I. General Provisions
1.1. This Privacy Policy (hereinafter – the "Privacy Policy") governs the processing of personal data of individuals by the Limited Liability Company "FUTURA SYSTEMS", including the collection, storage and use thereof.
1.2. The Company processes and protects the personal data of individuals, including, in particular:
- visitors to the websites operated by the Company;
- individuals engaged in employment under an employment contract or in the provision of services under civil law contracts (hereinafter jointly referred to as "Contractors");
- candidates for Contractors;
- individuals representing the interests of other organisations,
(hereinafter collectively referred to as "Data Subjects"), in accordance with the requirements of the Law of the Republic of Armenia "On Personal Data Protection" (hereinafter – the "Law").
1.3. Terms used in this Privacy Policy shall have the meanings ascribed to them in the Law.
II. Data Controller
2.1. For the purposes of this Privacy Policy, the data controller is the Limited Liability Company "FUTURA SYSTEMS" (hereinafter – the "Data Controller"), a legal entity registered under the laws of the Republic of Armenia, located at: Republic of Armenia, Yerevan, 26A M. Khorenatsi Street, Office 210.
2.2. The Data Controller processes the personal data of Data Subjects applying strict security measures, ensuring transparency, oversight and regulatory compliance at every stage.
2.3. For all matters relating to the processing of personal data, as well as to exercise your rights (rectification, restriction, erasure, withdrawal of consent, objection to processing), please contact the Data Controller by email: info@futura-systems.org or in writing at the Data Controller's registered address.
III. Categories of Personal Data
3.1. The Data Controller collects the following personal data:
- Data identifying the Data Subject (individual), who may be a citizen of the Republic of Armenia, a foreign national or a dual citizen, including first name, last name, and patronymic — to the extent voluntarily provided by the Data Subject;
- Contact details of the Data Subject: email address and telephone number, for the purposes of business communication and/or conclusion of an employment contract or civil law contract;
- Professional and educational data of Contractor candidates and Contractors, including CV / résumé, information regarding educational institution, academic performance, qualifications, professional experience and work history, certificates obtained, professional skills and references;
- Other data collected during the selection of Contractor candidates, including test results and professional assessments, reference checks, and other information voluntarily provided by a candidate in the course of such selection. For the purposes of this Policy, "recruitment" and "selection" mean contacting, interviewing and/or assessing one or more candidates, including through an individual interaction process or via a bootcamp;
- Account credentials for access to the Data Controller's website (username and password), as well as to the Data Controller's internal information systems (including HR and payroll systems);
- Internet data (IP addresses, cookies) on websites operated by the Data Controller;
- Other data of Contractors engaged under employment or civil law contracts, in addition to the data specified above, including bank details for the payment of remuneration, taxpayer identification number, service permits / visas where applicable;
- Data of representatives of legal entities and potential partners: first name, last name, position, contact details (email, telephone, business address) for the purposes of business communication and entering into contracts.
(hereinafter collectively referred to as "Personal Data").
3.2. The Data Controller does not collect, store or process special categories of personal data, including information on racial or ethnic origin, health condition or sex life, or biometric personal data. The Data Controller does not intentionally collect personal data of minors under the age of 18.
3.3. Notwithstanding the foregoing, situations may arise in which individuals voluntarily provide special categories of personal data or biometric personal data as referred to in clause 3.2 of this Privacy Policy. The processing of such data does not form part of the purposes pursued by the Data Controller. Should the Data Controller become aware that such personal data have been inadvertently received, they will be promptly destroyed.
3.4. The Data Controller does not carry out any profiling that, under applicable law, could significantly affect the rights and freedoms of individuals.
IV. Legal Bases and Purposes of Personal Data Processing
4.1. The Data Controller processes personal data on one of the following lawful bases:
- Consent of the Data Subject or a person authorised by the Data Subject;
- Necessity to perform obligations under a contract concluded between the Data Subject and the Data Controller;
- Pursuit of the legitimate and specific interests of the Data Controller;
- Compliance with legal requirements.
