This English translation is provided for convenience only. In case of any discrepancy, the Russian version prevails.
01 General provisions
This personal data processing policy has been drawn up in accordance with Federal Law No. 152-FZ of July 27, 2006 “On Personal Data” (the Personal Data Law) and sets out how Individual Entrepreneur Egor Yurievich Adrianov (the Operator) processes personal data and the measures it takes to keep that data secure.
1.1. The Operator’s paramount objective and a condition of all its activities is to observe the rights and freedoms of individuals and citizens when processing their personal data, including the rights to privacy and to personal and family secrets.
1.2. This Operator’s policy on personal data processing (the Policy) applies to all information the Operator may receive about visitors to the website https://kaskit-tech.com.
1.3. Operator details: Individual Entrepreneur Egor Yurievich Adrianov, TIN (INN) 772157150844, OGRNIP 326774600598898, address: apt. 169, 5 bldg. 1 Privolnaya St., Moscow, 109145, Russia.
1.4. The person responsible for organizing personal data processing is Egor Yurievich Adrianov, individual entrepreneur. Contacts: kaskit.tech@gmail.com, phone +7 919 779-07-51.
02 Key terms used in the Policy
2.1. Automated processing of personal data — processing of personal data by means of computer technology.
2.2. Blocking of personal data — temporary suspension of personal data processing (except where processing is needed to rectify the personal data).
2.3. Website — a set of graphic and informational materials, as well as computer programs and databases, that make them available on the internet at https://kaskit-tech.com.
2.4. Personal data information system — a set of personal data contained in databases, together with the information technologies and technical means used to process it.
2.5. Depersonalization of personal data — actions after which it is impossible, without additional information, to determine which User or other data subject the personal data belongs to.
2.6. Processing of personal data — any action (operation) or set of actions (operations) performed with personal data, with or without automation, including collection, recording, systematization, accumulation, storage, rectification (updating, amendment), retrieval, use, transfer (distribution, provision, access), depersonalization, blocking, deletion and destruction of personal data.
2.7. Operator — a state or municipal body, legal entity or individual that, alone or jointly with others, organizes and/or carries out the processing of personal data and determines the purposes of processing, the personal data to be processed and the actions (operations) performed with it.
2.8. Personal data — any information relating directly or indirectly to an identified or identifiable User of the website https://kaskit-tech.com.
2.9. User — any visitor to the website https://kaskit-tech.com.
2.10. Provision of personal data — actions aimed at disclosing personal data to a certain person or a certain group of persons.
2.11. Distribution of personal data — any actions aimed at disclosing personal data to an indefinite group of persons or at making personal data available to an unlimited number of persons, including publication in the media, posting in information and telecommunication networks or providing access to personal data in any other way.
2.12. Cross-border transfer of personal data — transfer of personal data to the territory of a foreign state, to a foreign state authority, a foreign individual or a foreign legal entity.
2.13. Destruction of personal data — any actions that irreversibly destroy personal data, making it impossible to restore its content in the personal data information system, and/or that destroy the physical media of personal data.
03 Rights and obligations of the Operator
3.1. The Operator has the right to:
- obtain accurate information and/or documents containing personal data from the data subject;
- if the data subject withdraws consent to processing or requests that processing stop, continue processing the personal data without the data subject’s consent where the Personal Data Law provides grounds for this;
- determine independently the scope and list of measures necessary and sufficient to fulfill the obligations under the Personal Data Law and the regulations adopted under it, unless otherwise provided by the Personal Data Law or other federal laws.
3.2. The Operator must:
- provide the data subject, on request, with information about the processing of their data;
- organize the processing of personal data as required by the laws of the Russian Federation;
- respond to appeals and requests from data subjects and their legal representatives in accordance with the Personal Data Law;
- provide the authorized body for the protection of data subjects’ rights (Roskomnadzor), at its request, with the necessary information within 10 working days of receiving the request;
- publish this Policy or otherwise provide unrestricted access to it;
- take legal, organizational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, provision or distribution, and from other unlawful actions;
- stop the transfer (distribution, provision, access) of personal data, stop processing and destroy personal data in the manner and cases provided for by the Personal Data Law;
- perform other obligations provided for by the Personal Data Law.
