Personal data

Personal data processing

English translation. View the Russian original.

The precise scope of processing depends on the feature, document and user consent.

Updated: 11 August 2026Controller: SPR-CONSULTING LLCContact: info@bioshealth.su
ContentsControllerScopeDataAnalyticsPurposesLegal basisRecipientsRetentionRightsSafeguardsEnquiries

1. Controller

The personal data controller is SPR-CONSULTING LLC, Russian state registration number (OGRN) 1267700010841, taxpayer ID / tax registration code (INN / KPP) 7751382557 / 775101001, registered address: 7 Andrey Tarkovsky Boulevard, Apt. 135, Vnukovo Municipal District, Moscow, Russia.

2. Scope

This page applies to the public BIOS website, contact forms and service features that reference it. Processing health information, creating a patient profile, electronic interaction and research participation require separate documents and legal bases.

Submitting a website enquiry does not constitute consent to medical data processing. Do not include diagnoses or attach medical documents in general-purpose forms.

3. Data that may be processed

When visiting the website

Technical information necessary to operate and protect the website: IP address, browser and device type, request time, referral pages, cookies and security events, to the extent collected by the tools actually enabled.

When making an enquiry

Name, work email, phone number, organisation, role, selected enquiry type and message text.

When subscribing to BIOS Media

Email address, consent version and source, subscription status, campaigns and technical statuses for acceptance, delivery, opening, clicks, non-delivery, complaints and unsubscribing. BIOS does not store IP addresses, geolocation, user agents, device information or the specific destination URL clicked in an email.

When using an account

Identification and contact details, profile information, internal identifiers, account statuses, consent documents and logs of legally significant actions.

Health information

Complaints, symptoms, medical documents, test results, diagnoses and treatment are a special category of data. They are processed only under a separate legal basis and separate C03 medical consent, or another basis provided by law.

4. Analytics and cookies

The public website may use Yandex Metrica, counter No. 111496809, only after the user chooses to allow analytics. The Metrica script is not loaded before that choice. The preference is stored in the browser and can be changed through Analytics settings in the website footer.

Metrica receives de-identified technical visit information, including the page path without query string or fragment, browser and device type, visit time and referral source within the scope of the service. Session replay, click maps, form analytics and ecommerce are disabled. Form contents, contact details and medical data are deliberately excluded from Metrica.

If a user separately subscribes to BIOS Media, technical email elements and link redirects enable internal tracking of delivery, approximate opens and clicks. This analytics is independent of the website Metrica cookie preference and is used to assess the quality of a particular mailing. Extended recipient information at the email provider is disabled; BIOS receives only minimal campaign statuses without IP addresses, geolocation, user agents or device data.

Metrica may use analytics cookies and browser local storage to distinguish visits. See the Yandex Metrica cookie documentation.

5. Purposes

  • responding to enquiries and arranging communication;
  • sending requested BIOS Media updates and evaluating delivery and engagement;
  • registering, authenticating, maintaining and protecting accounts;
  • providing requested BIOS features;
  • managing consent, enquiries and data subject rights;
  • de-identified assessment of public website traffic after separate permission;
  • security, auditing and abuse prevention;
  • fulfilling contractual and statutory obligations.

Research use and model training on medical data are not automatically included in general purposes and require separate governance and a lawful basis.

6. Legal bases

Depending on the use case, processing is based on the data subject's consent, performance of a contract or steps requested by the user, the controller's statutory obligations or another basis provided by law. Consents are given separately and tied to the exact document version.

7. Recipients and processing on behalf of the controller

The controller may engage providers of infrastructure, storage and backups, authentication, service messaging, web analytics, information security, monitoring and support. They receive only the necessary data and must comply with confidentiality and purpose limitations.

Sharing data with a doctor, clinic, laboratory, research partner, insurer, employer or another independent recipient does not take place on the basis of a general website form and requires a separate legal basis.

8. Data localisation, transfers and retention periods

When collecting data from citizens of the Russian Federation, initial recording and storage use databases located in the Russian Federation, except where the law provides otherwise. Cross-border transfers must not be enabled automatically; the necessary assessments and procedures are completed beforehand.

Retention periods depend on the purpose, contract, consent and mandatory requirements. Once the purpose is fulfilled, data is deleted, destroyed, de-identified or restricted unless another lawful basis applies. Backups and audit records may be deleted through a separate controlled cycle.

9. Data subject rights

Users may request information about processing, access to and correction of data, withdraw consent, request restriction, cessation or deletion where provided by law, and challenge the controller's actions.

Withdrawal of consent does not affect the lawfulness of processing before withdrawal and does not always entail immediate destruction of mandatory records.

10. Data safeguards

BIOS applies legal, organisational and technical measures proportionate to risk: access controls, separation of identification and medical data systems, logging, version management and fail-safe behaviour. Details are provided on the Data Security page.

11. Enquiries

To exercise your rights, send a request to info@bioshealth.su or the controller's postal address. Include your full name, contact method, the nature of your request and information establishing your relationship to the data. The controller may ask you to verify your identity to avoid disclosing data to another person.

12. Changes

A new version is published when processing changes. If the subject or scope of previously given consent changes, new uses are not automatically covered and may require separate confirmation.