Neogate Privacy Policy
Version of 25 September 2026
Reference translation. The Russian text is the binding version; if the two differ, the Russian one prevails.
This policy describes what personal data Arseniy Pavlovich Devov (the Contractor) processes when providing Neogate web resource protection services, why, and how long it is kept. The policy is adopted under Federal Law No. 152-FZ "On Personal Data" of the Russian Federation. Terms have the meanings given in the public offer.
#1. Customer data
1.1. The Contractor processes the following data of Customers and the members of their projects:
- email address;
- password, stored only as an irreversible hash;
- Telegram chat ID, if the Customer has turned on notifications;
- domain names of Resources and addresses of the Customer's Servers;
- invoice and payment details: plan, amount, date, status.
1.2. Purposes of processing: concluding and performing the agreement, access to the Dashboard, notifications about Attacks and payments, handling requests.
1.3. Legal basis: performance of a contract to which the Customer is a party (clause 5, part 1, article 6 of Law No. 152-FZ).
1.4. The Contractor does not receive or store bank card data or other payment details: payments are processed by the payment service.
#2. Data of visitors to Resources
2.1. When the traffic of a Resource passes through the Service, the Contractor, on the Customer's instruction, processes information about the requests of the Resource's visitors:
- IP address;
- request time, domain name, method and address of the request, response code, response size;
- the browser's User-Agent string;
- the technical fingerprint of the TLS connection.
2.2. This data is used only to detect and repel Attacks and for statistics and reports for the Customer. The Contractor does not use it for advertising, does not combine it with other data to identify a visitor, and does not pass it to third parties, except where the law requires it.
2.3. Retention periods:
| Data | Period |
|---|---|
| request log | 30 days |
| network flow records | 7 days |
| traffic samples during an Attack | 30 days |
| Attack records | 90 days after the Attack ends |
| Attack reports in the Dashboard | for the term of the agreement |
After the period ends the data is deleted automatically.
2.4. The operator of the personal data of the visitors to a Resource is the Customer. The Customer informs the Resource's visitors about the processing of their data.
#3. Cookies
3.1. The Dashboard uses one cookie, which holds the login session. It is valid for 7 days.
3.2. On Resources during an Attack the Service may set technical cookies on a visitor that confirm the browser check was passed. They are valid for no more than 1 hour, contain no personal data and are not used for tracking.
#4. Data transfers
4.1. The Contractor passes on data only as far as needed to provide the Service:
- to the payment service: the amount and invoice number, to take the payment;
- to Telegram: the text of notifications, to the chat the Customer has named;
- to the certificate authority Let's Encrypt: the domain name of the Resource, to issue the TLS certificate. Information about issued certificates is published in public certificate logs.
4.2. Data is stored on servers located in Germany.
#5. Data protection
5.1. Only persons who need it to provide the Service have access to data. Passwords are stored as a hash, connections to the Dashboard are encrypted, access to servers is restricted.
5.2. In the Dashboard the Customer sees only the data of their own Resources and of the projects they have been given access to.
#6. Rights of the data subject
6.1. A data subject may obtain information about the processing of their data, demand that it be corrected, blocked or deleted, and withdraw consent if the processing is based on consent.
6.2. Requests are sent by email to admin@neogate.systems. The Contractor answers within 10 business days.
6.3. Visitors to Resources send their requests to the operator, the Customer who owns the Resource. The Contractor helps the Customer to carry them out.
#7. Deletion of Customer data
7.1. After the agreement ends, the Customer's data is deleted within 30 days, except payment records, which the Contractor is required by law to keep.
#8. Changes to the policy
8.1. The Contractor may change the Policy. A new version is published at least 7 days before it takes effect.
#9. Contacts
Arseniy Pavlovich Devov
Email: admin@neogate.systems