Skip to content

Personal Data Processing Policy

Rules for processing and protecting the personal data of website visitors and group clients.

Complete the fields in square brackets before publishing.

Enter the legal entity details, current retention periods and contractors actually used. Remove this notice after completing the policy.

Effective date: [dd.mm.yyyy]

1. General provisions

This Personal Data Processing Policy (the “Policy”) sets out how [full name of the data controller] (the “Controller”) processes and protects personal data when people use pumptech.by, contact the Controller or otherwise interact with it.

The Policy has been prepared in accordance with the Law of the Republic of Belarus of 7 May 2021 No. 99-Z “On Personal Data Protection” and other applicable Belarusian legislation. It applies to personal data received through the website, by telephone or email, in documents and through other interactions.

The Controller processes personal data lawfully, fairly and transparently, only for specified purposes, to the extent necessary for those purposes, and no longer than the purposes or applicable law require.

2. Controller details

Name
[full legal name of the company / sole proprietor]
Taxpayer identification number
[taxpayer identification number]
Registered address
[registered address]
Personal data contact
[email] · [postal address] · [telephone]

3. Data processed and purposes of processing

Enquiries through website forms, by telephone and by email

Data: name, telephone number, email address, details of the enquiry, equipment details and files attached to the request.

Purpose: to receive and process the enquiry, prepare a response, select equipment or services, continue business communications, and, where applicable, conclude or perform a contract.

Legal basis: the data subject’s consent given when submitting the form; where applicable, conclusion or performance of a contract or another basis provided by law.

Retention period: [specify the actual retention period for enquiries and attachments].

Enquiries about products, services and cooperation

Data: name, position, organisation, telephone number, email address and other information voluntarily provided by the person.

Purpose: to prepare a quotation, agree cooperation terms, conduct negotiations and fulfil agreed arrangements.

Legal basis: consent, steps to conclude or perform a contract, and other grounds provided by law.

Retention period: [specify the actual retention period].

Information and marketing communications

Data: name and email address or telephone number.

Purpose: to send information about the Controller’s products, services, events and offers.

Legal basis: the data subject’s separate consent. It may be withdrawn using the same method by which it was given or through [specify the withdrawal method: unsubscribe link / email / other method].

Retention period: until consent is withdrawn or until [specify the period], unless the law requires otherwise.

Website operation, cookies and external services

Data: IP address, technical information about the browser and device, cookies, information about activity on the website and other data transmitted technically during a visit.

Purpose: to operate and secure the website, display its content correctly and, where consent has been given, analyse traffic and improve the website.

Legal basis: consent to non-essential cookies and other grounds provided by law. The use of cookies should be explained in [the cookie policy / cookie banner].

Important: the website uses or may use third-party services, including Google Maps and Google Fonts. Before publication, list all services actually connected, their recipients and countries of processing: [hosting provider], [email service], [CRM], [analytics], [maps], [other].

4. Data recipients and processing on behalf of the Controller

Only employees who need personal data to perform their duties have access to it. The Controller may entrust processing to authorised persons, such as hosting, corporate email, CRM, technical support and delivery providers, under contracts and solely for the specified purposes.

The Controller is responsible to the data subject for the actions of an authorised person carrying out processing entrusted to them. List of authorised persons: [insert the actual list or explain how to obtain it].

Personal data may be transferred to third parties where there is a lawful basis, including the data subject’s consent, performance of a contract or a legal requirement.

5. Cross-border transfers

Personal data is transferred across borders only in compliance with the laws of the Republic of Belarus. If data is transferred to a country that does not provide an adequate level of protection for data subjects’ rights, the Controller first obtains the data subject’s consent after informing them of the risks, or relies on another ground provided by law.

[State whether cross-border transfers take place and identify the countries, recipients and purposes. If there are no such transfers, replace this text with: “The Controller does not transfer personal data across borders.”]

6. Security measures

The Controller takes legal, organisational and technical measures to protect personal data against unlawful or accidental access, alteration, blocking, copying, distribution, disclosure, deletion and other unlawful actions.

  • appoints a person or unit responsible for internal control of personal data processing;
  • approves internal policies on personal data processing and protection and establishes access procedures;
  • grants access only to authorised employees, informs them of legal requirements and provides training;
  • uses technical and organisational safeguards appropriate to the nature of the data and the risks of processing;
  • updates, blocks or deletes inaccurate or unlawfully obtained data where required by law.

7. Rights of the data subject

Unless the laws of the Republic of Belarus provide otherwise, a data subject may:

  • receive information about the processing of their personal data, including its purposes, retention periods and recipients;
  • receive information about the disclosure of their personal data to third parties;
  • request correction, amendment, blocking or deletion of inaccurate or unlawfully obtained data;
  • request that processing cease and/or that data be deleted where there is no legal basis for processing;
  • withdraw consent to personal data processing at any time without giving a reason;
  • appeal the Controller’s actions, omissions or decisions that violate their rights to the authorised personal data protection authority.

8. How to submit a request or withdraw consent

A request to exercise rights may be sent to the Controller at [postal address] or electronically, signed with an electronic digital signature, to [email for requests]. Consent given through an electronic form on the website may also be withdrawn in the manner specified when it was obtained or by contacting [email].

The request should include information sufficient to identify the applicant and the data processed by the Controller, describe the request, and bear a handwritten or electronic digital signature where required by law. The Controller may request information needed to identify the applicant and fulfil the request.

9. Changes to the Policy

The Controller may update this Policy when legislation, personal data processing methods or website operation change. The current version is always available on this page. A new version takes effect when published unless it states otherwise.

10. Contact details

For questions about personal data processing, exercising your rights or withdrawing consent, contact: [contact person or unit], [email], [telephone], [postal address].