1. General Provisions
This personal data processing policy has been drawn up in accordance with the requirements of Federal Law No. 152-FZ of 27 July 2006 No. 152-FZ ‘On Personal Data’ (hereinafter referred to as the ‘Personal Data Act’) and sets out the procedures for the processing of personal data and the measures taken by KVASAR GROUP LLC (hereinafter referred to as the ‘Controller’) to ensure the security of personal data.
1.1. The Operator regards the observance of human and civil rights and freedoms when processing personal data, including the protection of the rights to privacy and personal and family confidentiality, as its primary objective and a prerequisite for carrying out its activities.
1.2. This policy of the Operator regarding the processing of personal data (hereinafter referred to as the ‘Policy’) applies to all information that the Operator may obtain about visitors to the website https://kvazar.info.
2. Key terms used in the Policy
2.1. Automated processing of personal data — the processing of personal data using computerised means.
2.2. Blocking of personal data — the temporary suspension of the processing of personal data (except where processing is necessary to verify the accuracy of the personal data).
2.3. Website — a collection of graphic and informational materials, as well as computer programmes and databases, ensuring their availability on the internet at the web address https://kvazar.info.
2.4. Personal data information system — a collection of personal data contained in databases, together with the information technology and technical resources that enable their processing.
2.5. Anonymisation of personal data — actions which result in it being impossible, without the use of additional information, to determine that the personal data relates to a specific User or other data subject.
2.6. Processing of personal data — any action (operation) or set of actions (operations) carried out with or without the use of automated means in relation to personal data, including the collection, recording, organisation, accumulation, storage, clarification (updating, amendment), retrieval, use, transfer (dissemination, provision, access), anonymisation, blocking, erasure and destruction of personal data.
2.7. Controller — a state body, a local authority, a legal entity or a natural person who, independently or jointly with other persons, organises and/or carries out the processing of personal data, as well as determines the purposes of the processing of personal data, the scope of personal data to be processed, and the actions (operations) carried out on personal data.
2.8. Personal data means any information relating directly or indirectly to an identified or identifiable User of the website https://kvazar.info.
2.9. Personal data authorised by the data subject for disclosure, — personal data to which an unlimited number of persons have been granted access by the data subject through the giving of consent to the processing of personal data authorised by the data subject for disclosure in accordance with the procedure laid down in the Personal Data Act (hereinafter referred to as ‘personal data authorised for disclosure’).
2.10. User — any visitor to the website https://kvazar.info.
2.11. Provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons.
2.12. Disclosure of personal data — any actions aimed at disclosing personal data to an unspecified group of persons (transfer of personal data) or to enable an unlimited group of persons to access personal data, including the publication of personal data in the media, posting on information and telecommunications networks, or providing access to personal data by any other means.
2.13. Cross-border transfer of personal data — the transfer of personal data to the territory of a foreign state to a public authority of a foreign state, a foreign natural person or a foreign legal entity.
2.14. Destruction of personal data — any actions resulting in the irreversible destruction of personal data, such that the content of the personal data cannot be subsequently recovered from the personal data information system and/or the physical media containing the personal data are destroyed.
3. Key rights and obligations of the Controller
3.1. The Controller has the right to:
— to receive from the data subject accurate information and/or documents containing personal data;
— in the event that the data subject withdraws their consent to the processing of personal data, or submits a request to cease the processing of personal data, the Controller is entitled to continue processing personal data without the data subject’s consent where there are grounds specified in the Personal Data Act;
— to determine independently the scope and list of measures necessary and sufficient to ensure compliance with the obligations set out in the Personal Data Act and the regulatory legal acts adopted in accordance with it, unless otherwise provided for by the Personal Data Act or other federal laws.
3.2. The controller is obliged to:
— provide the data subject, at their request, with information concerning the processing of their personal data;
— organise the processing of personal data in accordance with the procedure established by the current legislation of the Russian Federation;
— respond to communications and requests from data subjects and their legal representatives in accordance with the requirements of the Personal Data Act;
— to provide the authorised body for the protection of the rights of data subjects with the necessary information, upon request from that body, within 10 days of receiving such a request;
— to publish or otherwise ensure unrestricted access to this Policy on the processing of personal data;
— take legal, organisational and technical measures to protect personal data from unauthorised or accidental access, destruction, alteration, blocking, copying, disclosure or dissemination, as well as from other unlawful actions in relation to personal data;
— to cease the transfer (dissemination, disclosure, access) of personal data, to cease processing and to destroy personal data in accordance with the procedure and in the circumstances provided for by the Personal Data Act;
— to fulfil other obligations provided for by the Personal Data Act.
