Approved by Order No. 1-1K
On Approval of the Privacy Policy (Personal Data Protection and Processing Policy)
dated 30.12.2025

Privacy Policy

Personal Data Protection and Processing Policy

This Privacy Policy is effective as of 1 January 2026.
Last revised: 1 January 2026.

← Back to main page

I. General Provisions

1.1. This Privacy Policy (hereinafter – the "Privacy Policy") governs the processing of personal data of individuals by the Limited Liability Company "FUTURA SYSTEMS", including the collection, storage and use thereof.

1.2. The Company processes and protects the personal data of individuals, including, in particular:

(hereinafter collectively referred to as "Data Subjects"), in accordance with the requirements of the Law of the Republic of Armenia "On Personal Data Protection" (hereinafter – the "Law").

1.3. Terms used in this Privacy Policy shall have the meanings ascribed to them in the Law.

II. Data Controller

2.1. For the purposes of this Privacy Policy, the data controller is the Limited Liability Company "FUTURA SYSTEMS" (hereinafter – the "Data Controller"), a legal entity registered under the laws of the Republic of Armenia, located at: Republic of Armenia, Yerevan, 26A M. Khorenatsi Street, Office 210.

2.2. The Data Controller processes the personal data of Data Subjects applying strict security measures, ensuring transparency, oversight and regulatory compliance at every stage.

2.3. For all matters relating to the processing of personal data, as well as to exercise your rights (rectification, restriction, erasure, withdrawal of consent, objection to processing), please contact the Data Controller by email: info@futura-systems.org or in writing at the Data Controller's registered address.

III. Categories of Personal Data

3.1. The Data Controller collects the following personal data:

(hereinafter collectively referred to as "Personal Data").

3.2. The Data Controller does not collect, store or process special categories of personal data, including information on racial or ethnic origin, health condition or sex life, or biometric personal data. The Data Controller does not intentionally collect personal data of minors under the age of 18.

3.3. Notwithstanding the foregoing, situations may arise in which individuals voluntarily provide special categories of personal data or biometric personal data as referred to in clause 3.2 of this Privacy Policy. The processing of such data does not form part of the purposes pursued by the Data Controller. Should the Data Controller become aware that such personal data have been inadvertently received, they will be promptly destroyed.

3.4. The Data Controller does not carry out any profiling that, under applicable law, could significantly affect the rights and freedoms of individuals.

IV. Legal Bases and Purposes of Personal Data Processing

4.1. The Data Controller processes personal data on one of the following lawful bases:

4.2. The applicable legal bases and purposes of personal data processing, by category of personal data, are set out in the table below:

No. Category of Personal Data Purpose of Processing Legal Basis
i. Name, contact details, account credentials Identification of the user on the website, including where such identification is required in connection with the recruitment of Contractors or similar events (including bootcamps), organisation of the selection process, conclusion of contracts with selected candidates, and payment of remuneration thereunder Legitimate interest of the Data Controller
ii. Name, contact details for marketing communications Conducting marketing communications Consent of the Data Subject
iii. Professional and educational data Selection of Contractors and/or subsequent conclusion of an employment contract or service agreement, in cases where the provision of services by the Data Subject to the Data Controller requires confirmation of professional and educational qualifications in accordance with applicable law and the Data Controller's internal policies Legitimate interest of the Data Controller
iv. Contractor data under contracts Negotiating and entering into employment or civil law service contracts with Contractors. Administering contractual obligations, including payment of remuneration to Contractors Performance of a contract concluded with the Contractor
v. IP addresses, strictly necessary cookies Ensuring the operation of the website Legitimate interest of the Data Controller
vi. Statistical / analytical cookies Analysis of website traffic Consent of the Data Subject (provided upon first visit to the website)
vii. Data of representatives of legal entities and potential partners Interaction with the Data Controller, its affiliates, partners, counterparties and clients (where applicable), including business communication and entering into contracts Legitimate interest of the Data Controller
viii. Data of Contractor applicants / candidates Recruitment of Contractors and development of the Company's business Consent of the Data Subject — provided upon submission of a CV or application; upon further negotiations — Legitimate interest of the Data Controller
ix. Employment-related data (for Contractors engaged under an employment contract): position held, salary, leave and other periods of absence, temporary incapacity records, disciplinary measures Administration of employment relations Performance of the employment contract and legal requirements
x. Data on services rendered / work performed Calculation and payment of remuneration (service acceptance acts, reports, invoices) under the contract Performance of the contract concluded with the Contractor
xi. Access control system data in respect of Contractors providing services using the Data Controller's systems, where such systems are applied Quality and volume control of services provided by Contractors under the relevant contracts. Protection of the Data Controller's legitimate interests, including security of operations, fraud prevention and protection of rights in judicial or other proceedings Legitimate interest of the Data Controller
xii. (applicable to all categories listed above) Compliance with the requirements of applicable law of the Republic of Armenia and other applicable jurisdictions, including accounting, tax and anti-money laundering legislation Legal obligation (clause 4.1(iv))
xiii. (applicable to all categories listed above) Handling of requests, queries, disputes and complaints relating to the matters specified above Legitimate interest of the Data Controller

V. Technical and Organisational Security Measures

5.1. To ensure the security of personal data, the Data Controller implements the necessary technical and organisational security measures to protect personal data against accidental loss, unauthorised access to information systems, unlawful use, recording, destruction, alteration, restriction, copying, dissemination or other interference.

