Personal Data Processing Policy

  • General provisions 1.1. This Policy of the limited liability company “MARKETOLOGY” regarding the processing of personal data (hereinafter – the Policy) is developed in pursuance of the requirements of paragraph 2 part 1 of article 18.1 of the Federal law of 27.07.2006 No. 152-FZ “On personal data” (hereinafter – the Law on personal data) in order to ensure the protection of human rights and freedoms when processing his personal data, including the protection of the rights to privacy, personal and family secrets.
    1.2. The Policy applies to all personal data processed by the limited liability company “MARKETOLOGY” (hereinafter – the Operator, LLC “MARKETOLOGY”).
    1.3. The Policy applies to relations in the field of personal data processing that arose at the Operator both before and after the approval of this Policy.
    1.4 Pursuant to the requirements of Part 2 of Art. 18.1 of the Law on Personal Data, this Policy is published in free access in the information and telecommunication network Internet on the website of the Operator. marketologiya.com.
  • Terms and abbreviations adopted Personal data (PD)) – any information relating directly or indirectly to a specific or identifiable natural person (personal data subject).
    Personal data allowed by the subject of personal data for dissemination personal data, access of an unlimited number of persons to which is provided by the subject of personal data by giving consent to the processing of personal data allowed by the subject of personal data for distribution.
    Personal data controller (operator) a state body, municipal body, legal or natural person, independently or jointly with other persons organizing and (or) carrying out the processing of personal data, as well as determining the purposes of personal data processing, the composition of personal data to be processed, actions (operations) performed with personal data.
    Processing of personal data – any action (operation) or set of actions (operations) with personal data, performed with or without the use of automation tools.
    collection; recording; systematization; accounting accumulation; storage; refinement (update, change); extraction; use; transfer (provision, access); distribution; depersonalization; blocking; removal; destruction.Automated processing of personal data – processing of personal data using computer equipment.
    Provision of personal data actions aimed at disclosing personal data to a certain person or a certain circle of persons.
    Dissemination of personal data actions aimed at disclosing personal data to an indefinite circle of persons.
    Blocking personal data temporary termination of the processing of personal data (except where the processing is necessary to clarify personal data).
    Destruction of personal data actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which material carriers of personal data are destroyed.
    Depersonalization of personal data actions as a result of which it becomes
    It is impossible without the use of additional information to determine the ownership of personal data to a specific subject of personal data.
    Personal data information system a set of personal data contained in databases and ensuring their processing, information technologies and technical means.
    Cross-border transfer of personal data transfer of personal data to the territory of a foreign state to the authority of a foreign state, a foreign individual or a foreign legal entity.
    Protection of personal data activities aimed at preventing the leakage of protected personal data, unauthorized and unintentional impacts on protected personal data.
  • collection;
  • recording;
  • systematization;
  • accounting
  • processing
  • accumulation;
  • storage;
  • clarification (update, change);
  • extraction;
  • use;
  • transfer (provision, access);
  • distribution;
  • depersonalization;
  • blocking;
  • removal;
  • destruction.
  • directly;
  • using the information system of the authorized body for the protection of the rights of personal data subjects.
  • obtaining personal data in oral and written form directly with the consent of the personal data subject to the processing or dissemination of his personal data;
  • entering personal data into the journals, registers and information systems of the Operator;
  • use of other methods of processing personal data.
  • identifies threats to the security of personal data during their processing;
  • adopts local regulations and other documents regulating relations in the field of processing and protection of personal data;
  • appoint persons responsible for ensuring the security of personal data in the structural units and information systems of the Operator;
  • creates the necessary conditions for working with personal data;
  • organizes registration of documents containing personal data;
  • organizes work with information systems in which personal data are processed;
  • stores personal data in conditions under which their safety is ensured and illegal access to them is excluded;
  • organizes training of the Operator’s employees who process personal data.
  • ensuring compliance with the Constitution, federal laws and other normative legal acts of the Russian Federation;
  • implementation of its activities in accordance with the Charter of LLC “Marketologiya”;
  • management of personnel records;
  • assistance to employees in employment, education and promotion, ensuring the personal safety of employees, monitoring the quantity and quality of work performed, ensuring the safety of property;
  • attracting and selecting candidates for work from the Operator;
  • organization of individual (personalized) registration of employees in the system of compulsory pension insurance;
  • filling and transfer to executive authorities and other authorized organizations of the required reporting forms;
  • implementation of civil legal relations;
  • accounting management;
  • implementation of the pass regime;
  • promotion of goods, works, services in the market.
