Personal Data Processing Policy
  1. General Provisions This Policy on Personal Data Processing is drawn up in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006, “On Personal Data” (hereinafter the Law on Personal Data) and sets out the procedure for processing personal data and the measures to ensure the security of personal data, undertaken by LLC "Arch Group" (hereinafter the Operator).
1.1. The Operator’s foremost goal and condition for carrying out its activities is to safeguard the rights and freedoms of individuals in their processing of personal data, including the right to privacy, personal and family secrets.
1.2. This Policy of the Operator regarding the processing of personal data (hereinafter the Policy) applies to all information that the Operator may receive about visitors to the website https://archgroupp.com/.
2. Key Concepts Used in the Policy
2.1. Automated processing of personal data — processing of personal data by means of computer technology.
2.2. Blocking of personal data — temporary cessation of processing of personal data (except when processing is necessary to clarify the personal data).
2.3. Website — the collection of graphical and informational materials, as well as software and databases that ensure their availability on the Internet at the network address https://archgroupp.com/.
2.4. Information system of personal data — the set of personal data contained in databases and the information technologies and technical means that ensure their processing.
2.5. Anonymization of personal data — actions by which it becomes impossible to identify the data subject without the use of additional information.
2.6. Processing of personal data — any action (operation) or set of actions (operations) performed using automation tools or without them with personal data, including collection, recording, systematization, accumulation, storage, clarification (update, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion, destruction of personal data.
2.7. Operator — a government body, municipal body, legal or natural person, acting alone or jointly with others, organizing and/or carrying out the processing of personal data, and also determining the purposes of processing, the composition of personal data to be processed, and actions (operations) performed with personal data.
2.8. Personal data — any information directly or indirectly relating to a specific or identifiable User of the website https://archgroupp.com/.
2.9. Personal data allowed for dissemination — personal data the access to which is provided to an unlimited circle of persons by the data subject’s consent for processing of personal data, in the manner provided by the Law on Personal Data (hereinafter — personal data allowed for dissemination).
2.10. User — any visitor to the website https://archgroupp.com/.
2.11. Providing personal data — actions aimed at disclosing personal data to a specific person or a specific circle of persons.
2.12. Dissemination of personal data — any actions aimed at disclosing personal data to an undefined circle of persons (transmission of personal data) or making personal data available to an undefined circle of persons, including publication in mass media, posting on information and telecommunication networks, or providing access to personal data by any other means.
2.13. Cross-border transfer of personal data — transfer of personal data to the territory of a foreign state to a government body of a foreign state, a foreign natural person, or a foreign legal entity.
2.14. Destruction of personal data — actions by which personal data are irretrievably destroyed and cannot be restored in the information system of personal data and/or destroyed on physical media.
3. The Operator’s Rights and Obligations
3.1. The Operator has the right: — to obtain from the data subject reliable information and/or documents containing personal data; — in the event of withdrawal of consent to the processing of personal data by the data subject, as well as upon receipt of a request to cease processing, the Operator may continue processing personal data without the data subject’s consent if there are grounds specified in the Law on Personal Data; — to independently determine the composition and list of measures necessary and sufficient to ensure compliance with the obligations provided by the Law on Personal Data and regulatory acts adopted in accordance with it, unless otherwise provided by the Law on Personal Data or other federal laws.
3.2. The Operator must: — provide the data subject with information concerning the processing of their personal data upon request; — organize the processing of personal data in the manner established by current legislation of the Russian Federation; — respond to requests and inquiries from data subjects and their lawful representatives in accordance with the requirements of the Law on Personal Data; — inform the authorized body for protecting the rights of data subjects upon its request of the necessary information within 10 days from the date of receipt of such request; — publish or otherwise ensure unrestricted access to this Policy on the processing of personal data; — take legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, dissemination, or other unlawful actions with respect to personal data; — terminate transfers (dissemination, provision, access) of personal data, stop processing, and destroy personal data in the manner and in cases provided by the Law on Personal Data; — perform other duties provided by the Law on Personal Data.
4.The Rights and Obligations of Data Subjects
4.1. Data subjects have the right: — to receive information concerning the processing of their personal data, except as provided by federal law. Information must be provided in an accessible form and must not contain personal data relating to other data subjects, unless there are lawful grounds for disclosure of such data. The list of information and the procedure for obtaining it are established by the Law on Personal Data; — to require the Operator to clarify, block, or destroy their personal data if the data are incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated purpose of processing, and to take legal measures to protect their rights; — to impose a condition of prior consent for processing of personal data for the purposes of marketing; — to withdraw consent to processing of personal data, as well as to issue a requirement to cease processing; — to appeal to the competent authority for the protection of data subjects’ rights or to a court against unlawful actions or inaction of the Operator in processing their personal data; — to exercise other rights provided by the legislation of the Russian Federation.
4.2. Data subjects are obligated to: — provide reliable data about themselves to the Operator; — inform the Operator about clarifications (updates, changes) to their personal data.
4.3. Persons who provided unreliable information about themselves or information about another data subject without consent bear responsibility under the law of the Russian Federation.
5. Principles of Personal Data Processing
5.1. Processing of personal data is carried out on a legal and fair basis.
5.2. Processing of personal data is limited to achieving specific, predefined, and legitimate purposes. Processing of personal data incompatible with the purposes of collection is not allowed. ,
5.3. It is not allowed to merge databases containing personal data whose processing purposes are incompatible with each other.
5.4. Only personal data that meet the purposes of processing are to be processed.
5.5. The content and scope of processed personal data must correspond to the declared purposes of processing. There must be no excessive processing of personal data relative to the declared purposes.
