Company policy regarding the processing of personal data

2023 YEAR

1. GENERAL PROVISIONS


This Policy defines the procedure for processing personal data and measures to ensure the security of personal data in IP Antonchenko Tatyana Aleksandrovna (hereinafter referred to as the Operator) in order to protect the rights and freedoms of a person and citizen when processing his personal data, including protecting the rights to privacy, personal and family secrets.


The following basic concepts are used in the Policy:
  • automated processing of personal data — processing of personal data using computer technology;
  • blocking of personal data - temporary suspension of the processing of personal data (except when processing is necessary to clarify personal data);
  • personal data information system - a set of personal data contained in databases, and information technologies and technical means that ensure their processing;
  • depersonalization of personal data - actions, as a result of which it is impossible to determine, without the use of additional information, the ownership of personal data by a specific subject of personal data;
  • processing of personal data - any action (operation) or a set of actions (operations) performed with the use of automation tools or without the use of such tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data;
  • operator - a state body, a municipal body, a legal entity or an individual, independently or jointly with other persons organizing and (or) carrying out the processing of personal data, as well as determining the purposes of processing personal data, the composition of personal data to be processed, actions (operations) performed with personal data;
  • Personal Information — any information relating to a directly or indirectly identified or identifiable natural person (subject of personal data);
  • provision of personal data - actions aimed at disclosing personal data to a certain person or a certain circle of persons;
  • dissemination of personal data - actions aimed at disclosing personal data to an indefinite circle of persons (transfer of personal data) or familiarizing with personal data of an unlimited number of persons, including the disclosure of personal data in the media, placement in information and telecommunication networks or providing access to personal data to any otherwise;
  • cross-border transfer of personal data - transfer of personal data to the territory of a foreign state to the authority of a foreign state, a foreign individual or foreign legal entity.
  • destruction of personal data — actions as a result of which it is impossible to restore the content of personal data in the information system of personal data and (or) as a result of which material carriers of personal data are destroyed;

The Company is required to publish or otherwise make available
this Personal Data Processing Policy.


2 PRINCIPLES AND CONDITIONS FOR PROCESSING PERSONAL DATA


2.1 Principles of personal data processing

The processing of personal data by the Operator is carried out on the basis of the following principles:
- legality and fair basis;
restrictions on the processing of personal data by achieving specific, predetermined and legitimate goals;
- preventing the processing of personal data that is incompatible with the purposes of collecting personal data;
- preventing the merger of databases containing personal data, the processing of which is carried out for purposes that are incompatible with each other;
- processing only those personal data that meet the purposes of their processing;
compliance of the content and scope of the processed personal data with the stated purposes of processing;
- preventing the processing of personal data that is excessive in relation to the stated purposes of their processing;
- ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of processing personal data;
- destruction or depersonalization of personal data upon reaching the goals of their processing or in case of loss of the need to achieve these goals, if it is impossible for the Operator to eliminate the committed violations of personal data, unless otherwise provided.

2.2 Conditions for the processing of personal data

The operator processes personal data in the presence of at least one of the following conditions:
- processing of personal data is carried out with the consent of the subject of personal data to the processing of his personal data;
- the processing of personal data is necessary to achieve the goals provided for by an international treaty or law, to exercise and fulfill the functions, powers and duties assigned to the operator;
- the processing of personal data is necessary for the administration of justice, the execution of a judicial act, an act of another body or official subject to execution in accordance with enforcement proceedings;
- the processing of personal data is necessary for the performance of an agreement to which the personal data subject is a party or beneficiary or guarantor, as well as to conclude an agreement on the initiative of the personal data subject or an agreement under which the personal data subject will be the beneficiary or guarantor;
- the processing of personal data is necessary to exercise the rights and legitimate interests of the operator or third parties or to achieve socially significant goals, provided that the rights and freedoms of the subject of personal data are not violated;
- processing of personal data is carried out, the access of an unlimited number of persons to which is provided by the subject of personal data or at his request (hereinafter referred to as publicly available personal data);
- processing of personal data subject to publication or mandatory disclosure in accordance with the law is carried out.

2.3 Privacy of personal data

The operator and other persons who have gained access to personal data are obliged not to disclose to third parties and not to distribute personal data without the consent of the subject of personal data, unless otherwise provided.

2.4 Public sources of personal data

For the purpose of information support, the Operator may create publicly available sources of personal data of subjects, including directories and address books. Publicly available sources of personal data, with the written consent of the subject, may include his last name, first name, patronymic, date and place of birth, position, contact phone numbers, e-mail address and other personal data reported by the subject of personal data.

Information about the subject must be excluded from public sources of personal data at any time at the request of the subject or by decision of the court or other authorized state bodies.


2.5 Special categories of personal data

Processing by the Operator of special categories of personal data relating to race, nationality, political views, religious or philosophical beliefs, health status, intimate life is allowed in cases where:
- the subject of personal data has given his consent in writing to the processing of his personal data;
- personal data is made public by the subject of personal data;
- processing of personal data is carried out in accordance with the legislation on state social assistance, labor legislation on pensions for state pensions, labor pensions;
- the processing of personal data is necessary to protect the life, health or other vital interests of the subject of personal data or the life, health or other vital interests of other persons and obtaining the consent of the subject

The processing of special categories of personal data must be immediately terminated if the reasons for which they were processed have been eliminated, unless otherwise established.

