Personal Data Processing Policy for Rich Witch Users
Revised 25 September 2026
This Policy sets out which personal data is processed when visiting and using the platform at https://richwitch.com, for what purposes and on what grounds, to whom it may be entrusted, how long it is retained, and how the user can exercise their rights. The Policy must be permanently available at https://richwitch.com/privacy and next to every form that collects personal data.
1 Operator and scope
1.1. The personal data operator: Sole Proprietor Maksim Vladimirovich Stolyarov, OGRNIP 314504803100020, INN 504808687272, address: 142300, Moscow Region, Chekhov, Mira St., 10, apt. 98, email: maxim@namnecash.ru. Requests from data subjects are also accepted at support@richwitch.com.
1.2. The Policy applies to site visitors, registered users, buyers, recipients of personal services, participants in chats, online and in-person meetings, persons who have sent a request, and subscribers to the promotional mailing. The Platform is intended only for persons aged 18 and over and does not knowingly collect data from minors.
1.3. The Policy is developed in accordance with Federal Law No. 152-FZ of 27 July 2006 "On Personal Data", Federal Law No. 38-FZ of 13 March 2006 "On Advertising", Federal Law No. 149-FZ of 27 July 2006 "On Information, Information Technologies and the Protection of Information", and other applicable acts.
2 Principles and legal grounds for processing
2.1. The Operator processes only the data necessary for predetermined lawful purposes, does not combine incompatible databases, verifies that data is up to date, and does not keep it longer than the purposes of processing and the law require.
2.2. The legal grounds are: concluding and performing a contract at the User's initiative; the Operator's performance of duties under the law; the separate consent of the data subject, where required; and the protection of the rights and legitimate interests of the Operator or third parties, subject to respecting the data subject's rights.
2.3. Consent to the processing of personal data is executed separately from the Offer, the Terms, age confirmation, and other documents. Consent to promotional mailings is likewise executed separately and is never pre-selected.
3 Purposes, data, grounds and retention periods
Site operation and session protection
Data and subjects: IP address, date and time, user agent, technical cookies, session identifier, and information about visitors' and users' errors and requests.
Ground and period: providing the requested functionality, performing the contract, security. Technical cookies — until the end of the session or the set technical period; security logs — up to 1 year, unless an incident requires longer retention.
Creating and protecting the account
Data and subjects: name or nickname, email, password hash, ID, role, registration and login dates, session identifiers.
Ground and period: the contract and pre-contractual actions; consent where necessary. Until the account is deleted, then up to 30 days, except for data that must be kept by law or to protect rights.
Placing and fulfilling the Order
Data and subjects: user and Order ID, Event, Tier, add-on services, price, discount, currency, statuses, dates, access period.
Ground and period: concluding and performing the contract, record-keeping requirements. For the term of the contract and thereafter within mandatory record-keeping and the period of any possible claims.
Personal services
Data and subjects: email, phone or Telegram, recipient's name, wishes, duration, fulfilment status, internal notes.
Ground and period: performance of the contract; a third party's data is provided by the User where a lawful basis exists. Until fulfilled and any possible claims are resolved, then deletion or anonymisation.
Payments, refunds and receipts
Data and subjects: transaction identifier, Order number, amount, status, dates, receipt composition, encrypted operation key; the Platform does not store the full card number or CVV.
Ground and period: performance of the contract and statutory requirements. For the periods of mandatory tax, cash-register and accounting record-keeping.
Support, account recovery and complaints
Data and subjects: email, request text and attachments, recovery token, technical information, Order number, correspondence.
Ground and period: performance of the contract, consent where necessary, protection of rights. Token — until used or expired; a request — until resolved and within the period of any possible claims.
Access to video meetings and security
Data and subjects: Order and media ID, JWT or another token, issue time, IP and network headers, device and browser information, authorisation and restriction results.
Ground and period: performance of the contract, preventing abuse, and protecting rights. Tokens — short-term; logs — up to 1 year or until the incident review and related claims are concluded.
Recording of intent
Data and subjects: document revision and checkbox text, date and time, account or Order ID, email, IP, user agent or another technical identifier.
Ground and period: the duty to prove consent, conclusion of the contract, and protection of rights. For as long as the corresponding basis applies and no less than the period of any possible claims after it ends.
Promotional and informational messages
Data and subjects: name or nickname, email, user ID, interests or a segment based on the services chosen, the date and source of consent, and delivery, open, click, and opt-out statuses.
Ground and period: only separate prior consent to advertising and separate consent to processing data for this purpose. Until consent is withdrawn; the mailing stops immediately, and data needed only for marketing is deleted no later than 30 days absent another basis.
In-person meeting with INSTASAMKA in Dubai
Data and subjects: the name and contact of the buyer of the service, the selected meeting format, the slot and place, confirmation status; where booking or admission genuinely requires it — the minimal foreign-passport and travel details needed by the specific recipient. A copy of the document — only where reasonably necessary.
