Policy regarding the processing of personal data

Last updated: August 4, 2026

This Personal Data Processing Policy of 24TTL DIGITAL MARKETING SOLUTIONS DMCC (24TTL DIGITAL MARKETING SOLUTIONS DMCC, Licence Number: DMCC-581850, Number Value Added Tax (TRN): 100622528600003) (the «Policy») has been developed in accordance with the requirements of Federal Law No. 152-FZ dated 27 July 2006 «On Personal Data» (the «Personal Data Law») for the purpose of ensuring the protection of the rights and freedoms of individuals and citizens in the processing of their personal data by 24TTL DIGITAL MARKETING SOLUTIONS DMCC, including the protection of the right to privacy and personal and family privacy, and applies to all information that 24TTL DIGITAL MARKETING SOLUTIONS DMCC may obtain about a User in connection with the User’s use of 24TTL DIGITAL MARKETING SOLUTIONS DMCC’s website with the domain name http://idrf.online/ on the Internet information and telecommunications network (the «Internet»).

This Policy applies to all Users of the Website. All terms and definitions used in this Policy shall be interpreted in accordance with the applicable legislation of the Russian Federation, in particular the Personal Data Law. Users expressly consent to the processing of their personal data as described in this Policy. Use of the Website or provision of personal data by the User through the Website feedback form constitutes the User's unconditional acceptance of this Policy, the personal data processing terms set out herein, and the collection and use of cookies by the Administrator. If the User does not agree to the terms of this Policy, the User must refrain from using the Website.

1. DEFINITIONS AND TERMS

The following definitions and terms are used in this Policy:

Personal Data Operator (Operator) means a state authority, municipal authority, legal entity or individual that independently or jointly with others organizes and/or carries out the processing of personal data and also determines the purposes of personal data processing, the scope of personal data to be processed, and the actions (operations) performed in relation to personal data.

Administrator means 24TTL DIGITAL MARKETING SOLUTIONS DMCC, the personal data Operator (Licence Number: DMCC-581850, Number Value Added Tax (TRN): 100622528600003) (also referred to as the «Operator»).

Website means the website available on the Internet under the domain name http://idrf.online/, containing information about the Administrator’s services and enabling the User to submit an application through the «Submit request» or «Schedule a call» feedback form (the «Application»). The Administrator is the copyright holder of the Website.

Website Administration means the Administrator’s authorized employees responsible for managing the Website, acting on behalf of the Administrator, who organize and/or carry out personal data processing and determine the purposes of personal data processing, the scope of personal data to be processed, and the actions (operations) performed in relation to personal data.

Personal Data (or the «personal data») means any information relating directly or indirectly to an identified or identifiable individual (personal data subject).

Processing of Personal Data means any action (operation) or set of actions (operations) performed with or without the use of automation tools in relation to personal data, including collection, recording, systematization, accumulation, storage, updating (modification), retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data.

Confidentiality of Personal Data means a mandatory requirement for the Operator (Website Administrator) or any other person who has obtained access to personal data not to disclose such data without the consent of the personal data subject or other lawful grounds.

Publicly Available Personal Data means personal data to which an unlimited number of persons have been granted access with the consent of the personal data subject or in respect of which confidentiality requirements do not apply under federal laws.

Website User (the User) means an individual, a user of the Website, a personal data subject who voluntarily provides personal data through the Website feedback form or via cookies.

Technical Information means information that does not constitute personal data. The Administrator uses cookies (small text files stored on Users’ computers containing information about their previous actions on the Website), which make it possible to identify the User. Cookies are a small piece of data sent by a web server and stored on the User’s computer, which the web client or web browser sends back to the web server in an HTTP request each time it attempts to open a page of the relevant website. Cookies are also text files available to the Administrator for processing information about the User’s activity, including information about which pages the User visited and how long the User used such pages. The User may disable cookies in the browser settings. Technical Information also includes information automatically transmitted to the Administrator during the use of the Website via software installed on the User’s device.

Automated Processing of Personal Data means personal data processing using computer equipment.

Dissemination of Personal Data means actions aimed at disclosing personal data to an indefinite number of persons.

