Privacy and Personal Data Processing Policy
Limited Liability Company “NEGUS EXPO International” (LLC “NEGUS EXPO International”)
APPROVED
Executive Director
LLC “NEGUS EXPO International”
September 1, 2025
1. GENERAL PROVISIONS
1.1. This document (hereinafter referred to as the “Policy”) defines the policy regarding the processing of personal data by Limited Liability Company “NEGUS EXPO International” (hereinafter referred to as the “Operator”, the “Company”, the “Society”).
1.2. This Policy has been developed in compliance with the requirements of Paragraph 2, Part 1, Article 18.1 of Federal Law No. 152‑FZ dated July 27, 2006, “On Personal Data” (hereinafter referred to as the “Personal Data Law”).
1.3. The terms contained in Article 3 of the Personal Data Law are used in this Policy with the same meaning.
1.4. This Policy applies to all operations performed by the Operator with personal data, whether using automation tools or not.
1.5. Main Rights and Obligations of the Operator
1.5.1. The Operator has the right to:
- obtain reliable information and/or documents containing personal data from the personal data subject;
- require the personal data subject to timely update the provided personal data.
1.5.2. The Operator is obliged to:
- process personal data in accordance with the procedure established by the current legislation of the Russian Federation;
- consider requests from the personal data subject (or their legal representative) regarding personal data processing and provide reasoned responses;
- provide the personal data subject (or their legal representative) with free access to their personal data;
- take measures to update or destroy the personal data of the personal data subject in response to their (or their legal representative’s) lawful and justified requests;
- organize the protection of personal data in accordance with the requirements of the legislation of the Russian Federation.
1.6. Main Rights and Obligations of Personal Data Subject
1.6.1. Personal data subjects have the right to:
- receive full information about their personal data processed by the Operator;
- access their personal data, including the right to obtain a copy of any record containing their personal data, except in cases provided for by federal law;
- request the updating, blocking, or deletion of their personal data if the data are incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated purpose of processing;
- revoke consent to the processing of their personal data;
- take measures provided by law to protect their rights;
- exercise other rights provided for by the legislation of the Russian Federation.
1.6.2. Personal data subjects are obliged to:
- provide the Operator only with reliable data about themselves;
- submit documents containing personal data to the extent necessary for the purpose of processing;
- inform the Operator about any updates (changes) to their personal data.
1.6.3. Persons who provided the Operator with unreliable information about themselves or information about another personal data subject without the latter’s consent shall be held liable in accordance with the legislation of the Russian Federation.
2. SCOPE AND CATEGORIES OF PROCESSED PERSONAL DATA, CATEGORIES OF PERSONAL DATA SUBJECTS
2.1. The Operator may process personal data of the following personal data subjects:
- employees of the Company, former employees, job applicants, as well as relatives of employees;
- clients and counterparties of the Company (individuals), including potential ones;
- representatives/employees of the Company’s clients and counterparties (legal entities), including potential ones;
- visitors to the Company’s website(s) (hereinafter referred to as the “Website” and “Websites”);
- other persons whose personal data the Society is obliged to process in accordance with labor legislation and other acts containing labor law norms.
2.2. The personal data processed by the Operator include:
- the personal data subject’s surname, first name, and patronymic;
- place of residence (region/city);
- specialty/area of professional interests;
- mobile phone number;
- email address;
- history of requests and views on the Website and its services (for Website visitors);
- other information (the above list may be shortened or expanded depending on the specific case and processing purposes).
2.3. The Operator ensures that the content and scope of the processed personal data correspond to the stated processing purposes and, if necessary, takes measures to eliminate any redundancy in relation to the stated processing purposes.
2.4. The Operator processes biometric personal data subject to the written consent of the relevant personal data subjects, as well as in other cases provided for by the legislation of the Russian Federation.
2.5. The Operator does not process personal data relating to racial or national origin, political opinions, religious or philosophical beliefs, or private life.
2.6. The Operator processes special categories of personal data (health information) exclusively in cases provided for by labor legislation (processing of sick leave certificates, mandatory medical examinations) in accordance with Article 10 of the Personal Data Law.
2.7. The Operator does not carry out cross‑border transfer of personal data.
3. PURPOSES OF COLLECTING PERSONAL DATA
3.1. The Operator processes personal data for the following purposes:
- entering into any agreements with personal data subjects and their subsequent execution;
- registration on the website, provision of the Company’s services and tools to personal data subjects, as well as information about the Company’s development of new products and services, including promotional materials;
- providing feedback to personal data subjects, including processing their requests and appeals, and informing them about the operation of the Website, including subdomains;
- managing personnel work and organizing the accounting of the Company’s employees, regulating labor relations and other relations directly related to them;
- attracting and selecting candidates for employment at the Company;
- carrying out business activities;
- performing other functions, powers, and obligations assigned to the Operator by the legislation of the Russian Federation.
