Personal Data Processing and Protection Policy
Nobla IT Consulting LLC
1. General Provisions

1.1. This Personal Data Processing Policy (the “Policy”) has been prepared in accordance with Federal Law No. 152-FZ of July 27, 2006, “On Personal Data” (the “Personal Data Law”), taking into account the amendments introduced in 2024–2025. It sets out the procedures for processing personal data and the measures taken by Nobla IT Consulting LLC (the “Operator”) to ensure its security.
1.2. The Operator considers respect for human and civil rights and freedoms when processing personal data, including the rights to privacy and personal and family confidentiality, to be a fundamental objective and a prerequisite for its activities.
1.3. This Policy applies to all information the Operator may obtain about visitors to nobla.ru, as well as data subjects whose personal data the Operator processes in the course of its activities.
1.4. Personal data of citizens of the Russian Federation, including its collection, recording, organization, accumulation, storage, clarification (updating or amendment), and retrieval, is processed using databases located in the Russian Federation (the data localization requirement under Article 18(5) of the Personal Data Law).
1.5. Operator Details:
  • Full legal name: Nobla IT Consulting Limited Liability Company;
  • Primary State Registration Number (OGRN): 1247700419658;
  • Taxpayer Identification Number (INN): 9709111934;
  • Address: Premises 1/3, 62 Nikoloyamskaya Street, Moscow, 109004, Russia;
  • Email: info@nobla.ru
2. Key Terms Used in This Policy

2.1. Automated processing of personal data: processing personal data using computer technology.
2.2. Blocking of personal data: temporarily suspending the processing of personal data, except where processing is necessary to clarify that data.
2.3. Website: the collection of graphic and informational materials, computer programs, and databases that make those materials available online at nobla.ru.
2.4. Personal data information system: the personal data contained in databases, together with the information technologies and technical resources used to process it.
2.5. Depersonalization of personal data: actions that make it impossible, without additional information, to establish that personal data relates to a particular User or other data subject.
2.6. Processing of personal data: any action or set of actions performed on personal data, with or without automated means, including collection, recording, organization, accumulation, storage, clarification (updating or amendment), retrieval, use, transfer (dissemination, disclosure, or access), depersonalization, blocking, deletion, and destruction.
2.7. Operator: a state authority, municipal authority, legal entity, or individual that, alone or jointly with others, organizes and/or carries out the processing of personal data and determines the purposes of processing, the personal data to be processed, and the actions to be performed on that data.
2.8. Personal data: any information relating directly or indirectly to an identified or identifiable User of nobla.ru or another data subject.
2.9. Personal data authorized by the data subject for dissemination: personal data made accessible to an unlimited number of persons by the data subject through consent to the processing of personal data authorized for dissemination, in accordance with the procedure established by the Personal Data Law.
2.10. User: any visitor to nobla.ru.
2.11. Disclosure of personal data: actions intended to disclose personal data to a specific person or a defined group of persons.
2.12. Dissemination of personal data: any actions intended to disclose personal data to an undefined group of persons (transfer of personal data) or to make personal data available to an unlimited number of persons, including publication in the media, posting on information and telecommunications networks, or providing access by any other means.
2.13. Cross-border transfer of personal data: transferring personal data to the territory of a foreign state, to a foreign state authority, foreign individual, or foreign legal entity.
2.14. Destruction of personal data: any actions that irreversibly destroy personal data, making it impossible to restore its content in a personal data information system, and/or destroy the physical media containing personal data.
3. Principal Rights and Obligations of the Operator

3.1. The Operator has the right to:
  • obtain accurate information and/or documents containing personal data from the data subject;
  • continue processing personal data without the data subject’s consent following withdrawal of consent or a request to stop processing, where grounds for doing so exist under the Personal Data Law;
  • independently determine the measures necessary and sufficient to fulfill its obligations under the Personal Data Law and the regulations adopted pursuant to it, unless otherwise provided by the Personal Data Law or other federal laws.
3.2. The Operator must:
  • notify the authority responsible for protecting data subjects’ rights (Roskomnadzor) of its intention to process personal data before processing begins, except in the circumstances specified in Article 22(2) of the Personal Data Law;
  • provide data subjects, at their request, with information about the processing of their personal data;
  • organize the processing of personal data in accordance with applicable Russian law;
  • respond to inquiries and requests from data subjects and their legal representatives in accordance with the Personal Data Law;
  • provide the authority responsible for protecting data subjects’ rights with the information it requests within 10 working days of receiving the request;
  • if an unlawful or accidental transfer of personal data (disclosure, dissemination, or access) is discovered that has infringed data subjects’ rights, notify Roskomnadzor of the incident within 24 hours and of the results of the internal investigation within 72 hours;
  • publish this Personal Data Processing Policy or otherwise make it freely accessible;
  • take legal, organizational, and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, disclosure, dissemination, and other unlawful actions;
  • stop transferring personal data (dissemination, disclosure, or access), stop processing it, and destroy it in the manner and circumstances prescribed by the Personal Data Law;
  • fulfill all other obligations under the Personal Data Law.
4. Principal Rights and Obligations of Data Subjects

