Privacy Policy

POLICY ON THE PROCESSING OF CUSTOMERS' PERSONAL DATA

1. General provisions

1.1. This document is adopted pursuant to clause 2 of part 1 of article 18.1 of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" (hereinafter – the Personal Data Law) and defines the policy of Sole Proprietor Markov Nikolay Alekseevich, OGRNIP 308263503900040, (hereinafter – the Operator) with respect to the processing of customers' personal data in the course of the Operator's entrepreneurial (business) activity, as well as the procedures aimed at preventing and detecting violations of the legislation of the Russian Federation in the field of personal data protection and at eliminating the consequences of such violations.

1.2. For the purposes of this Policy, the Operator's customers are the following natural persons:

  • users of the "SmartyKinesio" website and online store (https://smartykinesio.ru) owned by the Operator,
  • users of the "Kinesiologist Assistant" application owned by the Operator and published in the Apple App Store and Google Play application stores (hereinafter – the Operator's application);
  • natural persons who enter into civil-law contracts with the Operator, including those who provide their personal data in connection with an intention to enter into such a contract or to obtain information about the services rendered by the Operator and about the Operator's other activities;
  • natural persons acting as representatives (including managers) and employees of legal entities and sole proprietors with which the Operator enters into civil-law contracts, including those who provide their personal data in connection with an intention to enter into such a contract or to obtain information about the services rendered by the Operator and about the Operator's other activities;

1.3. All matters relating to the processing of personal data that are not governed by this Policy shall be resolved in accordance with the applicable legislation of the Russian Federation in the field of personal data.

1.4. This Policy does not apply to the processing and protection of the personal data of the Operator's employees.

2. Terms and definitions

2.1. For the purposes of this Policy, the following principal terms are used:

  • personal data – any information relating directly or indirectly to a specified or identifiable natural person (data subject);
  • processing of personal data – any action (operation) or set of actions (operations) performed on personal data with or without the use of automation means, including collection, recording, systematization, accumulation, storage, adjustment (updating, modification), retrieval, use, transfer (dissemination, provision, access), anonymization, blocking, deletion, destruction of personal data;
  • dissemination of personal data – actions aimed at disclosing personal data to an indefinite range of persons;
  • provision of personal data – actions aimed at disclosing personal data to a specified person or a specified range of persons;
  • information – particulars (communications, data) regardless of the form of their presentation.

2.2. The meaning of other concepts referred to in this Policy shall be determined in accordance with the Personal Data Law, other regulatory legal acts adopted in the field of personal data protection, and other provisions of the legislation of the Russian Federation.

3. Purposes of processing customers' personal data, procedure for giving and withdrawing customers' consent to the processing of personal data

3.1. Customers' personal data is processed for the purposes of:

  • providing customers with information about the services rendered by the Operator, the works performed by the Operator, and the goods sold by the Operator;
  • considering matters relating to the possibility of further cooperation between the Operator and the natural person;
  • concluding and performing, with a natural person, contracts relating to the Operator's entrepreneurial (business) activity;
  • concluding and performing, with a legal entity, contracts relating to the Operator's entrepreneurial (business) activity;
  • the Operator's analysis of the quality and volumes of the services it renders, the works it performs, and the goods it sells.

3.2. The Operator is entitled to process customers' personal data with their consent, unless otherwise provided by law.

3.3. Consent to the processing of personal data may be given by a customer in the following ways:

  • in simple written form, by sending it directly to the address of the Operator's location;
  • in electronic form on the Operator's website (https://smartykinesio.ru), by marking acknowledgement of and agreement with this Policy on the relevant page of the Operator's application;
  • in electronic form in the Operator's application, by marking acknowledgement of and agreement with this Policy on the relevant page of the Operator's application;
  • in any other way.

3.4. Where a customer gives consent in electronic form in the Operator's application or on the Operator's website, the customer, in accordance with article 9 of the Personal Data Law, gives consent to Markov Nikolay Alekseevich (INN: 263403162204, OGRNIP: 308263503900040, location: Stavropol, Pirogova St., 41, bldg. A) to the automated processing of his or her personal data, as well as to processing without the use of automation means, namely the performance of the actions provided for in clause 3 of article 3 of the Personal Data Law. In this case, the customer gives consent to the processing of personal data subject to the following conditions:

  • the list of personal data to the processing of which consent is given:
    • surname, given name, patronymic;
    • sex, age;
    • date and place of birth;
    • details of the passport of a citizen of the Russian Federation;
    • driver's licence details;
    • details of the vehicle state registration certificate;
    • address of registration at the place of residence and actual place of residence;
    • telephone number (home, mobile);
    • SNILS (individual insurance account number);
    • INN (taxpayer identification number);
  • the period during which the consent is valid: consent to the processing of personal data is valid from the day it is given on the Operator's website until the day it is withdrawn;
  • the manner of withdrawing consent: withdrawal of consent to the processing of personal data may be made in simple written form bearing the customer's handwritten signature and the date. A withdrawal made in this manner may be sent to the address of the Operator's location, delivered to an authorized representative of the Operator against signature, or sent in scanned form by email to: ceo@smartycode.ru

3.5. Consent to the processing of personal data on the terms established in clause 3.4 of this Policy is also deemed to have been given by the customer upon sending the Operator any electronic message using the Operator's application or website.