3.2. The categories and list of processed personal data, the categories of subjects whose personal data are processed, the methods, terms of their processing and storage, and the procedure for destroying personal data for each purpose specified in this section are defined in the Appendix to this Policy, which is an integral part of this Policy.
4. LEGAL GROUNDS FOR PERSONAL DATA PROCESSING
4.1. The legal grounds for the Operator to process personal data are as follows:
- the Constitution of the Russian Federation;
- the Labour Code of the Russian Federation;
- the Civil Code of the Russian Federation;
- Federal Law No. 149-FZ of July 27, 2006, «On Information, Information Technologies and Information Protection»;
- Law of the Russian Federation No. 2124-1 of December 27, 1991, «On Mass Media»;
- Federal Law No. 294-FZ of December 26, 2008, «On the Protection of the Rights of Legal Persons and Individual Entrepreneurs during State Control (Supervision) and Municipal Control»;
- Decree of the President of the Russian Federation No. 188 of March 6, 1997, «On Approving the List of Confidential Information»;
- Resolution of the Government of the Russian Federation No. 512 of July 6, 2008, «On Approving the Requirements for Material Carriers of Biometric Personal Data and Technologies for Storing Such Data Outside Personal Data Information Systems»;
- Resolution of the Government of the Russian Federation No. 687 of September 15, 2008, «On Approving the Regulations on the Specific Features of Personal Data Processing Carried Out Without the Use of Automation»;
- Resolution of the Government of the Russian Federation No. 1119 of November 1, 2012, «On Approving the Requirements for the Protection of Personal Data During Their Processing in Personal Data Information Systems»;
- Order of Roskomnadzor No. 996 of September 5, 2013, «On Approving the Requirements and Methods for Personal Data Anonymization»;
- Order of FSTEC of Russia No. 21 of February 18, 2013, «On Approving the Composition and Content of Organizational and Technical Measures to Ensure the Security of Personal Data During Their Processing in Personal Data Information Systems»;
- the Operator’s charter documents;
- agreements concluded between the Operator and personal data subjects;
- consents of personal data subjects to the processing of their personal data;
- other grounds where consent to personal data processing is not required by law.
5. PROCEDURE AND CONDITIONS FOR PERSONAL DATA PROCESSING
5.1. To achieve the stated purposes, the Operator uses the following methods of personal data processing:
- non‑automated personal data processing;
- automated personal data processing with or without transmission of the obtained information via information and telecommunications networks;
- mixed personal data processing.
5.2. The list of actions performed by the Operator with personal data includes: collection, systematization, accumulation, storage, clarification (updating, modification), use, transfer, anonymization, blocking, deletion, destruction, as well as any other actions in accordance with the current legislation of the Russian Federation.
5.3. Personal data processing is carried out by the Operator subject to obtaining the personal data subject’s consent (hereinafter referred to as the “Consent”), except for cases established by the legislation of the Russian Federation where personal data processing may be carried out without such Consent.
If the personal data subject refuses to provide their personal data and/or their consent to its processing, the purposes of personal data processing cannot be achieved.
5.4. The personal data subject makes the decision to provide their personal data and gives Consent freely, of their own will, and in their own interest.
5.5. Consent is given in any form that allows confirming the fact of its receipt. In cases provided for by the legislation of the Russian Federation, Consent is provided in writing.
When providing their personal data on the Company’s Website, including subdomains, the personal data subject gives consent to the processing of personal data by checking the box next to the consent text and then clicking the “Submit” button used on the Website. Without checking the box indicating consent, the subsequent click on the button is not available.
5.6. Grounds for termination of personal data processing may include: achievement of the purposes of personal data processing, expiration of the Consent period, or revocation of Consent by the personal data subject, as well as detection of unlawful personal data processing.
5.7. Consent may be revoked by sending a written notice to the Company via registered mail.
5.8. When processing personal data, the Operator takes or ensures the taking of necessary legal, organizational, and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, as well as from other unlawful actions regarding personal data.
5.9. Personal data is stored in a form that allows identifying the personal data subject for no longer than required for the purposes of personal data processing, except in cases where the storage period for personal data is established by federal law or by a contract to which the personal data subject is a party, beneficiary, or guarantor.
5.11. In carrying out personal data storage, the Operator uses databases located on the territory of the Russian Federation.
6. UPDATION, CORRECTION, REMOVAL AND DESTRUCTION OF PERSONAL DATA, RESPONSES TO SUBJECT REQUESTS FOR ACCESS TO PERSONAL DATA
6.1. If the inaccuracy of personal data or the unlawfulness of their processing is confirmed, the personal data shall be updated by the Operator, or the processing thereof shall be terminated, accordingly.
