1. General Provisions
1. This Personal Data Processing Policy (hereinafter — the "Policy") has been developed in accordance with Clause 2, Part 1, Article 18.1 of Federal Law No. 152-FZ "On Personal Data" dated July 27, 2006 (hereinafter — the "Personal Data Law") and constitutes the foundational document of Sole Proprietor Voistinnykh Julia Yuryevna, Tax ID (INN) 771532906401, OGRNIP 326774600279901 (hereinafter — the "Operator"), defining the key areas of the Operator's activity in the field of personal data processing and protection (hereinafter — "Personal Data" or "PD").
2. The Policy has been developed to implement the requirements of legislation in the field of personal data processing and protection and is aimed at ensuring the protection of the rights and freedoms of individuals when the Operator processes their Personal Data, including protection of the right to privacy, personal and family confidentiality.
3. This Policy has been developed on the basis of the Constitution of the Russian Federation, the Civil Code of the Russian Federation, the Labor Code of the Russian Federation, and in accordance with the requirements of Federal Law No. 152-FZ "On Personal Data" dated July 27, 2006, Decree of the Government of the Russian Federation No. 211 dated March 21, 2012 "On Approval of the List of Measures Aimed at Ensuring Compliance with the Obligations Provided for by the Federal Law 'On Personal Data'", and other regulatory legal acts adopted in accordance with it.
This Personal Data Processing Policy (hereinafter — the "Policy") applies to all personal data processed by the Operator and to all information the Operator may obtain about visitors of the website
https://julia-nutrimind.com4. The Policy applies to relations in the field of personal data processing that arose for the Operator both before and after this Policy was approved.
5. In fulfillment of the requirements of Part 2, Article 18.1 of the Personal Data Law, this Policy is published in open access on the information and telecommunications network Internet on the Operator's website.
2. The Concept and Composition of Personal Data
Terms related to the processing of Personal Data are used in the meaning given to them in Article 3 of the Personal Data Law:
personal data — any information relating directly or indirectly to an identified or identifiable individual (data subject);
personal data permitted by the data subject for distribution — personal data to which an unrestricted number of persons is granted access by the data subject, by giving consent to the processing of personal data permitted by the data subject for distribution;
personal data operator (operator) — a government body, municipal body, legal entity or individual that independently or jointly with other persons organizes and/or carries out the processing of personal data, as well as determines the purposes of personal data processing, the composition of personal data to be processed, and the actions (operations) performed with personal data;
processing of personal data — any action (operation) or set of actions (operations) performed with personal data, whether or not using automation tools, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data;
automated processing of personal data — the processing of personal data using computer technology;
distribution of personal data — actions aimed at disclosing personal data to an indefinite number of persons;
provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons;
blocking of personal data — the temporary suspension of personal data processing (except when processing is necessary to clarify personal data);
destruction of personal data — actions as a result of which it becomes impossible to restore the content of personal data in a personal data information system and/or as a result of which the physical media containing personal data are destroyed;
depersonalization of personal data — actions as a result of which it becomes impossible, without the use of additional information, to determine that the personal data belongs to a specific data subject;
personal data information system (PDIS) — a set of personal data contained in databases and the information technologies and technical means that ensure their processing;
cross-border transfer of personal data — the transfer of personal data to the territory of a foreign state, to a foreign government authority, a foreign individual, or a foreign legal entity;
personal data protection — activities aimed at preventing the leakage of protected personal data and unauthorized or unintentional impacts on protected personal data.
3. Purposes and Cases of Personal Data Processing
1) Personal data may be processed only for purposes directly related to the Operator's actual activities, as well as activities provided for by the Operator's founding documents, and the Operator's specific business processes within specific personal data information systems, in particular for:
· providing informational and consulting services;
· complying with the procedures and rules for the provision of services by the Operator;
· keeping individual records of clients' results, as well as archiving data on these results on paper and/or electronic media;
· keeping records of the exercise of clients' right to receive information;
· ensuring client safety while services are being provided (video surveillance);
· video recording and posting video materials on the Operator's website and social media as part of the service-provision process;
· using materials to populate the informational resources of the Operator's website, albums, photo, and video materials about the Operator's work;
· maintaining, populating, and promoting the Operator's website;
· keeping statistics; monitoring the Operator's activities;
· exercising the Operator's rights and legitimate interests, or achieving socially significant purposes, provided that the rights and freedoms of the data subject are not violated in the process.
2) The Operator collects data only to the extent necessary to achieve the above purposes.
3) Personal data may not be transferred to third parties without written consent.
