Privacy Policy
Last Updated: October 17, 2025
This Privacy Policy describes how personal data is collected, used, shared, and protected in connection with the website located at peterrogov.com (the "Website") and related services. It outlines the categories of data processed, the purposes and legal bases, the recipients of data, retention periods, and the choices available to data subjects. This Policy is intended to comply with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and other applicable laws.
Controller and Contact
The party responsible for the processing of personal data is the data controller.
- Data Controller: Peter Rogov (Rogov Petr IE)
- Registered Address: Hanrapetutyan str., 39, Kentron 0010, Yerevan, Armenia
- Contact: Submit requests via contact form.
Categories of Personal Data
Personal data processed by the Website generally falls into the categories below. Specific data may vary depending on features used.
- Technical data: IP address, device and browser details, and connection metadata collected automatically.
- Security and anti‑bot signals: challenge results, token responses, and related telemetry required to detect and prevent abuse.
- Communications: content submitted when contacting support or otherwise communicating.
- AI interactions: prompts, messages, conversation transcripts, and any files or content you choose to submit when using AI‑powered features (e.g., conversational assistant).
- AI usage and telemetry: timestamps, interaction metadata, approximate location derived from IP, feature flags, error logs, and quality signals used for monitoring and troubleshooting.
- AI outputs and derived data: generated responses and limited derived summaries or extracted fields necessary to fulfill your request (e.g., booking or follow‑up context).
Sources of Personal Data
Personal data is obtained either directly from the user (e.g., through forms or interactive features) or automatically when interacting with the Website.
- Direct provision by the user via features of the Website.
- Automatic collection via strictly necessary cookies and security tooling.
- User submissions to AI‑powered features (e.g., a conversational assistant), including messages and uploaded files.
- Processing by third‑party AI model providers acting on the controller’s instructions to generate responses.
Purposes and Legal Bases (GDPR Art. 6)
Personal data is processed only where a lawful basis applies and for the purposes described below.
- Operation of the Website and interactive features (legitimate interests).
- Security, fraud prevention, and bot detection (legitimate interests).
- Responding to inquiries (legitimate interests).
- Compliance with legal obligations (legal obligation).
- Providing AI‑powered features and services, including answering questions about Peter Rogov, portfolio, offerings, and assisting with actions such as submitting requests or booking engagements (legitimate interests; contract where necessary to fulfill your request).
- Monitoring, troubleshooting, and improving quality and safety of AI‑powered features (legitimate interests).
Processing Not Undertaken
The following activities are not conducted with respect to personal data processed by the Website.
- Personal data is not sold or rented.
- Personal information is not “sold” or “shared” as defined under California law (CPRA).
- Behavioral advertising and cross‑site tracking are not conducted.
- Profiling or automated decision‑making producing legal effects is not performed.
- Marketing communications are not sent without separate consent.
Use of Artificial Intelligence
The Website uses artificial intelligence (AI) to provide certain features and services to users. Where AI is used to provide services, the processing described in the other sections of this Policy applies.
For a functional description of the conversational assistant and related user obligations, see the Terms and Conditions.
What is collected via AI‑powered features
- Content you submit, including messages, prompts, and files/attachments.
- Conversation metadata (timestamps, feature flags, message counts) and technical data as described in Categories above.
- AI outputs (generated responses) and, where necessary, limited derived summaries or extracted fields to carry out your request.
Use of AI data
-
To generate responses and provide the AI‑powered experience you request.
-
To facilitate follow‑up actions (e.g., drafting a message, routing a request, or assisting with a booking you initiate).
-
To monitor, detect abuse, ensure safety, and improve reliability and quality of service.
-
Market AI tools and large language models are used to process AI interactions. Additional or alternative providers may be used from time to time.
-
Where possible, strict privacy protections are implemented in contracts and configuration, including requirements for non‑disclosure, prohibitions on using your data for model training or unrelated purposes, and restrictions on retention. If a provider cannot meet these requirements, alternative safeguards will be implemented or that provider will not be used for AI‑powered interactions.
User responsibilities and prohibited submissions
- Do not submit sensitive personal data, health or financial information, government IDs, or confidential third‑party information to AI‑powered features.
- Only submit content you are legally permitted to share with Controller and service providers for processing in order to fulfill your request.
