This Policy regarding the processing of personal data at Vladisart Joint Stock Company (hereinafter referred to as the Policy) has been developed in accordance with Federal Law № 152–FZ of 27.07.2006 on Personal Data (hereinafter referred to as Law № 152-FZ) for the purposes of implementation by Vladisart Joint Stock Company (hereinafter referred to as the Operator, Company). the provisions of the Legislation of the Russian Federation, which define the cases and specifics of personal data processing (hereinafter referred to as PD), as well as establish requirements for PD processing, and are aimed at ensuring the protection of human and civil rights and freedoms (of a PD subject) when organizing and/or processing his personal data by a Company, including the protection of privacy rights. life, personal and family secrets.
The Policy is the foundation for organizing the processing and protection of personal data within the Company, including for the development of local regulations governing the procedure for processing and protecting personal data within the Company, and it defines:
The basics of the procedure for considering requests from personal data subjects regarding the processing of personal data; measures to ensure the confidentiality and security of personal data; the Company’s rights and obligations, and the rights of the personal data subject. The Company’s employees are familiarized with this Policy, including any amendments to this Policy, by signing a document. The provisions and requirements of this Policy are mandatory for all Company employees who have access to personal data. This Policy is to be posted on the Company’s website at https://vladisart.ru/ in the information and telecommunications network “Internet”, as well as on all pages of the Company’s website that are used to collect personal data of data subjects.
Personal data (PD) – any information related directly or indirectly to a specific or identifiable natural person (PD subject).
The subject of PD is an individual who is directly or indirectly identified or identifiable.
Automated PD processing is the processing of personal data using computer technology.
PD security is the state of PD security, which is characterized by the ability of users, technical means and information technologies to ensure the confidentiality, integrity and accessibility of PD during their processing.
Biometric personal data is information that characterizes the physiological and biological characteristics of a personal data subject, makes it possible to establish (identify) his identity and is used by the Company to establish (identify) his identity.
PD blocking is the temporary termination of PD processing (except in cases where processing is necessary to clarify PD) at the request of the PD subject or Roskomnadzor.
The legislation of the Russian Federation is a set of provisions of the regulatory legal acts of the Russian Federation, which define the cases and features of personal data processing, as well as establish requirements for the processing of personal data.
Personal Data Information System (ISPD) – a set of personal data contained in databases and information technologies and technical means that ensure their processing.
Confidentiality of personal data is the obligation not to disclose or distribute personal data to third parties without the consent of the personal data subject, unless otherwise provided by federal law.
A supervisory authority is a body authorized to exercise state control and supervision over the compliance of PD processing with legal requirements, as well as compliance with the rights of PD subjects (Roskomnadzor).
PD processing is any action (operation) or set of actions (operations) performed with or without the use of automation tools with PD, including collection, recording, systematization, accumulation, storage, refinement (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deleting, and destroying personal data.
Operator – a state body, municipal body, legal entity or individual who independently or jointly with other persons organize and (or) process personal data, as well as determine the purposes of personal data processing, the composition of personal data to be processed, and actions (operations) performed with personal data.
Special categories of PD are PD related to race, national origin, political views, religious or philosophical beliefs, health status, intimate life, as well as information about criminal records.
Cross‑border transfer of PD is the transfer of PD to the territory of a foreign state to a foreign government authority, a foreign individual, or a foreign legal entity.
Destruction of personal data (PD) refers to actions that make it impossible to restore the content of personal data in the PD information system and/or that result in the destruction of material media containing personal data.
Personal Data Processing in the Company is carried out in compliance with the following principles established by the legislation of the Russian Federation:
The legal grounds for processing the personal data of data subjects are established taking into account the conditions for processing personal data specified in Law № 152-FZ. The legal grounds for processing personal data are:
The Company processes the personal data of data subjects for predetermined purposes. Depending on the specific purposes of processing the personal data, such processing may include, in particular, performing all or some of the following actions (operations) with the personal data: collection (acquisition), recording, systematization, accumulation, storage, clarification (update, modification), extraction, use, transfer (provision, access), blocking, deletion, destruction of the personal data.
