Online

Personal Data Processing Policy

This document outlines the principles, goals, and conditions for processing users' personal data, as well as the measures taken to protect and ensure their privacy.

1. General Provisions

1.1. This Policy defines the procedure for processing personal data by the operator, as well as information about the implemented requirements for personal data protection.

1.2. The Policy is publicly available and published on the Internet for access by an unlimited number of persons.

1.3. The purpose of this Policy is to ensure the protection of human and civil rights and freedoms when processing personal data, including the protection of the right to privacy, personal and family secrecy.

1.4. The requirements of this Policy are mandatory for review and compliance by all employees of the operator involved in the processing of personal data.

1.5. Clicking the consent confirmation button in the Privacy Policy window or selecting the relevant checkbox constitutes the user’s unconditional agreement with the terms of this Policy.


2. Key Definitions

The following key terms are used in this Policy:

  • personal data — any information relating to a directly or indirectly identified individual (data subject), including identification, financial, payment, accounting and other information;

  • personal data permitted for distribution by the data subject — data to which an unlimited number of persons is granted access by the data subject through consent;

  • operator — a person who independently or jointly with others organizes and/or carries out the processing of personal data;

  • processing of personal data — any action or set of actions performed on personal data, including collection, recording, storage, use, transfer, blocking, deletion, and destruction;

  • automated processing — processing of personal data using computer equipment;

  • distribution, provision, blocking, destruction, anonymization — used in the meanings established by the Federal Law “On Personal Data”;

  • personal data information system — a set of databases and technologies ensuring their processing;

  • cross-border transfer of personal data — transfer of data to the territory of a foreign state;

  • mobile application, personal account, login and password, user, website — used in the meanings defined in this Policy and the operator’s offer.


3. Processing of Personal Data on mint-change.ru/

3.1. The operator processes personal data of users of the mint-change.ru/ website.

3.2. The list of processed personal data includes, but is not limited to:

  • email address;

  • phone number;

  • exchange transaction history;

  • account identifiers;

  • API keys;

  • bank card number;

  • passport data (including photos or scanned copies);

  • verification status information;

  • correspondence with technical support;

  • other data necessary for the functioning of the service.

3.3. Data processing is carried out for the following purposes:

  • creating and maintaining a user account;

  • performing exchange transactions;

  • providing software features of the service;

  • accrual and accounting of cashback;

  • providing technical support and informing users.

3.4. User verification is carried out through third-party services. The operator receives only information about the fact of verification and does not have access to the data transmitted to third parties.

3.5. Biometric personal data is not processed.

3.6. Cross-border transfer of personal data to countries that do not provide adequate protection is not carried out.

3.7. The operator does not process information about users’ place of residence, location, or citizenship.

3.8. Personal data is stored on the territory of the Russian Federation.


4. Website and Mobile Application Identifiers

4.1. Data collection is carried out in two ways:

  • data provided by the user;

  • automatically collected information.

4.2. Data is provided by filling out forms on the website and in the mobile application or by sending emails to the operator.

4.3. Automatically collected information includes:

  • data on the use of website sections;

  • search queries;

  • statistical and analytical information.

4.4. Cookies, web beacons, and other analytics tools are used for automatic data collection.

4.5. Cookies are used for the proper functioning of the website and analysis of user activity. The user has the right to restrict the use of cookies in browser settings.

4.6. Web beacons are used to evaluate the effectiveness of website pages and email messages.


5. Rights and Obligations of the Operator and Data Subjects

5.1. The operator undertakes not to disclose personal data to third parties without the subject’s consent, except in cases provided by law.

5.2. The operator explains to the data subject the legal consequences of refusing to provide personal data if such provision is mandatory.

5.3. The data subject has the rights provided by the Federal Law “On Personal Data,” including the right to protection and to appeal the operator’s actions.

5.4. The operator does not make decisions affecting the subject’s rights solely on the basis of automated processing without legal grounds provided by law.


6. Updating, Correction, Deletion, and Destruction of Personal Data

6.1. The data subject has the right to request clarification, blocking, or destruction of personal data in cases provided by law.

6.2. Upon confirmation of data inaccuracy, the operator updates the data.

6.3. If unlawful processing is identified, the operator terminates data processing.

6.4. Personal data is destroyed upon achievement of processing purposes or upon withdrawal of consent, unless other legal grounds for processing exist.


7. Procedure for Handling Requests from Data Subjects and Authorized Authorities

7.1. The data subject has the right to obtain information provided by the Federal Law “On Personal Data.”

7.2. Requests are considered within up to 10 business days, with a possible extension of no more than 5 business days.

7.3. The operator has the right to refuse to provide information in cases expressly provided for by the legislation of the Russian Federation.

7.4. Information is provided in a form corresponding to the form of the request.


8. Implemented Personal Data Protection Measures

8.1. The operator takes legal, organizational, and technical measures to protect personal data, including:

  • appointment of a responsible person;

  • development of local regulations;

  • use of encryption;

  • access control and activity logging;

  • prevention and elimination of security incident consequences.

8.2. The level of protection is determined taking into account current security threats.

8.3. The operator interacts with state systems for detection and prevention of computer attacks in accordance with established procedures.


9. Final Provisions

9.1. This Policy is a local regulatory act and is publicly available.

9.2. The Policy may be revised in the following cases:

  • changes in legislation;

  • receipt of instructions from authorized authorities;

  • changes in purposes, сроки, or technologies of data processing;

  • reorganization of the operator;

  • other grounds requiring document updates.

9.3. The Policy enters into force from the moment it is published on the mint-change.ru/ website.