6.2. The fact of inaccuracy of personal data or unlawfulness of their processing may be established either by the personal data subject or by the competent state bodies of the Russian Federation.
6.3. Upon a written request from the personal data subject or their representative, the Operator shall provide information on the processing of the subject’s personal data carried out by them. The request shall contain:
- the number of the main identity document of the personal data subject and their representative;
- details on the date of issue of the document and the body that issued it;
- details confirming the subject’s participation in relations with the Operator (contract number, date of conclusion, conventional verbal designation and/or other details), or other details that otherwise confirm that the Operator is processing the subject’s personal data;
- the signature of the personal data subject or their representative.
The request may be submitted in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
6.4. If the request of the personal data subject does not contain all the necessary details or the subject does not have the rights to access the requested information, the Operator shall send a reasoned refusal.
6.5. In the manner provided for in paragraph 6.3, the personal data subject shall have the right to require the Operator to update their personal data, block them, or destroy them if the personal data are incomplete, outdated, inaccurate, illegally obtained, or are not necessary for the stated purpose of processing, as well as to take measures provided by law to protect their rights.
6.6. Upon achievement of the purposes of personal data processing, as well as in the event that the personal data subject revokes their Consent, the personal data shall be destroyed if:
- the Operator is not entitled to process the data without the subject’s Consent;
- unless otherwise provided by a contract to which the personal data subject is a party, beneficiary, or guarantor;
- unless otherwise provided by another agreement between the Operator and the personal data subject.
6.7. The decision on destruction of personal data shall be made by a commission established by an order of the Operator’s head.
6.8. The procedure for destroying personal data upon achievement of the purposes of processing and upon occurrence of other lawful grounds shall be established by the Operator’s local regulatory act.
6.9. Personal data shall be destroyed by the Operator’s responsible person with the preparation of a corresponding act.
6.10. Upon achievement of the purposes of processing or in the event of revocation of Consent, the Operator undertakes to destroy personal data within a period not exceeding 30 (thirty) days, unless otherwise provided by the contract, law, or another agreement between the Operator and the personal data subject.
6.11. Documentary confirmation of destruction of personal data shall be carried out in accordance with the requirements of the Roskomnadzor Order of 28.10.2022 No. 179:
- in the case of processing of personal data without the use of automation means — by drawing up an Act on Destruction of Personal Data;
- in the case of processing of personal data with the use of automation means — by drawing up an Act on Destruction of Personal Data and forming an extract from the event registration log in the personal data information system.
7. SECURITY OF PERSONAL DATA
7.1. To ensure the security of personal data, the Company takes necessary and sufficient organizational and technical measures to protect personal data of personal data subjects from unlawful or accidental access, destruction, alteration, blocking, copying, dissemination, as well as from other unlawful actions. These measures include, but are not limited to:
- developing and maintaining up‑to‑date local regulatory documents of the Company regarding personal data processing and personal data security, establishing procedures aimed at identifying and preventing violations of the legislation of the Russian Federation in the field of personal data within the Company, and eliminating the consequences of such violations;
- conducting periodic internal control, as well as control carried out by third‑party organizations (external audit) under a contract for work or services, to verify compliance of personal data processing with the requirements of personal data legislation and the Operator’s local regulatory acts adopted in accordance with it;
- assessing the harm that may be caused to personal data subjects in the event of a violation of personal data legislation;
- familiarizing the Company’s employees who directly process personal data with the provisions of the legislation of the Russian Federation and the Company’s local regulatory documents regarding personal data processing and personal data security;
- identifying security threats to personal data during their processing in personal data information systems (hereinafter referred to as “PDIS”);
- applying organizational and technical measures to ensure the security of personal data during processing in PDIS, necessary to meet the requirements for personal data protection;
- detecting instances of unauthorized access (hereinafter referred to as “UA”) to personal data and taking appropriate measures;
- restoring personal data modified or destroyed as a result of UA;
- establishing access rules to personal data processed in PDIS, as well as ensuring registration and accounting of all actions performed with personal data in PDIS;
- monitoring the measures taken to ensure personal data security and the level of protection of PDIS.
8. FINAL PROVISIONS
8.1. All relations concerning personal data processing that are not covered by this Policy shall be governed by the provisions of the legislation of the Russian Federation.
8.2. The Operator has the right to amend this Policy. When amendments are made, the date of the latest update shall be indicated in the current version. The new version of the Policy shall come into force upon its posting on the Website, unless otherwise provided in the new version of the Policy. The current version is permanently available on the Websites at the following addresses: negusexpo.ru, wetex.negusexpo.ru, iranairshow.negusexpo.ru, negusexpo.com, expoclub.ru, negusplus.ru.