Personal Data Processing Policy
Effective date: 27 July 2026
This Personal Data Processing Policy (the "Policy") describes how personal data of natural persons is collected, used, disclosed, retained, and protected when you interact with the website jemio.ru or communicate with us by email or messenger.
The Policy is drafted in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), Russian Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" ("152-FZ"), and Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), as applicable to the data subject's jurisdiction.
Related documents: Consent to Personal Data Processing, Terms of Use, Cookie Policy, Public Offer Agreement.
1. Data Controller
Legal form: Individual Entrepreneur Khamzin Artem Maratovich (IE Khamzin A.M.)
TIN (INN): 166019255124
Registration number (OGRNIP): 325169000153195
Registered address: 420075, Kazan, Republic of Tatarstan, 3rd Klenovaya str., 100, Russian Federation
Contact for personal data requests: hello@jemio.ru (subject: "Personal data")
General contact: hello@jemio.ru · Studio: studio@jemio.ru · Telegram: https://t.me/ahamzin
The controller processes personal data independently. Processing by third parties acting as processors on the controller's behalf takes place only in the cases and to the extent expressly set out in Section 5 of this Policy, under terms ensuring confidentiality and compliance with Art. 28 GDPR and Art. 6(3) of 152-FZ.
2. Scope and Applicable Law
This Policy applies to:
- Visitors of jemio.ru located anywhere in the world;
- Individuals whose personal data is submitted through website forms, email, or messengers.
The service is intended exclusively for individuals of legal age (18+) acting in a business capacity (B2B: employees, authorized representatives of legal entities, sole proprietors, self-employed professionals).
Applicable regimes:
- EU / EEA residents: GDPR
- Russian residents: 152-FZ
- Turkish residents: KVKK No. 6698
- Other jurisdictions: applicable local law without prejudice to the above
3. Categories of Personal Data
Depending on the interaction, we may process:
- Identification data: first name, last name, patronymic (if applicable), organization name, job title;
- Contact data: email, phone number, Telegram username;
- Enquiry data: task description, briefing, shoot parameters, preferences;
- Source materials: product images or files provided by the subject for service delivery (may contain trademarks, logos, or images of natural persons as part of the product);
- Technical and analytical data: IP address, browser type, operating system, referrer URL, UTM parameters, cookie data (see Cookie Policy);
- Payment data: for direct bank transfers — organizational bank details; for card payments — card data is not stored by the controller and is handled exclusively by the payment acquirer.
We do not process special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, criminal convictions).
4. Purposes and Legal Basis of Processing
| Purpose | Legal basis (GDPR) | Legal basis (152-FZ / KVKK) |
|---|---|---|
| Processing enquiries, preparing commercial proposals | Art. 6(1)(b) — pre-contractual measures | 152-FZ Art. 6(1)(5) / KVKK Art. 5(2)(c) |
| Concluding and performing the service agreement | Art. 6(1)(b) — contract | 152-FZ Art. 6(1)(5) / KVKK Art. 5(2)(c) |
| Business correspondence, responses to enquiries | Art. 6(1)(f) — legitimate interest | 152-FZ Art. 6(1)(1) — consent / KVKK Art. 5(1) |
| Website operation, analytics | Art. 6(1)(a) — consent (cookie banner) | 152-FZ Art. 6(1)(1) / KVKK Art. 5(1) |
| Service quality improvement, internal analysis | Art. 6(1)(f) — legitimate interest | 152-FZ Art. 6(1)(1) / KVKK Art. 5(2)(f) |
| Compliance with legal obligations | Art. 6(1)(c) — legal obligation | 152-FZ Art. 6(1)(2) / KVKK Art. 5(2)(a) |
Processing is limited to specified, explicit, and legitimate purposes. Further processing incompatible with these purposes is not carried out.
Where consent is relied upon as the legal basis, it is given on the terms set out in the Consent to Personal Data Processing and may be withdrawn at any time.
5. Recipients and Cross-Border Data Transfers
5.1. Recipients
| Recipient | Purpose | Legal basis |
|---|---|---|
| Yandex LLC (Yandex Forms) | Receipt and storage of enquiries submitted through the form on the site (the form is embedded in a Yandex Forms frame on every language version) | Consent / contract |
| Telegram Messenger (bot @jemio_studio_bot) | Delivery of enquiry notifications | Consent / contract |
| Yandex LLC (Yandex Metrica) | Website analytics | Consent (cookie banner) |
| Payment acquirer | Payment processing | Contract |
| External automated image generation and processing services (processors) | Provision of services under the Public Offer Agreement: generation and post-processing of product images | Contract (GDPR Art. 28; 152-FZ Art. 6(3)) |
5.1.1. External image processing services
To deliver the services, the controller uses external software services for automated image generation and processing, acting as processors (sub-processors) on the controller's instructions.
Such services receive product images only, as submitted by the client for performance of the task. Contact and identification data (name, phone, email, Telegram), the content of business correspondence, and payment data are not transferred to them.
Where submitted product images contain images of natural persons (for example, a person appearing in the original product photography), such images are processed only to the extent necessary to perform the task and are deleted within the periods set out in Section 6 of this Policy.
