Privacy and personal data processing policy of the Speech service

This is a translation for convenience. The Russian original is the legally binding version; in case of any discrepancy the Russian text prevails.

20 March 2026

1. General provisions

1.1. This Personal Data Processing Policy (hereinafter — the “Policy”) describes the personal data processing activities and the applicable personal data protection requirements of Individual entrepreneur Aleksandr Nikolaevich Zhirnov, INN 614210823699, OGRNIP 323619600053708, who acts as an independent personal data operator (hereinafter — the “Operator”).

1.2. The Policy has been developed to meet the requirements of the personal data legislation of the Russian Federation and is aimed at protecting human and civil rights and freedoms when the Operator organises and/or carries out the processing of personal data, including the right to privacy and to personal and family confidentiality.

1.3. The Policy has been developed in accordance with the Constitution of the Russian Federation and Federal Law No. 152-FZ “On Personal Data” of 27 July 2006.

1.4. The Policy uses the following key terms:

Automated processing of personal data — the processing of personal data by means of computing equipment;

Blocking of personal data — the temporary suspension of the processing of personal data (except where processing is necessary to update the personal data);

Personal data information system — a set of personal data contained in databases together with the information technologies and technical means that process it;

Processing of personal data — any action (operation) or set of actions (operations) performed on personal data with or without the use of automation, including collection, recording, systematisation, accumulation, storage, updating (renewal, modification), retrieval, use, transfer (distribution, provision, access), depersonalisation, blocking, deletion and destruction of personal data;

Operator — in this Policy, individual entrepreneur Aleksandr Nikolaevich Zhirnov, INN 614210823699, OGRNIP 323619600053708; a state body, municipal body, legal entity or individual that alone or jointly with others organises and/or carries out the processing of personal data and determines the purposes of processing, the composition of the personal data to be processed and the actions (operations) performed on it;

Website — a set of interlinked web pages published on the internet at the unique address (URL) https://speech.systems/, including subdomains, through which a Visitor can access the features of the Operator’s website and the Speech software (service);

Speech software (service) (hereinafter — the Service) — a service providing an interface for transcribing and summarising meetings, calls and recordings (audio and video);

Visitor — any individual who visits or uses the Operator’s Website over the internet;

Personal data — any information relating directly or indirectly to an identified or identifiable individual (hereinafter — the “data subject”, the “Subject”), including information obtained while using the Operator’s Website and Service at https://speech.systems/;

Provision of personal data — actions aimed at disclosing personal data to a particular person or to a particular group of people;

Distribution of personal data — actions aimed at disclosing personal data to an indefinite group of people (transfer of personal data) or at making personal data available to an unlimited number of people, including publishing personal data in the media, placing it in information and telecommunication networks or granting access to it in any other way;

Cross-border transfer of personal data — the transfer of personal data to the territory of a foreign state, to a foreign public authority, or to a foreign individual or legal entity;

Destruction of personal data — any actions as a result of which personal data is irretrievably destroyed, with no possibility of subsequently recovering its content in the personal data information system, and/or the physical media holding the personal data is destroyed.

1.5. In its activity the Operator follows the personal data processing principles set out in article 5 of Federal Law No. 152-FZ “On Personal Data” of 27 July 2006.

2. Purposes and conditions of personal data processing

2.1. The processing of personal data is limited to achieving specific, predefined and lawful purposes. Processing of personal data that is incompatible with the purposes of its collection is not permitted.

