Personal Data Processing Policy for the “Moya Bron” Online Accommodation Booking Service
Version dated 6 August 2026. Effective as of publication.
1. General Provisions
1.1. This Personal Data Processing Policy (the “Policy”) sets out the procedure and terms for processing personal data when using the “Moya Bron” online accommodation booking service (the “Service”), available through the moyabron.ru website (the “Website”) and the official “Moya Bron” mobile applications for iOS and Android.
1.2. Personal data controller: Moya Bron Limited Liability Company (Moya Bron LLC), Primary State Registration Number (OGRN) 1247700470566, Taxpayer Identification Number (INN) 9717165404, registered address: Premises 3/7, Building 1, 102 Prospekt Mira, Moscow, 129626, Russian Federation (the “Operator”).
1.3. This Policy has been prepared in accordance with the Constitution of the Russian Federation, Russian Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”, and other applicable laws and regulations of the Russian Federation.
1.4. This Policy applies to the personal data of:
- visitors to the Website and users of the mobile applications;
- registered Users of the Service;
- persons who make, pay for, modify or cancel a Booking;
- Guests for whom a Booking is made;
- payment instrument owners and payers to the extent that their data become available to the Operator;
- persons who contact support or submit enquiries or claims to the Operator.
1.5. The terms “User”, “Guest”, “Booking”, “Offer”, “Accommodation Property”, “Provider” and “Booking Confirmation” have the meanings given to them in the current version of the User Agreement.
1.6. To the extent that the Operator independently determines the purposes and scope of processing, it acts as a personal data controller. The Provider, an authorised supplier of Offers, a payment provider and other recipients may independently act as personal data controllers in relation to processing whose purposes they determine themselves. The Operator’s status as an agent or sub-agent when accepting and transferring online payments does not change the allocation of personal data obligations.
1.7. This Policy is an information document and does not in itself constitute consent to personal data processing. Where consent is required for a particular operation, the Operator obtains it separately from the User Agreement and other documents confirmed by the User. Reviewing this Policy or continuing to use the Service does not replace such consent.
1.8. This Policy does not govern independent data processing on third-party websites, applications or information systems that the User visits on their own initiative. Before transferring data to such a party, the Operator provides the necessary information about the transfer or makes that information available through the Service interface.
2. Processing Principles
2.1. The Operator processes personal data lawfully, fairly and only for predetermined purposes, does not process data in a manner incompatible with those purposes, and does not combine databases created for incompatible purposes.
2.2. The scope of processed data is limited to the information necessary for the relevant purpose. The Operator does not request excessive data and takes steps to correct, block or delete inaccurate and excessive information.
2.3. The processing period is determined by the purpose, the terms of the contract, the duration of consent and mandatory statutory retention periods. Once the purpose has been achieved or another legal ground arises, processing is terminated and the data are destroyed or anonymised unless their continued retention is required by law.
2.4. The Operator maintains the confidentiality of personal data and does not disclose them to an indefinite group of persons without a separate lawful basis.
3. Categories and Sources of Personal Data
3.1. Account and authentication data:
- internal User identifier;
- first name and surname;
- telephone number and email address;
- information about the selected authentication method and the result of contact verification;
- session data and authentication tokens;
- profile settings and information about linked sign-in methods.
One-time codes are used to confirm sign-in or contact details. The User must not disclose such codes to the Operator’s employees or to third parties.
3.2. Data used for searching and personalising the Service:
- the locality or other selected search area;
- travel dates;
- the number of adults and children and the children’s ages;
- selected filters, language, currency and interface theme;
- the list of favourite properties and other saved settings.
Before a Booking is made, this information may not by itself identify a person, but it constitutes personal data if it is associated with an identified or identifiable individual.
3.3. User and Guest data used for a Booking:
- the first name and surname of the main contact and each Guest;
- the telephone number and email address of the contact person;
- the selected Accommodation Property, room or room category, check-in and check-out dates and times, number of Guests, scope of services, rate, meals and other terms of the Offer;
- the Booking number and status and information about its confirmation, modification, cancellation, no-show and refund;
- preferences and comments voluntarily provided by the User for the Provider;
- information about any promotional code or discount applied and the source from which the User arrived at the Service.
