Capycafe

Daily from 10.00 to 22.00

Moscow, Sokolniki Park, Guid Park

Coordinates: 55.792607, 37.668632

Write to us

PERSONAL DATA PROCESSING AND PRIVACY POLICY
KHROOM-KHROOM LLC

Version dated 14 August 2026

1. General Provisions

1.1. This Personal Data Processing and Privacy Policy (the "Policy") sets forth the procedure and terms governing the processing of personal data by KHROOM-KHROOM LLC (the "Operator") in connection with the use of the Capybara Café website available at https://capycafe.ru (the "Website"), as well as in connection with the purchase of tickets and gift certificates, submission of applications and inquiries, and use of other Website services.

1.2. This Policy has been developed in accordance with Federal Law No. 152-FZ dated 27 July 2006 "On Personal Data", the Law of the Russian Federation "On Protection of Consumer Rights", the Federal Law "On Advertising", and other applicable laws and regulations of the Russian Federation.

1.3. This Policy is a publicly available document and is made freely accessible on the Website.

1.4. By using the Website, submitting an application, or purchasing a ticket or gift certificate, the user confirms that they have reviewed this Policy. Where the processing of personal data requires the consent of the personal data subject, such consent shall be obtained separately from other documents and confirmations.

1.5. This Policy applies solely to the Website and the Operator's services. The Operator does not control and shall not be liable for third-party websites or services that a user may access through links on the Website, unless otherwise expressly required by law.

2. Definitions

2.1. "Personal Data" means any information relating directly or indirectly to an identified or identifiable individual.

2.2. "Processing of Personal Data" means any operation or set of operations performed on personal data, including collection, recording, organization, accumulation, storage, updating, retrieval, use, transfer, anonymization, blocking, deletion, and destruction.

2.3. "Operator" means KHROOM-KHROOM LLC, which independently or jointly with other persons organizes and/or carries out the processing of personal data.

2.4. "Personal Data Subject" means a Website user, purchaser of a ticket or gift certificate, café visitor, purchaser representative, event participant, person submitting an inquiry, or any other individual to whom personal data relates.

2.5. "Cookies" means small data files stored on a user’s device and used for Website operation, analytics, personalization, and other purposes specified in this Policy.

3. Operator Details

3.1. Operator: KHROOM-KHROOM LLC.

Taxpayer Identification Number (INN): 9734023463. Tax Registration Reason Code (KPP): 773401001. Primary State Registration Number (OGRN): 1267700063564.

Registered address: Premises 11B/3, Building 1, 2 3rd Khoroshevskaya Street, Khoroshevo-Mnevniki Municipal District, Moscow 123308, Russian Federation.

Actual café address: Hyde Park, Sokolniki Park, Moscow. Coordinates: 55.792607, 37.668632.

E-mail for personal data inquiries, claims, refunds, tickets, and certificates: info@capycafe.ru.

Telephone: +7 (966) 276-00-00.

Café opening hours: daily from 10:00 to 22:00. Customer support hours: daily from 10:00 to 21:00. The first Monday of each month is a sanitary day: the animal area is closed and only the café operates. Inquiries, refunds, and rescheduling requests are processed on business days from 10:00 to 18:00.

3.2. Requests from personal data subjects shall be submitted using the contact details specified in Clause 3.1 of this Policy.

4. Categories of Personal Data Subjects

4.1. The Operator may process personal data relating to the following categories of data subjects:

4.1.1. Website visitors.

4.1.2. Users purchasing tickets to visit the café.

4.1.3. Users purchasing gift certificates.

4.1.4. Users submitting applications for events, café rental, private session buyouts, photo shoots, or closed/private events.

4.1.5. Users submitting inquiries through feedback forms, e-mail, messaging services, or other communication channels.

4.1.6. Recipients of service notifications relating to ticket or certificate purchases, rescheduling, cancellation, or confirmation of a visit.

4.1.7. Café visitors entering areas covered by video surveillance.

4.1.8. Café visitors who may appear in general photo and video recordings, as well as visitors who have provided separate consent to the use of their image where such consent is required by law.

4.1.9. Minor café visitors, where processing of their personal data is necessary and is carried out through their legal representatives or with the consent of their legal representatives.

