Skip links

Limited Liability Company “Svyaz”

APPROVED BY
by order of the General Director
Svyaz LLC
D. Sh. Mikhaylova
dated 31 March 2026, No. 13

Personal Data Processing Policy

 

1. GENERAL PROVISIONS

1.1. This Personal Data Processing Policy (hereinafter, the “Policy”) has been developed in accordance with the requirements of Paragraph 2 of Part 1 of Article 18.1 of Federal Law No. 152-FZ dated 27 July 2006, “On Personal Data” (hereinafter, the “Personal Data Law”), in order to protect the rights and freedoms of individuals and citizens in the processing of their personal data, including the right to privacy and personal and family confidentiality.

1.2. This Policy applies to the following category of personal-data subjects: visitors to the Operator’s website.

1.3. Key terms used in the Policy:

Personal data means any information relating directly or indirectly to an identified or identifiable individual (personal-data subject);

Personal Data Operator (Operator) means  Svyaz LLC, Primary State Registration Number 1197746533599, Taxpayer Identification Number 9718144693, Tax Registration Reason Code 771801001, address: 107553, Russia, Moscow, Okruzhnoy Proezd, property 2A, building 1, which independently or jointly with other persons organises and/or performs personal-data processing and determines the purposes of personal-data processing, the categories of personal data to be processed and the actions (operations) performed with personal data;

Personal data processing means any action (operation) or set of actions (operations) performed with personal data, whether or not using automation tools. Personal data processing includes, among other things: collection, recording, systematisation, accumulation, storage, clarification (updating, alteration), retrieval, use, transfer (dissemination, provision, access), depersonalisation, blocking, deletion and destruction;

Automated processing of personal data means processing personal data using computer technology;

Dissemination of personal data means actions aimed at disclosing personal data to an indefinite group of persons;

Provision of personal data means actions aimed at disclosing personal data to a specified person or specified group of persons;

Blocking of personal data means temporary suspension of personal-data processing, except where processing is necessary to clarify personal data;

Destruction of personal data means actions as a result of which it becomes impossible to restore the content of personal data in the personal-data information system and/or as a result of which tangible media containing personal data are destroyed;

Depersonalisation of personal data means actions as a result of which it becomes impossible, without additional information, to determine whether personal data belongs to a particular personal-data subject;

Personal data information system means a set of personal data contained in databases and the information technologies and technical means that ensure its processing;

Cross-border transfer of personal data means transfer of personal data to the territory of a foreign state to a foreign state authority, foreign individual or foreign legal entity;

Website means a set of computer programmes and other information contained in an information system, access to which is provided through the Internet information and telecommunications network and located at: https://powerapp.world/.

1.4. Main rights and obligations of the Operator.

1.4.1. The Operator is entitled to:

  • independently determine the composition and list of measures necessary and sufficient to ensure compliance with the obligations provided for by the Personal Data Law and regulatory legal acts adopted pursuant to it, unless otherwise provided by the Personal Data Law or other federal laws;
  • entrust personal-data processing to another person with the consent of the personal-data subject, unless otherwise provided by federal law, under an agreement entered into with that person. A person processing personal data on the Operator’s instructions must comply with the personal-data processing principles and rules provided for by the Personal Data Law;
  • if a personal-data subject withdraws consent to personal-data processing, continue processing personal data without the subject’s consent where the grounds specified in the Personal Data Law exist.

1.4.2. The Operator is obliged to:

  • organise personal-data processing in accordance with the requirements of the Personal Data Law;
  • respond to applications and requests from personal-data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
  • provide the authorised authority for the protection of the rights of personal-data subjects (hereinafter, “Roskomnadzor”), at that authority’s request, with the necessary information within 10 business days after receiving the request.

1.5. Main rights of personal-data subjects. A personal-data subject has the right to:

  • receive information relating to the processing of their personal data, except in cases provided for by federal laws. The Operator provides the information to the personal-data subject in an accessible form, and it must not contain personal data relating to other personal-data subjects except where there are legal grounds for disclosure of such personal data. The list of information and the procedure for obtaining it are established by the Personal Data Law;
  • require the Operator to rectify, block or destroy their personal data if the personal data are incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the stated purpose of processing, and take measures provided by law to protect their rights;
  • appeal to Roskomnadzor or to a court against unlawful actions or omissions of the Operator in processing their personal data.

