Privacy Policy.
Sole Proprietor Ksenia Stanislavovna Yao
INN 519017997774 OGRNIP 324237500380660
POLITICS
processing of personal data
Revised August “14,” 2026
Russian Federation, 2026
TABLE OF CONTENTS
1. GENERAL PROVISIONS3
2. PURPOSES OF COLLECTING PERSONAL DATA4
3. LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA6
4. SCOPE AND CATEGORIES OF PERSONAL DATA PROCESSED, CATEGORIES OF DATA SUBJECTS6
5. PROCEDURES AND CONDITIONS FOR THE PROCESSING OF PERSONAL DATA7
6. UPDATE, CORRECTION, DELETION, AND DESTRUCTION OF PERSONAL DATA; RESPONSES TO DATA SUBJECTS’ REQUESTS FOR ACCESS TO PERSONAL DATA8
1. GENERAL PROVISIONS
1.1. This Policy on the Processing of Personal Data (hereinafter referred to as the “Policy”) has been developed in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006, “On Personal Data” (hereinafter referred to as the “Personal Data Law”) to ensure the protection of human and civil rights and freedoms in the processing of personal data, including the protection of the rights to privacy and personal and family confidentiality.
1.2. This Policy applies to all personal data processed by Sole Proprietor Ksenia Stanislavovna Yao, TIN 519017997774, OGRNIP 324237500380660 (hereinafter referred to as the “Controller”).
1.3. This Policy applies to relationships involving the processing of personal data that arose for the Operator both before and after the adoption of this Policy.
1.4. In accordance with the requirements of Part 2 of Article 18.1 of the Personal Data Law, this Policy is published and freely accessible on the Internet at the Operator’s website at the following web address: https://tsuyuperfumes.art, and also applies to its subdomains (hereinafter referred to as the “Website”).
1.5. Key Terms Used in the Policy:
Personal data—any information relating directly or indirectly to an identified or identifiable natural person (hereinafter referred to as the “Data Subject”), including information obtained from visitors and users (hereinafter referred to as “Users”) while using the Website.
personal data controller (Controller) – a person who, independently or jointly with others, organizes and/or carries out the processing of personal data, as well as determines the purposes of such processing, the scope of the personal data, and the actions (operations) performed on the personal data;
processing of personal data—any action (operation) or set of actions (operations) involving personal data, whether performed using automated means or not. The processing of personal data includes, among other things:
- collection;
- entry;
- systematization;
- accumulation;
- storage;
- clarification (update, change);
- excerpt;
- use;
- transfer (distribution, provision, access);
- depersonalization;
- blocking;
- deletion;
- destruction.
automated processing of personal data—the processing of personal data using computer technology;
disclosure of personal data—actions aimed at disclosing personal data to an unspecified group of people;
disclosure of personal data—actions aimed at disclosing personal data to a specific person or a specific group of persons;
blocking of personal data—the temporary suspension of the processing of personal data (except in cases where processing is necessary to verify the accuracy of the personal data);
Destruction of personal data—actions that make it impossible to restore the content of personal data in a personal data information system and/or that result in the destruction of physical media containing personal data;
de-identification of personal data—actions that make it impossible to determine, without using additional information, that the personal data pertains to a specific data subject;
personal data information system—a collection of personal data contained in databases, along with the information technology and technical resources used to process such data;
Cross-border transfer of personal data—the transfer of personal data to the territory of a foreign country to a government authority of that foreign country, a foreign individual, or a foreign legal entity.
1.6. The Operator’s Basic Rights and Obligations.
1.6.1. The operator has the right to:
- independently determine the scope and list of measures necessary and sufficient to ensure compliance with the obligations set forth in the Personal Data Law and the regulatory legal acts adopted pursuant to it, unless otherwise provided by the Personal Data Law or other federal laws;
- to entrust the processing of personal data to another party on the basis of a contract entered into with that party, in compliance with the requirements of the Personal Data Act. A person processing personal data on behalf of the Operator is required to comply with the principles and rules of processing, confidentiality, and security requirements for personal data;
- If the data subject withdraws consent to the processing of personal data, the operator has the right to continue processing the personal data without the data subject’s consent if the grounds specified in the Personal Data Act apply.
