noesa

Personal Data Processing Policy

POLITICS

processing of personal data and information

1. GENERAL PROVISIONS

This document defines the policy of Individual Entrepreneur Arthur Aramovich Berudzhanyan, TIN: 773771872612 (commercial designation “Noesa”), hereinafter referred to as the “Operator”), regarding the processing and confidentiality of personal data and other information, and sets out the basic principles, goals, conditions and methods of processing personal data and information, a list of personal data subjects, a list of processed personal data data, the functions of the Operator when processing personal data, the rights and obligations of personal data subjects, the procedure for requesting information by the subject of personal data, as well as the requirements for the processing and protection of personal data implemented by the Operator.

This Policy has been developed in accordance with the following regulatory documents:

- Constitution of the Russian Federation;

- Civil Code of the Russian Federation;

- Federal Law of the Russian Federation of July 27, 2006 No. 152-FZ “On Personal Data” (hereinafter referred to as the “Law”);

- Federal Law of the Russian Federation of July 27, 2006 No. 149-FZ “On information, information technologies and information protection”;

- Decree of the Government of the Russian Federation of September 15, 2008 No. 687 “On approval of the Regulations on the specifics of processing personal data carried out without the use of automation tools”;

- Decree of the Government of the Russian Federation dated November 1, 2012 No. 1119 “On approval of requirements for the protection of personal data during their processing in personal data information systems”;

- Order of the FSTEC of Russia dated February 18, 2013 No. 21 “On approval of the composition and content of organizational and technical measures to ensure the security of personal data during their processing in personal data information systems”;

- Basic model of threats to the security of personal data during their processing in personal data information systems. Approved by Deputy Director of the FSTEC of Russia on February 15, 2008;

- Internal regulatory documents of the Operator regulating the processing and ensuring information security of personal data.

The Policy governs the relationship between the Operator and:

1) any individual (client, client representative and other persons specified in paragraph 3 of the Policy) for the processing of personal data of these persons provided by them to the Operator;

2) any individual, individual entrepreneur and legal entity, user of the Operator’s websites (hereinafter referred to as the User, you) for the processing of personal information provided by the User and/or information collected from the User.

The Policy applies to all operations for the processing of Personal Data performed by the Operator, as well as to all information that the Operator and/or its affiliates or other authorized persons acting on behalf of the Operator may receive about the User.

The Policy is mandatory for familiarization and execution by all persons authorized by the Operator to process personal data, and persons involved in organizing the processing and ensuring the security of personal data.

Providing unlimited access to the Policy is implemented by publishing it on the website (domains and subdomains) of the Operator on the Internet at https://noesa.ai (hereinafter referred to as the Website).

The policy is subject to updating in the following cases:

- changes in the legislation of the Russian Federation on personal data;

- identifying inconsistencies affecting the processing and (or) protection of personal data, based on the results of monitoring compliance with the requirements for the processing and (or) protection of personal data;

- by decision of the Operator’s management.

2. BASIC TERMS

1) Personal data (PD) - any information relating to a directly or indirectly identified or identifiable individual (subject of personal data);

2) Processing of personal data - actions (operations) with personal data, including collection, systematization, accumulation, storage, clarification (updating, changing), use, distribution (including transfer), depersonalization, blocking, deletion.

3) Website - a collection of information, texts, graphic elements, design, images, photos and videos and other results of intellectual activity, as well as computer programs contained in an information system that ensures the availability of such information on the Internet.

4) All other terms found in the text of this Policy regarding the processing and protection of personal data are interpreted by the Parties in accordance with the current legislation of the Russian Federation and the usual rules for the interpretation of the relevant terms established on the Internet.

3. PROCESSING OF PERSONAL DATA BY THE OPERATOR

### 3.1. Purposes, legal grounds and terms of Personal Data Processing

The Operator processes Personal Data for the following purposes:

When specifying the category of the entity “Counterparty”, the Operator’s clients and partners are understood together, unless clarification is provided.

1. Formation and provision of reporting established by law, including payment of taxes and contributions established by law.

Category of subjects: Counterparty (individual), representative of the counterparty (individual).

PD category: general/other.

List of personal data: full name, passport details or other identification document, SNILS number, INN, registration address, contact phone number, email address, date of birth.

