Privacy Policy
Privacy Policy of Albion LLC Regarding Personal Data Processing
1. Purpose
1.1. This Personal Data Processing Policy (hereinafter – the Policy) has been developed in accordance with Federal Law No. 152-FZ of July 27, 2006 “On Personal Data” (hereinafter – FZ-152), subordinate legislation thereto, and the Recommendations of Roskomnadzor on compiling a document defining the operator’s policy regarding personal data processing, in the manner established by FZ-152.
1.2. This Policy defines the general purposes and principles of personal data processing and measures to ensure the security of personal data in Albion LLC with the aim of protecting the rights and freedoms of individuals and citizens in the processing of their personal data, and sets forth the intentions and commitments officially expressed by the management of Albion LLC in this area.
1.3. This Policy is valid for 3 (three) years and may be revised upon expiration of this period, or earlier – in the event of changes to applicable legislation in the field of personal data protection and processing.
2. Scope of Application
2.1. This Policy is mandatory for application by all employees of Albion LLC regardless of their position, including full-time and part-time employees, from the date the Policy enters into force. Other local regulatory acts on ensuring and protecting personal data in Albion LLC must not contradict this Policy.
3. Terms and Definitions
3.1 Service — software administered by the Operator that serves as a source of information and enables interaction between the User and the Operator using technical means, including the website located at albatros-bct.com, with a unique URL (Uniform Resource Locator), representing a group of interconnected web pages (Personal Accounts), as well as mobile applications designed for use on smartphones, tablets, and other mobile devices on iOS and Android platforms.
3.2. Automated processing of personal data – processing of personal data using computing equipment.
3.3. Blocking of personal data – temporary cessation of personal data processing (except in cases where processing is necessary for clarifying personal data).
3.4. Anonymization of personal data – actions resulting in the impossibility of determining, without the use of additional information, the attribution of personal data to a specific personal data subject.
3.5. Processing of personal data – any action (operation) or set of actions (operations) with personal data, whether performed using automation tools or without them. Processing of personal data includes:
collection;
recording;
systematization;
accumulation;
storage;
clarification (updating, modification);
retrieval;
use;
transfer (distribution, provision, access);
anonymization;
blocking;
deletion;
destruction.
3.6. Operator – an organization that independently or jointly with other persons organizes the processing of personal data, and also determines the purposes of processing personal data subject to processing, the actions (operations) performed with personal data. The Operator under this Policy is Limited Liability Company “Albion”.
3.7. Personal data – any information relating directly or indirectly to an identified or identifiable natural person (personal data subject). For the purposes of this Policy, personal data means both information that the User provides about themselves independently when using the Service, and information that is automatically transmitted to the Operator in the process of using the Service via software installed on the User’s device.
3.8. Identified (or identifiable) person – any natural person using the Service and providing Personal Data to the Operator.
3.9. Provision of personal data – actions aimed at disclosing personal data to a specific person or a specific group of persons.
3.10. Distribution of personal data – actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data).
3.11. Cross-border transfer of personal data – transfer of personal data to the territory of a foreign state to a foreign government authority, foreign natural person, or foreign legal entity.
3.12. Destruction of personal data – actions resulting in the impossibility of restoring the content of personal data in the personal data information system and/or resulting in the destruction of physical media containing personal data.
3.13. Personal data information system – a set of personal data contained in databases and the information technologies and technical means that ensure their processing.
4. Responsibility / Process Owner
4.1. Employees of the Operator found guilty of violating the requirements of this Policy may be held liable, including financial liability, for causing material damage to the Operator associated with the Operator being held administratively or criminally liable in the form of a fine, or the Operator compensating property and/or moral damage to the personal data subject as a result of unlawful actions by such employees of the Operator.
4.2. Oversight of compliance with the requirements of this Policy is carried out by the Management of the Operator company (Albion LLC).