5.6. When processing personal data, the accuracy of personal data, their sufficiency, and, where necessary, their relevance to the purposes of processing must be ensured. The Operator takes necessary measures and/or ensures their adoption to delete or update incomplete or inaccurate data.
5.7. Personal data retention is carried out in a form that allows identifying the data subject, no longer than is required for the purposes of processing, unless a retention period is established by federal law, by contract, or by a party to which the contract is concluded, with the data subject being the beneficiary or guarantor. Personal data are destroyed or anonymized after achieving the purposes of processing or if there is no longer a need to achieve these purposes, unless otherwise provided by federal law.
6. Purposes of Personal Data Processing Purpose of processing — informing the User by sending electronic mailings Personal Data — surname, given name, patronymic; email address; phone numbers Legal Basis — Federal Law “On Information, Information Technologies and the Protection of Information” of July 27, 2006 No. 149-FZ Types of Personal Data Processing — Sending informational emails to the email address
7. Conditions for Personal Data Processing
7.1. Processing is carried out with the consent of the data subject for the processing of their personal data.
7.2. Processing is necessary to achieve the purposes provided for by international treaty of the Russian Federation or by law, and to perform functions, powers, and duties established for the Operator.
7.3. Processing is necessary for the administration of justice, execution of a judicial act, an act of another body or official, to be executed in accordance with the law on enforcement proceedings.
7.4. Processing is necessary for the performance of a contract, to which the data subject is a party or beneficiary or guarantor, or at the initiative of the data subject or for the conclusion of a contract at the initiative of the data subject or where the data subject will be a beneficiary or guarantor.
7.5. Processing is necessary to protect the legitimate interests of the Operator or third parties or for achieving socially significant goals, provided that the rights and freedoms of the data subject are not violated.
7.6. Processing of personal data that is publicly available because the data subject provided access to it or because it is accessible to an unlimited circle of persons.
7.7. Processing of personal data that must be published or disclosed in accordance with federal law.
8. Procedures for Collection, Storage, Transfer, and Other Types of Processing of Personal Data The security of Personal Data processed by the Operator is ensured by implementing legal, organizational, and technical measures necessary to fully meet the requirements of applicable law in the field of personal data protection.
8.1. The Operator ensures the safety of Personal Data and takes all possible measures to prevent access to Personal Data by unauthorized persons. 8.2. Personal Data of the User will never be transferred to third parties, except in cases related to the enforcement of applicable law or if the data subject consents to transferring the data to a third party to fulfill obligations under a civil contract.
8.3. If inaccuracies are found in Personal Data, the User can update them themselves by sending a notification to the Operator’s email address info-archgroup@yandex.ru with the note “Updating Personal Data.”
8.4. The retention period for Personal Data is determined by achieving the purposes for which the data were collected, unless another period is established by contract or applicable law. A user may at any time withdraw their consent to the processing of Personal Data by sending a notice to the Operator at the email address info-archgroup@yandex.ru with the note “Withdrawal of consent to processing of personal data.”
8.5. All information collected by third-party services, including payment systems, communications services, and other service providers, is stored and processed by those entities (the Operators) in accordance with their Terms of Service and Privacy Policy. The data subject and/or the documents referenced apply. The Operator bears no responsibility for the actions of third parties, including the service providers mentioned in this section.
8.6. Prohibitions imposed by the data subject on transfers (except for access) and on processing or processing conditions (except for access) of data allowed for dissemination do not apply in cases of processing of data in the public interest, public authorities, and other public interests as determined by law.
8.7. The Operator ensures the confidentiality of Personal Data during processing.
8.8. The Operator stores Personal Data in a form allowing identification of the data subject no longer than is required for the purposes of processing, unless a longer retention period is provided by federal law, by contract, or by the party to which the contract is concluded, with the data subject being the beneficiary or guarantor.
8.9. A condition for the termination of processing of Personal Data may be the achievement of the purposes of processing, the expiration of the data subject’s consent, withdrawal of consent by the data subject, or a demand to stop processing, as well as detection of unlawful processing of Personal Data.
9. List of Actions Performed by the Operator with Received Personal Data
9.1. The Operator collects, records, systematizes, accumulates, stores, updates (clarifies), retrieves, uses, transfers (disseminates, provides, gives access), anonymizes, blocks, deletes, and destroys Personal Data.
9.2. The Operator performs automated processing of Personal Data with the receipt and/or transfer of received information over information and telecommunications networks or without such networks.
10. Cross-Border Transfer of Personal Data
10.1. Before beginning activities related to cross-border transfer of Personal Data, the Operator must notify the authorized body for protecting the rights of data subjects about its intention to conduct cross-border transfers (such notification is sent separately from the notification of the intention to process Personal Data).
10.2. Before filing the above notification, the Operator must obtain from foreign authorities, foreign natural persons, and foreign legal entities from whom cross-border transfers are planned, the relevant information.
11. Confidentiality of Personal Data The Operator and other persons who have access to Personal Data are obligated not to disclose or disseminate Personal Data to third parties without the data subject’s consent, unless otherwise provided by federal law.
12. Final Provisions
12.1. A user may obtain any explanations regarding questions about processing their Personal Data by contacting the Operator at the email info-archgroup@yandex.ru.
12.2. This document will reflect any changes to the Operator’s Personal Data Processing Policy. The Policy is in effect indefinitely until replaced by a new version.
12.3. The current version of the Policy is freely available on the Internet at https://archgroupp.com/