1. GENERAL PROVISIONS

The Personal Data Processing Policy (hereinafter referred to as the Policy) has been developed in accordance with the Federal Law of 27.07.2006. No. 152-FZ "On Personal Data" (hereinafter referred to as the Policy).
This Policy defines the procedure for processing personal data and measures to ensure the security of personal data in OOO "AQ" in order to protect the rights and freedoms of an individual and citizen when processing his personal data, including protecting the rights to privacy, personal and family secrets.

The Policy uses the following basic concepts:

automated processing of personal data - processing of personal data using computer technology;

blocking of personal data - temporary suspension of processing of personal data (except for cases where processing is necessary to clarify personal data);

personal data information system — a set of personal data contained in databases and the information technologies and technical means that ensure their processing;

depersonalization of personal data — actions that make it impossible to determine without the use of additional information the ownership of personal data by a specific subject of personal data;

personal data processing — any action (operation) or set of actions (operations) performed with the use of automation tools or without the use of such tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data;

operator — a government agency, municipal agency, legal entity or individual that, independently or jointly with other persons, organizes and/or carries out the processing of personal data, as well as determines the purposes of processing personal data, the composition of personal data to be processed, and actions (operations) performed with personal data;

personal data — any information relating to a directly or indirectly identified or determinable individual (subject of personal data);

provision of personal data — actions aimed at disclosing personal data to a specific person or a specific group of persons;

dissemination of personal data — actions aimed at disclosing personal data to an indefinite number of persons (transfer of personal data) or familiarizing an unlimited number of persons with personal data, including disclosure of personal data in the media, posting in information and telecommunication networks or providing access to personal data in any other way;

cross-border transfer of personal data — transfer of personal data to the territory of a foreign state to a foreign government body, foreign individual or foreign legal entity;

destruction of personal data — actions that make it impossible to restore the content of personal data in the personal data information system and (or) that result in the destruction of tangible media of personal data.

The Company is obliged to publish or otherwise ensure unrestricted access to this Personal Data Processing Policy in accordance with Part 2 of Article 18.1 of Federal Law No. 152.

2. PRINCIPLES AND CONDITIONS OF PERSONAL DATA PROCESSING

2.1. Principles of personal data processing

The Operator processes personal data based on the following principles:

— legality and fairness;

— limiting the processing of personal data to achieving specific, predetermined and legitimate goals;

— preventing the processing of personal data that is incompatible with the purposes of collecting personal data;

— preventing the merging of databases containing personal data that are processed for purposes incompatible with each other;

— processing only those personal data that meet the purposes of their processing;

— compliance of the content and volume of the processed personal data with the stated purposes of processing;

— preventing the processing of personal data that is excessive in relation to the stated purposes of their processing;

— ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of personal data processing;

— destruction or depersonalization of personal data upon achieving the purposes of their processing or in the event of loss of the need to achieve these purposes, if the Operator is unable to eliminate the committed violations of personal data, unless otherwise provided by federal law.

2.2. Conditions for processing personal data

The Operator processes personal data if at least one of the following conditions is present:

— personal data is processed with the consent of the subject of personal data to the processing of his personal data;

— personal data processing is necessary to achieve the purposes stipulated by an international treaty of the Russian Federation or by law, for the implementation and performance of the functions, powers and duties imposed on the operator by the legislation of the Russian Federation;

— the processing of personal data is necessary for the administration of justice, the execution of a judicial act, an act of another body or official subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings;

— the processing of personal data is necessary for the performance of an agreement to which the personal data subject is a party, beneficiary or guarantor, as well as for concluding an agreement at the initiative of the personal data subject or an agreement under which the personal data subject will be a beneficiary or guarantor;

— the processing of personal data is necessary for the exercise of the rights and legitimate interests of the operator or third parties or for the achievement of socially significant goals, provided that the rights and freedoms of the personal data subject are not violated;

— the processing of personal data is carried out, access to which is granted to an unlimited number of persons by the personal data subject or at his request;

— personal data subject to publication or mandatory disclosure in accordance with federal law is processed.

2.3. Confidentiality of personal data
The Operator and other persons who have gained access to personal data are obliged not to disclose to third parties or distribute personal data without the consent of the personal data subject, unless otherwise provided by federal law.

2.4. Publicly available sources of personal data

For the purposes of information support, the Operator may create publicly available sources of personal data of subjects, including directories and address books. With the written consent of the subject, publicly available sources of personal data may include his/her last name, first name, patronymic, date and place of birth, position, contact phone numbers, email address and other personal data reported by the personal data subject.

Information about the subject must be excluded from publicly available sources of personal data at any time at the request of the subject or by decision of a court or other authorized state bodies.

2.5. Специальные категории персональных данных

Обработка Оператором специальных категорий персональных данных, касающихся расовой, национальной принадлежности, политических взглядов, религиозных или философских убеждений, состояния здоровья, интимной жизни, допускается в случаях, если:

— субъект персональных данных дал согласие в письменной форме на обработку своих персональных данных;

— персональные данные сделаны общедоступными субъектом персональных данных;

— обработка персональных данных осуществляется в соответствии с законодательством о государственной социальной помощи, трудовым законодательством, законодательством Российской Федерации о пенсиях по государственному пенсионному обеспечению, о трудовых пенсиях;

— обработка персональных данных необходима для защиты жизни, здоровья или иных жизненно важных интересов субъекта персональных данных либо жизни, здоровья или иных жизненно важных интересов других лиц и получение согласия субъекта персональных данных невозможно;

— обработка персональных данных осуществляется в медико-профилактических целях, в целях установления медицинского диагноза, оказания медицинских и медико-социальных услуг при условии, что обработка персональных данных осуществляется лицом, профессионально занимающимся медицинской деятельностью и обязанным в соответствии с законодательством Российской Федерации сохранять врачебную тайну;

— обработка персональных данных необходима для установления или осуществления прав субъекта персональных данных или третьих лиц, а равно и в связи с осуществлением правосудия;

— обработка персональных данных осуществляется в соответствии с законодательством об обязательных видах страхования, со страховым законодательством.

