Office 548, Bldg. 1, 55/59 Bolshaya Pochtovaya St., Moscow 105082 (Elektrozavodskaya metro station)

+7 (499) 755-54-96
+7 (916) 007-81-01
sales@cifp.ru
RUEN

Policy of Sales Solutions Group LLC on the processing and protection of personal data

1. General provisions

1.1. This policy (hereinafter, the “Policy”) has been developed in accordance with Article 18.1 of Federal Law No. 152-FZ “On Personal Data” dated July 27, 2006 (hereinafter, the “PD Law”) and is a local regulation of Sales Solutions Group Limited Liability Company (hereinafter, the “Company”) that defines the key areas of its activities in the processing and protection of personal data (hereinafter, “PD”) for which the Company acts as the operator.

1.2. The Policy has been developed to implement the requirements of legislation on the processing and protection of PD as one of the legal measures aimed at protecting human and civil rights and freedoms when a person’s PD is processed by the Company.

1.3. The provisions of the Policy apply to relations involving the processing and protection of PD obtained by the Company both before and after the approval of the Policy, except where, for legal, organizational, or other reasons, the provisions of the Policy cannot be applied to relations involving the processing and protection of PD obtained before its approval.

1.4. The provisions of the Policy and other local regulations of the Company on personal data protection apply to the processing and protection of the PD of heirs (legal successors) and/or representatives of PD subjects, even if such persons are not expressly mentioned in the Company’s local regulations but actually participate in legal relations with the Company.

1.5. This Policy is published on the Company’s website https://cifp.ru to make it available to an unlimited number of persons.

2. Grounds and purposes of personal data processing by the Company

2.1. The Company processes PD in the course of its statutory activities, in particular: in employment and directly related relations in which the Company acts as an employer; in connection with the performance of contracts to which the PD subject is a party; and in connection with appeals, inquiries, and other forms of feedback sent to the Company.

2.2. In connection with employment and directly related relations in which the Company acts as an employer, the Company processes the PD of job applicants, employees of the Company (hereinafter, “Employees”), and former Employees in accordance with labor legislation. For the purposes of concluding, performing, and terminating civil law contracts, as well as in the course of pre-contract work, the Company processes the PD of individuals who are clients and prospective clients of the Company, as well as the PD of individual entrepreneurs and representatives (contact persons) of legal entities that are counterparties.

2.3. In connection with the exercise of its rights and obligations as a legal entity, in accordance with Part 2 of Article 22 of the PD Law, the Company also processes the PD of:

  • individuals who are counterparties (potential counterparties) of the Company under civil law contracts, the PD of managers, members of collegial executive bodies, and representatives of legal entities, and the PD of other individuals submitted by procurement (tender) participants, including data obtained from open public registers and information systems (the Unified State Register of Legal Entities (EGRUL), the Unified State Register of Individual Entrepreneurs (EGRIP), the public procurement portal, etc.), for the purpose of concluding contracts in accordance with legal requirements and ensuring the fulfillment of contractual obligations;
  • citizens and representatives of organizations who contact the Company in writing regarding its activities (other than the persons specified in clause 2.2 of the Policy) and provide their PD in their communication (application, claim, etc.), for the purpose of sending them responses and providing information. 2.4. PD is obtained and processed by the Company with the consent of the PD subject or, without the subject’s consent, on the basis of federal laws and other regulatory legal acts of the Russian Federation.

2.4. PD is obtained and processed by the Company with the consent of the PD subject or, without the subject’s consent, on the basis of federal laws and other regulatory legal acts of the Russian Federation, in particular Article 86 of the Labor Code of the Russian Federation with respect to employee data.

2.5. With the written consent of the PD subject, the Company may, in the course of its activities and in the prescribed manner, entrust the processing of PD to third parties.

2.6. The Company provides the PD it processes to state and municipal authorities, bodies of state extra-budgetary funds, and institutions that are entitled under federal law to receive such PD.

