EAEU
EAEU: privacy framework for supplies to Russia
Privacy annex for EAEU supply routes: suppliers, logistics, SPOT, DOPP, QR, RNPT and related documents.
Status: Regional framework; country annexes and legal approval remain required
Legal information
Website: bernev.com
International privacy information
International landing pages, enquiry forms, the Telegram calendar, LinkedIn account-based marketing and future language versions are subject to the main policy and the relevant country's privacy requirements.
EAEU
Privacy annex for EAEU supply routes: suppliers, logistics, SPOT, DOPP, QR, RNPT and related documents.
Status: Regional framework; country annexes and legal approval remain required
Kazakhstan
Kazakhstan privacy annex covering the ru-KZ page, planned kk-KZ version, trade and consignment documents, traceability, trade routes and initial enquiries.
Status: Draft; local legal and language approval pending
Belarus
Belarus privacy annex covering suppliers, carriers, transit, navigation seals and Russian disputes.
Status: Draft; local legal and language approval pending
Armenia
Armenia privacy annex covering intermediaries, single-window processes, supply routes and Russian disputes.
Status: Draft; local legal and language approval pending
Kyrgyzstan
Kyrgyzstan privacy annex covering advance information, trade routes, intermediaries and Russian disputes.
Status: Draft; local legal and language approval pending
China
China privacy annex covering PIPL/CAC, supplier enquiries, English information for in-house counsel, documents and Russian disputes.
Status: Draft; public Chinese-language enquiry forms remain blocked pending legal and language approval
Global
The bernev.com service-provider map covers GA4, the Telegram bot, YouTube, LinkedIn, email, bookings and pre-launch verification for international pages.
Status: Implementation checklist; legal approval pending
This Personal Data Processing Policy sets out the rules for processing personal data through https://bernev.com (the Website). It is an internal policy based on Russian law and principles of good faith and proportionality. It covers automated and manual collection, recording, organisation, accumulation, storage, correction, retrieval, use, disclosure or access, restriction, deletion and destruction.
This Policy applies when you use the Website or its listed communication channels, including messaging, email, telephone and video calls. Contact may require processing for the stated purpose, but a valid legal basis is still required. The rules on cross-border transfers and your data rights also apply. Using a channel is not blanket consent to unrelated processing.
The person determining the processing remains accountable for it. This Policy sets out requirements relevant to regulatory checks, disputes and data-rights requests; it is not proof of compliance by itself. It must be read consistently with the law, giving priority to data-subject rights while respecting the Operator's lawful interests. The rules on legal bases and processing records also apply.
These definitions apply throughout the Policy, including its provisions on data-subject rights and the Operator's responsibilities. They must be read with the rules on third-party disclosures, processing entrusted to third parties and cross-border transfers.
Personal data means information relating directly or indirectly to an identified or identifiable individual. This includes information that can identify someone when combined with other data, such as an IP address, device identifiers or correspondence. The same definition applies to cookies, web analytics and security measures.
The personal data operator is Andrey Eduardovich Bernev, an individual resident in Georgia. References to the Website Administration mean this Operator.
A data subject is the individual whose personal data is processed. This includes a company representative acting in a business-to-business relationship.
Processing means any operation or set of operations involving personal data, including collection, recording, organisation, accumulation, storage, correction, retrieval, use, transfer, anonymisation, restriction, deletion and destruction.
Transfer means disclosing personal data to specified recipients or granting access to it, including entrusting processing to a third party. The term also applies to the Policy's rules on data-subject rights, processing procedures and records.
Cross-border transfer means transferring personal data to a foreign country or foreign recipient, subject to the applicable legal definition. The Policy's cross-border transfer rules also apply to transfers involving cookies and web analytics.
A personal data information system comprises the databases, technology and equipment used to process personal data. These systems must meet the Policy's security requirements.
Consent means a freely given, specific, informed and unambiguous indication of an individual's wishes, expressed through affirmative action. It must be recorded in line with the Policy's consent requirements and any applicable localisation and storage rules.