2.2. The Operator processes personal data for the following purposes:

Purpose No. 1: Analytics of activity on the Operator’s website and service, and keeping the Operator’s website and service running
Categories of personal dataOther (general) personal data
List of personal data processed- usage data (location information; OS type and version; browser type and version; provider; the source the Visitor/User came from; user session duration; entry points (third-party websites from which the Visitor/User follows a link to the Operator’s Website); - OS and browser language; - IP address; - cookies.
Categories of data subjects whose personal data is processed- Visitors; - Users.
Personal data processing period- until the purpose of processing the personal data is achieved; - until the data subject withdraws consent; - until the date the Operator ceases its business activity.
Personal data retention periodNo more than 3 years from the Visitor’s/User’s last visit to the Operator’s website or service
Methods of processing and storing personal dataAutomated
List of operations performed on personal dataCollection, recording, systematisation, accumulation, storage, updating (renewal, modification), retrieval, use, blocking, deletion and destruction of personal data.
Procedure for destroying personal data once the purposes of processing are achieved or other lawful grounds arisePersonal data is destroyed by deletion from the Operator’s database. The destruction of personal data is documented by drawing up a corresponding certificate of destruction of personal data together with an export from the event log of the personal data information system (where the personal data was entered into the information system), or by taking screenshots of the successive steps of destroying the personal data. Once the certificate is approved, the personal data is irretrievably deleted from the Operator’s database.
Purpose No. 2: Registration on the service, creating and filling in a profile, including payment where the service is used for a fee (conclusion and performance of the agreement)
Categories of personal dataOther (general) personal data
List of personal data processed- last name, first name; - email address; - phone number; - photograph; - gender (when Yandex is used at registration); - Yandex login (when Yandex is used at registration); - bank card details.
Categories of data subjects whose personal data is processed- Visitors; - Users; - Beneficiaries under agreements.
Personal data processing period- until the agreement expires; - until the data subject withdraws consent; - until the purpose of processing the personal data is achieved; - until the date the Operator ceases its business activity.
Personal data retention periodNo more than 3 years from the last visit to the Operator’s website or service
Methods of processing and storing personal dataAutomated
List of operations performed on personal dataCollection, recording, systematisation, accumulation, storage, updating (renewal, modification), retrieval, use, transfer (provision, access), blocking, deletion and destruction of personal data
Procedure for destroying personal data once the purposes of processing are achieved or other lawful grounds arisePersonal data is destroyed by deletion from the Operator’s database. The destruction of personal data is documented by drawing up a corresponding certificate of destruction of personal data together with an export from the event log of the personal data information system (where the personal data was entered into the information system), or by taking screenshots of the successive steps of destroying the personal data. Once the certificate is approved, the personal data is irretrievably deleted from the Operator’s database.
Purpose No. 3: Communication, feedback and technical support
Categories of personal dataOther (general) personal data
List of personal data processed- last name, first name; - email address; - phone number.
Categories of data subjects whose personal data is processed- Visitors; - Users; - Beneficiaries under agreements.
Personal data processing period- until the agreement expires; - until the purpose of processing the personal data is achieved; - until the data subject withdraws consent; - until the date the Operator ceases its business activity.
Personal data retention periodNo more than 3 years from the last visit to the Operator’s website or service
Methods of processing and storing personal dataAutomated
List of operations performed on personal dataCollection, recording, systematisation, accumulation, storage, updating (renewal, modification), retrieval, use, blocking, deletion and destruction of personal data.
Procedure for destroying personal data once the purposes of processing are achieved or other lawful grounds arisePersonal data is destroyed by deletion from the Operator’s database. The destruction of personal data is documented by drawing up a corresponding certificate of destruction of personal data together with an export from the event log of the personal data information system (where the personal data was entered into the information system), or by taking screenshots of the successive steps of destroying the personal data. Once the certificate is approved, the personal data is irretrievably deleted from the Operator’s database.
Purpose No. 4: Use of the service’s features
Categories of personal dataOther (general) personal data
List of personal data processed- last name, first name; - email address; - phone number; - photograph; - audio and video recordings.
Categories of data subjects whose personal data is processed- Visitors; - Users; - Beneficiaries under agreements.
Personal data processing period- until the agreement expires; - until the purpose of processing the personal data is achieved; - until the data subject withdraws consent; - until the date the Operator ceases its business activity.
Personal data retention periodNo more than 3 years from the last visit to the Operator’s website or service
Methods of processing and storing personal dataAutomated
List of operations performed on personal dataCollection, recording, systematisation, accumulation, storage, updating (renewal, modification), retrieval, use, blocking, deletion and destruction of personal data.
Procedure for destroying personal data once the purposes of processing are achieved or other lawful grounds arisePersonal data is destroyed by deletion from the Operator’s database. The destruction of personal data is documented by drawing up a corresponding certificate of destruction of personal data together with an export from the event log of the personal data information system (where the personal data was entered into the information system), or by taking screenshots of the successive steps of destroying the personal data. Once the certificate is approved, the personal data is irretrievably deleted from the Operator’s database.

