Personal Data Processing Policy
NPK NPO SPECZASHCHITA
Revision: 1.1
Effective date: 14 August 2026, from the moment of posting on the site.
The electronic version is published 14.08.2026; paper copy is made.
1. General
1.1. This Policy defines the principles, goals, conditions and procedure for processing personal data by the Non-commercial Consumer Cooperative "Scientific and Production Association "SPECZASHCHITA" in the conduct of the activities of the Cooperative, using the site SPECZASHCHITA.com, personal account, corporate correspondence and information systems.
1.2. The policy is developed taking into account the Constitution of the Russian Federation, the Civil Code of the Russian Federation, the Labor Code of the Russian Federation, the Tax Code of the Russian Federation, Federal Laws from 27.07.2006 № 152-FZ "Personal Data", from 27.07.2006 № 149-FZ Information, Information Technology and Information Protection, from 06.12.2011 № 402-FZ "Accounting", from 22.10.2004 № 125-FZ "On the Archival Case in the Russian Federation", the Law of the Russian Federation 19.06.1992 № 3085-1, Cooperative Charters, Treaties and Local Acts.
1.3. Federal Law No 152-FZ establishes the requirements for the processing and protection of personal data, but is not itself used as an independent material basis for each operation. Specific grounds are given for processing purposes in the section 5.
1.4. The policy is a public document. It does not constitute consent to the processing of personal data, membership agreement, application for membership or public offer. When the basis of processing is the consent of the subject or the law requires its receipt, such consent is requested specifically, before the relevant processing begins and separately from other information and (or) documents that the subject confirms and (or) signs.
1.5. The Policy uses concepts in the meanings determined by the legislation of the Russian Federation on personal data.
2. Operator and contacts
2.1. Personal data operator:
- full name: Non-commercial Consumer Cooperative "Scientific and Production Association "SPECZASHCHITA";
- short name: NPK "NPO "SPECZASHCHITA";
- OGRN: 1207700383087;
- INN / KPP: 9709066128 / 770901001;
- address of location and postal address: 109004, g. Moscow, st. Stanislavsky, 22, p. 2, p. 11;
- e-mail address for personal data: office@speczashchita.com;
- Phone: +7 (921) 307-67-01.
2.2. The organization of personal data processing is provided by the responsible person appointed by the administrative document. Appeals of subjects are accepted through the above channels, regardless of whether they are addressed personally to the responsible person.
2.3. Passport, bank and other sensitive documents should not be sent by ordinary email. After entering the protected download, they are transmitted through the personal account or in another separately agreed secure way.
3. Principles of processing
Operator:
- process data lawfully, in good faith and only for predetermined purposes;
- does not combine databases processed for incompatible purposes;
- request only the information necessary for a particular stage;
- does not collect information "for the future" just because they may be needed;
- ensures the accuracy of the data and the possibility of their clarification;
- limits storage to the period necessary for the purpose, the requirements of the law and the protection of rights;
- provides access only to authorized persons on the principle of minimum rights;
- by default does not publish a profile, documents, information about the application, membership, contributions or payments;
- does not make decisions on membership that have legal consequences in an exclusively automated way.
4. Categories of subjects
Depending on the purpose, the Operator processes the data:
1. site visitors;
2. persons creating an account, registered users and persons directing appeals;
3. applicants, current and former members of the Cooperative, including foreign citizens and persons 16–17 years in cases permitted by the Charter and law;
4. legal representatives, representatives of applicants, members and organizations;
5. managers, signatories, contact persons and representatives of legal entities;
6. right holders and co-owners of property offered as a non-monetary unit;
7. employees, former employees and applicants;
8. individuals and individual entrepreneurs - counterparties, customers, beneficiaries, guarantors and participants in claim, judicial or enforcement proceedings;
9. representatives and contact persons of contracting organizations.
5. Objectives, composition of data and bases
5.1. Site, account, personal account and appeals
Objectives: operation and protection of the site; registration and maintenance of the account; confirmation of the email address; authentication and restoration of access; provision of functions of the personal account; sending service notifications; processing of appeals; prevention, detection and investigation of security incidents.
