PRIVACY AND PERSONAL DATA PROCESSING POLICY

This Privacy and Personal Data Processing Policy (the “Policy”) sets out the rules governing the collection, use, processing, storage, disclosure and protection of personal data in connection with the IQsha service available through the websites iqsha.ru and iqsha.com (the “Website”) and the IQsha mobile application (the “Application”).

This Policy applies together with the applicable Website End User License Agreement, Mobile Application End User License Agreement, Cookie Policy and other terms applicable to the IQsha service and forms an integral part thereof.

The data controller is:

MEDIARTIS LTD Cyprus Tax No. 10433075P Agiou Dometiou 17-302, Engomi, Nicosia, 2407, Cyprus Email for personal data enquiries: [email protected]

Personal data is processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR), the laws of the Republic of Cyprus and other applicable mandatory data protection laws.

1. GENERAL PROVISIONS

1.1. Terms used in this Policy that are defined in the applicable End User License Agreements shall have the same meanings unless otherwise stated in this Policy.

1.2. The Provider processes personal data lawfully, fairly and transparently, for specified and legitimate purposes and only to the extent necessary to achieve those purposes.

Processing may be carried out by automated means and through information systems, as well as by non-automated means where necessary for the relevant processing purpose.

1.3. A User and Account holder must be a legally competent adult.

A minor may use IQsha Content under the supervision of their parent, adoptive parent, guardian, custodian or another person having the appropriate legal authority.

The service is not intended for minors to register independently as Users.

1.4. A User who creates a profile for a minor or permits a minor to use the Website or Application confirms that they have the necessary legal authority to do so and is responsible for the lawful provision to the Provider of information relating to that minor.

1.5. The Provider does not require Users to provide their real first or last names, or those of a child, for ordinary registration and use of the service. Users may use nicknames or other chosen identifiers in the relevant fields.

A User’s email address is used for Account creation and operation, authentication, access recovery, technical support and other purposes described in this Policy.

1.6. Users are advised not to provide personal data that is not objectively necessary for use of the service or consideration of a particular request through free-text fields, technical support requests or other communications with the Provider.

1.7. Information provided by the User is generally accepted by the Provider in the form in which it is submitted. The Provider is not required to verify the accuracy of each item of information provided by the User unless such verification is required by law or by the nature of the relevant service.

The User is responsible for the accuracy of the information provided and for having a lawful basis to provide it.

2. CATEGORIES OF PERSONAL DATA PROCESSED

2.1. Depending on the Website or Application functionality used by the User, the Provider may process the following categories of data:

— the User’s email address;

— the User’s chosen name, nickname or other identifier;

— the chosen name, nickname or other identifier of a minor’s profile;

— the minor’s age, date of birth, year of birth or age category, where such information is required by the relevant functionality;

— Account and profile settings;

— information relating to completion of Tasks, Exercises and Training Sessions;

— Statistics, progress, results, rewards, activity history and other information generated through use of the service;

— information concerning the purchased License and access plan;

— limited information concerning payment transactions received from payment service providers, such as payment status, amount, currency, transaction date, transaction identifier and information concerning the purchased plan;

— technical support requests and related correspondence;

— technical information necessary for the operation, security and diagnostics of the service, including IP address, User Agent, browser type and version, operating system, device type, Application version, language and regional settings, date and time of requests, requested pages or functions, technical event logs and error logs;

— information relating to consents, marketing communication preferences and opt-out records;

— other information voluntarily provided by the User in connection with a particular request or use of a specific function of the service.

2.2. The Provider does not directly collect or store full payment card details, CVV/CVC codes, online banking passwords or other confidential payment credentials of Users.

Such information is processed directly by the App Store, Google Play, banks, payment systems, payment aggregators and other relevant payment service providers.

2.3. The Provider does not seek to obtain special categories of personal data, including health information, except in limited circumstances where a User voluntarily applies for a social benefit made available by the service for a minor with a disability or health-related limitation.

In such circumstances, the Provider requests only the minimum information necessary.

Users are advised to remove or obscure names, addresses, dates of birth, document numbers and other information that is not necessary to establish eligibility for the relevant benefit.

Where submitted materials contain health information, such information shall be processed solely for the purpose of considering the relevant request and on an appropriate legal basis permitted by law, including explicit consent where required by applicable law.

Following a decision on the request, the relevant materials shall be deleted unless their further retention is required by law.