2.3. The Operator processes personal data where at least one of the following conditions is met:

2.3.1. the personal data is processed with the data subject’s consent to the processing of their personal data;

2.3.2. the processing is necessary to achieve purposes provided for by an international treaty of the Russian Federation or by law, or to exercise and perform the functions, powers and duties vested in the operator by the legislation of the Russian Federation;

2.3.3. the processing is carried out in connection with a person’s participation in constitutional, civil, administrative or criminal proceedings, or proceedings in commercial courts, and is necessary to enforce a judicial act or an act of another body or official that is enforceable under the enforcement proceedings legislation of the Russian Federation;

2.3.4. the processing is necessary to perform an agreement to which the data subject is a party, beneficiary or guarantor, or to conclude an agreement at the data subject’s initiative or an agreement under which the data subject will be a beneficiary or guarantor;

2.3.5. the processing concerns personal data subject to publication or mandatory disclosure under federal law.

3. Scope and categories of personal data processed

3.1. Categories of personal data processed by the Operator: other (general).

3.2. The content and scope of the personal data processed by the Operator must correspond to the stated purposes of processing set out in Section 2 of this Policy. The personal data processed must not be excessive in relation to the stated purposes.

3.3. The Operator does not process special categories of personal data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, health, sex life, nor does it process biometric personal data.

4. General procedure for processing and storing personal data

4.1. Personal data is processed with the consent of the data subjects to the processing of their personal data, and without such consent in the cases provided for by the legislation of the Russian Federation.

Exceptions are the cases provided for by the legislation of the Russian Federation. In particular, consent is not required on the following grounds:

• the processing is necessary to achieve purposes provided for by an international treaty of the Russian Federation or by law, or to exercise and perform the functions, powers and duties vested in the operator by the legislation of the Russian Federation (clause 2 of article 6 of Federal Law No. 152-FZ);

• the processing is carried out in connection with a person’s participation in constitutional, civil, administrative or criminal proceedings, or proceedings in commercial courts (clause 3 of article 6 of Federal Law No. 152-FZ);

• the processing is necessary to enforce a judicial act or an act of another body or official that is enforceable under the enforcement proceedings legislation of the Russian Federation (clause 3.1 of article 6 of Federal Law No. 152-FZ);

• the processing is necessary to perform an agreement to which the data subject is a party, beneficiary or guarantor, or to conclude an agreement at the data subject’s initiative or an agreement under which the data subject will be a beneficiary or guarantor. An agreement concluded with a data subject may not contain provisions restricting the data subject’s rights and freedoms, provisions establishing cases of processing minors’ personal data unless otherwise provided by the legislation of the Russian Federation, or provisions allowing the data subject’s inaction to serve as a condition for concluding the agreement (clause 5 of article 6 of Federal Law No. 152-FZ);

• the processing is necessary to protect the life, health or other vital interests of the data subject where obtaining the data subject’s consent is impossible (clause 6 of article 6 of Federal Law No. 152-FZ);

• the processing is necessary to exercise the rights and legitimate interests of the operator or of third parties, including in the cases provided for by the Federal Law “On Protecting the Rights and Legitimate Interests of Individuals in Debt Collection Activities and on Amendments to the Federal Law ‘On Microfinance Activity and Microfinance Organisations’”, or to achieve socially significant purposes, provided that this does not infringe the data subject’s rights and freedoms (clause 7 of article 6 of Federal Law No. 152-FZ);

• the processing concerns personal data subject to publication or mandatory disclosure under federal law (clause 11 of article 6 of Federal Law No. 152-FZ).

