Introduction
Ensuring the confidentiality and security of personal data processing in the Company is one of the organization's priority tasks.
For these purposes, the Company has put into effect a set of organizational and administrative documents that are binding on all employees authorized to process personal data.
Processing, storage, and ensuring the confidentiality and security of personal data are carried out in accordance with the applicable laws of the Russian Federation on personal data protection and the Company's local acts.
This Policy defines the principles, procedure, and conditions for processing personal data of the Company's employees and consumers of the Company's services whose personal data are processed by the organization, in order to ensure the protection of human and civil rights and freedoms when personal data are processed, including the right to privacy and personal and family secrecy, and also establishes the responsibility of Company officials who have access to personal data for failure to comply with the requirements governing the processing and protection of personal data.
This Policy on the processing of personal data in the Company (hereinafter, the Policy) has been prepared in accordance with Federal Law No. 152-FZ of 27 July 2006 "On Personal Data".
1. Concept and composition of personal data
The list of personal data subject to protection in the Company is determined by the following regulatory acts of the Russian Federation:
- Federal Law No. 152-FZ of 27 July 2006 "On Personal Data";
- Federal Law No. 197-FZ of 30 December 2001 "Labour Code of the Russian Federation";
- Federal Law No. 402-FZ of 6 December 2001 "On Accounting";
- Tax Code of the Russian Federation;
- Civil Code of the Russian Federation;
- Federal Law No. 27-FZ of 1 April 1996 "On Individual (Personalized) Records in the Compulsory Pension Insurance System";
- the Labour Code of the Russian Federation and other regulatory legal acts.
Personal data in the Company means any information relating to a directly or indirectly identified or identifiable natural person (personal data subject).
2. Purposes of personal data processing
The Company processes personal data for the following purposes:
- organizing the Company's HR records;
- ensuring compliance with laws and other regulatory legal acts;
- conducting HR administration;
- fulfilling tax-law requirements in connection with calculation and payment of personal income tax and the unified social tax, and pension legislation when forming and submitting personalized data on each income recipient taken into account when assessing compulsory pension insurance contributions;
- completing primary statistical documentation in accordance with the Labour Code of the Russian Federation, the Tax Code of the Russian Federation, federal laws (in particular "On Individual (Personalized) Records in the Compulsory Pension Insurance System", "On Personal Data") and other regulatory legal acts;
- performing contractual obligations, including warranty service for consumers of the Company's services;
- other activities in accordance with the Company's Charter and the applicable laws of the Russian Federation.
3. Personal data processing periods
Personal data processing periods are determined in accordance with the term of the contract (agreement) with the personal data subject, limitation periods, achievement of processing purposes, and other requirements of Russian Federation law.
The Company creates and stores documents containing information about personal data subjects. Requirements for the Company's use of standard document forms are established by Decree of the Government of the Russian Federation No. 687 of 15 September 2008 "On Approval of the Regulation on Specifics of Personal Data Processing Carried Out Without Automation Tools".
4. Rights and obligations
As a personal data operator, the Company is entitled to:
- defend its interests in court;
- provide subjects' personal data to third parties if required by applicable law (tax authorities, law-enforcement bodies, etc.) or by the subject's agreement;
- refuse to provide personal data in cases provided by applicable law;
- use a subject's personal data without consent in cases provided by law.
A personal data subject is entitled to:
- require clarification, blocking, or destruction of personal data if they are incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated processing purpose, and take statutory measures to protect their rights;
- require a list of their personal data processed by the Company and the source of those data;
- receive information on the periods of processing of their personal data, including retention periods;
- require notice to all persons who previously received incorrect or incomplete personal data of all exclusions, corrections, or additions made;
- appeal to the authorized body for protection of personal data subjects' rights or to a court against unlawful acts or omissions in the processing of their personal data.
5. Principles and conditions of personal data processing
Personal data are processed in the Company based on the following principles:
- lawfulness of the purposes and methods of personal data processing;
- consistency of processing purposes with the purposes predetermined and stated when personal data were collected;
- consistency of the volume and nature of processed personal data and processing methods with the processing purposes;
- accuracy of personal data and their sufficiency for processing purposes, and impermissibility of processing personal data that are excessive relative to the purposes stated at collection;
- impermissibility of merging databases containing personal data that were created for incompatible purposes;
- storage of personal data in a form that allows identification of the personal data subject no longer than required by the processing purposes;
- destruction upon achievement of processing purposes or when those purposes are no longer necessary.
A consumer's refusal to consent to processing of their personal data makes it impossible to achieve the processing purposes.
6. Ensuring personal data security
The Company takes necessary organizational and technical measures to protect personal data from accidental or unauthorized access, destruction, alteration, blocking of access, and other unauthorized actions.
To coordinate personal data security measures, the Company has appointed a person responsible for organizing personal data protection.
7. Final provisions
This Policy is intended for publication on the Company's publicly available information resources.
This Policy is subject to amendment and supplementation if new legislative acts and special regulatory documents on personal data processing and protection appear, but at least once every three years.
Compliance with this Policy is supervised by the person responsible for organizing personal data processing in the Company.
The liability of Company officials who have access to personal data for failure to meet the requirements governing personal data processing and protection is determined in accordance with the laws of the Russian Federation and the Company's internal documents.