3. PURPOSES AND LEGAL BASES OF PROCESSING

3.1. Personal data may be processed for the following purposes:

— creating and maintaining an Account;

— providing the User with a purchased or free License;

— ensuring operation of the Website and Application;

— providing Content and service functionality;

— personalising Content based on age, the selected profile, activity history and other settings;

— generating and maintaining progress, Statistics, results and rewards;

— synchronising an Account between the Website and Application;

— authentication and access recovery;

— handling technical support requests;

— confirming payments and activating or restoring purchased access;

— processing refunds and payment disputes;

— preventing fraud and misuse;

— maintaining information and technical security;

— detecting, diagnosing and resolving errors;

— analysing, developing and improving the service;

— complying with applicable law and lawful binding requests from competent authorities;

— establishing, exercising or defending legal claims;

— protecting the rights and legitimate interests of the Provider and Users;

— sending service-related communications;

— sending marketing communications where permitted by applicable law.

3.2. Depending on the relevant purpose, the Provider relies on one or more legal bases available under the GDPR:

performance of a contract — where processing is necessary for registration, creation and maintenance of an Account, provision of a License and service functionality, maintenance of progress, processing of a purchase or provision of technical support;

compliance with a legal obligation — where processing, retention or disclosure of certain information is required by law;

legitimate interests of the Provider — including maintaining security, preventing fraud, protecting the rights of the Provider and Users, diagnosing technical issues, maintaining necessary internal analytics and improving the service, provided that such interests are not overridden by the rights and freedoms of the data subject;

consent — where applicable law requires consent for the relevant processing, including certain marketing communications or processing of special categories of personal data.

3.3. Where processing is based on consent, the User may withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

4. CHILDREN’S DATA

4.1. An IQsha Account is intended to be registered by an adult User.

4.2. Information contained in a minor’s profile is provided by the User and is used primarily for organising and personalising activities.

4.3. The Provider does not require a minor to provide a separate email address, telephone number, real first or last name or other directly identifying information unless such information is objectively necessary for a particular service function.

4.4. If the Provider becomes aware that a minor has independently created an Account or provided personal data without the necessary authority or consent of a legal representative, the Provider may restrict use of the relevant Account and take reasonable steps to delete the relevant data.

A parent or other legal representative may contact the Provider at [email protected].

5. SERVICE AND MARKETING COMMUNICATIONS

5.1. The Provider may send communications necessary for Account operation and performance of the contract, including:

— registration confirmations;

— password recovery communications;

— security-related notifications;

— information concerning purchased access and payments;

— technical support communications;

— material information concerning operation of the service and the terms governing its use.

Such communications are service-related and may be sent regardless of whether the User has subscribed to marketing communications where their delivery is objectively necessary for Account servicing or performance of the contract.

5.2. Marketing communications, including information about discounts, special offers and promotional campaigns, are sent in accordance with applicable law.

5.3. Users may opt out of marketing communications by using an unsubscribe link contained in the relevant message or another available opt-out method.

Opting out of marketing communications does not prevent the Provider from sending necessary service-related communications.

5.4. The Provider may use specialised service providers to deliver electronic communications.

Following deletion of an Account, certain technical records may remain with such providers for a reasonable period where necessary to maintain an opt-out, prevent further unwanted communications, ensure security or comply with legal requirements.

6. PAYMENT INFORMATION

6.1. Payments may be processed by the App Store, Google Play, banks, payment systems, payment aggregators and other payment service providers.

6.2. Such parties may independently request information from the User that is necessary to process a payment, identify the payer, prevent fraud and comply with their own legal obligations.

Such processing is carried out by the relevant provider in accordance with its own privacy policy and applicable law.

6.3. The Provider may receive limited information concerning a payment transaction where necessary to:

— confirm payment;

— activate or restore a License;

— identify a purchase;

— process a refund;

— resolve a payment dispute or chargeback;

— prevent fraud;

— comply with mandatory legal requirements.

6.4. The Provider is not responsible for the independent processing of personal or payment data by a payment service provider to the extent that the relevant provider acts as an independent data controller and such processing is outside the Provider’s reasonable control.

7. SHARING PERSONAL DATA WITH THIRD PARTIES

7.1. The Provider does not sell Users’ personal data.

7.2. To operate IQsha, the Provider may engage service providers that may receive access to a limited amount of data solely to the extent necessary to perform the relevant function.