3.4. Payment data:
- the amount, currency, method, date and status of a payment or refund;
- Booking and payment transaction identifiers;
- the name or technical description of the payment instrument, the masked portion of the card number, and other limited information received from the payment provider;
- data required to issue a cash register receipt and review a payment-related enquiry.
The full bank card number, expiry date and security code are entered on the secure page or form of an authorised payment provider. The Operator does not receive or store full bank card details.
3.5. Enquiry data:
- the applicant’s name and contact details;
- the content of correspondence, telephone calls, enquiries or claims;
- the Booking number and information required to investigate the enquiry;
- documents, photographs and other materials voluntarily supplied to the Operator by the applicant;
- the date, time, channel, status and outcome of the enquiry.
3.6. Technical data:
- IP address and the date and time of access;
- browser type and version, operating system, device type and interface language;
- the address of the requested page, referral source, and advertising or partner-link parameters;
- cookie, session and device identifiers;
- actions taken in the interface and information about errors, failures, performance and information security events;
- approximate location determined from the IP address, or geolocation if the User separately permits access to it in the device or browser settings.
3.7. Data sources. The Operator obtains data:
- directly from the User when the User uses the Service, creates an account, makes or manages a Booking, or contacts support;
- automatically from the User’s device and software;
- from the Provider, the Bronevik booking system, the payment provider and other participants in performance of the Booking, in relation to its status, modification, payment, refund and performance;
- from the search engine or partner service through which the User arrived at the Service, to the extent of technical referral identifiers and the parameters of the selected Offer.
3.8. Data of other persons. If the User supplies data relating to a Guest, payer, payment instrument owner or another person, the User confirms that they have the authority and lawful basis to do so, must inform that person about the processing of their data, and must not provide information beyond what is necessary for the Booking. At the Operator’s request, the User provides evidence of the relevant basis in the cases prescribed by law.
3.9. Data of minors. The Service is not intended for minors to create accounts independently. Personal data of a minor Guest required for a family Booking must be supplied by that Guest’s legal representative or another duly authorised adult.
3.10. Special categories of data. The Operator does not seek to process information concerning health, nationality, political opinions, religious or philosophical beliefs, intimate life or criminal convictions, or biometric data. The User must not include such information, passport details or full bank card details in comments or enquiries unless the Operator has expressly requested specific information on a basis provided by law.
4. Purposes, Data, Legal Bases and Processing Periods
| Purpose of processing | Categories of data and data subjects | Legal basis | Processing and retention period |
|---|---|---|---|
| Providing search, property pages, favourites, settings and other Service functionality | Users and visitors; search data, settings and necessary technical data | conclusion and performance of the User Agreement; steps taken at the User’s request before conclusion of a contract; the Operator’s legitimate interests in providing core functionality without infringing the data subject’s rights | until the User deletes the relevant settings, the cookie or local-storage period expires, or the User stops using the function; server records are retained no longer than necessary for the purpose |
| Creating an account, authentication and maintaining the personal account area | registered Users; identifier, first name, surname, telephone number, email address, authentication and session data | conclusion and performance of the User Agreement; consent for operations that cannot be carried out on another lawful basis | while the account remains active; for no more than 30 days after its deletion, except for information that must be retained longer by law or is required to perform an active Booking, resolve a dispute or maintain security |
| Making, instantly confirming, modifying, cancelling and performing a Booking | Users and Guests; contact details, Guest data, Booking parameters and status, and comments | conclusion and performance of a contract to which the data subject is a party, beneficiary or recipient of services; steps taken before conclusion of a contract; consent or another basis provided by law where the data were supplied by another person; compliance with statutory obligations | during performance of the Booking and thereafter for mandatory retention and claim periods; as a rule, no more than 5 years after the end of the calendar year in which the Booking was completed, unless a longer period is required by law |
| Accepting online payment, transferring funds, issuing a receipt, making a refund and reconciling payments | Users, payers and payment instrument owners; limited payment data, amount, status, transaction and Booking identifiers | performance of the contract and the Operator’s agency or sub-agency authority; compliance with obligations under payment, accounting and tax law | during settlement and thereafter for the mandatory retention period applicable to financial and accounting records; as a rule, at least 5 years unless another period is established by law |
