Privacy Policy

Last updated: June 1, 2026

At SETALABS, accessible from setalabs.com, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by SETALABS and how we use it.

If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.

Scope of Regulation

This Policy applies to data received both before and after this Policy implementation.

The Company is committed to protecting personal data by implementing appropriate technical and organizational measures. We recognize the importance and value of personal data and respect the privacy rights of individuals in accordance with applicable data protection laws.

Features of Data processing and protection collected by Company using the Internet

Company processes Data received from Site’s users from resource: setalabs.com (hereinafter jointly referred to Site), as well as arriving at Company’s e-mail address: mail@setalabs.com, through Company’s feedback form, located at: setalabs.com.

Data collection
There are two main ways in the Company to receive Data using the Internet:
Providing Data

Providing data (Data self-input):

  • Name;

  • Email;

  • Phone number;

  • Telegram.

Data Subjects enter it through Company’s feedback form located at setalabs.com, Form is sent to Company’s e-mail address: mail@setalabs.com.

Automatically collected information

Company can collect and process non-personal data:

  • information about users’ interests on the Site on the basis of their entered search requests on goods by Company with the purpose of providing up-to-date information to Company’s customers when using the Site, as well as summarizing and analyzing information what Site sections and goods are most in demand between Company customers;

  • processing and storing of Site users’ search requests in order to generalize and create client statistics about Site sections use.

Company automatically receives some types of information obtained during users’ interaction with the Site, e-mail correspondence, etc. It is about technologies and services, such as web protocols, cookies, web markers, as well as applications and tools specified by third side.

Herewith, web markers, cookies and other monitoring technologies do not allow automatic data retrieval. Only processes of automatic detailed information collection for website convenient use and / or improving interaction with users are launched if site user submits his Data at his own discretion, for example, when filling out feedback form or sending email.

Log Files

SETALABS follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this and a part of hosting services' analytics. The information collected by log files include internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to any information that is personally identifiable. The purpose of the information is for analyzing trends, administering the site, tracking users' movement on the website, and gathering demographic information. 

Cookies and Web Beacons

Like any other website, SETALABS uses "cookies". These cookies are used to store information including visitors' preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the users' experience by customizing our web page content based on visitors' browser type and/or other information.

Please see our Cookie Policy for more information.  

Legal Basis for Processing Personal Data

The Company processes personal data only where there is a lawful basis to do so under applicable data protection laws, including the General Data Protection Regulation (GDPR), where applicable.

Depending on the circumstances, we process personal data on one or more of the following legal bases:

  • Consent – where you have freely given your consent for us to process your personal data for a specific purpose, such as subscribing to newsletters or submitting a contact form.

  • Performance of a Contract – where processing is necessary to enter into or perform a contract with you, including providing access to our services, processing orders, and delivering customer support.

  • Legal Obligation – where processing is necessary for compliance with applicable legal or regulatory requirements, including accounting, tax, and other statutory obligations.

  • Legitimate Interests – where processing is necessary for our legitimate business interests, such as maintaining the security of our services, preventing fraud, improving our website and services, analyzing website usage, and protecting our legal rights, provided that such interests are not overridden by your fundamental rights and freedoms.

Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out before such withdrawal.

If you have any questions regarding the legal basis for the processing of your personal data, you may contact us using the contact information provided in this Privacy Policy.

Using Data

The Company has the right to process and use Personal Data for the purposes described in this Privacy Policy, provided that such processing is carried out on a lawful basis and, where required by applicable data protection laws, with the Data Subject's consent.

Obtained data in a generalized and impersonal form can be used to better understand customers of goods and services implemented by Company and improve service quality.

Data transmission

Company may entrust Data processing to third parties only with Data Subject consent. Data can be also transferred to third parties in the following cases:

а) As a response to legitimate requests of authorized state bodies, in accordance with laws, court decisions, etc.;

б) Data can not be transferred to third parties for marketing, commercial and other similar purposes, except for cases of obtaining preliminary consent of Data Subject.

Site contains links to other web resources with useful and interesting information for Site users. In this case, this Policy does not affect such sites. Users following links to other sites are advised to familiarize themselves with Data processing policies on such sites.

Site user may withdraw his consent for Data processing at any time by sending a message to Company’s e-mail address: mail@setalabs.com

Data processing (retention) period

Data processing (retention) period is determined on the basis of data processing purposes, in accordance with term of Agreement with Data Subject, requirements of federal laws, data operators’ requirements for data processing by Company, basic rules of archives of organizations, limitation period.

Data whose processing (storage) period has expired must be destroyed, unless otherwise stipulated by federal law. Data storage after termination of their processing is allowed only after depersonalization.

Requirements for Data protection

Company takes necessary legal, organizational and technical measures to protect Data from unauthorized and / or unauthorized access to, data destruction, modification, blocking, copying, provision, dissemination, and other unlawful activities with respect to Data when processing Data.

