1. General Provisions
1.1. This Policy regarding the processing of personal data of Kolinkor Limited Liability Company (hereinafter referred to as the Policy) has been developed in compliance with the requirements of paragraph 2, part 1, article 18.1 of Federal Law No. 152-FZ of July 27, 2006, "On Personal
Data" (hereinafter referred to as the Personal Data Law) in order to ensure the protection of human and civil rights and freedoms when processing their personal data, including the protection of privacy rights, personal and family secrets.
1.2. This Policy applies to all personal data processed by Kolinkor Limited Liability Company (hereinafter referred to as the Operator).
1.3. This Policy applies to personal data processing relationships that arose with the Operator both before and after the approval of this Policy.
1.4. In compliance with the requirements of Part 2 of Article 18.1 of the Personal Data Law, this Policy is publicly available on the Operator’s website, kolinkor.com.
Terms and Abbreviations
Personal data (PD) — any information relating directly or indirectly to an identified or identifiable individual (to the personal data subject).
Personal data authorized for distribution by the personal data subject are personal data to which the general public has been granted access by the personal data subject by giving consent to the processing of personal data authorized for distribution by the personal data subject.
Personal data operator (operator) is a government agency, municipal body, legal entity, or individual that, independently or jointly with other persons, organizes and/or carries out the processing of personal data, and determines the purposes of personal data processing, the composition of personal data subject to processing, and the actions (operations) performed with personal data.
Personal data processing is any action (operation) or set of actions (operations) with personal data, performed with or without the use of automation tools. Personal data processing includes, but is not limited to:
• collection;
• recording;
• systematization;
• accumulation;
• storage;
• clarification (updating, modification);
• retrieval;
• use;
• transfer (provision, access);
• distribution;
• Anonymization;
• Blocking;
• Deletion;
• Destruction.
Automated processing of personal data is the processing of personal data using computer technology.
Provision of personal data is actions aimed at disclosing personal data to a specific person or a specific group of persons.
Dissemination of personal data is actions aimed at disclosing personal data to an unspecified group of persons.
Blocking of personal data is the temporary cessation of processing of personal data (except in cases where processing is necessary to clarify the personal data). Destruction of personal data is actions that make it impossible to restore the contents of personal data in a personal data information system and/or that result in the destruction of tangible media containing personal data.
Anonymization of personal data is actions that make it impossible to determine the ownership of personal data by a specific data subject without the use of additional information.
Personal data information system is the set of personal data contained in databases and the information technologies and technical means that support their processing.
Cross-border transfer of personal data is the transfer of personal data to a government agency in a foreign state. a foreign state, a foreign individual, or a foreign legal entity. Personal data protection is an activity aimed at preventing the leakage of protected personal data and unauthorized and unintentional impacts on protected personal data.
2. Purposes of Personal Data Processing
2.1. The processing of personal data is limited to achieving specific, predetermined, and legitimate purposes. Processing of personal data that is incompatible with the purposes of collecting the personal data is prohibited.
2.2. Only personal data that meets the purposes for which it is processed may be processed.
2.3. The Operator processes personal data for the following purposes:
• accounting and personnel records;
• carrying out its activities in accordance with the charter of Kolinkor LLC, including the preparation, conclusion, and execution of contracts with counterparties and the provision of services to clients.
2.4. The processing of employees' personal data may be carried out solely for the purpose of ensuring compliance with laws and other regulatory legal acts.
3. Scope and categories of personal data processed, categories of personal data subjects
3.1. The content and volume of processed personal data must correspond to the stated processing purposes set out in Section 2 of this Policy. The processed personal data must not be excessive in relation to the stated processing purposes.
3.2. The Operator may process the personal data of the following categories of personal data subjects.
3.2.1. Candidates for employment with the Operator — for the purposes of enforcing labor legislation within the framework of employment and other directly related relationships:
• last name, first name, patronymic;
• gender;
• citizenship;
• date and place of birth;
• contact information;
• information about education, work experience, qualifications;
• other personal data provided by candidates in their resumes and cover letters.