• the processing of personal data that the data subject has permitted to be distributed is carried out subject to the prohibitions and conditions provided for by article 10.1 of Federal Law No. 152-FZ (clause 2 of part 2 of article 10 of Federal Law No. 152-FZ);

• the processing is necessary to protect the life, health or other vital interests of the data subject or of other persons and obtaining the data subject’s consent is impossible (clause 3 of part 2 of article 10 of Federal Law No. 152-FZ);

• in accordance with the legislation of the Russian Federation, to achieve the lawful purposes set out in their constituent documents, provided that the personal data will not be distributed without the written consent of the data subjects (clause 5 of part 2 of article 10 of Federal Law No. 152-FZ);

• the processing is necessary to establish or exercise the rights of the data subject or of third parties, or in connection with the administration of justice (clause 6 of part 2 of article 10 of Federal Law No. 152-FZ);

4.1.1. Consent is given in any form that allows the fact of its receipt to be confirmed. In the cases provided for by the legislation of the Russian Federation, consent is given in writing as a separate document. The data subject provides the Operator with accurate information about themselves. If the subject refuses to provide personal data where such consent is mandatory, the Operator explains to the data subject the legal consequences of refusing consent to processing.

4.1.2. Personal data is provided on the Website; consent to the processing of personal data is given at the moment of registering on the service and pressing the “continue” button. The Consent and the Personal Data Processing Policy are available for review. By continuing to register on the Service, the data subject consents to the processing of personal data in accordance with the terms of the Personal Data Processing Policy published on the Operator’s Website.

  • The Operator processes personal data by automated means, with transfer over the internet.
  • The actions (operations) performed on personal data by the Operator to achieve each of the purposes of processing are set out in clause 2.2 of this Policy.
  • The Operator does not create publicly available sources of personal data (directories, address books and the like).
  • The processing of personal data may end when the purposes of processing are achieved, when the consent expires or the data subject withdraws consent to the processing of their personal data, when the agreement/offer expires, when the Parties have performed their obligations under the agreement/offer, and also when unlawful processing of personal data is discovered.
  • The personal data of subjects is stored by a person authorised by the Operator, in compliance with the personal data protection measures provided for by the regulations of the Russian Federation and for the period set out in clause 2.2 of the Policy.
  • The Operator stores personal data in a form that allows the data subject to be identified for no longer than each purpose of processing set out in clause 2.2 of the Policy requires, unless a different retention period is established by federal law, by an agreement or by this Policy.
  • Only persons authorised to carry out such processing are admitted to the processing of data subjects’ personal data.
  • The periods for processing and storing personal data are set on the basis of the processing conditions determined by Federal Law No. 152-FZ “On Personal Data” of 27 July 2006, the provisions of the agreement to which the data subject is a party, beneficiary or guarantor, and/or the data subject’s consent.
  • Personal data is processed and stored for no longer than the purposes of processing require, unless otherwise established by Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 and by the terms of this Policy.
  • The periods for processing and storing personal data may not exceed the periods set out in clause 2.2 of this Policy. The Operator ensures that the recording, systematisation, accumulation, storage, updating (renewal, modification) and retrieval of the personal data of citizens of the Russian Federation are carried out using databases and online services located within the territory of the Russian Federation.
  • The Operator and other persons who have obtained access to personal data must not disclose it to third parties or distribute it without the data subject’s consent, unless otherwise provided by federal law.
  • Personal data is transferred to bodies of inquiry and investigation, to the Federal Tax Service, the Pension Fund of the Russian Federation, the Social Insurance Fund and other authorised bodies and organisations in accordance with the requirements of the legislation of the Russian Federation.