4) The confidentiality regime for personal data is lifted in cases where the data is depersonalized or included in publicly available sources of personal data, unless otherwise provided by law.
5) The Operator ensures that everyone has the opportunity to review documents and materials directly affecting their rights and freedoms, unless otherwise provided by law or by this Policy.
6) Personal data may not be used to cause property or moral harm to citizens, or to impede the exercise of the rights and freedoms of citizens of the Russian Federation. Restricting the rights of citizens of the Russian Federation based on information about their social origin, race, nationality, language, religion, or party affiliation is prohibited and punishable in accordance with the law.
7) The Operator and individuals who, in accordance with their authority, possess, receive, and use information about citizens bear responsibility in accordance with the legislation of the Russian Federation for violations of the regime for the protection, processing, and use of such information.
8) This Policy is approved by the Operator and is binding on all employees who have access to the Subject's personal data.
4. Legal Grounds for Personal Data Processing
1) agreements concluded between the Operator and the personal data subject;
2) consents to the processing of personal data provided by data subjects;
3) internal local regulations and the Operator's founding documents;
4) Decree of the Government of the Russian Federation No. 1119 dated November 1, 2012 "On Approval of Requirements for the Protection of Personal Data When Processed in Personal Data Information Systems";
5) Federal Law No. 273-FZ dated December 29, 2012 "On Education in the Russian Federation";
6) Decree of the President of the Russian Federation No. 188 dated March 6, 1997 "On Approval of the List of Confidential Information";
7) Decree of the Government of the Russian Federation No. 687 dated September 15, 2008 "On Approval of the Regulation on the Specifics of Processing Personal Data Carried Out Without the Use of Automation Tools";
8) Decree of the Government of the Russian Federation No. 512 dated July 6, 2008 "On Approval of Requirements for Physical Media of Biometric Personal Data and Technologies for Storing Such Data Outside Personal Data Information Systems";
9) Order of the FSTEC of Russia No. 55, the FSB of Russia No. 86, and the Ministry of Information Technologies and Communications of Russia No. 20 dated February 13, 2008 "On Approval of the Procedure for Classifying Personal Data Information Systems";
10) Order of the FSTEC of Russia No. 21 dated February 18, 2013 "On Approval of the Composition and Content of Organizational and Technical Measures to Ensure the Security of Personal Data When Processed in Personal Data Information Systems";
11) Order of Roskomnadzor No. 996 dated September 5, 2013 "On Approval of Requirements and Methods for the Depersonalization of Personal Data";
12) other regulatory legal acts of the Russian Federation and regulatory documents of authorized government bodies.
5. Scope and Categories of Personal Data Processed
No. | Data Subjects | Purposes of Processing | Categories of Personal Data
1. | Visitors of the Operator's website | Marketing research on demand | Full name, city of residence, email address, phone number, information about marital status, presence (number) of children; IP address, browser information, cookie data, geolocation data, and other data automatically collected and processed on websites belonging to the Operator.
2. | The Operator's clients | Provision of services | Full name; gender; passport/ID details; citizenship; postal address; email address; phone numbers; marital, social, and financial status; age, gender, height, weight, information about health status and habits; photographs, video images.
3. | Counterparties (contractors, customers, representatives of counterparties / employees of counterparties) | Conclusion and performance of contracts | Full name; gender; Tax ID (INN); Individual Insurance Account Number (SNILS); passport/ID details; date and place of birth; citizenship; education information; work information (length of service and experience, qualifications, position, work performed); addresses; phone numbers; military registration information; marital, social, and financial status; photograph.
Any other necessary information that the Subject voluntarily provides about themselves in order to receive services provided by the Operator, provided its processing is not prohibited by law.
6. Procedure and Conditions for Processing the Subject's Personal Data
1) Personal data is processed with the consent of data subjects to the processing of their personal data, as well as without such consent in cases provided for by the legislation of the Russian Federation.
2) Consent to the processing of personal data permitted by the data subject for distribution is executed separately from other consents of the data subject to the processing of their personal data.
3) Consent to the processing of personal data permitted by the data subject for distribution may be provided to the operator:
a. directly;
b. using the information system of the authorized body for the protection of the rights of personal data subjects.
4) The Operator processes the Subject's personal data both on paper without the use of automation tools (non-automated processing) and electronically in computer programs (electronic databases) using automation tools (automated processing).