Confidentiality requires the Operator to prevent disclosure of personal data to third parties without consent or another lawful basis. This duty must be read with the Policy's security and interpretation rules.
Terms not defined here have the meaning given by applicable Russian law and relevant legal interpretation. The Policy's interpretation rules must respect that meaning.
The Policy is based on the Russian Constitution, Federal Law No. 152‑ФЗ on Personal Data, Federal Law No. 149‑ФЗ on Information, Information Technologies and Information Protection, and other applicable rules on processing, security and localisation. Relevant regulatory guidance must also be considered when interpreting the Policy and assessing responsibility.
The Policy takes a risk-based approach, reads legal requirements together and requires documented legal grounds and procedures. Each processing operation must have a defined purpose, a valid legal basis, a retention period and appropriate safeguards.
Personal data processing may be necessary to meet obligations to individuals or pursue the Operator's lawful interests. Processing purposes, legal grounds, responsibilities and record-keeping requirements must be considered together.
The personal data operator is Andrey Eduardovich Bernev, an individual resident in Georgia.
For personal data enquiries, use only the email address bernev_64@mail.com. You may request access, correction or deletion of your data, or withdraw consent, at this address. Explain the request and provide enough information to locate your correspondence. Do not attach a passport or your full case file to the first email.
The Operator is responsible for determining the purposes, means and scope of processing, controlling access and adopting internal procedures. Appointing authorised persons or contractors does not remove the Operator's responsibility for lawful processing or compliance with the Policy's third-party processing and security requirements.
Internal instructions must define responsibilities, authority and access restrictions, while limiting data to what is needed and keeping datasets separate. The Operator must document control, audit and incident-response procedures, with responsibilities and retention requirements clearly defined.
The Policy covers processing connected with the Website and related services, including enquiries, consultation requests, subscriptions, separately agreed document exchanges and technical browsing data. This is not an exhaustive list. Any forms or other processing must have a stated purpose and a valid legal basis. The Website has no public document-upload facility; document exchange remains subject to separate arrangements and the Policy's limits.
Linked third-party websites and services have their own privacy arrangements. This Policy does not govern their independent processing. That distinction does not remove the Operator's own legal duties, including providing relevant information about cross-border transfer risks and transfers involving cookies or web analytics.
The Policy covers information you actively provide and technical events such as cookies and access logs. Both are subject to the Policy's processing purposes, legal-basis requirements and retention limits.
Processing must be lawful, fair and limited to specified purposes and necessary data. Data must be accurate, kept no longer than permitted and treated as confidential. These principles apply together, alongside the legal-basis requirements; none overrides mandatory law.
Only data necessary for the stated purpose may be processed. It must not be used for incompatible purposes, and reasonable steps must keep it accurate and up to date. When the purpose ends, data must be destroyed under the Policy's retention and destruction rules, unless an overriding legal requirement applies.
priority to data-subject rights where the lawfulness of processing is in doubt.
The categories below reflect how people interact with the Website and the legal practice. Processing rules depend on the purpose and substance of the relationship, including any contractual or pre-contractual dealings, rather than a person's role alone.
A company representative's information may be needed for pre-contract discussions or work under a business engagement. The appropriate legal basis must still be assessed. The representative retains their data rights and the right to have requests considered under the Policy's request-handling procedures; a business role does not remove those protections.
participants in video consultations and other communications.
The data processed must match its purpose and legal basis, and the Operator must regularly check that no more is processed than necessary. The amount of information in an enquiry may vary, but that does not remove the duty to limit unnecessary processing.
The Website does not seek special categories of personal data. If documents exchanged by separate arrangement contain such information, processing requires an appropriate legal basis, heightened confidentiality and additional access restrictions. Applicable law governs how these safeguards are applied.
communication and mailing preferences, subject to separate consent.
