Privacy Policy
1. General Provisions
1.1. This personal data processing policy (hereinafter - the Policy) has been prepared in accordance with the requirements of Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data" and defines the purposes, procedure for processing personal data, and measures to ensure the security of personal data implemented by NAKITA LLC (TIN 7813678204, TRRC 781301001, PSRN 1247800015737) (hereinafter - the Operator).
1.2. The Operator considers the observance of human and civil rights and freedoms in the course of personal data processing, including protection of the rights to privacy and personal and family secrecy, to be its most important goal and condition of its activity.
1.3. This Operator's personal data processing policy (hereinafter - the Policy) applies to all information that the Operator may obtain about visitors/users (hereinafter - the User) of the website semplery.ru (hereinafter - the Website).
1.4. The Policy is an integral part of the public offer of NAKITA LLC posted on the website https://www.semplery.com/ and accepted by the Website User. The laws of the Russian Federation apply to relations arising between the Operator and the User.
1.5. Any User's actions aimed at starting to use the Website, including registration, as well as providing personal data to the Operator, mean consent to this Operator's personal data processing policy.
1.6. If the User disagrees with the terms of the Policy, the User must immediately stop using the Website.
2. Basic Terms Used in the Policy
- Personal data - any information relating directly or indirectly to an identified or identifiable individual User of the website (personal data subject);
- User - any visitor of the website;
- Operator - a state authority, municipal authority, legal entity or individual that independently or jointly with other persons organizes and/or carries out personal data processing, and also determines the purposes of personal data processing, the composition of personal data subject to processing, and the actions (operations) performed with personal data;
- Personal data processing - any action (operation) or set of actions (operations) performed with or without automation tools in relation to personal data, including collection, recording, systematization, accumulation, storage, уточнение (updating, modification), extraction, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data;
- Automated personal data processing - personal data processing using computer technology;
- Dissemination of personal data - actions aimed at disclosure of personal data to an indefinite circle of persons;
- Provision of personal data - actions aimed at disclosure of personal data to a specific person or a specific circle of persons;
- Blocking of personal data - temporary cessation of personal data processing (except where processing is necessary to clarify personal data);
- Destruction of personal data - actions that make it impossible to restore the content of personal data in a personal data information system and/or actions that destroy physical media containing personal data;
- Depersonalization of personal data - actions that make it impossible to determine, without the use of additional information, that personal data belongs to a specific personal data subject;
- Personal data information system - a set of personal data contained in databases, and the information technologies and technical means ensuring their processing;
- Cross-border transfer of personal data - transfer of personal data to the territory of a foreign state, to a foreign state authority, foreign individual or foreign legal entity;
- Website - a set of graphic and informational materials, as well as software and databases, that ensure their availability on the Internet at the network address;
- Personal data information system - a set of personal data contained in databases, and the information technologies and technical means ensuring their processing;
2.1. Automatically Collected Data (Cookie Files)
When visiting the website, technical data may be collected automatically using cookie files and similar technologies.
Cookie files are small text files stored on the user's device that make it possible to recognize the user's browser, save the user's settings, and analyze website usage.
The following data may be collected automatically using cookie files:
- the user's IP address;
- device and browser type;
- interface language;
- date and time of website visit;
- addresses of visited pages;
- user actions on the website;
- technical parameters of the device.
Data obtained using cookie files is used exclusively for:
- ensuring the proper functioning of the website;
- improving user experience;
- analyzing website traffic and performance.
The User may change cookie settings in the browser, including the option to fully disable cookie files. In this case, some website functions may work incorrectly.
By continuing to use the website, the User confirms consent to the use of cookie files in accordance with this Personal Data Processing Policy.
