Personal Data Processing Policy

Last updated: 2026-09-03

Document revision: 2026-09-03

This document is the operator's policy regarding the processing of personal data, published pursuant to Article 18.1(2) of Russian Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" (the "Law"). It defines the purposes, legal bases, scope and procedure for processing personal data, as well as the measures the operator takes to protect it.

This Policy applies to all personal data the operator receives from users of the wolkup.com (wolkup.ru) website and the Wolkup mobile application (together, the "Platform").

A plain-language description of what data each Platform feature collects and how it is used is provided in the Privacy Policy. The terms of using the Platform are set out in the Terms of Use. This Policy is published in English for reference; it is prepared under Russian law, and the Russian version prevails.

1. Personal data operator

Artem Zaborskikh, natural person, citizen of the Republic of Kazakhstan. Personal data is processed by the operator personally; the operator has no employees and has not assigned personal data processing to any other party, except as stated in Section 8.

Email address for requests from data subjects, including on personal data processing matters: [email protected]

The operator is entered in the register of operators processing personal data under registration number 78-26-216532 (order No. 272 of 27 August 2026). The notification of personal data processing was submitted to Roskomnadzor on 26 August 2026; the date processing began is 7 June 2025.

2. Definitions

The terms "personal data", "processing of personal data", "operator", "anonymisation", "blocking", "destruction of personal data", "automated processing" and "provision of personal data" are used with the meanings defined in Article 3 of the Law.

The operator processes personal data on the following legal bases:

  • Article 6(1)(5) of the Law — processing is necessary to perform a contract to which the data subject is a party: providing access to the Platform under the Terms of Use;
  • Article 6(1)(1) of the Law — the data subject's consent: sending promotional and news messages;
  • Articles 9 and 10 of the Law — the data subject's separate consent in written form: processing of special categories of personal data (information characterising the state of health), executed as a separate document — Consent to the Processing of Special Categories of Personal Data;
  • Article 6(1)(2) of the Law — processing is necessary to fulfil obligations imposed on the operator by the legislation of the Russian Federation.

Processing is limited to achieving specific, pre-defined and lawful purposes; processing incompatible with the purposes of collection is not permitted. Only personal data that serves the purposes of processing is processed.

4. Purposes of processing, categories of data subjects and scope of personal data

4.1. User registration and authentication

Categories of data subjects: Platform users.

Personal data: email address; name (display name); username; one-time sign-in confirmation codes; account identifier; date and time of account creation and of sign-ins; technical information about the device and application version; trusted-device token (where the user has chosen the "remember this device" option).

The operator neither sets nor stores user passwords: the primary sign-in method is a one-time code sent to the user's email address.

Sign in with Apple and Google sign-in are additionally available, as is linking these sign-in methods to an existing account. When they are used, personal data is received by the operator from Apple Inc. or Google LLC in the following scope: the user's identifier in the relevant service, name, and email address (where the data subject has permitted it to be shared). The data subject's password for those services is not transmitted to the operator. Where Apple's "Hide My Email" feature is used, a relay address in the privaterelay.appleid.com domain is transmitted instead of the email address; the operator identifies the data subject by the Apple identifier and does not replace a previously provided email address with such a relay address.

Apple and Google sign-in buttons are not displayed to users connecting from IP addresses identified as belonging to the Russian Federation; sign-in by one-time code sent to an email address is available to them. Linking these sign-in methods to an existing account is available without that restriction.

For accounts created before Telegram sign-in was discontinued, the information obtained through such authorisation is retained (name, user identifier in the external service, profile image link). No new authorisation by this method takes place; this information is not used and is deleted at the data subject's request.

4.2. Providing Platform functionality

Categories of data subjects: Platform users.

Personal data: workout information (activity type, date and time, duration, repetition count, distance, pace, energy expenditure, steps, cadence, summary heart-rate figures for the workout); geolocation data recorded during a workout (the route as a set of geographic coordinates, visited exploration map cells); information about achievements, workout streaks and levels; date of birth and sex; account settings; information about follows and mutual follows between users; reactions to activity feed events; workout data imported from services connected by the user (Apple Health, Strava), including information about the source device.