5) Personal data is processed based on the following principles:
· lawfulness of the purposes and methods of personal data processing, and good faith;
· conformity of the purposes of personal data processing with the purposes predetermined and declared when the personal data was collected, as well as with the Operator's authority;
· conformity of the scope and nature of the personal data processed and the methods of processing with the purposes of processing;
· accuracy of personal data, its sufficiency for the purposes of processing, and inadmissibility of processing personal data that is excessive in relation to the purposes declared when it was collected;
· inadmissibility of combining databases of personal data information systems created for incompatible purposes;
· destruction of personal data once the purposes of processing have been achieved or if the need to achieve them has been lost;
· personal responsibility of the Operator's employees for the safekeeping and confidentiality of personal data, as well as of the media containing such information.
6) Personal data is processed by:
· receiving personal data verbally or in writing, directly with the consent of the data subject to the processing or distribution of their personal data;
· entering personal data into the Operator's logs, registers, and information systems;
· using other methods of personal data processing.
7) Sources for obtaining personal data:
· the data subject;
· the legal representative of the data subject.
8) Disclosure of personal data to third parties and distribution of personal data without the data subject's consent is not permitted, unless otherwise provided by federal law.
9) The transfer of personal data to inquiry and investigation authorities, the Federal Tax Service, the Pension Fund, the Social Insurance Fund, and other authorized executive bodies and organizations is carried out in accordance with the requirements of the legislation of the Russian Federation.
10) If it becomes necessary to interact with third parties in order to achieve the purposes of personal data processing, personal data is transferred to third parties on the basis of a data-processing agency agreement, for the purposes and to the extent necessary to fulfill the Operator's functions, taking into account the requirements for the protection of the personal data being processed.
11) The Operator stores personal data in a form that allows the data subject to be identified for no longer than is required by the purposes of processing, unless the storage period is established by federal law, a contract, or an agreement.
12) As a general rule, the processing and storage of personal data continues until the legal grounds for it cease to exist.
13) Grounds for terminating the processing of personal data include: the purposes of processing being achieved, the expiration of the consent period, withdrawal of the data subject's consent to the processing of their personal data, and the discovery of unlawful processing of personal data.
14) The retention period for documents containing personal data is determined by the "List of Standard Administrative Archival Documents Generated in the Course of Activities of Government Bodies, Local Self-Government Bodies, and Organizations, Indicating Retention Periods," approved by Order of the Ministry of Culture of the Russian Federation No. 558 dated August 25, 2010, and in other cases provided for by the legislation of the Russian Federation.
15) Cross-border transfer of personal data is not carried out. When collecting personal data, including via the Internet, the Operator ensures the recording, systematization, accumulation, storage, clarification (updating, modification), and extraction of personal data of citizens of the Russian Federation using databases located within the territory of the Russian Federation, except in cases specified in the Personal Data Law.
7. Information About the Operator
1) Full name: Sole Proprietor Voistinnykh Julia Yuryevna, Tax ID (INN) 771532906401, OGRNIP 326774600279901
2) Short name: Sole Proprietor Voistinnykh J.Y.
3) Legal address: 127349, Moscow, Leskova St., 6, Apt. 280.
Postal address: 127349, Moscow, Leskova St., 6, Apt. 280.
8. Obligations of the Operator
In order to ensure the rights and freedoms of individuals, the Operator, when processing the Subject's personal data, is obligated to comply with the following requirements:
1) The Subject's personal data may be processed exclusively for the purpose of providing services to Subjects;
2) Personal data of the Subject shall be obtained from the Subject directly. If the Subject's personal data was obtained from a third party, the Operator must notify the Subject and obtain their written consent. Subjects must be informed about the purposes, expected sources, and methods of obtaining personal data, as well as the nature of the personal data to be obtained and the consequences of the Subject's refusal to give written consent to obtain it;
3) The Operator has no right to obtain or process personal data concerning race, nationality, political views, religious or philosophical beliefs, or intimate life, except in cases provided for by law. In particular, the Operator may process such personal data of the Subject only with their written consent;
4) The Operator shall provide the Subject or their representative with information about the existence of personal data relating to that data subject, as well as provide the opportunity to review it upon the Subject's or their representative's request, or within ten days of receiving such a request;
5) The storage and protection of the Subject's personal data from unlawful use or loss is ensured by the Operator, at its own expense, in the manner established by the current legislation of the Russian Federation;
6) If inaccurate personal data or unlawful actions with it by the operator are discovered, upon request or inquiry from the Subject or the authorized body for the protection of the rights of personal data subjects, the Operator is obligated to block the personal data for the duration of the review;
7) If the fact of the personal data's inaccuracy is confirmed, the operator, based on documents submitted by the Subject or the authorized body for the protection of the rights of personal data subjects, or other necessary documents, is obligated to correct the personal data and lift the block;
8) Once the purpose of personal data processing has been achieved, the Operator is obligated to immediately cease processing the personal data and destroy it within a period not exceeding 10 business days, and to notify the Subject accordingly, as well as the authorized body for the protection of the rights of personal data subjects if the request was sent by such a body;
9) If the Subject withdraws consent to the processing of their personal data, the Operator is obligated to cease processing and destroy the personal data within a period not exceeding 10 business days, unless otherwise provided by an agreement between the Operator and the Subject. The Operator is obligated to notify the Subject of the destruction of the personal data.
