1. General provisions
The Operator processes the personal data of clients who make bookings through NaKogda and dashboard users who manage organizations, schedules, and bookings.
Processing is carried out in accordance with the laws of the Russian Federation, this Policy, and the separate consent of the relevant data subject.
2. Data subjects and categories of data
For clients, the Operator processes their name, telephone number, comment, details of the selected organization, service, specialist, booking date and time, as well as confirmation and reminder settings.
For dashboard users, the Operator processes their telephone number or email address, profile data, an uploaded photograph, settings, information about organizations, and actions performed in the dashboard.
When a user signs in with Google, Yandex, or VK ID, the Operator receives a stable external account identifier, email, available email verification attributes, first name, last name, and photo URL from the selected provider. The fields actually received depend on the provider response.
For all data subjects, technical session data may be processed, including the IP address, User-Agent, authentication identifiers, essential cookies, the date and time of actions, and information required to keep the service secure.
3. Purposes of processing
Personal data is not used for marketing, profiling, or bulk messaging without a separate legal basis.
- Registration, authentication, and maintenance of a secure session.
- Creation, management, confirmation, modification, and cancellation of a client booking.
- Sending one-time codes, service confirmations, and reminders through the selected channels.
- Providing dashboard functionality, maintaining schedules, and interacting with the selected organization.
- Responding to requests, maintaining security, preventing misuse, and complying with legal requirements.
4. Legal grounds and methods of processing
The legal grounds for processing include the data subject’s consent, performance of a contract with the data subject or steps taken at their request before entering into a contract, the Operator’s legal obligations, and other grounds provided by law.
The Operator may collect, record, organize, accumulate, store, update, retrieve, use, disclose in the cases provided for by this Policy, anonymize, restrict, and delete data by automated or non-automated means.
5. Recipients and processing on behalf of the Operator
Client booking details are disclosed to the selected organization and its authorized users to the extent necessary to provide the service and manage the booking.
To operate the service, the Operator may engage hosting, infrastructure, security analytics, and communications providers to process data. A telephone number or Telegram identifier is used by the relevant provider only when that channel has been selected and enabled.
Data may also be disclosed to a public authority in the cases and to the extent expressly required by law. Other recipients do not receive data without a separate legal basis.
6. External sign-in with Google, Yandex, and VK ID
Google sign-in requests only the openid, email, and profile scopes; Yandex sign-in requests login:email, login:info, and login:avatar; VK ID sign-in requests email. These scopes are used only to identify the user and obtain their email and available profile details.
Calendar scopes are not part of this sign-in and may be requested only through a separate explicit action by the user. Any future calendar sync will receive only busy intervals with start and end, without event titles, descriptions, participants, or other content.
The provider authorization page receives the public client_id, exact redirect URI, requested scopes, a one-time state, and a PKCE challenge. NaKogda does not send the user’s profile, organization, booking, or calendar data back to the provider.
The persistent external-account link stores the provider code and stable account identifier. The provider email is not stored in that link; when a new user is created, the received email becomes the email in their NaKogda account profile.
Before matching, an email is normalized by trimming surrounding whitespace and converting it to lowercase. A user email is globally unique in NaKogda, so linking uses only an exact match between normalized addresses.
If the provider returns a first name, last name, or photo, they may be copied only into a new user’s profile. An existing profile is not overwritten. Photo import is best-effort and an import failure does not block sign-in; the remote URL is not stored, and after successful source, format, and file checks only a verified local copy is retained.
Access tokens, ID tokens, and a possible refresh token exist only briefly in Node.js memory during the provider exchange and are not stored in the database, profile, logs, or browser. A one-time provider authorization code is processed during the callback and is not stored in the database, profile, or logs. The raw email code for an external-account link is also not stored in the database; only its keyed HMAC is retained.
7. Retention and deletion
Data is processed until the stated purposes are achieved, consent is withdrawn, or another legal basis ceases to apply. Certain information and logs may be retained for longer where required by law, to protect the Operator’s rights, or to investigate violations.
An active OAuth request is retained for no longer than 10 minutes. Once it reaches a terminal result, the service immediately removes its personal and operational fields. An expired or abandoned request is cleared during the next five-minute cleanup cycle.
A minimal technical tombstone without a user identifier, provider, email, IP address, User-Agent, or return path is retained for 24 hours and then deleted during the next five-minute cleanup cycle. This cleanup applies to the one-time OAuth request and does not delete a user account or the account email created during a successful sign-in.
Of the identifying data, a confirmed consent record for external sign-in retains only the user identifier, provider, confirmation method, accepted document code and version, and creation and confirmation timestamps. The technical UID, contact hash, IP address, and User-Agent are removed.
When the relevant grounds cease to apply, data is deleted, destroyed, or anonymized within the period prescribed by law and the Operator’s internal procedures. Unverified codes and the related pending consents are retained only for the duration of the verification process.
8. Security measures
The Operator restricts access to data and applies authorization checks, secure connections, logging of significant actions, backups, and organizational rules for handling information.
These measures are reviewed in light of the nature of the data, current threats, and potential harm. If an incident is discovered, the Operator takes steps to contain it and fulfils applicable notification obligations where required by law.
10. Data subject rights and withdrawal of consent
A data subject may request information about processing, require data to be corrected, restricted, or deleted, and withdraw consent by contacting the Operator at the email address shown below.
Revoking access in Google, Yandex, or VK ID settings ends NaKogda’s authorization to receive data from that provider, but it is not the same as withdrawing consent from the Operator. Consent to the Operator must be withdrawn separately using the Operator email shown below.
Withdrawal ends processing based solely on consent but does not end processing for which an independent legal basis remains. To handle a request, the Operator may ask for information needed to verify the applicant’s identity.
Personal data operator
- Name
- Email for requests and withdrawal of consent
- support@nakogda.ru
- Phone
- Taxpayer ID (INN)
- 563500962846
- Sole proprietor registration number (OGRNIP)
- 326565800088148
- Registration address
- Registration date
- 25.08.2026
- Registration authority
- Межрайонная инспекция Федеральной налоговой службы № 10 по Оренбургской области