Processing time: period of validity of the contract; 5 years after the expiration of the contract.

Type of processing: mixed.

Legal basis: performance of functions, powers and duties assigned to the Operator by law (clause 2, part 1, article 6 of the Law).

2. Conclusion, execution, amendment and termination of an agreement to which the Operator is a party.

Category of subjects: Counterparty (individual), representative of the counterparty (individual).

PD category: general/other.

List of PD: full name, passport details or other identification document, TIN, SNILS number, registration address, contact phone number, email address, bank details.

Processing time: period of validity of the contract; termination of the Operator's activities.

Type of processing: mixed.

Legal basis: execution of an agreement, the party/beneficiary of which is the subject/conclusion on the initiative of the subject of an agreement under which he will be the beneficiary (clause 5, part 1, article 6 of the Law).

3. Providing the opportunity to use the products, works and services of the Operator.

Category of subjects: Counterparty - Client (individual), representative of the counterparty (individual).

PD category: general/other.

List of PD: full name, email address, contact phone number, login from the Operator’s website, IP address, cookie data (necessary), information about visiting the site provided by statistics services.

Processing time: period of validity of the contract; 5 years after the expiration of the contract; before withdrawing consent to processing.

Type of processing: mixed.

Legal basis: execution of an agreement, the party/beneficiary of which is the subject/conclusion on the initiative of the subject of an agreement under which he will be the beneficiary (clause 5, part 1, article 6 of the Law).

4. Technical support and consultations.

Category of subjects: Counterparty - Client/Partner (individual), representative of the counterparty/partner (individual).

PD category: general/other.

List of PD: full name, contact phone number, email address.

Processing time: contract period.

Type of processing: automated.

Legal basis: execution of an agreement, the party/beneficiary of which is the subject/conclusion on the initiative of the subject of an agreement under which he will be the beneficiary (clause 5, part 1, article 6 of the Law).

5. Sending gifts.

Category of subjects: Counterparty - Partner (individual), representative of the counterparty/partner (individual).

PD category: general/other.

List of PD: full name, email address, contact phone number.

Processing time: contract period.

Type of processing: automated.

Legal basis: execution of an agreement, the party/beneficiary of which is the subject/conclusion on the initiative of the subject of an agreement under which he will be the beneficiary (clause 5, part 1, article 6 of the Law).

6. Fulfillment of duties assigned to the Operator in connection with the need to verify counterparties.

Category of subjects: Counterparty (individual), representative of the counterparty (individual).

PD category: general/other.

List of PD: full name, passport details or other identification document, TIN, SNILS number, registration address, contact phone number, email address, bank details.

Processing time: until the termination of the Operator's activities.

Type of processing: automated.

Legal basis: performance of functions, powers and duties assigned to the Operator by law (clause 2, part 1, article 6 of the Law); legitimate interest of the Operator (clause 7, part 1, article 6 of the Law).

7. Analysis of user experience in order to improve the offered product, work and services of the Operator.

Category of subjects: Counterparty - Client/Partner (individual), representative of the counterparty/partner (individual), user of websites, as well as domains and subdomains.

PD category: general/other.

List of PD: information about site visits provided by statistics services, IP address, cookie data.

Processing times: 14, 24 months (depending on the type of analytics).

Type of processing: automated.

Legal basis: legitimate interest of the Operator (clause 7, part 1, article 6 of the Law); consent of the subject to the processing of personal data (clause 1, part 1, article 6 of the Law); processing for statistical and other research purposes (clause 9, part 1, article 6 of the Law).

8. Implementation of information and advertising mailings.

Category of subjects: Counterparty - Client/Partner (individual), representative of the counterparty/partner (individual), user of the counterparty, webinar participant.

PD category: general/other.

List of PD: information about visiting the site, domains and subdomains, IP address, cookie data, personal name, phone number, email address.

Processing time: until the consent to data processing is withdrawn.

Type of processing: automated.

Legal basis: consent of the subject to the processing of personal data (clause 1, part 1, article 6 of the Law).

9. Organization and holding of events and webinars.

Category of subjects: Counterparty - Partner (individual), representative of the counterparty/partner (individual), webinar participant.

