1. GENERAL PROVISIONS1.1. This personal data processing policy has been prepared in accordance with the requirements of Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (hereinafter the Personal Data Law) and determines the procedure for processing personal data and the measures for ensuring the security of personal data taken by Individual Entrepreneur Gerasimenko Pavel Borisovich (hereinafter the Operator).
1.2. The Operator sets as his most important goal and condition of carrying out his activities the observance of human and civil rights and freedoms when processing personal data, including protection of the rights to privacy, personal and family secrets.
1.3. This Operator's policy on personal data processing (hereinafter the Policy) applies to all information that the Operator may obtain about visitors to the website https://www.scanxpro.ru (hereinafter the Website). The Website does not control and is not responsible for third-party websites to which the User may go via links available on the Website https://www.scanxpro.ru.
1.4. Use of the Website services means the User's unconditional consent to this Policy and the terms of processing of the User's personal information specified therein. If the User disagrees with these terms, the User must refrain from using the services.
2. TERMS USED IN THE POLICY 2.1. Automated processing of personal data means processing of personal data using computer equipment.
2.2. Blocking of personal data means temporary termination of personal data processing, except where processing is necessary to clarify personal data.
2.3. Website means a set of graphic and informational materials, as well as computer programs and databases, ensuring their availability on the Internet at the network address https://www.scanxpro.ru.
2.4. Personal data information system means a set of personal data contained in databases and the information technologies and technical means ensuring their processing.
2.5. Depersonalization of personal data means actions as a result of which it is impossible, without using additional information, to determine that personal data belongs to a specific User or another personal data subject.
2.6. Processing of personal data means any action (operation) or set of actions (operations) performed with personal data using automation tools or without using such tools, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion and destruction of personal data.
2.7. Operator means a government authority, municipal authority, legal entity or individual that independently or jointly with other persons organizes and/or carries out personal data processing, as well as determines the purposes of personal data processing, the scope of personal data to be processed, and the actions (operations) performed with personal data.
2.8. Personal data means any information relating directly or indirectly to an identified or identifiable User of https://www.scanxpro.ru.
2.9. Personal data permitted by the personal data subject for distribution means personal data to which an unlimited number of persons is granted access by the personal data subject by giving consent to processing of personal data permitted by the personal data subject for distribution in the manner provided by the Personal Data Law (hereinafter personal data permitted for distribution).
2.10. User means any visitor to https://www.scanxpro.ru.
2.11. Provision of personal data means actions aimed at disclosing personal data to a specific person or a specific group of persons.
2.12. Distribution of personal data means any actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data) or making personal data available to an unlimited group of persons, including publication of personal data in mass media, placement in information and telecommunication networks, or providing access to personal data by any other means.
2.13. Cross-border transfer of personal data means transfer of personal data to the territory of a foreign state to an authority of a foreign state, foreign individual or foreign legal entity.
2.14. Destruction of personal data means any actions as a result of which personal data is irreversibly destroyed with no possibility of further restoration of the content of personal data in the personal data information system and/or material media of personal data are destroyed.
3. RIGHTS AND OBLIGATIONS OF THE OPERATOR3.1. The Operator has the right:
– to receive from the personal data subject reliable information and/or documents containing personal data;
– if the personal data subject withdraws consent to personal data processing, the Operator has the right to continue processing personal data without the personal data subject's consent where there are grounds specified in the Personal Data Law;
– to independently determine the composition and list of measures necessary and sufficient to ensure fulfillment of the obligations provided by the Personal Data Law and regulatory legal acts adopted in accordance with it, unless otherwise provided by the Personal Data Law or other federal laws.
3.2. The Operator is obliged:
- to provide the personal data subject, at his or her request, with information concerning the processing of his or her personal data;
- to organize personal data processing in the manner established by the current legislation of the Russian Federation;
- to respond to applications and requests from personal data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
- to provide the authorized body for the protection of the rights of personal data subjects, upon request of that body, with the necessary information within 10 business days from the date of receipt of such request;
- to publish or otherwise ensure unrestricted access to this Policy on personal data processing;
- to take legal, organizational and technical measures to protect personal data against unlawful or accidental access to it, destruction, modification, blocking, copying, provision, distribution of personal data, as well as against other unlawful actions with respect to personal data;
- to stop transfer (distribution, provision, access) of personal data, stop processing and destroy personal data in the manner and cases provided by the Personal Data Law;
- to fulfill other obligations provided by the Personal Data Law.
