Personal Data Processing Policy
1. General Provisions
1.1. This Personal Data Processing Policy (hereinafter referred to as the Policy) of zozi.cash (hereinafter referred to as the Operator) is an official document that defines the general principles, purposes, and procedures for processing personal data of users of the website (zozi.cash) (hereinafter referred to as the Website), as well as information about the personal data protection measures implemented.
1.2. The Policy is developed in accordance with the legislation of the Russian Federation in the field of personal data and the requirements of the General Data Protection Regulation (GDPR) of the European Union.
1.3. This Policy applies solely to the Website. The Operator does not control and is not responsible for third-party websites that the User may access through links available on the Website.
1.4. The Operator’s processing of personal data belonging to other categories of data subjects is regulated by other local acts of the Russian Federation.
1.5. This Policy enters into force from the moment of its approval and remains valid indefinitely until replaced by a new Policy.
2. Key Terms and Definitions
2.1. The following terms are used in this Policy:
2.1.1. Personal Data Information System – a set of personal data contained in databases, and the information technologies and technical tools that ensure their processing.
2.1.2. Personal data processing – any action (operation) or a set of actions (operations) performed using automation tools or without them with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion, and destruction of personal data.
2.1.3. Personal Data Operator (Operator) – a government authority, municipal authority, legal or natural person, independently or jointly with others, organizing and (or) performing the processing of personal data, as well as determining the purposes of processing personal data, the composition of personal data to be processed, and actions (operations) performed with personal data.
2.1.4. Personal data – any information relating directly or indirectly to an identified or identifiable individual (personal data subject).
2.1.5. Website user – any person visiting the website and using the information, materials, and services of the site.
2.1.6. Website – a set of interconnected web pages hosted on the Internet at a unique address (URL), including its subdomains.
2.1.7. Cookies – a small data fragment sent by a web server and stored on the User’s computer, which a web client or web browser sends to the web server in an HTTP request each time it attempts to open a page of the corresponding site.
2.1.8. IP address – a unique network address of a node in a computer network through which the User accesses the website.
3. Procedure and Conditions for Personal Data Processing
3.1. The basis for processing personal data of Website Users is their consent to the processing of personal data. Users of the Website give their consent to the processing of their personal data in the following cases:
- when registering on the Website in a personal account;
- when logging in via social networks;
- when filling out a feedback form.
- when registering on the Website in a personal account;
- when logging in via social networks;
- when filling out a feedback form.
3.2. If the User disagrees with the terms of this Policy, use of the Website and/or any services available through the Website must be immediately discontinued.
3.3. The personal data of Website Users is processed for the following purposes:
- promotion of goods, work, services;
- establishing feedback with the User, including sending notifications, requests and their processing, as well as processing requests and applications from the User;
- maintaining statistics and analyzing the Website’s performance.
- promotion of goods, work, services;
- establishing feedback with the User, including sending notifications, requests and their processing, as well as processing requests and applications from the User;
- maintaining statistics and analyzing the Website’s performance.
3.4. The list of personal data of users processed on the Website using automation tools includes:
- last name, first name, patronymic;
- nickname;
- email address;
- phone number;
- information about banking details (card number, surname, first name, wallet number, country, phone number);
- other information that the user decides to provide.
- last name, first name, patronymic;
- nickname;
- email address;
- phone number;
- information about banking details (card number, surname, first name, wallet number, country, phone number);
- other information that the user decides to provide.
3.5. To maintain statistics and analyze Website performance, the Operator processes the following data using metric services Google Analytics and Yandex.Metrica:
- IP address;
- browser information;
- cookie data;
- access time;
- referrer (previous page address).
- IP address;
- browser information;
- cookie data;
- access time;
- referrer (previous page address).
3.6. Google Analytics, a web analysis tool by Google Inc., registered at Amphitheatre Parkway, Mountain View, California 94043, USA (hereinafter – Google), is used for continuous Website optimization. Google Analytics uses cookies and creates pseudonymous usage profiles that enable analysis of Users' interaction with the Website. Information stored in such cookies (e.g., browser type/version, operating system used, referrer URL, hostname of accessing computer, request time) is usually transferred and stored on Google’s servers. To block Google Analytics, you can download and install the add-on via the link
http://tools.google.com/dlpage/gaoptout. For more information, see Google's privacy policy:
https://www.google.com/intl/ru/policies/privacy.