Data:
- name and email address;
- ID and account status, date of creation and confirmation;
- cryptographic password hash; password is not stored openly;
- identifiers and hashes of one-time tokens and sessions, their validity period and information about withdrawal;
- information about identifiers, editorial offices and checksums of the User Agreement, Policy and separate Consent to the processing of personal data for the creation and maintenance of the account; fact, date and time of acceptance of the Agreement, familiarization with the Policy and providing consent;
- IP address or its protected derivative, user-agent or its hash, necessary technical cookies, date, time, URL, request ID and the result of the request;
- events of registration, confirmation of mail, entry, exit, restoration of access, account restriction, audit and information security;
- subject and content of the appeal, history of correspondence and response.
The name is used for registration and does not confirm the identity of the person. The email confirmation confirms control of the mailbox, but is not KYC or document verification.
Subjects: visitors to the site; persons creating an account; registered users; persons directing appeals.
Grounds: separate consent of the subject - for the creation and maintenance of the account, confirmation of contact data, authentication, restoration of access, provision of functions of the personal account, sending service notifications and account protection; conclusion and execution of the User Agreement at the initiative of the subject - in terms of processing necessary for the conclusion, execution and termination of the Agreement; fulfillment of the obligations of the Operator established by law; exercise of the rights and legitimate interests of the Operator and users in terms of information security, prevention of abuse and protection of claims. For another operation based on consent, the Operator requests independent consent corresponding to a specific purpose.
Consent to the processing of personal data for the creation and maintenance of the account is provided by a separate independent action after the opportunity to familiarize yourself with its current edition. The consent field is not marked by default. No account is created without consent. This consent does not apply to the preliminary application, formal application for membership, verification of identity and documents, membership, payment and other subsequent procedures, advertising or distribution of personal data; they apply to independent grounds and documents.
Registration of an account is not an application for membership, does not start the term of consideration of the application, does not create a membership and does not create an obligation to contribute.
5.2. Accession applications, membership cases, contributions, shares and payments
Objectives: preparation and consideration of applications; verification of identity, powers and documents; adoption and documentation of decisions; membership and registry management; organization of corporate interaction; accounting for entrance, unit, additional, membership and target contributions; maintenance of personal unit accounts; evaluation and accounting of cash and non-cash units; payments and return of units; execution of the Charter, contracts, decisions of cooperative bodies, requirements of accounting, tax and archival legislation.
Depending on the stage and status of the applicant, only the necessary information can be processed:
- surname, first name, patronymic; former names, if necessary, verification of documents;
- date and place of birth, gender, nationality, family and property status - when required by the applicable form, law or nature of the property transaction;
- address of residence, registration and address for correspondence;
- email and phone;
- data of the identity document in the Russian Federation or abroad, migration and visa information, translation of the document;
- INN, SNILS and foreign tax identifier - only when they are necessary for the statutory, tax, contractual or membership procedure;
- tax residency;
- number, date and status of the application; membership number, membership number, information about the decisions of the cooperative bodies;
- information about the representative and the document confirming the authority;
- type, size, date, purpose and currency of contribution; accruals, payments, payments and returns;
- bank details necessary for transfer or accounting, without a full set of bank card details and security code;
- information on the rights, value, valuation, encumbrances, owners and co-owners of non-monetary units;
- contracts, statements, annexes, acts, accounts, correspondence and documents confirming execution;
- a photo of the person if it is contained in the document or is necessary for the approved verification procedure;
- profession, position and income - only if they are objectively necessary for a specific procedure, verification of the source of funds, powers or execution of the law.
Standard public registration does not collect passport, SNILS, income information, bank details, KYC-files or biometric data. Their request is possible only after registration, in a separate protected process and to the extent necessary for the selected procedure.
Photos, videos, voice recordings or fingerprints are biometric personal data when the Operator uses them for identification purposes. Such processing is not included in the standard registration and can begin only after a separate documented decision, determination of the legal basis and fulfillment of special requirements of the law. Special categories of data are not requested unless their processing is expressly required by law and the relevant basis is not formalized.