5. General Provisions
5.1. This Policy defines the procedure and conditions for personal data processing by the Operator, the procedure for access to personal data, the personal data protection system, and the procedure for organizing internal control in the processing of personal data. The Policy has been developed for the purpose of complying with the requirements of the legislation of the Russian Federation on personal data protection when using the User’s personal data for the operation of the Service, identifying the User when using the Service, including during User registration in the Service and creation of an account, carrying out interaction with the User, including by sending notifications, requests, and information related to the use of the Service, execution of agreements, contracts, and transactions with the Operator, as well as processing requests from the User.
5.2. By using the Service, the User, in compliance with the requirements of Federal Law No. 152-FZ of July 27, 2006 “On Personal Data”, provides the Operator with their consent to the processing of their personal data in accordance with this Policy.
5.2.1. By using the Service, the User unconditionally agrees to receive service SMS messages and push notifications necessary for the implementation of the Operator’s mobile application functionality, including information about order status changes, changes in the procedure and conditions of service provision, and organizational and news messages from the Operator.
5.2.2. The Operator has the right to inform the User about the procedures and methods of using the Service, in particular the Operator’s mobile application, about marketing, advertising, and other events conducted by the Operator by making calls, sending SMS messages and push notifications to the User. Acceptance of the terms of this Agreement means the User’s unconditional consent to receive SMS messages and push notifications sent by the Operator as part of marketing activities, including those containing advertising information.
5.3. This Policy does not address issues of ensuring the security of personal data that have been classified as state secrets of the Russian Federation in the established manner.
6. Principles and Conditions of Personal Data Processing
6.1. Principles of personal data processing:
6.1.1. Personal data processing must be carried out on a lawful and fair basis;
6.1.2. Personal data processing must be limited to the achievement of specific, predetermined, and lawful purposes. Processing of personal data that is incompatible with the purposes of personal data collection is not permitted;
6.1.3. The merging of databases containing personal data processed for purposes that are incompatible with each other is not permitted;
6.1.4. Only personal data that meets the purposes of its processing shall be subject to processing;
6.1.5. The content and scope of processed personal data must correspond to the stated purposes of processing. The processed personal data must not be excessive in relation to the stated purposes of its processing;
6.1.6. When processing personal data, the accuracy of personal data, its sufficiency, and, where necessary, its relevance to the purposes of personal data processing must be ensured;
6.1.7. Storage of personal data must not continue longer than required by the purposes of personal data processing, unless the personal data storage period is established by federal law or a contract to which the User is a party;
6.1.8. Processed personal data shall be subject to destruction or anonymization upon the achievement of the processing purposes or in the event that the necessity of achieving these purposes has been lost, unless otherwise provided by federal law.
6.2. Conditions of personal data processing.
6.2.1. Processing of Users’ personal data is carried out on the basis of the current legislation of the Russian Federation in the field of personal data protection, including the Constitution of the Russian Federation, the Civil Code of the Russian Federation, and Federal Law No. 152-FZ of July 27, 2006 “On Personal Data”.
6.2.2. Personal data processing is carried out in compliance with the principles and rules provided for by this Policy and the legislation of the Russian Federation.
6.3. Confidentiality of personal data.
6.3.1. The Operator and other persons who have gained access to personal data are obliged not to disclose to third parties and not to distribute personal data without the consent of the personal data subject, unless otherwise provided by federal law of the Russian Federation.
6.4. Delegation of personal data processing to another person.
6.4.1. The Operator has the right to delegate the processing of personal data to other persons with the consent of the personal data subject, unless otherwise provided by federal law and/or GDPR, on the basis of a contract concluded with such person. The person processing personal data on behalf of the Operator is obliged to comply with the principles and rules of personal data processing provided for by FZ-152 and this Policy.
7. Purposes of Personal Data Processing.
7.1. Processing of Users’ personal data is carried out exclusively for the purpose of providing the User with the ability to interact with the Service and facilitating communication between the Operator and the User, including by sending notifications, requests, and information related to the use of the Service, execution of agreements, contracts, and transactions with the Operator, as well as processing requests from the User.
7.2. The Operator processes only those personal data that are necessary for the use of the Service or the execution of agreements and contracts with the User, except in cases where the legislation provides for other requirements for personal data processing.