A personal data subject may exercise the rights to obtain information concerning processing of their personal data, and the rights to rectify, block or destroy their personal data, by submitting a request to the Operator at: 107553, Russia, Moscow, Okruzhnoy Proezd, property 2A, building 1, or by submitting thecorresponding request byemail: info@powerapp.world.

1.6. Compliance with this Policy is monitored by an authorised person responsible for organising personal-data processing at the Operator.

1.7. Liability for breaching the legislation of the Russian Federation and the Operator’s local acts in the area of personal-data processing and protection is determined in accordance with the legislation of the Russian Federation.

2. PRINCIPLES OF PERSONAL DATA PROCESSING

  • lawfulness and fairness;
  • limiting personal-data processing to the achievement of specific, predetermined and lawful purposes;
  • preventing personal-data processing that is incompatible with the purposes of collection .of personal data;
  • prohibiting the combination of databases containing personal data where their processing is carried out for incompatible purposes;
  • processing only personal data that correspond to the purposes of their processing;
  • ensuring that the content and volume of personal data processed correspond to the stated purposes of processing;
  • prohibiting the processing of personal data excessive in relation to the stated purposes of processing;
  • ensuring the accuracy, adequacy and relevance of personal data in relation to the purposes of personal-data processing;
  • destroying or depersonalising personal data when the purposes of processing are achieved or there is no longer a need to achieve those purposes, where the Operator cannot remedy violations in personal-data processing, unless otherwise provided by federal law.

3. LEGAL GROUNDS FOR PERSONAL DATA PROCESSING

3.1. The legal grounds for personal-data processing are the set of regulatory legal acts pursuant to and in accordance with which the Operator processes personal data, including:

  • the Constitution of the Russian Federation;
  • the Civil Code of the Russian Federation;
  • other regulatory legal acts governing relationships connected with the Operator’s activities.

3.2. The consent of the personal-data subject to personal-data processing is also a legal ground for processing personal data.

4. SCOPE, CATEGORIES AND CONDITIONS OF PERSONAL DATA PROCESSED; CATEGORIES OF PERSONAL DATA SUBJECTS IN RELATION TO THE DECLARED PURPOSES OF PERSONAL DATA PROCESSING

4.1. Personal-data processing is limited to achieving specific, predetermined and lawful purposes. Personal-data processing incompatible with the purposes of collecting personal data is not permitted. Only personal data that correspond to the purposes of their processing are subject to processing.

4.2. The content and volume of personal data processed must correspond to the stated purposes of processing provided for in this section. Personal data processed must not be excessive in relation to the stated purposes of their processing. The Operator processes personal data for the following purposes:

  • offering and promoting its own products and brand in the market by conducting marketing, advertising and public-relations activities and stimulating sales;
  • processing incoming requests from the Website.

4.3. Processing of personal data for the purpose of offering and promoting the Operator’s own products and brand in the market by conducting marketing, advertising and public-relations activities and stimulating sales.

4.3.1. Under this section of the Policy, the Operator determines the categories and list of personal data processed, the methods and periods for its processing and storage, and the procedure for destroying personal data upon achievement of the processing purpose or upon other legal grounds, in relation to the purpose of offering and promoting its own products and brand on the market through marketing, advertising and PR activities and sales promotion.

4.3.2. For the purpose specified in this section of the Policy, the Operator processes the personal data of visitors to the Operator’s Website.

4.3.3. For the purpose specified in this section of the Policy, the Operator processes the following categories and list of personal data of Website visitors:

(a) processing of general (other) categories of visitors’ personal data is carried out in accordance with the following list:

  • surname, first name and patronymic
  • phone number
  • information collected through analytics software

(b) special categories of Website visitors’ personal data are not processed;

(c) biometric personal data of Website visitors, meaning information characterising a person’s physiological and biological characteristics on the basis of which their identity can be established, are not processed.

4.3.4. For the purpose specified in this section of the Policy, the Operator carries out mixed processing of Website visitors’ personal data without transfer through an internal network and with transfer through the Internet.

4.3.5. The list of actions performed by the Operator with Website visitors’ personal data for the purpose specified in this section: collection, recording, systematisation, accumulation, storage, clarification (updating, alteration), retrieval, use, transfer (provision, access), blocking, deletion and destruction.

4.3.6. Processing of Website visitors’ personal data for the purpose specified in this section of the Policy is carried out subject to prior consent to such processing.

