This is an English translation provided for convenience. In case of any discrepancy with the Russian version, the Russian text prevails. The agreement is governed by the laws of the Russian Federation.
This Personal Data Processing Policy is drafted in accordance with the requirements of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" (the "Personal Data Law") and defines the procedure for processing personal data and the security measures taken by the Sole Proprietor P.S. Bataev (the "Operator").
1. General provisions
1.1. The Operator's most important goal and condition for its activities is respect for human and civil rights and freedoms when processing personal data, including protection of the right to privacy of personal and family life.
1.2. This Policy applies to all information that the Operator may obtain about visitors of the website https://neiroset.com.
2. Key terms used in the Policy
2.1. Automated processing of personal data — processing of personal data using computing technology.
2.2. Blocking of personal data — temporary cessation of personal data processing (except where processing is needed to update the data).
2.3. Website — the set of graphical and informational materials, computer programs and databases ensuring their availability on the Internet at https://neiroset.com.
2.4. Personal data information system — a set of personal data contained in databases together with the information technologies and technical means ensuring their processing.
2.5. Anonymization of personal data — actions resulting in the impossibility of determining, without additional information, whether the personal data belong to a specific User.
2.6. Processing of personal data — any action (operation) or set of actions performed using or without using automation tools, including collection, recording, systematization, accumulation, storage, refinement (update, change), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion, destruction.
2.7. Operator — a state or municipal authority, legal entity, or individual who, alone or jointly with others, organizes and/or carries out personal data processing and defines its purposes, the data composition, and the actions performed.
2.8. Personal data — any information that relates directly or indirectly to a defined or definable User of the website https://neiroset.com.
2.9. Personal data permitted by the data subject for distribution — personal data that the data subject grants access to an unlimited number of persons by giving consent for processing such data, in the manner provided by the Personal Data Law (the "data permitted for distribution").
2.10. User — any visitor of the website https://neiroset.com.
2.11. Provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons.
2.12. Distribution of personal data — any actions aimed at disclosing personal data to an unlimited group of persons (transferring personal data) or making personal data available to an unlimited group, including publishing in mass media, posting on networks, or providing access in any other way.
2.13. Destruction of personal data — actions resulting in irrevocable destruction of personal data, with no ability to restore the contents in the personal data information system, and/or destruction of physical media.
3. The Operator's main rights and obligations
3.1. The Operator has the right to:
- obtain reliable information and/or documents containing personal data from the data subject;
- continue processing personal data without the data subject's consent if grounds set out in the Personal Data Law are present, in case the data subject revokes consent;
- independently determine the composition and list of measures necessary and sufficient to fulfill obligations under the Personal Data Law and related regulations, unless otherwise provided by law.
3.2. The Operator must:
- provide the data subject, upon request, with information regarding the processing of their personal data;
- organize personal data processing as required by the laws of the Russian Federation;
- respond to requests and inquiries from data subjects and their legal representatives in accordance with the Personal Data Law;
- provide the authorized body for the protection of data subjects' rights, upon its request, with the necessary information within 30 days of receipt of the request;
- publish or otherwise ensure unrestricted access to this Policy;
- take legal, organizational, and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, provision, distribution, and other unlawful actions;
- cease transfer (distribution, provision, access) of personal data, stop processing, and destroy personal data in accordance with the Personal Data Law;
- fulfill other duties under the Personal Data Law.
4. Main rights and obligations of data subjects
4.1. Data subjects have the right to:
- obtain information about the processing of their personal data, except in cases provided by federal laws;
- require the Operator to update, block, or destroy their personal data when it is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary, and to take legal measures to protect their rights;
- require prior consent for processing personal data for the purpose of marketing;
- revoke consent and require cessation of processing;
- appeal unlawful actions or omissions of the Operator to the authorized body or in court;
- exercise other rights provided by Russian law.
4.2. Data subjects must:
- provide the Operator with reliable information about themselves;
- inform the Operator of any update (change) to their personal data.
4.3. Persons who provide the Operator with false information about themselves or about another data subject without that subject's consent bear responsibility under Russian law.
5. Personal data of the User that the Operator may process
5.1. Email address.
5.2. Phone numbers.
5.4. First and last names.
5.5. The site also collects and processes anonymized visitor data (including cookies) using web analytics services (Yandex Metrica and others).
5.6. The above data are referred to throughout this Policy as Personal Data.
5.7. Special categories of personal data concerning racial and ethnic origin, political views, religious or philosophical beliefs, or intimate life are not processed by the Operator.
