Privacy and Personal Data Processing Policy of the www.loyalclub.ru Service
Effective Date: June 1, 2025
Last Updated: November 10, 2025
1. General Provisions
1.1. This Privacy and Personal Data Processing Policy (the “Policy”) has been developed in accordance with the requirements of Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data” (the “Personal Data Law”) and defines the procedure for personal data processing and the measures to ensure personal data security undertaken by Limited Liability Company “LOYAL CLUB” (LOYAL CLUB LLC), TIN 9715518580, PSRN 1257700492389, address: 127495, Moscow, intracity territory, Municipal District Severny, Dmitrovskoe Highway, 165E, building 7, premises 22/1 (the “Operator”).
1.2. This Policy applies to all information that the Operator may obtain about the Service User while the User is using the website located at www.loyalclub.ru (the “Service”).
1.3. Use of the Service, including registration, means the Service User’s unconditional consent to this Policy and to the terms of processing of their personal data and data contained in documents uploaded by them. If the Service User disagrees with these terms, they must refrain from using the Service.
1.4. Key terms used in this Policy:
Service — a software and hardware system available on the Internet at www.loyalclub.ru, created by LOYAL CLUB LLC, constituting its intellectual property, intended for personal communication between the Customer and the Customer’s Clients, and provided by the Operator.
Operator — LOYAL CLUB LLC. With respect to Service User Data, the Operator acts as the personal data operator.
Service User — an individual (acting on their own behalf or as a representative of a legal entity/individual entrepreneur) registered with and using the Service at www.loyalclub.ru.
Customer — a person who has entered into an agreement with LOYAL CLUB LLC that предусматривает transfer of personal data by the Customer to LOYAL CLUB LLC and processing of such personal data by LOYAL CLUB LLC.
Customer’s Client — an individual who is a potential, current, or former client of the Customer, or another individual whose personal data is processed by the Customer on a lawful basis.
Service User Data — personal data directly related to the Service User (email address, and optionally full name).
Customer / Customer’s Client Data — any information (including personal data) transferred to LOYAL CLUB LLC for processing.
Personal data processing — any action (operation) or set of actions (operations) performed with personal data, with or without automation tools.
Confidentiality of personal data — a mandatory requirement for the Operator or any person who has gained access to personal data not to disclose such data without the consent of the personal data subject or another lawful basis.
Cross-border data transfer — transfer of personal data to the territory of a foreign state, to a foreign public authority, foreign individual, or foreign legal entity.
2. Personal Data Processed by the Operator
2.1. Service User Data
The Operator processes the following personal data of the Service User:
Email address (mandatory for registration and use of the Service);
Last name, first name, patronymic (provided at the User’s discretion; not mandatory).
The Operator does not collect or store Service Users’ IP addresses or other automatically collected data (except technically necessary cookies; see Section 7).
Data is provided by the Service User independently during registration or in profile settings.
2.2. Customer Data
Within this category, LOYAL CLUB LLC processes personal data obtained in connection with entering into an agreement to which the personal data subject is a party, and used by LOYAL CLUB LLC solely for performance of that agreement and conclusion of agreements with the personal data subject, including: last name, first name, patronymic; gender; citizenship; date (day, month, year) and place of birth (country, republic, region, area, district, city, township, village, other locality); residential address (postal code, country, republic, region, area, district, city, township, village, other locality, street, building, block, apartment); registration-at-residence or stay details (postal code, country, republic, region, area, district, city, township, village, other locality, street, building, block, apartment); phone numbers (home, mobile, work), email address; position held; taxpayer identification number (date and place of tax registration, date of certificate issuance); passport data or data of another identity document; information on participation in management of a business entity (except housing, housing construction, garage cooperatives, gardening/horticultural/dacha consumer cooperatives, homeowners’ associations and duly registered trade unions), engagement in entrepreneurial activity; current account number.
2.3. Customer’s Client Data
LOYAL CLUB LLC is entitled to process personal data of the Customer’s Clients provided by the Customer on the Customer’s instructions, such as: last name, first name, patronymic; gender; email; phone number; date of birth; IP addresses; data about the device used to view the website or mobile application; other data provided by the Customer (excluding special categories and biometric personal data). Personal data category: other.
3. Purposes of Personal Data Processing
3.1. Personal data processing is limited to achieving specific, predetermined, and lawful purposes. Processing incompatible with the purposes of data collection is not permitted.