Anyone providing another person's data must have a lawful basis and appropriate authority, and remains responsible for the lawfulness of that disclosure. This does not remove the Operator's own confidentiality and processing obligations.
Data is mainly provided voluntarily by the individual through enquiries, separately arranged document exchanges or the listed communication channels. It may also come from an authorised representative or counterparty, but only with appropriate authority and a lawful basis.
Data may be received through Website interfaces, email, messaging and other channels listed by the Operator. Technical data may also be collected automatically through server logs or analytics, subject to the Policy's cookie and web analytics rules, including applicable consent requirements.
information provided by company representatives.
Processing purposes must be specific and transparent, not open to broader interpretation. If a purpose changes, the Operator must establish a valid legal basis and inform the individuals concerned, respecting their data rights.
Each processing purpose must be linked to the relevant data categories and retention periods. Stating a purpose does not create consent. Where consent is required, it must be obtained separately under the Policy's consent rules.
sending publications with separate consent.
Personal data may be processed only on a lawful basis that can be documented. Without one, processing is not permitted. Anonymised web analytics may be used only where the applicable requirements are met; anonymisation does not remove the need for a lawful basis for any personal data processing involved.
Relying on a legitimate interest requires an assessment of proportionality and a balance between that interest and the individual's rights, consistent with the processing principles. Information supplied for a legal engagement, including legally significant documents, may be processed on a contractual or pre-contractual basis only where the conditions for that basis are met.
other grounds expressly provided by law.
Each legal basis must be used in a way that interferes with privacy no more than necessary. The Policy's data-minimisation, destruction, anonymisation and restriction requirements also apply.
Consent is a separate legal basis used where no other valid basis applies or where the law expressly requires it. It requires affirmative action and cannot be inferred merely from visiting the Website. The Policy's cookie, analytics and marketing rules also apply.
Consent records must show what was agreed, when and on what terms. Evidence must be kept in technical logs or other records, together with previous versions of the consent wording. These records are subject to the Policy's record-keeping and accountability requirements.
without consent, processing requires another valid legal basis.
When you request legal services, necessary data may be processed to assess the matter, prepare a proposal and agree terms. Where a valid pre-contractual basis covers those specific steps, separate consent may not be required. Processing must still be limited to the necessary data and stated purposes.
After an engagement is agreed, data may be processed to perform it, including preparing legal opinions, corresponding, representing the client and assembling evidence. The scope depends on the agreement and the nature of the instructions. Retention is subject to applicable law and the Policy's retention requirements.
using data on a lawful basis to defend the Operator's rights in a dispute.
Processing combines automated and manual operations. Information systems support storage, retrieval and access control. Manual work includes reviewing documents, preparing advice and considering legal positions.
Processing procedures must make each material step lawful, traceable and capable of being evidenced. This includes registering enquiries, organising documents, monitoring retention periods and recording subsequent destruction under the Policy's retention and destruction rules.
archiving, anonymising or destroying data in accordance with retention rules.
Disclosing personal data to a third party requires a lawful basis, such as an applicable contractual ground, legal obligation or consent. Entrusted processing must be covered by an agreement specifying the operations and the processor's confidentiality and security duties. The agreement must prohibit the processor from setting independent purposes for that processing. The Policy's security and record-keeping requirements also apply.
Only the data needed for the relevant purpose may be transferred. The Operator assesses contractors' ability to protect it and includes responsibility for confidentiality breaches in the agreement.
compliance with the processing agreement is subject to monitoring and audit.
Individuals retain the right to information about transfers of their data to third parties. Requests are handled under the Policy's data-rights and request-handling procedures.
A cross-border transfer requires a lawful basis and an assessment of the protection available in the recipient country. Even where data is stored locally, it may pass through foreign infrastructure. Individuals must receive relevant information about those transfers, including transfers involving cookies or analytics. The Policy's destruction, anonymisation and restriction requirements also remain applicable.
