Privacy Policy
Privacy Policy
Introduction
This document defines the policy of the Company (hereinafter referred to as the Company) with respect to the processing of personal data (hereinafter also referred to as Personal Data).
The Company acts as a Personal Data operator in accordance with applicable personal data protection legislation.
This Policy has been developed in compliance with applicable legislation in the field of personal data protection.
This Policy applies to all Personal Data that the Company may receive about a data subject in the course of using any of the Company's websites, software, products and/or services, as well as the Company's accounts on third-party websites, social networks, messengers and applications.
This Policy covers any action (operation) or set of actions (operations) performed with or without the use of automated means with respect to Personal Data, including collection, recording, organization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion and destruction of Personal Data.
This Policy may be amended. The Company reserves the right to make amendments at its sole discretion, including but not limited to cases where such amendments are required by changes in applicable legislation or by changes in the operation of the Company's websites, software, products and/or services.
Key Definitions
Automated processing of Personal Data – processing of Personal Data using computer technology.
Blocking of Personal Data – temporary suspension of Personal Data processing (except where processing is required for the purpose of clarifying Personal Data).
Personal Data information system – a set of Personal Data contained in databases and information technologies and technical means ensuring their processing.
Anonymization of Personal Data – actions as a result of which it becomes impossible, without the use of additional information, to determine whether Personal Data belongs to a specific user or other data subject.
Processing of Personal Data – any action (operation) or set of actions (operations) performed with or without the use of automated means with respect to Personal Data, including collection, recording, organization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion and destruction of Personal Data.
Operator – a legal entity or individual that, independently or jointly with other persons, organizes and/or carries out the processing of Personal Data, and also determines the purposes of processing Personal Data, the composition of Personal Data to be processed, and the actions (operations) to be performed with Personal Data.
Personal Data – any information relating directly or indirectly to an identified or identifiable individual (data subject).
User – an individual or legal entity using the Company's websites, software, products and/or services.
Destruction of Personal Data – any actions as a result of which Personal Data is destroyed irreversibly with no possibility of further restoration of the content of Personal Data in the Personal Data information system, and/or physical data carriers are destroyed.
Principles of Personal Data Processing
Personal Data is processed on the basis of the following principles:
processing of Personal Data is carried out on a lawful and fair basis;
processing of Personal Data is limited to the achievement of specific, predetermined and legitimate purposes;
processing of Personal Data that is incompatible with the purposes of collection is not permitted;
the merging of databases containing Personal Data processed for incompatible purposes is not permitted;
the content and volume of Personal Data processed are consistent with the stated processing purposes. Personal Data processed is not excessive in relation to the stated processing purposes;
when processing Personal Data, accuracy, sufficiency and relevance of Personal Data in relation to the stated processing purposes are ensured;
Personal Data is stored in a form that allows identification of the data subject for no longer than required by the purposes of Personal Data processing;
Personal Data subject to destruction or anonymization upon achievement of processing purposes or in the event that the need to achieve such purposes is lost.
Scope and Categories of Personal Data Processed
The Company may collect the following categories of Personal Data about Users during their use of the Company's websites, software, products and/or services:
Personal Data provided by the User when contacting the Company, such as first name, last name, phone number, email address, company name and job title;
electronic data (HTTP headers, IP address, cookies, web beacons, pixel tags, browser identifier data, hardware and software information);
date and time of access to the Company's websites, software, products and/or services;
information about User activity during the use of the Company's websites and services;
other information about the User necessary for processing in accordance with the terms governing the use of specific websites, software, products and/or services of the Company.
The Company collects anonymized statistics on the use of its websites for the purpose of their development and improvement.
The Company does not process special categories of personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, intimate life or other special categories.
Methods of Personal Data Processing
Collection: via website forms, email, messengers;
Recording: into information systems and databases;
Organization, accumulation: storage of data by categories;
Storage: on servers and in cloud storage;
Clarification (updating, modification): manually or automatically;
Use: to communicate with users and to provide the Company's services;
Transfer (distribution, provision, access): to third parties in cases provided for by this Policy;
Anonymization and destruction: automatically or manually, upon achievement of the purpose and expiry of the processing period.