7.3. Sources of obtaining Users’ personal data.
7.3.1. The source of information about all personal data of the User is the User themselves.
7.3.2. The source of information about the User’s personal data is data obtained as a result of the Operator granting the User the right to use the Service.
7.3.3. Personal data of Users constitutes confidential information with restricted access.
7.3.4. Ensuring the confidentiality of personal data is not required in the case of their anonymization, as well as in relation to publicly available personal data.
7.3.5. The Operator does not have the right to collect and process the User’s personal data regarding their race, nationality, political views, religious or philosophical beliefs, or private life, except in cases provided for by applicable legislation.
7.3.6. The Operator does not have the right to obtain and process the User’s personal data regarding their membership in public associations or their trade union activities, except in cases provided for by applicable legislation of the Russian Federation.
7.4. Methods of personal data processing.
7.4.1. Personal data of Users is processed exclusively using automation tools.
7.5. Rights of Users.
7.5.1. The User has the right to receive information about the Operator, its location, whether the Operator possesses personal data relating to a specific personal data subject (the User), as well as to review such personal data, except in cases provided for by Part 8 of Article 14 of the Federal Law “On Personal Data”.
7.5.2. The User has the right to receive from the Operator, upon personal application or upon the Operator’s receipt of a written request from the User, the following information relating to the processing of their personal data, including:
- confirmation of the fact of personal data processing by the Operator, as well as the purpose of such processing;
- legal grounds and purposes of personal data processing;
- purposes and methods of personal data processing applied by the Operator;
- the name and location of the Operator, information about persons (other than the Operator's employees) who have access to personal data or to whom personal data may be disclosed on the basis of a contract with the Operator or on the basis of federal law;
- the personal data being processed relating to the relevant personal data subject, the source of their acquisition, unless a different procedure for providing such data is established by federal law;
- personal data processing periods, including storage periods;
- the procedure for the personal data subject to exercise the rights provided for by federal law;
- information about completed or planned cross-border data transfers;
- the name or surname, first name, patronymic, and address of the person processing personal data on behalf of the Operator, if processing has been or will be delegated to such person;
- other information provided for by applicable legislation of the Russian Federation.
7.5.3. The User has the right to request the modification, clarification, or deletion of information about themselves.
7.5.4. The User has the right to supplement personal data of an evaluative nature with a statement expressing their own point of view.
7.5.5. The User has the right to designate representatives for the protection of their personal data.
7.5.6. The User has the right to request that the Operator notify them of all changes made to or exclusions from their data.
7.5.7. The User has the right to file a complaint with the authorized body for the protection of personal data subjects’ rights or to take legal action against the actions or inaction of the Operator if they believe that the latter is processing their personal data in violation of the requirements of the Federal Law “On Personal Data” or otherwise violating their rights and freedoms.
7.5.8. The personal data User has the right to protect their rights and legitimate interests, including the right to compensation for damages and/or compensation for moral harm through judicial proceedings.
7.6. Obligations of the Operator.
7.6.1. Upon personal application or upon receipt of a written request from the personal data subject or their representative, the Operator, if there are grounds, is obliged to provide the information within the scope established by federal law within 30 days from the date of application or receipt of the request from the personal data subject or their representative. Such information must be provided to the personal data subject in an accessible form, and it must not contain personal data relating to other personal data subjects, except in cases where there are lawful grounds for disclosing such personal data.
7.6.2. All applications from personal data subjects or their representatives are registered in the Log of Citizens’ (Personal Data Subjects’) Applications Regarding Personal Data Processing.
7.6.3. In the event of a refusal to provide the personal data subject or their representative with information about the existence of personal data about the relevant personal data subject, the Operator is obliged to provide a motivated response in writing containing a reference to the provision of Part 8 of Article 14 of the Federal Law “On Personal Data” or another federal law that serves as the basis for such refusal, within a period not exceeding 30 days from the date of application by the personal data subject or their representative, or from the date of receipt of the request from the personal data subject or their representative.