Retention for AI interactions
- AI interactions (messages, files, transcripts, metadata) may be retained for up to 12 months (1 year) for quality assurance, security, and service improvement, unless a longer period is required by law or a shorter period is required by applicable regulations.
Nothing in this section authorizes AI‑powered features to make decisions that produce legal or similarly significant effects about you; these features provide advisory outputs only.
Disclosure to Third Parties
Personal data may be disclosed to trusted service providers acting on documented instructions of the data controller for hosting, security, and support. Such processors are bound by confidentiality and data protection obligations and may not use personal data for their own purposes.
- Cloudflare Turnstile (independent controller): processes limited technical data for bot detection and security (e.g., IP address, TLS fingerprints, user‑agent, site identifiers). Cloudflare’s Turnstile Privacy Policy: https://www.cloudflare.com/turnstile-privacy-policy/.
- Hosting and content delivery providers (processors): infrastructure and delivery of the Website, acting under instructions of the controller.
- AI model providers (processors): receive interaction content (e.g., prompts, messages, files) as necessary to generate responses under the controller’s instructions. Providers are configured to apply strict privacy protections where available, including prohibitions on using data for model training and restrictions on retention. AI provider privacy policies and data usage notices may be listed and updated in this section from time to time.
Cookies (Strictly Necessary Only)
The Website uses only strictly necessary cookies that are required to provide requested services and to ensure security. Under GDPR and the ePrivacy Directive, these cookies are exempt from consent requirements.
- Purposes include session management (if applicable), CSRF protection, and security/bot detection.
- Analytics, advertising, and social media cookies are not used.
- Users may block cookies through browser settings; doing so may impair security protections or restrict access to interactive features of the Website.
- AI‑powered features may use a strictly necessary session mechanism (e.g., a session cookie or local storage key) to maintain conversation context you initiate; blocking this may limit functionality.
Retention
Personal data is retained only for as long as necessary for the purposes set out in this Policy, or as required by law, after which it is deleted or anonymized.
- Session/security data: retained until session or token expiry.
- Security logs/technical data: retained for 3 months for security monitoring and incident response.
- Contact form communications: retained for up to 12 months for follow‑up and record‑keeping.
- AI‑powered interactions (messages, files, transcripts, metadata): retained for up to 12 months (1 year) for quality assurance, troubleshooting, and safety monitoring.
Security Measures
Appropriate technical and organizational measures are implemented to protect personal data against unauthorized access, disclosure, alteration, or destruction. Measures include encryption in transit and at rest, CSRF protection, access controls, monitoring, and regular updates. No method of transmission or storage is entirely secure. For AI‑powered features, additional privacy engineering controls may include input validation and size limits, secret or obvious identifier redaction where feasible, least‑privilege scoping of model context, and contractual and technical restrictions with model providers to minimize unnecessary retention and prohibit training on your data.
Data Subject Rights
Under applicable law, data subjects have rights of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent (where applicable) and to lodge a complaint with a supervisory authority. To exercise rights, submit your request via the contact form. A response will be provided within one month of receipt, and additional information may be requested to verify identity. For data processed by Cloudflare via Turnstile, contact Cloudflare directly. You may also contact your local authority; a list of EU authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. If your request concerns AI‑powered interactions that were processed by third‑party model providers under the controller’s instructions, relevant deletion or access requests will, where applicable, be relayed or forwarded to those providers to facilitate your rights.
International Transfers
Personal data may be processed outside the EEA/UK, including in Armenia (controller location) and the United States (e.g., Cloudflare and AI model providers). Where required, appropriate safeguards such as the European Commission Standard Contractual Clauses (and UK equivalents) are applied, or adequacy decisions or other lawful mechanisms are relied upon. Additional contractual commitments are sought from AI model providers to prohibit training on your data and restrict retention where feasible.
Children
The Website is not intended for children under 16 years old. Personal data from children is not knowingly collected. If such collection is identified, the data will be deleted.
Changes to This Policy
This Policy may be updated to reflect changes in practices or legal requirements. Material changes will be communicated, and the “Last Updated” date will identify the current version.
Contact Information
Questions regarding privacy and the handling of personal data may be submitted via the contact form.