Policy regarding the processing of personal data at IE Zenin A.D.
1.1. This policy regarding the processing of personal data defines the policy of Individual Entrepreneur Zenin Andrey Dmitrievich, TIN: 771676304550 (hereinafter referred to as the "Operator") regarding the processing of personal data (hereinafter referred to as the "Policy") and is a publicly available document.
1.2. The requirements of the Policy are mandatory for the Operator and all employees of the Operator who have been granted access to personal data.
1.3. Decisions to amend this Policy are made based on:
1.3.1. the results of audits, monitoring and oversight activities for ensuring the security of personal data carried out by authorized bodies;
1.3.2. changes to regulatory legal acts and normative-methodological documents of the Russian Federation governing relations related to ensuring the security of personal data during their processing in personal data information systems (hereinafter referred to as "PDIS");
1.3.3. changes to the processes of personal data processing in the Operator's PDIS;
1.3.4. the results of analysis of information security incidents in PDIS.
1.4. Key terms used in the Policy:
1.4.1. personal data — any information relating to a directly or indirectly identified or identifiable natural person (personal data subject);
1.4.2. personal data operator (operator) — a state body, municipal body, legal entity or natural person that independently or jointly with other persons organizes and (or) carries out the processing of personal data, as well as determines the purposes of personal data processing, the composition of personal data to be processed, and the actions (operations) performed with personal data;
1.4.3. processing of personal data — any action (operation) or set of actions (operations) performed with or without the use of automated means with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data;
1.4.4. automated processing of personal data — processing of personal data using computer technology;
1.4.5. distribution of personal data — actions aimed at disclosing personal data to an indefinite number of persons;
1.4.6. provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons;
1.4.7. blocking of personal data — temporary cessation of personal data processing (except in cases where processing is necessary for clarifying personal data);
1.4.8. destruction of personal data — actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which the physical media of personal data are destroyed;
1.4.9. depersonalization of personal data — actions as a result of which it becomes impossible to determine, without the use of additional information, the association of personal data with a specific personal data subject;
1.4.10. personal data information system — a set of personal data contained in databases and the information technologies and technical means ensuring their processing;
1.4.11. cross-border transfer of personal data — transfer of personal data to the territory of a foreign state to a foreign state authority, a foreign natural person, or a foreign legal entity.
2.1. Rights and obligations of the Personal Data Operator:
2.1.1. The Operator is obliged to immediately cease, at the request of the personal data subject, the processing of their personal data for the purpose of promoting goods, works, and services on the market through direct contact with a potential consumer using communication means.
2.1.2. The Operator is obliged to explain to the personal data subject the procedure for making decisions based exclusively on automated processing of their personal data and the possible legal consequences of such a decision, to provide the opportunity to object to such a decision, and also to explain the procedure for protecting the personal data subject's rights and legitimate interests.
2.1.3. The Operator is obliged to consider the objection against a decision based exclusively on automated processing of the personal data subject's personal data within thirty days from the date of its receipt and to notify the personal data subject of the results of the consideration of such objection.
2.1.4. When collecting personal data, the Operator is obliged to provide the personal data subject, at their request, with information stipulated by Part 7 of Article 14 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data."
2.1.5. If the provision of personal data is mandatory in accordance with federal law, the Operator is obliged to explain to the personal data subject the legal consequences of refusing to provide their personal data.
2.1.6. The Operator is obliged to inform, in the manner prescribed by Article 14 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data," the personal data subject or their representative about the existence of personal data relating to the respective personal data subject, and also to provide the opportunity to review these personal data upon request of the personal data subject or their representative, or within thirty days from the date of receipt of the request of the personal data subject or their representative.
2.1.7. The Operator is obliged to provide the personal data subject or their representative with free access to review personal data relating to that subject. Within a period not exceeding seven business days from the date of the personal data subject or their representative providing information confirming that personal data are incomplete, inaccurate, or outdated, the Operator is obliged to make the necessary changes. Within a period not exceeding seven business days from the date of the personal data subject or their representative providing information confirming that such personal data were unlawfully obtained or are not necessary for the stated purpose of processing, the Operator is obliged to destroy such personal data. The Operator is obliged to notify the personal data subject or their representative of the changes made and measures taken, and to take reasonable steps to notify third parties to whom the personal data of this subject were transferred.