Processors are engaged on terms ensuring the confidentiality and security of personal data, and the controller remains responsible for their actions towards the data subject. An up-to-date named list of processors is provided on written request to hello@jemio.ru (subject: "Personal data"); clients and data subjects in the EU/EEA may request it under Art. 28(2) GDPR. A Data Processing Agreement under Art. 28 GDPR is available on request.
Processors may be located outside the Russian Federation and outside the EEA — see clause 5.2.
5.2. Cross-Border Data Transfers
Important disclosure: when you submit a form on our website, the data is delivered to Telegram Messenger, whose server infrastructure is located outside the Russian Federation and outside the European Economic Area (including the United Arab Emirates and EU member states).
In addition, the external automated image generation and processing services referred to in clause 5.1.1, to which product images are transferred, may be located outside the Russian Federation and outside the EEA.
Legal basis for the transfer:
- EU/EEA residents: GDPR Chapter V (Articles 44–49). We rely on Telegram's data transfer mechanisms and, where required, on your explicit consent given by submitting the form (Art. 49(1)(a));
- Russian residents: 152-FZ Art. 12 — the operator has verified that either the receiving country provides adequate protection of personal data, or the transfer is carried out with the subject's consent on terms ensuring data confidentiality;
- Turkish residents: KVKK Art. 9 — cross-border transfers subject to explicit consent or other lawful basis.
You may refuse to use the website form and instead contact us directly at studio@jemio.ru — in that case, no automated cross-border transfer occurs.
5.3. No Sale of Personal Data
We do not sell and do not share your personal data with advertising networks, data brokers, or other third parties for purposes unrelated to the provision of our services.
6. Retention Periods
| Category | Retention |
|---|---|
| Enquiry data (name, contact, task description) | 3 years from last interaction (Russian statute of limitations) |
| Source files provided by client | 1 year after project completion, then destroyed |
| Active contract data | Contract term + 5 years (tax and accounting obligations) |
| Technical logs, analytics | 2 years (Yandex Metrica retention policy) |
| Cookie data | Per Cookie Policy |
Upon expiry of the retention period, data is destroyed or anonymized in accordance with internal procedures.
7. Your Rights as a Data Subject
7.1. Rights available under GDPR (EU/EEA residents)
You have the right to:
- Access your personal data (Art. 15);
- Rectification of inaccurate or incomplete data (Art. 16);
- Erasure ("right to be forgotten"; Art. 17);
- Restriction of processing (Art. 18);
- Data portability in a machine-readable format (Art. 20);
- Object to processing based on legitimate interest or for direct marketing (Art. 21);
- Not to be subject to automated decision-making producing legal effects (Art. 22);
- Withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal (Art. 7(3)).
7.2. Rights under 152-FZ and KVKK
Russian residents (152-FZ Art. 14, 21) and Turkish residents (KVKK Art. 11) have equivalent rights of access, rectification, erasure, restriction, and objection.
7.3. How to Exercise Your Rights
To exercise any of these rights, send a request to:
- Email: hello@jemio.ru
- Subject: "Personal data"
- Content: full name, description of the right you wish to exercise, contact details for our response.
We will respond within 30 calendar days of receipt. In exceptional cases, the period may be extended by another 30 days with notice.
7.4. Right to Lodge a Complaint
- EU/EEA residents: the supervisory authority in your country of habitual residence (GDPR Art. 77);
- Russian residents: Roskomnadzor;
- Turkish residents: KVKK Authority (kvkk.gov.tr).
8. Security Measures
We apply the following technical and organizational measures:
- TLS/HTTPS encryption in transit;
- Access control based on the principle of least privilege;
- Strong passwords and multi-factor authentication for accounts with access to data;
- Regular review and update of security measures.
We do not claim ISO/IEC 27001, SOC 2, or equivalent certification and do not guarantee absolute protection from unauthorized access.
9. Automated Decision-Making
We do not perform automated decision-making that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22, KVKK Art. 11(g)), and we do not carry out profiling. AI-based image generation is used solely for the creative production of visual content on your instruction — including through the external processors described in clause 5.1.1 — and does not produce legal consequences for you.
10. Children's Privacy
The service is intended exclusively for adults (18+) acting in a business capacity. We do not knowingly collect personal data of minors. If you believe we have collected data of a person under 18, please contact us at hello@jemio.ru and we will delete it promptly.
11. Changes to This Policy
We may amend this Policy from time to time. The new version enters into force upon publication at jemio.ru/legal/privacy.
Material changes (new processing purposes, new categories of recipients, changes to subject rights) will be notified by email to subjects with an active business relationship.
Continued use of the website after publication of a new version constitutes acceptance of the changes.
12. Contact
For any question regarding personal data processing:
Email: hello@jemio.ru (subject: "Personal data")
Telegram: https://t.me/ahamzin
Registered controller: Individual Entrepreneur Khamzin Artem Maratovich, address 420075, Kazan, Republic of Tatarstan, 3rd Klenovaya str., 100, Russian Federation
We aim to respond to all requests within 5 business days; maximum response time is 30 calendar days.