Privacy Policy Regarding the Processing of Personal Data in the “POLARIS IQ Home” Mobile Application

Moscow

Version dated August 1, 2026

 

Approved by
General Director
AGI Electronics LLC
S. A. Sholokh

1.        Introductory Provisions
1.     
1.1.    This Personal Data Processing Policy (hereinafter referred to as the “Policy”) is issued and maintained by AGI Electronics Limited Liability Company, Primary State Registration Number (OGRN) 1207700169687, Taxpayer Identification Number (INN) 9725032535, registered address: 11 Ordzhonikidze St., Bldg. 3, Floor 4, Room I, Office 13 (hereinafter referred to as the “Operator”), in accordance with Clause 2, Part 1, Article 18.1 of Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data,” establishes the purposes of personal data processing, the procedure and conditions for such processing, and measures to ensure its security.
1.2.   This Policy establishes the procedure and conditions governing the Operator’s processing of personal data obtained in the “POLARIS IQ Home” mobile application (hereinafter referred to as the “Application”). The Policy sets forth provisions aimed at ensuring compliance with the legislation of the Russian Federation on personal data processing.
1.3.   Use of the Application and/or provision of personal data to the Operator means that the User has read and understood this Policy and its terms. If the User does not agree with the Policy, the User must discontinue use of the Service.
1.4.   All matters related to the processing of personal data that are not addressed in this Policy shall be governed by the applicable legislation of the Russian Federation on personal data.

2.       Terms
2.1. The following terms and definitions are used in this Policy in accordance with this section:

“Personal Data”

(abbreviated as “PD”)

any information relating directly or indirectly to an identified or identifiable individual.

 

“Personal Data Operator”

(abbreviated as the “Operator”)

 

a state authority, municipal authority, legal entity or individual that, independently or jointly with other persons, organizes and/or carries out the processing of personal data, as well as determines the purposes of personal data processing, the categories of personal data subject to processing, and the actions (operations) performed with personal data. For the purposes of this Policy, the Personal Data Operator is AGI Electronics LLC.

 

“Personal Data Subject”

an individual who is directly or indirectly identified by means of personal data and whose personal data is being processed.

 

“Processing of Personal Data”

any action (operation) or set of actions (operations) performed with personal data, with or without the use of automation tools, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data.

 

“Automated Processing of Personal Data”

processing of personal data using computer technology.

 

 

 

“Cross-Border Transfer of Personal Data”

transfer of personal data to the territory of a foreign state to a foreign state authority, foreign individual or foreign legal entity.

 

 

“Provision of Personal Data”

actions aimed at disclosing personal data to a specific person or a specific group of persons.

 

 

“Destruction of Personal Data”

actions resulting in the inability to restore the content of personal data in a personal data information system and/or resulting in the destruction of physical media containing personal data.

 

 

“Blocking of Personal Data”

temporary suspension of personal data processing (except where processing is necessary to clarify the personal data).

 

 

“Application”

 

a computer program in the form of a mobile application called “POLARIS IQ Home,” intended for use on the User’s mobile devices in accordance with its intended purpose.

 

 

“152-FZ”

Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data.”

 

 

“User”

 

a person using the Application.

 

 

“Technical Data”

information automatically collected when using the Application, including User and device identifiers, information about the software and hardware, the Application version, as well as other data necessary to ensure the proper functioning and security of the Application.

 

 
3.       Principles of Personal Data Processing
3.1. The Operator processes PD in accordance with the following principles:
¾       PD shall be processed lawfully and fairly;
¾       PD processing shall be limited to the achievement of specific, predetermined and legitimate purposes;
¾       PD shall not be processed in a manner incompatible with the purposes of personal data collection;
¾       Databases containing PD, the processing of which is carried out for purposes that are incompatible with each other, shall not be combined;
¾       Only PD that are relevant to the purposes of their processing shall be processed;
¾       The content and scope of the PD processed shall correspond to the stated purposes of processing;
¾       The PD processed shall not be excessive in relation to the stated purposes of their processing;
¾       The accuracy, sufficiency and relevance of PD shall be ensured in relation to the purposes of processing;
¾       PD shall be stored in a form that allows the PD Subject to be identified, for no longer than necessary to achieve the purposes of PD processing, and shall be destroyed once the purposes of processing have been achieved or when there is no longer a need to achieve them;
¾       PD shall be processed in a manner that ensures their security, using appropriate legal, technical and organizational measures.