Such providers may include:

— hosting and cloud service providers;

— server infrastructure and data storage providers;

— email and notification service providers;

— analytics and technical diagnostic services;

— payment service providers;

— technical support providers;

— software and other technology infrastructure providers.

7.3. Where a third party processes personal data on behalf of the Provider as a processor, the Provider takes reasonable measures to engage service providers that offer sufficient guarantees of compliance with the GDPR and appropriate security of processing.

7.4. Personal data may also be disclosed:

— to competent governmental, judicial or law enforcement authorities where the Provider is subject to a lawful and binding request;

— to the Provider’s professional advisers, including lawyers, auditors and accountants, to the extent necessary;

— to insurers or other professional parties where objectively necessary for the resolution of a dispute or protection of the Provider’s legitimate interests;

— to a new owner, rights holder, purchaser of the business or purchaser of the IQsha project in connection with a sale, transfer, restructuring or other lawful transfer of the project, rights or assets, subject to applicable data protection requirements;

— to other parties with the User’s consent or where otherwise permitted or required by law.

8. INTERNATIONAL DATA TRANSFERS

8.1. Certain providers of technical or other services may be located, or may process data, outside the Republic of Cyprus or the European Economic Area.

8.2. Where personal data is transferred to a country that is not subject to an adequacy decision of the European Commission, the Provider uses safeguards required by applicable law where required in the particular circumstances, including the European Commission’s Standard Contractual Clauses or other permitted transfer mechanisms.

8.3. Users may contact the Provider for additional information concerning safeguards applicable to international transfers of their personal data.

9. COOKIES, ANALYTICS AND TECHNICAL INFORMATION

9.1. The Website and Application may use technical means and technologies necessary for authentication, storing settings, maintaining security, diagnostics, analysis of service operation and other purposes described in this Policy.

9.2. The use of Cookies and similar technologies on the Website is additionally governed by the Cookie Policy.

9.3. Where analytics, advertising or other non-essential technologies require prior User consent under applicable law, such technologies shall be used only where an appropriate legal basis exists.

10. DATA RETENTION

10.1. The Provider retains personal data only for as long as necessary for the purposes for which it is processed, unless longer retention is required or permitted by law, including where necessary for the establishment, exercise or defence of legal claims.

10.2. Core Account information, profiles, settings and usage history may be retained for the lifetime of the Account.

10.3. Following deletion of an Account, data directly associated with its use shall be deleted or anonymised within a reasonable technical period, except for information that the Provider is required or permitted to retain for longer periods in connection with:

— accounting, tax or other legal obligations;

— payment transactions and financial disputes;

— fraud prevention;

— information security;

— the establishment, exercise or defence of legal claims;

— technical backup cycles;

— the need to maintain evidence of marketing opt-outs or other User preferences.

10.4. Data contained in backups may remain after deletion of the primary data until the relevant backup is routinely overwritten or deleted.

Such data shall not be used for ordinary operation of the deleted Account and shall be restored from backups only where there is a corresponding technical or legal necessity.

10.5. Anonymised and aggregated information that can no longer reasonably be used to identify an individual, directly or indirectly, may be retained and used without limitation, to the extent permitted by applicable law.

11. BACKUPS AND BUSINESS CONTINUITY

11.1. The Provider may create and maintain backups to support service resilience and recovery following technical failures, errors, data corruption, security incidents or other unforeseen circumstances.

11.2. Backups may contain Account data and information necessary to restore software, servers, databases and other components of the IQsha infrastructure.

11.3. Access to backups is restricted to persons for whom such access is objectively necessary to perform relevant technical or organisational functions.

11.4. The frequency, architecture, retention periods and methods used for creating backups are determined by the Provider and its technical service providers having regard to the current service architecture, the nature of the data and information security requirements, and may change without amendment of this Policy.

12. ACCOUNT DELETION

12.1. A User may delete their Account using the relevant functionality available on the Website or in the Application or may contact the Provider at [email protected].

12.2. Deletion of an Account terminates ordinary access to data associated with the Account and may result in permanent deletion of progress, Statistics, rewards, settings and other information without the possibility of subsequent recovery.

12.3. Account deletion does not necessarily result in the immediate deletion of every technical record from all backups, security logs, accounting systems, payment provider systems, email systems or other third-party systems.

Such data shall be processed and deleted in accordance with this Policy, applicable law and the relevant retention periods.