5. Principles of Personal Data Processing

5.1. Personal data shall be processed lawfully and fairly.

5.2. Personal data processing shall be limited to the achievement of specific, predetermined, and lawful purposes.

5.3. Personal data shall not be processed in a manner incompatible with the purposes for which it was collected.

5.4. Only personal data relevant to the stated purposes of processing shall be processed.

5.5. The content and volume of personal data processed shall correspond to the stated purposes of processing. The Operator shall not process excessive personal data.

5.6. The Operator shall ensure the accuracy, sufficiency, and, where necessary, relevance of personal data.

6. Purposes of Personal Data Processing

6.1. The Operator processes personal data for the following purposes:

6.1.1. Operation and functionality of the Website.

6.1.2. Processing purchases of tickets to visit the café.

6.1.3. Processing purchases of gift certificates.

6.1.4. Confirming purchases and sending electronic tickets, electronic certificates, rescheduling or cancellation notices, and visit reminders.

6.1.5. Organizing café visits, booking visit dates and times, and recording the number of guests.

6.1.6. Processing applications for events, café rental, private events, photo shoots, and other special visit formats.

6.1.7. Accepting payments, issuing refunds, and generating and sending fiscal receipts.

6.1.8. Reviewing inquiries, claims, refund requests, rescheduling requests, and requests to restore certificates.

6.1.9. Ensuring the safety and security of visitors, employees, animals, and the Operator’s property, including through video surveillance.

6.1.10. Taking photographs and videos of the general environment, animals, interiors, employees, and visitors, and using such materials in the Operator’s public materials where the visitor has consented or another lawful basis exists, if consent is required by law.

6.1.11. Sending advertising and informational communications where the user has provided separate prior consent.

6.1.12. Analyzing Website traffic, improving Website operation, and evaluating advertising effectiveness and user experience where the appropriate lawful grounds and user consents exist, if such consents are required by law.

6.1.13. Compliance with obligations imposed by the laws of the Russian Federation, including accounting, tax, cash-register, consumer protection, and personal data requirements.

7. Categories of Personal Data Processed

7.1. Depending on the manner in which the user interacts with the Website and the Operator, the following personal data may be processed:

7.1.1. User name.

7.1.2. Telephone number.

7.1.3. E-mail address.

7.1.4. Date and time of visit.

7.1.5. Number of guests.

7.1.6. Comments relating to an order, booking, or application.

7.1.7. Information concerning a promotional code, certificate, order number, ticket number, or booking number.

7.1.8. Payment information: amount, payment status, payment method, payment identifier, and information required to process a refund. The Operator does not store users’ full bank card details. The purchaser’s full banking details may be requested and processed additionally solely for the purpose of issuing a refund where the refund cannot be made using the original payment method or where such details are required for the refund.

7.1.9. Information concerning the purchase of a ticket or certificate, an event, rescheduling, cancellation, or refund.

7.1.10. Photo and video materials depicting visitors where such materials are created by the Operator’s personnel.

7.1.11. Images of visitors captured in video-surveillance areas within the café and/or contact area.

7.1.12. Technical data: IP address, browser, device, operating system, language, date and time of visit, referral source, cookie identifiers, information about actions taken on the Website, and web analytics data.

7.2. A telephone number and e-mail address, as well as other data necessary to complete a booking or purchase and send confirmation, are mandatory for the purchase of a ticket or certificate.

7.3. The Operator does not intentionally process biometric personal data.

7.4. The Operator does not intentionally process special categories of personal data.

8. Legal Grounds for Processing Personal Data

8.1. The Operator processes personal data on the following legal grounds:

8.1.1. Performance of a contract to which the personal data subject is a party, or entering into a contract at the initiative of the personal data subject.

8.1.2. Compliance with obligations imposed on the Operator by the laws of the Russian Federation.

8.1.3. Consent of the personal data subject, where processing is based on consent.

8.1.4. Exercise of the rights and legitimate interests of the Operator or third parties, provided that the rights and freedoms of the personal data subject are not thereby infringed.

8.2. Advertising communications, advertising cookies, advertising pixels, and other marketing tools shall be used only with the user’s prior consent where such consent is required by law.

8.3. Consent to personal data processing shall be obtained separately from acceptance of the public offer, visitor rules, and other documents where separate consent is required by law.

9. Procedure and Conditions for Personal Data Processing

9.1. Personal data shall be processed both by automated means and without the use of automated means.

9.2. The Operator may collect, record, organize, accumulate, store, update, use, transfer, anonymize, block, delete, and destroy personal data.