9. Rights of the Subject
1) The right to access information about themselves.
2) The right to determine the forms and methods of personal data processing.
3) The right to withdraw consent to the processing of personal data.
4) The right to restrict the methods and forms of personal data processing, and to prohibit the distribution of personal data without their consent.
5) The right to demand the modification, clarification, or destruction of information about themselves.
6) The right to appeal unlawful actions or omissions related to the processing of personal data and to demand appropriate compensation through the courts.
7) The right to supplement evaluative personal data with a statement expressing their own point of view.
8) The right to designate representatives to protect their personal data.
9) The right to demand that the Operator notify all persons to whom incorrect or incomplete personal data about the Subject was previously communicated of any changes made to it or its exclusion.
10.1. Cookies
The Operator uses "cookie" files. Cookies are small text files placed on the hard drives of users' devices while using various websites, designed to help customize the user interface according to user preferences.
Most browsers allow you to decline cookies and delete them from your device's hard drive.
10.2. Links to Third-Party Websites
The Operator's website may contain links to third-party websites and services that the Operator does not control. The Operator is not responsible for the security or privacy of any information collected by third-party websites or services.
10.3. Embedded Content From Other Websites
Pages on the Operator's website may include embedded content (for example: videos, images, articles, contact forms, etc.). Such content behaves in exactly the same way as if the visitor had visited another website.
These websites may collect data about the user, use cookies, embed additional third-party tracking, and monitor the user's interaction with the embedded content, including tracking that interaction if the user has an account and is logged into that website.
11. Personal Data Protection
1) A threat or risk of loss of personal data is understood to mean any single or combined, real or potential, active or passive manifestation of malicious capabilities by external or internal sources of threat that could create unfavorable events or have a destabilizing effect on protected information.
2) Risks to any information resources are created by natural disasters, extreme situations, acts of terrorism, failures of technical equipment and communication lines, other objective circumstances, as well as persons interested or uninterested in the emergence of such a threat.
3) The protection of personal data represents a strictly regulated technological process that prevents violations of the availability, integrity, accuracy, and confidentiality of personal data, and ultimately ensures a sufficiently reliable level of information security in the course of the Operator's activities.
4) In accordance with the requirements of regulatory documents, the Operator has created a Personal Data Protection System (PDPS), consisting of legal, organizational, and technical protection subsystems.
5) The legal protection subsystem is a set of legal, organizational, administrative, and regulatory documents that ensure the creation, functioning, and improvement of the PDPS.
6) The organizational protection subsystem includes the organization of the PDPS management structure, an access-authorization system, and information protection when working with employees, partners, and third parties.
7) The technical protection subsystem includes a set of technical, software, and hardware-software tools that ensure the protection of personal data.
8) The main protective measures used by the Operator are:
a. Appointing a person responsible for personal data processing, who organizes the processing of personal data, conducts training and briefings, and exercises internal control over the institution's and its employees' compliance with personal data protection requirements.
b. Identifying current threats to the security of personal data during their processing in personal data information systems, and developing measures to protect personal data.
c. Developing a policy on the processing of personal data.
d. Establishing rules for access to personal data processed in personal data information systems, as well as ensuring the registration and recording of all actions performed with personal data in such systems.
e. Establishing individual employee access passwords to the information system in accordance with their job responsibilities.
f. Processing personal data in automated information systems at workstations with a separation of authority, restricting access to workstations, and applying password- and electronic-key-based access identification mechanisms and cryptographic protection tools;
g. Using information security tools that have undergone the established compliance-assessment procedure.
h. Certified anti-virus software with regularly updated databases.
i. Complying with conditions that ensure the safekeeping of personal data while working with it, in premises containing computer equipment, and preventing unauthorized access to it.
j. Storing personal data on paper media in guarded or locked premises, safes, and cabinets.
k. Detecting instances of unauthorized access to personal data and taking corrective measures.
l. Restoring personal data that has been modified or destroyed as a result of unauthorized access.
m. Training the Operator's employees who directly process personal data on the provisions of Russian legislation on personal data, including requirements for its protection, documents defining the Operator's policy on personal data processing, and local acts on personal data processing matters.
n. Conducting internal monitoring and audits.