5.8. Processing of data permitted for distribution from special categories listed in Article 10(1) of the Personal Data Law is allowed if the prohibitions and conditions provided in Article 10.1 are observed.
5.9. Consent to processing of data permitted for distribution is given separately from other consents. The conditions of Article 10.1 of the Personal Data Law apply. The content requirements are set by the authorized body for the protection of data subjects' rights.
5.9.1. The User gives consent for processing of data permitted for distribution directly to the Operator.
5.9.2. The Operator must, within three business days from receiving such consent, publish information about the conditions, prohibitions, and conditions for the processing of data permitted for distribution.
5.9.3. Transfer of data permitted by the data subject for distribution must cease at any time at the data subject's request. Such request must include the subject's full name, contact information (phone, email or postal address), and the list of data whose processing must stop. Such data may be processed only by the Operator to whom the request is sent.
5.9.4. Consent to processing of data permitted for distribution terminates upon receipt by the Operator of the request mentioned in 5.9.3.
5.10. Use of Yandex Metrica
5.10.1. To analyze the website's traffic at https://neiroset.com, improve its functionality, and provide a better user experience, the Operator uses Yandex Metrica, provided by Yandex LLC (Russian Federation, 119021, Moscow, Lev Tolstoy St. 16).
5.10.2. Yandex Metrica uses cookies and similar technologies to collect data on user actions on the website. Use of the service is based on the User's consent expressed by continued use of the website after seeing the cookie notice.
5.10.3. Data processed via Yandex Metrica:
- IP address;
- location data (based on IP, accurate to city);
- device type, operating system and browser;
- visited site pages (URLs);
- time and duration of the visit;
- actions on the site (clicks, scrolling, link follow-throughs);
- cookie identifiers and other technical data needed for the service.
This data is anonymized and does not allow direct identification of an individual without additional information.
5.10.4. Purposes of processing data via Yandex Metrica:
- analysis of site traffic;
- evaluation of content effectiveness and improvement of user experience;
- detection and elimination of technical errors on the site.
5.10.5. Data collected via Yandex Metrica may be transferred to Yandex LLC as part of providing the service. The Operator ensures confidentiality and security requirements upon transfer.
5.10.6. The User may decline cookies via browser settings or request information about the volume and purposes of processing by contacting the Operator at hi@neiroset.com.
5.10.7. Data collected via Yandex Metrica is stored for the period necessary to achieve the processing purposes, but no longer than 24 months from collection unless required otherwise by law.
6. Principles of personal data processing
6.1. Personal data processing is carried out on a lawful and fair basis.
6.2. Personal data processing is limited to specific, predetermined, and lawful purposes. Processing incompatible with the purposes of collection is not allowed.
6.3. Combining databases containing personal data, processed for incompatible purposes, is not allowed.
6.4. Only personal data meeting the processing purposes is processed.
6.5. The content and volume of processed personal data correspond to the stated processing purposes. Excessive processing relative to stated purposes is not allowed.
6.6. Accuracy, sufficiency, and where necessary relevance are ensured. The Operator takes (or causes to be taken) steps to delete or correct incomplete or inaccurate data.
6.7. Personal data is stored in a form allowing identification of the data subject for no longer than required by the processing purposes, unless a different period is set by federal law, an agreement to which the data subject is a party, beneficiary, or guarantor. Processed personal data is destroyed or anonymized once the purposes are achieved or no longer needed, unless otherwise provided by federal law.
7. Purposes of personal data processing
7.1. The purposes of processing the User's personal data:
- Granting the User access to services, information, and/or materials at https://neiroset.com;
- Analyzing and understanding how the User interacts with the Platform;
- Developing, modifying, optimizing, and personalizing the Platform's functionality in the User's interest;
- Ensuring access to the User's account and related services;
- Communicating with the User, including sending notifications, requests, messages, and other information related to the Platform;
- Offering the User third-party products and services that may be of interest, including showing relevant advertising.
7.2. The Operator may also send notifications about new products, services, special offers, and various events. The User may always opt out of informational messages by emailing the Operator at hi@neiroset.com with the note "Unsubscribe from new products, services, and special offers".
7.3. Anonymized data of Users collected via web analytics services serves to gather information on user actions on the site and to improve site quality and content.