 

4.       Purposes of Personal Data Processing
4.1. Personal data may be processed only for specific, predetermined and legitimate purposes. Processing that is incompatible with the purposes of personal data collection shall not be permitted.
4.2. The Operator processes personal data in the Service for the following purposes:

Purpose No. 1

User registration, account creation and provision of access to the Application

1.1.   Categories of Personal Data Subjects

Users.

1.2.   Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

1.3.   Categories and List of Personal Data Processed

¾     Other personal data.

¾     telephone number;

¾     email address;

¾     User’s name;

¾     User account identifier (ID);

¾     photograph (if provided, not for identification purposes);

¾     gender;

¾     date of birth;

¾     weight, height;

¾     information about the User’s habits.

1.4.   Personal Data Processing Period

During the term of the User Agreement and for 3 years after its termination on any grounds.

1.5.   Methods of Personal Data Processing

Actions performed using automated means with respect to PD: collection, creation, recording, systematization, accumulation, storage, retrieval, use, clarification (updating, modification), combination (linking), blocking, depersonalization, deletion and destruction.

 

Purpose No. 2

User authentication and ensuring secure access to the User’s account

 

2.1.    Categories of Personal Data Subjects

Users.

2.2.   Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

2.3.   Categories and List of Personal Data Processed

Other personal data.

¾     telephone number;

¾     email address;

¾     authentication data obtained through third-party services;

¾     User account identifier (ID);

¾     session information;

¾     technical data required to verify access;

2.4.   Personal Data Processing Period

During the term of the User’s account and for 90 days after its deletion by the User.

2.5.   Method of Personal Data Processing

Actions performed using automated means with respect to PD: collection, recording, verification, storage, use, clarification (updating, modification), combination (linking), blocking, depersonalization, deletion and destruction.

 

Purpose No. 3

Ensuring the connection, configuration and remote control of compatible smart devices, execution of User commands, display of device status, synchronization of settings, and proper functioning of the Application

3.1.    Categories of Personal Data Subjects

Users.

3.2.   Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

3.3.   Categories and List of Personal Data Processed

Other personal data.

¾     account data;

¾     User account identifier (ID);

¾     information about connected devices (device identifiers, serial numbers, device model);

¾     information about the device’s association with the User’s account;

¾     device name assigned by the User;

¾     command execution logs and information about device status;

¾     technical data required to connect and interact with the devices.

3.4.   Personal Data Processing Period

Until the User ceases to use the relevant device (unlinks the device from the account) or deletes the account, whichever occurs first.

3.5.   Method of Personal Data Processing

Actions performed using automated means with respect to PD: collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (where necessary, to the device manufacturer and other persons responsible for ensuring the functioning of the device), depersonalization, blocking, deletion and destruction.

 

Purpose No. 4

Ensuring the connection and interaction between the Application and smartwatches, displaying information transmitted by the device, and monitoring activity and other indicators

4.1.   Categories of Personal Data Subjects

Users.

4.2.  Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

4.3.  Categories and List of Personal Data Processed

Other personal data.

¾     User account data;

¾     smartwatch identifiers;

¾     information about the device model;

¾     information about connection and synchronization;

¾     data transmitted by smartwatches (including information about physical activity, workouts, number of steps, calorie expenditure, sleep, measurements recorded by the device, as well as other data depending on the device model and permissions granted by the User);

¾     technical logs of synchronization and device operation. ID;

¾     surname, name;

¾     User account identifier (ID);

¾     gender;

¾     date of birth;

¾     weight, height;

¾     information about the User’s habits (smoking, consumption of sweets, coffee, wine, etc.).