Ground and period: performance of the contract and the law; separate consent where necessary. Booking data — until fulfilled and any possible claims are settled, then deletion or anonymisation unless the law sets another period.
Fraud detection and prevention
Data and subjects: account and Order ID, login time and result, IP address, browser and device information, session identifiers, access logs, the amount and status of a payment or refund, a notice of a disputed transaction, and correspondence relating to the incident. Without the full card number and CVV.
Ground and period: performance of the contract, security, and protection of legitimate interests, subject to respecting the data subject's rights. Logs — up to 1 year; materials of a specific incident — until the review and related claims are concluded or for the statutory mandatory retention period.
3.1. For ordinary registration and payment, the Operator does not request a passport, residential address, date of birth, SNILS, biometric data, special categories of personal data, information of an intimate nature, the full bank card number, or CVV. When arranging and performing a purchased in-person meeting with INSTASAMKA in Dubai, separate details may be needed for admission or booking, but only once the necessary list has been determined and disclosed to the data subject. Travel details are processed only where necessary for the service agreed in the Order. A passport copy is not collected by default. Such information should not be entered into the Platform's free-text fields.
3.2. If the User provides another person's minimal data for a video greeting or a meeting, the User is responsible for having a lawful basis to disclose it. The Operator uses it only to perform the corresponding service.
4 Promotional mailings
4.1. The Operator may send emails about new Events, Tiers, discounts, special offers, platform features, surveys, and Rich Witch materials only after obtaining the recipient's separate voluntary consent. Declining does not affect registration, payment, access, or other services.
4.2. Consent is recorded separately from the Offer, the Terms, consent to the processing of personal data for performing the contract, and age confirmation. The Operator retains the text and revision of the consent, the date, time, email, account or Order ID, the form's source, and a technical identifier of the action. The checkbox is never pre-selected.
4.3. Every promotional email contains a clear link or another available way to unsubscribe. An opt-out is also accepted at support@richwitch.com. Distributing advertising to the requester stops immediately. A separate opt-out from advertising does not block service messages necessary to fulfil the Order, for security, refunds, or the rescheduling or cancellation of the Event.
4.4. This Policy is not itself consent to advertising. The terms of the promotional mailing are set out in the separate document "Consent to Receive Promotional and Informational Messages and to the Processing of Personal Data for Sending Them".
5 Cookies and similar technologies
5.1. The Platform uses technical cookies and local storage necessary for authorisation, keeping the session, security, payment, and protected playback. Disabling them may make the corresponding functionality unavailable.
5.2. Analytical, advertising, and other non-essential cookies, if introduced, are used only after the User separately chooses to allow them in the cookie-management interface. The accept and decline buttons must be equally accessible; the choice can be changed at any time.
5.3. The Operator does not use cookies to determine special categories of personal data or information of an intimate nature. The current list of cookies, their providers, purpose, and each file's retention period are published in the cookie-management interface.
6 Recipients and processors
6.1. The Operator may entrust processing, only to the extent necessary, to persons bound by a contract and by confidentiality and security duties. The Operator does not sell personal data and does not hand its subscriber base to partners for their own promotional use without a separate lawful basis.
Timeweb Cloud / the actual legal entity under the Operator's agreement: TIMEWEB.CLOUD LLC
Hosting of the application and database: account, Orders, logs, requests and other data stored on the Platform.
Timeweb Mail / the actual legal entity: TIMEWEB JSC
Delivery of recovery and support emails: email, sender address, subject, body and technical headers of the message.
Robokassa / the actual legal entity under the agreement: ROBOKASSA LLC
Payment acceptance, fiscalisation, and refunds: Order number and amount, receipt composition, statuses; card details are entered by the User on the payment service's side.
Kinescope / the actual legal entity under the agreement: Kinescope B.V.
Protected playback: media and Order ID, access JWT, network and browser information, authorisation result.
Online meeting service: Zoom / the actual legal entity: Zoom Communications, Inc.
Organising the chosen meeting: name/nickname, contact, link, time and connection technical details.
Unisender / the actual legal entity: Unisender Smart LLC
Email mailings and notifications: email address, name/nickname, and subscription and email-interaction information necessary to send and account for the mailings.
Personal-service performers and authorised administrators
Contact, permitted wishes, duration, and fulfilment status, only to the extent the service requires.
The meeting's organiser, restaurant, yacht, carrier, hotel (specific recipients are identified before data is collected and transferred)
Only the name, contact, and details necessary for booking/admission once attendance is confirmed. A cross-border transfer only after the requirements of Section 7 are met and the recipient is disclosed.
6.2. Before publishing the Policy, the Operator fills in the exact names, addresses, and roles of the actual counterparties under current agreements. A material change to the set of recipients is reflected in the Policy; new consent is obtained before any transfer where required by law or by the terms of a previously given consent.
6.3. Disclosure to government authorities and other persons without consent is permitted only in the cases and manner established by law.