8. Legal grounds for personal data processing
8.1. The legal grounds for the Operator's processing of personal data are:
- Federal Law No. 149-FZ of 27 July 2006 "On Information, Information Technologies and Information Protection";
- the Operator's constitutional documents;
- contracts between the operator and the data subject;
- federal laws and other regulatory acts on personal data protection;
- Users' consents to processing of their personal data, including data permitted for distribution.
8.2. The Operator processes the User's personal data only when the User submits or fills in special forms on https://neiroset.com or sends them by email. By filling in the forms or sending personal data, the User expresses consent to this Policy.
8.3. The Operator processes anonymized data about the User if browser settings allow it (cookies and JavaScript enabled).
8.4. The data subject independently decides whether to provide their personal data and gives consent freely, of their own will and in their own interest.
9. Conditions of personal data processing
9.1. Personal data processing is carried out with the data subject's consent.
9.2. Personal data processing is necessary to achieve the purposes provided by an international treaty of the Russian Federation or by law, to perform the operator's functions, powers, and duties imposed by Russian law.
9.3. Personal data processing is necessary for the administration of justice, the execution of a court act or an act of another body or official subject to enforcement under Russian law on enforcement proceedings.
9.4. Personal data processing is necessary to perform a contract to which the data subject is a party, beneficiary, or guarantor, or to enter into such a contract on the data subject's initiative.
9.5. Personal data processing is necessary to exercise the rights and lawful interests of the operator or third parties, or to achieve socially significant goals, provided that the rights and freedoms of the data subject are not violated.
9.6. Processing of personal data, access to which is granted to an unlimited number of persons by the data subject or at their request (publicly available personal data), is carried out.
9.7. Processing of personal data subject to publication or mandatory disclosure under federal law is carried out.
10. Procedure of collection, storage, transfer and other processing
The security of personal data processed by the Operator is ensured by implementing legal, organizational, and technical measures necessary for full compliance with applicable law on personal data protection.
10.1. The Operator ensures the safety of personal data and takes all possible measures to prevent access to personal data by unauthorized persons.
10.2. The Platform may transfer Personal Information to third parties to the extent necessary to achieve the purposes of this Policy. Such third parties may include:
- Advertisers and other persons placing and showing advertisements to Users on the Platform;
- Persons providing technological, analytical, informational, and other services necessary for detecting threats to Platform security.
10.3. If inaccuracies in personal data are detected, the User may update them independently by sending the Operator a notification by email at hi@neiroset.com with the note "Update of personal data".
10.4. The processing period is determined by achieving the purposes of collection, unless a different period is set by contract or applicable law.
The User may at any time revoke consent to personal data processing by sending the Operator a notification by email at hi@neiroset.com with the note "Revocation of consent to personal data processing".
10.5. All information collected by third-party services, including payment systems, communication tools, and other service providers, is stored and processed by such persons (Operators) in accordance with their User Agreements and Privacy Policies. The User must read these documents on their own. The Operator is not responsible for the actions of third parties, including the service providers mentioned here.
10.6. Restrictions on transfer (other than provision of access) and on processing or processing conditions (other than obtaining access) of data permitted for distribution, set by the data subject, do not apply when processing in state, public, or other public interests as defined by Russian law.
10.7. The Operator ensures confidentiality of personal data when processing it.
10.8. The Operator stores personal data in a form allowing identification of the data subject for no longer than required by the processing purposes, unless a different period is set by federal law, an agreement to which the data subject is a party, beneficiary, or guarantor.
10.9. Conditions for terminating personal data processing may include achievement of the processing purposes, expiration of the data subject's consent or revocation of consent, or detection of unlawful processing.
11. Operations performed by the Operator with personal data
11.1. The Operator carries out collection, recording, systematization, accumulation, storage, updating (modification, change), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion, and destruction of personal data.
11.2. The Operator carries out automated processing of personal data with or without receiving and/or transmitting the obtained information via information and telecommunications networks.
12. Confidentiality of personal data
The Operator and other persons who have obtained access to personal data must not disclose to third parties or distribute personal data without the data subject's consent, unless otherwise provided by federal law.
13. Final provisions
13.1. The User may obtain any clarifications regarding the processing of their personal data by contacting the Operator by email at hi@neiroset.com.
13.2. This document reflects any changes to the Operator's personal data processing policy. The Policy is valid indefinitely until replaced by a new version.
13.3. The current version of the Policy is freely available on the Internet at https://neiroset.com/privacy-policy.
Sole Proprietor Pavel Sergeevich Bataev
TIN: 540135549436
OGRNIP: 322547600138098
Contact: hi@neiroset.com