Special categories of personal data (height, body mass and its history, heart rate during workouts — average, maximum and the series of readings, received from the user's watch or together with an imported workout) are processed solely where the data subject has given the separate consent described in Section 3 of this Policy. The scope, purposes and withdrawal procedure for that consent are set out in Consent to the Processing of Special Categories of Personal Data.

Processing of device camera images during repetition-counted exercises takes place entirely on the data subject's device: frames are not stored and are not transmitted to the operator. The operator does not process biometric personal data.

Resting heart rate is not stored on the operator's servers and is not transmitted to the operator.

4.3. Sending service messages

Categories of data subjects: Platform users.

Personal data: email address; device push notification token; notification settings; information about the fact and result of message delivery.

4.4. Sending promotional and news messages

Categories of data subjects: Platform users who have given consent.

Personal data: email address; name; the consent setting for receiving such messages.

Consent is withdrawn in the application settings or via the unsubscribe link in the message itself, without signing in to the account.

4.5. Handling enquiries

Categories of data subjects: Platform users, website visitors, and other persons who submit an enquiry.

Personal data: email address; name; the content of the enquiry and correspondence; account identifier (if any).

4.6. Website operation and security

Categories of data subjects: website visitors.

Personal data: IP address; browser and device information; date and time of the request; requested page addresses; technical cookies (language, colour theme, authorisation flag).

5. List of actions with personal data and methods of processing

The operator performs the following actions: collection, recording, systematisation, accumulation, storage, clarification (updating, modification), extraction, use, anonymisation, blocking, deletion and destruction of personal data.

Processing is carried out by mixed means — both with and without the use of automation — with transmission of data over the Internet.

The operator does not disseminate personal data, that is, does not disclose it to an indefinite range of persons. The content of a user's profile is available only to other authorised Platform users and only to the extent determined by the profile privacy settings chosen by the user; profiles of new accounts are private by default.

The operator does not take decisions producing legal effects concerning the data subject, or otherwise affecting their rights and legitimate interests, solely on the basis of automated processing of personal data.

The operator does not knowingly collect personal data of persons below the age established by the Terms of Use.

6. Place of processing and cross-border transfer

Personal data is processed and stored, including its entry into databases, on a server located in the territory of the Russian Federation (Moscow), provided to the operator under a contract with a Russian hosting organisation. Encrypted database backups are stored in object storage located in the territory of the Russian Federation.

The operator does not carry out cross-border transfer of personal data. On sign-in via Sign in with Apple and Google (Section 4.1), personal data is received by the operator from those services and is not transferred to them: the exchange with those services is limited to verifying a token or authorisation code they issued.

Parties entrusted with the processing of personal data (Section 8.1) carry out that processing in the territory of the Russian Federation. Personal data is not transferred to the service providers listed in Section 8.2: they receive anonymised technical information that is not accompanied by the data subject's name, email address, account identifier or IP address, does not permit identification of the data subject and, under Article 3 of the Law, does not constitute personal data.

Delivery of push notifications to users' devices (Section 8.3) is carried out by means of the Apple and Google operating systems and is an unavoidable condition of operating the mobile application.

7. Retention periods and destruction procedure

Personal data is processed for as long as necessary to achieve the purposes of processing, namely:

  • data processed for the purposes of Sections 4.1–4.3 — for as long as the account exists;
  • data processed on the basis of consent (Section 4.4 and special categories of personal data) — until the purpose of processing is achieved or the relevant consent is withdrawn;
  • enquiry data (Section 4.5) — for one year from the end of the correspondence;
  • technical information about website operation (Section 4.6) — for as long as necessary to ensure the security of the Platform;
  • backups — no more than 30 days from the creation of the backup, after which the backup is deleted automatically.

A user deletes their account themselves in the application, in the profile settings section; the personal data processed in connection with the account is thereby destroyed irrecoverably. Destruction upon a data subject's request is carried out within 30 days of receipt of the request (Article 21(3) of the Law). Personal data may remain in backups until the backup retention period stated above expires and is not used after the primary record has been destroyed.

