PRIVACY POLICY
Effective Date: July 20, 2026
This Privacy Policy (hereinafter – the "Policy") is an integral part of the Terms of Use posted on the website at: https://autofamily.com/ (hereinafter – the "Site").
By using the Site's services, the User unconditionally agrees to this Policy and the terms of processing of their personal information specified herein. In case of disagreement with these terms, the User must refrain from using the Site's services.
This Policy is compiled in accordance with the requirements of the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the California Consumer Privacy Act (CCPA), the ePrivacy Directive (Directive 2002/58/EC), and other applicable data protection laws. This Policy defines the procedure for processing personal data and measures to ensure the security of personal data taken by Obshchestvo s ogranichennoy otvetstvennostyu "Autofamily" (OOO "Autofamily"), INN 5050139342, OGRN 1185050008483 (hereinafter – the "Operator," "Company," "we," "us," or "our").
This Policy applies to all information that the Operator may collect about visitors to the Site https://autofamily.com/
1. KEY TERMS USED IN THIS POLICY
1.1. Automated processing of personal data – processing of personal data using computer technology.
1.2. Blocking of personal data – temporary cessation of personal data processing (except where processing is necessary to clarify personal data).
1.3. Website – a collection of graphic and informational materials, as well as computer programs and databases, ensuring their availability on the Internet at the network address https://autofamily.com/
1.4. Personal data information system – a collection of personal data contained in databases, and the information technologies and technical means that ensure their processing.
1.5. Depersonalization / Anonymization of personal data – actions that make it impossible to determine, without the use of additional information, the attribution of personal data to a specific User or other subject of personal data.
1.6. Processing of personal data – any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data.
1.7. Operator / Controller – Obshchestvo s ogranichennoy otvetstvennostyu "Autofamily" (OOO "Autofamily"), INN 5050139342, OGRN 1185050008483, located at: 27A Moskovskaya Street, Building 27A, Office 411, Shchyolkovo, Moscow Region, 141112, Russian Federation. The Operator is the Controller within the meaning of the GDPR.
1.8. Personal data – any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
1.9. User / Data subject – any visitor to the Site.
1.10. Provision of personal data – actions aimed at disclosing personal data to a specific person or a specific group of persons.
1.11. Dissemination of personal data – any actions aimed at disclosing personal data to an indefinite circle of persons (transfer of personal data) or making personal data available to an unlimited circle of persons, including publication of personal data in the media, placement in information and telecommunication networks, or providing access to personal data in any other way.
1.12. Destruction of personal data – any actions as a result of which personal data are destroyed irrevocably with the impossibility of further restoration of the content of personal data in the personal data information system and/or material carriers of personal data are destroyed.
1.13. Consent – any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
1.14. Personal data breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
1.15. Supervisory authority – an independent public authority established by a Member State of the European Union responsible for monitoring the application of the GDPR.
2. GENERAL PROVISIONS
2.1. Within the framework of this Policy, the User's personal information means:
2.1.1. Personal information that the User provides about themselves independently in the process of using the Services on the Site:
— First name, Last name;
— Date of birth;
— Passport / ID details (series, number, issued by, date of issue);
— Residential address (registration) and actual place of residence;
— Contact phone numbers (mobile, home);
— Email address (E-mail);
— Other information that the User consciously and voluntarily provides to the Operator when filling out forms on the Site.
2.1.2. Data that is automatically transmitted to the Site's services in the process of their use through software installed on the User's device, including IP address, cookie data, browser information (or other program used to access the services), technical characteristics of equipment and software, date and time of access to the services, addresses of requested pages, and other similar information.
2.1.3. The Site also collects and processes anonymized data about visitors (including files) using internet statistics services, namely: Yandex.Metrica (for more information, see: https://yandex.ru/legal/metrica_termsofuse/).
2.2. Information required for the provision of Services is marked in a special way. By filling out the relevant forms and/or sending their personal data to the Operator, the User expresses their consent to this Policy.
2.3. This Privacy Policy applies only to the Operator's Site. The Operator does not control and is not responsible for third-party sites to which the User may navigate via links available on the Operator's Site.