3.7. The Yandex.Metrica service, available at
https://api.yandex.com/metrika, allows various User services and applications to interact with the Yandex.Metrica service by LLC “Yandex”, registered at 16, Leo Tolstoy Street, Moscow, 119021 (hereinafter – Yandex). Yandex.Metrica uses cookies and creates pseudonymous usage profiles to analyze Website usage. The information stored in such cookies (e.g., browser type/version, operating system used, referrer URL, hostname of accessing computer, request time) is usually transferred and stored on Yandex’s servers. To block Yandex.Metrica, you can download and install the add-on via the link
https://yandex.com/support/metrica/general/opt-out.html
For more information, see Yandex’s privacy policy:
https://yandex.com/legal/confidential/.
3.8. If Google Analytics and Yandex.Metrica are blocked, some functions of the Website may become unavailable.
3.9. The Website does not process biometric personal data or special categories of personal data relating to race, ethnicity, political views, religious or philosophical beliefs, health, or sex life.
3.10. The Operator does not verify the accuracy of the information provided by the User and assumes that the User provides accurate and sufficient information and keeps it up to date.
3.11. The Operator performs the following actions with personal data: collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), blocking, deletion, destruction.
3.12. Personal data is stored in a form that allows identifying the personal data subject no longer than required for the purposes of personal data processing.
3.13. Grounds for termination of personal data processing may include achievement of the processing purpose, expiration of the processing period, withdrawal of the Website User’s consent, or detection of unlawful processing.
3.14. The retention period for Website Users’ personal data is one year from the date of last data submission.
4. Measures to Ensure the Security of Personal Data
4.1. The security of personal data processed by the Operator is ensured through the implementation of legal, organizational, technical, and software measures necessary and sufficient to meet the requirements of the legislation of the Russian Federation.
4.2. The Operator undertakes the following measures to ensure the security of personal data:
- appointment of responsible persons for organizing the processing and protection of personal data;
- limiting the number of employees of the Operator with access to personal data;
- determining the level of protection of personal data when processed in personal data information systems;
- establishing access control rules for personal data processed in personal data information systems and ensuring the registration and accounting of all actions performed with personal data;
- restricting access to premises where the main technical means and systems of personal data information systems are located and where non-automated processing of personal data is carried out;
- keeping records of personal data storage devices;
- organizing backup and recovery of operability of personal data information systems and personal data modified or destroyed as a result of unauthorized access;
- setting password complexity requirements for access to personal data information systems;
- implementing antivirus control, preventing the introduction of malicious software (viruses) and software bookmarks into the corporate network;
- timely updating of software used in personal data information systems and information protection tools;
- regularly assessing the effectiveness of measures taken to ensure the security of personal data;
- detecting incidents of unauthorized access to personal data and taking measures to identify causes and eliminate possible consequences;
- monitoring the security measures taken and the protection levels of personal data information systems.
- appointment of responsible persons for organizing the processing and protection of personal data;
- limiting the number of employees of the Operator with access to personal data;
- determining the level of protection of personal data when processed in personal data information systems;
- establishing access control rules for personal data processed in personal data information systems and ensuring the registration and accounting of all actions performed with personal data;
- restricting access to premises where the main technical means and systems of personal data information systems are located and where non-automated processing of personal data is carried out;
- keeping records of personal data storage devices;
- organizing backup and recovery of operability of personal data information systems and personal data modified or destroyed as a result of unauthorized access;
- setting password complexity requirements for access to personal data information systems;
- implementing antivirus control, preventing the introduction of malicious software (viruses) and software bookmarks into the corporate network;
- timely updating of software used in personal data information systems and information protection tools;
- regularly assessing the effectiveness of measures taken to ensure the security of personal data;
- detecting incidents of unauthorized access to personal data and taking measures to identify causes and eliminate possible consequences;
- monitoring the security measures taken and the protection levels of personal data information systems.