9.3. The Operator shall maintain the confidentiality of personal data and shall not disclose it to third parties without a lawful basis.

9.4. Access to personal data shall be granted only to persons who require such access to perform their employment duties, contractual obligations, or assignments from the Operator.

9.5. According to the Operator’s information, café administrators have access to applications and purchaser data. Where necessary, access may also be granted to accounting personnel, technical specialists, contractors, payment services, booking services, fiscal data operators, and other persons to the extent required for the performance of their respective functions.

10. Localization of Personal Data

10.1. When collecting personal data of citizens of the Russian Federation, including through the Internet, the Operator shall ensure that such personal data is recorded, organized, accumulated, stored, updated, and retrieved using databases located within the territory of the Russian Federation, except in cases provided for by the laws of the Russian Federation.

11. Transfer of Personal Data to Third Parties

11.1. The Operator may transfer personal data to third parties only to the extent necessary to achieve the purposes of processing and where a lawful basis exists.

11.2. Personal data may be transferred to the following categories of third parties:

11.2.1. A payment service provider and/or acquiring bank, for accepting payments, confirming payments, and issuing refunds.

11.2.2. An online cash-register service, fiscal data operator, and other services necessary to generate and send fiscal receipts.

11.2.3. An online booking and/or ticketing service, for selecting the date and time of a visit, issuing a ticket or certificate, and confirming a booking.

11.2.4. A corporate e-mail and e-mail notification service, for sending electronic tickets, certificates, purchase confirmations, visit reminders, and rescheduling or cancellation notices.

11.2.5. A hosting provider and technical contractors, for operation of the Website and technical support.

11.2.6. Web analytics and mapping services, for traffic analytics, Website improvement, and display of the café’s location, subject to the existence of the necessary lawful grounds.

11.2.7. Government authorities and other authorized persons, in the cases and in accordance with the procedures prescribed by the laws of the Russian Federation.

11.3. According to the Operator’s information, the following services may be used on the Website:

11.3.1. Web analytics service: Yandex.Metrica.

11.3.2. Mapping service: Yandex Maps.

11.3.3. Acquiring bank / payment service: JSC "TBank" (INN 7710140679, OGRN 1027739642281, BIC 044525974).

11.3.4. Online booking service: Restoplace LLC (INN 1650381531, KPP 165001001, OGRN 1191690061045; registered address: Office B103, Building 91, Mashinostroitelnaya Street, Naberezhnye Chelny, Republic of Tatarstan 423824, Russian Federation; e-mail: info@restoplace.cc).

11.3.5. Fiscal data operator: Platforma OFD / Evotor OFD LLC (INN 9715260691).

11.3.6. Corporate mail / Business Mail service and hosting provider: Registrar of Domain Names REG.RU LLC (INN 7733568767, KPP 774301001, OGRN 1067746613494; registered address: Building 3, 72 Leningradsky Prospekt, Aeroport Municipal District, Moscow 125315, Russian Federation).

11.3.7. Advertising pixels and retargeting services: as of the date of this version of the Policy, no specific services are listed. If such services are introduced, they shall be used only where the user has provided the appropriate consent and such services are identified in the then-current version of the Policy and/or cookie notice.

11.4. Where the Operator engages third parties to process personal data on its behalf, the relevant contractual terms shall require compliance with confidentiality and personal data protection requirements.

12. Cross-Border Transfers of Personal Data

12.1. As of the date of this version of the Policy and according to the Operator’s information, no cross-border transfer of personal data takes place in connection with operation of the Website.

12.2. If the Operator intends in the future to use services involving cross-border transfers of personal data, the Operator shall, before commencing such transfers, comply with the requirements of the laws of the Russian Federation, including submitting a notification to the competent authority for the protection of personal data subjects’ rights where and in the manner required by law.

13. Cookies, Analytics, and Advertising Technologies

13.1. The Website uses cookies and similar technologies.

13.2. Cookies may be used to operate the Website, save user preferences, facilitate purchases of tickets or certificates, operate booking services, analyze traffic, and improve Website quality. Advertising, retargeting, and advertising pixels shall be used only with the user’s separate consent where such consent is required by law.

13.3. The Website may use technical, analytical, and functional cookies. Advertising cookies and advertising pixels shall be used only with the user’s separate consent if they are enabled on the Website.

13.4. Technical cookies are necessary for the proper operation of the Website and its basic functions.

13.5. Analytical cookies are used, inter alia, through Yandex.Metrica and subject to the consent settings selected by the user where such settings are implemented on the Website.