2.4. The data subject independently decides to provide their personal data and gives consent freely, of their own will, and in their own interest.
2.5. Legal basis for processing: We process your personal data based on one or more of the following legal grounds:
(a) your consent (Article 6(1)(a) GDPR);
(b) the performance of a contract with you or taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR);
(c) compliance with a legal obligation to which we are subject (Article 6(1)(c) GDPR);
(d) our legitimate interests, provided these do not override your fundamental rights and freedoms (Article 6(1)(f) GDPR).
3. PURPOSES OF PROCESSING USERS' PERSONAL INFORMATION
3.1. The Operator collects and stores only the personal information necessary to provide services to the User, except in cases where the law provides for mandatory storage of personal information for a period established by law.
3.2. The Operator processes the User's personal information for the following purposes:
3.2.1. Providing the User with access to the Site's Services or personalized resources of the Site, as well as information and/or materials contained on the Site.
3.2.2. Informing the User by sending electronic messages. The Operator has the right to send the User notifications about new products and services, special offers, and various events. The User can always refuse to receive informational messages by sending a letter to the Operator at info@autofamily.com with the note "Opt-out of notifications about new products and services."
3.2.3. Establishing feedback with the User, including sending notifications, requests, and informational messages regarding the use of the Site, as well as processing resumes, requests, and applications from the User.
3.2.4. Confirming the accuracy and completeness of personal data provided by the User.
3.2.5. Notifying the User about the development of the Site and its Services.
3.2.6. Providing the User with effective customer and technical support in case of problems related to the use of the Site.
3.2.7. Complying with applicable legal obligations, including tax, accounting, and regulatory requirements, as well as for the administration of justice and execution of judicial acts.
3.3. Anonymized User data collected through the internet statistics services specified in clause 2.1.3 of this Policy serves to collect information about Users' actions on the Site, improve the quality of the Site and its content.
4. CONDITIONS AND PRINCIPLES OF PROCESSING USERS' PERSONAL INFORMATION AND ITS TRANSFER TO THIRD PARTIES
4.1. Personal data processing is carried out on a lawful, fair, and transparent basis.
4.2. Personal data processing is carried out on the basis of the data subject's consent to the processing of their personal data, or on other legal grounds as specified in clause 2.5 of this Policy.
4.3. Personal data processing is limited to achieving specific, predetermined, and legitimate purposes. Processing of personal data incompatible with the purposes of personal data collection is not permitted (purpose limitation principle).
4.4. It is not permitted to combine databases containing personal data processed for incompatible purposes.
4.5. The content and volume of processed personal data correspond to the stated purposes of processing. Excessive processing of personal data in relation to the stated purposes is not permitted (data minimization principle).
4.6. When processing personal data, the accuracy, sufficiency, and, where necessary, relevance of personal data in relation to the purposes of processing are ensured (accuracy principle).
4.7. Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation principle).
4.8. The Operator does not process special categories of personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation.
4.9. With respect to the User's personal information, its confidentiality is maintained, except in cases where the User voluntarily provides consent to the dissemination of information about themselves to an unlimited circle of persons.
4.10. The Company may transfer the User's personal information to third parties in the following cases:
4.10.1. The User has expressed consent to such actions.
4.10.2. The transfer is required by applicable law or a court order, within the framework of the procedure established by law.
4.10.3. The transfer is necessary to protect the vital interests of the User or other natural persons.
4.10.4. In the event of a merger, acquisition, or sale of all or part of the Company's assets, all obligations to comply with the terms of this Policy regarding the personal information obtained shall be transferred to the successor.
4.11. Processing of the User's personal data is carried out by the following methods until the purpose of personal data processing is achieved or until the Operator receives the User's withdrawal of consent to the processing of personal data: collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, depersonalization, blocking, deletion, and destruction of personal data, including in personal data information systems with or without the use of automation tools. Processing of Users' personal data is carried out in accordance with the GDPR, CCPA, and other applicable data protection laws.
4.12. Personal data breach notification: In the event of a personal data breach, the Operator shall, without undue delay and, where feasible, not later than 72 (seventy-two) hours after having become aware of it, notify the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the breach is likely to result in a high risk to the rights and freedoms of natural persons, the Operator shall also inform the affected Users without undue delay.