PD category: general/other.

List of PD: full name, email address, contact phone number.

Terms of processing: until the purpose of processing is achieved; before withdrawing consent to data processing.

Type of processing: automated.

Legal basis: consent of the subject to the processing of personal data (clause 1, part 1, article 6 of the Law); execution of an agreement, the party/beneficiary of which is the subject/conclusion on the initiative of the subject of the agreement, under which he will be the beneficiary (clause 5, part 1, article 6 of the Law).

10. Placing information about performers on the Operator’s website, domains and subdomains in order to increase customer loyalty and form a positive attitude of users towards the Operator’s goods, works and services.

Category of subjects: Performers of the Operator.

PD category: general/other.

List of PD: full name, contact details, photograph.

Processing time: until the consent to data processing is withdrawn.

Type of processing: automated.

Legal basis: consent to the processing of personal data authorized by the subject of personal data for distribution (Article 10.1 of the Law).

11. Posting on the Operator’s website reviews from the Operator’s clients and partners in order to increase customer loyalty and form a positive attitude of users towards the Operator’s goods, works and services.

Category of subjects: Counterparty (individual), representative of the counterparty (individual).

PD category: general/other.

List of PD: full name, contact details, photograph, position, place of work.

Processing time: until the consent to data processing is withdrawn.

Type of processing: automated.

Legal basis: consent to the processing of personal data authorized by the subject of personal data for distribution (Article 10.1 of the Law).

12. Providing users with access to computer software, including the Site, including social networks on the Internet.

Category of subjects: Counterparty (individual), representative of the counterparty (individual).

PD category: general/other.

List of personal data: full name, contact details, photograph, year/month/date of birth, gender, email address, residence address/registration address, telephone number, bank card details, personal account number, profession, position, information collected through metric programs.

Processing time: until the consent to data processing is withdrawn.

Type of processing: automated.

Legal basis: consent of the subject to the processing of personal data (clause 1, part 1, article 6 of the Law).

3.1.1. The Operator does not process biometric Personal Data.

3.1.2. The operator does not intentionally process the personal data of minors. The Contractor recommends that persons over 18 years of age use the site. Responsibility for the actions of minors, including their purchase of services on the Site, lies with the legal representatives of minors. All visitors under 18 years of age are required to obtain permission from their legal guardians before providing any personal information about themselves.

If the Operator becomes aware that he has received personal information about a minor without the consent of legal representatives, then such information will be deleted as quickly as possible.

3.1.3. The operator does not check the existence of a special regime for processing personal data of the subject of personal data. If the subject of personal data is a citizen of the European Union or a citizen of other states, temporarily or permanently residing in the territory of the EU countries and accesses the Site from European countries, the Operator takes all reasonable measures to ensure compliance with such requirements of the legislation on the protection of personal data. To do this, the subject of personal data is obliged to notify the Operator about the existence of a special regime for the protection of his personal data by contacting the Operator's e-mail address privacy@noesa.ai.

3.1.4. The operator generally does not verify the accuracy of personal information provided by the subjects of personal data and does not exercise control over their legal capacity. The risk of providing false personal data, including providing data of third parties as one’s own, is borne by the subject of the personal data.

3.1.5. The operator assumes that:

(a) The subject of personal data provides reliable and sufficient personal information up to date.

(b) The subject of personal data is familiar with this Policy and expresses his informational and informed consent to it.

3.1.6. The terms for processing personal data are determined taking into account:

(1) the established purposes of processing personal data;

(2) the validity period of contracts with personal data subjects and/or consents of personal data subjects to the processing of their personal data;

(3) deadlines determined by regulatory legal acts of the Russian Federation.

### 3.2. Principles and conditions for the Processing of Personal Data by the Operator

3.2.1. The Operator carries out the Processing of Personal Data on a legal and fair basis.

3.2.2. When Processing Personal Data, its accuracy, sufficiency, and relevance in relation to the purposes of Processing Personal Data are ensured.

3.2.3. The Operator carries out the Processing of Personal Data using and without automation tools. At the same time, the Operator fulfills the requirements for automated and non-automated processing of personal data provided for by the Law and regulatory legal acts adopted in accordance with it.

