Privacy Policy

1. General Provisions. This Personal Data Processing Policy has been drafted in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006, No. 152-FZ “On Personal Data” (hereinafter referred to as the “Personal Data Law”) and defines the procedure for processing personal data and the measures taken by Evgeny Yuryevich Fateev (hereinafter referred to as the “Controller”) to ensure the security of personal data.

1.1. The Operator considers respect for human and civil rights and freedoms—including the rights to privacy and to personal and family confidentiality—when processing personal data to be its foremost objective and a prerequisite for conducting its business.

1.2. This Operator’s policy regarding the processing of personal data (hereinafter referred to as the “Policy”) applies to all information that the Operator may obtain about visitors to the website http://streetart-marshrut.ru.

2. Key Terms Used in the Policy

2.1. Automated processing of personal data—the processing of personal data using computer technology.

2.2. Blocking of personal data—the temporary suspension of the processing of personal data (except in cases where processing is necessary to verify the accuracy of the personal data).

2.3. A website is a collection of graphic and informational materials, as well as computer programs and databases, that make them accessible on the Internet at the web address http://streetart-marshrut.ru.

2.4. A personal data information system is a collection of personal data contained in databases, along with the information technology and technical resources that enable its processing.

2.5. Anonymization of personal data—actions that make it impossible to determine, without the use of additional information, that the personal data belongs to a specific User or another data subject.

2.6. Processing of personal data—any action (operation) or set of actions (operations) performed with or without the use of automated means on personal data, including the collection, recording, organization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, disclosure, access), anonymization, blocking, deletion, and destruction of personal data.

2.7. Controller—a government agency, municipal authority, legal entity, or individual that, either independently or jointly with others, organizes and/or carries out the processing of personal data, as well as determines the purposes of such processing, the scope of personal data to be processed, and the actions (operations) performed on the personal data.

2.8. Personal data—any information relating directly or indirectly to an identified or identifiable user of the website http://streetart-marshrut.ru.

2.9. Personal data authorized for disclosure by the data subject refers to personal data to which an unlimited number of persons are granted access by the data subject through the provision of consent to the processing of personal data authorized for disclosure by the data subject in accordance with the procedure established by the Personal Data Act (hereinafter referred to as “personal data authorized for disclosure”).

2.10. User—any visitor to the website http://streetart-marshrut.ru.

2.11. Disclosure of personal data—actions aimed at disclosing personal data to a specific person or a specific group of persons.

2.12. Disclosure of personal data—any actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data) or at allowing an unlimited number of people to access personal data, including the publication of personal data in the media, posting on information and telecommunications networks, or providing access to personal data by any other means.

2.13. Cross-border transfer of personal data—the transfer of personal data to the territory of a foreign state to a government authority of that foreign state, a foreign individual, or a foreign legal entity.

2.14. Destruction of personal data—any actions that result in the irreversible destruction of personal data, making it impossible to subsequently restore the content of the personal data in the personal data information system, and/or the destruction of physical media containing personal data.

3. The Operator’s Basic Rights and Obligations

3.1. The Operator has the right to:
— receive from the data subject accurate information and/or documents containing personal data;
— in the event that the data subject revokes consent to the processing of personal data or submits a request to cease processing personal data, the Operator has the right to continue processing personal data without the data subject’s consent if there are grounds specified in the Personal Data Act;
— to independently determine the composition and list of measures necessary and sufficient to ensure compliance with the obligations set forth in the Personal Data Act and the regulatory legal acts adopted pursuant thereto, unless otherwise provided by the Personal Data Act or other federal laws.

3.2. The controller is required to:
— provide the data subject, upon request, with information regarding the processing of their personal data;
— organize the processing of personal data in accordance with the procedures established by the current legislation of the Russian Federation;
— respond to inquiries and requests from data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
— provide the authorized body responsible for protecting the rights of data subjects with the necessary information, upon request by that body, within 10 days of receiving such a request;
— publish or otherwise ensure unrestricted access to this Policy regarding the processing of personal data;
— take legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, alteration, blocking, copying, disclosure, or dissemination, as well as from other unlawful actions involving personal data;
— to cease the transfer (disclosure, provision, or access) of personal data, to cease processing, and to destroy personal data in accordance with the procedures and under the circumstances provided for by the Personal Data Act;
— to fulfill other obligations provided for by the Personal Data Act.