4.4.  Personal Data Processing Period

Throughout the period during which the User uses the smartwatch together with the Application, or until the relevant function is discontinued (the device is unlinked) or the account is deleted, whichever occurs first.

4.5.  Method of Personal Data Processing

Actions performed using automated means with respect to PD: collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (if necessary to ensure interaction with smartwatches and the functioning of the Application), depersonalization, blocking, deletion and destruction.

 

Purpose No. 5

Ensuring the functioning of the Voice Assistant, processing the User’s voice and text requests using artificial intelligence technologies, generating responses, executing commands to control compatible devices, and providing informational and reference materials

5.1.     Category of Personal Data Subjects

Users.

5.2.    Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

5.3.    Category and List of Personal Data Processed

Other personal data.

¾     User account data (ID);

¾     text queries;

¾     voice messages (when using voice input);

¾     automatically generated text transcriptions of voice messages;

¾     content of queries and commands;

¾     information about the results of processing queries;

¾     technical information about the interaction session (date and time of the request, session identifier, information about the device and Application version);

¾     other data voluntarily provided by the User while interacting with the Voice Assistant.

5.4.    Personal Data Processing Period

For as long as the User uses the Voice Assistant functionality or until the User deletes the relevant interaction history (if such functionality is available) or deletes the account, whichever occurs first.

5.5.     Method of Personal Data Processing

Actions performed using automated means in relation to Personal Data: collection, recording, systematization, accumulation, storage, updating (including modification), retrieval, use, transfer, depersonalization, blocking, deletion, destruction.

 

Purpose No. 6

Ensuring the functioning of the Application, identification of the User’s session, retention of User settings, and proper functioning of the Application as a whole

2.    

3.    

4.    

6.1.   Category of Personal Data Subjects

Users.

 

6.2.  Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

6.3.  Category and List of Personal Data Processed

Other personal data.

¾     User account identifier (ID);

¾     Application installation identifier;

¾     session identifiers;

¾     authorization and refresh tokens (access token, refresh token);

¾     device information (model, manufacturer, operating system version, system language, Application version);

¾     IP address; network connection information; technical logs of the Application’s operation;

¾     information about failures, errors and User actions related to the functioning of the Application.

6.4.  Personal Data Processing Period

For as long as the User’s account remains active and, for certain technical data, no longer than objectively necessary to ensure the security, authorization and functioning of the Application.

6.5.  Method of Personal Data Processing

Actions performed using automated means in relation to Personal Data: collection, recording, systematization, accumulation, storage, updating (including modification), retrieval, use, depersonalization, blocking, deletion, destruction.

 

Purpose No. 7

Promoting the Application through marketing communications, including advertising messages, notifications about new features, special offers and promotions

 

7.     

7.1.    Category of Personal Data Subjects

Users.

7.2.   Legal Basis for Personal Data Processing

User consent to the processing of personal data (such consent is given by clicking the relevant checkbox to opt in to advertising communications).

 

7.3.   Category and List of Personal Data Processed

Other personal data.

¾     name;

¾     email address;

¾     telephone number;

¾     account information;

¾     information about the current subscription and use of the Application (where necessary to personalize messages);

¾     User preferences regarding how messages are received.

7.4.   Personal Data Processing Period

Until the User withdraws consent to receive advertising communications or the Operator ceases to process Personal Data for the relevant purposes.

7.5.   Method of Personal Data Processing

Actions performed using automated means in relation to PD: collection, recording, accumulation, storage, retrieval, use, clarification (updating, modification), combination (linking), blocking, depersonalization, deletion, and destruction.

Purpose No. 8

Provision of paid Application functionality and payment processing

 

8.    

8.1.   Categories of Personal Data Subjects

Users.

8.2.  Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

8.3.  Categories and List of Personal Data Processed

Other personal data.