3.2.4. The Operator entrusts the Processing of Personal Data to other persons. At the same time, the Operator fulfills all the requirements for ordering the processing of personal data provided for by the Law.

3.2.5. The Operator does not disclose or distribute Personal Data to third parties, except in the following cases:

(1) The PD subject has expressed his consent to such disclosure in advance.

(2) The transfer is necessary for the execution of an agreement to which the Personal Data subject is a party or beneficiary or guarantor, as well as for concluding an agreement at the initiative of the Personal Data subject or an agreement under which he will be a beneficiary or guarantor.

(3) The transfer is necessary to protect the rights and legitimate interests of the Operator or third parties;

(4) The transfer is initiated by the subject of the Personal Data.

(5) The transfer is necessary for the administration of justice, the execution of a judicial act, an act of another body or official, subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings or other cases provided for by the current legislation of the Russian Federation.

(6) Ensuring proper fulfillment by the Operator of its obligations to the User to provide access to the Site, services, works and goods of the Operator.

### 3.3. Conditions and restrictions on the processing of personal data authorized by the subject for distribution

3.3.1. The Operator, based on the separate consent of the subject of Personal Data, processes certain categories of Personal Data authorized by the subject for distribution and provision of access to an unlimited number of persons by posting them on the Site, including in widgets, in support chats, in presentations, articles, in photos, audio and other works, in advertising on the Internet, in social networks - in official groups and accounts.

3.3.2. Personal data is posted for the purpose of (1) increasing the loyalty of users of the Sites and goods, works, services of the Operator; (2) forming a positive attitude of users towards the products, works and services of the Operator; (3) promotion of goods, works and services of the Operator.

3.3.3. Processing is carried out during the period of validity of the consent of the subject of the Personal data permitted for distribution.

### 3.4. Rights of Personal Data Subjects

3.4.1. The subject of Personal Data has the following rights:

(1) The right to receive information regarding the processing of his Personal Data - send a written request to the email address: privacy@noesa.ai in the manner prescribed by Article 14 of the Law.

(2) The right to clarification, blocking or destruction of data if the Personal Data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing.

(3) The right to withdraw previously provided consent to the processing of Personal Data - send a corresponding notification to the Operator’s email address privacy@noesa.ai marked “Withdrawal of consent to the processing of personal data.” Termination of Processing of Personal Data by the Operator may make it impossible to further use goods, works and services.

The Operator stops Processing Personal Data within 10 working days.

3.4.2. To implement the provisions in subparagraphs (1) and (3) of paragraph 3.4.1. Policies The Operator may require confirmation of the identity of the subject of Personal Data, requiring the provision of such confirmation in any form that does not contradict the law.

### 3.5. Performing the duties of the Operator

3.5.1. To ensure the fulfillment of the obligations provided for by the Federal Law of the Russian Federation “On Personal Data” No. 152-FZ of July 27, 2006 and the regulatory legal acts adopted in accordance with it, the operator has taken the following measures:

(1) a person responsible for organizing the processing of personal data has been appointed;

(2) local acts have been issued on the issues of processing and ensuring the security of personal data, as well as local acts establishing procedures aimed at preventing and identifying violations of the legislation of the Russian Federation, eliminating the consequences of such violations: Policy on the processing of personal data; other local acts on the processing and security of personal data;

(3) legal, organizational and technical measures have been applied to ensure the security of personal data;

(4) internal control is carried out regarding the compliance of the processing of personal data with the requirements of the Law and regulatory legal acts adopted in accordance with it, the Policy, and local acts of the Operator;

(5) an assessment was made of the harm that may be caused to personal data subjects in the event of a violation of the requirements of federal legislation on personal data, a correlation was made between the said harm and the measures taken by the Operator aimed at ensuring the fulfillment of the obligations provided for by the requirements of the Law and regulatory legal acts adopted in accordance with it;

(6) Persons authorized by the Operator who directly process personal data are familiar with the provisions of the Law and regulations adopted in accordance with it, the Policy and local acts of the Operator on the processing of personal data.