2.1.8. The Operator is obliged to provide the authorized body for the protection of the rights of personal data subjects, upon request of that body, with the necessary information within thirty days from the date of receipt of such request.
2.1.9. In the event of the detection of unlawful processing of personal data upon the request of the personal data subject or their representative, or upon the request of the personal data subject or their representative, or the authorized body for the protection of the rights of personal data subjects, the Operator is obliged to block the unlawfully processed personal data relating to that subject, or to ensure their blocking (if personal data processing is carried out by another person acting on behalf of the Operator) from the moment of such request or receipt of the said request for the period of verification. In the event of the detection of inaccurate personal data upon the request of the personal data subject or their representative, or upon their request, or upon the request of the authorized body for the protection of the rights of personal data subjects, the Operator is obliged to block the personal data relating to that subject, or to ensure their blocking (if personal data processing is carried out by another person acting on behalf of the Operator) from the moment of such request or receipt of the said request for the period of verification, provided that blocking of personal data does not violate the rights and legitimate interests of the personal data subject or third parties.
2.1.10. In the event of confirmation of the fact of inaccuracy of personal data, the Operator, on the basis of information provided by the personal data subject or their representative, or the authorized body for the protection of the rights of personal data subjects, or other necessary documents, is obliged to clarify the personal data or ensure their clarification (if personal data processing is carried out by another person acting on behalf of the Operator) within seven business days from the date of provision of such information and to unblock the personal data.
2.1.11. In the event of the detection of unlawful processing of personal data carried out by the Operator or a person acting on behalf of the Operator, the Operator is obliged, within a period not exceeding three business days from the date of such detection, to cease the unlawful processing of personal data or to ensure the cessation of the unlawful processing of personal data by the person acting on behalf of the Operator. In the event that it is impossible to ensure the lawfulness of the personal data processing, the Operator is obliged, within a period not exceeding ten business days from the date of detection of unlawful processing of personal data, to destroy such personal data or to ensure their destruction. The Operator is obliged to notify the personal data subject or their representative of the elimination of the violations committed or the destruction of the personal data, and in the event that the request of the personal data subject or their representative or the request of the authorized body for the protection of the rights of personal data subjects was submitted by the authorized body for the protection of the rights of personal data subjects, also to notify the said body.
2.1.12. Upon achievement of the purpose of personal data processing, the Operator is obliged to cease the processing of personal data or to ensure its cessation (if personal data processing is carried out by another person acting on behalf of the Operator) and to destroy the personal data or to ensure their destruction (if personal data processing is carried out by another person acting on behalf of the Operator) within a period not exceeding thirty days from the date of achievement of the purpose of personal data processing, unless otherwise provided by a contract to which the personal data subject is a party, beneficiary, or guarantor, by another agreement between the Operator and the personal data subject, or if the Operator is not entitled to carry out personal data processing without the consent of the personal data subject on the grounds provided by Federal Law No. 152-FZ of July 27, 2006 "On Personal Data" or other regulatory legal acts.
2.1.13. In the event that the personal data subject withdraws consent to the processing of their personal data, the Operator is obliged to cease their processing or to ensure the cessation of such processing (if personal data processing is carried out by another person acting on behalf of the Operator) and, in the event that the retention of personal data is no longer required for the purposes of personal data processing, to destroy the personal data or to ensure their destruction (if personal data processing is carried out by another person acting on behalf of the Operator) within a period not exceeding thirty days from the date of receipt of the said withdrawal, unless otherwise provided by a contract to which the personal data subject is a party, beneficiary, or guarantor, by another agreement between the Operator and the personal data subject, or if the Operator is not entitled to carry out personal data processing without the consent of the personal data subject on the grounds provided by this federal law or other federal laws.