13. DATA SUBJECT RIGHTS

13.1. Where provided by the GDPR, Users have the right to:

— obtain confirmation as to whether their personal data is being processed;

— access their personal data;

— obtain information about the purposes of processing, categories of personal data, recipients, retention periods and other circumstances of processing required by the GDPR;

— obtain a copy of personal data undergoing processing;

— request rectification of inaccurate data or completion of incomplete data;

— request erasure of personal data;

— request restriction of processing;

— object to processing based on legitimate interests;

— receive personal data in a structured, commonly used and machine-readable format and exercise the right to data portability where provided by law;

— withdraw consent where processing is based on consent;

— object to direct marketing;

— not be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them, where provided by the GDPR;

— lodge a complaint with a competent supervisory authority.

13.2. Users may exercise their rights by contacting [email protected].

13.3. The Provider may request information reasonably necessary to verify the identity of the person making a request and to prevent disclosure of personal data to an unauthorised person.

The Provider will not request more information than is objectively necessary for such verification.

13.4. The first copy of personal data provided pursuant to the GDPR shall be provided free of charge.

Where additional copies are requested, the Provider may charge a reasonable fee based on administrative costs in the circumstances and to the extent permitted by the GDPR.

13.5. Requests shall be handled without undue delay and, as a general rule, within one month of receipt.

Where permitted by the GDPR, this period may be extended taking into account the complexity and number of requests, in which case the User shall be notified in accordance with applicable law.

13.6. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Provider may take the measures permitted by the GDPR, including charging a reasonable fee or refusing to act on the request where permitted by law.

14. SUPERVISORY AUTHORITY

14.1. If a User believes that the processing of their personal data infringes applicable data protection law, they may contact the Provider at [email protected].

14.2. Users also have the right to lodge a complaint with a competent supervisory authority.

The Provider’s supervisory authority in the Republic of Cyprus is:

Office of the Commissioner for Personal Data Protection
Republic of Cyprus

Users may also lodge a complaint with another competent supervisory authority where this right is available under the GDPR.

15. PERSONAL DATA SECURITY

15.1. The Provider implements technical and organisational measures appropriate to the nature of the data processed, the current state of technology and existing risks in order to protect personal data against unlawful or accidental access, destruction, loss, alteration, unauthorised disclosure or other unlawful processing.

15.2. Such measures may include:

— use of secure connections;

— restrictions on access to information systems and data;

— access rights management;

— protection of Accounts;

— logging and monitoring of technical events;

— backups and recovery measures;

— software updates;

— detection and remediation of technical vulnerabilities;

— measures designed to prevent and detect unauthorised access;

— organisational requirements applicable to employees and contractors having access to data.

15.3. Specific technical and organisational measures may change as technology, service architecture and relevant risk assessments evolve.

15.4. Despite the measures implemented by the Provider, no information system, storage method or method of transmission over the Internet can guarantee absolute security.

16. PERSONAL DATA BREACHES

16.1. A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed.

16.2. Where a possible security incident is identified, the Provider takes reasonable measures to investigate it and assesses, in particular:

— the nature of the incident;

— the categories and scope of affected data;

— the approximate number of affected data subjects;

— potential consequences;

— risks to the rights and freedoms of individuals;

— available measures to mitigate the consequences and prevent recurrence.

16.3. Where applicable law requires notification of a competent supervisory authority in relation to a personal data breach, the Provider shall make such notification in the manner and within the time limits prescribed by the GDPR.

16.4. Where a personal data breach is likely to result in a high risk to the rights and freedoms of an individual and applicable law requires notification of that individual, the Provider shall notify the affected individual without undue delay in accordance with the GDPR.

16.5. The Provider takes reasonable technical and organisational measures to contain the incident, minimise potential harm and prevent similar incidents from recurring.

17. CHANGES TO THIS POLICY

17.1. The Provider may amend this Policy from time to time, including in response to changes in applicable law, IQsha functionality, technologies used, service providers, infrastructure or data processing practices.

17.2. The current version of this Policy is published on the Website at:

https://iqsha.ru/policies/confidential/

17.3. Where the nature of an amendment requires separate notification to the User or renewed consent under applicable law, the Provider shall take the appropriate steps.

18. GOVERNING LAW AND CONTACT DETAILS

18.1. This Policy is governed by the laws of the Republic of Cyprus and applicable European Union data protection legislation.

18.2. For any questions concerning the processing of personal data, the exercise of data subject rights or this Policy, Users may contact:

[email protected]

18.3. This Policy forms an integral part of the applicable End User License Agreements governing the use of the IQsha Website and Application.