Operator’s Personal Data Processing Policy

Version dated 29 June 2026

1. General Provisions

1.1. This Operator’s Personal Data Processing Policy (the “Policy”) has been developed to protect the rights and freedoms of personal data subjects when their personal data is processed, including the rights to privacy and to personal and family confidentiality.

1.2. Key terms used in this Policy:
• personal data — any information relating to an identified or identifiable individual (personal data subject);
• personal data processing — any action (operation) or set of actions (operations) performed on personal data, with or without automated means, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data;
• automated personal data processing — processing of personal data using computing equipment;
• dissemination of personal data — actions aimed at disclosing personal data to an indefinite number of persons;
• provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons;
• blocking of personal data — temporary suspension of personal data processing (except where processing is necessary to clarify personal data);
• destruction of personal data — actions making it impossible to restore the content of personal data in a personal data information system and/or resulting in the destruction of physical media containing personal data;
• depersonalization of personal data — actions making it impossible, without additional information, to determine that personal data belongs to a specific personal data subject;
• personal data operator (the “Operator”) — Individual Entrepreneur Olga Vladimirovna Ponomareva, INN 665910795955, OGRNIP 326965800152672, email: inbox@olgaponomareva.com, telephone: +7-925-804-99-52;
• Website — https://olgaponomareva.com.

1.3. The Operator, having obtained access to personal data, must maintain the confidentiality of such personal data and must not disclose it to third parties or disseminate it without the consent of the personal data subject, unless otherwise provided by federal law.

2. Purposes of Personal Data Collection

2.1. Personal data processing is limited to achieving specific, predetermined, and lawful purposes. Processing of personal data that is incompatible with the purposes for which the personal data was collected is not permitted.

2.2. The purposes for which the Operator processes personal data include:
• entering into, performing, and terminating a civil-law contract;
• arranging consultation bookings;
• communicating with clients;
• maintaining accounting records.

2.3. Purpose: entering into, performing, and terminating a civil-law contract.
- Category of data subjects: clients.
- Data processed: full name, telephone number, email address, Telegram messenger ID, profession, position, employment information (including length of service and current employment details).
- Data category: general personal data.
- Method of personal data processing: automated collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, and use.
- Processing period: for 1 (one) year from the date the personal data is received.
- Destruction: personal data is destroyed by deletion from the Personal Data Operator’s servers.
- Personal data processed for this purpose may be transferred to YANDEX 360 FOR BUSINESS LLC, OGRN 1257700155668.

2.4. Purpose: arranging consultation bookings.
- Category of data subjects: clients.
- Data processed: full name, telephone number, email address.
- Data category: general personal data.
- Method of personal data processing: automated collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, and use.
- Processing period: for 1 (one) year from the date the personal data is received.
- Destruction: personal data is destroyed by deletion from the Personal Data Operator’s servers.

2.5. Purpose: communicating with clients.
- Category of data subjects: clients.
- Data processed: full name, telephone number, email address.
- Data category: general personal data.
- Method of personal data processing: automated collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, and use.
- Processing period: for 1 (one) year from the date the personal data is received.
- Destruction: personal data is destroyed by deletion from the Personal Data Operator’s servers.

2.6. Purpose: maintaining accounting records.
- Category of data subjects: clients.
- Data processed: full name, telephone number, email address, bank details.
- Data category: general personal data.
- Method of personal data processing: automated collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, and use.
- Processing period: for 5 (five) years from the date the personal data is received.
- Destruction: personal data is destroyed by deletion from the Personal Data Operator’s servers.
- Personal data processed for this purpose may be transferred to PF SKB Kontur JSC, OGRN 1026605606620.

3. Principles of Personal Data Processing

3.1. The Operator processes personal data on the basis of the following principles:
• lawfulness of the purposes and methods of personal data processing and good faith of the Operator;
• fairness and transparency (the personal data subject is informed in advance of the purposes, legal grounds, and procedure for processing their personal data);
• purpose limitation (personal data processing is limited to achieving specific, predetermined, and lawful purposes; processing incompatible with the purposes for which the data was collected is not permitted);
• data minimization (the content and volume of personal data processed must correspond to the stated processing purposes; processing personal data excessive in relation to those purposes is not permitted);
• personal data must be accurate and, where necessary, kept up to date; the Operator takes reasonable measures to ensure that inaccurate personal data is corrected or deleted in a timely manner;
• personal data is stored in a form that permits identification of the personal data subject for no longer than required by the purposes of processing; once the processing purposes have been achieved, the personal data must be destroyed unless otherwise provided by federal law.