2.1.14. In the event that it is impossible to destroy personal data, the Operator shall block such personal data or ensure their blocking (if personal data processing is carried out by another person acting on behalf of the Operator) and shall ensure the destruction of personal data within a period of no more than six months, unless a different period is established by federal laws.
2.2. Rights of personal data subjects:
2.2.1. The personal data subject has the right to obtain information about the processing of their personal data by the Operator.
2.2.2. The personal data subject has the right to demand that the Operator processing their personal data clarify, block, or destroy such personal data if they are incomplete, outdated, inaccurate, unlawfully obtained, or are not necessary for the stated purpose of processing, and also to take measures provided by law to protect their rights.
2.2.3. In the event that the information specified in Part 7 of Article 14 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data," as well as the processed personal data, were provided for review to the personal data subject at their request, the personal data subject has the right to contact the Operator again or to send a repeat request in order to obtain the information specified in Part 7 of this article and to review such personal data no earlier than thirty days after the initial request or the initial submission, unless a shorter period is established by a federal law, a regulatory legal act adopted in accordance with it, or a contract to which the personal data subject is a party, beneficiary, or guarantor.
2.2.4. The personal data subject has the right to contact the Operator again or to send a repeat request in order to obtain the information specified in Part 7 of Article 14 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data," as well as to review the processed personal data before the expiration of the period specified in Part 4 of Article 14 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data," in the event that such information and (or) processed personal data were not provided to them for review in full based on the results of the consideration of the initial request.
2.2.5. The right of the personal data subject to access their personal data may be restricted in accordance with Part 8 of Article 14 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data" in the following cases:
2.2.6. If the processing of personal data, including data obtained as a result of operational-investigative, counterintelligence, and intelligence activities, is carried out for the purposes of strengthening the country's defense, ensuring state security, and maintaining law and order;
2.2.7. If the processing of personal data is carried out by authorities that have detained the personal data subject on suspicion of committing a crime, or that have charged the personal data subject in a criminal case, or that have applied a preventive measure to the personal data subject before charges are brought, except in cases provided by the criminal procedural legislation of the Russian Federation where the suspect or the accused is allowed to review such personal data;
2.2.8. If the processing of personal data is carried out in accordance with the legislation on countering the legalization (laundering) of proceeds from crime and the financing of terrorism;
2.2.9. If the access of the personal data subject to their personal data violates the rights and legitimate interests of third parties;
2.2.10. If the processing of personal data is carried out in cases provided by the legislation of the Russian Federation on transport security, for the purposes of ensuring the stable and safe functioning of the transport complex, and protecting the interests of individuals, society, and the state in the sphere of the transport complex from acts of unlawful interference;
2.2.11. If the personal data subject believes that the Operator is processing their personal data in violation of the requirements of this Federal Law or otherwise violates their rights and freedoms, the personal data subject has the right to appeal the actions or inaction of the Operator to the authorized body for the protection of the rights of personal data subjects or in court.
2.2.12. The personal data subject has the right to protect their rights and legitimate interests, including compensation for damages and (or) compensation for moral harm through the courts.
3.1. Personal data is processed for the following purposes:
3.1.1. processing incoming requests from users of the website located on the Internet at: https://zenin1.ru/ (hereinafter referred to as the "Website"), received through feedback forms and other forms on the Website;
3.1.2. entering into and fulfilling contracts with clients, including for the purpose of executing contracts on the Operator's Website;
3.1.3. promotion of goods, works, and services on the market through direct contact with potential consumers using communication means;
3.1.4. providing information about new events, special promotions, and offers;
3.1.5. carrying out activities in accordance with the constituent documents.
4.1. The Operator processes personal data in accordance with:
4.2. The Constitution of the Russian Federation, Federal Law No. 149-FZ of July 27, 2006 "On Information, Information Technologies and Information Protection";
4.3. Decrees of the Government of the Russian Federation No. 687 of September 15, 2008 "On Approval of the Regulation on the Specifics of Personal Data Processing Carried Out Without the Use of Automated Means," No. 1119 of November 1, 2012 "On Approval of Requirements for the Protection of Personal Data During Their Processing in Personal Data Information Systems";
4.4. This Policy regarding the processing of personal data;
4.5. Consent to the processing of personal data given by the personal data subject;
4.6. Civil law contracts entered into by the Operator with clients and counterparties, as well as annexes to such contracts.