| Sending the Booking Confirmation, cash register receipt, notices concerning payment, cancellation and refund, and other service communications | Users, Guests and payers; name, contact details, number, terms and status of the Booking or payment | performance of the contract and statutory obligations; the legitimate interests of the Operator and User in receiving information about the Booking | during performance of the Booking; message-delivery information may be retained with the Booking or enquiry records for the corresponding period |
| Support and review of enquiries, claims and disputes | applicants, Users, Guests and payers; contact details, correspondence, documents, Booking and payment data | performance of the contract; compliance with statutory obligations; exercise of the rights and legitimate interests of the Operator or the data subject without infringing the latter’s rights | while the enquiry is being considered and, as a rule, for 3 years after it is closed; longer if required by law or if a dispute remains ongoing |
| Information security and prevention of fraud and unauthorised access | all categories of data subjects; technical, authentication, transaction and Service activity data | the Operator’s security obligations; exercise of the rights and legitimate interests of the Operator and Users without infringing data subjects’ rights | security logs are generally retained for no more than 1 year; incident-related information is retained until the investigation and remediation are complete and the applicable claim period has expired |
| Analysing Service operation and improving the interface using Yandex Metrica | visitors and Users; cookies, technical data and information about actions in the interface, without the Operator transmitting names, telephone numbers, email addresses or Guest data | the User’s separate consent obtained through the cookie settings, where consent is required for the processing | until consent is withdrawn or the period set for the analytics identifier expires, but no longer than the period specified in the cookie settings and the relevant consent |
| Sending advertising and offers from the Operator | Users who have separately agreed to receive advertising; name, telephone number, email address, selected channel and consent history | separate prior consent to receive advertising and to data processing for that purpose | until the consent expires or is withdrawn, whichever occurs first; records of withdrawal and termination of communications are retained for the period necessary to demonstrate compliance with the request |
| Compliance with requests from public authorities and mandatory legal requirements | persons to whom a lawful request relates; data within the scope of the request | performance of an obligation imposed by law; exercise of rights in judicial or administrative proceedings | for the period established by law or for the duration of the relevant proceedings |
4.1. Where several legal bases apply to the same purpose, termination of one basis does not require deletion of data that the Operator is required or entitled to continue processing on another lawful basis. For example, withdrawal of consent to advertising does not require deletion of information about a completed Booking and payment that must be retained under a contract or by law.
4.2. Where certain data are required to conclude or perform a contract or comply with a mandatory legal requirement, refusal to provide those data may make it impossible to create an account or make, pay for or perform a Booking. Refusal of optional analytics or advertising does not restrict access to the Service’s core functionality.
5. Processing Methods and Operations
5.1. The Operator carries out mixed personal data processing: both with and without automated means, and with or without transmission over information and telecommunications networks.
5.2. The Operator may perform the following operations: collection, recording, organisation, accumulation, storage, correction and updating, retrieval, use, matching, transfer by provision or access, anonymisation, blocking, deletion and destruction of personal data.
5.3. Automatic checks of availability, payment and indications of unauthorised use may suspend an incomplete transaction or refer it for additional review. The Operator does not make decisions based solely on automated processing that produce legal effects for the data subject or otherwise materially affect that person’s rights, except where permitted by law or by separate valid consent. The User may contact support to request a review of the result.
6. Data Transfers and Processing on the Operator’s Instructions
6.1. The Operator transfers personal data only to the extent necessary for the stated purpose, under a contract or another lawful basis, and subject to confidentiality and security requirements.
6.2. For performance of a Booking, data may be received by:
- the Provider that directly supplies the accommodation services;
- a person that manages the relevant Accommodation Property or is authorised by the Provider to accept and perform Bookings;
- the Bronevik booking system and the person that supplies Offers to the Operator through that system;
- another authorised supplier of Offers if it is expressly identified in the information for the relevant Booking.