4. Fundamental Rights and Obligations of Data Subjects

4.1. Data subjects have the right to:
— receive information regarding the processing of their personal data, except as provided for by federal laws. The information is provided to the data subject The operator must provide this information in an accessible format, and it must not contain personal data relating to other data subjects, except where there are lawful grounds for disclosing such personal data. The list of information and the procedure for obtaining it are established by the Personal Data Act;
— to request that the data controller correct, block, or delete their personal data if such data is incomplete, outdated, inaccurate, obtained unlawfully, or not necessary for the stated purpose of processing, as well as to take the measures provided by law to protect their rights;
— to require prior consent for the processing of personal data for the purpose of marketing goods, works, and services;
— to withdraw consent to the processing of personal data, as well as to submit a request to cease the processing of personal data;
— to file a complaint with the authorized body responsible for protecting the rights of data subjects or to seek judicial remedy against the Operator’s unlawful actions or omissions in the processing of the data subject’s personal data;
— to exercise other rights provided for by the legislation of the Russian Federation.

4.2. Data subjects are required to:
— provide the Controller with accurate information about themselves;
— notify the Controller of any corrections (updates, changes) to their personal data.

4.3. Individuals who have provided the Operator with false information about themselves, or information about another data subject without that person’s consent, shall be held liable in accordance with the laws of the Russian Federation.

5. Principles Governing the Processing of Personal Data

5.1. Personal data is processed on a lawful and fair basis.

5.2. The processing of personal data is limited to the achievement of specific, predetermined, and legitimate purposes. The processing of personal data that is incompatible with the purposes for which the personal data was collected is not permitted.

5.3. It is prohibited to combine databases containing personal data that are processed for purposes that are incompatible with one another.

5.4. Only personal data that is relevant to the purposes of its processing may be processed.

5.5. The content and scope of the personal data being processed correspond to the stated purposes of processing. The personal data being processed must not exceed what is necessary for the stated purposes of processing.

5.6. When processing personal data, the accuracy, adequacy, and, where necessary, relevance of the personal data in relation to the purposes of the processing are ensured. The controller takes the necessary measures and/or ensures that such measures are taken to delete or correct incomplete or inaccurate data.

5.7. Personal data shall be stored in a form that allows for the identification of the data subject for no longer than is necessary to achieve the purposes of the processing, unless the retention period for the personal data is established by federal law or by a contract to which the data subject is a party, or under which the data subject is a beneficiary or guarantor. Personal data being processed shall be destroyed or anonymized once the purposes of processing have been achieved or when it is no longer necessary to achieve those purposes, unless otherwise provided by federal law.

6. Purposes of Personal Data Processing

Purpose of processing:

to provide the User with access to the services, information, and/or materials contained on the website

Personal information:

  • private adress
  • cookies date

Legal Basis:

  • Federal Law ‘On Information, Information Technologies and the Protection of Information’ of 27 July 2006 No. 149-FZ

Types of personal data processing:

  • The collection, recording, organisation, storage, retention, destruction and anonymisation of personal data

7. Terms and conditions regarding the processing of personal data

7.1. The processing of personal data is carried out with the consent of the data subject to the processing of their personal data.

7.2. The processing of personal data is necessary to achieve the objectives set out in an international treaty of the Russian Federation or in legislation, and to enable the controller to carry out the functions, powers and duties assigned to it by the legislation of the Russian Federation.

7.3. The processing of personal data is necessary for the administration of justice, or for the enforcement of a court order or a decision issued by another authority or public official, which is enforceable in accordance with the legislation of the Russian Federation on enforcement proceedings.

7.4. The processing of personal data is necessary for the performance of a contract to which the data subject is a party, or under which the data subject is a beneficiary or guarantor, as well as for the conclusion of a contract at the initiative of the data subject or a contract under which the data subject will be a beneficiary or guarantor.

