This Personal Data Processing Policy (the "Policy") is published in accordance with Art. 18.1(2) of Russian Federal Law No. 152-FZ "On Personal Data" and sets out the approach of Ivan Ivanov, a self-employed individual operating under Russia's professional income tax (NPD) regime (the "Operator"), to the processing and protection of personal data.
1. Categories of Personal Data Processed
The Operator processes the following categories of personal data:
- identification data (first and last name);
- contact data (phone number, email address);
- data about the purpose of the request (destination country, visa type, and the content of the inquiry);
- technical data related to use of the website (IP address, cookie data, device and browser information).
The Operator does not process special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health, or sex life) as an independent purpose of processing.
2. Methods of Processing
Personal data is processed both with the use of automation tools (automated processing) and without such tools, to the extent necessary to achieve the purposes described in the Privacy Policy. The following operations may be performed on personal data: collection, recording, systemization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (disclosure, access), depersonalization, blocking, deletion, and destruction.
3. Automated Processing and Decision-Making
The Operator does not apply exclusively automated processing of personal data that produces legal effects for, or otherwise significantly affects, a data subject, without the involvement of an authorized staff member. Automated tools (including the website form) are used only to collect and initially organize inquiries.
4. Storage of Personal Data
Personal data is stored on servers operated by the Operator or by the technical service providers it engages, with the protective measures described in Section 7 of this Policy applied. The retention period is set out in the Privacy Policy.
5. Destruction of Personal Data
Once the purposes of processing are achieved, the consent period expires, or the data subject withdraws consent, personal data is destroyed or depersonalized, unless Russian law provides otherwise. Destruction of personal data on electronic media is carried out by irreversible deletion in a manner that prevents further processing.
6. Access Control
Access to personal data is granted only to Operator staff and engaged specialists who require it to perform their job duties, and only to the extent necessary for the specific purpose of processing.
7. Staff Responsibilities
Staff and engaged specialists granted access to personal data must:
- keep confidential any personal data they become aware of in the course of their duties;
- process personal data only to the extent and for the purposes necessary to perform their assigned functions;
- promptly report any identified violations of personal-data processing procedures to the Operator.
This obligation survives the termination of the employment or civil-law relationship with the Operator.
8. Data Protection Measures
The Operator takes the necessary legal, organizational, and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, disclosure, distribution, or other unlawful actions, including:
- appointing a person responsible for organizing personal-data processing;
- limiting the circle of persons granted access to personal data;
- using information-security tools that have undergone the required conformity-assessment procedure;
- monitoring the effectiveness of the security measures applied.
9. Contact
Questions regarding this Policy may be sent to privacy@visarun.online or to the Operator's address: Moscow, Russian Federation.