2.7. When PD is processed, its accuracy, sufficiency, and, where necessary, relevance to the purposes of processing are ensured. The Company takes the necessary measures to delete or correct incomplete or inaccurate PD.

3. Principles of personal data security

3.1. The main objective of ensuring the security of PD processed by the Company is to prevent unauthorized access to PD by third parties and to prevent deliberate software, technical, and other actions aimed at stealing PD or destroying or distorting it during processing.|

3.2. To ensure PD security, the Company is guided by the following principles:

  1. legality: PD protection is based on the provisions of regulatory legal acts and guidance documents of the authorized state bodies in the field of PD processing and protection;
  2. comprehensiveness: PD protection is built using a range of legal and organizational measures and the functional capabilities of the technical means available to the Company;
  3. continuity: PD protection is ensured at all stages of PD collection, accumulation, and processing, up to and including its destruction;
  4. timeliness: measures ensuring an adequate level of PD security are taken before processing begins;
  5. elimination of non-compliance and improvement of measures: the Company promptly eliminates any identified violations of legislation on PD processing and protection and upgrades and expands PD protection measures and tools, including on the basis of assessing new threats to PD security;
  6. personal responsibility: responsibility for ensuring PD security is assigned to specific Employees within the scope of their duties related to PD processing and protection;
  7. minimization of access rights: Employees are granted access to PD only to the extent necessary to perform their job duties;
  8. flexibility: PD protection functions continue to be performed when the volume and composition of the processed PD change;
  9. observability and transparency: PD security measures must be planned so that the results of their application are clearly observable (transparent) and can be assessed by those exercising oversight, as well as by the PD subjects themselves, including by receiving written responses to their requests;
  10. continuous monitoring and assessment: procedures are established for periodic checks of compliance with the measures developed, and the results of these checks are recorded in logs.

4. Access to processed personal data

4.1. Access to PD processed by the Company is granted to Employees authorized by an order of the Company, as well as to persons whom the Company has entrusted with PD processing under a concluded contract.

4.2. Employees access processed PD in accordance with their job duties and the requirements of the Company’s local regulations.

4.3. The procedure for a PD subject’s access to their PD processed by the Company is determined in accordance with the law and ensured by the Company’s local regulations.

4.4. Requests and inquiries from PD subjects seeking information on the processing of their PD should be sent to the Company’s officer responsible for organizing personal data processing at: Office 450, 55/59 Bolshaya Pochtovaya St., Bldg. 1, Moscow

5. Personal data protection measures implemented

5.1. The set of legal, organizational, and technical measures is determined, and local regulations on PD processing and protection are approved (issued) by the Company, based on the requirements of the PD Law, Chapter 14 of the Labor Code of the Russian Federation, and other regulatory legal acts of the Russian Federation on PD processing and protection.

5.2. The Company familiarizes its employees who directly process PD with the provisions of PD legislation, including PD protection requirements, this Policy, and other local regulations on PD processing, and, where necessary, provides these employees with training on PD processing and protection.

5.3. The following organizational measures are applied when processing PD:

  1. an Officer responsible for organizing PD processing is appointed;
  2. Employee access is restricted and differentiated;
  3. internal control and/or audits are carried out to verify that PD processing complies with the PD Law and the regulatory legal acts adopted pursuant to it, PD protection requirements, the Policy, and other regulations of the Company;
  4. other measures are taken to ensure the fulfillment of obligations under the PD Law, in particular, threat modeling and risk assessment.


5.4. The following technical measures are applied when processing PD:

  1. an access control system and physical security of the premises are in place, and locking devices are used;
  2. alarm and event logging tools are used to detect unauthorized access to PD and take appropriate action;
  3. when PD is processed in information systems (PDIS), information security tools are used to ensure the appropriate level of protection, along with measures to restore modified or destroyed PD and measures to register and record all actions performed with PD in the personal data information system.


01.03.2026