¾     subscription plan information;

¾     subscription status;

¾     payment information;

¾     information about transactions;

¾     information about the linked bank card;

¾     other payment data.

8.4.  Personal Data Processing Period

During the term of the User Agreement + 3 years after its termination or until the User withdraws information about the payment method.

8.5.   Method of Personal Data Processing

Actions performed using automation tools in relation to PD: collection, recording, storage, use, transfer, clarification, blocking, depersonalization, deletion, destruction.

Purpose No. 9

Receiving, reviewing and processing User requests and providing User support

 

9.    

9.1.   Categories of Personal Data Subjects

Users

9.2.   Legal Basis for Personal Data Processing

User Agreement between the Operator and the User (Article 6, Part 1, Clause 5 of 152-FZ).

9.3.   Categories and List of Personal Data Processed

Other personal data.

¾     name;

¾     telephone number;

¾     email address;

¾     content of the User’s request/feedback;

¾     technical information related to the request (e.g., information about the device, Application version, error description);

¾     screenshots and other materials voluntarily provided by the User.

9.4.   Personal Data Processing Period

For the period necessary to review the request, provide a response and complete the interaction with the User, but no longer than 3 years from the date of the last interaction with the User.

9.5.   Methods of Personal Data Processing

Actions performed using automation tools in relation to PD: collection, recording, use, deletion, destruction.

5.        Procedure and Conditions for Personal Data Processing
5.1. Services provided by computing capacity providers may be provided by the following entities, and the computing capacity itself may be located at the following addresses, exclusively within the territory of the Russian Federation:
 

1.1.1.                          

Yandex.Cloud LLC

INN 7704458262

1 Poiskovaya St., Bldg. 2, Energetik microdistrict, Vladimir, Vladimir Region, 600902


5.2. For the purposes of PD processing, the Operator may transfer PD to third parties by entrusting the processing of PD to third parties, without entrusting them with such processing, and may also receive PD from third parties where there is an appropriate legal basis. If the Operator entrusts the processing of personal data to another person, the Operator shall be liable to the personal data subject for the actions of such person. A person processing personal data on behalf of the Operator shall be responsible to the Operator for the security of personal data and compliance with the requirements of applicable legislation on personal data.
5.3. The Operator does not carry out cross-border transfers of PD.
5.4. The Operator does not process special categories of PD concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, or intimate life.
5.5. The Operator does not process biometric PD containing information that characterizes the physiological and biological characteristics of an individual and makes it possible to establish their identity.
5.6. The Operator does not make decisions that produce legal effects in relation to a PD subject or otherwise affect the rights and legitimate interests of PD subjects based solely on automated processing of personal data. Data that produce legal effects or affect the rights and legitimate interests of a PD subject shall be reviewed by authorized employees of the Operator before being used.
5.7. The Operator does not publish the personal data of a PD subject in publicly accessible sources without their prior consent.
5.8. The Operator processes PD using automated means in compliance with the requirements for automated processing of personal data established by the Law on Personal Data and regulatory legal acts adopted pursuant thereto.
5.9. Information relating to PD that becomes known to the Operator constitutes confidential information and is protected by law.
5.10. The Operator uses the information received from the PD subject exclusively for the purposes of PD processing.
5.11. The Operator uses the information received from the PD subject exclusively for the purposes of PD processing.

6.       Access to the Functions of the User’s Mobile Device
6.1. For the purposes of implementing the functionality of the Application, the Operator may request access to the functions of the User’s mobile device through the operating system’s standard system permissions, including:
6.2. Permission to access the User’s location (geolocation): used when scanning for devices via Bluetooth and when receiving data from connected devices;
6.3. Permission to use Bluetooth and Wi-Fi: used for pairing and data transfer with connected devices;
6.4. Permission to use the microphone and audio device: used for voice input and operation of the Voice Assistant;
6.5. Permission to access the camera: used for scanning QR codes when connecting devices and for object recognition.
6.6. Permission to use the Internet: used for data transfer, checking the connection, and operating service functions;
6.7. Permission to send push notifications to the User;
6.8. Permission to access information transmitted by sensors of various devices and household appliances (e.g., room temperature and humidity levels; room maps created by robot vacuum cleaners; the amount of water remaining in a kettle, etc., depending on the type of device used).
6.9. Access to the functions of the mobile device is granted solely with the User’s consent through the mobile device’s operating system permission mechanisms.
6.10. The User may at any time deny or restrict the relevant permissions in the settings of their mobile device, while acknowledging that this may restrict or prevent the use of certain functions of the Application.