Such measures in accordance with the Law, in particular, include:

  • designation of responsible person for organization of data processing, and responsible person for ensuring data security;

  • development and approval of local acts on data processing and protection;

  • application of legal, organizational and technical measures to ensure data security:
    ·  identification of data security threats when processing it in personal data information systems;
    ·  the Company implements appropriate organizational and technical measures to ensure the security of Personal Data during processing within its information systems. These measures are designed to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, alteration, or disclosure, and are implemented in accordance with applicable data protection laws and industry best practices.
    ·  application of procedure set in established order for evaluating compliance of information protection means;
    ·  evaluation of taken measures effectiveness to ensure Data security before putting into operation an information system for personal data;
    ·  registration of computer data carriers, if data storage is carried out on machine carriers;
    ·  detection of unauthorized access facts to Data and taking measures to prevent similar incidents in the future;
    ·  data recovery, modified or destroyed due to unauthorized access to them;
    · setting rules for access to Data processed in personal data information system, as well as ensuring registration and recording of all actions performed with Data in personal data information system.

  • control over measures taken to ensure data security and level of information systems security of personal data;

  • harm evaluation that may be caused to Data Subjects in case of violation of law requirements, ratio of said harm and measures taken by Company aimed to ensure duties fulfillment provided by Law;

  • observance of conditions excluding unauthorized access to material data carriers and ensuring data safety;

  • the Company ensures that employees who process Personal Data are familiar with applicable data protection laws, this Privacy Policy, and the Company's internal policies and procedures relating to the processing and protection of Personal Data. The Company also provides appropriate training to employees to ensure compliance with these requirements.

Rights and obligations of Data Subjects as well as Company in terms of data processing 

Data Subject has the right:

— To receive the following information from Company:

  • confirmation of data processing fact and its availability related to relevant Data Subject;

  • information on legal grounds and purposes of data processing;

  • information on methods of Data processing by Company;

  • information on Company name and location;

  • information on persons (with the exception of Company employees) who have access to Data or who may be disclosed Data on the basis of Agreement or Federal law;

  • list of data processed relating to Data Subject and information on their receipt source, unless another procedure for providing such Data is provided for by Federal law;

  • information on Data processing time including time period for retaining personal data;

  • information on procedure for execution of rights by Data Subject provided by Law;

  • name (name and last name) and address of person processing Data on behalf of the Company;

— To request from Company:

  • his Data clarification, its blocking or destroying in case Data is incomplete, outdated, inaccurate, illegally obtained or not necessary for processing purpose;

  • withdraw own consent to process personal Data at any time; demand elimination of Company illegal actions with respect to its Data;

  • appeal against actions or inaction of Company to Federal Service for Supervision of Communications, Information Technology, and Mass Media or in court if Data Subject believes that Company is processing its Data in violation of Law requirements or otherwise violates it rights and freedoms;

— to protect own rights and legitimate interests, including compensation for damages and / or compensation for moral harm in the courts.

Company is required in Data processing:

  •  provide information regarding Data processing to Data Subject upon his request or lawfully provide a refusal within thirty days from date of request receipt by Data Subject or his representative;

  • explain to Data Subject legal consequences of refusal to provide Data if its provision is mandatory in accordance with the Federal law;

  • provide Data Subject with the following information before Data processing:
    1) name or last name, patronymic and Company address or its representative;
    2) purpose of data processing and its legal basis;
    3) prospective users of Data;
    4) Data Subjects rights established by law;
    5) source of Data acquisition.

  • take necessary legal, organizational and technical measures or ensure their acceptance to protect Data from unauthorized or accidental access to them, destruction, modification, blocking, copying, provision, dissemination of Data, as well as from other illegal actions with respect to Data;

  • publish on the Internet and provide unrestricted access using the Internet to a document that defines its policy regarding Data processing, to information about current requirements for data protection;

  •  provide Data Subjects and / or their representatives with free of charge opportunity to get acquainted with Data when handling relevant request within 30 days from receipt date of such request;

  •  block illegally processed Data pertaining to Data Subject, or ensure that they are blocked (if data processing is performed by another person acting on behalf of Company) from application time or request receipt for verification period, in case Data is illegally processed when Data Subject is accessed or his representative, or, upon request, to Data Subject or his representative or authorized body for protection of rights of personal Data Subjects;

  • clarify Data or ensure clarification (if data processing is performed by another person acting on behalf of Company) within 7 working days from information submission date and to remove data blocking in case of confirmation of Data inaccuracy on the basis of information submitted by Data Subject or his representative;

  •  stop improper Data processing or ensure that Data is not illegally processed by a person acting on behalf of Company in case that undocumented data processing is performed by Company or a person acting on the basis of Company Agreement within a period not exceeding 3 business days from such disclosure date;

  • terminate Data processing or ensure its termination (if data processing is performed by another person acting under Company Agreement) and destroy Data or ensure its destruction (if data processing is performed by another person acting under Company Agreement) upon purpose achievement of Data processing if the other is not provided by the Agreement, party of which, beneficiary or guarantor is Data Subject, in case achievement of Data processing purpose;

  • stop Data processing or ensure its termination and destroy Data or ensure its destruction in case Data Subject withdraws consent to process Data if Company is not entitled to process Data without Data Subject consent;

  • keep a record book of personal data requests, in which requests of Data Subjects for receiving Data should be recorded, as well as facts of providing Data for these requests.

Children's Information

Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

SETALABS does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

Online Privacy Policy Only

This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they shared and/or collect in SETALABS. This policy is not applicable to any information collected offline or via channels other than this website.

Consent

By using our website, you hereby consent to our Privacy Policy and agree to its Terms of Service.