For each purpose of processing personal data, the Company defines:
The purposes of processing personal data and the corresponding categories, as well as the list of processed personal data and categories of data subjects, are set out in Appendix № 1 to this Policy, which is an integral part of it.
For the purposes of processing personal data specified in Appendix № 1 to this Policy, the following methods of processing personal data are provided:
When processing personal data using an automated method, the Company takes the necessary measures to ensure the security of the processed personal data.
Processing personal data using a non‑automated method, including the storage of physical carriers of personal data, is carried out in premises that ensure their safety, with the possibility of identifying the storage locations for personal data (physical carriers) in accordance with the procedure established by the legislation of the Russian Federation.
The duration for processing and storing personal data for each purpose of processing personal data specified in Appendix No. 1 to this Policy is established taking into account compliance with requirements, including the conditions for processing personal data as defined by the legislation of the Russian Federation, and/or taking into account the provisions of a contract in which the data subject is a party, beneficiary, or guarantor, and/or the consent of the data subject to the processing of their personal data. At the same time, the processing and storage of personal data shall not exceed the period required to achieve the purpose of processing personal data, unless otherwise established by the legislation of the Russian Federation.
Procedure for the destruction of personal data. The destruction of personal data, the processing of which is carried out within the framework of the purposes specified in Appendix № 1 to this Policy, is carried out in the following cases:
The methods for destroying personal data are determined by the Company’s local regulatory acts on the processing and protection of personal data, depending on the methods of processing personal data and the material carriers of personal data on which the data is recorded and stored. The fact of data destruction is confirmed in accordance with the procedure provided for in clause 6.8 of this Policy.
6.1. When processing personal data, the Company adheres to the principles and requirements for the procedure and conditions for processing personal data as established by the provisions of the legislation of the Russian Federation, this Policy, and other local regulatory acts of the Company.
6.2. The collection (acquisition) and subsequent actions (operations) related to the processing of personal data are carried out in compliance with the rights and legitimate interests of the subjects of personal data within the framework of the approved processes and/or local regulatory acts of the Company, which define:
The procedure for stopping the processing and destruction/ensuring the destruction of personal data (if the processing of personal data is carried out by a person acting on behalf of the Company).
6.3. The Company defines the list of persons who process personal data. Access to the processed personal data is granted only to those Company employees who need it to perform specific functions as part of their job duties. The job descriptions of Company employees and/or employment contracts, including, if applicable, additional agreements to employment contracts, include obligations to ensure the confidentiality and security of personal data and liability measures for failure to comply with these obligations.
Prior to processing personal data, the Company’s employees whose job functions and responsibilities include processing personal data must be familiarized, by signature, with the provisions of Russian legislation on personal data, including the requirements for the protection of personal data, as well as with the requirements of the Company’s local regulatory acts regulating the processing and protection of personal data.
6.4. When processing personal data in the Company, timely clarification (update, modification) of the personal data of the data subject is ensured, which is carried out, in particular, in the event of confirmation of the fact that the personal data is inaccurate, based on:
6.5. The Company’s receipt of personal data from a third party and/or the transfer (provision, access) of personal data to a third party, as well as the assignment of the processing of personal data to a third party, is permitted with the consent of the data subject to the processing of personal data, including that provided to a third party, or if there are other grounds provided for by the legislation of the Russian Federation. The Company’s receipt of personal data from a third party and/or the transfer (provision, access) The processing of personal data by a third party, as well as the assignment of such processing to a third party, is carried out on the basis of an appropriate agreement with the third party, which includes the terms of the personal data processing, the requirements for ensuring the confidentiality and security of personal data during its processing, and other requirements in accordance with Law № 152‑FZ.
The transfer of personal data to government bodies and institutions, municipal authorities, and state extra‑budgetary funds, as well as the receipt of personal data from government bodies and institutions, municipal authorities, and state extra‑budgetary funds, is permitted in the absence of the subject’s consent to the processing of their personal data, in accordance with the procedure and in cases provided for by the legislation of the Russian Federation.