7.       Voice Data and User Search Query Data
7.1. For the purposes of performing the User Agreement regarding the provision of the Voice Assistant functionality, the Operator may collect and process the User’s personal data specified in Clause 5.3 of Section 4 of the Policy.
7.2. The collection of the User’s voice data does not constitute the processing of their biometric data, since the Operator does not intend to establish the User’s identity based on such data and does not use it to identify the User.
7.3. Voice data is collected exclusively for the purposes of implementing the “Voice Assistant” functionality of the Application and performing speech recognition to convert the User’s request into a command for a device connected to the User’s Application or into a text search query, and to provide the User with search results.
7.4. Voice data is processed for a limited period of time and only for as long as necessary to recognize it and convert it into a text search query. Upon completion of the recognition process, voice data is not stored and is destroyed.
7.5. User search queries and search results may be stored in the User’s profile in the Application solely for the purposes of:
7.5.1.       providing the User with a history of their queries;
7.5.2.      improving the quality of the Application’s functionality;
7.5.3.      protecting the rights and legitimate interests of the Operator where necessary.
7.6. Voice and search data is not transferred to third parties, except where expressly provided for by the legislation of the Russian Federation or where necessary for the functioning of the Application and the provision of the relevant functionality to the User (e.g., for the technical processing of search queries using artificial intelligence algorithms).

8.       Measures to Ensure the Security and Protection of Personal Data
8.1. The Operator takes necessary and sufficient organizational and technical measures to protect the PD of Personal Data Subjects from unlawful or accidental access, destruction, modification, blocking, copying, dissemination, and other unlawful actions by third parties. These measures include: issuing internal regulations on the processing and security of PD, as well as regulations establishing procedures aimed at preventing and detecting violations of the legislation of the Russian Federation and eliminating the consequences of such violations; using information security measures that have undergone a conformity assessment procedure to ensure compliance with the requirements of the legislation of the Russian Federation in the field of information security; detecting unauthorized access; restoring PD; establishing rules governing access to PD; conducting internal control and assessing the effectiveness of the measures applied.
8.2. To prevent unauthorized access to PD, the Operator has implemented measures to protect PD, including:
¾     appointing persons responsible for organizing the processing and ensuring the security of PD;
¾     conducting internal control over the Operator’s compliance with 152-FZ, including the requirements for the protection of PD;
¾     monitoring the receipt and processing of requests and inquiries from PD subjects or their representatives;
¾     restricting the number of persons having access to PD;
¾     ensuring the security of PD storage media;
¾     differentiating PD subjects’ access to information resources and hardware and software used for information processing;
¾     implementing a system for registering and recording the actions of PD subjects in personal data information systems.