Before a cross-border transfer, the Operator must assess the applicable requirements and obtain separate consent where required. Choosing a communication channel requests communication through it; it does not replace any mandatory consent or other transfer requirement. You may decline that channel.
review communication channels when the legal framework changes.
Where applicable law requires localisation of Russian citizens' personal data, the Operator must meet those requirements, including initial storage in Russia. The Operator must identify and document the actual storage infrastructure and its location. Local storage does not replace other applicable processing duties.
External communication services may transfer data outside Russia. Where applicable law requires initial recording or storage in Russia, that requirement must be met alongside the rules on cross-border transfers and retention.
checks against the applicable infrastructure-security requirements.
Retention must be limited by the processing purpose, legal requirements and what is lawfully necessary to protect the Operator's rights. When the purpose ends, data must be destroyed or anonymised unless the law requires or permits continued retention.
Retention decisions take account of limitation periods, accounting and tax duties, and evidential needs. Relevant records may be retained until a dispute is finally resolved where a lawful basis permits this.
mailing consent: until withdrawal.
Data must be destroyed or anonymised when its purpose ends, consent is withdrawn or another legal requirement calls for it, unless retention remains necessary on another lawful basis to fulfil obligations or protect the Operator's rights. Processing may be restricted temporarily during a dispute or while accuracy is checked. The Policy's data-rights and request-handling procedures also apply.
Destruction methods must prevent data recovery, and the action must be recorded. Data anonymised for statistics or service improvement must not allow individuals to be re-identified. The Policy's web analytics requirements also apply.
recording destruction in a certificate or log.
The Operator must use organisational and technical safeguards against unauthorised access, loss, alteration, disclosure and other misuse. Safeguards must reflect the nature of the data, the scale of processing and identified risks, alongside incident-response and accountability requirements. They cannot guarantee that no incident will occur.
Under this Policy, the Operator must establish internal procedures, assign responsibilities and provide training. The Operator must check that confidentiality requirements are met. This Policy also requires encrypted communication channels, backups, malware protection and security-event monitoring.
contractor audits and checks on processing agreements.
A security incident is an event that compromises, or may compromise, the confidentiality, integrity or availability of personal data. The Operator must establish procedures to detect, record and respond to incidents, consistent with applicable law and the Policy's security requirements.
Following a significant incident, the Operator takes steps to contain its effects, assess harm and restore systems. Data subjects and authorities are notified where legally required. The incident and lessons learned are recorded and used to improve safeguards.
document the response and corrective action.
You have the rights provided by applicable law, including information about processing, correction, restriction or destruction of data, withdrawal of consent and the right to challenge the Operator's actions. Requests are subject to appropriate identity checks and protection of third-party rights under the Policy's request-handling procedures.
The Operator responds within its powers and the applicable legal deadlines. A request may be refused or limited only on lawful grounds, with an explanation.
the right to challenge the Operator's actions.
Requests sent through the designated privacy contact are registered. The Operator checks the requester's identity or authority, assesses the legal basis and responds within the statutory period.
Where necessary, the Operator may request proportionate additional information to identify the requester or clarify the request. Failure to provide it may prevent fulfilment only where the law permits that result. Your data rights remain applicable.
fulfil the request where required and record the result.
The Website uses cookies and local storage for site functions, preferences and consent records. Strictly necessary storage is separate from optional traffic analytics. On production hosts, Google Analytics runs only after explicit consent. Applicable consent and legal-basis requirements depend on the technology and processing purpose; describing data as anonymous does not by itself remove those requirements.
You can manage cookies through your browser, although restrictions may affect Website functions. Analytics are not used to make automated decisions with legal consequences for you.
marketing cookies only with consent.
Sending informational publications and advertising messages requires separate consent. Joining a mailing list is not a condition of receiving legal services, and consent may be withdrawn at any time.
Each mailing includes an opt-out. Marketing processing is limited to necessary data, which is not transferred to third parties unless an applicable lawful basis permits it, subject to the Policy's transfer requirements.
sharing mailing-list data with a third party requires a lawful basis and must meet the Policy's disclosure and processor-agreement requirements.