4. Key rights and obligations of data subjects
4.1. Data subjects have the right:
— to receive information concerning the processing of their personal data, except in cases provided for by federal laws. The information shall be provided to the data subject by the Controller in an accessible form and shall not contain personal data relating to other data subjects, except where there are lawful grounds for the disclosure of such personal data. The list of information and the procedure for obtaining it are set out in the Personal Data Act;
— to require the Controller to rectify, block or erase their personal data if such data is incomplete, out of date, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and to take the measures provided for by law to protect their rights;
— to make the processing of personal data for the purpose of marketing goods, works and services subject to prior consent;
— to withdraw consent to the processing of personal data, and to request that the processing of personal data be discontinued;
— to lodge a complaint with the authorised body for the protection of the rights of data subjects or through the courts regarding any unlawful actions or omissions by the Controller in the processing of their personal data;
— to exercise other rights provided for by the legislation of the Russian Federation.
4.2. Data subjects are obliged to:
— to provide the Controller with accurate information about themselves;
— to notify the Operator of any corrections (updates or changes) to their personal data.
4.3. Persons who have provided the Operator with inaccurate information about themselves, or information about another data subject without the latter’s consent, shall be liable in accordance with the legislation of the Russian Federation.
5. Principles governing the processing of personal data
5.1. The processing of personal data is carried out on a lawful and fair basis.
5.2. The processing of personal data is limited to the fulfilment of specific, pre-defined and legitimate purposes. The processing of personal data that is incompatible with the purposes for which the personal data was collected is not permitted.
5.3. Databases containing personal data that are processed for purposes incompatible with one another must not be merged.
5.4. Only personal data that is relevant to the purposes of its processing may be processed.
5.5. The content and scope of the personal data being processed shall correspond to the stated purposes of processing. The personal data being processed must not be excessive in relation to the stated purposes of processing.
5.6. When processing personal data, the accuracy, adequacy and, where necessary, relevance of the personal data in relation to the purposes of processing shall be ensured. The data controller shall take the necessary measures and/or ensure that such measures are taken to delete or rectify incomplete or inaccurate data.
5.7. Personal data shall be stored in a form that allows the data subject to be identified for no longer than is necessary for the purposes of processing the personal data, unless the retention period for personal data is established by federal law or by a contract to which the data subject is a party, or under which the data subject is a beneficiary or guarantor. Personal data being processed shall be destroyed or anonymised once the purposes of processing have been achieved or where there is no longer a need to achieve those purposes, unless otherwise provided for by federal law.
6. Purposes of processing personal data
Purpose of processing: Advising clients and processing enquiries received via the feedback form
Personal data:
surname, first name, patronymic
email address
telephone numbers
Legal basis:
Federal Law ‘On Information, Information Technologies and the Protection of Information’ dated 27 July 2006 No. 149-F3
Types of personal data processing:
Collection, recording, organisation, accumulation, storage, destruction and anonymisation of personal data
Sending information emails to an email address
7. Conditions for the processing of personal data
7.1. The processing of personal data is carried out with the consent of the data subject to the processing of their personal data.
7.2. The processing of personal data is necessary to achieve the objectives set out in an international treaty of the Russian Federation or by law, and to fulfil the functions, powers and obligations assigned to the controller by the legislation of the Russian Federation.
7.3. The processing of personal data is necessary for the administration of justice, the enforcement of a court order, or an order issued by another authority or public official, which is enforceable in accordance with the legislation of the Russian Federation on enforcement proceedings.
7.4. The processing of personal data is necessary for the performance of a contract to which the data subject is a party, or under which the data subject is a beneficiary or guarantor, as well as for the conclusion of a contract at the initiative of the data subject or a contract under which the data subject will be a beneficiary or guarantor.
