Personal Data Processing Policy
1. General provisions
This personal data processing policy has been drawn up in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006, “On Personal Data,” and defines the procedure for processing personal data and measures to ensure its security.
The initial collection, systematization, and storage of personal data of Russian citizens is carried out on servers physically located in the Russian Federation.
Operator: NPO Stekloplastic, located at: 3-A building, Andreevka village, Solnechnogorsk area, Moscow region, Russia, 141551 (hereinafter referred to as the Operator).
Website: https://npo-stekloplastic.com/ and its services
The website and its services are not intended for persons under the age of 18. The user confirms that he/she is ≥ 18 years old by clicking the “Agree”/“Accept” button.
The policy applies to any information about individuals that the Operator receives when using the website https://npo-stekloplastic.com/ and related services.
The Operator does not control and is not responsible for third-party websites that the User may access via links available on the Website.
The Operator’s most important goal is to respect human and civil rights and freedoms when processing personal data, including protecting the right to privacy.
By using the Website, the User confirms that they have read this Policy and the Consent to the processing of personal data. By submitting data through the forms on the Website, the User confirms their consent to this Policy and the Consent to the processing of personal data. If the User does not agree, they must stop using the Website.
2. Key terms
− Personal data — any information relating to a specific or identifiable user of the website
− Processing of personal data — any action involving personal data, including collection, recording, systematization, accumulation, storage, clarification, use, depersonalization, transfer, blocking, deletion, destruction
− User — any visitor to the website https://npo-stekloplastic.com/
− Blocking of personal data — temporary suspension of the processing of personal data (except in cases where processing is necessary to clarify personal data)
− Destruction of personal data — actions resulting in the irretrievable destruction of personal data
− Automated processing of personal data — processing of personal data using computer technology
− Website — a collection of graphic and informational materials, as well as computer programs and databases that ensure their availability on the Internet at the network address https://npo-stekloplastic.com/
− Personal data information system — a collection of personal data contained in databases and information technologies and technical means that ensure their processing
− Depersonalization of personal data — actions that make it impossible to determine, without the use of additional information, the ownership of personal data by a specific User or other subject of personal data
− Operator — a state body, municipal body, legal entity, or individual who, independently or jointly with other persons, organizes and/or carries out the processing of personal data, as well as determines the purposes of personal data processing, the composition of personal data to be processed, and the actions (operations) performed with personal data
− Provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons
3. Legal Grounds and Purposes of Processing
Personal data are processed solely for the following purposes:
| Purpose of Processing | Categories of Data | Legal Basis (Art. 6, Federal Law 152-FZ) | Retention Period |
|---|---|---|---|
| Providing access to the Website and its services | Full name, e-mail, phone, technical cookies | User consent (para. 1, part 1, art. 6) | While the account is active (if any) + 3 years to protect rights |
| Ensuring security and preventing fraud | IP address, user-agent, system logs, strictly necessary cookies | Legitimate interest of the Operator (para. 7, part 1, art. 6) | 1 year |
| Protection against spam and DDoS | IP, e-mail, anti-spam service cookies | Legitimate interest of the Operator (para. 7, part 1, art. 6) | 1 year |
| Processing requests and inquiries (contact forms) | Full name, e-mail, phone, message text | User consent (para. 1, part 1, art. 6) | Until request is fulfilled + 3 years |
| Technical support of users | Full name, contact details, correspondence, technical logs | User consent (para. 1, part 1, art. 6) | Until ticket is closed + 3 years |
| Maintenance of Website operability | System logs, technical cookies | Legitimate interest of the Operator (para. 7, part 1, art. 6) | 1 year |
| Web analytics and statistics | Masked IP, analytical cookies, pages visited, device | User consent (para. 1, part 1, art. 6) | Cookies — 13 months; aggregated anonymized data — indefinitely |
| Establishing feedback (notifications, service messages) | Name, e-mail, phone, messenger ID | User consent (para. 1, part 1, art. 6) | Until consent is withdrawn |
| Advertising and marketing activities | Advertising/tracking cookies, contact details | User consent (para. 1, part 1, art. 6) | Until consent is withdrawn or 12 months since last interaction |
4. Categories of personal data and methods of collection
4.1. Personal data collected
− Full name − Contact phone number − Email address − Data from social networks and messengers (when using the corresponding functions) − Other information voluntarily provided in the text of the message
4.2. Automatically collected technical data
− IP address − Browser information (user agent)
− Data on visited pages
− Technical characteristics of the device
− Date and time of access to the site
− Statistics on interaction with the site
− Cookies (see section 8)
4.3. Special categories of personal data (Art. 10 152-FZ)
The operator does not carry out targeted collection of special categories of personal data.