4. Legal Grounds for Personal Data Processing

4.1. The legal grounds for personal data processing are:
• consent to personal data processing;
• a contract to which the personal data subject is a party.

5. Rights and Obligations of the Parties

5.1. The Operator must:
• process personal data in accordance with Federal Law No. 152-FZ dated 27 July 2006 “On Personal Data”, other regulatory legal acts of the Russian Federation governing personal data, and this Policy;
• not process personal data without the consent of the personal data subject, except in cases provided by federal laws;
• protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, and other unlawful actions involving personal data;
• provide the personal data subject, upon receipt of an appropriate request, with information about personal data relating to that subject and an opportunity to review such personal data;
• make timely changes to personal data upon the written request of the personal data subject or their legal representative;
• cease processing personal data once the purposes of processing have been achieved, upon withdrawal of the subject’s consent, or upon the occurrence of other grounds established by law;
• notify the authorized authority for the protection of personal data subjects’ rights (the Federal Service for Supervision of Communications, Information Technology and Mass Media, hereinafter “Roskomnadzor”) of unlawful or accidental transfer (provision, dissemination, access) of personal data in the manner and within the time limits established by law;
• take organizational and technical measures to ensure personal data security.

5.2. The personal data subject has the right to:
• receive information concerning the processing of their personal data, including the purposes and legal grounds for processing, the processing methods used, data retention periods, the name and address of the Operator, the list of persons to whom personal data may be transferred, and the measures taken by the Operator to ensure personal data security;
• request clarification, blocking, or deletion of their personal data if the data is incomplete, inaccurate, outdated, unlawfully obtained, or unnecessary for the stated processing purpose;
• give consent to personal data processing and withdraw that consent at any time by sending a written statement to the Operator’s email address: inbox@olgaponomareva.com;
• request cessation of personal data processing in cases of unlawful processing and upon other grounds provided by the Personal Data Law;
• challenge the Operator’s actions (or omissions) before the authorized authority for the protection of personal data subjects’ rights;
• protect their rights and legitimate interests, including seeking damages and/or compensation for moral harm through the courts.

5.3. The Operator and the personal data subject must comply with all other requirements established by Federal Law No. 152-FZ dated 27 July 2006 “On Personal Data” and other regulatory legal acts of the Russian Federation governing personal data.

6. Procedure and Conditions for Personal Data Processing

6.1. Personal data is processed by automated means, including transmission through the Operator’s internal network and over the Internet.

6.2. The Operator does not carry out cross-border transfers of personal data.

6.3. The Operator’s processing of personal data is limited to achieving specific, predetermined, and lawful purposes. Only personal data corresponding to the purposes of processing is processed. The content and volume of personal data processed must correspond to the stated purposes.

6.4. The source from which personal data is obtained is the Website.

6.5. Personal data is stored on the Operator’s servers and on the servers of persons processing personal data in connection with the use of the Website, including YANDEX 360 FOR BUSINESS LLC and PF SKB Kontur JSC, OGRN 1026605606620.

6.6. Personal data processing ceases when the processing purpose has been achieved, the retention period has expired, or consent to personal data processing has been withdrawn.

6.7. The Operator and other persons who have obtained access to personal data must not disclose personal data to third parties or disseminate it without the consent of the personal data subject. The transfer (dissemination, provision, access) of personal data that the personal data subject has permitted for dissemination must be terminated at any time upon the subject’s request. Such request must include the surname, first name and patronymic (if any), contact information (telephone number, email address, or postal address) of the personal data subject, as well as a list of the personal data whose processing must cease. The personal data specified in such request may be processed only by the Operator to whom the request was submitted.

6.8. The Operator takes the following measures to ensure personal data security: appointing a person responsible for organizing personal data processing; issuing documents defining the Operator’s personal data processing policy; using password protection and antivirus software; regularly updating software; and preventing unauthorized access.

