Version dated February 10, 2026
1. Terms and accepted abbreviations
1.1 Personal data (PD) – any information relating to a directly or indirectly identified or identifiable individual (PD subject).
1.2 Processing of personal data – any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (update, modification), extraction, use, transfer (distribution, provision, access), anonymization, blocking, deletion, destruction of personal data.
1.3 Automated processing of personal data – processing of personal data using computer technology.
1.4 Personal data information system (PDIS) – a set of personal data contained in databases and information technologies and technical means ensuring their processing.
1.5 Personal data made publicly available by the PD subject – PD to which access by an unlimited circle of persons is provided by the PD subject or at their request.
1.6 Blocking of personal data – temporary suspension of processing of personal data (except in cases where processing is necessary to clarify personal data).
1.7 Destruction of personal data – actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which the physical media of personal data are destroyed.
1.8 Cookie – a piece of data automatically stored on the computer’s hard drive each time a website is visited. Thus, a cookie is a unique browser identifier for a website. Cookies enable storing information on the server and help navigate the web space more easily, and also allow site analysis and performance evaluation. Most web browsers allow the use of cookies, but you can change the settings to refuse cookies or track their distribution path. At the same time, some resources may not work correctly if cookies are disabled in the browser.
1.9 Web beacons. On certain web pages or emails, the Operator may use the common Internet technology “web beacons” (also known as “tags” or “clear GIF technology”). Web beacons help analyze the effectiveness of websites, for example, by measuring the number of site visitors or the number of “clicks” made on key positions of the site page.
1.10 Operator – RUKI LLC, INN 9725051231, legal address: 115533, Moscow, Nagatinskaya Embankment, 14, building 1, office 304. – an organization that independently or jointly with other persons organizes and (or) carries out the processing of personal data, as well as determines the purposes of processing personal data, the composition of personal data to be processed, and actions (operations) performed with personal data.
1.11 User – an Internet user.
1.12 Site — https://r-eight.com/
2. General provisions
2.1 This Privacy Policy regarding the processing of personal data (hereinafter – the Policy) has been drawn up in accordance with paragraph 2 of Article 18.1 of the Federal Law “On Personal Data” No. 152-FZ of July 27, 2006, as well as other regulatory legal acts of the Russian Federation in the field of protection and processing of personal data, and applies to all personal data that the Operator may receive from the User during their use of the Site on the Internet.
2.2 The Operator ensures the protection of processed personal data from unauthorized access and disclosure, unlawful use or loss in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006 “On Personal Data.”
2.3 The Operator has the right to make changes to this Policy. When changes are made, the date of the last update of the version is indicated in the header of the Policy. The new version of the Policy comes into force from the moment it is posted on the site, unless otherwise provided by the new version of the Policy.
2.4 The Operator is obliged to publish or otherwise ensure unrestricted access to this Privacy Policy in accordance with Part 2 of Article 18.1 of Federal Law No. 152-FZ.
3. Principles of processing personal data
The processing of personal data by the Operator is carried out on the basis of the following principles:
— legality and fair basis;
— limiting the processing of personal data to the achievement of specific, predetermined and legitimate purposes;
— preventing the processing of personal data incompatible with the purposes of collecting personal data;
— preventing the merging of databases containing personal data, the processing of which is carried out for purposes incompatible with each other;
— processing only those personal data that meet the purposes of their processing;
— compliance of the content and volume of processed personal data with the stated purposes of processing;
— preventing the processing of personal data that is excessive in relation to the stated purposes of their processing;
— ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of processing personal data;
— destruction or anonymization of personal data upon achieving the purposes of their processing or in case of loss of the need to achieve these purposes, if the Operator cannot eliminate violations of personal data, unless otherwise provided by federal law.
4. Processing of personal data
4.1 Acquisition of PD
4.1.1 All PD should be obtained from the PD subject themselves. If the PD of the subject can only be obtained from a third party, then the subject must be notified of this or their consent must be obtained.
4.1.2 The Operator must inform the PD subject about the purposes, intended sources and methods of obtaining PD, the nature of the PD to be obtained, the list of actions with PD, the period during which the consent is valid and the procedure for its withdrawal, as well as the consequences of the PD subject’s refusal to give written consent to their receipt.
4.1.3 Documents containing PD are created by receiving PD via the Internet from the PD subject during their use of the Site.
4.1.4 Receiving PD via the Internet from an operator who has received PD and consent for their processing from the PD subject, in compliance with the requirements of applicable law.