5. Processing of cookies

5.1. Cookies are small files saved on a device (personal computer, laptop, tablet, mobile phone and the like) when people visit the Operator’s Website, which hosts the documents governing the Operator’s processing of personal data and through which the Operator carries out its activity.

5.2. Purpose of collecting cookies:

  • to improve the operation of the Operator’s website and service;
  • to improve the Operator’s service and provide targeted information about it.

5.3. Depending on the browser and device used, different sets of cookies are used, including:

  • session cookies. These exist only in temporary memory while the Visitor/User is on a page of the Operator’s website. Browsers usually delete session cookies once the Visitor/User closes the website window.
  • persistent cookies. These are stored on the person’s computer and are not deleted when the browser is closed.
  • statistical cookies. This set of cookies serves to improve the website’s functionality and includes information about how the User uses the site.
  • essential cookies. The minimum set of cookies required for the Operator’s Website to work correctly.

5.4. Where cookies are processed, a banner is shown on the first visit to the Operator’s Website warning the Visitor/User that cookies are collected and asking for their consent to the processing of their cookies. By pressing the “agree” button (or a similar button) or by continuing to use the Operator’s Website, the User gives consent to the processing of their cookies and confirms their agreement with the provisions of this Policy.

5.5. A Visitor/User of the Operator’s Website may refuse the use of cookies in their browser settings and in their device settings. In that case the Website will use only those cookies that are strictly necessary for its operation and for the services it offers; however, such refusal may cause the site to work incorrectly.

5.6. The Operator does not collect data in order to build a “profile” of a Website Visitor/User to an extent that could materially affect their rights and freedoms under the legislation of the Russian Federation.

5.7. The Operator does not control and is not responsible for third-party websites that a Visitor/User may reach via links available on the Website, including links in search results.

5.8. The Operator may analyse User preferences and monitor consumer behaviour using third-party analytics services.

6. Processing of personal data using the Yandex.Metrica analytics tool

6.1. The Yandex.Metrica analytics tool means the web analytics system provided by Yandex LLC (hereinafter — the Service Provider), designed to collect, process and analyse statistical information about traffic to an internet resource.

6.2. Yandex.Metrica is used to monitor the effectiveness of the website, analyse user behaviour and subsequently optimise the content.

6.3. The following data is collected using Yandex.Metrica:

  • the device’s IP address (depersonalised, partially masked);
  • browser type, version and language;
  • operating system;
  • data about actions on the site (pages visited, clicks, form completion, time on site);
  • referral source (search engine, advertising, social networks);
  • technical parameters of the device (screen, resolution and so on);
  • cookies (user identifiers and others).

6.4. Purposes of data processing:

  • analysing traffic statistics and improving the quality of the site;
  • adapting content to interests;
  • ensuring the technical stability and security of the site.

6.5. The Operator ensures that the data obtained is stored and processed on servers located within the territory of the Russian Federation, in accordance with the requirements of article 18 of Federal Law No. 152-FZ “On Personal Data” of 27 July 2006.

6.6. A Visitor/User can manage the use of Yandex.Metrica themselves:

  • install a tracker blocker or Yandex’s “Protect” extension;
  • disable cookies in the browser settings;
  • use the “Do Not Track” feature;
  • go to https://yandex.ru/support/metrika/general/opt-out.html to opt out of data collection by Yandex.Metrica.

6.7. The Operator takes all the necessary organisational and technical measures provided for by article 19 of Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 to protect data against unauthorised access, modification, disclosure or destruction.

7. Transfer of personal data to third parties

7.1. Where interaction with third parties is necessary to achieve the purposes of processing personal data, the Operator may transfer personal data to third parties — payment systems.