3.2. Processing purposes derive, among other things, from the actual activities of LOYAL CLUB LLC, activities provided by its constituent documents, and specific business processes within specific personal data information systems.
3.3. LOYAL CLUB LLC does not itself collect personal data of Customers’ Clients and is not required to obtain consent for processing such data under agreements concluded with Customers.
3.4. Processing of Customers’ Clients’ personal data is carried out on the Customer’s instructions. Processing purposes are defined by agreements concluded with Customers. In particular, such purposes include provision of services under the agreement: marketing campaigns, including electronic mailings, creation of Customer Client data segments, and Customer Client data analysis. Processing purposes may not contradict the laws of the Russian Federation.
3.5. Processing of personal data of the Customer’s representatives is carried out for the purpose of concluding and performing agreements, including provision of services by LOYAL CLUB LLC to the Customer.
3.6. Processing of Service Users’ personal data may be carried out for the following purposes: website optimization; addressing advertising and informational materials to existing and potential clients; assessing effectiveness of published advertising materials and adapting them for users; internal technical work as part of platform administration, data analysis, tests, research, surveys, improvement and optimization of the website, including adaptation of website content display to users’ devices.
3.7. LOYAL CLUB LLC may process personal data for statistical or other research purposes provided that personal data is mandatorily anonymized.
3.8. LOYAL CLUB LLC does not process personal data that is not required to achieve the purposes specified in this Policy and does not use personal data for any purposes other than those stated above.
4. Legal Grounds for Personal Data Processing
4.1. Legal grounds for personal data processing are: the Constitution of the Russian Federation; constituent documents of LOYAL CLUB LLC; agreements concluded in the course of LOYAL CLUB LLC activities; consent to personal data processing (in cases not directly provided by Russian law but corresponding to the operator’s powers).
4.2. LOYAL CLUB LLC processes Service Users’ personal data based on the data subject’s consent granted when filling in forms on the website.
4.3. LOYAL CLUB LLC processes Customer personal data based on the data subject’s consent granted when filling in forms on the website, as well as performance of an agreement (User Agreement/Offer) to which the Customer is a party. In accordance with Russian law, LOYAL CLUB LLC does not use personal data to the detriment of data subjects.
4.4. LOYAL CLUB LLC processes Customers’ Clients’ personal data based on agreements concluded with Customers.
4.5. LOYAL CLUB LLC takes all necessary measures to comply with legal requirements and does not process personal data in cases where this is not permitted.
5. Procedure and Conditions of Personal Data Processing
5.1. Processing of Service User/Customer Data is carried out in automated form (for Service operation) and non-automated form (when handling requests).
5.2. Service User/Customer Data storage (email, and optionally full name) continues until account deletion by the User, automatically within 30 days after subscription termination, or upon request sent to support@loyalclub.ru, unless otherwise required by law.
5.3. LOYAL CLUB LLC processes personal data in accordance with the following principles:
legality and fair basis for personal data processing;
limitation of personal data processing to specific, predetermined, and lawful purposes;
correspondence of the content and scope of processed personal data to the declared processing purposes;
prevention of merging databases containing personal data processed for purposes incompatible with one another;
ensuring accuracy, sufficiency, and relevance of personal data in relation to processing purposes;
storage of personal data in a form allowing identification of the personal data subject no longer than required by processing purposes, unless a storage period is established by federal law or an agreement to which the personal data subject is a party or beneficiary;
destruction, or ensuring destruction, of personal data upon achievement of declared processing purposes or when such purposes are no longer needed, where LOYAL CLUB LLC cannot eliminate violations of the legally established processing procedure, when consent is withdrawn by the personal data subject, unless otherwise provided by law.
5.4. LOYAL CLUB LLC does not disclose to third parties or distribute personal data without the data subject’s consent, unless otherwise provided by law.
5.5. LOYAL CLUB LLC performs the following actions with personal data:
with respect to Customers’ Clients’ personal data: recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (granting access), blocking, deletion, destruction.
5.6. LOYAL CLUB LLC ensures confidentiality of personal data it processes. Confidentiality is not required for:
personal data after anonymization;
personal data permitted by the data subject for distribution;
personal data subject to publication or mandatory disclosure under federal laws.