4.2. The applicable legal bases and purposes of personal data processing, by category of personal data, are set out in the table below:
| No. | Category of Personal Data | Purpose of Processing | Legal Basis |
|---|---|---|---|
| i. | Name, contact details, account credentials | Identification of the user on the website, including where such identification is required in connection with the recruitment of Contractors or similar events (including bootcamps), organisation of the selection process, conclusion of contracts with selected candidates, and payment of remuneration thereunder | Legitimate interest of the Data Controller |
| ii. | Name, contact details for marketing communications | Conducting marketing communications | Consent of the Data Subject |
| iii. | Professional and educational data | Selection of Contractors and/or subsequent conclusion of an employment contract or service agreement, in cases where the provision of services by the Data Subject to the Data Controller requires confirmation of professional and educational qualifications in accordance with applicable law and the Data Controller's internal policies | Legitimate interest of the Data Controller |
| iv. | Contractor data under contracts | Negotiating and entering into employment or civil law service contracts with Contractors. Administering contractual obligations, including payment of remuneration to Contractors | Performance of a contract concluded with the Contractor |
| v. | IP addresses, strictly necessary cookies | Ensuring the operation of the website | Legitimate interest of the Data Controller |
| vi. | Statistical / analytical cookies | Analysis of website traffic | Consent of the Data Subject (provided upon first visit to the website) |
| vii. | Data of representatives of legal entities and potential partners | Interaction with the Data Controller, its affiliates, partners, counterparties and clients (where applicable), including business communication and entering into contracts | Legitimate interest of the Data Controller |
| viii. | Data of Contractor applicants / candidates | Recruitment of Contractors and development of the Company's business | Consent of the Data Subject — provided upon submission of a CV or application; upon further negotiations — Legitimate interest of the Data Controller |
| ix. | Employment-related data (for Contractors engaged under an employment contract): position held, salary, leave and other periods of absence, temporary incapacity records, disciplinary measures | Administration of employment relations | Performance of the employment contract and legal requirements |
| x. | Data on services rendered / work performed | Calculation and payment of remuneration (service acceptance acts, reports, invoices) under the contract | Performance of the contract concluded with the Contractor |
| xi. | Access control system data in respect of Contractors providing services using the Data Controller's systems, where such systems are applied | Quality and volume control of services provided by Contractors under the relevant contracts. Protection of the Data Controller's legitimate interests, including security of operations, fraud prevention and protection of rights in judicial or other proceedings | Legitimate interest of the Data Controller |
| xii. | (applicable to all categories listed above) | Compliance with the requirements of applicable law of the Republic of Armenia and other applicable jurisdictions, including accounting, tax and anti-money laundering legislation | Legal obligation (clause 4.1(iv)) |
| xiii. | (applicable to all categories listed above) | Handling of requests, queries, disputes and complaints relating to the matters specified above | Legitimate interest of the Data Controller |
V. Technical and Organisational Security Measures
5.1. To ensure the security of personal data, the Data Controller implements the necessary technical and organisational security measures to protect personal data against accidental loss, unauthorised access to information systems, unlawful use, recording, destruction, alteration, restriction, copying, dissemination or other interference.
5.2. The Data Controller restricts access to personal data processing systems to authorised persons only.
5.3. The Data Controller undertakes to maintain the confidentiality of personal data both during and after the processing thereof, until the expiry of the applicable retention period.
5.4. In the event of a personal data security breach (including a data leak, unauthorised access, destruction of data or other incident), the Data Controller undertakes to:
- notify the Personal Data Protection Agency of the Republic of Armenia of the breach within 72 (seventy-two) hours of becoming aware of it;
- where there is a high risk to the rights and freedoms of Data Subjects — notify the affected Data Subjects directly within a reasonable timeframe and without undue delay;
- take immediate steps to remedy the consequences of the breach and prevent its recurrence.
VI. Retention Periods for Personal Data
6.1. The Data Controller retains personal data for the period necessary to fulfil the purposes of processing, in accordance with the following retention periods:
(1) data of participants in Contractor selection events who were not selected — no more than 2 (two) years from the date of completion of the event;
(2) data of Data Subjects who have entered into an employment contract or civil law contract with the Data Controller — no more than 5 (five) years from the date of termination of the contract;
(3) data used for marketing communications — until the relevant consent is withdrawn;
(4) statistical cookies — no more than 1 (one) year;
(5) other data — no more than 3 (three) years.
6.2. Upon expiry of the applicable retention period set out in this section, the Data Controller shall ensure the secure destruction of personal data in accordance with applicable law.
VII. Transfer of Personal Data to Third Parties and Other Countries
7.1. The Data Controller hereby notifies that personal data may be transferred to third parties, including those located in other countries, for the purposes of processing.
7.2. The Data Controller hereby notifies that the level of personal data protection in other countries may not correspond to the level of protection applicable in the country under whose jurisdiction the Data Subject falls.
7.3. Third parties and other countries include:
- Companies affiliated with the Data Controller. An up-to-date list of affiliates to whom the Data Subject's personal data have been transferred on the basis of and in accordance with this Policy shall be provided upon written request;
- Banks or other financial institutions;
- Contractor recruitment platforms and staffing agencies;
- Providers of payroll and Contractor relationship administration services (e.g. accounting and financial administration service providers; working time, leave and sick leave management systems; transport agents and others);
- Persons who have entered into civil law contracts with the Data Controller and who operate in the United Arab Emirates, the United States of America, the People's Republic of China (including Hong Kong), the Member States of the European Union and other jurisdictions, for the purposes of implementing the terms of such contracts that involve the participation of the Data Subject (in particular, but not exclusively, where the Data Subject acts as a contractor under an agreement with the Data Controller in favour of the persons referred to in this sub-clause). An up-to-date list of persons to whom the Data Subject's personal data have been transferred on the basis of and in accordance with this sub-clause shall be provided upon written request.