7.2. The Operator may transfer personal data to third parties subject to the following conditions:

  • the data subject has consented to the transfer and processing of their personal data by third parties in accordance with clause 6.3.2 of this Policy.
  • the third party processes personal data using databases and services located within the territory of the Russian Federation;
  • the third party ensures the confidentiality of personal data when processing and using it, and undertakes not to disclose it to other persons or to distribute the personal data of subjects without their consent;
  • the third party guarantees compliance with the following personal data security measures during processing: the use of information protection tools; the detection and recording of unauthorised access to personal data and the taking of measures to restore personal data; restriction of access to personal data; logging and accounting of operations performed on personal data; monitoring and assessment of the effectiveness of the personal data security measures applied.

7.3. Consent to the transfer and processing of personal data by third parties is given separately from the data subject’s other consents to the processing of their personal data. Consent to the transfer and processing of personal data by third parties is given through the Operator’s website or service.

7.4. The distribution of personal data to an unlimited group of people is permitted only with the separate consent of the data subject. The Operator does not distribute the personal data of data subjects.

8. Updating, correcting, deleting and destroying personal data; responses to subjects’ requests for access to personal data

8.1. A data subject or their representative has the right to obtain information concerning the processing of their personal data.

8.2. Confirmation of the fact that the Operator processes personal data, the legal grounds and purposes of processing, and the other information specified in part 7 of article 14 of Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 are provided by the Operator to the data subject or their representative within 10 (ten) business days of the request being made or received.

That period may be extended, but by no more than 5 (five) business days, if the Operator sends the data subject a reasoned notice stating the reasons for extending the period for providing the requested information.

8.3. A data subject’s request must contain:

  • the number of the principal identity document of the data subject or their representative, together with the date of issue of that document and the issuing authority;
  • information confirming the data subject’s involvement in a relationship with the Operator (agreement number, date of conclusion, a conventional verbal designation and/or other information), or information otherwise confirming that the Operator processes the personal data;
  • the signature of the data subject or their representative.

A request may be sent as an electronic document signed with an electronic signature in accordance with the legislation of the Russian Federation.

Where a request is sent by a representative of the data subject, it must contain the details of the document confirming the representative’s authority, with that document attached.

8.4. If a data subject’s request does not contain all the information required by Federal Law No. 152-FZ “On Personal Data” of 27 July 2006, or if the subject does not have rights of access to the requested information, a reasoned refusal is sent to them.

8.5. The Operator provides information to the data subject or their representative in the same form in which the request was sent, unless the request states otherwise.

8.6. If inaccurate personal data is discovered following a request from the data subject or their representative, or at the request of Roskomnadzor, the Operator blocks the personal data relating to that data subject from the moment of such a request for the period of verification, provided that blocking the personal data does not infringe the rights and legitimate interests of the data subject or of third parties.

8.7. If the inaccuracy of the personal data is confirmed, the Operator, on the basis of the information provided by the data subject or their representative or by Roskomnadzor, or on the basis of other necessary documents, updates the personal data within 7 (seven) business days of that information being provided and lifts the blocking of the personal data.

8.8. If unlawful processing of personal data is discovered following a request from the data subject or their representative or from Roskomnadzor, the Operator blocks the unlawfully processed personal data relating to that data subject from the moment of such a request.

8.9. If it is impossible to make the processing of personal data lawful, the Operator must, within a period not exceeding 10 (ten) business days from the date the unlawful processing was discovered, destroy that personal data or ensure its destruction.

8.10. The Operator must notify the data subject or their representative that the violations have been remedied or that the personal data has been destroyed and, where the request of the data subject or their representative was sent by Roskomnadzor, must also notify that state body.

8.11. Where the Operator, Roskomnadzor or another interested party discovers unlawful or accidental transfer (provision, distribution) of personal data (or access to personal data) that has infringed the rights of data subjects, the Operator:

8.11.1. within 24 hours — notifies Roskomnadzor of the incident, its presumed causes, the presumed harm to the rights of data subjects and the measures taken to remedy the consequences of the incident, and provides details of the person authorised by the Operator to liaise with Roskomnadzor on matters related to the incident;

8.11.2. within 72 hours — notifies Roskomnadzor of the results of the internal investigation of the incident and provides details of the persons whose actions caused it (if any).