9.       Conditions for Terminating the Processing of Personal Data and Procedure for Their Destruction
9.1. The Operator shall terminate PD processing in the following cases:
9.1.1.        the purpose of PD processing has been achieved and/or the established period for PD processing has expired, including any period established by the legislation of the Russian Federation;
9.1.2.       the need to achieve the purposes of PD processing has ceased to exist;
9.1.3.       unlawful processing of PD has been identified;
9.1.4.       it is impossible to ensure the lawfulness of PD processing;
9.1.5.       the PD subject has withdrawn their consent to PD processing (in the absence of another lawful basis for PD processing);
9.1.6.       the Operator has received a request from the PD subject to terminate PD processing, except in cases provided for by law;
9.1.7.       termination of the Operator’s activities.
9.2. If it is impossible to destroy PD before the expiry of the periods established by 152-FZ, the Operator shall block such PD or ensure that it is blocked (if PD is processed by another person acting on behalf of the Operator) and shall ensure that the PD is destroyed within a period not exceeding 6 (six) months, unless another period is established by the legislation of the Russian Federation.
9.3. PD shall be destroyed in a manner that makes it impossible to restore such PD. If PD cannot be destroyed without causing such damage to the physical medium containing the PD as would prevent its further use for its intended purpose, both the PD and the physical medium containing the PD shall be destroyed.
9.4. Confirmation of the destruction of PD shall be carried out in accordance with the requirements established by the authorized body for the protection of the rights of PD subjects.
9.5. To destroy PD, the Operator uses internal data erasure tools incorporating a data destruction function that complies with the requirements of the legislation of the Russian Federation.



10.       Procedure for Ensuring the Rights of Personal Data Subjects
10.1. The Operator and its officials shall bear civil, administrative and other liability for non-compliance with the principles and conditions of processing the PD of individuals, as well as for the disclosure or unlawful use of PD in accordance with the legislation of the Russian Federation.
10.2. The Operator provides unlimited access to this Policy by publishing it at: https://polaris.ru/privacy-app/.
10.3. A personal data subject may also exercise all rights guaranteed to them by 152-FZ and obtain clarification on matters concerning the processing of their personal data by contacting the Operator at the following email address: info@agiel.ru
10.4. The Operator ensures the rights of personal data subjects and fulfills its obligations in accordance with the procedure established by Chapters 3 and 4 of No. 152-FZ.
10.5. The information specified in Part 7 of Article 14 of No. 152-FZ shall be provided to the Personal Data Subject or their representative upon receipt of a request from the Personal Data Subject or their representative within 10 (ten) business days.
10.6. The request must contain information confirming the Personal Data Subject’s involvement in relations with the Operator, confirming the fact that the Operator processes personal data, and the signature of the Personal Data Subject or their representative. If these requirements are not met, the Operator may refuse to provide the requested information.
10.7. The Operator undertakes to provide the Personal Data Subject or their representative, free of charge, with an opportunity to review the personal data relating to such Personal Data Subject. Within a period not exceeding 7 (seven) business days from the date on which the Personal Data Subject or their representative provides information confirming that the personal data is incomplete, inaccurate or outdated, the Operator undertakes to make the necessary amendments thereto.
10.8. Within a period not exceeding 7 (seven) business days from the date on which the Personal Data Subject or their representative provides information confirming that such personal data was obtained unlawfully or is not necessary for the stated processing purpose, the Operator undertakes to destroy such personal data. The Operator undertakes to notify the Personal Data Subject or their representative of the amendments made and measures taken and to take reasonable measures to notify third parties to whom the personal data of such Personal Data Subject was transferred.

11.        Final Provisions
11.1. The Operator reserves the right to amend this Policy without prior notice to Users. The Operator shall review the Policy as necessary.
11.2. The Policy shall remain in effect indefinitely until replaced by a new version in order to keep it up to date.
11.3. All matters not regulated by this Policy shall be governed by the applicable legislation of the Russian Federation.
11.4. All possible disputes shall be resolved in accordance with the legislation of the Russian Federation at the Operator’s place of location.
11.5. Before filing a claim with a court, the User must comply with the mandatory pre-trial dispute resolution procedure and submit a corresponding written claim to the Operator. The period for responding to a claim shall be 30 (thirty) calendar days.

12.       Operator Details
 
AGI Electronics LLC
OGRN 1207700169687
INN 9725032535,
Registered address: 11 Ordzhonikidze St., Bldg. 3, Floor 4, Room
I, Office 13, Moscow, 115419
Email: info@agiel.ru
By continuing to use our website, you consent to the processing of cookies, which include: location information; type, language and version of the operating system and browser; information about the device used. The data is processed to provide our services and improve the quality of our website.

More detailed
OK