7.6.4. In the event of receiving a request from the authorized body for the protection of personal data subjects’ rights to provide information necessary for the activities of the said body, the Operator is obliged to provide such information to the authorized body within 30 days from the date of receipt of such request.
7.6.5. In the event of discovering unlawful processing of personal data upon application or request from the personal data subject or their representative or the authorized body for the protection of personal data subjects’ rights, the Operator is obliged to block the unlawfully processed personal data relating to this personal data subject from the moment of such application or receipt of the specified request for the duration of the investigation.
7.6.6. In the event of discovering unlawful processing of personal data carried out by the Operator, the latter is obliged to cease the unlawful processing of personal data within a period not exceeding 3 (three) business days from the date of such discovery. The Operator is obliged to notify the personal data subject or their representative about the elimination of the committed violations, and if the application of the personal data subject or their representative or the request of the authorized body for the protection of personal data subjects’ rights was sent by the authorized body, the said body must also be notified.
7.6.7. In the event of achieving the purpose of personal data processing, the Operator is obliged to cease processing personal data and destroy the personal data within a period not exceeding 30 (thirty) business days from the date of achieving the purpose of personal data processing, unless otherwise provided by the contract to which the personal data subject is a party.
7.6.8. It is prohibited to make decisions based solely on automated personal data processing that produce legal consequences for the personal data subject or otherwise affect their rights and legitimate interests.
7.7. Regime of confidentiality of personal data.
7.7.1. The Operator ensures the confidentiality and security of personal data during their processing in accordance with the requirements of the legislation of the Russian Federation.
7.7.2. The Operator does not disclose to third parties and does not distribute personal data without the User’s consent thereto, unless otherwise provided by federal law.
7.7.3. In accordance with the list of personal data processed under this Policy, the personal data of Users constitutes confidential information.
7.7.4. Persons processing personal data are obliged to comply with the requirements of the Operator’s regulatory documents regarding the confidentiality and security of personal data.
8. Personal Data Processing.
8.1. The list of Users’ personal data subject to processing, provided including through filling in the corresponding input fields when using the Service, may include the following information:
- surname;
- first name;
- patronymic (if applicable);
- gender;
- date of birth;
- contact phone number;
- email address;
- other information about the User generated when using the Service.
8.2. In accordance with the legislation of a number of countries, it is necessary to provide additional information about the User, including passport data. The User undertakes to provide this information to the Operator upon request. If the necessary information is not provided, the Operator will not be able to fulfill its obligations arising from contractual relations with the User and will have the right to refuse to provide the service.
8.3. Personal data permitted for processing in accordance with this Policy and automatically transmitted to the Operator in the process of using the Service via software installed on the User’s device may include the following information:
- IP address of the User's device;
- information about the User's browser;
- technical characteristics of the device and software used by the User;
- date and time of access to the Service;
- addresses of requested web pages;
- User's location (based on GPS and network).
The Operator does not store this information.
Geolocation data: The Operator may also access, collect, track, and/or remotely store the “geolocation data” of Users, which may include GPS coordinates of the User’s location or similar information about the location of the User’s mobile device.
8.4. Persons entitled to access personal data.
8.4.1. Persons authorized with the corresponding powers in accordance with their official duties have the right to access the personal data of Users.
8.4.2. The list of persons with access to personal data is approved by the General Director of the Operator.
8.5. Procedure and periods of personal data storage.
8.5.1. The Operator stores Users’ personal data on the Service.
8.5.2. The periods of storage of Users’ personal data on the Service are defined by the conditions of this Policy, take effect from the moment the User accepts (accedes to) this Policy by interacting with the Operator’s Service, and remain in effect until the User declares their desire to delete their personal data from the Service.
8.5.3. In the event of data deletion from the Service upon the initiative of either party, namely cessation of use of the Service, the User’s personal data is stored in the Operator’s databases for five years in accordance with the legislation of the Russian Federation.
8.5.4. Upon expiration of the above storage period, the User’s personal data is automatically deleted by an algorithm set by the Operator.