3.5.2. The Operator implements the following measures to ensure confidentiality and security when Processing Personal Data:

(1) A security regime has been established for the premises in which information systems are located, preventing the possibility of uncontrolled entry or stay in these premises by persons who do not have access to these premises;

(2) The Operator has approved a document defining the list of persons whose access to personal data processed in the information system is necessary for them to fulfill their contractual obligations;

(3) Information security tools are used that have passed the procedure for assessing compliance with the requirements of the legislation of the Russian Federation in the field of information security;

(4) The requirements established by the Decree of the Government of the Russian Federation of September 15, 2008 No. 687 “On approval of the Regulations on the specifics of processing personal data carried out without the use of automation tools” have been implemented.

### 3.6. Procedure for terminating the Processing of Personal Data

3.6.1. The operator stops processing personal data:

(1) upon expiration of the established deadlines;

(2) upon achievement of the purposes of their processing or in case of loss of the need to achieve these purposes;

(3) at the request of the subject of Personal Data (in relation to Personal Data that is incomplete, outdated, inaccurate, illegally obtained or not necessary for the stated purpose of processing), if it is impossible to ensure the legality of the processing of Personal Data;

(4) in the event that the subject of personal data withdraws consent to the processing of his Personal Data (in relation to Personal Data processed on the basis of the consent of the subject);

(5) in case of termination of activities by the Operator.

3.6.2. Procedure for destruction of Personal data. Destruction of personal data is carried out in the following cases:

(1) unlawful processing of personal data;

(2) the PD is excessive for the stated purpose;

(3) withdrawal of consent to PD processing;

(4) achievement of the purpose of PD processing or loss of the need to achieve such a purpose;

(5) expiration of the PD storage periods established by the regulatory legal acts of the Russian Federation;

(6) recognizing the unreliability of personal data or obtaining it illegally at the request of the authorized body for the protection of the rights of subjects of personal data;

(7) recognition of the unreliability of the PD at the request of the competent government agency.

4. COOKIE NOTICE

4.1. By visiting or using the Site, you agree that the Operator uses certain monitoring and tracking technologies, such as cookies, beacons, pixels, tags, and scripts (collectively, “Cookies”). These technologies are used to provide, maintain and improve the Site, to optimize the Operator's offerings and marketing activities (for example, to track User preferences, improve Site security, identify technical issues, and monitor and improve the overall effectiveness of user behavior).

This notice contains information about what Cookies are, the types of Cookies used on the Site, and how to disable Cookies in your browser.

4.2. What are Cookies?

Cookies are small text files that are stored through the browser on your computer or mobile device. They allow websites to store information such as user preferences. You can think of cookies as so-called memory for the site so that it can recognize you when you return and respond appropriately. Cookies are usually classified as "session cookies", which are automatically deleted when you close your browser, or "persistent cookies", which usually remain on your device until you delete them or they expire.

4.3. Types of Cookies and similar technologies

Technical/necessary cookies. Necessary for the normal operation of certain areas of the Site. They also allow you to distribute the load on servers, collect information about User preferences regarding the use of cookies, etc. Cookies in this category include both session cookies and persistent cookies. Without these files, the Site does not function properly or does not work.

Analytical cookies. Designed to collect information about how visitors use the Site. This information is used to compile reports and improve the Site to make it easier to use and monitor its performance.

Such data consists of connection, technical and aggregate usage data such as IP addresses and general location, device and application data (such as type, operating system, mobile device or application ID, browser version, language settings and language used), date and time stamps of use, associated cookies and pixels installed on or interacted with through such device, and logged activity (sessions, clicks, feature usage, logged actions, mouse movements and other interactions) of Users in communications with the use of the Site. In addition, telephone calls (for example, with customer service or product consultants) may be automatically recorded, tracked and analyzed for purposes including analytics, service, operations and business quality control and improvement, training and record keeping.

These cookies collect non-personal information.

The operator may use analytical tools and corresponding cookies from various service providers, the main ones being:

Yandex.Metrica: Yandex Privacy Policy - https://yandex.ru/legal/confidential/ru

Third party cookies. Used to embed third-party elements into the Site, such as videos, feedback forms, or social networking buttons that allow you to share site content.

Marketing and advertising cookies.