4.13. The Operator takes necessary organizational and technical measures to protect the User's personal information from unauthorized or accidental access, destruction, modification, blocking, copying, distribution, as well as from other unlawful actions of third parties.
4.14. All information collected by third-party services, including data automatically transmitted to the Site's services, is stored and processed by such persons (operators/processors) in accordance with their User Agreement and Privacy Policy. The User must independently and timely familiarize themselves with these documents. The Operator is not responsible for the actions of third parties, including the service providers specified in this clause.
4.15. The Operator, together with the User, takes all necessary measures to prevent losses or other negative consequences caused by the loss or disclosure of the User's personal data.
4.16. If inaccuracies are detected in personal data, the User may update them independently by sending a notification to the Operator's email address info@autofamily.com with the note "Updating personal data."
4.17. The User may withdraw their consent to the processing of personal data at any time, as well as send a request to cease the processing of personal data, by sending the Operator a corresponding notification with the note "Withdrawal of consent to the processing of personal data" or "Request to cease the processing of personal data."
The notification of withdrawal of consent to the processing of personal data or the request to cease the processing of personal data shall be sent to the email address: info@autofamily.com, as well as by written request to the legal address: 27A Moskovskaya Street, Building 27A, Office 411, Shchyolkovo, Moscow Region, 141112, Russian Federation.
Upon receipt by the Operator of the User's withdrawal of consent to the processing of their personal data, the Operator shall cease processing them and, if the storage of personal data is no longer required for the purposes of personal data processing, shall destroy the personal data within a period not exceeding 30 (thirty) days from the date of receipt of said withdrawal.
Upon receipt by the Operator of the User's request to cease the processing of personal data, the Operator shall cease processing them within a period not exceeding 10 (ten) business days from the date of receipt of the corresponding request, except in cases provided for by applicable law.
4.18. International data transfers: If personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, the Company shall ensure appropriate safeguards are in place, such as Standard Contractual Clauses, adequacy decisions, or other mechanisms provided by applicable law.
4.19. Data retention: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and applicable legal requirements.
5. OBLIGATIONS OF THE PARTIES
5.1. The User is obliged to:
5.1.1. Provide information about personal data necessary for using the Site.
5.1.2. Update and supplement the provided personal data information in the event of changes to such information.
5.1.3. Provide the Operator with accurate data about themselves.
5.1.4. Inform the Operator about the clarification (updating, modification) of their personal data.
5.2. The User has the right to:
5.2.1. Right of access: Receive confirmation as to whether or not personal data concerning them is being processed, and where that is the case, access to the personal data and the following information:
1) the purposes of the processing;
2) the categories of personal data concerned;
3) the recipients or categories of recipients to whom the personal data have been or will be disclosed;
4) where possible, the envisaged period for which the personal data will be stored, or if not possible, the criteria used to determine that period;
5) the existence of the right to request from the Operator rectification or erasure of personal data, or restriction of processing of personal data concerning the data subject, or to object to such processing;
6) the right to lodge a complaint with a supervisory authority;
7) where personal data are not collected from the data subject, any available information as to their source;
8) the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject;
9) information about any international data transfers and the safeguards in place.
5.2.2. Right to rectification: Require the Operator to correct inaccurate personal data concerning them without undue delay, or to have incomplete personal data completed.
5.2.3. Right to erasure ("right to be forgotten"): Require the Operator to erase personal data concerning them without undue delay, where one of the grounds specified in Article 17 of the GDPR applies.
5.2.4. Right to restriction of processing: Require the Operator to restrict processing where one of the conditions specified in Article 18 of the GDPR applies.
5.2.5. Right to data portability: Receive the personal data concerning them, which they have provided to the Operator, in a structured, commonly used, and machine-readable format, and have the right to transmit those data to another controller without hindrance from the Operator.
5.2.6. Right to object: Object, on grounds relating to their particular situation, at any time to processing of personal data concerning them, including profiling.