Subjects: applicants; current and former members of the Cooperative; legal representatives; representatives of applicants and members; foreign citizens; minors 16–17 years old and their legal representatives in applicable cases; managers, signatories and representatives of legal entities; right holders and co-owners of property.
Grounds: consent - for operations for which it is required; actions on the initiative of the subject before the conclusion of the contract; conclusion and execution of contracts; Charter and decisions of the authorized bodies of the Cooperative; Law of the Russian Federation No. 3085-1, Articles 123.2–123.3 of the Civil Code of the Russian Federation, the norms of accounting, tax and archival legislation; exercise of the rights and legitimate interests of the Cooperative and its members, subject to the rights of the subject.
5.3. Personnel activities and performance of employer responsibilities
Objectives: selection of candidates; conclusion, execution, modification and termination of employment contracts; maintenance of personnel, military, accounting and tax accounting; calculation and implementation of payments; labor protection; performance of employer duties; storage of personnel documents and maintenance of personnel archives.
Data: only necessary for a specific process name, date and place of birth, gender, contacts, addresses, citizenship, marital status, passport data, INN, SNILS, data on education and qualifications, profession and position, information on employment, income and payments, bank account for transfer of payments, information on military registration, photo for personnel document, other information directly provided for by labor, tax and legislation.
Subjects: employees, former employees and applicants.
Grounds: Labor Code of the Russian Federation, Tax Code of the Russian Federation, Federal Laws No 402-FZ, № 27-FZ, № 125-FZ and other applicable norms; conclusion and execution of an employment contract; consent of the applicant to the personnel reserve - if applicable.
5.4. Contracts, counterparties and business correspondence
Objectives: preparation, conclusion, execution, modification and termination of contracts; verification of powers; business correspondence; contractual, accounting and tax accounting; settlement; claim and judicial work; protection of the rights and legitimate interests of the Cooperative and third parties.
Data: name, position, contacts, addresses, INN, identity document data, if necessary, settlement account; information about contracts, powers of attorney, statements, annexes, agreements, acts, accounts, claims, court and enforcement cases; electronic signature and electronic document management data; payment and settlement information; documents confirming the fulfillment of obligations.
Subjects: individuals and individual entrepreneurs - parties, beneficiaries and guarantors; heads, representatives and contact persons of organizations; participants in claim, judicial and enforcement proceedings.
Grounds: actions at the initiative of the subject before the conclusion of the contract; conclusion and execution of the contract; Civil Code of the Russian Federation, Tax Code of the Russian Federation, Federal Law No 402-FZ and applicable procedural legislation; exercise of the rights and legitimate interests of the Cooperative and third parties, subject to the rights of the subject.
6. Operations and methods of processing
6.1. The operator may collect, record, systematize, accumulate, store, refine, extract, use, transfer in the form of provision or access to an authorized person or processor, block, delete and destroy.
6.2. Processing is carried out in a mixed way: with the use of automation tools and without their use, with transmission over the Internet. As of the date of revision, separate transfer of personal data through the office or other corporate local network of the Operator is not carried out. Between cabinet components, data is technically transmitted over private Docker networks on the server; this is part of automated processing in the information system, not the office LAN.
6.3. Automatic verification of the format, completeness, duration of the link or security risk is auxiliary. The decision to become a member of the Cooperative is made by the authorized body, not an algorithm.
7. Obtaining and Compulsory Data
7.1. The main source of data is the subject himself or his authorized representative. Data may be obtained from official registers, from a counterparty, employer or other legal source, if this is necessary for the stated purpose and is allowed by law.
7.2. Mandatory fields are marked in the interface. If the data is necessary for the conclusion or execution of the agreement, submission of the application or fulfillment of the legal requirement, the refusal to provide them may make the relevant operation impossible. Optional data is not a condition for access to a function for which they are not needed.
7.3. The entity shall not transfer the information of a third party without authority or upload redundant data that the Operator has not requested.
