WGM
← HomeRUEN

Privacy Policy of the WGM Service

Version dated June 25, 2026

PrivacyTermsCookieDPA

This Privacy Policy describes how personal data is processed when you use the WGM (Website Growth Manager) subscription-based online service, available at https://wgm.49port.ru. WGM is a multi-tenant SaaS platform for website owners and agencies: technical and SEO audit of a website, semantic clustering, rank tracking, OAuth-based connection of the client's official analytics, AI recommendations, safe application of changes to the client's website (write-back) only after the client's explicit approval, and optionally GEO features (brand visibility in AI assistants). The service is intended for users in the Russian Federation and in other countries; accordingly, this Policy is drafted to comply both with Russian Federal Law No. 152-FZ "On Personal Data" and with the EU General Data Protection Regulation (GDPR). Effective date: June 25, 2026. This English version is provided for convenience; in case of any discrepancy, the Russian-language text prevails.

1. Who is the operator (controller) and contact details

The operator of personal data and owner of the WGM service is:

  • Individual Entrepreneur Marina Vladimirovna Sleptsova
  • INN: 561407059668
  • OGRNIP: 323508100225874
  • Address: Vidnoe, Moscow Region, Russia
  • Postal address for written requests of data subjects: Vidnoe, Moscow Region, Russia (the full postal address is available on request via the contact email below)
  • Contact email (including for data-related requests): ya@49port.ru

For any questions regarding the processing of personal data, the exercise of data subject rights, and this Policy, you may contact us at the email address above. Written requests from data subjects are also accepted at the operator's postal address in Vidnoe, Moscow Region, Russia.

2. Data processing roles: controller and processor

WGM acts in two distinct roles depending on the category of data.

With respect to account and user data (name, email address, organization and project details, activity logs, IP address, cookies, and similar data), WGM acts as the operator (a controller under GDPR terminology): it independently determines the purposes and means of processing such data.

With respect to data that the client connects or uploads about ITS OWN website and analytics (metrics from Google Search Console, Google Analytics 4, Yandex.Webmaster, Yandex.Metrica, the content of the client's website pages, OAuth tokens granting access to the client's analytics), WGM acts as a processor on behalf of the client: it processes such data on the client's instructions and for the purpose of providing the service. The terms of such processing are governed by a separate Data Processing Agreement (DPA), in which the client is the controller and WGM is the processor. If the client's website or analytics data contains personal data of third parties (for example, visitors to the client's website), the client, as controller, is responsible for having a lawful basis and for informing such individuals.

3. What data we collect

Account and user data:

  • user name;
  • email address;
  • password (stored only as a cryptographic hash, never in plain text);
  • organization details and created projects (websites);
  • user activity logs within the service;
  • IP address;
  • cookies and similar technologies.

Client website and analytics data (processed by WGM as a processor on the client's behalf):

  • URLs and content of the client's website pages (obtained by crawling);
  • metrics from Google Search Console, Google Analytics 4, Yandex.Webmaster, and Yandex.Metrica;
  • OAuth access and refresh tokens granting access to the client's analytics (stored in encrypted form);
  • audit results and generated recommendations.

Payment data: subscription payments are processed by payment providers. WGM does not store full payment card details. With respect to information about the fact of payment, subscription status, and related account records, WGM acts as the operator (controller); full payment card details are processed by the payment provider as a separate, independent operator (controller).

4. Purposes of processing and legal bases

We process personal data for the following purposes and on the following legal bases under Article 6 GDPR, as well as in accordance with the requirements of Federal Law No. 152-FZ.

  • Registration and maintenance of the account and provision of the subscription service features (audit, clustering, rank tracking, analytics connection, AI recommendations, write-back, and optionally GEO) — basis: performance of the service contract (Article 6(1)(b) GDPR). The corresponding account data (name, email address, organization and project details) is processed on this basis;
  • Billing and processing of subscription payments — basis: performance of the contract (Article 6(1)(b) GDPR) and legal obligation to keep and retain financial records (Article 6(1)(c) GDPR);
  • Analytics, marketing, and recommendation technologies (cookies and related) — basis: the user's consent (Article 6(1)(a) GDPR);
  • Ensuring the security of the service, preventing fraud and abuse, and maintaining and improving the service — basis: the operator's legitimate interest (Article 6(1)(f) GDPR), namely the operator's legitimate interest in ensuring the information security of the service and its users, preventing fraud and abuse, and maintaining and improving the service. On this basis, in particular, the IP address and user activity logs are processed (for security purposes). You have the right to object to such processing as described in the data subject rights section;
  • Compliance with legal requirements (responding to lawful requests, retaining data for statutory periods) — basis: legal obligation (Article 6(1)(c) GDPR).