7.5. The processing of personal data is necessary for the exercise of the rights and legitimate interests of the controller or third parties, or for the pursuit of objectives of general public interest, provided that this does not infringe the rights and freedoms of the data subject.

7.6. Personal data is processed where the data subject has granted access to such data to an unlimited number of persons, or where such access has been granted at the data subject’s request (hereinafter referred to as ‘publicly available personal data’).

7.7. Personal data that is subject to publication or mandatory disclosure in accordance with federal law is processed.

8. Procedures for the collection, storage, transfer and other forms of processing of personal data. The security of personal data processed by the Controller is ensured through the implementation of legal, organisational and technical measures necessary to comply fully with the requirements of current legislation on the protection of personal data.

8.1. The operator ensures the security of personal data and takes all possible measures to prevent unauthorised persons from accessing personal data.

8.2. The User’s personal data will never, under any circumstances, be disclosed to third parties, except where required by applicable law or where the data subject has given their consent to the Operator to disclose the data to a third party for the purpose of fulfilling obligations under a civil law contract.

8.3. Should any inaccuracies be identified in their personal data, Users may update it themselves by sending a notification to the Operator at the Operator’s email address hello@stenograffia.ru, marked ‘Update of personal data’.

8.4. The period for which personal data is processed is determined by the fulfilment of the purposes for which the personal data was collected, unless a different period is specified in a contract or by applicable legislation.

The user may withdraw their consent to the processing of personal data at any time by sending a notification to the Operator via email to the Operator’s email address hello@stenograffia.ru, marked ‘Withdrawal of consent to the processing of personal data’.

8.5. All information collected by third-party services, including payment systems, telecommunications providers and other service providers, is stored and processed by those parties (Operators) in accordance with their Terms of Use and Privacy Policy. The data subject and/or the documents specified. The Operator shall not be liable for the actions of third parties, including the service providers referred to in this clause.

8.6. Any restrictions imposed by the data subject on the transfer (other than the provision of access) or on the processing, or any conditions relating to the processing (other than the provision of access), of personal data authorised for disclosure shall not apply in cases where personal data is processed in the interests of the state, the public or other public interests as defined by the legislation of the Russian Federation.

8.7. When processing personal data, the data controller ensures the confidentiality of personal data.

8.8. The data controller shall store personal data in a form that allows the data subject to be identified for no longer than is necessary for the purposes of processing the personal data, unless the period for which the personal data is to be stored is specified by federal law or by a contract to which the data subject is a party, or under which the data subject is a beneficiary or guarantor.

8.9. The processing of personal data may cease where the purposes of such processing have been achieved, where the data subject’s consent has expired, where the data subject has withdrawn their consent or requested that the processing of their personal data be ceased, or where unlawful processing of personal data has been identified.

9. List of actions carried out by the Controller with regard to the personal data received

9.1. The Operator carries out the collection, recording, organisation, accumulation, storage, refinement (updating, amendment), retrieval, use, transfer (dissemination, provision, access), anonymisation, blocking, erasure and destruction of personal data.

9.2. The Data Controller carries out the automated processing of personal data, with or without the receipt and/or transmission of the information obtained via information and telecommunications networks.

10. Cross-border transfer of personal data

10.1. Before commencing any cross-border transfer of personal data, the controller must notify the competent authority responsible for protecting the rights of data subjects of its intention to carry out a cross-border transfer of personal data (such notification must be submitted separately from the notification of the intention to process personal data).

10.2. Prior to submitting the aforementioned notification, the operator is obliged to obtain the relevant information from the authorities of the foreign state, and from the foreign natural persons and legal entities to whom the cross-border transfer of personal data is intended.

11. Confidentiality of personal data: The Controller and any other persons who have access to personal data are obliged not to disclose such data to third parties or disseminate it without the consent of the data subject, unless otherwise provided for by federal law.

12. Final provisions

12.1. Users may obtain further information on any queries they may have regarding the processing of their personal data by contacting the Controller via email at hello@stenograffia.ru.

12.2. Any changes to the Controller’s personal data processing policy will be reflected in this document. The policy remains in force indefinitely until it is replaced by a new version.

12.3. The current version of the Policy is freely available online at https://streetart-marshrut.ru/privacy.