3. The Operator May Process the Following Personal Data of the User
- surname, first name, patronymic
- year of birth
- month of birth
- date of birth
- place of birth
- marital status
- income
- gender
- email address
- residential address
- registration address
- phone number
- SNILS
- TIN
- citizenship
- identity document details
- driver's license details
- data contained in the birth certificate
- bank card details
- bank account number
- personal account number
- profession
- position
- employment information (including work experience, current employment data indicating the organization name and settlement account)
- attitude to military duty, military registration information
- information collected through metric programs
- education information
The above data is hereinafter collectively referred to as Personal Data throughout the text of the Policy.
4. Purposes of Personal Data Processing
4.1. Personnel and accounting administration, ensuring compliance with the tax legislation of the Russian Federation, ensuring compliance with the legislation of the Russian Federation on countering legalization and financing of terrorism, participation of a person in constitutional, civil, administrative and criminal proceedings, proceedings in arbitration courts, preparation, conclusion and performance of a civil law contract, statistical accounting, and promotion of goods, works and services on the market.
5. Legal Grounds for Personal Data Processing
5.1. The Operator processes the User's personal data only if such data is filled in and/or submitted by the User independently through special forms located on the website.
5.2. By filling in the relevant forms and/or submitting personal data, the User expresses consent to this Policy.
5.3. The Operator processes anonymized data about the User if this is permitted in the User's browser settings (cookie storage and JavaScript technology are enabled).
5.4. Personal data processing is carried out in compliance with the principles and rules established by Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data".
5.5. Personal data processing by the Operator is permitted in the following cases:
- personal data processing is carried out with the consent of the personal data subject to the processing of his or her personal data,
- personal data processing is carried out in connection with a person's participation in constitutional, civil, administrative and criminal proceedings, proceedings in arbitration courts;
- personal data processing is necessary to achieve the purposes provided for by an international treaty of the Russian Federation or by law, for the exercise and performance of functions, powers and duties imposed on the operator by the legislation of the Russian Federation
- personal data processing is carried out for statistical or other research purposes, except for the purposes specified in Article 15 of the Federal Law "On Personal Data", subject to mandatory depersonalization of personal data;
- personal data processing is necessary for the performance of a contract to which the personal data subject is a party, beneficiary or guarantor, as well as for concluding a contract at the initiative of the personal data subject or a contract under which the personal data subject will be a beneficiary or guarantor. A contract concluded with the personal data subject may not contain provisions limiting the rights and freedoms of the personal data subject
6. Procedure for Collection, Storage, Transfer and Other Types of Personal Data Processing
6.1. The security of personal data processed by the Operator is ensured by implementing legal, organizational and technical measures necessary for full compliance with the requirements of current legislation in the field of personal data protection.
6.2. The Operator ensures the safety of personal data and takes all possible measures to prevent access to personal data by unauthorized persons, including:
- appointment of a person responsible for organizing personal data processing by the Operator;
- adoption of local regulatory acts and other documents in the field of personal data processing and protection;
- compliance with conditions ensuring the safety of personal data and preventing unauthorized access to it;
- detection of unauthorized access to personal data and taking appropriate measures;
- organization of training and methodological work with the Operator's employees admitted to working with personal data, including through information systems;
- obtaining consent of personal data subjects to the processing of their personal data, except where otherwise provided by the legislation of the Russian Federation;
- segregation of personal data processed without automation tools from other information, in particular by recording it on separate physical media containing personal data, in special sections;
- ensuring separate storage of personal data and their physical media, the processing of which is carried out for different purposes and which contain different categories of personal data;
- ensuring the security of personal data when transmitted through open communication channels;
- identification of current threats to the security of personal data during processing in a personal data information system and development of measures and actions for personal data protection;
- setting individual employee passwords for access to the information system in accordance with their job responsibilities;
- use of certified antivirus software with regularly updated databases;
- storage of physical media containing personal data under conditions ensuring the safety of personal data and preventing unauthorized access to it;
- internal control over compliance of personal data processing with Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data" and regulatory legal acts adopted in accordance therewith, personal data protection requirements, this Policy, and the Operator's local regulatory acts;
- other measures предусмотренные legislation of the Russian Federation in the field of personal data.