7 Processing procedure, localisation and cross-border transfer
7.1. Processing is carried out by automated and non-automated means and includes collection, recording, systematisation, accumulation, storage, clarification, retrieval, use, transfer (by way of provision or access), anonymisation, blocking, deletion, and destruction.
7.2. When collecting the personal data of citizens of the Russian Federation via the Internet, recording, systematisation, accumulation, storage, clarification, and retrieval are carried out using databases located within the Russian Federation, except in cases provided by law.
7.3. A cross-border transfer — including to an in-person meeting's organiser, a hotel, a carrier, or another recipient in the UAE — is not carried out until the Operator meets the legal requirements, including assessing the recipient and sending the required notification, and until the country, recipient, purpose, and composition of the data are disclosed. A User following an external link may constitute the User's own independent interaction with that service under its terms.
8 Data protection and incident response
8.1. The Operator takes legal, organisational, and technical measures with regard to the nature of the data and the risks involved: it appoints a responsible person, segregates access, applies identification and authentication, backups, logging, software updates, protected channels, vulnerability management, contractor oversight, and training for authorised staff.
8.2. In the event of data loss, account compromise, or suspected unauthorised access, the User reports it to support@richwitch.com and does not share the password, CVV, SMS codes, or the full card number.
8.3. The Operator documents incidents, takes steps to mitigate harm, and fulfils its duties to notify the authorised body and conduct an internal investigation within the periods set by law.
9 Fraud detection and prevention
9.1. The Operator processes the data necessary to protect accounts, payments, and paid access; to detect the unlawful use of another person's payment instruments, chargebacks on disputed transactions, the transfer of access to third parties, automated registrations, and other actions showing signs of fraud. Such processing is carried out to perform the contract, ensure security, and protect the rights and legitimate interests of the Operator and Users, subject to respecting their rights; separate consent is used only where the law requires it.
9.2. Within this purpose, the Operator analyses account and Order information, the time and result of authorisation, the IP address, browser and device information, session identifiers, the access log, the identifier, amount, and status of a payment or refund, the payment service's notices of a disputed transaction, and related requests and correspondence. The Operator does not collect the full card number, CVV, or a passport copy for this purpose and does not use special categories of personal data. Data from other sources is used only where a lawful basis and a verified need exist.
9.3. On detecting signs of abuse, the Operator may carry out a review, request an explanation via the contact the User provided, and temporarily restrict the suspicious transaction or access to the extent necessary to prevent harm. Technical signs alone do not establish the User's fault. A material restriction of a paid service is reviewed by an authorised staff member; the User may contact support@richwitch.com, provide an explanation, and request that the decision be reconsidered. Mistaken restrictions are corrected, and the consumer's rights to paid services and refunds are preserved.
9.4. Only authorised persons have access to review materials. Necessary information may be disclosed to the payment service, the bank, law-enforcement authorities, or a court to examine a specific incident, dispute a payment, or fulfil a lawful request, to the extent and in the manner provided by law. Data is not disclosed to third parties for their own profiling or promotional purposes under this section.
9.5. Security logs are kept for up to 1 year, as stated in Section 3. Materials for a specific incident are kept until the review and any related claims and disputes are resolved, or for the statutory period of mandatory retention, and are then deleted or anonymised once the basis for keeping them ends. The Operator restricts access to such materials and reviews whether continued retention is still necessary.
10 The data subject's rights and requests
10.1. The data subject may obtain information about the processing, demand clarification, blocking, cessation of processing, or destruction of data, withdraw consent, opt out of advertising, appeal the Operator's actions, and exercise other rights provided by law.
10.2. A request is sent to support@richwitch.com or to the Operator's address and must contain information that reasonably confirms the requester's identity and allows the corresponding data to be found, such as the account email and the Order number. The Operator may not demand excessive passport data if identification is possible by a less burdensome means.
10.3. The Operator responds to a request for information within 10 business days, with a possible reasoned extension of no more than 5 business days; corrects data confirmed to be inaccurate within 7 business days; and stops processing on request within 10 business days, with a possible reasoned extension of no more than 5 business days, except where processing may lawfully continue.
10.4. Once the purpose is achieved or consent is withdrawn, data is deleted or destroyed no later than 30 days thereafter, absent another lawful basis. If immediate destruction is not possible, the data is blocked and destroyed no later than 6 months thereafter. Withdrawal does not affect the lawfulness of processing carried out before it was received.
11 Changes to the Policy and contacts
11.1. A new revision is published at https://richwitch.com/privacy with its date shown. If a change requires new consent or expands the purpose, the data, or the recipients beyond what was previously agreed, the Operator obtains new consent before starting such processing.
11.2. Operator's contacts: Sole Proprietor Maksim Vladimirovich Stolyarov; address: 142300, Moscow Region, Chekhov, Mira St., 10, apt. 98; email: maxim@namnecash.ru; requests about personal data and opting out of advertising: support@richwitch.com.
