Personal Data Processing Policy for users of lgc.ru
1. General provisions
1.1. This Policy explains how Limited Liability Company “Leon Group” (Russian legal name: Общество с ограниченной ответственностью «Леон Групп», hereinafter “Leon Group LLC” or the “Operator”) processes personal data of users of https://lgc.ru.
1.2. Operator details:
- INN: 7708462118;
- OGRN: 1267700227189;
- address: 107140, Moscow, Krasnoprudnaya St., 12/1, Building 1, Premises 1/6b;
- personal data contact: dev@lgc.ru.
1.3. The Policy applies to data received through the equipment request, software development request and contact forms, by e-mail and during technical use of the website.
1.4. Processing is governed by the laws of the Russian Federation, including Federal Law No. 152-FZ on Personal Data.
2. Data subjects and data categories
2.1. Website visitors
The Operator may process IP address, request date and time, requested URL, referrer, browser, operating system, device type, selected language, security logs and cookie-related identifiers described in the Cookie Policy.
2.2. Representatives of organisations submitting requests
The Operator may process:
- first and last name;
- position, if provided;
- organisation name and INN;
- business e-mail;
- telephone number;
- preferred contact method;
- message content;
- equipment specifications;
- software project description, indicative schedule and budget;
- documents and personal data contained in uploaded files;
- consent record, request ID and technical submission logs.
2.3. The Operator does not intend to collect sensitive categories of personal data, biometric data, criminal record data, passport details, passwords, private keys or personal payment details through the public website. Users must not include such data in messages or attachments.
3. Purposes and legal bases
The Operator processes data to:
- receive and respond to equipment supply requests;
- evaluate software development requirements;
- prepare quotations, NDAs, specifications and contracts;
- communicate with a representative of a prospective or current client;
- take steps requested before entering into a contract and perform contracts;
- operate and secure the website;
- meet legal obligations and protect lawful rights;
- obtain aggregated analytics only after the user has consented to analytics cookies.
Legal bases include consent, steps taken at the data subject's request before contract conclusion, contract performance, compliance with law and exercise of lawful rights where the subject's rights are not infringed.
The website does not use automated decision-making that produces legal effects and does not create advertising profiles.
4. Processing operations
Processing may be automated, non-automated or mixed and may include collection, recording, organisation, accumulation, storage, updating, retrieval, use, disclosure to authorised processors, restriction, deletion and destruction.
Access is limited to staff and processors who require it and are bound by confidentiality and security obligations.
5. Consent
Consent is collected using a separate unticked checkbox linked to the standalone Consent to Personal Data Processing. The request ID, date and time, form type, locale, consent version and consent-text hash are included in the service section of the e-mail accepted by the corporate SMTP server. The website does not create a separate request database or consent log.
Consent can be withdrawn by writing to dev@lgc.ru. Withdrawal does not affect processing already lawfully carried out and does not prevent continued processing where another legal basis applies.
6. Localisation, retention and deletion
Initial recording, organisation, accumulation, storage, updating and retrieval of personal data of Russian citizens collected online are performed using databases located in the Russian Federation, unless a statutory exception applies.
After confirmed SMTP delivery, a request and its attachments are retained in the corporate mailbox until the purpose is achieved, consent is withdrawn or the Operator's approved retention period expires, whichever occurs first, unless longer retention is required by law or to protect legal rights. No separate copy is retained on the web server.
Data required for a contract, accounting, claims or statutory obligations is retained for the applicable legal period. Security logs are normally retained for no more than 12 months unless needed for an incident investigation.
Data is deleted or destroyed when the purpose is achieved or lawful processing ends. Where immediate destruction is impossible, data is restricted until destruction.
7. Recipients and processors
Data may be disclosed to authorised employees and Russian providers of hosting, e-mail, corporate-mail backup where used, malware scanning and technical support acting under the Operator's instructions and appropriate contractual safeguards.
The Operator does not sell personal data or disclose it for independent third-party advertising. Disclosure to public authorities is made only where permitted or required by law.
8. Cross-border transfers
The baseline website configuration does not involve cross-border transfers. No foreign CRM, form service, CDN, analytics, font, anti-bot, storage or e-mail forwarding service may receive personal data without a prior legal and technical review and completion of the notification procedure required by Russian law.
9. Cookies
Necessary cookies support website operation, security, locale and consent settings. Analytics cookies are used only after active consent and can be rejected or withdrawn through “Cookie settings” in the footer. Further details are provided in the Cookie Policy.
10. User rights
Users may request access, correction, restriction, deletion, withdrawal of consent or termination of processing where provided by law, and may complain to Roskomnadzor or a court.
Requests should be sent to dev@lgc.ru and include enough information to identify the requester and relevant submission. The Operator may request proportionate proof of identity or authority without collecting excessive data.
11. Security
The Operator applies legal, organisational and technical safeguards, including access control, activity logging, HTTPS, software updates, backups, malware scanning of uploads, vulnerability management, staff instructions and incident response procedures.
12. Children
The website is designed for B2B interaction and is not directed at children. The Operator does not knowingly collect children's data through the website.
13. Changes and contacts
The current version is published on this page. Material changes to purposes, data categories or recipients require a new consent where required by law.
Questions, requests and consent withdrawals: dev@lgc.ru.