Personal Data Retention Period
Personal Data is stored for 5 years from the date of the last interaction with the data subject, or until the processing purposes are achieved, or until the data subject withdraws consent to its processing.
Categories of Data Subjects
The Company processes Personal Data of the following categories of data subjects:
clients of the Company (individuals and representatives of legal entities);
individuals who are representatives of legal entities that are partners or clients of the Company;
visitors to the Company's website.
Conditions and Purposes of Personal Data Processing
Personal Data is processed in the following cases:
processing of Personal Data is carried out with the consent of the data subject;
processing of Personal Data is necessary for the performance of a contract to which the data subject is a party, a beneficiary or a guarantor, or for the conclusion of a contract at the initiative of the data subject;
processing of Personal Data is necessary for the exercise of the legitimate interests of the operator or third parties, provided that the rights and freedoms of the data subject are not violated;
processing of Personal Data is carried out for statistical or other research purposes, subject to mandatory anonymization of Personal Data.
Purposes of Personal Data processing:
responding to User inquiries and requests;
providing information about the Company's services;
entering into and performing contracts;
traffic analytics and improvement of the website;
sending informational and commercial communications with the User's consent.
When entrusting the processing of Personal Data to another party, the Company enters into an agreement with that party requiring it to comply with the principles and rules of Personal Data processing.
The Company undertakes, and obliges other parties granted access to Personal Data, not to disclose to third parties or distribute Personal Data without the consent of the data subject, unless otherwise provided by applicable legislation.
Personal Data Security Measures
When processing Personal Data, the Company applies the necessary legal, organizational and technical measures to protect Personal Data against unauthorized or accidental access, destruction, modification, blocking, copying, provision, distribution and other unlawful actions. The security of Personal Data is ensured by the following measures:
identification of threats to the security of Personal Data during its processing in Personal Data information systems;
application of organizational and technical measures to ensure the security of Personal Data;
assessment of the effectiveness of measures taken to ensure the security of Personal Data;
detection of unauthorized access to Personal Data and implementation of appropriate response measures;
establishment of rules for access to Personal Data processed in Personal Data information systems;
monitoring compliance of Personal Data processing with applicable legislation and internal Company documents.
Rights of the Data Subject
The data subject has the right to:
obtain confirmation of the fact that Personal Data is being processed by the Company, as well as information about the legal grounds, purposes, methods and retention periods of processing;
demand that the Company clarify, block or destroy his or her Personal Data if the Personal Data is incomplete, outdated, inaccurate, unlawfully obtained or is no longer necessary for the stated processing purpose;
withdraw consent to the processing of Personal Data and demand the destruction of his or her Personal Data in cases provided by law;
lodge a complaint with the competent supervisory authority for the protection of data subjects' rights.
Confidentiality of Personal Data
Access to Personal Data is granted only to those employees of the Company who require it in connection with the performance of their job duties.
The Company does not disclose to third parties or distribute Personal Data without the consent of the data subject, unless otherwise provided by applicable legislation.
Third parties granted access to Personal Data on behalf of the Company undertake to comply with the confidentiality and security requirements for Personal Data in accordance with the agreements concluded.
Personal Data Destruction Procedure
Personal Data is destroyed upon achievement of the processing purposes, upon expiry of the retention period, or upon withdrawal of consent by the data subject, unless otherwise provided by applicable legislation.
Destruction is carried out in the following ways:
deletion from electronic storage media with no possibility of recovery;
physical destruction of paper-based media;
deletion from databases using software tools with no possibility of recovery.
Final Provisions
This Policy is subject to periodic review and improvement, including in cases of changes to applicable legislation or internal regulatory documents of the Company.
Compliance with the requirements of this Policy is monitored by persons responsible for organizing Personal Data processing and ensuring Personal Data security within the Company.