  • individuals who are members of LLC “Marketologiya” in labor relations, or their relatives;
  • individuals who have resigned from “Marketologiya”;
  • natural persons who are candidates for work;
  • counterparties;
  • representatives of counterparties;
  • clients;
  • natural persons, consisting of LLC “Marketologiya” in civil relations.
  • data obtained in the implementation of employment relations;
  • data obtained for the selection of candidates for work;
  • data obtained in the implementation of civil law relations;
  • data obtained during the implementation of the pass mode to the territory of LLC “Marketologiya”;
  • data obtained when promoting goods, works, services of LLC “Marketologiya” on the market.
  • 4.1 In accordance with the requirements of regulatory documents, the Operator has created a system for the protection of personal data, consisting of subsystems of legal, organizational and technical protection.
    4.2 The subsystem of legal protection is a set of legal, organizational, administrative and regulatory documents that ensure the creation, functioning and improvement of the SPD.
    The organizational protection subsystem includes the organization of the management structure of the SWPD, the licensing system, the protection of information when working with employees, partners and third parties.
    The technical protection subsystem includes a complex of technical, software, software and hardware tools that ensure the protection of PD.
    The main PD protection measures used by the Operator are:
    4.5.1. Appointment of the person responsible for PD processing, who organizes PD processing, training and briefing, internal control over the compliance of the institution and its employees with the requirements for PD protection.
    4.5.2. Identification of current threats to PD security when they are processed in ISPD and development of measures and measures to protect PD.
    4.5.3. Development of a policy regarding the processing of personal data.
    Establishing rules for access to PD processed in the ISPD, as well as ensuring the registration and accounting of all actions performed with PD in the ISPD.
    4.5.5 Establishment of individual passwords for employees’ access to the information system in accordance with their work duties.
    4.5.6. Application of the procedure of conformity assessment of means of information protection passed in the established manner.
    4.5.7 Certified antivirus software with regularly updated databases.
    4.5.8 Compliance with conditions that ensure the safety of PD and exclude
    Unauthorized access to them.
    4.5.9. detection of facts of unauthorized access to personal data and taking measures.
    4.5.10 Restoration of PD modified or destroyed as a result of
    unauthorized access to them.
    4.5.11. training of the Operator’s employees who directly process personal data, the provisions of the legislation of the Russian Federation on personal data, including requirements for the protection of personal data, documents defining the Operator’s policy regarding the processing of personal data, local acts on the processing of personal data.
    Implementation of internal control and audit.
  • Basic rights of the PD subject and obligations of the Operator 5.1. Fundamental rights of the PD subject.
    The subject has the right to access his personal data and the following information:
    confirmation of the fact of processing PD by the Operator; legal grounds and purposes of processing PD; purposes and methods of processing PD used by the Operator; name and location of the Operator, information about persons (except for employees of the Operator) who have access to PD or who can be disclosed to PD on the basis of a contract with the Operator or on the basis of federal law; terms of processing of personal data, including the terms of their storage; procedure for the implementation by the subject of the rights provided by this federal law; name or surname, name, patronymic and address of the person who processes PD on behalf of the Operator, if the Operator or the transaction is directed to such person.
    The operator shall:
    when collecting PD, provide information on the processing of PD; in cases where the PD was not received from the PD subject, notify the subject; when refusing to provide PD to the subject, the consequences of such refusal are explained; publish or otherwise provide unrestricted access to the document defining its policy regarding the processing of PD, to information on the implemented requirements for the protection of PD; take the necessary legal, organizational and technical measures or ensure their adoption to protect the PD from illegal or accidental access to them, destruction, modification, blocking, copying, granting, distribution of PD, as well as from other unlawful actions in relation to the PD representatives;
  • confirmation of the fact of processing PD by the Operator;
  • legal grounds and purposes of PD processing;
  • purposes and methods of PD processing used by the Operator;
  • the name and location of the Operator, information about persons (except employees of the Operator) who have access to the PD or who can be disclosed to the PD on the basis of an agreement with the Operator or on the basis of federal law;
  • terms of personal data processing, including the terms of their storage;
  • the procedure for the implementation by the subject of PD of the rights provided for by this federal law;
  • the name or surname, name, patronymic and address of the person processing PD on behalf of the Operator, if the processing is entrusted or will be entrusted to such person;
  • contacting the Operator and sending him requests;
  • appeal against the actions or omissions of the Operator.