8.5.5. The Operator does not process Users’ personal data on paper media.
8.6. Blocking of personal data.
8.6.1. Blocking of personal data means the temporary cessation by the Operator of processing operations at the User’s request upon discovery of inaccurate processed data or actions that the personal data subject considers unlawful with respect to their data.
8.6.2. Blocking of personal data is carried out on the basis of a written application from the personal data subject.
8.7. Destruction of personal data.
8.7.1. Destruction of personal data means actions resulting in the impossibility of restoring the content of personal data on the Website and/or resulting in the destruction of physical media containing personal data.
8.7.2. The User has the right to request in writing the destruction of their personal data if the personal data is incomplete, outdated, inaccurate, unlawfully obtained, or is not necessary for the stated purpose of processing.
8.7.3. In the event that destruction of personal data is not possible, the Operator blocks such personal data.
8.7.4. Destruction of personal data is carried out by erasing information using software with guaranteed destruction (in accordance with the specified characteristics for the installed software with guaranteed destruction).
8.7.5. The Operator does not delegate the processing of personal data to third parties or organizations. The Operator may transfer personal data to third parties exclusively for the proper fulfillment of its obligations under contracts and agreements concluded with the personal data subject. The personal data of Users is processed by the Operator’s employees (database administrators, etc.) who have been granted access to the processing of Users’ personal data in the established manner.
8.8. Ensuring the security of personal data.
8.8.1. The security of personal data processed by the Operator is ensured through the implementation of legal, organizational, and technical measures necessary to meet the requirements of federal legislation in the field of personal data protection.
8.8.2. To prevent unauthorized access to personal data, the Operator applies the following organizational and technical measures:
8.8.2.1. Appointment of officials responsible for organizing the processing and ensuring the security of personal data.
8.8.2.2. Limiting the composition of persons granted access to personal data processing.
8.8.2.3. Familiarizing employees with the requirements of federal legislation and the Operator’s regulatory documents on the processing and protection of personal data.
8.8.2.4. Organization of accounting, storage, and handling of media containing information with personal data.
8.8.2.5. Development of local regulatory acts in the field of personal data protection.
8.8.2.6. Carrying out internal control of compliance of personal data processing with applicable legislation in the field of personal data processing and security.
8.8.2.7. Monitoring and tracking of deadlines for processing applications and requests for the realization of personal data subjects’ rights.
8.8.2.8. Taking measures to ensure the security of personal data processing by third parties who gain access to personal data (concluding special contracts and processing commissions).
8.8.2.9. Tracking security incidents (if any) and their consequences, investigating them, and, if necessary, notifying the supervisory authority, as well as personal data subjects (if necessary) within 72 hours.
8.8.2.10. Conducting regular audits of personal data processing procedures.
9. Final Provisions.
9.1. In the event of changes to the applicable legislation of the Russian Federation or amendments to regulatory documents on personal data protection, this Policy remains in force in the part that does not contradict the applicable legislation until it is brought into compliance with such changes.
9.2. The conditions of this Policy are established, amended, and revoked by the Operator unilaterally without prior notice to the User. From the moment a new version of the Policy is published on the Service, the previous version is considered to have lost its force. In the event of a material change to the conditions of this Agreement, the Operator notifies Users by publishing a corresponding message on the Service.
10. Contact Information
Limited Liability Company
“Albion”
Albion LLC
Legal address/actual address: 353925, Krasnodar Territory, Novorossiysk, Dzerzhinsky Ave., 211 bld. 5, Office 2
TIN (INN) 2312312633
Tax Registration Reason Code (KPP) 231501001
Primary State Registration Number (OGRN) 1222300045296
Bank Identification Code (BIC) 045004774
Ruble current account No. 40702810923060002329 at the NOVOSIBIRSK BRANCH of JSC ALFA-BANK
TIN 7728168971 / OGRN 1027700067328 / BIC 045004774
Correspondent account: 30101810600000000774 at the SIBERIAN MAIN DIRECTORATE OF THE BANK OF RUSSIA