The processing of personal data on a criminal record may be carried out by the Operator only in cases and in the manner determined in accordance with the law.


2.6 Biometric personal data

Information that characterizes the physiological and biological characteristics of a person, on the basis of which it is possible to establish his identity - biometric personal data - can be processed by the Operator only with the consent in writing of the subject.


2.7 Entrusting the processing of personal data to another person

The operator has the right to entrust the processing of personal data to another person with the consent of the subject of personal data, unless otherwise provided, on the basis of an agreement concluded with this person.

The person who processes personal data for
on behalf of the Operator, is obliged to comply with the principles and rules for the processing of personal data provided for by law.


2.8 Cross-border transfer of personal data

The operator is obliged to make sure that the foreign state, to whose territory the transfer of personal data is supposed to be carried out, provides adequate protection of the rights of personal data subjects, before the start of such transfer.

Cross-border transfer of personal data on the territory of foreign states that do not provide adequate protection of the rights of personal data subjects can be carried out

in cases of:
- availability of consent in writing of the subject of personal data to -- cross-border transfer of his personal data;
performance of an agreement to which the subject of personal data is a party.

3 RIGHTS OF THE SUBJECT OF PERSONAL DATA
3.1 Consent of the subject of personal data to the processing of his personal data

The subject of personal data decides to provide his personal data and agrees to their processing freely, by his own will and in his own interest. Consent to the processing of personal data may be given by the subject of personal data or his representative in any form that allows confirming the fact of its receipt, unless otherwise
established by law.

The obligation to provide proof of obtaining the consent of the subject of personal data to the processing of his personal data or proof of the existence of the grounds specified in the legislation rests with the Operator.


3.2 Rights of the subject of personal data

The subject of personal data has the right to receive information from the Operator regarding the processing of his personal data, if such right is not limited in accordance with the law. The subject of personal data has the right to demand from the Operator the clarification of his personal data, their blocking or destruction if the personal data is incomplete, outdated, inaccurate, illegally obtained or not necessary for the stated purpose of processing, as well as take measures provided by law to protect their rights .

The processing of personal data in order to promote goods, works, services on the market by making direct contacts with a potential consumer using means of communication, as well as for the purposes of political campaigning, is allowed only with the prior consent of the subject of personal data.

The specified processing of personal data is recognized as carried out without the prior consent of the subject of personal data, if the Company does not
prove that such consent has been obtained.

The operator is obliged to immediately stop, at the request of the subject of personal data, the processing of his personal data for the above purposes.

It is prohibited to make decisions on the basis of exclusively automated processing of personal data that give rise to legal consequences in relation to the subject of personal data or otherwise affect his rights and legitimate interests, except as provided by law, or if there is consent in
written form of the subject of personal data.

If the subject of personal data believes that the Operator is processing his personal data in violation of the requirements of the law or otherwise violates his rights and freedoms, the subject of personal data has the right to appeal against the actions or inaction of the Operator to the Authorized body for the protection of the rights of subjects of personal data or in court.

The subject of personal data has the right to protect his rights and legitimate interests, including compensation for losses and (or) compensation for moral damage in court.


4 KEEPING THE SECURITY OF PERSONAL DATA

The security of personal data processed by the Operator is ensured by the implementation of legal, organizational and technical measures necessary to ensure the requirements of legislation in the field of personal data protection.

To prevent unauthorized access to personal data, the Operator applies the following organizational and technical measures:

- appointment of officials, if necessary, responsible for organizing the processing and protection of personal data;
- restriction of the composition of persons having access to personal data;
familiarization of the subjects with the requirements of the legislation and regulatory documents of the Operator for the processing and protection of personal data;
- organization of accounting, storage and circulation of information carriers;
identification of threats to the security of personal data during their processing, the formation of threat models on their basis;
- development of a personal data protection system based on the threat model;
verification of the readiness and effectiveness of the use of information security tools;
- delimitation of user access to information resources and
software and hardware for information processing;
- registration and accounting of actions of users of personal data information systems;
- use of anti-virus tools and means of restoring the personal data protection system;
- application, if necessary, of firewalls, intrusion detection, security analysis and cryptographic information protection;
organization of access control to the territory of the Operator, protection of premises with technical means of processing personal data.


5 FINAL PROVISIONS

Other rights and obligations of the Operator, as an operator of personal data, are determined by legislation in the field of personal data.

Officials of the Operator guilty of violating the rules governing the processing and protection of personal data will bear material, disciplinary, administrative, civil or criminal liability in the manner prescribed by law.

The Company has the right to make changes to this Privacy Policy without the consent of the User.

All suggestions or questions regarding this Privacy Policy should be reported to the "Contacts" section of the site.

The current Privacy Policy is posted on the page at: https://antinteriordevelopment.com/confidentiality-personal

Made on
Tilda