. 6(1)(b) — contract152-FZ Art. 6(1)(5) / KVKK Art. 5(2)(c)
Business correspondence, responses to enquiriesArt. 6(1)(f) — legitimate interest152-FZ Art. 6(1)(1) — consent / KVKK Art. 5(1)
Website operation, analyticsArt. 6(1)(a) — consent (cookie banner)152-FZ Art. 6(1)(1) / KVKK Art. 5(1)
Service quality improvement, internal analysisArt. 6(1)(f) — legitimate interest152-FZ Art. 6(1)(1) / KVKK Art. 5(2)(f)
Compliance with legal obligationsArt. 6(1)(c) — legal obligation152-FZ Art. 6(1)(2) / KVKK Art. 5(2)(a)

Processing is limited to specified, explicit, and legitimate purposes. Further processing incompatible with these purposes is not carried out.

Where consent is relied upon as the legal basis, it is given on the terms set out in the Consent to Personal Data Processing and may be withdrawn at any time.


5. Recipients and Cross-Border Data Transfers

5.1. Recipients

RecipientPurposeLegal basis
Yandex LLC (Yandex Forms)Receipt and storage of enquiries submitted through the form on the site (the form is embedded in a Yandex Forms frame on every language version)Consent / contract
Telegram Messenger (bot @jemio_studio_bot)Delivery of enquiry notificationsConsent / contract
Yandex LLC (Yandex Metrica)Website analyticsConsent (cookie banner)
Payment acquirerPayment processingContract
External automated image generation and processing services (processors)Provision of services under the Public Offer Agreement: generation and post-processing of product imagesContract (GDPR Art. 28; 152-FZ Art. 6(3))

5.1.1. External image processing services

To deliver the services, the controller uses external software services for automated image generation and processing, acting as processors (sub-processors) on the controller's instructions.

Such services receive product images only, as submitted by the client for performance of the task. Contact and identification data (name, phone, email, Telegram), the content of business correspondence, and payment data are not transferred to them.

Where submitted product images contain images of natural persons (for example, a person appearing in the original product photography), such images are processed only to the extent necessary to perform the task and are deleted within the periods set out in Section 6 of this Policy.

Processors are engaged on terms ensuring the confidentiality and security of personal data, and the controller remains responsible for their actions towards the data subject. An up-to-date named list of processors is provided on written request to hello@jemio.ru (subject: "Personal data"); clients and data subjects in the EU/EEA may request it under Art. 28(2) GDPR. A Data Processing Agreement under Art. 28 GDPR is available on request.

Processors may be located outside the Russian Federation and outside the EEA — see clause 5.2.

5.2. Cross-Border Data Transfers

Important disclosure: when you submit a form on our website, the data is delivered to Telegram Messenger, whose server infrastructure is located outside the Russian Federation and outside the European Economic Area (including the United Arab Emirates and EU member states).

In addition, the external automated image generation and processing services referred to in clause 5.1.1, to which product images are transferred, may be located outside the Russian Federation and outside the EEA.

Legal basis for the transfer:

  • EU/EEA residents: GDPR Chapter V (Articles 44–49). We rely on Telegram's data transfer mechanisms and, where required, on your explicit consent given by submitting the form (Art. 49(1)(a));
  • Russian residents: 152-FZ Art. 12 — the operator has verified that either the receiving country provides adequate protection of personal data, or the transfer is carried out with the subject's consent on terms ensuring data confidentiality;
  • Turkish residents: KVKK Art. 9 — cross-border transfers subject to explicit consent or other lawful basis.

You may refuse to use the website form and instead contact us directly at studio@jemio.ru — in that case, no automated cross-border transfer occurs.

5.3. No Sale of Personal Data

We do not sell and do not share your personal data with advertising networks, data brokers, or other third parties for purposes unrelated to the provision of our services.


6. Retention Periods

CategoryRetention
Enquiry data (name, contact, task description)3 years from last interaction (Russian statute of limitations)
Source files provided by client1 year after project completion, then destroyed
Active contract dataContract term + 5 years (tax and accounting obligations)
Technical logs, analytics2 years (Yandex Metrica retention policy)
Cookie dataPer Cookie Policy

Upon expiry of the retention period, data is destroyed or anonymized in accordance with internal procedures.


7. Your Rights as a Data Subject

7.1. Rights available under GDPR (EU/EEA residents)

You have the right to:

  1. Access your personal data (Art. 15);
  2. Rectification of inaccurate or incomplete data (Art. 16);
  3. Erasure ("right to be forgotten"; Art. 17);
  4. Restriction of processing (Art. 18);
  5. Data portability in a machine-readable format (Art. 20);
  6. Object to processing based on legitimate interest or for direct marketing (Art. 21);
  7. Not to be subject to automated decision-making producing legal effects (Art. 22);
  8. Withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal (Art. 7(3)).

7.2. Rights under 152-FZ and KVKK

Russian residents (152-FZ Art. 14, 21) and Turkish residents (KVKK Art. 11) have equivalent rights of access, rectification, erasure, restriction, and objection.

7.3. How to Exercise Your Rights

To exercise any of these rights, send a request to:

  • Email: hello@jemio.ru
  • Subject: "Personal data"
  • Content: full name, description of the right you wish to exercise, contact details for our response.

We will respond within 30 calendar days of receipt. In exceptional cases, the period may be extended by another 30 days with notice.

7.4. Right to Lodge a Complaint

  • EU/EEA residents: the supervisory authority in your country of habitual residence (GDPR Art. 77);
  • Russian residents: Roskomnadzor;
  • Turkish residents: KVKK Authority (kvkk.gov.tr).

8. Security Measures

We apply the following technical and organizational measures:

  • TLS/HTTPS encryption in transit;
  • Access control based on the principle of least privilege;
  • Strong passwords and multi-factor authentication for accounts with access to data;
  • Regular review and update of security measures.

We do not claim ISO/IEC 27001, SOC 2, or equivalent certification and do not guarantee absolute protection from unauthorized access.


9. Automated Decision-Making

We do not perform automated decision-making that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22, KVKK Art. 11(g)), and we do not carry out profiling. AI-based image generation is used solely for the creative production of visual content on your instruction — including through the external processors described in clause 5.1.1 — and does not produce legal consequences for you.


10. Children's Privacy

The service is intended exclusively for adults (18+) acting in a business capacity. We do not knowingly collect personal data of minors. If you believe we have collected data of a person under 18, please contact us at hello@jemio.ru and we will delete it promptly.


11. Changes to This Policy

We may amend this Policy from time to time. The new version enters into force upon publication at jemio.ru/legal/privacy.

Material changes (new processing purposes, new categories of recipients, changes to subject rights) will be notified by email to subjects with an active business relationship.

Continued use of the website after publication of a new version constitutes acceptance of the changes.


12. Contact

For any question regarding personal data processing:

Email: hello@jemio.ru (subject: "Personal data")

Telegram: https://t.me/ahamzin

Registered controller: Individual Entrepreneur Khamzin Artem Maratovich, address 420075, Kazan, Republic of Tatarstan, 3rd Klenovaya str., 100, Russian Federation

We aim to respond to all requests within 5 business days; maximum response time is 30 calendar days.