These cookies allow the Operator to know whether you have seen an advertisement or type of advertisement on the Internet, how you interacted with such advertising, and how long it has been since you saw it. The Operator also uses Cookies to deliver targeted advertising. The Operator may use Cookies set by another organization so that the Operator can more accurately target advertising to you. The Operator has also installed Cookies on some other sites on which we advertise our products, works and services. If you receive one of these Cookies, the Operator may use it to identify you as having visited that site and having viewed its advertisement there if you later visit the Site.

Operator's use of web beacons and analytical services.

Some web pages of the Operator Site may contain electronic tags called web beacons, which are used to facilitate the placement of cookies on our Site, determine the number of visitors to the Site, and to provide products jointly with other companies. Web beacons or similar technologies are also included in electronically sent advertisements or newsletters to determine whether the messages have been opened and what happens subsequently.

4.4. Cookie management. Refusal of installation of cookies.

4.4.1. You can prevent the installation of some or all cookies.

4.4.2. Most browsers automatically accept cookies, but you have the ability to manage your browser settings to block or delete cookies. Please refer to your browser settings for further instructions on how to delete cookies.

4.4.3. Certain features of the Site depend on the use of cookies. If you choose to block cookies, you will not be able to sign in or use features and settings that rely on cookies. Deleting cookies deletes any settings and preferences stored in those cookies, including settings related to advertising; you will need to recreate them later.

5. RESPONSIBILITY OF THE PARTIES

5.1. An operator who fails to fulfill its obligations is liable for losses incurred by the User in connection with the unlawful use of personal data, in accordance with the legislation of the Russian Federation.

5.2. In the event of loss or disclosure of Confidential Information, the Operator is not responsible if this confidential information:

5.2.1. Became public domain until it was lost or disclosed.

5.2.2. Was received from a third party prior to its receipt by the Operator.

5.2.3. Was disclosed with the consent of the User.

5.3. In the event of a leak of personal data of the subject of personal data, the Operator is obliged to notify the relevant government authorities about the leak of personal data and the results of the investigation of this leak, within the time limits provided for by the current legislation of the Russian Federation.

6. DISPUTE RESOLUTION

6.1. Before filing a claim in court regarding disputes arising from the relationship between the User and the Operator, it is mandatory to submit a claim (a written proposal for a voluntary settlement of the dispute).

6.2. The recipient of the claim, within 10 (ten) calendar days from the date of receipt of the claim, notifies the claimant in writing of the results of consideration of the claim.

6.3. If no agreement is reached, the dispute will be referred to a judicial authority in accordance with the current legislation of the Russian Federation.

6.4. The current legislation of the Russian Federation applies to this Policy regarding the processing of personal data and the relationship between the User and the Operator.

7. CONFIDENTIALITY OF PERSONAL DATA

7.1. Information related to personal data that has become known to the Operator is confidential information and is protected by law.

7.2. The Operator's employees and other persons who have access to the processed personal data have signed an obligation not to disclose confidential information, and are also warned of possible disciplinary, administrative, civil and criminal liability in case of violation of the norms and requirements of the current legislation of the Russian Federation in the field of personal data processing.

8. ADDITIONAL CONDITIONS

8.1. The policy applies to any action (operation) or set of actions (operations) performed with personal data using automation tools or without the use of such means, including collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data.

8.2. Other rights and obligations of the Operator as an operator of personal data are determined by the legislation of the Russian Federation in the field of personal data.

8.3. The operator is obliged to publish or otherwise provide unrestricted access to this Personal Data Processing Policy in accordance with Part 2 of Art. 18.1. FZ-152. The electronic version of the Policy is posted on the Operator’s Website. User requests regarding the processing and protection of personal data are accepted by the operator at the email address: privacy@noesa.ai.

8.4. The operator has the right to make changes to this Policy without the consent of the personal data subjects.

8.5. The new Policy comes into force from the moment it is posted on the Site, unless otherwise provided by the new edition of the Policy for the Processing and Protection of Personal Data.

8.6. The invalidity of individual provisions of this Policy, if recognized by a court or other authorized government body, does not entail its invalidity as a whole.

9. OPERATOR DETAILS

IP Berudzhanyan A.A.

INN: 773771872612

OGRN: 326774600057471

Responsible for the processing of personal data is Berudzhanyan A.A.