1. Controller
- Operator
- Individual Entrepreneur Dmitry Sergeevich Sokolov
- Tax ID (INN)
- 234401764767
- Sole proprietor registration
- 320237500150111
- Registered
- 11.06.2020
- Registered location
- Ilyinskaya stanitsa, Novopokrovsky District, Krasnodar Krai, Russian Federation
- Legal notices
- legal@reelee.pro
2. Data processed
- Identifiers and contacts: email, Telegram ID and username, name, country, selected city, language, and photo.
- Profile and public data: bio, website, topics, languages, prices, brands, platforms, handles, and verification status.
- Contractual data: offers, applications, deal terms and status, messages, attachments, disputes, reviews, and event history.
- Technical data: IP, user agent, sessions, timestamps, cookies, security logs, short links, click hashes, and automated-traffic indicators.
- Payment data: plan, amount, status, payment ID, card mask, and recurring-payment token. The bank processes full card details and CVC; Reelee does not receive them.
- Public metrics and evidence: views, reactions, publication date, channel ID, and anti-fraud results.
3. Purposes and legal bases
Data is used for registration and authentication; contract and subscription performance; profiles, discovery, deals, and messaging; resource and metric checks; fraud prevention; support and disputes; notifications; accounting and legal records; security; and service improvement. Bases include contract, consent where required, legitimate interests in security and improvement, and legal obligations.
Fields marked as required are necessary to supply the account or feature. Public fields are identified by the interface; do not publish information you do not want counterparties or visitors to see.
4. Operations, automation, and sources
The operator collects, records, organizes, stores, updates, retrieves, uses, shares with authorized recipients, restricts, pseudonymizes, and deletes data using automated processing. Sources include the user, counterparties, Telegram/OAuth, the bank, public supported-platform pages, and technical logs. Fraud scores are probabilistic and may be challenged through disputes or support; no solely automated score produces a final legal decision.
5. Recipients and services
- T-Bank: subscription and recurring-payment processing.
- Telegram: sign-in, Mini App, and user-selected notifications.
- Mail.ru and email infrastructure: service and authentication messages.
- YouTube/Google, VK, and Apify with relevant platforms: only for requested ownership and public-metric checks.
- GeoNames: source of reference city names and identifiers; the city selected by a user is stored by Reelee and is not sent to GeoNames.
- Hosting, database, and Redis providers: hosting and technical operation.
- Authorities and others: only under lawful demand, to protect rights, or on another valid basis.
The operator does not sell personal data. A counterparty sees only catalog and shared-deal information. Internal anti-fraud review notes are not disclosed to deal parties.
6. Hosting and international transfers
Personal data of Russian citizens is initially recorded in a database located in the Russian Federation. Providers and infrastructure in other countries may be used for specific technical functions; any such transfer requires a valid legal basis, contractual safeguards, and applicable notices. Current regional details are disclosed in the country supplements.
7. Retention
- OTP: up to 10 minutes; user sessions: up to 30 days; admin sessions: up to 12 hours.
- Account and profile data: while active; after deletion, identifiers and public fields are pseudonymized unless a legal dispute or retention duty requires otherwise.
- Deals, payments, consents, disputes, and audit records: for limitation, accounting, and mandatory periods, generally up to five years after the relationship ends.
- Messages and attachments: for the deal and dispute period, then deleted or pseudonymized on schedule; backups rotate within 30 days.
- Technical logs and anti-fraud signals: up to 12 months unless an incident requires longer retention.
8. Individual rights
Users may access processing information, correct data, download the available export, withdraw consent, restrict or object to processing, and request deletion where no mandatory retention basis applies. Settings, export, sessions, and deletion are available in the account; other requests go to legal@reelee.pro. Identity verification may be required. Responses follow applicable statutory deadlines.
9. Security and incidents
Controls include access separation, session hashing, OAuth-token encryption, private attachment storage, rate limiting, logs, and backups. No system is absolutely secure; the operator contains incidents, assesses impact, and notifies users and authorities where and when law requires.