Policy on Personal Data Processing

Policy on Personal Data Processing

Date of Policy Revision Publication: 1st March 2023

This document sets out the Policy of IP Azambayeva Jamal Amangeldievna, TIN (Taxpayer Identification Number): 550409914866, OGRNIP (Primary State Registration Number of Individual Entrepreneur): 321774600375142 (referred to as the "Operator") regarding the processing of personal data (referred to as the "Policy").

The aim of the Policy is to ensure the protection of individual rights and freedoms in relation to the processing of their personal data.

The Policy applies to all personal data that the Operator may receive from data subjects.

Terms and Definitions

Website - An internet resource where the Operator carries out the processing of personal data, located at the address: https://jemiko.ru/ and all its subdomains.
Personal data - Any information that directly or indirectly relates to a specific or identifiable User.
User - An individual who uses the Website for personal purposes or as a representative of another person.
Processing of Personal Data - Any action or set of actions performed with or without the use of automated tools, involving personal data. Processing includes, among other things, collection, recording, systematization, storage, updating, use, transfer, depersonalization, blocking, deletion, and destruction.
Automated processing of personal data - Processing of personal data using computer technology.
Providing personal data - Actions aimed at disclosing personal data to a specific person or a defined group of individuals.
Dissemination of personal data - Actions aimed at disclosing personal data to an indefinite group of individuals.
Cross-border transfer of personal data - The transfer of personal data to the territory of a foreign state, to a foreign authority, or to a foreign individual or legal entity.

1. General Provisions
1.1. The Policy is an internal document of the Operator that outlines the procedures for the processing of personal data.
1.2. The Operator has developed this Policy in accordance with the Constitution of the Russian Federation, Federal Law No. 152-FZ of 27th July 2006, "On Personal Data" (referred to as the "Law"), and other applicable laws and regulations governing the processing of personal data.

1.3. The legal basis for the processing of personal data includes:

  • Agreements concluded between the Operator and the data subject.
  • Federal laws and other regulatory legal acts related to the protection of personal data.
  • Users' consent for the processing of their personal data and for the authorized distribution of personal data.

1.4. The objectives of the Policy are:
  • Ensuring the protection of individual rights and freedoms in relation to the processing of their personal data, including privacy and family secrets.
  • Compliance with the legislation of the Russian Federation relating to personal data.
  • Prevention of unauthorized actions by third parties in relation to the processing of personal data.
  • Mitigation of potential threats to the security of Users' personal data.

1.5. By submitting their personal data through the Website's forms or providing consent via instant messengers or email, the User agrees to the terms of the Policy.

1.6. The Operator publishes a new version of the Policy on the Website whenever changes are made. The revised edition becomes effective upon publication.

1.7. If the User continues to use the Website after the Policy has been revised, it is considered that they have read and agreed to the Policy in its new edition.

2. Principles of Processing

2.1. The Operator processes Personal Data based on the following principles:
  • Lawful and fair basis of processing.
  • Processing in accordance with specific, predetermined, and legitimate purposes.
  • Prevention of merging databases containing Personal Data processed for incompatible purposes.
  • Compliance of the content and volume of Personal Data with the stated purposes of processing.
  • Accuracy, sufficiency, relevance, and reliability of Personal Data.
  • Lawfulness of technical measures aimed at processing.
  • Reasonableness and appropriateness of processing.
  • Storage of Personal Data for no longer than necessary, unless the storage period is established by law or an agreement to which the User is a party.
  • Destruction or depersonalization of Personal Data upon achieving the purposes of processing or when the need to achieve them is lost, unless otherwise provided by law.

3.Purpose of Processing and List of Processed Personal Data

3.1. The Operator processes the Personal Data provided by the User through the Site's forms, phone calls, instant messengers, or emails indicated on the Site.
3.2. Purpose of personal data processing, categories and list of processed personal data, categories of subjects whose personal data is processed, methods and terms of processing and storage, procedure for destroying personal data when the goals of their processing are achieved or when other legal grounds occur:

1.
User authentication for concluding an agreement and provision of services:
  • Personal data: last name, first name, phone number, email.
  • Category: general.
  • Subjects of personal data: Users of the Site.
  • Processing methods: collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, depersonalization, transfer (access, provision), blocking, deletion, destruction.
  • Processing and storage period: until the User requests to stop processing or withdraws consent, or for 10 years.
  • Procedure for the destruction of personal data: The Operator shall erase the data by overwriting (replacing all information storage units with "0") and draw up an act on the destruction of personal data.