8.12. Once the purpose of processing personal data has been achieved, and also where the data subject withdraws consent to processing, the personal data is subject to destruction, unless:

  • otherwise provided by this policy or by an agreement to which the data subject is a party, beneficiary or guarantor;
  • the Operator is entitled to process the data without the data subject’s consent on the grounds provided for by Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 or by other federal laws;
  • otherwise provided by another arrangement between the Operator and the data subject.

8.13. Personal data is destroyed by the Operator alone, in the following order:

  • The Operator identifies, regularly or as needed, the personal data to be destroyed because the purposes of processing have been achieved or the established retention periods have expired. The decision to destroy is taken by the Operator alone;
  • Personal data processed in electronic form is deleted from the Operator’s servers and workstations without the possibility of recovery;
  • The fact, date and composition of the destroyed personal data are recorded in a Certificate of destruction of personal data signed by the Operator. A separate order establishing a commission is not required. Where the Operator has employees, issuing an order establishing a special commission is mandatory, and the destruction of personal data and the drawing up of the Certificate of destruction are carried out by the commission. That order determines whether the personal information is still relevant, whether it needs to be destroyed together with its media, and decides on its destruction. The composition of the commission is approved by an order of the Operator.
  • The documents confirming the destruction of data subjects’ personal data are the Certificate of destruction of personal data and an export from the event log of the personal data information system by exporting a log file (hereinafter — the “Log export”), or screenshots of the successive steps of destroying the personal data.
  • Contents of the documents confirming the destruction of personal data:
  • The Certificate of destruction of personal data must contain:
  • the name and address of the Operator;
  • the full name of the subject and other information relating to the particular individual whose personal data was destroyed;
  • the list of categories of the data subject’s personal data that were destroyed;
  • the names of the information systems/databases from which the personal data was destroyed;
  • the names of the personal data information systems from which the personal data was destroyed (where personal data is processed by automated means);
  • the method of destroying the personal data (for example, “irretrievable deletion of files”, “clearing of databases”);
  • the reason for destroying the personal data (for example, “expiry of the retention period”, “achievement of the purposes of processing”);
  • the date the personal data was destroyed;
  • the Operator’s signature with the full name spelled out. Where there are employees on the staff, the Certificate of destruction is drawn up by a special commission and signed, with full names spelled out, by every person taking part in the commission.
  • The Log export must contain:
  • the full name of the subject or other information relating to the particular individual whose personal data was destroyed;
  • the list of categories of the data subject’s personal data that were destroyed;
  • the name of the personal data information system from which the personal data of the data subject(s) was destroyed;
  • the reason for destroying the personal data;
  • the date the personal data was destroyed.

The Log export is accompanied by an export of the log file.

Where a screenshot is taken, it must show the date and time the data and information were destroyed.

9. Measures to ensure the security of personal data

9.1. The security of the personal data processed by the Operator is ensured by implementing the legal, organisational and technical measures necessary to meet the requirements of federal personal data protection legislation.

9.2. To prevent unauthorised access to personal data, the Operator applies the following organisational and technical measures:

  • the organisation of processing and of personal data security is carried out directly by the Operator, who bears personal responsibility for compliance with personal data legislation. Where the Operator has employees, the organisation of processing and of personal data security is carried out by appointing officials responsible for organising the processing and protection of personal data;
  • limiting the number of persons admitted to the processing of personal data;
  • familiarising data subjects with the requirements of federal legislation and of the Operator’s internal documents on the processing and protection of personal data;
  • organising the accounting, storage and handling of media containing personal data;
  • carrying out internal monitoring and/or audits of the compliance of personal data processing with Federal Law No. 152-FZ of 27 July 2006 and the regulations adopted under it, with personal data protection requirements, with the Operator’s personal data processing policy and with the Operator’s internal regulations;
  • maintaining a security regime in the premises housing the information systems. As part of the Operator’s compliance with Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 and the regulations of the Russian Federation adopted under it, the Operator’s premises housing personal data information systems and in which data subjects’ personal data is processed meet the following requirements:
    • uncontrolled entry into the premises housing personal data information systems and in which data subjects’ personal data is processed is prevented;
    • the possibility of unauthorised persons viewing the personal data being processed is excluded; in particular, the monitors of the computers on which personal data is processed are positioned so as to prevent unauthorised persons from viewing data subjects’ personal data.
  • identifying threats to the security of personal data during processing and building threat models and a set of measures on their basis;
  • using certified anti-virus software;
  • concluding agreements with contractors/partners and third parties engaged by the Operator that set out the terms and procedure for processing the personal data received and for observing the principle of confidentiality;
  • assessing the effectiveness of the measures taken to ensure the security of personal data in personal data information systems. The assessment of the effectiveness of the personal data security measures implemented within the personal data protection system is carried out by the Operator itself or by engaging, under a contract, legal entities and individual entrepreneurs licensed to carry out technical protection of confidential information;
  • detecting instances of unauthorised access to data subjects’ personal data and taking measures to respond to unauthorised access to data subjects’ personal data;
  • assessing the harm that may be caused to data subjects in the event of a breach of Federal Law No. 152-FZ “On Personal Data” of 27 July 2006, and weighing that harm against the measures taken by the Operator to ensure the performance of the duties provided for by that Federal Law;
  • the Operator does not check whether a special personal data processing regime applies to a data subject. If a data subject is a citizen of a European Union country or a citizen of another state temporarily or permanently residing in a European Union country and accesses the Website from Europe, the Operator takes all reasonable measures to comply with those personal data protection requirements. For this purpose the data subject must notify the Operator that a special protection regime applies to their personal data;
  • all notifications, requests and enquiries are made by the data subject to the Operator’s email address: hello@speech.systems.

10. Cross-border transfer of personal data

10.1. The Operator does not carry out cross-border transfers of the personal data of the subjects specified in clause 2.2 of this Policy.

11. Liability for breaching the rules governing the processing of personal data

11.1. Persons responsible for breaching the personal data legislation of the Russian Federation when processing personal data are subject to disciplinary and material liability in the manner established by the Labour Code of the Russian Federation (where applicable) and by other federal laws, and are also subject to administrative, civil or criminal liability in the manner established by federal laws.

11.2. Moral harm caused to a subject as a result of the infringement of their rights, of a breach of the personal data processing rules, or of a failure to meet the personal data protection requirements established by Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 is subject to compensation in accordance with the legislation of the Russian Federation. Compensation for moral harm is made irrespective of compensation for pecuniary harm and for the losses incurred by the subject.

12. Final provisions

12.1. The Operator may amend the Policy without the consent or notification of the data subject. A new version of the Policy takes effect from the moment it is published on the Website and the service, unless the new version of the Policy provides otherwise.

12.2. The Operator’s other rights and obligations in connection with the processing of personal data are determined by the personal data legislation of the Russian Federation.

12.3. This Policy takes effect from the moment it is approved by the Operator and remains in force until a new version is adopted.

12.4. The current Policy is published on the Operator’s Website and service.

12.5. To exercise their rights and legitimate interests, a data subject may contact the Operator by sending a request in person, with a mandatory email sent from the email address previously provided to the Operator, to the Operator’s email address hello@speech.systems.

12.6. Requests sent to the Operator in any other way and/or in any other form and not duplicated to that email address are not recognised as official requests of the data subject.

Individual entrepreneur Aleksandr Nikolaevich Zhirnov

INN: 614210823699

OGRNIP: 323619600053708

Account: 40802810952090409025

Sberbank PJSC, South-Western Bank, Rostov-on-Don

Corr. account: 30101810600000000602

BIC: 046015602

E-mail: hello@speech.systems

Support: support@speech.systems