4.2 The Operator processes PD if at least one of the following conditions is met:
— processing of personal data is carried out with the consent of the PD subject to the processing of their personal data;
— processing of personal data is necessary to achieve the purposes provided for by an international treaty of the Russian Federation or law, to exercise and perform the functions, powers and duties assigned to the operator by the legislation of the Russian Federation;
— processing of personal data is necessary for the administration of justice, execution of a judicial act, act of another body or official, subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings;
— processing of personal data is necessary for the performance of a contract to which the PD subject is a party, or a beneficiary or guarantor, as well as for concluding a contract on the initiative of the PD subject or a contract under which the PD subject will be a beneficiary or guarantor;
— processing of personal data is necessary to exercise the rights and legitimate interests of the operator or third parties, or to achieve socially significant goals, provided that the rights and freedoms of the PD subject are not violated;
— processing of personal data to which access by an unlimited circle of persons is provided by the PD subject or at their request (hereinafter — publicly available personal data);
— processing of personal data subject to publication or mandatory disclosure in accordance with federal law.
4.3 The Operator may process PD for the following purposes:
— increasing the awareness of the PD subject about the Operator’s products and services;
— concluding and executing contracts with the PD subject;
— informing the PD subject about the Operator’s news and offers;
— identifying the PD subject on the Site;
— ensuring compliance with laws and other regulatory legal acts in the field of personal data;
— execution of contracts — orders of PD operators, for PD that are processed in the interests of third parties — PD operators on the basis of a contract (order of PD operators).
4.4 Categories of PD subjects. PD of the following PD subjects are processed: – individuals who are in civil law relations with the Operator;
– individuals who are Users of the Site;
4.5 PD processed by the Operator:
– data received from Site Users, namely: email address, contact phone number;
4.6 Processing of personal data is carried out:
– using automation tools;
– without the use of automation tools.
4.7 Storage of PD
4.7.1 PD of subjects may be received, undergo further processing and be transferred for storage both on paper and in electronic form.
4.7.2 PD recorded on paper are stored in locked cabinets or in locked rooms with restricted access rights.
4.7.3 PD of subjects, processed using automation tools for different purposes, are stored in different folders.
4.7.4 Storage and placement of documents containing PD in open electronic catalogs (file sharing) in the PDIS is not allowed.
4.7.5 Storage of PD in a form that allows identification of the PD subject is carried out no longer than required by the purposes of their processing, and they are subject to destruction upon achieving the processing purposes or in case of loss of the need to achieve them.
4.8 Destruction of PD
4.8.1 Destruction of documents (media) containing PD is carried out by burning, crushing (grinding), chemical decomposition, turning into a shapeless mass or powder. The use of a shredder is allowed for the destruction of paper documents.
4.8.2 PD on electronic media are destroyed by erasing or formatting the media.
4.8.3 The fact of destruction of PD is documented by an act of destruction of media.
4.9 Transfer of PD
4.9.1 The Operator transfers PD to third parties in the following cases: – the subject has expressed their consent to such actions;
– transfer is provided for by Russian or other applicable law within the framework of the procedure established by law.
4.9.2 List of persons to whom PD is transferred. Third parties to whom PD is transferred: The Operator does not transfer PD to third parties.
5. Protection of personal data
5.1 In accordance with the requirements of regulatory documents, the Operator has created a personal data protection system (PDPS) consisting of legal, organizational and technical protection subsystems.
5.2 The legal protection subsystem is a set of legal, organizational and regulatory documents that ensure the creation, operation and improvement of the PDPS.
5.3 The organizational protection subsystem includes the organization of the PDPS management structure, the permitting system, and information protection when working with employees, partners and third parties.
5.4 The technical protection subsystem includes a set of technical, software, and hardware-software means that ensure the protection of PD.
5.5 The main PD protection measures used by the Operator are: – appointment of a person responsible for PD processing, who organizes PD processing, training and instruction, internal control over compliance by the institution and its employees with the requirements for PD protection.
– identification of current threats to PD security during their processing in the PDIS and development of measures and activities for PD protection.
– development of a policy regarding the processing of personal data.
– establishing rules for access to PD processed in the PDIS, as well as ensuring registration and recording of all actions performed with PD in the PDIS.
– establishing individual employee access passwords to the information system in accordance with their production duties.
– use of information security means that have passed the conformity assessment procedure in accordance with the established procedure.