8. Technical cookies and logs
8.1. For the operation of the personal account, only the necessary cookies are used:
- __Host-sz_session - server authorization session; cookie is not available in JavaScript, expires when the session is released, withdrawn or expires;
- __Host-sz_csrf - protection against cross-site request forgery; cookie is not available in JavaScript and is used together with a one-time or signed value of the request.
8.2. The maximum duration of the active session is 12 hours, the period of inactivity is 30 minutes. These cookies are necessary for the function requested by the user and are not used for advertising or building a marketing profile.
8.3. As of the date of revision, individual advertising cookies and web analytics systems are not connected to the office. Their connection requires a preliminary assessment, updating of the Policy and, when required by law, separate consent.
9. Data processors and recipients
For the operation of information systems, the Operator can use the following Russian services within the limits of actually connected functions. The transfer of data to the service as a person processing them on behalf is allowed after checking its actual role, the applicable contractual terms and conditions and issuing a documented order when it is required. The indication of the service in this Policy does not in itself replace the contract and does not confirm the existence of yet unverified contractual terms.
| Service | Purpose | Information and restrictions transmitted |
| Timeweb Cloud | site and office hosting, databases, private object storage, backup and delivery of static materials | data of the relevant system; access is limited to the roles and technical measures actually configured, and the contractual terms are checked prior to processing being ordered |
| RuSender | delivery of service letters | e-mail, name if necessary, type of event, technical ID and safe one-time link; passport, membership, bank documents and attachments are not transferred |
| Yandex 360 for business | corporate mail and working interaction | contacts and content of ordinary business correspondence; passport and KYC-files are not requested by ordinary e-mail |
Transfer to state bodies, courts, banks, auditors and other recipients is carried out only if there is a legal basis and to the required extent. When placing an order, the contract should provide for confidentiality, data security, a list of operations and the fulfillment of the applicable requirements of the Operator for processing.
10. Localization and cross-border transfer
10.1. When collecting personal data of citizens of the Russian Federation, recording, systematization, accumulation, storage, refinement and extraction are performed using databases on the territory of the Russian Federation.
10.2. In the processes described in this Policy, cross-border transmission is not carried out. Prior to such transfer, the Operator shall separately determine the state, recipient, basis and protection measures, perform the procedure established by law and update the applicable documents and notifications.
11. Processing time and destruction procedure
The term is determined by the purpose, law, contract and approved nomenclature of cases. If longer storage is not required, the following limits apply:
| Data / Process | Term or condition of termination |
| unconfirmed account | no more than 30 calendar days after registration |
| account; evidence of acceptance of the Agreement, familiarization with the Policy and granting consent | account data - until its closure or withdrawal of consent; after that, limited evidence of registration, provision and withdrawal of consent, other legally significant actions and security events - up to 3 years to resolve the requirements, unless another period is established by law or a related case |
| one-time confirmation email link | 24 hours; after expiration can not be used |
| password recovery link | 30 minutes; after expiration or use can not be used |
| User session | before release or recall; no more than 30 minutes of inactivity and no more than 12 hours from the moment of entry |
| Ordinary Web Access Logs | before being replaced by limited local rotation in volume; in the current container circuit, they are not centrally archived, a fixed calendar period is not declared |
| Security and Audit Journals | during the period necessary for the investigation of events, confirmation of actions and protection of claims; events confirming legally significant actions are stored in the period of the related process; in the event of an incident, dispute or legal claim - until their completion and the expiration of the applicable term of protection of rights; automatic destruction of ordinary events for an unconfirmed 12-month period does not apply |
| treatment and correspondence | until completion of the application and up to 3 years after the response, if it is necessary to confirm the processing and protection of rights |
| Draft Statement | before the user deletes or the inactivity period established by the interface expires |
| Application and materials of verification of a person not accepted as a member | until the completion of the procedure and up to 3 years after the decision, withdrawal or closure of the case, unless the law requires otherwise |
| membership, contractual, accounting, tax, personnel and archival affairs | during the relationship and further within the time limits established by law and the nomenclature of cases |
| Backup of operating systems | on the configured cycle, but not more than 30 days; recovery is carried out in an isolated loop, and data return to the operating system is allowed only after re-application of current removal requirements |
Once the target is achieved, the data is deleted or destroyed if there is no other legal basis. If immediate destruction is not possible, the data is blocked and destroyed no later than the statutory deadline. Destruction in the information system is formalized in a way that allows you to confirm its implementation; paper media are destroyed in a way that excludes recovery.