13.6. Advertising cookies, advertising pixels, and other tracking tools shall be used only where a lawful basis exists and, where required, with the user’s consent.

13.7. A user may restrict or disable cookies in their browser settings. Disabling cookies may result in certain Website functions operating incorrectly.

13.8. The Website uses a cookie banner/notice. Where advertising cookies, advertising pixels, or retargeting are used, the Operator shall provide a mechanism to obtain and record the user’s consent to such processing.

14. Video Surveillance

14.1. Video surveillance may be conducted within the café premises and/or contact area.

14.2. Video surveillance is conducted for the purpose of protecting visitors, employees, animals, and the Operator’s property, and for resolving disputed situations.

14.3. The Operator shall display notices regarding video surveillance in the areas where it is conducted.

14.4. Video-surveillance footage shall not be used for public dissemination, advertising, or publication on social media without a separate lawful basis.

15. Photography and Video Recording of Visitors

15.1. Visitors may take personal photographs and videos in the café subject to the visitor rules, including restrictions on flash photography, professional equipment, tripods, and other restrictions established by the Operator.

15.2. Café personnel may photograph and record the general environment, animals, interiors, employees, and visitors. Such materials may be used by the Operator on the Website, on social media, and in CapyCafe advertising and informational materials.

15.3. The Operator endeavors to use such materials so that visitors incidentally appearing in a frame are not the principal subject of the recording. A visitor who does not wish to appear in photo or video materials may notify a café administrator before the session begins.

15.4. Publication of materials in which a visitor is the principal subject, appears in close-up, gives a testimonial, poses, participates in a staged shoot, or is otherwise clearly singled out in the frame shall be carried out with the visitor’s separate consent where such consent is required by law. In relation to minor visitors, consent to publication of photo and video materials shall be given by the legal representative.

16. Minor Visitors

16.1. The café’s contact area is open to visitors aged 3 years and older.

16.2. Visitors under 14 years of age may enter the contact area only when accompanied by an adult.

16.3. The Operator does not intentionally collect personal data of minors through the Website without the participation of their legal representatives.

16.4. Where personal data of a minor must be processed in connection with a visit, event, photography, or video recording, such processing shall be carried out through the minor’s legal representative or with the legal representative’s consent where such consent is required by law.

17. Advertising Communications and Service Messages

17.1. The Operator sends users service messages necessary for performance of contracts and provision of services, including purchase confirmations, electronic tickets, electronic certificates, visit reminders, rescheduling or cancellation notices, fiscal receipts, and responses to inquiries.

17.2. Service messages shall not constitute advertising communications where they relate to contract performance, a purchase, booking, rescheduling, cancellation, refund, or other mandatory user notification.

17.3. Advertising communications, including messages concerning promotions, promotional codes, prize draws, discounts, and special offers, shall be sent only with the user’s separate prior consent where such consent is required by law.

17.4. A user may unsubscribe from advertising communications using the method specified in the relevant message or by contacting the Operator at info@capycafe.ru.

18. Personal Data Retention Periods

18.1. Personal data shall be retained no longer than necessary to achieve the purposes of processing, unless a longer retention period is prescribed by the laws of the Russian Federation, a contract, or another lawful basis.

18.2. The principal retention periods are set out in the table below.

Purpose of ProcessingCategories of DataLegal BasisRetention Period
Purchase of tickets and certificates; bookingName, telephone, e-mail, visit date and time, number of guests, order/ticket/certificate number, payment statusContract / pre-contractual stepsFor the period required to perform obligations and thereafter within periods necessary for claims, accounting, and statutory requirements.
Payments, receipts, refundsPayment information, amount, payment method, transaction identifiers, contact details for sending the receiptContract; lawFor the periods prescribed by accounting, tax, and cash-register legislation and applicable limitation periods.
Inquiries and claimsName, telephone, e-mail, inquiry text, order/certificate detailsLegitimate interest; law; contractUntil the inquiry is resolved and thereafter within the applicable limitation period.
Service notificationsTelephone, e-mail, order, ticket, certificate, rescheduling, or cancellation informationContractFor the period required to perform obligations and thereafter for the period necessary to evidence performance.
Advertising communicationsE-mail and consent/unsubscribe informationConsentUntil consent is withdrawn or the mailing is discontinued.
Video surveillanceImages of visitors in video-surveillance areasLegitimate interest; securityAs determined by the Operator’s internal rules, unless longer retention is required in connection with an incident or claim.
Photo and video materials for publicationImages of visitorsConsent or other lawful basisUntil consent is withdrawn, use of the material ceases, or the processing purpose is achieved.
Cookies and analyticsIP address, cookie identifiers, browser/device data, Website eventsConsent / legitimate interest depending on cookie typeWithin the retention periods configured for the relevant services and/or until consent is withdrawn.