5.2. The Data Controller restricts access to personal data processing systems to authorised persons only.

5.3. The Data Controller undertakes to maintain the confidentiality of personal data both during and after the processing thereof, until the expiry of the applicable retention period.

5.4. In the event of a personal data security breach (including a data leak, unauthorised access, destruction of data or other incident), the Data Controller undertakes to:

VI. Retention Periods for Personal Data

6.1. The Data Controller retains personal data for the period necessary to fulfil the purposes of processing, in accordance with the following retention periods:

(1) data of participants in Contractor selection events who were not selected — no more than 2 (two) years from the date of completion of the event;

(2) data of Data Subjects who have entered into an employment contract or civil law contract with the Data Controller — no more than 5 (five) years from the date of termination of the contract;

(3) data used for marketing communications — until the relevant consent is withdrawn;

(4) statistical cookies — no more than 1 (one) year;

(5) other data — no more than 3 (three) years.

6.2. Upon expiry of the applicable retention period set out in this section, the Data Controller shall ensure the secure destruction of personal data in accordance with applicable law.

VII. Transfer of Personal Data to Third Parties and Other Countries

7.1. The Data Controller hereby notifies that personal data may be transferred to third parties, including those located in other countries, for the purposes of processing.

7.2. The Data Controller hereby notifies that the level of personal data protection in other countries may not correspond to the level of protection applicable in the country under whose jurisdiction the Data Subject falls.

7.3. Third parties and other countries include:

7.4. The transfer of personal data to countries included in the list of countries ensuring an adequate level of personal data protection, as approved by the Personal Data Protection Agency of the Republic of Armenia (Decision No. ATPP-001/24 dated 08.07.2024), including the Member States of the European Union and the United States of America (in respect of organisations certified under applicable standards), is carried out without the application of additional protective mechanisms.

7.5. The transfer of personal data to third parties listed in clause 7.3 of this Policy, to countries not included in the list of countries ensuring an adequate level of personal data protection as approved by the Personal Data Protection Agency of the Republic of Armenia (in particular, to the United Arab Emirates, the People's Republic of China including Hong Kong, and other countries), is carried out on the basis of:

(a) the consent of the Data Subject, provided in accordance with this Privacy Policy; and

(b) data protection agreements concluded between the Data Controller and such third parties (including, where applicable, intra-group agreements), incorporating standard contractual clauses that ensure an adequate level of personal data protection in accordance with the requirements of the Law.

By accepting this Privacy Policy, the Data Subject provides consent, inter alia, to the transfer of their personal data to the countries specified in the first paragraph of clause 7.5. Such consent is provided on a one-time basis.

VIII. Rights of Data Subjects

8.1. Data Subjects are entitled, in accordance with the Law, to:

8.2. To exercise the above rights, the Data Subject must contact the Data Controller by email. Requests shall be reviewed and addressed in the manner prescribed by the Law.

IX. Use of Cookie Technology

9.1. When accessing the Data Controller's website, cookies or similar technologies may be used. Cookies are small text files stored on the electronic device from which an individual accesses the website.

9.2. The Data Controller uses the following types of cookies:

9.3. Strictly necessary cookies and security cookies are set without obtaining additional consent from the Data Subject. Statistical cookies are set only upon the Data Subject's explicit consent, which is expressed upon first visiting the website. The Data Subject may withdraw their consent to the use of statistical cookies at any time via browser settings or a dedicated cookie management tool on the website.

X. Amendments to the Privacy Policy

10.1. The Data Controller reserves the right to amend and supplement this Privacy Policy at its discretion, including, without limitation, for the purpose of aligning it with changes and additions to the Law.

10.2. The Data Controller shall notify Data Subjects within a reasonable timeframe of any amendments or supplements relating to the categories of personal data processed, the purposes of processing and the procedure for processing.

10.3. Each amendment or supplement to the Privacy Policy shall take effect upon its publication on the website.

XI. Consent to Personal Data Processing and Withdrawal Procedure

11.1. Consent to the processing of personal data is provided by the Data Subject by means of an affirmative action (ticking the relevant box) upon registration on the website and/or upon submission of an application for staff recruitment, including participation in the selection of Contractors, as well as by other means provided for under applicable law, in cases where consent constitutes the legal basis for processing in accordance with Section IV of this Privacy Policy.

11.2. The processing of Contractors' personal data carried out on the basis of contract performance, legitimate interest, or applicable legal requirements is not conditional on the Data Subject's consent and cannot be discontinued by means of withdrawal of consent in the manner provided for in this Section XI.

11.3. By providing their personal data and/or accepting this Privacy Policy, the Data Subject:

11.4. The absence of voluntary consent to receiving marketing communications shall not affect the Data Subject's ability to participate in the Data Controller's Contractor selection process (including bootcamps) or to use the core functions of the website used in such selection.

11.5. The Data Subject may withdraw their consent at any time by submitting a written request to the Data Controller at the email address indicated on the website. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal. Following withdrawal of consent, the Data Controller shall cease processing the relevant personal data, except where such processing is permitted on other lawful grounds. Withdrawal of consent may result in the Data Subject being unable to participate in the Contractor selection process or to use certain functions of the website.