5.1. The Operator processes the following categories of personal data:
5.1.1. Clients and counterparties of the Operator (Natural persons): Surname, first name, patronymic; type, series, and number of the identity document, date of issue and information about the issuing authority, date of birth, place of birth, registration address, contact phone number; email address;
5.1.2. Representatives/employees of clients and counterparties of the Operator (legal entities and natural persons): Surname, first name, patronymic; contact phone number; email address; postal address (country, region, city, street, building number, apartment/office number).
6.1. The list of actions performed by the Operator with the personal data of subjects includes: collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, and destruction of personal data. The above actions are performed by the Operator both with and without the use of automated means.
6.2. Conditions for the cessation of personal data processing:
6.2.1. achievement of the purposes of personal data processing;
6.2.2. expiration of the consent period or withdrawal of consent by the personal data subject to the processing of their personal data;
6.2.3. detection of unlawful processing of personal data.
6.3. In order to comply with the legislation of the Russian Federation, and with the consent of personal data subjects, to achieve the purposes of processing, the Operator, in the course of its activities, has the right to provide personal data to third parties. Information about third parties involved in the processing of personal data:
6.3.1. Personal data of clients and counterparties of the Operator (Natural persons), representatives/employees of clients and counterparties of the Operator, for the fulfillment of contractual obligations between the Operator and the above-mentioned personal data subjects;
6.3.2. Employees and non-employees: upon receipt, within established authority, of motivated requests from prosecution authorities, law enforcement agencies, security agencies, state labor inspectors exercising state supervision and control over compliance with labor legislation, and other bodies authorized to request information about employees in accordance with the competence provided by the legislation of the Russian Federation.
6.4. When processing personal data, the Operator takes the necessary legal, organizational, and technical measures or ensures their adoption for the protection of personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, distribution of personal data, as well as from other unlawful actions with respect to personal data. Security is achieved through:
6.4.1. Identifying threats to the security of personal data during their processing in personal data information systems;
6.4.2. Applying organizational and technical measures to ensure the security of personal data during their processing in personal data information systems, necessary to meet the requirements for the protection of personal data, the fulfillment of which ensures the levels of protection of personal data established by the Government of the Russian Federation;
6.4.3. Applying information protection means that have undergone the established conformity assessment procedure;
6.4.4. Detecting instances of unauthorized access to personal data and taking measures;
6.4.5. Restoring personal data that have been modified or destroyed as a result of unauthorized access;
6.4.6. Establishing rules for access to personal data processed in the personal data information system, as well as ensuring the registration and recording of all actions performed with personal data in the personal data information system;
6.4.7. Monitoring the measures taken to ensure the security of personal data and the level of protection of personal data information systems.
6.5. The Operator stores personal data in accordance with the current legislation of the Russian Federation in a form that allows the identification of the personal data subject for no longer than required by the purposes of personal data processing, unless the period of storage of personal data is established by federal law, a contract to which the personal data subject is a party, beneficiary, or guarantor.
6.6. When storing personal data, the Operator uses databases located on the territory of the Russian Federation.
7.1. In the event of confirmation of the fact of inaccuracy of personal data or unlawfulness of their processing, the personal data shall be updated by the Operator, and the processing shall be ceased, respectively.
7.2. Upon achievement of the purposes of personal data processing, as well as in the event that the personal data subject withdraws consent to their processing, the personal data shall be destroyed, unless:
— otherwise provided by a contract to which the personal data subject is a party, beneficiary, or guarantor;
— the Operator is not entitled to carry out processing without the consent of the personal data subject on the grounds provided by Federal Law "On Personal Data" or other federal laws;
— otherwise provided by another agreement between the Operator and the personal data subject.