Provision of Personal Data means actions aimed at disclosing personal data to a specific person or a specific group of persons.

Blocking of Personal Data means temporary suspension of personal data processing, except where processing is necessary for clarification of personal data.

Destruction of Personal Data means actions resulting in the impossibility of restoring the contents of personal data in a personal data information system and/or resulting in the destruction of physical media containing personal data.

Depersonalization of Personal Data means actions resulting in the impossibility of determining, without the use of additional information, whether personal data belong to a specific personal data subject.

Personal Data Information System means a set of personal data contained in databases and the information technologies and technical means used for their processing.

Cross-Border Transfer of Personal Data means transfer of personal data to the territory of a foreign state to a foreign public authority, foreign individual, or foreign legal entity.

2. GENERAL PROVISIONS

The Website collects, accesses, and uses, for the purposes specified in this Policy, the Users’ Personal Data provided by them, as well as Technical Information related to Users.

This Policy applies only to the Website. The Website Administration does not control and is not responsible for third-party websites to which the User may navigate through links available on the Website.

The Website Administration does not verify the accuracy of the Personal Data and Technical Information provided by the Website User.

This Policy is publicly available and shall be published on the Internet on the Administrator’s Website.

This Policy applies to Personal Data and Technical Information processed by the Website Administration using automation tools, as well as without the use of such tools.

This Policy applies to relations in the field of personal data processing arising for the Administrator both before and after approval of this Policy.

Personal Data of Website Users constitute confidential information and may not be used by the Website Administration or any other person for personal purposes. At the same time, the Administrator shall maintain the confidentiality of the User’s personal data, except where the User voluntarily provides information about themselves for public access by an unlimited number of persons.

Scope of the English-language Privacy Policy version. This English-language Privacy Policy version applies only to those websites, webpages, and digital services of the Operator that display this Privacy Policy or contain a direct reference or link to it. This English-language Privacy Policy version shall not apply to any website, webpage, or digital service that does not display or refer to this Privacy Policy, or that is governed by its own separate privacy policy or personal data processing policy in the Russian language.

3. SUBJECT MATTER OF THE POLICY

This Policy establishes the procedure for the receipt, protection, storage, processing, and transfer of personal data of Website Users and applies to all information that the Website Administration may obtain about Users while they use the Website.

This Policy also establishes the obligations of the Website Administration with regard to the processing, non-disclosure, and safeguarding of personal data which the User provides at the request of the Website Administration when submitting an Application by sending a request (the «request») to the Administrator’s email address hello@24ttl.net, shishkin@24ttl.net (the «Administrator’s email address») or by completing the feedback form on the Website.

Personal Data permitted for processing under this Policy are provided by the User’s web browser when the User opens the Website and include Technical Information and cookies. The following Personal Data of Users are also permitted for processing: surname, first name, email address, contact telephone number, information regarding representation of a brand or retailer, the name of the company on whose behalf the application is submitted, and the User’s position/job title, provided when the User sends personal data to the Administrator’s email address, submits an Application, or completes the feedback form.

The Administrator protects the User’s personal data automatically transmitted in the course of the User’s use of the Website.

Disabling cookies may result in the inability to access certain parts of the Website.

Any other personal information not specified above (purchase history, browsers and operating systems used, etc.) shall be securely stored and not disclosed, except as provided in clauses 5.2 and 5.3 of this Policy.

4. PURPOSES OF COLLECTION OF THE USER’S PERSONAL DATA

The Website Administration may use the User’s Personal Data for the following purposes:

To identify the User registered on the Website for the purpose of registration and/or other actions.

To provide the User with access to the personalized resources of the Website.

To establish feedback with the User, including sending notifications and requests related to the use of the Website, and processing the User’s requests and applications.

To determine the User’s location for security and fraud prevention purposes.

To confirm the accuracy and completeness of the personal data provided by the User.

To send email notifications to the User.

To provide the User with efficient customer and technical support in the event of issues related to the use of the Website.

Subject to the User’s consent, to provide the User with product updates, special offers, pricing information, newsletters, and other information on behalf of the Administrator.

