Summary. Apollo Health Technologies processes your personal data, including health data, to operate the Apollo service. This document is a separate, public policy as required by 152-ФЗ. Health data (a special category) is processed only with your explicit, separately given consent. You can withdraw consent at any time at legal@apollo-life.ru.
1. Operator
The Operator of personal data is Apollo Health Technologies, ИНН [укажите], ОГРН [укажите], registered office: [укажите юридический адрес], Russian Federation. Contact: legal@apollo-life.ru. The Operator is included in the Register of Personal Data Operators maintained by Roskomnadzor under registration no. [укажите] (or notification submitted on [дата]).
2. Legal Framework
- Federal Law No. 152-ФЗ of 27 July 2006 "On Personal Data" as amended (incl. Federal Law No. 420-ФЗ of 30 November 2024 and the package effective 1 September 2025).
- Federal Law No. 149-ФЗ of 27 July 2006 "On Information, Information Technologies and Information Protection".
- Federal Law No. 323-ФЗ of 21 November 2011 "On the Fundamentals of Health Protection of Citizens".
- Government Decree No. 1119 of 1 November 2012 (technical protection levels) and No. 687 of 15 September 2008 (non-automated processing).
- Roskomnadzor Order No. 274 of 28 October 2022 and subsequent guidance treating cookies as personal data.
3. Categories of Personal Data Processed
3.1. Identification data: surname, given name and (optionally) patronymic, date of birth, gender, email, mobile phone, account password (hashed).
3.2. Service data: account ID, device identifiers, IP address, browser/OS type, app version, language, time zone, cookie identifiers and other technical attributes.
3.3. Special categories of personal data — health data (Art. 10 152-ФЗ): dietary intake, body weight and other anthropometric values, physical activity, sleep, mood-diary entries, photographs of meals, voluntary inputs about chronic conditions, allergies and medications. Processed only on the basis of separately given written consent.
3.4. Payment data: processed by certified Russian payment operators. We receive only the transaction status, masked card identifier and amount.
The Service is not intended for persons under 14. Persons aged 14–17 may use the Service only with consent of a parent or legal guardian.
4. Purposes and Legal Basis
- Conclusion and performance of the User Agreement and the Public Offer — basis: Art. 6 §1(5) 152-ФЗ.
- AI health-monitoring features (food log, mood diary, activity insights) — basis: separate consent and contract performance.
- Service communications, security alerts, billing — basis: Art. 6 §1(5) 152-ФЗ.
- Statistical and analytical work on aggregated, depersonalised data — basis: Art. 6 §1(7) 152-ФЗ (legitimate interest).
- Compliance with legal obligations (tax, accounting, breach notification) — basis: Art. 6 §1(2) 152-ФЗ.
5. Localisation (Art. 18 §5 152-ФЗ)
Recording, systematisation, accumulation, storage, clarification (updating, change), and retrieval of personal data of citizens of the Russian Federation are performed using databases located on the territory of the Russian Federation. Cross-border transfer is permitted only to jurisdictions providing adequate protection or upon prior notification to Roskomnadzor as required by Art. 12 152-ФЗ.
6. Third-Party Processors
By assignment of the Operator, processing is performed by:
- Hosting and cloud infrastructure providers located in the Russian Federation;
- Certified Russian payment operators;
- Email and push-notification delivery services;
- Analytics: Yandex.Метрика (servers in the Russian Federation).
Each processor acts on the basis of an instruction from the Operator and confidentiality obligations no less protective than those set in this Policy.
7. Retention Periods
- Account and service data — for the entire period of the User Agreement and three (3) years after termination, unless a longer period is required by law.
- Health-related entries — for the period set in the consent form, but not longer than the active subscription plus three (3) years; the user may request earlier deletion.
- Accounting and tax records — five (5) years (Art. 23 of the Tax Code).
- Server logs — up to one (1) year.
- Records of consents and consent withdrawals — five (5) years.
8. Security Measures
The Operator applies organisational and technical measures appropriate to the threat level determined under Government Decree No. 1119: encryption in transit and at rest, role-based access, segregation of production and analytics environments, key rotation, vulnerability scanning, employee NDA and instructions on PD handling, periodic audits, incident response.
9. Breach Notification
In case of an unauthorised access to or distribution of personal data, the Operator notifies Roskomnadzor within 24 hours of the incident with the initial information and within 72 hours with the results of the internal investigation, in line with Art. 21 §3.1 152-ФЗ. Affected subjects are informed without undue delay.
10. Your Rights
- To obtain confirmation of processing and a copy of your data;
- To rectify inaccurate or incomplete data;
- To withdraw consent and request erasure ("right to be forgotten");
- To restrict or object to processing;
- To request information about third parties to whom your data is or has been transferred;
- To lodge a complaint with Roskomnadzor (rkn.gov.ru) or with the courts of the Russian Federation.
Submit requests to legal@apollo-life.ru. We respond within 10 business days; complex requests — within 30 days.
11. Cookies
The Service uses cookies and similar technologies. Categories, purposes and the consent mechanism are described in the Cookie Policy.
12. Changes
This Policy may be updated. The current version is always available at https://apollo-life.ru/ in the footer. Material changes are announced inside the Service no less than 10 days before they take effect.