4.3.7. Without the personal data subject’s consent, the Operator does not disclose to third parties or disseminate Website visitors’ personal data for the purpose specified in this section of the Policy, unless otherwise provided by Russian law.

4.3.8. With Website visitors’ consent, the Operator may transfer their personal data within Russia for the purpose specified in this section of the Policy to the following third party: YANDEX LLC (TIN 7736207543), address: 119021, Moscow, Lev Tolstoy Street, 16.

4.3.9. Website visitors’ consent must be specific, informed, conscious and unambiguous, that is, contain information enabling an unambiguous conclusion on the purposes and methods of processing, specifying the actions performed with personal data and the scope of personal data processed.

4.3.10. The Operator does not carry out cross-border transfer of Website visitors’ personal data for the purpose specified in this section of the Policy.

4.4. Processing of personal data for the purpose of processing incoming requests from the Website.

4.4.1. Under this section of the Policy, the Operator determines the categories and list of personal data processed, the methods and periods for its processing and storage, and the procedure for destroying personal data upon achievement of the processing purpose or upon other legal grounds, in relation to the purpose of processing incoming requests from the Website.

4.4.2. For the purpose specified in this section of the Policy, the Operator processes the personal data of visitors to the Operator’s Website.

4.4.3. For the purpose specified in this section of the Policy, the Operator processes the following categories and list of personal data of Website visitors:

(a) processing of general (other) categories of Website visitors’ personal data is carried out in accordance with the following list:

  • surname, first name and patronymic
  • phone number
  • information collected through analytics software

(b) special categories of Website visitors’ personal data are not processed;

(c) biometric personal data of Website visitors, meaning information characterising a person’s physiological and biological characteristics on the basis of which their identity can be established, are not processed.

4.4.4. For the purpose specified in this section of the Policy, the Operator carries out mixed processing of Website visitors’ personal data without transfer through an internal network and with transfer through the Internet.

4.4.5. The list of actions performed by the Operator with Website visitors’ personal data for the purpose specified in this section: collection, recording, systematisation, accumulation, storage, clarification (updating, alteration), retrieval, use, transfer (provision, access), blocking, deletion and destruction.

4.4.6. Processing of Website visitors’ personal data for the purpose specified in this section of the Policy is carried out subject to prior consent to such processing.

4.4.7. Without the personal data subject’s consent, the Operator does not disclose to third parties or disseminate Website visitors’ personal data for the purpose specified in this section of the Policy, unless otherwise provided by Russian law.

4.4.8. With Website visitors’ consent, the Operator may transfer their personal data within Russia for the purpose specified in this section of the Policy to YANDEX LLC (TIN 7736207543), address: 119021, Moscow, Lev Tolstoy Street, 16.

4.4.9. Website visitors’ consent must be specific, informed, conscious and unambiguous, that is, contain information enabling an unambiguous conclusion on the purposes and methods of processing, specifying the actions performed with personal data and the scope of personal data processed.

4.4.10. The Operator does not carry out cross-border transfer of Website visitors’ personal data for the purpose specified in this section of the Policy.

5. PROCEDURE FOR PROCESSING VISITORS’ PERSONAL DATA USING COOKIE FILES

5.1. Cookie files transmitted to the technical devices of a personal-data subject may be used to provide the personal-data subject with statistical and research purposes and to improve the operation of the Website.

5.2. The personal-data subject understands that the equipment and software used to visit websites on the Internet may have a function for disabling operations with cookie files, whether for all websites or for particular websites, and for deleting previously received cookie files.

5.3. The Operator may establish that certain Website functions are available only if the personal-data subject has permitted the acceptance and receipt of cookie files.

5.4. The structure, content and technical parameters of a cookie file are determined by the Operator and may be changed without prior notice to the personal-data subject.

5.5. Counters placed on the Website or its application may be used to analyse the personal-data subject’s cookie files, collect and process statistical information about Website use, and ensure the operation of the Website as a whole or its individual functions. The technical operating parameters of the counters are determined by the Operator and may be changed without prior notice to personal-data subjects.

6. PROCEDURE FOR COLLECTION AND STORAGE OF PERSONAL DATA

6.1. When collecting personal data, including through the Internet information and telecommunications network, the Operator ensures the recording, systematisation, accumulation, storage, rectification (updating, amendment) and retrieval of personal data of citizens of the Russian Federation using databases located in the territory of the Russian Federation.