3.6. All ways of giving consent provided for by this Policy have equal legal force; the use of any one of these ways is sufficient to express the customer's will.

4. Customers' rights relating to the processing of personal data

4.1. A customer has the right to:

  • obtain access to his or her personal data and review it;
  • require the Operator to clarify, remove or correct personal data that is incomplete, incorrect, outdated, inaccurate, unlawfully obtained or not necessary for the Operator;
  • obtain from the Operator:
    • information about the persons who have access to the personal data or to whom such access may be granted;
    • the list of personal data being processed and the source from which it was obtained;
    • the periods for processing the personal data, including the periods of its storage;
    • information about the legal consequences that the processing of the data subject's personal data may entail for the data subject.
  • require the Operator to notify all persons to whom incorrect or incomplete personal data was previously communicated of all removals, corrections or additions made to it;
  • appeal, to the authorized body for the protection of data subjects' rights or in court, against unlawful acts or omissions of the Operator in the processing and protection of his or her personal data;
  • take other actions provided for by the legislation of the Russian Federation in the field of personal data protection.

4.2. All enquiries of the Customer on matters relating to the processing of his or her personal data may be sent to the operator by email to: wallet@kf26.ru

5. Access to customers' personal data and its protection

5.1. The list of persons having access to customers' personal data, including to personal data information systems, is established by an order of the Operator's head.

5.2. The right of access to the Operator's premises where tangible media containing personal data are located, as well as the right of access to the personal data information systems belonging to the Operator, is held exclusively by the persons named in the list approved in accordance with clause 5.1 of this Policy. Access of other persons to such premises and to personal data information systems is provided in the presence and with the consent of the persons having access to customers' personal data.

5.3. Persons having access to customers' personal data are obliged to:

  • ensure the safekeeping of tangible media containing personal data, including by storing such tangible media (including paper documents) on premises at the address of the Operator's location;
  • observe the restrictions on access to personal data information systems established by this Policy (including by setting passwords providing access to the technical means of such an information system);
  • immediately notify the Operator's head of all instances of unauthorized access to personal data and of its unlawful processing.

5.4. By an order of the Operator's head, an employee is appointed who is responsible for organizing the processing of personal data and ensuring the security of customers' personal data in information systems, and who ensures:

  • internal control over compliance by the Operator and its employees with the legislation of the Russian Federation on personal data, including the requirements for the protection of personal data, as well as with the Operator's policy on the processing of personal data and the Operator's local acts;
  • communication to the Operator's employees of the provisions of the legislation of the Russian Federation on personal data, of local acts on matters of personal data processing, and of the requirements for the protection of personal data;
  • the organization of the receipt and handling of enquiries and requests from customers or their representatives and (or) the exercise of control over the receipt and handling of such enquiries and requests;
  • the recording of machine-readable media containing personal data by drawing up a corresponding written list of machine-readable media and agreeing it with the Operator's head;
  • the timely detection of instances of unauthorized access to customers' personal data and the immediate communication of this information to the Operator's head;
  • the restoration of customers' personal data that has been modified or destroyed as a result of unauthorized access to it;
  • ongoing control over maintaining the level of protection of customers' personal data;
  • compliance with the conditions for the use of information protection means provided for by the operational and technical documentation;
  • where violations of the procedure for the provision of customers' personal data are detected, the immediate suspension of the provision of personal data to users of the personal data information system until the causes of the violations are identified and eliminated;
  • the investigation of, and preparation of conclusions on, instances of non-compliance with the conditions for storing tangible media containing customers' personal data or for using information protection means that may lead to a breach of the confidentiality of customers' personal data or to other violations resulting in a reduction of the level of protection of customers' personal data, and the development and adoption of measures to prevent possible dangerous consequences of such violations.

6. Liability for violation of the rules governing the processing of personal data

6.1. Persons guilty of violating the procedure for handling customers' personal data shall bear disciplinary, administrative, civil or criminal liability in accordance with the requirements of the legislation of the Russian Federation.

7. Final provisions

7.1. This Policy enters into force upon its approval by the Operator's head.

7.2. Amendments to this Policy are made by decision of the Operator's head. The amendments made enter into force upon approval of the new version of the Policy by the Operator's head.

7.3. By visiting the Operator's application and using the information posted on it, the Customer confirms that he or she has reviewed this Policy and expresses agreement with its terms.

7.4. This Policy is publicly available. Public availability of this Policy is ensured by publishing its text in electronic form on the Operator's website and in the Operator's application, as well as in hard copy at the address of the Operator's location, with the opportunity for any interested person to review it.

Operator

Sole Proprietor Markov Nikolay Alekseevich

INN 263403162204

OGRNIP 308263503900040

Current account (₽) 40802810102500041748

Bank name TOCHKA PJSC BANK "FC OTKRITIE"

City Stavropol

BIC 044525999

Corr. account 30101810845250000999

Last updated: 15.07.2025