19. Rights of Personal Data Subjects

19.1. A personal data subject shall have the right to:

19.1.1. Obtain information concerning the processing of their personal data.

19.1.2. Require correction, blocking, or destruction of personal data where the data is incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary for the stated processing purpose.

19.1.3. Withdraw consent to personal data processing where processing is based on consent.

19.1.4. Opt out of advertising communications.

19.1.5. Challenge the Operator’s acts or omissions before the competent authority for the protection of personal data subjects’ rights or before a court.

20. Procedure for Personal Data Subject Requests

20.1. To exercise their rights, a personal data subject may submit a request by e-mail to info@capycafe.ru.

20.2. Postal requests shall be sent to the Operator’s registered address: Premises 11B/3, Building 1, 2 3rd Khoroshevskaya Street, Khoroshevo-Mnevniki Municipal District, Moscow 123308, Russian Federation.

20.3. A request must contain information sufficient to identify the applicant and confirm that the Operator processes the applicant’s personal data: name, telephone number, e-mail address, order, ticket, or certificate number where available, and the substance of the request.

20.4. The Operator shall provide information to the personal data subject or their representative within 10 business days from the date of receipt of the request or inquiry.

20.5. The above period may be extended by no more than 5 business days, provided that the Operator sends the personal data subject a reasoned notice stating the grounds for the extension.

21. Destruction of Personal Data

21.1. Personal data shall be destroyed or anonymized upon achievement of the processing purposes, withdrawal of consent, expiration of retention periods, discovery of unlawful processing, or in other cases prescribed by the laws of the Russian Federation.

21.2. Personal data shall be destroyed as follows:

21.2.1. For data in information systems: by deletion, erasure, anonymization, or another method preventing further use of the data to identify the personal data subject.

21.2.2. For data on physical media: by destroying the medium or removing the information in a manner preventing its recovery.

21.3. In the cases and manner prescribed by the competent authority, destruction of personal data shall be documented. Where personal data is processed without automated means, a personal data destruction certificate shall be prepared. Where personal data is processed using automated means, destruction shall be evidenced by a personal data destruction certificate and an extract from the event log of the personal data information system, where such an extract is applicable to the relevant information system.

21.4. Documents evidencing destruction of personal data shall be retained by the Operator for the period prescribed by applicable requirements.

22. Personal Data Protection Measures

22.1. The Operator shall implement the necessary legal, organizational, and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, and other unlawful actions.

22.2. Depending on applicability and the systems used, the Operator shall implement access restrictions; appoint persons responsible for personal data processing; maintain access records and controls; use passwords and other security measures; perform backups; use anti-virus protection; update software; impose contractual confidentiality obligations on persons with access to personal data; and take other measures necessary to protect personal data.

23. Incident Response

23.1. Where unlawful or accidental transfer, provision, dissemination, or access to personal data is identified and such event results in a violation of personal data subjects’ rights, the Operator shall act in accordance with the procedures and time limits prescribed by the laws of the Russian Federation.

23.2. Where the Operator is required to notify the competent authority, it shall submit an initial incident notification within 24 hours after discovery of the incident and a notification of the results of the internal investigation within 72 hours after discovery of the incident.

24. Amendments to the Policy

24.1. The Operator may amend this Policy.

24.2. A new version of the Policy shall take effect upon publication on the Website unless otherwise provided in the new version.

24.3. The current version of the Policy shall be made freely available on the Website.

25. Operator Details

KHROOM-KHROOM LLC.

INN: 9734023463. KPP: 773401001. OGRN: 1267700063564.

Registered address: Premises 11B/3, Building 1, 2 3rd Khoroshevskaya Street, Khoroshevo-Mnevniki Municipal District, Moscow 123308, Russian Federation.

Actual café address: Hyde Park, Sokolniki Park, Moscow.

E-mail: info@capycafe.ru.

Telephone: +7 (966) 276-00-00.