To carry out advertising activities with the User’s consent.

5. SCOPE AND CATEGORIES OF PERSONAL DATA PROCESSED; CATEGORIES OF PERSONAL DATA SUBJECTS

The content and scope of the personal data processed must correspond to the stated purposes of processing set out in Section 4 of this Policy. The personal data processed must not be excessive in relation to the stated purposes of processing.

The Website Administration is entitled to process personal data of the following categories of personal data subjects: Website Users.

The list of personal data processed by the Website Administration includes the surname and first name of the Website User, email address, contact telephone number, information regarding representation of a brand or retailer, the name of the company on whose behalf the application is submitted, and the User’s position/job title, provided by Users when submitting an Application or completing the feedback form, as well as the Website Users’ Technical Information (cookies) referred to in clause 3.3 of this Policy.

6. LEGAL GROUNDS FOR PROCESSING PERSONAL DATA

The Operator (Administrator) processes the User’s personal data only if such data are completed and/or sent by the User independently through special forms located on the Website. By completing the relevant forms and/or sending their personal data to the Operator through the Website, the User expresses their consent to this Policy.

7. PROCEDURE AND CONDITIONS FOR PROCESSING PERSONAL DATA

The Administrator processes personal data with the consent of the personal data subject to the processing of their personal data, unless otherwise provided by the legislation of the Russian Federation in the field of personal data, by the following method: automated processing of personal data, with or without transmission of the obtained information via information and telecommunications networks.

The User gives consent to the processing of their Personal Data by opening the Website using a web browser, submitting an Application, and completing the feedback form.

The User acknowledges and agrees that by opening the Website using a web browser, including by submitting an Application or completing the feedback form, the User grants the Administrator consent to processing, i.e., to the performance of the actions provided for in paragraph 3 of Article 3 of the Personal Data Law. Personal Data shall be processed in accordance with the purposes specified in Section 4 of this Policy. The conditions for termination of personal data processing are cessation of the User's use of the Website and receipt by the Administrator of a written notice withdrawing this Consent to the processing of personal data. Consent to the processing of personal data shall remain effective from the date on which the User sends personal data to the Administrator's email address, completes the feedback form, or submits an Application, until the date on which the User withdraws such consent in writing. The User is entitled to withdraw consent to the processing of personal data by sending such withdrawal to the Administrator's email address.

Personal data processing by the Administrator is limited to the achievement of specific, predetermined, and lawful purposes. Only personal data that meet the purposes of processing are subject to processing.

Only the Administrator’s authorized employees (the Website Administration) whose job duties include the processing of personal data are permitted to process personal data. The list of Website employees who have access to Website Users’ personal data shall be approved by the Administrator’s order.

Website Users’ personal data are stored on paper media or in electronic form in the Website’s personal data information system, as well as in backup copies of the Website’s databases.

When storing Website Users’ personal data, organizational and technical measures are observed to ensure their safety and prevent unauthorized access thereto.

When storing personal data, the Administrator uses exclusively databases located within the territory of the Russian Federation in accordance with Part 5 of Article 18 of the Personal Data Law.

Only employees of the Website Administration who have been admitted to work with Website Users’ personal data and have signed a non-disclosure agreement regarding Website Users’ personal data may have access to the processing of Website Users’ personal data.

Personal data shall be stored in a form allowing identification of the personal data subject and information on their actions on the Website for no longer than required by the purposes of personal data processing, unless a storage period for personal data is established by federal law or by a contract to which the personal data subject is a party, beneficiary, or guarantor.

Personal data on paper media shall be stored for the storage periods established by the legislation of the Russian Federation on archival records management for documents for which such periods are provided.

The storage period for personal data processed in personal data information systems shall correspond to the storage period for personal data on paper media.

Processed personal data shall be destroyed or depersonalized upon achievement of the purposes of processing or if the need to achieve such purposes is lost, unless otherwise provided by federal law.

Conditions for termination of personal data processing may include achievement of the purposes of personal data processing, expiry of the consent period, withdrawal by the personal data subject of consent to the processing of their personal data, as well as identification of unlawful personal data processing.