12. Protection of personal data
Taking into account the nature of processing and current threats, the Operator applies the necessary legal, organizational and technical measures, including:
- appointment of a responsible and approval of local acts;
- accounting of information systems, media, roles and persons with access;
- access control, personal accounts and minimum powers;
- for a personal account - a ban on issuing an administrative session to an employee without verified multi-factor authentication; for other administrative systems - the use of MFA only after its actual setting, along with additional access restrictions;
- Password hashing, secure server sessions, CSRF-protection and frequency restriction of requests;
- Encryption of communication channels, backups and working devices to the applicable extent;
- log security events and control actions with sensitive data;
- backup and restore verification;
- Software update, vulnerability management and incident response;
- check of contractual conditions and registration of requirements for persons processing data on behalf before the relevant transfer;
- assessment of possible harm, identification of current threats and control of the effectiveness of measures.
Secure document downloads, when enabled, should include private storage, quarantine, type and size verification, anti-virus verification, random object names, encryption, versioning, and access log. Until it is ready, KYC files are not accepted through public registration.
13. Rights of the subject and treatment
The subject has the right to obtain information about the processing, to request clarification, blocking or destruction of data, to withdraw consent, to demand the termination of processing in cases provided for by law, to refuse advertising and to appeal the actions of the Operator.
The appeal is sent through the available function of the office, by mail to the address of the Operator or to office@speczashchita.com. The appeal shall indicate the information allowing to identify the applicant and the corresponding processing. The operator has the right to request a minimum confirmation of identity or authority, without collecting excessive data.
The main terms of execution of requirements are determined by the Federal Law No 152-FZ, including:
- providing information on request - 10 working days with a possible motivated extension of no more than 5 working days;
- clarification of confirmed inaccurate data - 7 working days;
- Termination of unlawful processing - before 3 working days, destruction if it is impossible to ensure legality - up to 10 working days;
- destruction upon achievement of the goal or withdrawal of consent in the absence of another reason - up to 30 days;
- termination of processing at the request of the subject - 10 working days with a possible motivated extension of no more than 5 working days.
Withdrawal of consent to the processing of personal data for the creation and maintenance of the account may make it impossible to continue using the account. Upon receipt of the revocation, the Operator terminates the processing based on consent and destroys the data related to this purpose within the period established by law, unless there is another legal basis. The withdrawal does not cancel the legality of the processing performed before its receipt, and does not stop the processing, which continues on another legal basis. Closing the account also does not entail the destruction of documents and limited evidence of legally significant actions that the Operator is obliged or entitled to keep by law, contract or for the protection of rights.
14. Incidents
In case of detection of illegal or accidental transfer, provision, distribution or access to personal data, the Operator conducts an internal investigation and notifies Roskomnadzor within the prescribed time frame: initial notification - within 24 hours, the results of the investigation - within 72 hours. The need and procedure for informing subjects are determined taking into account the nature of the incident and the risk to their rights.
15. Change and Publication of Policy
15.1. The current edition and archive of previous editions are published on SPECZASHCHITA.com with an indication of the version and date of entry into force. On the pages of personal data collection there is a direct link to the current edition.
15.2. The new version applies to the processing from the date of its entry into force. A change to the Policy does not in itself extend the consent previously given and does not replace the notice or new consent if required for a new purpose.
15.3. In case of a significant change in the purposes, composition of data, recipients, cross-border transmission or retention periods, the Operator shall update the Policy, internal matrix and, when required, information sent to Roskomnadzor before the changed processing begins.