1.6.2. The operator must:
- organize the processing of personal data in accordance with the requirements of the Personal Data Act;
- respond to communications and requests from data subjects and their legal representatives in accordance with the requirements of the Personal Data Act;
- provide Roskomnadzor with the necessary information within the timeframes established by the Personal Data Law;
1.7. Basic Rights of the Data Subject. The data subject has the right to:
- to receive information regarding the processing of his or her personal data, except as provided for by federal laws. The information shall be provided to the Data Subject by the Controller in an accessible form and shall not contain personal data relating to other Data Subjects, except in cases where there are lawful grounds for the disclosure of such personal data. The list of information and the procedure for obtaining it are established by the Personal Data Law;
- to request that the operator correct, block, or delete their personal data if such data is incomplete, outdated, inaccurate, obtained unlawfully, or not necessary for the stated purpose of processing, as well as to take the measures provided by law to protect their rights;
- require prior consent for the processing of personal data for the purpose of marketing goods, works, and services;
- to file a complaint with Roskomnadzor or through the courts regarding any unlawful actions or omissions by the Operator in the processing of his or her personal data.
1.8. Compliance with the requirements of this Policy is monitored by an authorized representative responsible for organizing the processing of personal data at the Operator.
1.9. Liability for violations of the laws of the Russian Federation regarding the processing and protection of personal data is determined in accordance with the laws of the Russian Federation.
1.10. This Policy applies to all information that the Operator receives about Site visitors, customers, payers, order recipients, and other individuals who interact with the Operator.
1.11. The User’s acknowledgment of this Policy is confirmed by checking the pre-emptively unchecked box—the checkbox—when placing an order or filling out the corresponding form on the Website. Confirmation of having read the Policy does not constitute consent to the processing of personal data. Consent to the processing of personal data, where required by the laws of the Russian Federation, is provided by the User separately.
2. PURPOSES OF COLLECTING PERSONAL DATA
2.1. The processing of personal data is limited to the pursuit of specific, predetermined, and legitimate purposes. The Controller considers respect for human and civil rights and freedoms—including the rights to privacy and personal and family confidentiality—in the processing of personal data to be its primary objective and a prerequisite for conducting its activities. The processing of personal data that is incompatible with the purposes for which it was collected is not permitted.
2.2. Only personal data that is relevant to the purposes of its processing may be processed.
2.3. The Operator processes personal data for the following purposes:
- processing, confirming, and fulfilling orders; entering into and performing retail sales contracts;
- managing payments, tax compliance, shipping, returns of goods and refunds, and handling inquiries and complaints;
- sending service messages, ensuring the operation and security of the Site, and sending promotional messages, provided that separate prior consent has been obtained.
Purpose No. 1: Processing, confirming, and fulfilling orders; communicating with the Buyer and sending service messages
1. Categories and list of personal data being processed
Last name, first name, middle name; phone number; email address; information about the order, payment, and recipient
2. Categories of data subjects whose personal data is processed
Website users, buyers, payers, and recipients of orders
3. Processing and Retention Periods
Until the contract is fulfilled and the statutory document retention periods expire
4. Processing Methods
Automated, non-automated, and hybrid
5. Procedure for the Destruction of Personal Data
Personal data is destroyed in accordance with the procedures and timeframes established by the legislation of the Russian Federation. Once the purpose has been fulfilled or consent has been withdrawn, the data is deleted from information systems and destroyed, and a document confirming the destruction is prepared, unless there are other legal grounds for retaining it.
Objective #2: Entering into and fulfilling a contract; organizing payment, shipping, returns, and customer support
1. Categories and List of Personal Data Processed
Last name, first name, middle name; phone number; email address; shipping address; information about orders, payments, shipping, inquiries, and returns; bank account information for refunds
2. Categories of individuals whose personal data is processed
Customers, payers, order recipients, and individuals who submitted inquiries
3. Processing and Retention Periods
Until obligations are fulfilled, inquiries and disputes are resolved, and thereafter for the retention periods established by law
4. Processing Methods
Automated, non-automated, and hybrid
5. Procedure for the Destruction of Personal Data
Personal data is destroyed in accordance with the procedures and timeframes established by the legislation of the Russian Federation. Once the purpose has been fulfilled or consent has been withdrawn, the data is deleted from information systems and destroyed, and a document confirming the destruction is prepared, unless there are other lawful grounds for retaining it.
Objective No. 3: Sending advertising and promotional messages upon receipt of separate prior consent
1. Categories and List of Personal Data Processed
Name; email address; phone number; messenger ID (if provided); information regarding the granting and revocation of consent to receive advertising
2. Categories of individuals whose personal data is processed
Website users and customers who have provided separate consent
3. Processing and Retention Periods
Until the consent is withdrawn or the purpose of the processing is achieved
4. Processing Methods
Automated and Mixed
5. Procedure for the Destruction of Personal Data
Personal data is destroyed in accordance with the procedures and timeframes established by the laws of the Russian Federation. Once the purpose has been fulfilled or consent has been withdrawn, the data is deleted from information systems and destroyed, and a document confirming the destruction is prepared, unless there are other legal grounds for retaining it.