– certified anti-virus software with regularly updated databases.
– compliance with conditions that ensure the safety of PD and exclude unauthorized access to them.
– detection of facts of unauthorized access to personal data and taking measures.
– restoration of PD modified or destroyed as a result of unauthorized access to them.
– training of the Operator’s employees directly involved in the processing of personal data on the provisions of the legislation of the Russian Federation on personal data, including requirements for the protection of personal data, documents defining the Operator’s policy on the processing of personal data, and local acts on personal data processing.
– implementation of internal control and audit.
6. Basic rights of the PD subject and obligations of the Operator
6.1 Basic rights of the PD subject.
6.1.1 The subject has the right to access their personal data and the following information: – confirmation of the fact of PD processing by the Operator;
– legal grounds and purposes of PD processing;
– purposes and methods of PD processing used by the Operator;
– name and location of the Operator, information about persons (except for the Operator’s employees) who have access to PD or to whom PD may be disclosed on the basis of a contract with the Operator or on the basis of federal law;
– terms of processing personal data, including terms of their storage;
– procedure for the PD subject to exercise the rights provided for by this Federal Law;
– name or last name, first name, patronymic and address of the person processing PD on behalf of the Operator, if processing is or will be entrusted to such person;
– contacting the Operator and sending requests to them;
– appealing the actions or inactions of the Operator.
6.1.2 The Site User may at any time withdraw their consent to PD processing by sending an electronic message to the email address: info@r-eight.ru, or by sending a written notification to the address: 115533, Moscow, Nagatinskaya Embankment, 14, building 1, office 304.
After receiving such a message, the processing of the User’s PD will be terminated, and their PD will be deleted, except in cases where processing may be continued in accordance with the law.
6.2 Obligations of the Operator. The Operator is obliged to:
– when collecting PD, provide information about PD processing;
– in cases where PD was not obtained from the PD subject, notify the subject;
– if the subject refuses to provide PD, the consequences of such refusal are explained to the subject;
– publish or otherwise provide unlimited access to the document defining its policy on PD processing, to information on the implemented requirements for PD protection;
– take necessary legal, organizational and technical measures or ensure their adoption to protect PD from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution of PD, as well as from other unlawful actions in relation to PD;
– give answers to requests and appeals from PD subjects, their representatives and the authorized body for the protection of the rights of PD subjects.
7. Features of processing and protection of data collected using the Internet
7.1 There are two main ways in which the Operator obtains data via the Internet:
– provision of PD by PD subjects by filling out Site forms;
– automatically collected information. The Operator may collect and process information that is not PD:
– information about Users’ interests on the Site based on the search queries entered by Site Users about services and goods sold and offered for sale, in order to provide up-to-date information to Users when using the Site, as well as to summarize and analyze information about which sections of the Site, services, and goods are most in demand among Site Users;
– processing and storage of Site Users’ search queries in order to summarize and create statistics on the use of Site sections.
7.2 The Operator automatically receives certain types of information obtained during the interaction of Users with the Site, email correspondence, etc. This refers to technologies and services such as cookies, Web beacons, as well as User applications and tools.
7.3 At the same time, Web beacons, cookies and other monitoring technologies do not allow automatic receipt of PD. If the Site User voluntarily provides their PD, for example, when filling out a feedback form, only then do the processes of automatic collection of detailed information start to facilitate the use of the Site and/or to improve interaction with Users.
8. Final provisions
8.1 This Policy is a local regulatory act of the Operator.
8.2 This Policy is publicly available. The public availability of this Policy is ensured by its publication on the Operator’s Site.
8.3 This Policy may be revised in any of the following cases:
– in case of changes in the legislation of the Russian Federation in the field of personal data processing and protection;
– in cases of receiving orders from competent state authorities to eliminate inconsistencies affecting the scope of the Policy
– by decision of the Operator;
– in case of changes in the purposes and terms of PD processing;
– in case of changes in the organizational structure or the structure of information and/or telecommunication systems (or the introduction of new ones);
– in case of application of new PD processing and protection technologies (including transfer and storage);
– when it becomes necessary to change the PD processing procedures related to the Operator’s activities.
8.4 In case of non-compliance with the provisions of this Policy, the Company and its employees bear responsibility in accordance with the current legislation of the Russian Federation.
8.5 Control over compliance with the requirements of this Policy is exercised by the persons responsible for organizing the processing of the Company’s Data, as well as for personal data security.