3.2.2. Employees and former employees of the Operator — for the purposes of accounting and HR records within the framework of employment and other directly related relationships:
• last name, first name, patronymic;
• gender;
• Citizenship;
• Date and place of birth;
• Image (photograph);
• Passport details;
• Registered address;
• Actual address;
• Contact details;
• Individual Taxpayer Identification Number;
• Social Insurance Number (SNILS);
• Education, qualifications, professional training, and advanced training;
• Marital status, presence of children, family ties;
• Employment history, including any incentives, awards, and/or disciplinary sanctions;
• Marriage registration information;
• Military registration information;
• Disability information;
• Information on alimony deductions;
• Income from previous employment;
• Other personal data provided by employees in accordance with labor legislation.
3.2.3. Family members of the Operator’s employees — for the purposes of enforcing labor legislation in the context of employment and other directly related relationships:
• last name, first name, patronymic;
• degree of kinship;
• year of birth;
• other personal data provided by employees in accordance with labor legislation.
3.2.4. Clients and contractors of the Operator (individuals) — for the purposes of carrying out their activities in accordance with the charter of Kolinkor LLC:
• last name, first name, patronymic;
• date and place of birth;
• passport details;
• registered address of residence;
• contact details;
• job title held;
• individual taxpayer identification number;
• bank account number;
• other personal data provided by clients and contractors (individuals) necessary for the conclusion and execution of contracts.
3.2.5. Representatives (employees) of the Operator’s clients and contractors (legal entities) — for the purposes of carrying out their activities in accordance with the charter of Kolinkor LLC:
• last name, first name, patronymic;
• passport details;
• contact details;
• job title held;
• other personal data provided by representatives (employees) of clients and contractors necessary for the conclusion and execution of contracts.
3.4. The Operator does not process special categories of personal data. concerning race, nationality, political views, religious or philosophical beliefs, health status, or intimate life, except in cases stipulated by Russian legislation.
4. Procedure and conditions for processing and storing personal data
4.1. The Operator processes personal data in accordance with the requirements of Russian legislation.
4.2. Personal data is processed with the consent of personal data subjects to the processing of their personal data, and without such consent in cases stipulated by Russian legislation.
4.3. Consent to the processing of personal data permitted by the personal data subject for dissemination is issued separately from other consents of the personal data subject to the processing of their personal data.
4.4. Consent to the processing of personal data permitted by the personal data subject for dissemination may be provided to the Operator:
• directly;
• using the information system of the authorized body for the protection of the rights of personal data subjects.
4.5. The Operator carries out both automated and non-automated processing of personal data.
4.6. Only the Operator’s employees whose job responsibilities include processing personal data are allowed to process personal data. personal data.
4.7. Personal data shall be processed by:
• obtaining personal data in oral and written form directly with the consent of the personal data subject (users) to the processing or dissemination of their personal data;
• entering personal data into the Operator’s logs, registers, and information systems;
• using other methods of processing personal data.
4.8. Disclosure to third parties and distribution of personal data without the consent of the personal data subject (users) is prohibited, unless otherwise provided by federal law.
4.9. Transfer of personal data to inquiry and investigative bodies, the Federal Tax Service, the Social Fund, and other authorized executive bodies and organizations is carried out in accordance with the requirements of the legislation of the Russian Federation.
4.10. The Operator takes the necessary legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, distribution, and other unauthorized actions, including:
• identifying threats to the security of personal data during its processing;
• adopting local regulations and other documents governing relations in the field of processing and protecting personal data;
• appointing persons responsible for ensuring the security of personal data in the Operator’s structural divisions and information systems;
• creating the necessary conditions for working with personal data;
• organizing the accounting of documents containing personal data;
• Organizes work with information systems in which personal data is processed;
• Stores personal data under conditions that ensure their security and prevent unauthorized access;
• Organizes training for the Operator’s employees processing personal data.