Employees of the Administrator who have obtained access to personal data are obliged not to disclose personal data to third parties and not to disseminate personal data without the consent of the personal data subject, unless otherwise provided by federal law.

The Administrator shall take measures necessary and sufficient to ensure compliance with the obligations provided by the Personal Data Law and the regulatory legal acts adopted pursuant thereto, including the following measures:

appointment of a person responsible for organizing personal data processing;

adoption of local regulations and other documents in the field of personal data processing and protection;

observance of conditions ensuring the safety of personal data and preventing unauthorized access thereto;

detection of unauthorized access to personal data and taking measures in response;

organization of training and methodological work with the Administrator’s employees admitted to work with personal data, including through information systems;

obtaining consent from personal data subjects to the processing of their personal data, except where otherwise provided by the legislation of the Russian Federation;

segregation of personal data processed without the use of automation tools from other information, including by recording such personal data on separate physical media and in separate sections;

ensuring separate storage of personal data and physical media processed for different purposes and containing different categories of personal data;

ensuring the security of personal data when transferring them through open communication channels;

use of certified antivirus software with regularly updated databases;

storage of physical media containing personal data in conditions ensuring the safety of personal data and preventing unauthorized access thereto;

internal control over compliance of personal data processing with the Personal Data Law, regulatory legal acts adopted pursuant thereto, personal data protection requirements, this Policy, and the Administrator’s local regulations;

other measures provided by the legislation of the Russian Federation in the field of personal data.

All information regarding the transfer of Website Users’ personal data shall be recorded for the purpose of monitoring the lawfulness of the use of such information by persons who received it.

In order to improve the quality of service and ensure the possibility of legal protection, the Website Administration may store log files regarding actions performed by Users while using the Website.

Cross-border transfer of personal data:

Before commencing a cross-border transfer of personal data, the Operator must ensure that the foreign state to whose territory the transfer of personal data is intended provides reliable protection of the rights of personal data subjects.

Cross-border transfer of personal data to the territories of foreign states that do not meet the above requirements may be carried out only if there is written consent of the personal data subject to the cross-border transfer of their personal data and/or for the performance of a contract to which the personal data subject is a party.

Before commencing activities involving the cross-border transfer of personal data, the Operator must notify the authorized authority for the protection of the rights of personal data subjects of its intention to carry out a cross-border transfer of personal data.

Possible Cross-Border Transfer of Personal Data. In the course of operating the Website and providing related services, the Operator may, where permitted by applicable law and subject to compliance with the requirements of the legislation of the Russian Federation, carry out the cross-border transfer of personal data to foreign jurisdictions, including to foreign service providers, contractors, or affiliated persons engaged in supporting the operation of the Website, communications, analytics, or other related functions. Where required by law, such cross-border transfer shall be carried out only after the Operator has complied with the mandatory legal requirements and obtained any consent required from the personal data subject.

8. METHODS AND PERIODS OF PERSONAL DATA PROCESSING; RESPONSES TO REQUESTS OF PERSONAL DATA SUBJECTS FOR ACCESS TO PERSONAL DATA

The User’s personal data shall be processed without limitation of time, by any lawful means, including in personal data information systems using automation tools or without using such tools.

The period of personal data processing is unlimited. The User is entitled at any time to withdraw their consent to the processing of personal data by sending a notice by email to the Operator’s email address hello@24ttl.net, shishkin@24ttl.net with the subject line «Withdrawal of consent to the processing of personal data».

The User agrees that the Website Administration is entitled to use personal data, including for determining statistics on Users’ actions.

The User’s personal data may be transferred to authorized state authorities of the Russian Federation only on the grounds and in the manner established by the legislation of the Russian Federation.

In the event of loss or disclosure of personal data, the Website Administration shall inform the User of the fact of loss or disclosure of personal data no later than 5 (five) business days thereafter.

The Website Administration shall take necessary organizational and technical measures to protect the User’s personal data from unlawful or accidental access, destruction, modification, blocking, copying, dissemination, and other unlawful actions of third parties.

