Transparency and respect

Personal data.

Registration, invitation requests and feedback forms within Esprio are not open yet. You can browse without an account. Reference listings link to organisers, who handle enquiries under their own rules.

1. Data controller and scope

Data controller details are being prepared for publication. Esprio does not open profile collection, registration or invitation requests until they are provided. This does not mean that the website processes no technical information when visited.

This policy covers Esprio at esprio.ru. When you follow a link to an organiser’s website, email or page, their rules apply. The service does not request sensitive categories of personal data, passport information or payment details.

2. Data we process and why

When accounts open, registration uses a name, email and password. Passwords are stored as secure hashes. Optional profile details make communication easier.

Invitation requests use the guest’s name, contact, party size, note, selected event and review status. The organiser needs this information to invite guests and record attendance. Do not include health information, identity documents or information about other people without an appropriate basis.

Organiser verification uses account details, the salon name, an official resource and an explanation of authority. Correction requests use the page address, issue description and contact provided. Security processing includes session information, request times and outcomes, and limited technical logs.

3. Legal bases and consent

Data is processed to provide requested features, comply with applicable legal requirements, ensure security and, where required, on the basis of separate consent. Analytics consent is separate from essential cookies. Registration or an invitation request does not imply consent to marketing messages.

4. Access and sharing

Requests are visible to the guest, verified representatives of the relevant salon and authorised administrators. Applying for an event means sharing the information the organiser needs to review the request; this is explained before submission. This data is not published in the directory.

When email delivery is enabled, the configured delivery services are used. Private organiser notifications should not contain guest contacts; details are available after sign-in. The operator describes hosting and database location before enabling features if the policy needs to change.

5. Retention and ending processing

Invitation contact details, names and notes are anonymised 365 days after both the event and the latest request update. Anonymous counts and statuses may be retained for statistics. Correction request texts are deleted after 365 days and declined organiser applications after 180 days. Rate-limit records and notification queues are cleared after 30 days, and audit logs after 90 days. Profiles remain until account deletion or the end of the lawful processing basis. Local backups have limited retention; deleting a live record does not immediately change an existing backup.

Users may request information about processing, correction, restriction or deletion where provided by law, and withdraw consent. Withdrawal does not automatically end processing where another lawful basis exists. Requests should be sent to the data controller’s contact.

6. Analytics and security

Yandex Metrika is loaded on public pages with visitor consent when analytics is enabled in service settings. It is not loaded in accounts or authentication pages. Form contents, passwords and contacts are not sent to analytics goals. See the cookies page for details.

Access to personal data is limited by role. The live website uses HTTPS. Changes to invitations and access rights are checked on the server. Security measures and documents are updated before the types of processed data change.

Contacts · Analytics settings