04 Rights and obligations of data subjects
4.1. Data subjects have the right to:
- receive information about the processing of their personal data, except as provided by federal laws. The Operator provides this information in an accessible form, without personal data of other data subjects unless there are legal grounds to disclose it. The list of information and how to obtain it are set by the Personal Data Law;
- demand that the Operator rectify, block or destroy their personal data if it is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and take the measures provided by law to protect their rights;
- require prior consent for processing of personal data for the purpose of promoting goods, works and services;
- withdraw consent to processing and demand that processing stop;
- appeal against unlawful actions or inaction of the Operator in processing their personal data to the authorized body for the protection of data subjects’ rights or in court;
- exercise other rights provided for by the laws of the Russian Federation.
4.2. Data subjects must:
- provide the Operator with accurate information about themselves;
- inform the Operator of any rectification (update, amendment) of their personal data.
4.3. Persons who have given the Operator false information about themselves, or information about another data subject without that person’s consent, are liable under the laws of the Russian Federation.
05 Principles of personal data processing
5.1. Personal data is processed lawfully and fairly.
5.2. Processing is limited to achieving specific, predetermined and lawful purposes. Processing incompatible with the purposes of collection is not allowed.
5.3. Databases containing personal data processed for incompatible purposes may not be combined.
5.4. Only personal data that meets the purposes of processing is processed.
5.5. The content and amount of processed personal data correspond to the stated purposes. Personal data may not be excessive in relation to those purposes.
5.6. Processing ensures the accuracy and sufficiency of personal data and, where necessary, its relevance to the purposes of processing. The Operator takes, or ensures that others take, the necessary measures to delete or rectify incomplete or inaccurate data.
5.7. Personal data is stored in a form that allows the data subject to be identified for no longer than the purposes of processing require, unless the storage period is set by federal law or by a contract to which the data subject is a party, beneficiary or guarantor. Processed personal data is destroyed or depersonalized once the purposes of processing are achieved or no longer need to be achieved, unless federal law provides otherwise.
06 Purposes of personal data processing
- Purpose
- handling a form submission made by the User on the Website: contacting the User to consult, prepare an offer and conclude a service contract
- Personal data
- name;
- phone number (for calls or WhatsApp) or Telegram username;
- information about the business and the task that the User enters in the form.
- Legal grounds
- the data subject’s consent to the processing of their personal data (clause 1, part 1, article 6 of the Personal Data Law), given by ticking the consent box in the form on the Website; concluding a contract at the data subject’s initiative (clause 5, part 1, article 6 of the Personal Data Law)
- Types of processing
- collection, recording, storage, use, transfer (provision, access), deletion and destruction of personal data; contacting the User by the phone number they gave, in WhatsApp or in Telegram
6.1. The Website does not use web analytics services. To protect the contact form from automated submissions it uses Yandex SmartCaptcha (servers in the Russian Federation): when the check runs, the service receives technical browser data and the IP address and processes them under its own rules. It stores one technical cookie in the browser for 1 year: the language the User picks in the language switch; it contains no personal data. For the duration of the session the browser also keeps a draft of the short form (to carry what was typed over to the Contact page) and a flag that the intro was shown; they are not sent to the Operator until the form is submitted and are deleted when the tab is closed. The User’s browser language is used only to open the home page in a suitable language on the first visit and is not stored. The User’s IP address is used only to protect the form from automated submissions: it is kept in the server’s memory for no longer than 10 minutes and is never written anywhere.
6.2. The Operator does not use personal data for advertising or newsletters without the User’s separate consent.
07 Conditions of personal data processing
7.1. Personal data is processed with the data subject’s consent to the processing of their personal data.
7.2. Processing is necessary to conclude a contract at the data subject’s initiative, or a contract under which the data subject will be a beneficiary or guarantor, and to perform such a contract.