Legal bases and scope of processing under Federal Law No. 152-FZ. Categories of data subjects: users and representatives of clients; natural persons acting as representatives of organizations; and, with respect to client website and analytics data, third parties (visitors to clients' websites) for whom the client acts as controller. Methods of processing are mixed: with and without the use of automation tools. The list of operations performed on personal data (Part 3, Article 3 of FZ-152): collection, recording, systematization, accumulation, storage, updating (renewal, modification), retrieval, use, transfer (provision, access), blocking, deletion, destruction, and anonymization. Legal bases of processing under FZ-152: items 1–5 of Part 1, Article 6 (performance of a contract to which the data subject is a party; exercise of the functions and powers vested in the operator; the data subject's consent), and, where not contrary to law, the Constitution of the Russian Federation and other regulatory legal acts.

Processing of personal data of Russian citizens is carried out on the grounds provided for by Federal Law No. 152-FZ, primarily for the performance of a contract to which the data subject is a party, and on the basis of the data subject's consent where consent is required (for example, for optional cookies and marketing communications). Consent to the processing of personal data is given by the data subject freely, of their own will and in their own interest, and is specific, informed, conscious, and unambiguous; the method of obtaining consent (a checkbox in the relevant form or confirmation via the cookie banner) is indicated at the time it is obtained.

The terms on which the service is provided are set out in the Terms of Service; the processing of client website and analytics data is governed by the Data Processing Agreement (DPA); the use of cookies is governed by the Cookie Policy. This Policy applies together with those documents.

WGM makes no guarantee, express or implied, of any increase in traffic, improvement of rankings, or other promotion outcomes. The service provides analysis tools and recommendations; the decision to apply them rests with the client.

5. AI recommendations and automated processing

The service generates AI recommendations and audit results using automated data processing, including by engaging large language model (LLM) providers via the LiteLLM proxy.

These recommendations are informational and advisory in nature. Changes to the client's website (write-back, for example modifying title and meta description) are not applied automatically: they take effect only after the client's explicit prior approval. The service does not make any decisions in respect of users based solely on automated processing that produce legal effects concerning them or similarly significantly affect them within the meaning of Article 22 GDPR, because any changes are applied only after an explicit human decision (by the client). For questions relating to the use of AI recommendations and automated processing, you may contact us at the contact email address above to obtain an explanation, express your point of view, and contest the results.

6. Sub-processors and recipients of data (register)

To provide the service and on the client's behalf, we engage sub-processors and disclose data to the following categories of recipients:

  • Google (Google Search Console, Google Analytics 4) — connecting and retrieving the client's official analytics;
  • Yandex (Yandex.Webmaster, Yandex.Metrica, and related services) — connecting and retrieving the client's official analytics;
  • large language model (LLM) providers, accessed via the LiteLLM proxy — generating AI recommendations and GEO features;
  • payment providers — processing subscription payments;
  • email delivery service — delivering system and service emails;
  • error monitoring service — ensuring the stability and security of the service;
  • hosting and object storage providers (located in the Russian Federation) — hosting and storing data.

The specific names of sub-processors are maintained in a sub-processor register and may be updated. The current list is available upon request at the contact email address above.

7. International data transfers and localization in Russia

For users in the Russian Federation, the recording, systematization, accumulation, storage, updating, and retrieval of personal data of Russian citizens are carried out using databases located within the territory of the Russian Federation (Part 5, Article 18 of Federal Law No. 152-FZ).

Where personal data is transferred internationally under GDPR, such transfer is carried out with appropriate data protection safeguards in place, in particular on the basis of the EU Standard Contractual Clauses (SCC) or other mechanisms provided for by GDPR. Some recipients and infrastructure (including hosting in the Russian Federation, for which the European Commission has not adopted an adequacy decision) are located outside the European Economic Area; such transfers rely on the EU Standard Contractual Clauses (SCC) and supplementary measures. A copy of the applicable safeguards may be requested at the contact email address above.

Cross-border transfers of personal data of Russian citizens are carried out in compliance with Article 12 of Federal Law No. 152-FZ, including, where necessary, on the basis of the data subject's separate consent to the cross-border transfer and after notifying Roskomnadzor of the intention to carry out such transfer, where the recipient is located in a country that does not provide adequate protection of the rights of data subjects.

8. Retention periods

We retain personal data for as long as necessary to achieve the processing purposes set out in this Policy.

  • Account and project data — for the duration of the account and for the period following its closure necessary to fulfil contractual and legal obligations;
  • Client website and analytics data and OAuth tokens — for the duration of the relevant project/connection; tokens and secrets may be revoked and deleted by the client;
  • Financial and payment information — for the period required by applicable law for the retention of accounting and tax records;
  • Activity logs and technical logs — for the period necessary for security and incident investigation.

Once the purposes of processing have been achieved, or upon withdrawal of consent (in the absence of any other lawful basis for continued processing), personal data is destroyed or anonymized within a period not exceeding 30 days, unless a different period is established by law (Part 7 of Article 5 and Article 21 of Federal Law No. 152-FZ). Where consent is withdrawn or an account is deleted, data is handled in accordance with the data subject rights described below, subject to the operator's remaining legal obligations.