4.1. Data subjects have the right to:
  • obtain information about the processing of their personal data, except in circumstances specified by federal law. The Operator must provide this information in an accessible form. It must not contain personal data relating to other data subjects unless there are lawful grounds for disclosing that data;
  • require the Operator to clarify, block, or destroy their personal data if it is incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary for the stated purpose of processing, and take measures provided by law to protect their rights;
  • require prior consent as a condition for processing their personal data to promote goods, works, or services;
  • withdraw consent to the processing of their personal data and request that processing be stopped;
  • challenge the Operator’s unlawful acts or omissions in processing their personal data before the authority responsible for protecting data subjects’ rights or in court;
  • exercise other rights provided by Russian law.
4.2. Data subjects must:
  • provide the Operator with accurate information about themselves;
  • notify the Operator of any clarification, update, or change to their personal data.
4.3. Persons who provide the Operator with inaccurate information about themselves or information about another data subject without that person’s consent are liable under Russian law.
5. Principles of Personal Data Processing

5.1. Personal data is processed lawfully and fairly.
5.2. Processing is limited to specific, predetermined, and lawful purposes. Processing that is incompatible with the purposes for which personal data was collected is not permitted.
5.3. Databases containing personal data processed for mutually incompatible purposes must not be combined.
5.4. Only personal data relevant to the purposes of processing may be processed.
5.5. The content and volume of personal data processed must correspond to the stated purposes of processing. Personal data must not be excessive in relation to those purposes.
5.6. Personal data must be accurate, sufficient, and, where necessary, up to date in relation to the purposes of processing. The Operator takes, and/or ensures that others take, the measures necessary to delete or clarify incomplete or inaccurate data.
5.7. Personal data is retained in a form that allows the data subject to be identified for no longer than is necessary for the purposes of processing, unless a retention period is prescribed by federal law or by a contract to which the data subject is a party, beneficiary, or guarantor. Personal data must be destroyed or depersonalized once the purposes of processing have been achieved or are no longer required, unless otherwise provided by federal law.
6. Purposes of Personal Data Processing

6.1. The Operator processes personal data for the following purposes:
Purpose of Processing
Providing the User with access to services, information, and/or materials on the Website; handling requests for information and commercial proposals; communicating with the User.
Personal Data
— Last name, first name, and patronymic;
— Email address;
— Telephone numbers.
Legal Grounds
— Federal Law No. 149-FZ of July 27, 2006, “On Information, Information Technologies and Information Protection”;
— Federal Law No. 152-FZ of July 27, 2006, “On Personal Data”;
— The data subject’s consent to the processing of their personal data.
Types of Processing
Collection, recording, organization, accumulation, storage, clarification (updating or amendment), retrieval, use, transfer (disclosure or access), blocking, deletion, destruction, and depersonalization of personal data.
6.2. Consent to personal data processing is recorded in a separate document or form, rather than incorporated into this Policy, a user agreement, or another document, and contains all information required by Article 9(4) of the Personal Data Law. Consent must be specific, purpose-specific, informed, conscious, and unambiguous, and must be given separately for each processing purpose.
7. Conditions for Personal Data Processing