Обработка специальных категорий персональных данных должна быть незамедлительно прекращена, если устранены причины, вследствие которых осуществлялась их обработка, если иное не установлено федеральным законом.

Обработка персональных данных о судимости может осуществляться Оператором исключительно в случаях и в порядке, которые определяются в соответствии с федеральными законами.

2.6. Биометрические персональные данные

Сведения, которые характеризуют физиологические и биологические особенности человека, на основании которых можно установить его личность — биометрические персональные данные — могут обрабатываться Оператором только при наличии согласия в письменной форме субъекта.

2.7. Поручение обработки персональных данных другому лицу

Оператор вправе поручить обработку персональных данных другому лицу с согласия субъекта персональных данных, если иное не предусмотрено федеральным законом, на основании заключаемого с этим лицом договора. Лицо, осуществляющее обработку персональных данных по поручению Оператора, обязано соблюдать принципы и правила обработки персональных данных, предусмотренные ФЗ-152.

2.8. Cross-border transfer of personal data

The operator is obliged to ensure that the foreign state to whose territory the personal data is supposed to be transferred ensures adequate protection of the rights of personal data subjects, before such transfer begins.

Cross-border transfer of personal data to the territory of foreign states that do not ensure adequate protection of the rights of personal data subjects may be carried out in the following cases:

— the presence of written consent of the personal data subject to the cross-border transfer of his personal data;

— execution of an agreement to which the personal data subject is a party.

3. RIGHTS OF THE PERSONAL DATA SUBJECT

3.1. Consent of the personal data subject to the processing of his personal data

The personal data subject makes a decision to provide his personal data and gives consent to their processing freely, of his own free will and in his interests. Consent to the processing of personal data may be given by the personal data subject or his representative in any form that allows confirming the fact of its receipt, unless otherwise established by federal law.
The obligation to provide proof of receipt of the consent of the personal data subject to the processing of his personal data or proof of the existence of the grounds specified in Federal Law 152 is imposed on the Operator.

3.2. Rights of the personal data subject

The personal data subject has the right to receive information from the Operator regarding the processing of his personal data, unless such right is limited in accordance with federal laws. The personal data subject has the right to demand that the Operator clarify his personal data, block or destroy it if the personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing, and also to take measures provided by law to protect his rights.
The processing of personal data for the purpose of promoting goods, works, services on the market by means of direct contacts with a potential consumer using communication tools, as well as for the purposes of political campaigning is permitted only with the prior consent of the personal data subject. The said processing of personal data is recognized as carried out without the prior consent of the personal data subject, unless the Company proves that such consent has been obtained. The Operator is obliged to immediately stop, at the request of the personal data subject, the processing of his personal data for the above purposes.
It is prohibited to make decisions based solely on the automated processing of personal data that generate legal consequences in relation to the personal data subject or otherwise affect his rights and legitimate interests, except in cases stipulated by federal laws, or in the presence of the written consent of the personal data subject.
If the personal data subject believes that the Operator processes his personal data in violation of the requirements of Federal Law 152 or otherwise violates his rights and freedoms, the personal data subject has the right to appeal the actions or inaction of the Operator to the Authorized Body for the Protection of the Rights of Personal Data Subjects or in court.
The personal data subject has the right to protect his rights and legitimate interests, including compensation for losses and (or) compensation for moral damage in court.

4. ENSURING THE SECURITY OF PERSONAL DATA

The security of personal data processed by the Operator is ensured by the implementation of legal, organizational and technical measures necessary to meet the requirements of federal legislation in the field of personal data protection.

To prevent unauthorized access to personal data, the Operator applies the following organizational and technical measures:

— appointment of officials responsible for organizing the processing and protection of personal data;

— limiting the composition of persons who have access to personal data;

— familiarizing subjects with the requirements of federal legislation and the Operator's regulatory documents on the processing and protection of personal data;

— organizing the accounting, storage and circulation of information carriers;

— identifying threats to the security of personal data during their processing, forming threat models on their basis;

— development of a personal data protection system based on the threat model;

— verification of the readiness and effectiveness of the use of information protection tools;

— delimitation of user access to information resources and software and hardware for information processing;

— registration and accounting of actions of users of personal data information systems;

— use of anti-virus tools and tools for restoring the personal data protection system;

— application, where necessary, of firewalls, intrusion detection, security analysis and cryptographic information protection tools;

— organization of access control to the Operator's territory, security of premises with technical means for processing personal data.

5. FINAL PROVISIONS

Other rights and obligations of the Operator as the operator of personal data are determined by the legislation of the Russian Federation in the field of personal data.
The Operator's officials guilty of violating the rules governing the processing and protection of personal data bear material, disciplinary, administrative, civil or criminal liability in the manner established by federal laws.