Those recipients receive the first names and surnames of the Guests and contact person, contact details, Booking parameters, the comment for the Provider, and other information without which the Booking cannot be confirmed, modified, cancelled or performed.
6.3. For online payments and refunds, the necessary data are transferred to an authorised payment provider, banks, payment system operators, a fiscal data operator and other settlement participants. Full payment instrument details are processed by the payment provider and bank without being transferred to the Operator. The recipients may independently process the data to conduct the transaction, prevent fraud and comply with their obligations.
6.4. To operate the Service, the Operator may engage Russian providers of hosting and cloud infrastructure, email, SMS and push-notification services, technical support, backup and information security to process data on its instructions. The instructions specify the categories of data and operations, processing purposes, and confidentiality, security and destruction requirements.
6.5. Yandex Metrica and maps. Subject to separate consent, analytics cookies and technical data may be transferred to YANDEX LLC for the operation of Yandex Metrica. When the User opens an interactive map, the technical data necessary to load and display that map are transferred to YANDEX LLC. The Operator does not use these tools to transfer Guest names, telephone numbers, email addresses, comments, complete Booking data or payment details.
6.6. Partner referrals. If the User arrives at the Service from a search engine or partner service, the Operator may receive and return to the partner a technical referral identifier and information about the result of the interaction that are required for attribution and integration quality assurance. The User’s or Guests’ names and contact details are not transferred to the partner for this purpose.
6.7. Public authorities and other persons receive data only in the cases and to the extent provided by law, an effective court order or a binding lawful request.
6.8. Transfer of data to a Provider or another independent controller means that the recipient is responsible for any further processing whose purposes it determines. The Operator remains responsible for the lawfulness of its own transfer and for selecting any person that processes data on the Operator’s instructions.
7. Data Localisation and Cross-Border Transfers
7.1. When collecting personal data of Russian citizens through the Internet, the Operator ensures that those data are recorded, organised, accumulated, stored, corrected and retrieved using databases located in the Russian Federation, except in the cases expressly provided by law.
7.2. If the User selects an Accommodation Property outside the Russian Federation, User and Guest data may be transferred to a Provider or authorised supplier located abroad in order to conclude and perform the contract. The country in which the Accommodation Property is located and information about the Provider are available to the User before the Booking is made.
7.3. Before beginning a cross-border transfer, the Operator complies with the requirements of Article 12 of Federal Law No. 152-FZ, including assessing the recipient and destination country, submitting the required notification to Roskomnadzor, and obtaining separate consent where the transfer cannot be made on another lawful basis. The Operator terminates or restricts a transfer where required by a decision of the competent authority.
8. Cookies and Local Storage
8.1. The Service uses cookies and local storage on the device. They may contain a session or device identifier, selected language, theme and currency, search dates, number of Guests, favourite properties, interface state and other technical settings.
8.2. Strictly necessary cookies provide authentication, security, retention of selected parameters and operation of the core functionality. Disabling them in the browser may cause certain Service functions to become unavailable or operate incorrectly.
8.3. Functional storage remembers choices made by the User, such as currency, theme, favourites or dismissal of an information banner. The User may delete this information through the browser or application settings.
8.4. Analytics cookies are used only after separate consent where such consent is required by applicable law. The User may reject them or withdraw consent through the cookie settings without losing access to search, booking or the personal account area.
8.5. The lifetime of a cookie depends on its purpose: session cookies are deleted at the end of the session, while persistent cookies remain until their stated expiry date, deletion by the User or withdrawal of consent. The Website authentication token is generally stored for up to 7 days, selected search dates for up to 7 days, and theme settings for up to 1 year. Other local settings may be stored until the User deletes them or clears the application or browser data.
9. Service Communications and Advertising
9.1. Booking Confirmations, cash register receipts, information about payments, refunds, modifications or cancellations, security notices and support responses are service communications. They are sent to perform a contract or comply with the law and do not constitute advertising.
9.2. Advertising and information about new services, discounts and promotions are sent by email, telephone, SMS or push notification only with separate prior consent to advertising and data processing for that purpose.
9.3. The User may opt out of advertising using the method stated in the communication, through the Service settings, or by contacting the Operator. The request is implemented immediately; opting out of advertising does not stop necessary service communications concerning an active Booking.