7.1. Personal data is processed with the data subject’s consent.
7.2. Processing is necessary to achieve purposes established by an international treaty of the Russian Federation or by law, and to perform the functions, powers, and obligations assigned to the Operator by Russian law.
7.3. Processing is necessary for the administration of justice or the enforcement of a judicial act or an act of another authority or official that is enforceable under Russian enforcement proceedings law.
7.4. Processing is necessary to perform a contract to which the data subject is a party, beneficiary, or guarantor, or to conclude a contract at the data subject’s initiative or under which the data subject will be a beneficiary or guarantor.
7.5. Processing is necessary to exercise the rights and legitimate interests of the Operator or third parties, or to achieve socially significant purposes, provided that the data subject’s rights and freedoms are not infringed.
7.6. Processing concerns personal data made accessible to an unlimited number of persons by the data subject or at their request (publicly available personal data).
7.7. Processing concerns personal data subject to publication or mandatory disclosure under federal law.
8. Procedures for Collecting, Storing, Transferring, and Otherwise Processing Personal Data

The security of personal data processed by the Operator is ensured through the legal, organizational, and technical measures necessary to comply fully with applicable personal data protection law.
8.1. The Operator safeguards personal data and takes all possible measures to prevent unauthorized persons from accessing it.
8.2. The User’s personal data will never, under any circumstances, be transferred to third parties, except where required to comply with applicable law or where the data subject has consented to the Operator transferring the data to a third party to fulfill obligations under a civil-law contract.
8.3. If the User identifies inaccuracies in their personal data, they may update it by emailing the Operator at info@nobla.ru with the subject line “Personal Data Update”.
8.4. Personal data is processed until the purposes for which it was collected have been achieved, unless a different period is specified by contract or applicable law. The User may withdraw consent at any time by emailing the Operator at info@nobla.ru with the subject line “Withdrawal of Consent to Personal Data Processing”.
8.5. All information collected by third-party services, including payment systems, communications services, and other service providers, is stored and processed by those parties (operators) in accordance with their user agreements and privacy policies. The Operator is not responsible for the actions of third parties, including the service providers referred to in this clause.
8.6. Restrictions imposed by a data subject on the transfer (other than granting access), processing, or conditions of processing (other than obtaining access) of personal data authorized for dissemination do not apply where the data is processed in state, societal, or other public interests defined by Russian law.
8.7. The Operator maintains the confidentiality of personal data during processing.
8.8. The Operator retains personal data in a form that allows the data subject to be identified for no longer than is necessary for the purposes of processing, unless a retention period is prescribed by federal law or by a contract to which the data subject is a party, beneficiary, or guarantor.
8.9. Processing may cease when its purposes have been achieved, the data subject’s consent has expired or been withdrawn, a request to stop processing has been received, or unlawful processing has been identified.
9. Actions Performed by the Operator on Personal Data Received

9.1. The Operator collects, records, organizes, accumulates, stores, clarifies (updates or amends), retrieves, uses, transfers (disseminates, discloses, or provides access to), depersonalizes, blocks, deletes, and destroys personal data.
9.2. The Operator processes personal data by automated means, with or without receiving and/or transmitting the information through information and telecommunications networks.
10. Cross-Border Transfers of Personal Data

10.1. The Operator does not transfer personal data across borders. Personal data of citizens of the Russian Federation is processed and stored using databases located in the Russian Federation.
10.2. If the Operator decides to transfer personal data across borders, it must notify the authority responsible for protecting data subjects’ rights before the transfer begins, separately from its notification of the intention to process personal data. It must comply with the conditions and time limits established by Article 12 of the Personal Data Law, including a period of at least 10 working days before transferring data to states that do not provide adequate protection of data subjects’ rights.
11. Confidentiality of Personal Data

The Operator and other persons who have obtained access to personal data must not disclose it to third parties or disseminate it without the data subject’s consent, unless otherwise provided by federal law.
12. Liability

12.1. Persons responsible for breaches of the Personal Data Law are subject to civil, administrative, and criminal liability under Russian law, including liability under Article 13.11 of the Code of Administrative Offences of the Russian Federation.
12.2. The Operator takes the measures necessary and sufficient to fulfill its obligations under the Personal Data Law, including appointing a person responsible for organizing personal data processing, issuing internal regulations on personal data processing, and implementing legal, organizational, and technical measures to ensure personal data security.
13. Final Provisions

13.1. The User may obtain clarification on any matter relating to the processing of their personal data by emailing the Operator at info@nobla.ru.
13.2. Any changes to the Operator’s personal data processing policy will be reflected in this document. The Policy remains in force indefinitely until replaced by a new version.
13.3. The current version of the Policy is freely available online at nobla.ru/privacy-policy.
Helping map out the tech roadmap to reach your business goals
OGRN 1247700419658
INN 9709111934