Purpose No. 4: Ensuring the Website’s operation and security, preventing fraud, and conducting web analytics
1. Categories and list of personal data processed
IP address; cookies; information about the device, browser, and the date and time of the visit; actions taken on the Site; technical logs
2. Categories of individuals whose personal data is processed
Visitors and Users of the Site
3. Processing and Retention Periods
For the period of time necessary for the relevant technical purposes, as specified in the Cookie Policy and settings
4. Processing Methods
Automated
5. Procedure for the Destruction of Personal Data
Personal data is destroyed in accordance with the procedures and timeframes established by the legislation of the Russian Federation. Once the purpose has been fulfilled or consent has been withdrawn, the data is deleted from information systems and destroyed, and a document confirming the destruction is prepared, unless there are other legal grounds for retaining it.
3. LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA
3.1. The legal grounds for the processing of personal data are regulatory legal acts, contracts, and the consent of the data subjects, in accordance with which the Operator processes personal data, including:
- The Constitution of the Russian Federation;
- Civil Code of the Russian Federation;
- Tax Code of the Russian Federation; Law of the Russian Federation No. 2300-1 of February 7, 1992, “On the Protection of Consumer Rights”; Federal Law No. 54-FZ of May 22, 2003, “On the Use of Cash Registers in Transactions in the Russian Federation”;
- Federal Law No. 152-FZ of July 27, 2006, “On Personal Data,” and other regulatory legal acts governing the Operator’s activities.
3.2. The legal grounds for processing personal data also include:
- retail sales contracts and other agreements entered into between the Operator and Users;
- Consent from data subjects, provided separately for the relevant purposes of processing, as well as other grounds provided for by the legislation of the Russian Federation.
4. SCOPE AND CATEGORIES OF PERSONAL DATA PROCESSED, CATEGORIES OF DATA SUBJECTS
4.1. The content and scope of the personal data being processed must correspond to the stated purposes of processing set forth in Section 2 of this Policy. The personal data being processed must not be excessive in relation to the stated purposes of processing.
4.2. The Operator may process the personal data of the following categories of data subjects.
4.2.1. Users and visitors to the Site, customers, payers, recipients of orders, and individuals who contact the Operator:
- last name, first name, middle name—if applicable and provided;
- contact information: email address, phone number; shipping address and recipient information;
- information regarding orders, payments, and delivery; information from inquiries, complaints, and correspondence; banking information required for refunds; technical information, including IP address, device information, browser information, cookies, and actions taken on the Website.
4.3. The Operator does not process special categories of personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, health, or sex life, nor does it process biometric personal data, except in cases expressly provided for by the legislation of the Russian Federation.
4.4. The Website may process technical data about visitors, including IP addresses, browser and device information, cookies, and information about activities on the Website. The terms of use for cookies and web analytics services are governed by this Policy and the cookie notice posted on the Website.
5. PROCEDURES AND CONDITIONS FOR THE PROCESSING OF PERSONAL DATA
5.1. The Operator processes personal data in accordance with the requirements of the laws of the Russian Federation.
5.2. Personal data is processed with the consent of the data subjects to the processing of their personal data, as well as without such consent in cases provided for by the legislation of the Russian Federation.
5.3. The operator processes personal data using both automated and non-automated methods.
5.4. Personal data is processed by the Operator, its employees, and persons who process personal data on behalf of the Operator pursuant to concluded agreements.
5.5. The operator collects personal data:
- directly from data subjects when they use the Site, place and pay for an order, contact customer support, or file a complaint;
- from the payer or the Buyer, who provides information about the recipient of the order, if there is a legal basis for providing such information;
- from banks, payment service providers, delivery services, and other third parties, to the extent necessary to fulfill the contract and comply with the law;
- automatically when using the Site—with respect to technical data, cookies, and event logs.
5.6. Personal data may not be disclosed to third parties or disseminated without the consent of the data subject or another legal basis. Consent to the processing of personal data that the data subject has authorized for dissemination must be obtained separately from other consents.
The Operator has the right to disclose necessary personal data to banks and payment services, the fiscal data operator, delivery services, owners of pickup locations, hosting providers, CRM and service notification providers, as well as other parties acting on behalf of the Operator. Each party receives only the amount of data necessary to perform the relevant function.