7.5. The processing of personal data is necessary for the exercise of the rights and legitimate interests of the controller or third parties, or for the pursuit of objectives of public interest, provided that this does not infringe upon the rights and freedoms of the data subject.
7.6. The processing of personal data to which an unlimited number of persons have been granted access by the data subject or at their request (hereinafter referred to as ‘publicly available personal data’) is carried out.
7.7. The processing of personal data subject to publication or mandatory disclosure in accordance with federal law is carried out.
8. Procedures for the collection, storage, transfer and other forms of processing of personal data
The security of personal data processed by the Controller is ensured through the implementation of legal, organisational and technical measures necessary to fully comply with the requirements of current legislation on the protection of personal data.
8.1. The Operator ensures the security of personal data and takes all possible measures to prevent unauthorised persons from accessing personal data.
8.2. The User’s personal data will never, under any circumstances, be disclosed to third parties, except where required by applicable legislation or where the data subject has given their consent to the Operator to disclose the data to a third party for the purpose of fulfilling obligations under a civil law contract.
8.3. Should any inaccuracies be identified in the personal data, the User may update them themselves by sending a notification to the Operator’s email address ri@kvazar.info, marked ‘Update of personal data’.
8.4. The period for which personal data is processed is determined by the fulfilment of the purposes for which the personal data was collected, unless a different period is provided for in the contract or by applicable legislation.
The User may withdraw their consent to the processing of personal data at any time by sending a notification to the Operator via email to the Operator’s email address ri@kvazar.info, marked ‘Withdrawal of consent to the processing of personal data’.
8.5. All information collected by third-party services, including payment systems, telecommunications providers and other service providers, is stored and processed by the said parties (Operators) in accordance with their Terms of Use and Privacy Policy. The data subject and/or the documents specified. The Operator shall not be liable for the actions of third parties, including the service providers referred to in this clause.
8.6. Any restrictions imposed by the data subject on the transfer (other than the provision of access), as well as on the processing or the conditions of processing (other than the provision of access) of personal data authorised for disclosure, shall not apply in cases where personal data is processed in the state, public or other public interests as defined by the legislation of the Russian Federation.
8.7. When processing personal data, the Controller shall ensure the confidentiality of personal data.
8.8. The Controller shall store personal data in a form that allows the data subject to be identified for no longer than is necessary for the purposes of processing personal data, unless the retention period for personal data is established by federal law, or by a contract to which the data subject is a party, or under which the data subject is a beneficiary or guarantor.
8.9. The termination of the processing of personal data may be triggered by the fulfilment of the purposes of such processing, the expiry of the data subject’s consent, the withdrawal of consent by the data subject or a request to cease processing, as well as the identification of unlawful processing of personal data.
9. List of actions carried out by the Controller with the personal data received
9.1. The Controller carries out the collection, recording, organisation, accumulation, storage, clarification (updating, amendment), retrieval, use, transfer (dissemination, provision, access), anonymisation, blocking, erasure and destruction of personal data.
9.2. The Operator carries out the automated processing of personal data, with or without the receipt and/or transmission of the information received via information and telecommunications networks.
10. Cross-border transfer of personal data
10.1. Before commencing activities involving the cross-border transfer of personal data, the Controller is obliged to notify the competent authority responsible for protecting the rights of data subjects of its intention to carry out the cross-border transfer of personal data (such notification shall be sent separately from the notification of the intention to process personal data).
10.2. Before submitting the above notification, the Controller must obtain the relevant information from the authorities of the foreign state, foreign natural persons and foreign legal entities to whom the cross-border transfer of personal data is planned.
11. Confidentiality of personal data
The Controller and other persons who have gained access to personal data are obliged not to disclose personal data to third parties or disseminate it without the consent of the data subject, unless otherwise provided for by federal law.
12. Final provisions
12.1. Users may obtain clarification on any queries they may have regarding the processing of their personal data by contacting the Controller via email at ri@kvazar.info.
12.2. Any changes to the Operator’s personal data processing policy will be reflected in this document. The policy remains in force indefinitely until replaced by a new version.
12.3. The current version of the Policy is freely available on the internet at https://kvazar.info/#privacy.