9. Security measures

The operator takes the legal, organizational, and technical measures provided for by Articles 18.1 and 19 of Federal Law No. 152-FZ, including appointing a person responsible for organizing the processing of personal data, adopting internal documents (a policy and local acts regarding the processing of personal data), assessing potential harm, determining threats to the security of personal data, and applying protection measures in accordance with the established protection level (taking into account Russian Government Decree No. 1119).

We apply organizational and technical measures to protect personal data, including:

  • encryption of secrets and OAuth tokens;
  • role-based access control (RBAC);
  • logging of actions and access;
  • data backups;
  • tenant isolation between customers.

10. Personal data incident response

If it is established that there has been an unlawful or accidental transfer (provision, dissemination, or access) of personal data that has resulted in a breach of data subjects' rights, the operator notifies Roskomnadzor within 24 hours of such incident and within 72 hours of the results of the internal investigation and of the persons whose actions caused the incident (Part 3.1, Article 21 of Federal Law No. 152-FZ).

The operator interacts with the State System for Detecting, Preventing, and Mitigating the Consequences of Computer Attacks (GosSOPKA) in the established manner. Where WGM acts as a processor on behalf of the client, it promptly notifies the client-controller of any incident of which it becomes aware affecting data processed on the client's behalf.

11. Data subject rights and how to exercise them

Under GDPR, you have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data (the "right to be forgotten");
  • restrict processing;
  • data portability;
  • object to processing, including processing based on legitimate interest; you also have the right to object at any time to processing for direct marketing purposes, and following such objection we will cease processing for those purposes;
  • withdraw previously given consent at any time;
  • not be subject to a decision based solely on automated processing which produces legal effects (Article 22 GDPR);
  • lodge a complaint with a data protection supervisory authority.

Under Federal Law No. 152-FZ, you have the right to:

  • obtain information concerning the processing of your personal data (including information about the operator, the purposes and legal bases of processing, the list of personal data processed, the processing periods, and other information provided for by law);
  • access your personal data;
  • have your personal data clarified;
  • have your personal data blocked;
  • have your personal data deleted;
  • withdraw consent to processing;
  • appeal the operator's actions or inaction to Roskomnadzor or in court.

To exercise any of these rights, send a request to the contact email address above or to the operator's postal address. We will respond without undue delay and in any event within one month of receipt of the request; this period may be extended by a further two months where necessary, taking into account the complexity and number of requests, of which we will inform you (Article 12(3) GDPR). For Russian citizens, the time limits set by Federal Law No. 152-FZ apply: information on how to exercise rights and a response to a request are provided within 10 business days of the request (extendable by no more than 5 business days, with notice of the reasons for the extension). Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.

If your request concerns client website or analytics data for which WGM acts as a processor, we will forward such a request to the relevant client-controller or provide reasonable assistance to that controller in handling it, since the legal basis for this data is determined by the client.

12. Cookies

We use cookies and similar technologies in the following categories:

  • strictly necessary cookies (authentication, session maintenance, security) — set without consent, as the service cannot function without them;
  • analytics cookies and, where applicable, marketing and recommendation technologies — set only after you have given consent via the cookie banner.

Consent to optional cookies may be changed or withdrawn at any time in the cookie settings. A detailed description of the cookies used is provided in a separate Cookie Policy.

13. Recommendation technologies

If the service uses recommendation technologies within the meaning of Article 10.2-2 of Federal Law No. 149-FZ, we inform you accordingly and describe the rules governing their use. The primary way to opt out of recommendation technologies is to manage cookies and the corresponding service settings.

14. Children and age requirements

The service is intended for use by website owners and agencies and is not directed at children. We do not knowingly collect personal data of minors below the age at which they may independently provide consent under applicable law. If you become aware that a minor's data has been provided without appropriate consent, please notify us at the contact address so that it can be deleted.

15. Compliance with Google API policies (Limited Use)

WGM's use and transfer to any other app of information received from Google APIs (including Google Search Console and Google Analytics) will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

  • access to Google data is requested as read-only and is used solely to provide and improve the features the user requested (showing the user's own statistics in the dashboard and generating recommendations);
  • we do not use data obtained through Google APIs for advertising, and we do not sell it;
  • we do not transfer Google data to third parties except as necessary to provide or improve the service, to comply with applicable law, for security purposes, or with the user's consent;
  • humans do not read data obtained through Google APIs, except where the user has given explicit consent, it is necessary for security purposes (e.g. investigating abuse), it is required by applicable law, or the data has been aggregated or de-identified and is used for internal operations in accordance with applicable requirements.

16. Changes to this Policy

We may update this Policy from time to time. The current version is always published at the service address. This Policy is a publicly available document; the operator ensures unrestricted access to it by publishing it at the service address (Part 2, Article 18.1 of Federal Law No. 152-FZ). For material changes affecting the purposes or legal bases of processing, we will notify users in advance (e.g. by email or in-service notice) and, where required, obtain renewed consent. The effective date indicates the version of the Policy currently in force.

17. Effective date

This Privacy Policy takes effect on June 25, 2026.