5.7. Personal data is transferred to government agencies in the cases and in accordance with the procedures provided for by the laws of the Russian Federation.
5.8. The Operator shall take the necessary legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, alteration, blocking, disclosure, and other unauthorized actions, including:
- identifies threats to the security of personal data during its processing;
- develops documents governing relationships in the field of personal data processing and protection;
- creates the necessary conditions for processing personal data;
- organizes the record-keeping of documents containing personal data;
- organizes the use of information systems that process personal data;
- stores personal data under conditions that ensure its security and prevent unauthorized access to it;
- organizes training for the Operator’s employees who process personal data.
5.9. The Controller shall retain personal data in a form that allows for the identification of the Data Subject for no longer than is necessary for the purposes of the processing, unless a different retention period is established by law, contract, or applicable document retention rules.
5.10. When collecting personal data of citizens of the Russian Federation, including via the Internet, the recording, organization, accumulation, storage, updating, and retrieval of such data shall be carried out using databases located within the territory of the Russian Federation. Cross-border transfers are permitted only after the requirements of Article 12 of the Personal Data Law have been met and must not violate localization requirements.
5.11. To update their personal data, the Data Subject may send a notice to the Operator’s email address: tsuyuperfumes@gmail.com, with the subject line “Update of Personal Data.”
5.12. The duration of personal data processing is determined by the purposes of the processing, the term of the contract, the document retention periods established by law, and the term of the relevant consent. The data subject has the right to withdraw consent or request the cessation of processing by sending a notice to tsuyuperfumes@gmail.com with the subject line “Withdrawal of Consent to the Processing of Personal Data.”
6. UPDATE, CORRECTION, DELETION, AND DESTRUCTION OF PERSONAL DATA; RESPONSES TO DATA SUBJECTS’ REQUESTS FOR ACCESS TO PERSONAL DATA
6.1. Confirmation of the fact that the Operator processes personal data, the legal grounds and purposes of such processing, as well as other information specified in Part 7 of Article 14 of the Personal Data Law shall be provided by the Operator to the Data Subject or the Data Subject’s representative upon request or upon receipt of a request from the Data Subject or the Data Subject’s representative.
The information provided does not include personal data relating to other data subjects, except in cases where there are lawful grounds for disclosing such personal data.
The request must include:
- the number of the primary identification document of the data subject or his or her representative, along with information regarding the date of issuance of said document and the issuing authority;
- information confirming the Data Subject’s relationship with the Controller (contract number, date of execution of the contract, descriptive term, and/or other information), or information otherwise confirming that the Controller has processed personal data;
- Signature of the data subject or his or her representative.
The request may be submitted in the form of an electronic document and signed with an electronic signature in accordance with the laws of the Russian Federation.
If the personal data subject’s request does not contain all the necessary information as required by the Personal Data Act, or if the subject does not have the right to access the requested information, a reasoned denial is sent to the subject.
The data subject’s right to access his or her personal data may be restricted in accordance with Article 14, Part 8 of the Personal Data Law, including if the data subject’s access to his or her personal data infringes upon the rights and legitimate interests of third parties.
6.2. If inaccurate personal data is identified following a request from the data subject or their representative, or at their request or at the request of Roskomnadzor, the Operator shall block the personal data relating to that data subject, from the time of such a request or receipt of the specified request for the duration of the verification, provided that blocking the personal data does not infringe upon the rights and legitimate interests of the data subject or third parties.
If it is confirmed that the personal data is inaccurate, the Operator, based on information provided by the Data Subject or his or her representative, or by Roskomnadzor, or other necessary documents, corrects the personal data within seven business days from the date such information is provided and lifts the restriction on the personal data.
6.3. If unlawful processing of personal data is identified following a request (request) from a data subject or their representative, or from Roskomnadzor, the Operator shall block the unlawfully processed personal data pertaining to that data subject effective from the time of such contact or receipt of the request.
6.4. Once the purposes of processing personal data have been achieved, or if the data subject revokes their consent to the processing of their personal data, the personal data shall be destroyed if:
- unless otherwise provided in a contract to which the Data Subject is a party, a beneficiary, or a guarantor;
- The controller may not process personal data without the consent of the data subject, except on the grounds provided for by the Personal Data Act or other federal laws;
- unless otherwise provided for in another agreement between the Operator and the Data Subject.
PERSONAL DATA CONTROLLER’S CONTACT INFORMATION
Sole Proprietor Ksenia Stanislavovna Yao
INN 519017997774
OGRNIP 324237500380660
Email: tsuyuperfumes@gmail.com