The Website Administration, jointly with the User, shall take all necessary measures to prevent losses or other adverse consequences caused by the loss or disclosure of the User’s personal data.

Confirmation of the fact of personal data processing, the legal grounds and purposes of personal data processing, as well as other information specified in Part 7 of Article 14 of the Personal Data Law, shall be provided to the personal data subject or their representative within 10 (ten) business days from the date of request or receipt of the request from the personal data subject or their representative. This period may be extended, but by no more than 5 (five) business days, for which purpose the Administrator shall send the personal data subject a reasoned notice indicating the reasons for extending the period for providing the requested information.

The information provided shall not include personal data relating to other personal data subjects, except where there are lawful grounds for the disclosure of such personal data.

The Administrator shall provide the information specified in Part 7 of Article 14 of the Personal Data Law to the personal data subject or their representative in the same form in which the relevant application or request was sent, unless otherwise specified in the application or request.

If the application (request) of the personal data subject does not contain all information required by the Personal Data Law or the subject does not have the rights of access to the requested information, a reasoned refusal shall be sent.

If inaccurate personal data are identified upon application by the personal data subject or their representative, or upon their request, or upon a request from Federal Service for Supervision of Communications, Information Technology, and Mass Media (the «Roskomnadzor»), the Administrator shall block the personal data relating to the relevant personal data subject from the moment of such application or receipt of the relevant request for the period of verification, provided that such blocking does not violate the rights and legitimate interests of the personal data subject or third parties.

If the inaccuracy of personal data is confirmed, the Administrator, on the basis of information provided by the personal data subject or their representative or Roskomnadzor, or on the basis of other necessary documents, shall clarify (update, correct) the personal data within 5 (five) business days from the date on which such information is provided and shall remove the block on the personal data.

If unlawful processing of personal data is identified upon application (request) of the personal data subject or their representative or Roskomnadzor, the Administrator shall block the unlawfully processed personal data relating to that personal data subject from the moment of such application or receipt of the request.

Upon achievement of the purposes of personal data processing, as well as in the event that the personal data subject withdraws consent to such processing, personal data shall be destroyed, unless:

otherwise provided by a contract to which the personal data subject is a party, beneficiary, or guarantor;

the Administrator is entitled to process personal data without the consent of the personal data subject on grounds provided by the Personal Data Law or other federal laws;

otherwise provided by another agreement between the Administrator and the personal data subject.

Conditions and periods for destruction of personal data by the Administrator:

Achievement of the purpose of personal data processing or loss of the need to achieve such purpose — within 30 (thirty) calendar days;

Expiry of the maximum storage periods for documents containing personal data — within 30 (thirty) calendar days;

Provision by the personal data subject (or their representative) of confirmation that the personal data were obtained unlawfully or are not necessary for the stated purpose of processing — within 7 (seven) business days;

Withdrawal by the personal data subject of consent to the processing of their personal data, if retention of the personal data is no longer required for the purposes of processing — within 30 (thirty) calendar days.

9. RIGHTS AND OBLIGATIONS OF THE PARTIES

The User shall:

Provide the Technical Information on personal data necessary for use of the Website where the normal functioning of the Website is impossible without such Technical Information, and provide accurate Personal Data for the purpose of submitting an Application or completing the feedback form.

Update and supplement the information on personal data previously provided to the Administrator in the event of changes thereto.

The Website Administration shall:

Use the information received solely for the purposes specified in Section 4 of this Policy.

Provide the personal data subject, upon request, with information relating to the processing of their personal data.

Organize the processing of personal data in the manner prescribed by the legislation of the Russian Federation in force.

Provide the authorized authority for the protection of the rights of personal data subjects, upon request, with the necessary information within 10 (ten) calendar days from the date of receipt of such request.

Observe the principles and rules of personal data processing provided by the Personal Data Law, maintain the confidentiality of personal data, and take the necessary measures aimed at ensuring compliance with the obligations provided by the Personal Data Law.

Ensure the confidentiality of personal data, not disclose them without the User’s prior written consent, and not sell, exchange, publish, or otherwise disclose the User’s transferred personal data, except as provided in clauses 5.2 and 5.3 of this Policy.