5. Website User Rights
5.1. The Website User has the right to receive information regarding the processing of their personal data, including the following:
- confirmation of the fact of personal data processing by the Operator;
- legal grounds and purposes for personal data processing;
- purposes and methods used by the Operator for personal data processing;
- the name and location of the Operator, information about persons (except Operator employees) who have access to personal data or to whom personal data may be disclosed based on an agreement with the Operator or based on federal law;
- processed personal data relating to the respective personal data subject, the source of its receipt, unless another procedure for providing such data is established by federal law;
- timeframes for personal data processing, including retention periods;
- the procedure for the subject to exercise rights as provided by the Federal Law “On Personal Data”;
- information about actual or intended cross-border data transfer;
- the name or full name and address of the person processing personal data on behalf of the Operator, if processing is or will be entrusted to such a person;
- other information provided by the Federal Law “On Personal Data” or other federal laws.
- confirmation of the fact of personal data processing by the Operator;
- legal grounds and purposes for personal data processing;
- purposes and methods used by the Operator for personal data processing;
- the name and location of the Operator, information about persons (except Operator employees) who have access to personal data or to whom personal data may be disclosed based on an agreement with the Operator or based on federal law;
- processed personal data relating to the respective personal data subject, the source of its receipt, unless another procedure for providing such data is established by federal law;
- timeframes for personal data processing, including retention periods;
- the procedure for the subject to exercise rights as provided by the Federal Law “On Personal Data”;
- information about actual or intended cross-border data transfer;
- the name or full name and address of the person processing personal data on behalf of the Operator, if processing is or will be entrusted to such a person;
- other information provided by the Federal Law “On Personal Data” or other federal laws.
5.2. The Website User has the right to request the Operator to clarify their personal data, block or delete it if the data is incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated processing purpose, and also to take measures to protect their rights as provided by law.
5.3. The Website User has the right to request a list of their personal data provided to the Operator for processing in a structured, universal, and machine-readable format and to instruct the Operator to transfer this data to a third party, if technically feasible. In this case, the Operator is not responsible for actions taken by the third party with the personal data.
5.4. All questions regarding the processing of personal data should be sent to: admin@zozi.club.
6. Liability
6.1. The User is fully responsible for complying with the legislation of the client’s country, including but not limited to laws on advertising, protection of copyright and related rights, protection of trademarks and service marks. This includes full responsibility for the content and form of materials in cases of quoting or otherwise using information obtained through the use of Website services.
7. Final Provisions
7.1. The Operator has the right to amend this Policy unilaterally in the event of changes to the legal regulations of the Russian Federation, as well as at its own discretion.
7.2. Compliance with the requirements of this Policy is monitored by the person responsible for organizing the processing of personal data.
7.3. Persons guilty of violating the rules governing the processing and protection of personal data bear material, disciplinary, administrative, civil, or criminal liability in accordance with the legislation of the Russian Federation.
8. Agreement to Receive Promotional and Informational Emails
By registering on our service, you confirm your consent to receive promotional and informational emails, which may include news, promotions, special offers, and other information related to our service’s offerings.
We guarantee that each email sent will contain a link to unsubscribe from future mailings. You can unsubscribe at any time by clicking the link at the bottom of the email.
We guarantee that each email sent will contain a link to unsubscribe from future mailings. You can unsubscribe at any time by clicking the link at the bottom of the email.
9. Company Information
Domain Name Information:
We are an international savings service operating in multiple domain zones. Zones may change and be expanded. As of now, in the CIS region, we operate under the domain "ru - zozi.ru", and in the rest of the world under "cash - zozi.cash".
Legal Identifiers:
For Asia, Kazakhstan, CIS: CASHBACK HUB LLP, BINN 220440025877, Kazakhstan, Almaty.
For the USA, Canada, Australia, the UK, and Europe: "EDGE EVOLUTION LLC" United States of America, Florida 7901 4TH ST N STE 30 ST PETERSBURG FL 33702 +1-267-405-0710