08 Collection, storage, transfer and other processing of personal data
The security of personal data processed by the Operator is ensured by legal, organizational and technical measures necessary to fully meet the requirements of the current personal data protection laws.
8.1. The Operator keeps personal data safe and takes all possible measures to prevent access to it by unauthorized persons, including: a person responsible for organizing personal data processing has been appointed; only the Operator has access to the server with the database, and logs in with SSH keys; the server runs a firewall and its software is updated regularly; data between the browser and the server travels over TLS (HTTPS); the database file is accessible only to the website’s service account; the form is protected from automated submissions (Yandex SmartCaptcha, rate limits); regular backups are made; every destruction of personal data is recorded in a journal.
8.2. The User’s personal data is not transferred to third parties, except in cases related to compliance with the law, or where the data subject has consented to the Operator transferring the data to a third party to perform obligations under a civil law contract.
8.3. Personal data entered in the form on the Website is recorded and stored in a database on a server of the hosting provider Timeweb Cloud located in the Russian Federation. Database backups are also stored in the Russian Federation. Once recorded, a copy of the submission is sent to the Operator’s authorized staff via the Telegram messenger so they can handle it promptly.
8.4. If the User finds inaccuracies in their personal data, they can update it by emailing the Operator at kaskit.tech@gmail.com with the subject line “Personal data update”.
8.5. Personal data from form submissions is kept for no longer than 6 (six) months from the date of the submission and is then destroyed automatically, unless the purpose of processing has been achieved or consent withdrawn earlier. Copies of submissions in the Telegram messenger are deleted within the same period; database backups are kept for no longer than 14 days. If a contract is concluded with the User, the data needed to perform it is processed for the term of the contract and the periods required by law. Destruction of personal data is confirmed by a destruction act and a journal export in accordance with the requirements approved by Roskomnadzor Order No. 179 of October 28, 2022.
8.6. The User may withdraw their consent to the processing of personal data at any time by emailing the Operator at kaskit.tech@gmail.com with the subject line “Withdrawal of consent”.
8.7. All information collected by third-party services, including payment systems, means of communication and other service providers, is stored and processed by those parties (operators) in accordance with their user agreements and privacy policies. The data subject and/or User is responsible for reviewing those documents in a timely manner. The Operator is not responsible for the actions of third parties, including the service providers mentioned in this clause.
8.8. The Operator ensures the confidentiality of personal data when processing it.
8.9. The Operator stores personal data in a form that allows the data subject to be identified for no longer than the purposes of processing require, unless the storage period is set by federal law or by a contract to which the data subject is a party, beneficiary or guarantor.
8.10. Processing may end when its purposes are achieved, when the data subject’s consent expires, when the data subject withdraws consent or demands that processing stop, or when unlawful processing is discovered.
09 Actions performed by the Operator with the personal data received
9.1. The Operator collects, records, systematizes, accumulates, stores, rectifies (updates, amends), retrieves, uses, transfers (provides, gives access to), blocks, deletes and destroys personal data.
9.2. The Operator carries out mixed (automated and non-automated) processing of personal data, receiving and/or transmitting the information over information and telecommunication networks.
10 Cross-border transfer of personal data
10.1. Before starting cross-border transfers of personal data, the Operator must notify the authorized body for the protection of data subjects’ rights of its intention to do so (this notice is sent separately from the notice of intent to process personal data).
10.2. Before sending that notice, the Operator must obtain the relevant information from the foreign state authorities, foreign individuals or foreign legal entities to whom the cross-border transfer is planned.
11 Confidentiality of personal data
The Operator and other persons who have gained access to personal data must not disclose it to third parties or distribute it without the data subject’s consent, unless federal law provides otherwise.
12 Final provisions
12.1. The User can get any clarification on matters concerning the processing of their personal data by contacting the Operator by email at kaskit.tech@gmail.com.
12.2. Any changes to the Operator’s personal data processing policy will be reflected in this document. The Policy is valid indefinitely until replaced by a new version.
12.3. The current version of the Policy is freely available online at https://kaskit-tech.com/en/privacy.