The Policy is interpreted under applicable Russian law. Mandatory law prevails over any conflicting provision, while unaffected provisions remain in force. Amendments take effect when published on the Website unless the new version states otherwise.
The Operator may review the Policy as legislation and legal practice change. Earlier versions are retained as part of the processing record. The Policy is publicly available and applies to processing through the Website and the Operator's related communication channels.
Internal procedures must record every material processing operation, including activity not visible in the interface, such as message routing, document-version archiving and checks on legal grounds. These records must support accountability and demonstrate how the Policy's legal-basis, processing and security requirements are met.
Internal record-keeping procedures must cover enquiries, consents, client files, processor appointments, destruction records and archives. They apply regardless of the scale of processing, while respecting data minimisation and retention limits.
The procedures below set out the basic requirements, not an exhaustive list. They may be supplemented as legal requirements and technology change, subject to the Policy's amendment and accountability rules.
The Operator must maintain an internal risk matrix assessing the likelihood of adverse consequences and the potential harm to individuals. The matrix is not public, but its findings must inform decisions on legal grounds, retention periods and security measures.
An impact assessment is undertaken when introducing relevant Website functions, external services or changes to the data processed. Identified risks may require narrower processing, stronger safeguards or a different procedure.
The risks below are examples. The assessment may include others relevant to an enquiry or a change in the law.
poor data quality leading to incorrect legal conclusions.
The Operator's responsibility is determined by applicable Russian law, agreements with individuals and this Policy. Independent processing by third parties outside the Operator's control is distinct from processing entrusted to them or covered by the Operator's contractual obligations. This distinction does not exclude liability imposed by law.
You must provide accurate information and have a lawful basis to disclose it, including appropriate authority when providing another person's data. The Operator may restrict or decline processing where there are grounds to believe the information was supplied unlawfully or in breach of third-party rights. The processing must still meet the Policy's lawfulness and legal-basis requirements.
The following provisions allocate responsibilities subject to mandatory law.
Responsibility for unauthorised third-party acts depends on the law and the Operator's own duties, not solely on whether the third party is a contractor.
Liability for disruption caused by force majeure is subject to the applicable legal requirements.
Provide current, accurate information sufficient for the relevant purpose.
You must have a lawful basis to supply another person's data.
The Operator may decline processing that has no lawful basis.
The Operator may restrict Website access in response to misuse.
Third-party services are responsible for their own privacy policies; the Operator's separate legal duties remain.
Messaging services may involve cross-border transfer risks. Choosing a service does not waive your rights or the Operator's mandatory duties, and you may decline that channel.
A consultation does not guarantee a particular outcome.
General information does not replace an individual assessment. Any limitation of liability remains subject to mandatory law.
Respect any applicable confidentiality obligations for information you receive.
The Operator may protect lawful interests through court proceedings.
Mandatory retention duties may limit deletion or other requests.
Data may be retained to protect legal rights within the relevant limitation period where a lawful basis permits it.
Providing false information may affect responsibility for resulting harm, without excluding the Operator's own legal duties.
The Operator must maintain legal, organisational and technical measures to support ongoing compliance with applicable data-protection law. These must include internal procedures, checks, training for authorised persons and regular document updates, consistent with the Policy's legal approach and security requirements.
Compliance audits are conducted periodically and when key processing arrangements change. Findings are documented, and identified departures from the Policy must be addressed through corrective action.
Publications, including case studies, must protect confidentiality and avoid identifying individuals. Information that could identify a client directly or indirectly may be published only with that client's explicit, documented consent and subject to applicable law. The Policy's consent and interpretation rules also apply.
Public materials are anonymised by removing identifiers, generalising details or aggregating information without distorting the legal meaning. The combined facts must also be considered because they may identify someone even without a name. Where anonymisation is doubtful, access or publication is restricted further.
consider further anonymisation or removal following a data-subject request.