2.
  • Communication with the User, sending messages, notifications, requests, responses, documents, informational messages:
  • Personal data: last name, first name, phone number, email, data of the User's social network accounts.
  • Category: general.
  • Subjects of personal data: Users of the Site.

Processing methods: collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, depersonalization, transfer (access, provision), blocking, deletion, destruction.

Processing and storage period: until the User requests to stop processing or withdraw consent, or 10 years.

The procedure for the destruction of personal data: The Operator shall erase the data by overwriting (replacing all information storage units with "0") with drawing up an act on the destruction of personal data.


2. Communication with the User, sending messages, notifications, requests, responses, documents, informational messages Personal data: last name, first name, phone number, email, data of the User's social network accounts.

Category: general.

Subjects of personal data: Users of the Site.

Processing methods: collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, depersonalization, blocking, deletion, destruction.

Processing and storage period: until the User requests to stop processing or withdraw consent, or 10 years.

The procedure for the destruction of personal data: The Operator shall erase the data by overwriting (replacing all information storage units with "0") with drawing up an act on the destruction of personal data.

3.
Processing of appeals, complaints, requests, messages from the Operator and the User to each other Personal data: last name, first name, phone number, e-mail, message text (if the text of the message contains personal data), bank details (if necessary for the fulfillment of obligations).

Category: general.

Subjects of personal data: Users of the Site.

Processing methods: collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, depersonalization, transfer (access, provision) blocking, deletion, destruction.

Processing and storage period: until the User requests to stop processing or withdraw consent, or 10 years.

The procedure for the destruction of personal data: The Operator shall erase the data by overwriting (replacing all information storage units with "0") with drawing up an act on the destruction of personal data.


4.
User feedback on services Personal data: last name, first name, message text (if the message text contains personal data), data of the User's social network accounts, image data: photographs, videos, other technical fixation of face and body images.

Category: general.

Subjects of personal data: Users of the Site.

Processing methods: collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, depersonalization, transfer (access, provision) blocking, deletion, destruction of personal data.

Processing and storage period: until the User requests to stop processing or withdraw consent, or 10 years.

The procedure for the destruction of personal data: The Operator shall erase the data by overwriting (replacing all information storage units with "0") with drawing up an act on the destruction of personal data.

3.3. The Operator does not process biometric Personal Data, special categories of Personal Data relating to race, nationality, political views, religious or philosophical beliefs, intimate life, medical information reflecting the state of health of the subject of personal data.

3.4. The operator does not check:
  • Legal capacity of the User;
  • Accuracy of the Personal Data provided by the User.

3.5. The user warrants that:
  • The provided Personal data are reliable and up-to-date.
  • The user has obtained the consent of a third party to transfer their Personal Data to the Operator and for their subsequent Processing if the User informs the Operator about the Personal Data of a third party.

4. Processing of Personal Data

4.1. The Operator processes Personal Data based on an application received from the User through the Site's forms.
4.2. The Operator collects Personal data voluntarily provided by the User when filling out the Site's forms or using other means of communication, including phone, email, and other methods.
4.3. Browsing the Site's pages is possible for Users without providing Personal Data or disclosing any information that directly identifies the User as an individual.
4.4. The Operator stores Personal Data in databases located within the territory of the Russian Federation.
4.5. The storage of personal data is carried out in a form that allows identifying the User for no longer than necessary for the purposes of the Processing, unless the period for storing personal data is established by federal law or an agreement to which the User is a party, beneficiary, or guarantor.
The processed Personal Data is subject to destruction or depersonalization upon achieving the purposes of processing, loss of the need to achieve these purposes, withdrawal of the consent of the subject of personal data (if processed based on consent), or the occurrence of other conditions established by applicable law for the termination of the processing of personal data.
4.6. The Operator carries out the Processing using both automation tools and manual methods.
4.7. The Operator has the right to transfer the User's personal information to third parties in the following cases:
  • The user has given consent to such actions.
  • The transfer is required by Russian or other applicable legislation within the framework of the procedures established by law.
  • The transfer occurs as part of the sale or other transfer of business (in whole or in part), and all obligations to comply with the terms of the Processing are transferred to the acquirer.
  • It is necessary to protect the rights and legitimate interests of the Operator or third parties in cases where the User violates the terms of use of the Site.
  • The use of analytical programs, including Yandex.Metrics, and others.
4.8. The Operator informs the recipients that the transmitted data can only be used for the purposes for which they were communicated.
4.9. In case of confirmation of the inaccuracy of Personal data, the Operator updates them.
4.10. The Operator has the right to temporarily suspend the processing of Personal Data by blocking the Processing (unless processing is necessary to clarify the Personal Data).
4.11. If Personal Data has been requested by law enforcement authorities or is required for legal proceedings, the Operator does not delete them until these issues are fully resolved and/or within the period required and/or allowed by applicable law.