Where consent to the processing of special categories of personal data is withdrawn, processing of the relevant data ceases and the data itself is deleted in the manner set out in Consent to the Processing of Special Categories of Personal Data.

8. Service providers

8.1. Parties entrusted with the processing of personal data

Processing is entrusted in accordance with Article 6(3) of the Law under contracts that require confidentiality of personal data and compliance with Article 19 of the Law. All such parties carry out processing in the territory of the Russian Federation:

  • a Russian hosting organisation — provision of server capacity and communication services, hosting of the database in the territory of the Russian Federation;
  • a Russian email service provider (REG.RU) — technical delivery of email messages to addresses provided by users.

8.2. Service providers to whom personal data is not transferred

These parties do not process personal data on the operator's behalf. Only information that does not permit identification of the data subject, and which under Article 3 of the Law does not constitute personal data, is transmitted to them:

  • PostHog (processing in the European Union region) — product analytics for the mobile application; anonymised technical events are transmitted, without account identifiers and without IP addresses;
  • OpenAI — generation of the text of analytical reports and training plans; anonymised numeric aggregate workout figures and coarse categories are transmitted, without name, email address or account identifier.

8.3. Push notification delivery and sign-in verification

  • Apple Inc., Google LLC — technical delivery of push notifications to users' devices by means of the operating systems, and confirmation of the user's identity on sign-in via Sign in with Apple and Google (Section 4.1).

The transfer is limited to the device token and the notification text and is an unavoidable condition of operating a mobile application on those platforms. Push notifications can be turned off in the application settings or in the operating system.

The operator does not transfer personal data to third parties for their own purposes, including for marketing purposes. Personal data is not sold.

9. Measures to ensure the security of personal data

Pursuant to Articles 18.1 and 19 of the Law, the operator has implemented the following measures:

  • issuing this Policy and providing unrestricted access to it by publishing it on the website;
  • identifying threats to the security of personal data during processing and assessing the harm that may be caused to data subjects;
  • establishing a procedure for internal control of the compliance of processing with the requirements of the Law, and carrying out such control at least once a year;
  • defining the list of personal data processed and the list of actions performed with it, and limiting the data processed to the necessary minimum;
  • familiarising persons who process personal data with the requirements of the Law and this Policy;
  • restricting and recording access to personal data: only the operator has access to the server and the database, using cryptographic key authentication;
  • encryption of traffic between users' devices and the server (TLS);
  • not storing user passwords: authentication is performed with a one-time code sent to the user's email address;
  • encryption of database backups and their automatic deletion once the retention period expires;
  • logging actions with personal data in a way that allows unauthorised access to be detected;
  • ensuring the ability to restore personal data modified or destroyed as a result of unauthorised access.

Security level three has been established for the operator's information system in accordance with Decree of the Government of the Russian Federation No. 1119 of 1 November 2012. The operator does not use cryptographic information protection tools that are subject to conformity assessment in the established manner.

10. Rights of the data subject

The data subject has the right to:

  • obtain information about the processing of their personal data to the extent provided for by Article 14(7) of the Law, and to access that data;
  • require the clarification, blocking or destruction of their personal data where it is incomplete, out of date, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing;
  • withdraw consent to the processing of personal data;
  • object to the sending of promotional and news messages and require such processing to cease;
  • appeal against the operator's acts or omissions to Roskomnadzor or in court.

Requests are sent to [email protected]. Information about the processing of personal data is provided to the data subject or their representative upon a request containing the information provided for by Article 14(3) of the Law.

The operator responds to a request within 10 working days of its receipt; this period may be extended by no more than 5 working days, with a reasoned notice sent to the data subject (Article 20(1) and (2) of the Law). Where unlawful processing is identified, the operator ceases the unlawful processing within 3 working days of identification. Personal data is clarified within 7 working days of the data subject providing information confirming its inaccuracy (Article 21(1) of the Law).

11. Updates to this Policy

The operator may amend this Policy. The current revision, with its update date, is permanently available at wolkup.com/legal/pd-policy. Where changes materially affect the rights of data subjects, the operator notifies users in the application or by email.

Wolkup