Read each provision in the context of the Policy as a whole. If the Policy conflicts with another internal document, this Policy takes priority unless the law requires otherwise.
If a provision is invalid, the unaffected provisions remain applicable. Any uncertainty must be resolved by balancing the interests involved, giving priority to data-subject rights while respecting the Operator's lawful interests. Mandatory law and the Policy's legal-basis and accountability requirements still apply.
the Policy applies to all processing within its stated scope, including Website activity and related services.
The Operator must classify data by sensitivity to set proportionate storage and access restrictions. Classification must be considered when data is first received, transferred, archived or destroyed, together with the Policy's retention, destruction and security requirements.
Access depends on the data category, source and purpose. Authorised persons receive only the access needed for their work, and changes are recorded. Where classification is uncertain, the stricter protection applies.
Data classification must be kept up to date and reviewed when processing purposes, contractual terms or applicable legal requirements change. The Policy's processing principles and amendment rules also apply.
This Policy requires risk-based planning, separation of processing activities and internal controls. The Operator must use relevant information-protection practices only where they are applicable and consistent with mandatory Russian law. This Policy does not claim certification to an international standard.
Document management, logging, incident handling and training must support a processing record that can be audited. These practices must operate within applicable law and the Policy's security, incident-response and accountability requirements.
The Operator commits to the following practices where applicable and consistent with Russian law:
data-subject complaint procedures with recorded outcomes.
Logs, registers and internal reports record material processing actions for possible audits or disputes. Recordkeeping applies to all relevant data categories, including technical and archived data, regardless of the scale of processing.
The Operator must notify individuals and authorities where the law requires it and record each notice's date, channel and content. Where needed, the notice must explain the individual's rights and how to exercise them under the Policy's request-handling procedures.
Processing records must be protected, with access limited to authorised persons. They must be kept only within the Policy's retention limits and remain subject to its destruction, anonymisation and restriction rules.
The Operator may use external email, analytics, notification and cloud video-conferencing providers to support the Website and communications. Any data transfer must meet the Policy's third-party disclosure, processor-agreement and cross-border transfer requirements, as well as its confidentiality and data-minimisation rules. Technical convenience is not a separate legal basis.
External services receive only the data needed for the relevant function, not the full dataset. Required agreements address confidentiality and security, and access is limited to the task. Relevant risks are explained. An alternative channel may be chosen where it allows the Operator to fulfil the engagement and legal obligations.
The examples below describe external-service uses and safeguards. Additional uses remain subject to the Policy's general requirements.
service terms recorded in the compliance register.
The Operator treats information received in legal work as confidential, including initial enquiries made in confidence before an engagement is agreed. The Policy's interpretation rules and confidentiality safeguards for publications also apply.
Information may be used only for the purposes permitted by this Policy, the engagement and applicable law. Publication, third-party disclosure or use for another client requires consent or another valid legal basis. The Operator takes steps to avoid conflicts of interest and keep different clients' files separate.
The following confidentiality and ethical requirements apply to personal data used in the practice:
internal checks on professional confidentiality.
Defined terms and references to related policy topics must be read together. A reference includes the relevant conditions and limitations, even where they are not repeated. The Policy must be interpreted as a whole, subject to mandatory law.
References to related policy topics preserve the conditions that apply to processing, including third-party disclosures, entrusted processing and cross-border transfers. A provision cannot be read in isolation from the processing principles, retention limits and security requirements.
Conditions on transfers, confidentiality, legal bases and retention may appear in several parts of the Policy. They must be read consistently across the rules on processing, data rights and responsibility. Repetition does not create a separate permission to process data.
terms not defined in the Policy are interpreted under applicable Russian law.
The Operator must check compliance with this Policy and applicable Russian law through scheduled reviews and ongoing monitoring. Checks must cover enquiry records, consent documentation and retention periods. Findings must be documented, and failures corrected within the required deadlines, in line with the Policy's compliance-review and record-keeping requirements.