7. Transfer of Personal Data to Third Parties
7.1. The Operator does not disclose personal data to third parties and does not disseminate personal data without the consent of the personal data subject or another lawful basis (unless otherwise provided by federal legislation of the Russian Federation).
7.2. The Operator transfers personal data to inquiry bodies, investigation authorities and courts, and other authorized bodies on the grounds provided for by the current legislation of the Russian Federation.
8. Terms of Personal Data Processing
8.1. The term of personal data processing by the Operator, subject to consent to personal data processing, is determined until the withdrawal of the person's consent to personal data processing or until the occurrence of cases specified by law.
8.2. The Operator shall cease processing personal data in the following cases:
- withdrawal by the User of consent to personal data processing, unless there are other legal grounds for processing provided for by the legislation of the Russian Federation;
- detection of unlawful personal data processing, if it is impossible to ensure lawful processing;
- liquidation of the Operator;
- achievement of the purposes of personal data processing, unless otherwise specified in the Agreement;
9. Updating, Correction, Deletion and Destruction of Personal Data, Responses to Requests of Personal Data Subjects for Access to Personal Data
9.1. The User's personal data shall be destroyed in the following cases:
- independent deletion of data by the User in the personal account;
- deletion by the Operator from the Website of information posted by the User, as well as deletion of the User's account;
- withdrawal of consent to personal data processing, unless other retention periods are established by the laws of the Russian Federation;
9.2. In the event personal data inaccuracies are identified, the User may update them independently by sending the Operator a notification to the Operator's email address marked "Personal Data Update".
9.3. The term of personal data processing is unlimited. The User may withdraw consent to personal data processing at any time by sending the Operator a notification by email to the Operator's email address marked "Withdrawal of Consent to Personal Data Processing".
10. Cross-Border Transfer of Personal Data
10.1. The Operator does not carry out cross-border transfer of personal data.
11. Final Provisions
11.1. The User has the right to send questions to the Operator, including requests regarding the use of personal data, in writing or in the form of an electronic document signed with a qualified electronic signature in accordance with the legislation of the Russian Federation.
11.2. Requirements for a request. It must contain:
- the number of the main identity document of the User, and if signed by a representative, the representative's identity document as well, as well as the information specified in the document;
- information on the date of issue of the specified document and the issuing authority;
- for a representative - a power of attorney confirming the right to represent the User's interests;
- all possible current contact details;
- information confirming the User's relationship with the Operator (for example, identification data: the name of the account/personal account used by the User);
- the signature of the User or the User's representative.
If the application (request) of the personal data subject does not reflect all required information in accordance with the requirements of Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data", or if the subject does not have the rights to access the requested information, a reasoned refusal shall be sent to the subject.
The Operator must provide access to personal data upon request of the personal data subject or the subject's representative within ten business days from the date of receipt of the request. This period may be extended, but by no more than five business days, if the Operator sends the personal data subject a reasoned notice indicating the reasons for extending the deadline for providing the requested information.
The information specified in Part 7 of Article 14 of Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data" shall be provided to the personal data subject or the subject's representative in the same form in which the relevant application or request was submitted, unless otherwise specified in the application or request.
The right of the personal data subject to access his or her personal data may be restricted in accordance with Part 8 of Article 14 of Federal Law No. 152-FZ dated 27.07.2006 "On Personal Data", including where access of the personal data subject to his or her personal data violates the rights and legitimate interests of third parties.
11.3. The Operator shall review and send a response to a proper User request within 10 business days from the date of receipt.
11.4. The User may obtain any explanations on matters of interest relating to the processing of personal data by contacting the Operator via email.
11.5. The Policy remains in force indefinitely until replaced by a new version.
11.6. The current version of the Policy is publicly available on the Internet at https://www.semplery.com/about/privacy/