4. RIGHTS AND OBLIGATIONS OF PERSONAL DATA SUBJECTS4.1. Personal data subjects have the right:
- to receive information concerning the processing of their personal data, except in cases provided by federal laws. Information is provided to the personal data subject by the Operator in an accessible form, and it must not contain personal data relating to other personal data subjects, except in cases where there are lawful grounds for disclosing such personal data. The list of information and the procedure for obtaining it are established by the Personal Data Law;
- to require the operator to clarify his or her personal data, block it or destroy it if the personal data is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and to take measures provided by law to protect his or her rights;
- to put forward the condition of prior consent when processing personal data for the purposes of promoting goods, works and services on the market;
- to withdraw consent to personal data processing;
- to appeal to the authorized body for the protection of the rights of personal data subjects or in court against unlawful actions or inaction of the Operator when processing his or her personal data;
- to exercise other rights provided by the legislation of the Russian Federation.
4.2. Personal data subjects are obliged:
- to provide the Operator with reliable data about themselves;
- to notify the Operator of clarification (updating, modification) of their personal data.
4.3. Persons who have provided the Operator with inaccurate information about themselves or information about another personal data subject without the latter's consent are liable in accordance with the legislation of the Russian Federation.
5. LIST OF USER PERSONAL DATA PROCESSED BY THE OPERATOR5.1. Surname, first name, patronymic.
5.2. Email address.
5.3. Phone numbers.
5.4. Year, month, date and place of birth.
5.5. Photographs.
5.6. Place of work, position.
5.7. The website collects and processes depersonalized data about visitors, including cookie files, using Internet statistics services: Yandex Metrica.
5.8. The above data is hereinafter collectively referred to in the Policy as "Personal Data".
5.9. The Operator does not process special categories of personal data concerning racial or ethnic origin, political views, religious or philosophical beliefs, or intimate life.
5.10. Processing of personal data permitted for distribution from among the special categories of personal data specified in Part 1 of Article 10 of the Personal Data Law is permitted if the prohibitions and conditions provided by Article 10.1 of the Personal Data Law are observed.
5.11. The User's consent to the processing of personal data permitted for distribution is executed separately from other consents to the processing of his or her personal data. At the same time, the conditions provided, in particular, by Article 10.1 of the Personal Data Law are observed. The requirements for the content of such consent are established by the authorized body for the protection of the rights of personal data subjects.
5.11.1. The User provides consent to the processing of personal data permitted for distribution directly to the Operator.
5.11.2. The Operator is obliged, no later than three business days from the moment of receiving the User's specified consent, to publish information about the processing conditions, the existence of prohibitions and conditions for processing by an unlimited number of persons of personal data permitted for distribution.
5.11.3. Transfer (distribution, provision, access) of personal data permitted by the personal data subject for distribution must be stopped at any time at the request of the personal data subject. This request must include the surname, first name, patronymic (if any), contact information (phone number, email address or postal address) of the personal data subject, as well as the list of personal data whose processing must be stopped. The personal data specified in this request may be processed only by the Operator to whom it is sent.
5.11.4. Consent to the processing of personal data permitted for distribution terminates from the moment the Operator receives the request specified in clause 5.11.3 of this Personal Data Processing Policy.
6. PRINCIPLES OF PERSONAL DATA PROCESSING6.1. Personal data processing is carried out on a lawful and fair basis.
6.2. Personal data processing is limited to achieving specific, predetermined and lawful purposes. Processing of personal data incompatible with the purposes of collecting personal data is not allowed.
6.3. Combining databases containing personal data whose processing is carried out for mutually incompatible purposes is not allowed.
6.4. Only personal data that meets the purposes of its processing may be processed.
6.5. The content and scope of personal data processed correspond to the stated purposes of processing. Excessiveness of processed personal data in relation to the stated purposes of processing is not allowed.