4.11. The Operator shall store personal data in a form that allows for the identification of the personal data subject for no longer than required for the purposes of processing the personal data, unless the storage period for the personal data is established by federal law, a contract, or an agreement.
4.12. When collecting personal data, including via the Internet information and telecommunications network, the Operator shall ensure the recording, systematization, accumulation, storage, clarification (updating, modification), and retrieval of personal data of citizens of the Russian Federation using databases located on the territory of the Russian Federation, except for cases specified in the Law on Personal Data.
4.13. Storage of Personal Data.
4.13.1. Personal data of subjects may be received, further processed, and transferred for storage in both paper and electronic form.
4.13.2. Personal data recorded on paper are stored in locked cabinets or locked rooms with limited access rights.
4.14.3. Personal data of subjects processed using automated means for different purposes are stored in different folders.
4.14.4. Storage and placement of documents containing personal data in open electronic directories (file sharing services) in the ISPD is prohibited.
4.15.5. Personal data shall be stored in a form that allows identification of the subject for no longer than required for the purposes of their processing, and they are subject to destruction upon achievement of the processing purposes or when the need for achieving them is no longer necessary.
4.16. Destruction of Personal Data.
4.16.1. Destruction of documents (media) containing personal data is performed by incineration, crushing (grinding), chemical decomposition, or transformation into a shapeless mass or powder. A shredder is permitted for the destruction of paper documents.
4.16.2. Personal data on electronic media is destroyed by erasing or formatting the media.
4.16.3. The destruction of personal data is documented by a media destruction certificate.
5. Personal Data Protection
5.1. In accordance with regulatory requirements, the Operator has created a personal data protection system (PDPS), consisting of legal, organizational, and technical protection subsystems.
5.2. The legal protection subsystem is a set of legal, organizational, administrative, and regulatory documents that ensure the creation, operation, and improvement of the PDPS.
5.3. The organizational protection subsystem includes the organization of the PDPS management structure, the permitting system, and information protection when working with employees, partners, and third parties.
5.4. The technical protection subsystem includes a set of technical, software, and hardware tools that ensure the protection of personal data.
The main measures to protect personal data used by the Operator are:
5.5.1. Appointment of a person responsible for processing personal data, who will organize the processing of personal data, provide training and instruction, and internal monitoring of compliance by the institution and its employees with personal data protection requirements.
5.5.2. Identifying current threats to the security of personal data processed in the ISPD and developing measures and activities to protect it.
5.5.3. Developing a policy regarding the processing of personal data.
5.5.4. Establishing rules for accessing personal data processed in the ISPD, as well as ensuring the registration and accounting of all actions performed with personal data in the ISPD.
5.5.5. Establishing individual passwords for employee access to the information system in accordance with their job responsibilities.
5.5.6. Using information security tools that have undergone the established compliance assessment procedure.
5.5.7. Certified antivirus software with regularly updated databases.
5.5.8. Compliance with conditions that ensure the security of personal data and prevent unauthorized access.
5.5.9. Detecting instances of unauthorized access to personal data and taking appropriate measures.
5.5.10. Restoration of personal data modified or destroyed due to unauthorized access.
5.5.11. Training the Operator’s employees directly involved in the processing of personal data in the provisions of Russian legislation on personal data, including personal data protection requirements, documents defining the Operator’s policy regarding the processing of personal data, and internal regulations on personal data processing.
5.5.12. Implementation of internal control and audit.
6. Basic Rights of the Personal Data Subject and Obligations of the Operator
6.1. Basic Rights of the Personal Data Subject.
The personal data subject has the right to access their personal data and the following information:
• confirmation of the processing of personal data by the Operator;
• legal grounds and purposes for processing personal data;
• purposes and methods used by the Operator for processing personal data;
• the name and location of the Operator, information about persons (except for the Operator’s employees) who have access to personal data or to whom personal data may be disclosed under an agreement with the Operator or under federal law;
• personal data processing periods, including storage periods;
• the procedure for exercising the rights provided for by this Federal Law by the personal data subject;
• the name or last name, first name, patronymic, and address of the person processing personal data on behalf of the Operator, if processing has been or will be entrusted to such person;
• contacting the Operator and sending them inquiries;
• appealing the actions or inactions of the Operator.