5. Rights of the User

5.1. The User has the right to request clarification of their Personal Data by contacting the Operator.
5.2. The User has the right to withdraw their consent to the processing of Personal Data by sending an appeal to the Operator via email at info@jemiko.ru.
5.3. The User has the right to send a request to the Operator, following the procedure established in the Policy, to receive information about the Processing, including:
  • Confirmation of the fact of Processing.
  • The legal basis for the Processing.
  • The purposes and methods of Processing applied by the Operator.
  • The type of Personal Data processed and the source of its receipt.
  • Terms of Processing, including the storage period of Personal Data.
  • The procedure for exercising the rights provided by the legislation of the Russian Federation.
  • Information about cross-border data transfers that have been performed or proposed.
  • Information about individuals to whom Personal Data may be disclosed based on an agreement with the Operator or in accordance with the legislation of the Russian Federation.
  • The name, surname, patronymic, and address of the person performing the Processing on behalf of the Operator, if the Processing is or will be entrusted to such a person.
  • Other information required by the legislation of the Russian Federation.

6.Obligations of the Operator
6.1. Upon request from the User, the Operator provides information about the Processing or provides a justified refusal.
6.2. At the request of the User, the Operator clarifies, blocks, or deletes the processed Personal Data if it is incomplete, outdated, inaccurate, illegally obtained, or no longer necessary for the stated purpose of the Processing.
6.3. The Operator ensures the legality of the Processing. If it is not possible to ensure the legality of the Processing, the Operator is obligated, within a period not exceeding 10 business days from the date of discovering the illegal Processing, to destroy the Personal Data or ensure its destruction.
6.4. The Operator stops the Processing and destroys the Personal Data if its storage is no longer required for the purposes of the Processing.

7.Measures for the protection of Personal Data and the responsibility of the Operator
7.1. In accordance with Article 18.1 of Federal Law No. 152-FZ "On Personal Data," the Operator determines the necessary and sufficient measures to fulfill obligations ensuring the security of Personal Data.
7.2. The measures may include:
  • Issuing documents that define the Processing policy.
  • Implementing internal control and/or audit of Processing compliance with Russian Federation legislation and the Policy.
  • Appointing a person responsible for organizing the Processing.
  • Limiting the number of persons with access to Personal Data and implementing a permission system for accessing them.
  • Rejecting any Processing methods that do not correspond to the purposes determined by the Operator.
  • Identifying and authenticating the subject when accessing data.
  • Limiting the software environment.
  • Protecting the storage media used for storing and/or processing Personal Data.
  • Registering security events.
  • Implementing antivirus protection.
7.3. In case of personal data leakage, the Operator is obliged to inform Roskomnadzor (the Federal Service for Supervision of Communications, Information Technology, and Mass Media) within 24 hours.
7.4. Within 72 hours, the Operator must conduct an internal investigation and report the results to Roskomnadzor.
7.5. The Operator is obliged to provide information about computer incidents leading to the illegal transfer of Personal Data to the state system for detecting, preventing, and eliminating the consequences of computer attacks on information resources of the Russian Federation (GosSOPKA).

8.User's Applications
8.1. The User has the right to send an appeal to the Operator via email at info@jemiko.

8.2. The User is obliged to:
  • Include in the appeal their last name, first name, email address, the essence of the appeal, and provide a handwritten signature.
  • Scan the appeal and send it as a file attachment via email.
8.3. By sending the appeal, the User agrees to the processing of the provided personal data for the purpose of its consideration by the Operator.
8.4. The Operator undertakes to consider the User's request and provide a response or a reasoned refusal within 10 days from the date of receiving the request.
8.5. All correspondence received by the Operator, including appeals in electronic form, is considered restricted information and is not disclosed without the written consent of the User.

Details of the Operator:
Individual Entrepreneur Azambayeva Jamal Amangeldievna Taxpayer Identification Number (TIN): 550409914866 Primary State Registration Number of the Individual Entrepreneur (OGRNIP): 321774600375142
info@jemiko.ru