9) Purposeful unfavorable conditions and difficult-to-overcome obstacles are created to prevent unauthorized access to and acquisition of information by a person attempting to commit such access.
10) Outside persons must not be made aware of the distribution of functions, work processes, or the technology for compiling, drafting, maintaining, and storing documents, files, and working materials. An "outside person" means any person not directly related to the Operator's activities.
12. Liability for Disclosure of Personal Data and Violations
1) The Operator is responsible for the personal information in its possession and establishes personal accountability for employees regarding compliance with this Policy.
2) Every employee of the Operator who is given access to physical media containing personal data for their work is responsible for the safekeeping of that media and the confidentiality of the information.
3) Persons found guilty of violating the rules governing the collection, processing, and protection of personal data bear disciplinary, administrative, civil, or criminal liability in accordance with federal law.
13. Updating, Correcting, Deleting, and Destroying Personal Data; Responses to Subject Requests for Access to Personal Data
1) The Subject's personal data may be provided to third parties only with the Subject's written consent.
2) Upon request from the data Subject or their representative, within 10 business days of receiving the request, the Operator shall provide the data subject or their representative with the information specified in Part 7, Article 14 of the Personal Data Law relating to the subject, including:
a. confirmation of the fact that the Operator is processing personal data, and the purpose of such processing;
b. the methods of personal data processing used by the Operator;
c. information about persons who have access to the personal data or to whom such access may be granted;
d. a list of the personal data being processed and the source from which it was obtained;
e. the periods of personal data processing, including storage periods.
3) The request must contain:
· the number of an identity document of the subject or their representative, along with details of the date it was issued and the issuing authority;
· information confirming the subject's involvement in a relationship with the Operator (contract number, contract date, conditional designation, and/or other information), or information otherwise confirming the fact that the Operator processes the subject's personal data;
· the signature of the personal data subject or their representative.
4) The request may be sent as an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
5) If the data subject's request does not contain all the information required under the Personal Data Law, or if the subject does not have the right to access the requested information, a reasoned refusal will be sent to them.
6) The data subject's right to access their personal data may be restricted in accordance with Part 8, Article 14 of the Personal Data Law, including if the subject's access to their personal data violates the rights and legitimate interests of third parties.
7) Information about personal data must be provided to the Subject in an accessible form, and must not contain personal data relating to other data subjects.
8) Upon request or inquiry from a personal data subject or their representative, as well as upon request from Roskomnadzor, the Operator shall block any unlawfully processed personal data of that subject from the moment the request or inquiry is received, for the duration of the review.
9) Based on information provided by the personal data subject or their representative, or by Roskomnadzor, or other necessary documents, the Operator shall correct the personal data within 7 (seven) business days of such information being provided.
10) If unlawful processing of personal data is discovered, the Operator shall cease such unlawful processing within a period not exceeding 3 (three) business days.
11) If the purposes of personal data processing have been achieved, or if the data subject withdraws consent to its processing, the Operator shall cease processing and destroy the personal data within a period not exceeding 30 days from the date the purpose of processing was achieved, unless:
· otherwise provided by an agreement to which the personal data subject is a party, beneficiary, or guarantor;
· the operator is entitled to process the data without the subject's consent on grounds provided for by the Personal Data Law or other federal laws;
· otherwise provided by another agreement between the Operator and the personal data subject.
14. Information on Measures Taken
In order to fulfill the requirements of the Personal Data Law, the Operator has approved the following documents:
1) Consent of the data subject or their legal representative to the processing of personal data;
2) Consent of the data subject or their legal representative to the processing of personal data permitted for distribution;
3) An order appointing the person responsible for personal data processing at the Operator.
4) Records of physical media containing personal data are maintained. Storage locations for personal data (physical media) have been determined.
5) A list of persons processing personal data and having access to it has been determined.
6) Separate storage of personal data (physical media) processed for different purposes is ensured.
15. Final Provisions
1) The electronic version of the current edition of this Policy is publicly available on the Operator's website on the Internet at:
https://julia-nutrimind.com/personaldataprocessingpolicy2) This Policy takes effect upon approval and remains in effect indefinitely until a new Policy is adopted or amendments are made to the current Policy.
3) Amendments are made by issuing a new edition of the Policy. The new edition of the Policy takes effect on the day of its approval. The previous edition of the Policy becomes void upon approval of the new edition.
4) Other local regulations of the Operator must be issued in accordance with this Policy and applicable personal data processing legislation.
Sole Proprietor
J.Y. Voistinnykh
April 15, 2026