6.6. When processing personal data, the accuracy of personal data, its sufficiency and, where necessary, relevance in relation to the purposes of personal data processing are ensured. The Operator takes necessary measures and/or ensures that they are taken to delete or clarify incomplete or inaccurate data.
6.7. Personal data is stored in a form that allows identification of the personal data subject for no longer than required by the purposes of personal data processing, unless the personal data storage period is established by federal law or by an agreement to which the personal data subject is a party, beneficiary or guarantor. Processed personal data is destroyed or depersonalized upon achievement of the processing purposes or if the need to achieve those purposes is lost, unless otherwise provided by federal law.
7. PURPOSES OF PERSONAL DATA PROCESSING7.1. Purpose of processing the User's personal data:
- informing the User by sending emails;
- providing the User with access to services, information and/or materials contained on https://www.scanxpro.ru.
7.1.1. Purpose: Carrying out entrepreneurial activity by the Operator through the sale of goods and services using the Website.
| Purpose of personal data processing | Categories of personal data subjects | Categories and list of personal data |
|---|
| – registration and maintenance of the client's account (personal account) on the Website; | – Website visitors; | – surname, first name, patronymic (specified together or separately); |
| – informing the client about goods and services, as well as ongoing promotions, contests and other incentive events; | – registered Website users; | – email address (e-mail); |
| – improving user interaction with the website and increasing the comfort of its use, including forming the best selection or list of goods in accordance with the user's preferences; | – individuals who are clients of the Individual Entrepreneur and purchase goods and services from the Individual Entrepreneur, including through the Website; | – city of residence; |
| – selling goods and services to the client; | – representatives and employees of legal entities that are clients of the Individual Entrepreneur. | – place of work, position; |
| – conducting advertising campaigns, organizing contests, prize drawings and other incentive events, including determining winners and delivering prizes; | | – vehicle data; state registration number, VIN number, year of manufacture, mileage, engine power, catalog numbers of parts, assemblies and units, vehicle color, and other vehicle data necessary to perform services for the client on the Website |
| – client participation in loyalty programs; | | |
| – providing clients with the opportunity to leave reviews on the Website, as well as the opportunity to read reviews from other clients; | | – data from cookie files, user data (IP address; type of device used; device operating system and browser type; source of entry to the website and information about the search or advertising query; user clicks; page views, field completions; impressions and views of banners and videos; session parameters; visit time data; user identifier stored in cookies; data characterizing audience segments). The collection of the specified data may be carried out, among other things, using metric software tools, including Yandex Metrica. When using the specified software, cross-border transfer of personal data is possible; |
| – ensuring communication with the client, establishing feedback with the client, including providing the client with the opportunity to send notifications, messages, requests and information concerning use of the Website and the possibility of purchasing goods on the Website, and providing clients with the opportunity to receive customer support by hotline telephone and email; | | – other information relating to the identity of the client/user that the client/user wishes to leave on the Website. |
| – sending clients informational messages about goods and services, events organized by the Individual Entrepreneur, and goods, works and services of partners of the Individual Entrepreneur and third parties; | | |
| – проведения Обществом опросов и ... | | |
| – using cookies to identify registered Website users, maintain statistics on Website users and their requests, count the number of Website visitors and evaluate the technical capabilities of the Website; | | |
| – проведения Обществом статистиче... | | |
7.1.2. Осуществление Обществом ад...