10. Personal Data Security
10.1. The Operator implements the necessary and sufficient legal, organisational and technical measures to comply with statutory requirements and protect data against unlawful or accidental access, destruction, modification, blocking, copying, provision, dissemination and other unlawful acts.
10.2. The measures are determined taking into account the nature of the data, current threats and applicable requirements and include appointing a person responsible for organising processing, adopting internal policies, segregating access, logging actions in information systems, using secure communication channels, monitoring contractors, detecting incidents, restoring data, and regularly evaluating the effectiveness of security measures to the extent necessary.
10.3. Employees and contractors are given access only to the extent necessary to perform their duties. Persons granted access must comply with confidentiality and security requirements.
10.4. The User must keep one-time codes and access credentials confidential, must not provide unauthorised persons with a Booking-management link or code, and must notify the Operator if unauthorised access is suspected.
11. Termination of Processing and Destruction of Data
11.1. The Operator terminates processing and destroys or anonymises data when the purpose has been achieved, the established period has expired, the lawful basis has ceased, consent has been withdrawn, or a lawful request has been received, provided that further processing is not permitted or required by law.
11.2. Data are destroyed by deleting them from active information systems and subsequently from backups as part of the established update cycle, or by another method that prevents recovery. Paper records are destroyed in a manner that prevents their content from being read or restored. Where necessary, destruction is documented in accordance with the prescribed procedure.
11.3. If immediate destruction from a backup is technically impossible, the data are isolated from ordinary use and deleted when the backup is next scheduled to be updated. The backup is not used for any other purpose.
11.4. When an account is deleted, access to the personal account area is terminated and data associated with the account are deleted, except for information required for active Bookings, refunds, dispute resolution, prevention of misuse, or statutory retention. The exception ceases to apply when the relevant period expires.
12. Rights of the Personal Data Subject
12.1. The personal data subject has the right to:
- obtain information about the processing of their personal data and access those data;
- require correction, blocking or destruction of data that are incomplete, outdated, inaccurate, unlawfully obtained or unnecessary;
- withdraw previously given consent;
- require at any time that processing for the direct promotion of goods and services be stopped;
- object to processing based on legitimate interests, subject to exceptions provided by law;
- challenge the Operator’s actions or omissions before Roskomnadzor or a court;
- exercise any other rights provided by the laws of the Russian Federation.
12.2. A request may be sent to support@moyabron.ru or by post to the Operator’s address. The request must make it possible to identify the applicant and their connection to the data and must contain a description of the request, contact details for the response, and the signature of the applicant or representative in the form required by law. The Operator may request additional information solely for reasonable verification of the applicant’s identity and authority.
12.3. The Operator considers the request and responds within the periods established by law. If the request cannot be fulfilled in full, the Operator provides the reasoned grounds for refusal. The response is provided in a form corresponding to the form of the request unless the applicant specifies otherwise and the law does not prohibit it.
12.4. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal was received and does not terminate processing for which the Operator retains another basis provided by law.
13. Amendments to the Policy
13.1. The Operator may amend this Policy following changes in legislation, the composition of the Service or processing activities. The new version is published on the permanent moyabron.ru/docs/privacy-policy page and states the version and effective dates.
13.2. The Operator additionally notifies data subjects of material changes by an available method before they are applied where required by law or where the changes materially affect data subjects’ rights.
13.3. A new version does not retroactively create new processing purposes and does not replace separate consent where such consent is required. Before beginning new consent-based processing, the Operator obtains new or updated consent.
13.4. If this Policy is translated into another language, the Russian-language version prevails.
14. Operator Contact Details
Moya Bron Limited Liability Company (Moya Bron LLC)
OGRN: 1247700470566
INN: 9717165404
Registered and postal address: Premises 3/7, Building 1, 102 Prospekt Mira, Moscow, 129626, Russian Federation
Email for personal data matters: support@moyabron.ru
Telephone: +7 922 902-26-65 (24/7)
Website: moyabron.ru
A complaint to Roskomnadzor may be submitted through its official website at rkn.gov.ru or to the appropriate territorial office.