If such data is accidentally obtained:
− The data is immediately identified and isolated
− A decision on its deletion is made within 24 hours
− Physical deletion is carried out within 3 working days
Users are asked to refrain from providing special categories of personal data in feedback forms and messages.
4.4. Methods of data collection
− Filling out feedback forms on the website
− Automatic collection when visiting the website
− Receiving data through integration with social networks and messengers
− Recording of consent to data processing (date, time, IP address) when clicking the button/checkbox.
4.5. Procedure for obtaining consent to the processing of personal data
− Checking the appropriate box on the form on the website
− Clicking the “Send” / “Agree” button in feedback forms
− Accepting cookies via the consent banner
Upon obtaining consent, the following is recorded:
− Date and time of consent
− User’s IP address
Data on the consent obtained is stored for 3 years after its withdrawal to confirm the legality of the processing.
5. Principles of personal data processing
Personal data is processed based on the following principles:
− Legality and fairness
− Proportionality and limitation to specific, predefined purposes
− Compliance of the amount of data with the stated purposes
− Accuracy and relevance of data
− Limitation of storage periods
− Data minimization
− No merging of databases containing personal data processed for incompatible purposes.
5.1. Automated processing of personal data
The operator carries out automated processing of personal data using the following information systems:
− Website management system
− Web analytics systems (Yandex.Metrica)
− Anti-spam protection systems
− Feedback form processing systems
Automated processing is carried out exclusively for the purposes specified in section 3 of this policy. Decisions that may have legal consequences for the subject of personal data or otherwise affect their rights and legitimate interests are not made solely on the basis of automated processing of personal data. Profiling of personal data for the purpose of analyzing or predicting personal preferences, economic situation, location, health status, personal preferences, or interests of the subject is not carried out.
6. Technical and organizational data protection
6.1. Technical and software protection measures
− Protection against automated requests (anti-spam systems)
− Control of access to personal data
− Logging of actions involving personal data
− Regular updating of security systems
− Backup and encryption of communication channels (HTTPS/SSL)
6.2. Organizational measures
− Restriction of access to personal data
− Appointment of a responsible person
− Monitoring of compliance with legal requirements
− Regular security audits
− Notification of Roskomnadzor about personal data security breaches — within 24 hours; Detailed report — within 72 hours
7. Data storage periods and transfer to third parties
7.1. Personal data storage periods
Data from feedback forms — until the purpose of processing is achieved or a request for deletion is received, but not less than 3 years from the date of withdrawal of consent (to protect legal interests)
Technical data (logs) — 1 year
Data for advertising activities — until consent is withdrawn
7.2. Transfer of data to third parties
Personal data is not transferred to third parties, except in the following cases:
− Compliance with the requirements of current legislation
− Obtaining the consent of the subject of personal data
There is no cross-border transfer of personal data.
7.3. Third-party services
All information collected by third-party services, including payment systems, communication tools, and other service providers, is stored and processed by the specified persons (Operators) in accordance with their User Agreement and Privacy Policy. The subject of personal data and/or the User is obliged to familiarize themselves with these documents in a timely manner. The Operator is not responsible for the actions of third parties who, as a result of using the Internet or the Site’s Services, have gained access to information about the User in accordance with the level of confidentiality selected by the User, or for the consequences of using information that, due to the nature of the Site, is available to any Internet user. The Operator recommends that Users take a responsible approach to deciding how much information about themselves to post on the Site.
8. Cookies and web analytics
8.1. Use of cookies
The website uses cookies for:
− Ensuring the correct functioning of the website (technical cookies)
− Analyzing traffic and user behavior (analytical cookies)
− Providing additional features (functional cookies)
The Website uses the following types of cookies:
— strictly necessary cookies / technical cookies: these cookies are necessary for the Website to function and to provide the User with Services; among other things, they allow the Company to identify the User’s hardware and software, including the type of browser, they collect information about how users interact with the website, which allows identifying errors and testing new features to improve the performance of the Services;
— Statistical/analytical cookies: these cookies allow us to recognize users, count their number, and collect information such as the operations performed on the websites, including information about the web pages visited and the content that the User receives;
— Functional cookies: these cookies enable certain features to be provided to facilitate the use of websites, for example by saving preferences (such as language and location);
— (third-party) tracking/advertising cookies: these cookies collect information about traffic sources, pages visited, and advertisements displayed to the User. They allow us to display advertisements that may be of interest to the User based on an analysis of the information collected about the User. They are also used for statistical and research purposes.