| Purpose of personal data processing | Categories of personal data subjects | Categories and list of personal data |
|---|
| – concluding and performing contracts with counterparties; | – representatives and employees of legal entities that are clients of the Individual Entrepreneur. | – surname, first name, patronymic (specified together or separately); |
| – organizing access control to the territory of the Individual Entrepreneur; | – лица, с которыми у Общества зак... | – contact telephone number; |
| – рекламирования Общества и его т... | – representatives of government authorities and local self-government bodies; | – email address (e-mail); |
| – представления интересов Обществ... | – посетители территории Общества;... | – passport data (passport series and number, by whom and when the passport was issued); |
| | – other persons interacting in any way with the Individual Entrepreneur within the framework of the Individual Entrepreneur's business activities. | – date of birth; |
| | – place of work, position; |
| | – details of powers of attorney; |
| | – city of residence; |
| | – correspondence address; |
| | – other information relating to the identity of the personal data subject that the person provides to the Individual Entrepreneur. |
7.1.3. Formalization and regulation by the Individual Entrepreneur of employment relations and other relations directly related to them
| Purpose of personal data processing | Categories of personal data subjects | Categories and list of personal data |
|---|
| – attracting and selecting candidates to fill vacant positions and maintaining them in the personnel reserve; | – работники Общества;............... | – surname, first name, patronymic (specified together or separately); |
| – maintaining personnel records and organizing accounting of employees of the Individual Entrepreneur; | – бывшие работники Общества;........ | – date and place of birth; |
| – оформления Обществом трудовых о... | – candidates for vacant positions with the Individual Entrepreneur; | – citizenship information; |
| – ensuring that employees perform their job duties (labor function); | – родственники работников Общества.. | – registered residential address and actual place of stay; |
| – ensuring control over the quantity and quality of work performed; | | – passport data (passport series and number, by whom and when the passport was issued); |
| – calculation of wages of employees of the Individual Entrepreneur; | | – INN; |
| – направления работников Общества... | | – SNILS number; |
| – ensuring the possibility for employees of the Individual Entrepreneur to undergo internal and external training; | | – bank details |
| – исполнения Обществом трудового ... | | – information about education, qualifications and awarded academic degree; |
| – calculation and payment of taxes, fees and mandatory social and pension insurance contributions provided by the legislation of the Russian Federation; | | – information contained in the employment record book: information about length of service and previous places of work; |
| – providing information to banking organizations for issuance of a bank card and/or transfer of wages; | | – information about income from previous places of work; |
| – providing information to medical institutions and insurance companies; | | – information about the employee's income from the Individual Entrepreneur; |
| – providing personal data subjects with a social package and benefits; | | – information about hiring, transfer, dismissal and other events related to the employee's employment activity with the Individual Entrepreneur; |
| – ensuring access control to the building of the Individual Entrepreneur; | | – data from other documents presented by the personal data subject when concluding the employment contract or during its term; |
| – ensuring the personal safety of personal data subjects; | | – military registration data and information contained in military registration documents; |
| – ensuring preservation of the property of the Individual Entrepreneur. | | – marital status, family composition (full names of relatives, degree of kinship, date of birth, contact details of relatives); |
| | | – photo and video images; |
| | | – information about personal and business qualities of an evaluative nature; |
| | | other information relating to the identity of the personal data subject that the specified person wishes to provide to the Individual Entrepreneur. |
| | | Special category: |
| | | – Information about the employee's health condition. |
| | | – Other information necessary for the performance of job duties: shoe size, headgear size, clothing size, dietary rules |
7.2. The Operator has the right to send the User notifications about new products and services, special offers and various events. The User may always refuse to receive informational messages by sending the Operator an email to vv@scanxpro.ru marked "Refusal of notifications about new products and services and special offers".
7.3. Depersonalized data of Users collected using Internet statistics services is used to collect information about Users' actions on the website and to improve the quality of the website and its content.
8. LEGAL GROUNDS FOR PERSONAL DATA PROCESSING8.1. The legal grounds for processing personal data by the Operator are:
- уставные (учредительные) документ...
- federal laws and other regulatory legal acts in the field of personal data protection;
- Users' consents to the processing of their personal data and to the processing of personal data permitted for distribution.
8.2. The Operator processes the User's personal data only if it is completed and/or sent by the User independently through special forms located on https://www.scanxpro.ru or sent to the Operator by email. By completing the relevant forms and/or sending personal data to the Operator, the User expresses consent to this Policy.
8.3. The Operator processes depersonalized data about the User if this is permitted in the User's browser settings (saving cookie files and using JavaScript technology are enabled).
8.4. The personal data subject independently decides to provide his or her personal data and gives consent freely, of his or her own will and in his or her own interest.