5.2.7. Right to withdraw consent: Withdraw consent to the processing of personal data at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
5.2.8. Right to lodge a complaint: Lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, or to seek a judicial remedy.
5.2.9. Exercise other rights provided for by applicable law.
5.3. The Operator is obliged to:
5.3.1. Use the information obtained exclusively for the purposes specified in this Policy.
5.3.2. Ensure the storage of confidential information in secret, not to disclose it without the prior written permission of the User, and not to sell, exchange, publish, or disclose the transferred personal data of the User in any other possible way, except as provided for in this Policy and applicable law.
5.3.3. Provide the data subject, upon their request, with information regarding the processing of their personal data, in the manner and to the extent provided for by the GDPR and other applicable data protection laws.
5.3.4. Organize the processing of personal data in the manner established by applicable law.
5.3.5. Respond to requests and inquiries of data subjects and their legal representatives in accordance with the requirements of the GDPR and other applicable data protection laws.
5.3.6. Respond to requests from supervisory authorities and provide the necessary information within the time limits established by applicable law.
5.3.7. Publish or otherwise ensure unrestricted access to this Policy regarding the processing of personal data.
5.3.8. Take legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, provision, distribution of personal data, as well as from other unlawful actions in relation to personal data.
5.3.9. Cease the transfer (distribution, provision, access) of personal data, cease processing, and destroy personal data in the manner and cases provided for by applicable law.
5.3.10. Block personal data relating to the relevant User from the moment of the User's (or their legal representative's) request or inquiry, or of the supervisory authority, for the period of verification in the event of detection of inaccurate personal data or unlawful actions.
5.3.11. Maintain records of processing activities in accordance with Article 30 of the GDPR.
5.3.12. Perform other duties provided for by applicable law.
5.4. The Operator has the right to:
5.4.1. Receive from the data subject accurate information and/or documents containing personal data.
5.4.2. In the event of withdrawal of consent to the processing of personal data by the data subject, continue processing personal data without the consent of the data subject if there are legal grounds specified in the GDPR and other applicable law.
5.4.3. Independently determine the composition and list of measures necessary and sufficient to ensure the fulfillment of obligations provided for by applicable law.
6. RESPONSIBILITY OF THE PARTIES
6.1. The Operator, which has not fulfilled its obligations, shall be liable for losses incurred by the User in connection with the unlawful use of personal data, in accordance with applicable law.
6.2. In the event of loss or disclosure of confidential information, the Operator shall NOT be liable if such confidential information:
6.2.1. Became public domain before its loss or disclosure.
6.2.2. Was lawfully obtained from a third party without confidentiality obligations before it was received from the User.
6.2.3. Was disclosed with the User's consent.
6.3. Persons who provided the Operator with inaccurate information about themselves or information about another data subject without the latter's consent shall be liable in accordance with applicable law.
7. DISPUTE RESOLUTION
7.1. Before filing a lawsuit in disputes arising from the relationship between the User and the Operator, it is mandatory to submit a claim (a written proposal for voluntary settlement of the dispute).
7.2. The recipient of the claim shall, within 30 (thirty) calendar days from the date of receipt of the claim, notify the claimant in writing of the results of the claim's consideration.
7.3. If no agreement is reached, the dispute shall be referred to the competent court in accordance with applicable law.
7.4. For Users residing in the European Union or the United Kingdom: You have the right to lodge a complaint with your local supervisory authority and/or seek a judicial remedy in your country of residence.
7.5. For Users residing in California, USA: You have the rights provided by the California Consumer Privacy Act (CCPA), including the right to know, the right to delete, and the right to non-discrimination.
7.6. This Policy and the relationship between the User and the Operator shall be governed by the laws of the Republic of Cyprus, unless mandatory provisions of the law of the User's country of residence provide otherwise.
8. FINAL PROVISIONS
8.1. The Operator has the right to make changes to this Policy without the User's consent.
8.2. The new Policy shall enter into force upon its placement on the Site, unless otherwise provided by the new version of the Policy.
8.3. All suggestions or questions regarding this Policy should be reported to the Operator's email address: info@autofamily.com.
8.4. The current Privacy Policy is posted on the page at: https://autofamily.com/company/policy/.