Take precautions to protect the User’s personal data in accordance with the procedure commonly used to protect information of this kind in current business practice.

Block personal data relating to the relevant User from the moment of application or request by the User, their legal representative, or the authorized authority for the protection of the rights of personal data subjects for the period of verification, in case inaccurate personal data or unlawful actions are identified.

Publish or otherwise ensure unrestricted access for Users to this Policy regarding the processing of personal data.

The User is entitled to:

Receive information relating to the processing of their personal data, except in cases provided by federal laws.

Require the Administrator to clarify, block, or destroy their personal data if the personal data are incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated purpose of processing, and to take measures provided by law to protect their rights.

Withdraw consent to the processing of personal data, and also send a request for cessation of personal data processing.

Appeal unlawful actions or omissions of the Administrator in the processing of their personal data to Roskomnadzor or in court.

The Website Administration is entitled to:

Independently determine the composition and list of measures necessary and sufficient to ensure compliance with the obligations provided by the Personal Data Law and regulatory legal acts adopted pursuant thereto, unless otherwise provided by the Personal Data Law or other federal laws.

Receive from the personal data subject accurate information and/or documents containing personal data.

Independently determine the composition and list of measures necessary and sufficient to ensure compliance with the obligations provided by the Personal Data Law and regulatory legal acts adopted pursuant thereto, unless otherwise provided by the Personal Data Law or other federal laws.

Entrust personal data processing to another person with the consent of the personal data subject, unless otherwise provided by federal law, on the basis of a contract concluded with such person, provided that the person processing personal data on behalf of the Administrator is obliged to comply with the principles and rules of personal data processing established by the Personal Data Law.

If the personal data subject withdraws consent to the processing of personal data, the Administrator is entitled to continue processing personal data without the consent of the personal data subject where there are grounds provided by the Personal Data Law.

LIABILITY FOR VIOLATION OF THE RULES GOVERNING THE PROCESSING AND PROTECTION OF WEBSITE USERS’ PERSONAL DATA

Persons guilty of violating the rules governing the receipt, processing, and protection of personal data of Website Users shall bear disciplinary, financial, civil, administrative, and criminal liability in accordance with the legislation of the Russian Federation in force.

Moral damage caused to a Website User as a result of violation of their rights, violation of the personal data processing rules established by the Personal Data Law, as well as the personal data protection requirements established pursuant to the said Federal Law, shall be compensated in accordance with the legislation of the Russian Federation. Compensation for moral damage shall be independent of compensation for pecuniary damage and losses incurred by the Website User.

DISPUTE RESOLUTION

Before filing a claim in court regarding disputes arising out of relations between the Website User and the Website Administration, it is mandatory to submit a complaint (a written proposal for voluntary settlement of the dispute).

The recipient of the complaint shall, within 30 (thirty) calendar days from the date of receipt of the complaint, notify the complainant in writing of the results of consideration of the complaint.

If no agreement is reached, the dispute shall be referred to a court in accordance with the legislation of the Russian Federation in force.

This Policy and the relations between the User and the Website Administration shall be governed by the legislation of the Russian Federation in force.

FINAL PROVISIONS

The User may obtain any clarifications on issues of interest concerning the processing of their personal data by contacting the Administrator by email at hello@24ttl.net, shishkin@24ttl.net.

The Administrator is entitled to make changes to this Policy. When changes are made, the current version shall indicate the date of the latest update. The new version of the Policy shall enter into force from the moment it is posted on the Website, unless otherwise provided by the new version of the Policy. The current version shall be permanently available on the Website. The Administrator shall ensure unrestricted access to this Policy.

This Policy shall be subject to unscheduled review in the event of significant changes in legislation in the field of personal data protection, changes in the list of Users’ personal data processed by the Administrator when the User uses the Website, changes in the purposes of personal data processing, and in other cases constituting grounds for amendments to the Policy, including by decision of the Administrator.

© 2019–2026 24TTL Privacy PolicyCookie settings idrf.online