5.7. Protection of personal data processed by LOYAL CLUB LLC is ensured through legal, organizational, and technical measures necessary and sufficient to comply with personal data protection legislation.
5.8. Legal measures include: development of LOYAL CLUB LLC local regulations implementing Russian legal requirements, including this Policy, and publication of this Policy on LOYAL CLUB LLC’s website; refusal to process personal data if such processing does not correspond to LOYAL CLUB LLC processing purposes.
5.9. Organizational measures include: appointment of a person responsible for organization of personal data processing and personal data security in information systems; regulation of personal data processing processes; identification of personal data security threats in information systems and development of threat models; limitation and differentiation of employee and other persons’ access to personal data and processing tools, monitoring actions involving personal data; familiarization of employees directly processing personal data with Russian personal data legislation and/or training of such employees.
5.10. Technical measures include:
ensuring physical security of premises and personal data processing tools, access control, security, and video surveillance;
based on threat models, development of a personal data protection system for levels of protection established by the Government of the Russian Federation when processing personal data in information systems;
use of security tools (antivirus software, firewalls, unauthorized access protection tools, and others as required by law and LOYAL CLUB LLC acts), including those that have passed conformity assessment procedures in the prescribed manner; backup of information to enable recovery;
accounting for and storage of information media to prevent theft, substitution, unauthorized copying, and destruction;
periodic monitoring of user actions and incident investigations in case of violations of personal data processing and protection rules;
use of encryption during transactions;
use of computer systems with restricted access;
storage of data in encrypted form, including when using third-party storage;
compliance control (independently or with contractual involvement of other persons licensed to perform technical protection of confidential information activities) at least once every 3 years.
5.11. Conditions for termination of personal data processing: achievement of processing purposes, termination of contractual relations with the Customer, expiration or withdrawal of consent, detection of unlawful personal data processing.
5.12. Payment processing: When paying for Service services, the User is redirected to the payment system page of “YooKassa” (YooMoney NKO LLC). The Operator does not collect, store, or process bank card data or other payment details of the Service User; such data is processed exclusively by the payment partner in accordance with its privacy policy.
6. Rights of Personal Data Subjects
6.1. Service User / Customer has the right to:
receive information regarding processing of their personal data;
request clarification, blocking, or destruction of their personal data (for example, by editing profile data or requesting account deletion);
withdraw consent to processing of their personal data by deleting their account or sending a request to the Operator;
exercise other rights provided by the Personal Data Law.
To exercise these rights, the Service User may contact the Operator using the contact details specified in Section 9 of this Policy.
6.2. Customer’s Client:
Since the Operator processes Customer’s Client Data temporarily, on the Customer’s instructions, and does not store such data, the Customer’s Client should contact the Customer directly to exercise their rights (access, clarification, deletion, withdrawal of consent to processing and cross-border transfer, etc.).
The Operator will provide necessary assistance to the Customer’s Client in fulfilling Customer Client requests within its technical capabilities and obligations as a processor.
7. Use of Cookies
7.1. The Service uses technically necessary cookies to ensure operation (for example, for Service User authentication and session persistence).
7.2. The Service may use analytical cookies (for example, Yandex.Metrica, Google Analytics) in anonymized form to improve Service performance.
7.3. The Service User may manage cookie settings in their browser. Disabling technically necessary cookies may make use of the Service impossible.
8. Liability
8.1. The Operator is liable for proper processing of Service User / Customer / Customer’s Client Data in accordance with Russian law.
8.2. The Operator is not liable for actions of the Service User / Customer / Customer’s Client, including:
lawfulness of obtaining the data they provide;
content and accuracy of the data provided.
9. Final Provisions
9.1. This Policy is a publicly available document and is permanently available at: www.loyalclub.ru.
9.2. This Policy also applies to personal data obtained by the Operator before this Policy came into force but processed after it came into force.
9.3. The Operator may amend this Policy. A new version of the Policy comes into force from the moment it is published at the address specified in Clause 9.1, unless otherwise provided by the new version of the Policy. Service Users are informed of changes by publication of the new version on the Website. Users are advised to regularly review the current version of the Policy.
9.4. All questions related to personal data processing by the Operator may be sent to:
127495, Moscow, intracity territory, Municipal District Severny, Dmitrovskoe Highway, 165E, building 7, premises 22/1,
LOYAL CLUB LLC,
or by email: support@loyalclub.ru.