Privacy Policy
Effective date: 05.08.2026
Published pursuant to Article 18.1(1)(2) of Russian Federal Law No. 152-FZ of 27.07.2006 "On Personal Data".
The Russian version is the legally binding one. This translation is provided for convenience.
1. Operator
| Operator | Individual entrepreneur Aigiz Iskuzhin |
| INN | 024803896842 |
| OGRNIP | 326028000044859 |
| OKVED | 62.01 "Computer software development" |
| Roskomnadzor operator registry | No. 2-26-056967 |
| Contact | legal@pir2pir.ru |
Official channels: Telegram bot @pir2pirbot, documentation at https://docs.pir2pir.ru, personal data requests at legal@pir2pir.ru.
2. Relationship to School 21
Pir2Pir (also written «Пир2Пир» in Cyrillic — the same name) is an independent service built by a member of the community. The Operator is not ANO «Школа 21» (School 21), is not affiliated with it and does not act on its behalf. Using Pir2Pir is not part of the educational process.
The Operator does not inherit School 21's legal basis and processes personal data under its own Consent, granted by the subject directly.
3. Principles
- Minimisation. Only data needed for account confirmation, participant matching and notification delivery is processed.
- Purpose limitation. Data is not used for purposes outside the Consent.
- Separate consents. Processing for advertising or transfer to commercial services requires separate consent and is not performed at present.
- Transparency. The data processed is listed in Consent, section 3.
4. Data processed
The full list is in section 3 of the Consent. In brief:
| Category | Source |
|---|---|
| School 21 login and student email | provided by the subject, confirmed by emailed code |
Name, telegram_user_id, @username, profile photo | Telegram, when connecting the bot |
| Campus, wave, education form, level, points, projects | School 21 public API |
| Chat messages and attachments | created by the participant |
| Internal identifiers and request logs | generated by the service |
| The login of an unregistered student and the address derived from it | supplied by a participant; the login's existence is checked against the School 21 public API |
| Daily history of level, experience and points; project status transitions | built by the service from School 21 public API data |
| The text of a review of the service, published with the login | written by the participant |
| Invitation code, the "who invited whom" link and ranking position | generated by the service |
| Type of School 21 notification, project code, review date and time, the login of a participant named in it | forwarded by the participant, who set forwarding up in their own mailbox |
5. Legal basis
Consent of the data subject — Article 6(1)(1) of 152-FZ. No other basis is used.
6. Third-party data
The Operator keeps no directory of participants, offers no search for people, and collects no information about School 21 students who have not registered with the service. Other participants' profiles are disclosed only to those who registered themselves and granted Consent, and only after both have agreed to talk.
Two further exceptions exist, and both happen only on a participant's own initiative:
- A review of the service. Once published it is available to an unlimited audience, together with the author's login; the first name and surname are not published. It is published only after the Operator has checked it and only if the participant wrote it themselves; it can be withdrawn at any time. See section 6.3 of the Consent.
- The ranking by number of people invited. Available to registered participants and not published outside the service. Display of one's login and photograph in the ranking can be turned off in the settings. See section 6.4 of the Consent.
The remaining exception is the invitation sent, at a participant's request, to a School 21 student who is not registered with the service. In that case the Operator processes that person's login, the email address derived from it, the text of the invitation and a record of delivery.
That data comes not from the subject but from the participant who supplied the login. The message being sent also serves as notice to the subject: it states who is asking, what is processed about them, where it came from and how to stop it. The opt-out link in the message takes effect immediately, permanently and across all channels. No account is created for such a person, no profile is built, and no further information about them is requested or retained.
The conditions and limits are set out in section 6.2 of the Consent.
6.1. Forwarded School 21 notifications
Where a participant has set up forwarding of School 21 mail to an address of the form
login@pir2pir.ru, such a message may name another School 21 student — the peer a review is booked
with, for instance. That login is extracted and stored alongside the notification, because without it
the notification means nothing to the person receiving it.
That data comes not from the subject but from the participant who set the forwarding up. The Operator processes only the login School 21 itself wrote into the notification: no account is created for that person, no profile is built, no further information about them is requested or retained, and nothing is sent to them. The login is shown only to the participant the notification was addressed to and never leaves the service.
Forwarding is entirely optional, switched on by the participant in their own mail provider, and switched off there at any time.
7. Retention
| Data | Period |
|---|---|
| Account and profile | until consent is withdrawn or the account is deleted |
| Verification codes | 10 minutes; the record of the request up to 24 hours, to rate-limit |
| Chat messages and attachments | 30 days after a conversation ends, then the content is deleted |
| Request logs | at most 90 days |
| Invitations to unregistered students | 12 months, then deleted |
| Opt-outs from invitations | indefinitely — the record of the refusal is what makes it enforceable |
| History of level, experience, points and project statuses | until consent is withdrawn or the account is deleted |
| A review of the service | until the participant withdraws it or the account is deleted |
| The "who invited whom" link | until one of the two accounts is deleted |
| The text of forwarded School 21 mail | not stored: deleted as soon as the details are read, and never beyond 7 days |
| A notification built from a forwarded message | 30 days after delivery |
| The service record of a received message | 30 days, to prevent the same message being processed twice |
| Data whose retention is required by law | for the statutory period |
Once a conversation ends — because either participant closed it, or because it went inactive — message text and attachments are deleted after 30 days. The record that a review happened is kept, since it belongs to the participants' study history, but its content is not recoverable.
After withdrawal, data is destroyed within 30 days.
7.1. Notifications
Chat content does not leave the Operator's infrastructure. A new-message notification containing a short excerpt is delivered only to the web application.
Telegram and any other connected messenger are told only that an event occurred — that a reviewer was found, or that a request to talk was received. No excerpt, full message text, attachment or chat content is sent to a messenger.
7.2. How far forwarded notifications can be relied on
Notifications built from forwarded mail are informational only. Inbound email has no technical protection against a forged sender, so the Operator cannot confirm that a message was genuinely sent by School 21.
Such notifications inform the participant and cause the service to do nothing else: they do not alter the study profile, play no part in matching reviewers, and create no obligation for the participant. Study profile data is taken solely from School 21's public API, never from email.
8. Security
Organisational and technical measures proportionate to the processing: restricted infrastructure access, TLS in transit, time-limited access tokens, and service logs that contain neither message contents nor verification codes.
9. Rights
The subject may obtain information about the processing; require correction, blocking or destruction of data that is incomplete, outdated, inaccurate or unlawfully obtained; withdraw consent at any time; and appeal to Roskomnadzor or in court.
Requests go to legal@pir2pir.ru and are answered within the statutory period — no more than 30 days.
10. Changes
The current version is published at https://docs.pir2pir.ru. Changes affecting the data processed or the purposes are announced through the Telegram bot.