6.2. Operator Responsibilities.
The Operator is obligated to:
• provide information on the processing of personal data when collecting personal data;
• notify the personal data subject if the personal data was not received from the personal data subject;
• explain the consequences of such refusal to the personal data subject if the personal data is refused;
• publish or otherwise provide unrestricted access to the document defining its personal data processing policy and to information on the implemented personal data protection requirements;
• take or ensure the adoption of necessary legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, provision, distribution, and other illegal actions against personal data;
• respond to inquiries and requests from personal data subjects, their representatives, and the authorized body for the protection of personal data subjects' rights.
7. Updating, Correcting, Deleting, and Destroying Personal Data; Responding to Personal Data Subject Access Requests
7.1. Confirmation of the personal data processing by the Operator, the legal grounds and purposes for which the personal data is processed, as well as other information specified in Part 7 of Article 14 of the Personal Data Law, shall be provided by the Operator to the personal data subject or their representative upon request or upon receipt of a request from the personal data subject or their representative.
The information provided shall not include personal data related to other personal data subjects, except in cases where there are legal grounds for disclosing such personal data.
The request must contain:
• the number of the primary identity document of the personal data subject or their representative, the date of issue of such document, and the issuing authority;
• information confirming the personal data subject’s relationship with the Operator (contract number, contract date, code word, and/or other information), or information otherwise confirming the processing
of personal data by the Operator;
• the signature of the personal data subject or their representative.
The request may be sent in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation. If a personal data subject’s request (appeal) does not contain all the necessary information in accordance with the requirements of the Personal Data Law, or if the subject does not have the right to access the requested information, a reasoned refusal will be sent. A personal data subject’s right to access their personal data may be limited in accordance with Part 8 of Article 14 of the Personal Data Law, including if the personal data subject’s access to their personal data violates the rights and legitimate interests of third parties.
7.2. If inaccurate personal data is discovered upon request by a personal data subject or their representative, or at their request, or at the request of Roskomnadzor,
the Operator will block the personal data related to this personal data subject from the moment of such request or receipt of the said request for the verification period, unless blocking the personal data violates the rights and legitimate interests of the personal data subject or third parties. If the fact of inaccuracy of personal data is confirmed, the Operator, based on information provided by the personal data subject or their representative, or Roskomnadzor, or other necessary documents, clarifies the personal data within seven business days from the date of submission of such information and unblocks the personal data.
7.3. If unlawful processing of personal data is detected upon request (application) from the personal data subject or their representative, or Roskomnadzor, the Operator blocks the unlawfully processed personal data related to this personal data subject from the moment of such request or receipt of the request.
7.4. Upon achieving the personal data processing objectives, or in the event that the personal data subject revokes consent to its processing, personal data shall be destroyed unless:
• otherwise provided by an agreement to which the personal data subject is a party, beneficiary, or guarantor;
• the Operator may not process personal data without the consent of the personal data subject on the grounds stipulated by the Personal Data Law or other federal laws;
• otherwise provided by another agreement between the Operator and the personal data subject.
8. Final Provisions
8.1. Liability for violating the requirements of Russian Federation legislation and the regulatory documents of Kolinkor Limited Liability Company in the field of personal data is determined in accordance with Russian Federation legislation.
8.2. This Policy shall enter into force upon approval and shall remain in effect indefinitely until a new Policy is adopted.
8.3. All amendments and additions to this Policy must be approved by the General Director of Kolinkor Limited Liability Company.
8.4. Guided by the requirements of Part 2 of RF Government Resolution No. 211 of March 21, 2012, documents defining the policy regarding the processing of personal data, namely this Policy, shall be published on the official website kolinkor.com within 10 days of approval.