1. PERSONAL DATA PROCESSING POLICY (HEREINAFTER REFERRED TO AS THE POLICY)
Developed in accordance with Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (hereinafter - FZ-152). This Policy defines the procedure for processing personal data and measures to ensure the security of personal data in Social Technologies LLC (hereinafter referred to as the Operator) in order to protect the rights and freedoms of a person and a citizen when processing his personal data, including the protection of the rights to privacy, personal and family secrets. The following basic concepts are used in the Policy: automated processing of personal data – processing of personal data using computer technology; blocking of personal data - temporary termination of processing of personal data (except in cases where processing is necessary to clarify personal data); personal data information system - a set of personal data contained in databases, and information technologies and technical means that ensure their processing; depersonalization of personal data - actions as a result of which it is impossible to determine, without the use of additional information, the ownership of personal data to a specific personal data subject; personal data processing - any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data; operator - a state body, municipal body, legal entity or individual, independently or jointly with other persons organizing and (or) processing personal data, as well as determining the purposes of processing personal data, the composition of personal data to be processed, actions (operations) performed with personal data; personal data – any information related directly or indirectly to a specific or identifiable individual (subject of personal data); provision of personal data – actions aimed at disclosure of personal data to a certain person or a certain circle of persons; dissemination of personal data - actions aimed at disclosure of personal data to an indefinite circle of persons (transfer of personal data) or familiarization with personal data of an unlimited circle of persons, including disclosure of personal data in the media, placement in information and telecommunications networks or providing access to personal data in any other way; cross-border transfer of personal data is the transfer of personal data to the territory of a foreign state to an authority of a foreign state, a foreign individual or a foreign legal entity. destruction of personal data - actions as a result of which it is impossible to restore the content of personal data in the personal data information system and (or) as a result of which the material carriers of personal data are destroyed; The Company is obliged to publish or otherwise provide unrestricted access to this Personal Data Processing Policy in accordance with Part 2 of Article 18.1. FZ-152.
2. PRINCIPLES AND CONDITIONS OF PERSONAL DATA PROCESSING
2.1 Principles of personal data processing
The processing of personal data by the Operator is carried out on the basis of the following principles: legality and fair basis; restriction of personal data processing to achieve specific, predetermined and legitimate goals; prevention of personal data processing incompatible with the purposes of personal data collection; prevention of combining databases containing personal data, the processing of which is carried out for purposes incompatible with each other; processing only those personal data that meet the purposes of their processing; compliance of the content and volume of the processed personal data with the stated purposes of processing; prevention of processing of personal data that is excessive in relation to the stated purposes of their processing; ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of personal data processing; destruction or depersonalization of personal data upon achievement of the goals of their processing or in case of loss of the need to achieve these goals, if it is impossible to eliminate violations of personal data by the Operator, unless otherwise provided by federal law.
2.2 Terms of personal data processing
2.3 Confidentiality of personal data
2.4 Publicly available sources of personal data
In order to provide information, the Operator may create publicly available sources of personal data of subjects, including directories and address books. The publicly available sources of personal data, with the written consent of the subject, may include his surname, first name, patronymic, date and place of birth, position, contact phone numbers, email address and other personal data provided by the subject of personal data. Information about the subject must be excluded from publicly available sources of personal data at any time at the request of the subject or by a court decision or other authorized state bodies.
2.5 Special categories of personal data
Processing by the Operator of special categories of personal data concerning race, nationality, political views, religious or philosophical beliefs, health status, intimate life is allowed in cases where: the subject of personal data has consented in writing to the processing of his personal data; personal data is made publicly available by the subject of personal data; processing of personal data is carried out in accordance with the legislation on state social assistance, labor legislation, the legislation of the Russian Federation on state pension pensions, on labor pensions; processing of personal data is necessary to protect the life, health or other vital interests of the subject of personal data or the life, health or other vital interests of other persons and obtaining the consent of the subject of personal data is impossible; the processing of personal data is carried out for medical and preventive purposes, for the purpose of establishing a medical diagnosis, providing medical and medical and social services, provided that the processing of personal data is carried out by a person professionally engaged in medical activities and obliged in accordance with the legislation of the Russian Federation to maintain medical secrecy; the processing of personal data is necessary to establish or exercise the rights of the subject of personal data or third parties, as well as in connection with the administration of justice; the processing of personal data is carried out in accordance with the legislation on mandatory types of insurance, with insurance legislation. The processing of special categories of personal data must be immediately terminated if the reasons for their processing have been eliminated, unless otherwise established by federal law. The processing of personal data on criminal record can be carried out by the Operator only in cases and in accordance with the procedure determined in accordance with federal laws.
2.6 Biometric personal data
Information that characterizes the physiological and biological characteristics of a person, on the basis of which it is possible to establish his identity - biometric personal data - can be processed by the Operator only with the written consent of the subject.
2.7 Assignment of personal data processing to another person
2.8 Cross-border transfer of personal data
The operator is obliged to make sure that the foreign state to whose territory the transfer of personal data is supposed to be carried out provides adequate protection of the rights of personal data subjects before the start of such transfer. The cross-border transfer of personal data on the territory of foreign states that do not provide adequate protection of the rights of personal data subjects may be carried out in the following cases: the written consent of the personal data subject to the cross-border transfer of his personal data; execution of the contract to which the subject of personal data is a party.
3. RIGHTS OF THE PERSONAL DATA SUBJECT
The subject of personal data decides on the provision of his personal data and consents to their processing freely, of his own free will and in his own interest. Consent to the processing of personal data may be given by the subject of personal data or his representative in any form that allows to confirm the fact of its receipt, unless otherwise established by federal law. The obligation to provide proof of obtaining the consent of the personal data subject to the processing of his personal data or proof of the existence of the grounds specified in FZ-152 is assigned to the Operator.
3.2 Rights of the personal data subject
4. ENSURING THE SECURITY OF PERSONAL DATA
The security of personal data processed by the Operator is ensured by the implementation of legal, organizational and technical measures necessary to meet the requirements of federal legislation in the field of personal data protection. To prevent unauthorized access to personal data, the Operator applies the following organizational and technical measures: appointment of officials responsible for organizing the processing and protection of personal data; restriction of the composition of persons with access to personal data; familiarization of subjects with the requirements of federal legislation and regulatory documents of the Operator for the processing and protection of personal data; organization of accounting, storage and circulation of information carriers; identification of threats to the security of personal data during their processing, formation of threat models based on them; development of a personal data protection system based on a threat model; checking the readiness and effectiveness of the use of information protection tools; differentiation of user access to information resources and hardware and software for information processing; registration and accounting of actions of users of personal data information systems; use of anti-virus tools and means of restoring the personal data protection system; use, if necessary, of means of inter-network shielding, intrusion detection, security analysis and cryptographic protection of information; organization of access control to the Operator's territory, protection of premises with technical means of personal data processing.
5. FINAL PROVISIONS
Other rights and obligations of the Operator as the operator of personal data are determined by the legislation of the Russian Federation in the field of personal data. The Operator's officials guilty of violating the norms governing the processing and protection of personal data bear material, disciplinary, administrative, civil or criminal liability in accordance with the procedure established by federal laws.