7.4. The transfer of personal data to countries included in the list of countries ensuring an adequate level of personal data protection, as approved by the Personal Data Protection Agency of the Republic of Armenia (Decision No. ATPP-001/24 dated 08.07.2024), including the Member States of the European Union and the United States of America (in respect of organisations certified under applicable standards), is carried out without the application of additional protective mechanisms.
7.5. The transfer of personal data to third parties listed in clause 7.3 of this Policy, to countries not included in the list of countries ensuring an adequate level of personal data protection as approved by the Personal Data Protection Agency of the Republic of Armenia (in particular, to the United Arab Emirates, the People's Republic of China including Hong Kong, and other countries), is carried out on the basis of:
(a) the consent of the Data Subject, provided in accordance with this Privacy Policy; and
(b) data protection agreements concluded between the Data Controller and such third parties (including, where applicable, intra-group agreements), incorporating standard contractual clauses that ensure an adequate level of personal data protection in accordance with the requirements of the Law.
By accepting this Privacy Policy, the Data Subject provides consent, inter alia, to the transfer of their personal data to the countries specified in the first paragraph of clause 7.5. Such consent is provided on a one-time basis.
VIII. Rights of Data Subjects
8.1. Data Subjects are entitled, in accordance with the Law, to:
- access their personal data;
- obtain information about their personal data, the processing being carried out, the grounds and purposes of processing, the identity and location of the Data Controller, and the categories of persons to whom personal data may be transferred;
- request the Data Controller to rectify, restrict or erase their personal data where such data are incomplete, inaccurate, outdated, obtained unlawfully or are no longer necessary for the purposes of processing;
- lodge a complaint with the Personal Data Protection Agency of the Republic of Armenia (official website: pdpa.am; address: Republic of Armenia, Yerevan, 54b Komitas Avenue) requesting confirmation of rectification, restriction or erasure of their personal data, and to file complaints regarding the Data Controller's actions;
- withdraw their consent to the processing of personal data at any time in the manner provided for in this Privacy Policy — in cases where consent is the applicable legal basis for processing;
- object to the processing of personal data carried out on the basis of the Data Controller's legitimate interest;
- not be subject to decisions based solely on automated processing of personal data that produce legal effects or otherwise significantly affect the interests of the Data Subject.
8.2. To exercise the above rights, the Data Subject must contact the Data Controller by email. Requests shall be reviewed and addressed in the manner prescribed by the Law.
IX. Use of Cookie Technology
9.1. When accessing the Data Controller's website, cookies or similar technologies may be used. Cookies are small text files stored on the electronic device from which an individual accesses the website.
9.2. The Data Controller uses the following types of cookies:
- Strictly necessary cookies, which ensure the proper functioning of the website;
- Statistical / analytical cookies, which collect information about website visitors;
- Security cookies, which ensure the protection and integrity of the website.
9.3. Strictly necessary cookies and security cookies are set without obtaining additional consent from the Data Subject. Statistical cookies are set only upon the Data Subject's explicit consent, which is expressed upon first visiting the website. The Data Subject may withdraw their consent to the use of statistical cookies at any time via browser settings or a dedicated cookie management tool on the website.
X. Amendments to the Privacy Policy
10.1. The Data Controller reserves the right to amend and supplement this Privacy Policy at its discretion, including, without limitation, for the purpose of aligning it with changes and additions to the Law.
10.2. The Data Controller shall notify Data Subjects within a reasonable timeframe of any amendments or supplements relating to the categories of personal data processed, the purposes of processing and the procedure for processing.
10.3. Each amendment or supplement to the Privacy Policy shall take effect upon its publication on the website.
XI. Consent to Personal Data Processing and Withdrawal Procedure
11.1. Consent to the processing of personal data is provided by the Data Subject by means of an affirmative action (ticking the relevant box) upon registration on the website and/or upon submission of an application for staff recruitment, including participation in the selection of Contractors, as well as by other means provided for under applicable law, in cases where consent constitutes the legal basis for processing in accordance with Section IV of this Privacy Policy.
11.2. The processing of Contractors' personal data carried out on the basis of contract performance, legitimate interest, or applicable legal requirements is not conditional on the Data Subject's consent and cannot be discontinued by means of withdrawal of consent in the manner provided for in this Section XI.
11.3. By providing their personal data and/or accepting this Privacy Policy, the Data Subject:
- confirms that they have read and understood the provisions of the Privacy Policy;
- voluntarily consents to the processing of their personal data — including their collection, storage and use — for the purposes set out in this Privacy Policy;
- voluntarily consents to the transfer of their personal data in accordance with clause 7.5 of this Privacy Policy.
11.4. The absence of voluntary consent to receiving marketing communications shall not affect the Data Subject's ability to participate in the Data Controller's Contractor selection process (including bootcamps) or to use the core functions of the website used in such selection.
11.5. The Data Subject may withdraw their consent at any time by submitting a written request to the Data Controller at the email address indicated on the website. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal. Following withdrawal of consent, the Data Controller shall cease processing the relevant personal data, except where such processing is permitted on other lawful grounds. Withdrawal of consent may result in the Data Subject being unable to participate in the Contractor selection process or to use certain functions of the website.