  • when collecting PD, provide information on the processing of PD;
  • in cases where the PD was not received from the PD subject, notify the subject;
  • in case of refusal to provide PD to the subject, the consequences of such refusal are explained;
  • publish or otherwise provide unrestricted access to the document defining its policy on PD processing, to information on the PD protection requirements implemented;
  • take the necessary legal, organizational and technical measures or ensure their adoption to protect PD from illegal or accidental access to them, destruction, modification, blocking, copying, provision, distribution of PD, as well as from other illegal actions in relation to PD;
  • respond to requests and appeals of PD subjects, their representatives and the authorized body for the protection of the rights of PD subjects.
  • Updating, rectification, deletion and destruction of personal data, responses to requests from subjects for access to personal data 6.1. Confirmation of the fact of processing personal data by the Operator, legal grounds and purposes of processing personal data, as well as other information specified in part 7 of Art. 14 of the Personal Data Law, are provided by the Operator to the personal data subject or his representative when applying or when receiving a request from the personal data subject or his representative.
    The information provided does not include personal data relating to other personal data subjects, unless there are legitimate grounds for disclosing such personal data.
    The request shall contain:
    the number of the main document certifying the identity of the personal data subject or his representative, information about the date of issue of the specified document and the body that issued it; information confirming the participation of the subject of personal data in relations with the Operator (contract number, date of conclusion of the contract, conditional verbal designation and (or) other information), or information otherwise confirming the fact of processing personal data by the Operator; signature of the personal data subject or his representative.The request can be sent in the form of an electronic document and signed by electronic signature in accordance with the legislation of the Russian Federation.
    If the request (request) of the subject of personal data does not reflect in accordance with the requirements of the Law on Personal Data all the necessary information or the subject does not have the rights of access to the requested information, then a reasoned refusal is sent to him.
    The right of the subject of personal data to access his personal data may be limited in accordance with Part 8 of Art. 14 of the Law on Personal Data, including if the access of the subject of personal data to his personal data violates the rights and legitimate interests of third parties.
    6.2 In case of revealing inaccurate personal data when the personal data subject or his representative applies or at their request or at the request of Roskomnadzor, the Operator blocks personal data relating to this personal data subject from the moment of such request or receipt of the specified request for the verification period, if the blocking of personal data does not violate the rights and legitimate interests of the personal data subject or third parties.
    In case of confirmation of the fact of inaccuracy of personal data, the Operator on the basis of information provided by the personal data subject or his representative or Roskomnadzor, or other necessary documents, clarifies personal data within seven working days from the date of submission of such information and removes the blocking of personal data.
    6.3. In case of detection of illegal processing of personal data when applying (request) of the personal data subject or his representative or Roskomnadzor, the Operator shall block unlawfully processed personal data relating to this personal data subject from the moment of such request or receipt of the request.
    6.4. Upon achievement of the purposes of personal data processing, as well as in case of withdrawal of consent by the subject of personal data to their processing, personal data shall be destroyed if:
    other is not provided by the contract, the party of which, the beneficiary or guarantor, under which is the subject of personal data; the operator is not entitled to process without the consent of the subject of personal data on the grounds provided for by the Law on personal data or other federal laws; otherwise is not provided by another agreement between the Operator and the subject of personal data.
  • the number of the main document certifying the identity of the personal data subject or his representative, information about the date of issue of the specified document and the body that issued it;
  • information confirming the participation of the subject of personal data in relations with the Operator (contract number, date of conclusion of the contract, conditional verbal designation and (or) other information), or information otherwise confirming the fact of processing personal data by the Operator;
  • signature of the personal data subject or his representative.
  • other is not provided by the contract, the party of which, the beneficiary or guarantor, under which the subject of personal data is;
  • the operator is not entitled to process without the consent of the subject of personal data on the grounds provided for by the Law on Personal Data or other federal laws;
  • other is not provided by another agreement between the Operator and the subject of personal data.
  • Final provisions 7.1 Responsibility for violation of the requirements of the legislation of the Russian Federation and regulatory documents of LLC “MARKETOLOGY” in the field of personal data is determined in accordance with the legislation of the Russian Federation.
    7.2 This Policy shall enter into force from the moment of approval and shall be valid indefinitely until the adoption of the new Policy.
    7.3 All changes and additions to this Policy must be approved by the General Director of LLC “Marketologiya”.
    7.4 The current version of the Policy is freely available on the Internet at the address marketologiya.com/policy.