SIBERCORP

SIBERCORP

Personal Data Processing Policy

A plain-language explanation of how we process data submitted with requests to source, manufacture, and supply goods from China.

Last updated: 24 July 2026

1. Data Controller and Scope

The personal data operator responsible for data submitted through sibercorp.ru is ООО “Финсмарт Логистик”, 47 Michurina Street, Tomsk, Russia. This Policy applies to requests submitted through the request form and to subsequent business correspondence.

2. Data We Collect

Users may provide their name, company name, phone number, email address, preferred contact method, project description, quantity, timeframe, budget, requirements for materials, packaging, and labeling, and attached files.

To protect the form and record consent, we automatically collect the IP address, browser information, the times at which the form was opened and submitted, the date of consent, and a record that consent was given. Please do not attach special categories of personal data, documents, passwords, or commercial information that is not required to assess your request.

3. Purposes and Basis for Processing

We use the data to receive and assess the request, contact the requester, clarify requirements, prepare an estimate or proposal, coordinate subsequent work, and protect the form from misuse.

The basis for processing is the user’s consent, indicated through the required checkbox before the form is submitted. A request cannot be submitted without a name, at least one contact detail, a description of the task, and consent.

4. File Storage and Protection

Requests are stored in a database, while files are stored in a non-public directory outside the publicly accessible area of the website. Files are assigned random system names and cannot be accessed by their original names or through a directory listing.

An employee receives an individual link containing an unpredictable token. By default, the link remains valid for 30 days. Once the link expires, the file can no longer be downloaded, but expiration alone does not mean that the request or file is immediately deleted.

5. Retention Period

Data and files are retained until work on the request is complete, but normally for no longer than three years from the date of the last interaction. Once the purpose of processing has been fulfilled, they are deleted or anonymized unless longer retention is required to perform a contract, protect legitimate interests, or comply with legal requirements.

6. Access and Disclosure

Access is limited to employees and contractors who need it to process the request, as well as hosting and email infrastructure providers to the extent necessary. The data is neither published nor sold.

If fulfilling the request requires information to be shared with a factory, carrier, or another participant in the supply chain, the specific data to be shared and the appropriate method of exchange will be agreed separately.

7. User Rights

Users may request information about the processing of their data, correction, restriction, or deletion of that data, and may withdraw their consent. Requests can be sent to finsmartlogistik@yandex.ru. To protect the data, the operator may ask the requester to confirm their identity.

Withdrawal of consent ends further processing, except where retaining the data is permitted or required by law.