9. CONDITIONS FOR PERSONAL DATA PROCESSING9.1. Personal data processing is carried out with the consent of the personal data subject to the processing of his or her personal data.
9.2. Personal data processing is necessary to achieve the purposes provided by an international treaty of the Russian Federation or by law, and for the operator to perform functions, powers and duties imposed by the legislation of the Russian Federation.
9.3. Personal data processing is necessary for administering justice, executing a judicial act, act of another authority or official subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings.
9.4. Personal data processing is necessary for the performance of a contract to which the personal data subject is a party, beneficiary or guarantor, as well as for concluding a contract at the initiative of the personal data subject or a contract under which the personal data subject will be a beneficiary or guarantor.
9.5. Personal data processing is necessary for exercising the rights and legitimate interests of the operator or third parties, or for achieving socially significant purposes, provided that the rights and freedoms of the personal data subject are not violated.
9.6. Personal data is processed where access to it has been provided by the personal data subject to an unlimited number of persons or at his or her request (hereinafter publicly available personal data).
9.7. Personal data subject to publication or mandatory disclosure in accordance with federal law is processed.
10. PROCEDURE FOR COLLECTION, STORAGE, TRANSFER AND OTHER TYPES OF PERSONAL DATA PROCESSING10.1. The security of personal data processed by the Operator is ensured by implementing legal, organizational and technical measures necessary to fully comply with the requirements of current legislation in the field of personal data protection.
10.2. The Operator ensures the safekeeping of personal data and takes all possible measures to prevent access to personal data by unauthorized persons.
10.3. The User's personal data will never, under any circumstances, be transferred to third parties, except in cases related to compliance with current legislation, or where the personal data subject has given consent to the Operator to transfer data to a third party for the performance of obligations under a civil-law contract.
10.4. The period of personal data processing is determined by achievement of the purposes for which the personal data was collected, unless another period is provided by contract or current legislation.
The User may at any time withdraw consent to personal data processing by sending the Operator a notice by email to the Operator's email address vv@scanxpro.ru marked "Withdrawal of consent to personal data processing".
10.5. All information collected by third-party services, including payment systems, communication means and other service providers, is stored and processed by those persons (Operators) in accordance with their User Agreement and Privacy Policy. The personal data subject and/or User is obliged to independently familiarize himself or herself with those documents in a timely manner. The Operator is not responsible for the actions of third parties, including the service providers specified in this clause.
10.6. Prohibitions established by the personal data subject on transfer (except provision of access), as well as on processing or conditions of processing (except obtaining access) of personal data permitted for distribution, do not apply in cases of personal data processing in state, public and other public interests determined by the legislation of the Russian Federation.
10.7. When processing personal data, the Operator ensures the confidentiality of personal data.
10.8. The Operator stores personal data in a form that allows identification of the personal data subject for no longer than required by the purposes of personal data processing, unless the personal data storage period is established by federal law or by an agreement to which the personal data subject is a party, beneficiary or guarantor.
10.9. The condition for termination of personal data processing may be achievement of the purposes of personal data processing, expiration of the personal data subject's consent or withdrawal of consent by the personal data subject, as well as detection of unlawful processing of personal data.
11. LIST OF ACTIONS PERFORMED BY THE OPERATOR WITH USERS' PERSONAL DATA11.1. The Operator collects, records, systematizes, accumulates, stores, clarifies (updates, modifies), extracts, uses, transfers (distributes, provides, grants access), depersonalizes, blocks, deletes and destroys personal data.
11.2. The Operator carries out automated processing of personal data with or without receipt and/or transfer of the received information via information and telecommunication networks.
12. CONFIDENTIALITY OF PERSONAL DATA12.1. The Operator and other persons who have gained access to personal data are obliged not to disclose personal data to third parties or distribute personal data without the consent of the personal data subject, unless otherwise provided by federal law.
13. POLICY AMENDMENT13.1. The Operator periodically updates this Policy and has the right to unilaterally change its terms at any time. At the same time, the Individual Entrepreneur is not obliged to notify personal data subjects of changes made. The Individual Entrepreneur recommends that personal data subjects independently monitor this Policy for possible changes.