6.2. Persons who provide the Operator, including through the Website, with information about another personal-data subject without the consent of the subject whose personal data were provided are liable in accordance with the legislation of the Russian Federation.

6.3. The Operator stores personal data in a form allowing identification of the personal-data subject for no longer than required by the purposes of personal-data processing, unless the personal-data retention period is established by federal law or by an agreement to which the personal-data subject is a party, beneficiary or guarantor.

6.4. Personal data processed are subject to destruction in the event of:

  • expiry of the personal-data processing period;
  • achievement of the purposes of personal-data processing;
  • the loss of need to achieve the purposes of personal-data processing;
  • receipt of a withdrawal of consent to personal-data processing;
  • the Operator’s exclusion from the Unified State Register of Legal Entities.

7. PERSONAL DATA PROTECTION

7.1. The Operator takes the necessary legal, organisational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, dissemination and other unauthorised actions, including:

  • identifying threats to the security of personal data during processing;
  • adopting local regulatory acts and other documents governing relations in the area of personal-data processing and protection;
  • appointing persons responsible for ensuring personal-data security in the Operator’s structural units and information systems;
  • creating the necessary conditions for working with personal data;
  • organising records of documents containing personal data;
  • organising work with information systems in which personal data are processed;
  • storing personal data under conditions that ensure their preservation and exclude unlawful access to them;
  • organising training for the Operator’s employees who process personal data.

8. UPDATING, RECTIFICATION, DELETION AND DESTRUCTION OF PERSONAL DATA; RESPONSES TO PERSONAL DATA SUBJECTS’ ACCESS REQUESTS

8.1. Confirmation that the Operator processes personal data, the legal grounds and purposes of personal-data processing, and other information specified in Part 7 of Article 14 of the Personal Data Law are provided by the Operator to the personal-data subject or their representative upon application or receipt of a request from the personal-data subject or their representative within 10 (ten) business days after receiving the application or request. The information provided does not include personal data relating to other personal-data subjects, except where there are legal grounds for disclosure of such personal data.

8.2. A request must contain:

  • the number of the main identity document of the personal-data subject or their representative, information about the date of issue of that document and the issuing authority;
  • information confirming the personal-data subject’s relationship with the Operator, such as the agreement number, date of conclusion, code word and/or other information, or information otherwise confirming that the Operator processes personal data;
  • the signature of the personal-data subject or their representative.

8.3. A request may be sent as an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.

8.4. If an application (request) from a personal-data subject does not contain all information required under the Personal Data Law or the subject does not have access rights to the requested information, a reasoned refusal is sent to the subject.

8.5. A personal-data subject’s right of access to their personal data may be restricted in accordance with Part 8 of Article 14 of the Personal Data Law, including where the subject’s access to their personal data infringes the rights and lawful interests of third parties.

8.6. If inaccurate personal data are identified upon an application from a personal-data subject or their representative, their request, or a request from Roskomnadzor, the Operator blocks the personal data relating to that personal-data subject from the time of the application or receipt of the request for the period of verification, provided that blocking the personal data does not infringe the rights and lawful interests of the personal-data subject or third parties.

8.7. If the inaccuracy of personal data is confirmed, the Operator, on the basis of information provided by the personal-data subject, their representative or Roskomnadzor, or other necessary documents, rectifies the personal data within seven business days after such information is provided and unblocks the personal data.

8.8. If unlawful processing of personal data is identified upon an application (request) from a personal-data subject, their representative or Roskomnadzor, the Operator blocks the unlawfully processed personal data relating to that personal-data subject from the time of that application or receipt of the request.

8.9. When the purposes of personal-data processing are achieved, and if a personal-data subject withdraws consent to their processing, personal data are subject to destruction unless:

  • otherwise provided by an agreement to which the personal-data subject is a party;
  • the Operator may process the data without the personal-data subject’s consent on grounds provided by the Personal Data Law or other federal laws;
  • otherwise provided by another agreement between the Operator and the personal-data subject.

9. FINAL PROVISIONS

9.1. In compliance with the requirements of Part 2 of Article 18.1 of the Personal Data Law, this Policy is published in freely accessible form on the Operator’s Website in the Internet information and telecommunications network.

We use cookies and Yandex Metrica analytics to collect statistics and improve the site. By continuing to use the site, you consent to data processing. Learn more in our Privacy Policy

Request a callback

We’ll call you back and go over the details.