The Policy is updated when needed, including after legal, technical or operational changes or identification of a legal risk. New versions are published on the Website and earlier versions archived.
Internal controls and document updates cover:
an archive of Policy versions and related documents.
The Policy applies to personal data processed through the Website and related communication channels, whether supplied actively or generated by technical processes. An exception requires a legal basis or a written agreement consistent with mandatory law.
The Policy takes effect on publication. A new version replaces the previous version unless stated otherwise, while earlier versions remain part of the record for their period of operation. Changes required by law or identified risks may be published without advance notice only to the extent permitted by law.
Read these provisions with the Policy's rules on interpretation, conflicting requirements, internal checks and updates. Related conditions and repeated provisions form part of the Policy as a whole, but cannot restrict statutory rights.
The Policy addresses the Operator's lawful interests and data-subject rights together. Individual provisions should be read with their relevant conditions and cross-references, not as independent permissions to process data.
The Policy is intended to operate as one document, interpreted in good faith and consistently with data-subject rights, the Operator's lawful interests and applicable law.
A provision affected by a change in law or legal interpretation must be applied consistently with mandatory law and updated where necessary. The Operator may make prompt corrections without reducing data-subject rights, while keeping the Policy consistent as a whole.
The Policy's cross-references, qualifications and related provisions are to be read together.
The Policy must be updated when processing purposes, data categories or services change. These changes do not remove the Operator's identity or the contact details for data-rights requests.
Andrey Eduardovich Bernev, an individual resident in Georgia. The sole contact for personal data enquiries is: bernev_64@mail.com.
Data is minimised for enquiries about supplies, disputes, documents, payments, valuation, classification, origin, marking, post-release checks or appeals involving the EAEU, China, Hong Kong, Kazakhstan, Belarus, Armenia, Kyrgyzstan or another foreign jurisdiction. Before an engagement is agreed, the Website requests only initial contact details: a name or business form of address, contact channel, company or transaction role, country or route, document type, receipt date, response deadline or proposed meeting date.
The Website has no public upload facility for files, customs declarations, contracts, invoices, bank records, third-party documents or material containing trade secrets. The booking calendar and Telegram bot are intended for meeting details and reminders, not document submission. Documents needed for analysis are exchanged by separate arrangement through direct contact. Share only what is needed, taking account of confidentiality, the documents involved, third-party information and applicable law.
EAEU enquiries use the Russian processing framework together with country annexes for Belarus, Kazakhstan, Armenia and Kyrgyzstan. The annexes address local terminology, data rights, cross-border transfers, minimisation and external services. Kazakh, Armenian, Kyrgyz and Belarusian versions are not published as unchecked machine translations; their publication remains subject to separate language and legal approval.
China–Russia enquiries, Hong Kong trading chains and the English page for Chinese businesses are subject to additional launch controls. Chinese-language forms remain unavailable pending approval of the page, processing notice, data categories, recipients, analytics, advertising tags and transfers against the relevant PIPL/CAC requirements. Russian text or an automatic translation is not presented as an approved Chinese version.
The Website may use or link to communication, analytics, video, advertising and professional outreach services. Each is assessed separately for purpose, data, loading time, recipient country, consent requirements and behaviour before and after consent.
Paid targeting, retargeting, LinkedIn Insight Tag, Chinese-language forms and EAEU or China-specific enquiry forms remain subject to an approved provider map. It records the service, purpose, data category, recipient and country, loading trigger, cookie/localStorage use, legal basis, consent requirement, privacy-policy link and live implementation test results.
Country annexes define launch restrictions; they are not individual advice from a lawyer in that country. Pending local legal approval, pages operate only in a limited mode: no file uploads, advertising pixels or hidden retargeting, and only minimal contact and deadline information.
Technical readiness is not full privacy approval. Until the country annex, provider map, implementation evidence and legal assessment are complete, a page may serve as an informational route only, not as an approved international data-collection service.