6.9. The Operator ensures personal data security through the use of licensed security software (antivirus software).

7. Updating, Correction, Deletion and Destruction of Personal Data; Responses to Data Subjects’ Access Requests

7.1. In accordance with Article 14 of the Personal Data Law, the Operator must inform the personal data subject or their representative whether personal data relating to that subject is held and provide an opportunity to review such personal data upon application by the subject or their representative, or within ten business days from receipt of a request from the subject or their representative. This period may be extended by no more than five business days if the Operator sends the personal data subject a reasoned notice explaining the reasons for extending the period for providing the requested information.

7.2. The Operator must provide the personal data subject or their representative, free of charge, with an opportunity to review personal data relating to that subject. Within no more than seven business days from the date on which the personal data subject or their representative provides information confirming that the personal data is incomplete, inaccurate, or outdated, the Operator must make the necessary changes. Within no more than seven business days from the date on which the personal data subject or their representative provides information confirming that such personal data was unlawfully obtained or is unnecessary for the stated processing purpose, the Operator must destroy such personal data. The Operator must notify the personal data subject or their representative of the changes made and measures taken and must take reasonable measures to notify third parties to whom that subject’s personal data was transferred.

7.3. If the inaccuracy of personal data is confirmed, the Operator, on the basis of information provided by the personal data subject or their representative, the authorized authority for the protection of personal data subjects’ rights, or other necessary documents, must correct the personal data or ensure its correction (where processing is carried out by another person acting on the Operator’s instructions) within seven business days from receipt of such information and remove the blocking of the personal data.

7.4. The Operator must cease processing personal data, or ensure that a person acting on the Operator’s instructions ceases such processing:
• where unlawful personal data processing by the Operator or a person acting on the Operator’s instructions is identified — within no more than three business days from the date it is identified;
• where the personal data subject withdraws consent to processing of their personal data;
• once the purpose of personal data processing has been achieved, and must destroy the personal data or ensure its destruction (where processing is carried out by another person acting on the Operator’s instructions) within no more than thirty days from the date the purpose is achieved. If destruction is not possible within that period, the Operator must block the personal data, or ensure its blocking (where processing is carried out by another person acting on the Operator’s instructions), and ensure destruction within no more than six months unless a different period is established by federal law.

7.5. If unlawful or accidental transfer (provision, dissemination, access) of personal data resulting in a violation of personal data subjects’ rights is established, the Operator must, from the moment the incident is identified by the Operator, the authorized authority for the protection of personal data subjects’ rights, or another interested person, notify the authorized authority for the protection of personal data subjects’ rights:
• within twenty-four hours — of the incident, the presumed causes that resulted in the violation of personal data subjects’ rights, the presumed harm caused to those rights, the measures taken to remedy the consequences of the incident, and information about the person authorized by the Operator to interact with the authorized authority on matters relating to the identified incident;
• within seventy-two hours — of the results of the internal investigation into the identified incident, as well as information about the persons whose actions caused the incident, if any.

7.6. If a personal data subject submits a request to the Operator to cease processing personal data, the Operator must, within no more than ten business days from receipt of the request, cease processing or ensure cessation of such processing (where processing is carried out by a person processing personal data), except in cases provided by the Personal Data Law. This period may be extended by no more than five business days if the Operator sends the personal data subject a reasoned notice explaining the reasons for extending the period for ceasing personal data processing.

7.7. After the statutory retention period for documents containing the subject’s personal data expires, or upon the occurrence of other lawful grounds, such documents must be destroyed.
Individual Entrepreneur Olga Vladimirovna Ponomareva
Taxpayer Identification Number (INN): 665910795955
Primary State Registration Number of Individual Entrepreneur (OGRNIP): 326965800152672
Registration authority: Inspectorate of the Federal Tax Service for the Verkh-Isetsky District of Yekaterinburg
Correspondence address: P.O. Box 282, Moscow, 125493, Russian Federation
Email: inbox@olgaponomareva.com
Telephone: +7-925-804-99-52
Website: olgaponomareva.com


Services are provided pursuant to the Public Offer.
Payments are officially accepted by Individual Entrepreneur Olga Vladimirovna Ponomareva.
An electronic fiscal receipt is sent to the email address or telephone number provided by the client before payment.

By booking a consultation or providing data for the delivery of services, the client confirms that they have read the Public Offer and the Personal Data Processing Policy.