A detailed list of cookies is available at the link.
https://npo-stekloplastic.com/cookies/
8.2. Yandex.Metrica
The website uses the Yandex.Metrica service to analyze traffic. Information about visits is transmitted to Yandex LLC and processed in accordance with Yandex’s privacy policy: https://yandex.ru/legal/confidential/
Users can disable data transfer to Yandex.Metrica using the tool: https://yandex.ru/support/metrika/general/opt-out.html
8.3. Cookie management
Cookies are managed by the Complianz — GDPR/CCPA Cookie Consent widget by clicking on the “Personal Data Processing Policy” button in the lower right corner of the screen.
Users can manage cookies through their browser settings. Disabling cookies may limit the functionality of the website.
9. Rights of personal data subjects
Users have the right to:
− Receive information about the processing of their personal data
− Request clarification, blocking, or deletion of personal data. The period for physical deletion/depersonalization is 10 days
− Withdraw consent to the processing of personal data by sending a request to info@npostek.ru. The operator shall cease processing within 10 working days of receiving such a request.
− The operator shall provide data only after confirming the identity of the subject (one-time code sent to email/phone).
− Request the cessation of personal data processing
− Receive personal data in a structured, machine-readable format
− Contact the authorized bodies for the protection of the rights of personal data subjects
9.1. Right to file a complaint
Personal data subjects have the right to file a complaint with the authorized body for the protection of the rights of personal data subjects in case of violation of their rights during the processing of personal data.
Roskomnadzor contacts:
− Official website: https://rkn.gov.ru/
− Electronic reception: https://rkn.gov.ru/treatments/ask-question/
9.2. Identity verification procedure
When a subject submits a request to exercise their rights, the operator has the right to request identity verification by:
− Sending a one-time code to the email address provided during registration
− Sending a one-time code to the phone number provided during registration
− Providing a copy of an identity document (if necessary)
Identity verification is required to prevent unauthorized access to the personal data of third parties.
To exercise your rights, please send your requests to the following email address: info@npostek.ru
10. Operator’s responsibilities
The operator undertakes to:
− Process personal data in accordance with the purposes specified in the policy
− Ensure the security of personal data
− Prevent unauthorized access to personal data
− Respond to requests from data subjects within 10 working days
− Maintain a register of requests from data subjects
− Notify of personal data security breaches
− Update this policy when legislation changes
− Record and store evidence of consent for at least 3 years.
− Notify Roskomnadzor and subjects of security breaches within the time limits specified in section 6.2.
11. User responsibilities
Users are obliged to:
− Provide accurate personal data
− Notify of changes to personal data in a timely manner
− Not provide personal data of third parties without their consent
12. Responsibility
The operator is not responsible for the loss or disclosure of personal data if:
− The information became publicly available before its loss or disclosure
− The information was obtained from third parties prior to its receipt by the operator
− The information was disclosed with the user’s consent
− The loss or disclosure occurred as a result of intentional unlawful actions by the user aimed at violating information security systems
− The loss/disclosure occurred as a result of force majeure circumstances
13. User requests
Users may send requests regarding the processing of personal data to: info@npostek.ru
The operator reviews requests and sends responses within 10 business days of receiving the request.
14. Final provisions
This policy is a public document and is available to all users of the website at: https://npo-stekloplastic.com/privacy-policy/
Policy version: 2.0
Effective date: 28.06.2025
The operator has the right to make changes to the Policy. When making significant changes:
− The new version is posted on the website at least 10 days before it comes into force
− Archived versions of the policy are retained to ensure transparency
By continuing to use the website after the changes have been made, the user agrees to the new version of the policy.
Change history:
− Version 1.0 dated May 5, 2024 — initial version.
− Version 2.0 dated June 18, 2025 — brought into compliance with the current requirements of Federal Law No. 152-FZ.
Contact details:
Operator: NPO Stekloplastic, located at: 3-A building, Andreevka village, Solnechnogorsk area, Moscow region, Russia, 141551 (hereinafter referred to as the Operator).
Mailing address for inquiries: info@npostek.ru
Last update: 06/18/2025
ATTENTION: Use of the site implies consent to the processing of personal data in accordance with this policy. If you disagree, you must stop using the site.