Transboundary transfer of personal data is not carried out.
6.6. PD processing is terminated upon achievement of the purposes of such processing, as well as upon expiration of the period stipulated by the legislation of the Russian Federation, the agreement or the consent of the PD subject to the processing of his personal data. If the PD subject withdraws consent to the processing of his personal data and/or demands to stop processing personal data, the Company has the right to continue processing personal data without the PD subject’s consent, provided that there are grounds (conditions for processing personal data) provided for by Law № 152-FZ.
6.7. If the Company does not have legal grounds for processing personal data (conditions for processing personal data), the Company, in accordance with the procedure established by Law № 152‑FZ, destroys the personal data or ensures its destruction (if the processing of personal data is carried out by a person acting on behalf of the Company). The destruction is carried out by performing actions that make it impossible to restore the content of the personal data in the information system for processing personal data and/or that result in the destruction of the material carriers of the personal data. Based on the results of the destruction, a Certificate of Destruction of Personal Data is drawn up, and an entry is made in the electronic log of events in the Personal Data Processing System in accordance with the requirements of Roskomnadzor Order № 179 dated 28.10.2022 “On Approval of the Requirements for Confirmation of Destruction of Personal Data,” or, in the event that these requirements lose force or are declared invalid in full or in part, in accordance with the provisions of Russian legislation.
In order to comply with the rights and legitimate interests of data subjects, the requirements regarding the timeframes for processing appeals and/or requests, to ensure the quality and completeness of measures taken in response to a legitimate request from a data subject, and to provide the necessary information regarding their appeal and/or request, the collection and processing of appeals from data subjects are carried out, as well as monitoring to ensure such collection and processing.
When considering appeals and/or requests from data subjects, the Company adheres to the provisions of Russian legislation, according to which a request and/or appeal submitted by a data subject must contain the information specified in Law № 152‑FZ, namely:
If the appeal and/or request is submitted in the form of an electronic document, the document is signed with an electronic signature in accordance with the legislation of the Russian Federation.
The Company provides information and/or takes other measures in response to appeals and/or requests from subjects of personal data in the scope and within the timeframes provided for by the legislation of the Russian Federation. The deadline established by the Legislation of the Russian Federation for responding to a PD subject to an appeal and/or request for information related to the processing of his PD may be extended based on the restrictions established by Law № 152-FZ, with a reasoned notification addressed to the PD subject containing information on the reasons for extending the deadline for providing the requested information.
Upon receiving an appeal and/or request from a data subject and having verified its legitimacy, the Company shall provide the data subject and/or their representative, who has the authority to represent the data subject’s interests, with the information specified in the request in the same form in which the relevant appeal or request was sent, unless otherwise specified in the appeal or request, and/or take other measures depending on the specifics (features) of the appeal and/or request. The information provided by the Company may not contain personal data belonging to other data subjects, except in cases where there are lawful grounds for disclosing such personal data.
The Company has the right to refuse to meet the requirements specified in the appeal and/or request by sending a reasoned refusal to the data subject or their representative if, in accordance with the Laws of the Russian Federation, the Company has lawful grounds to refuse to comply with/meet the received requirements.
The Company monitors the receipt and processing of requests from personal data subjects in order to ensure compliance with the rights and legitimate interests of personal data subjects, adherence to the deadlines for processing requests, and the quality and completeness of measures taken in response to a legitimate request from a personal data subject, as well as the provision of the necessary information regarding their request in accordance with the Company’s local regulatory acts.
To ensure the confidentiality and security of personal data of data subjects, to protect personal data from unlawful or accidental access to it, destruction, alteration, blocking, copying, provision, distribution of personal data, as well as from other unlawful actions regarding personal data in accordance with Law № 152‑FZ, the Company takes the necessary legal, organizational and technical measures or ensures that they are taken (if the processing of personal data is carried out by a person acting on behalf of the Company). In particular, the following measures are taken:
In addition, an assessment is carried out of the harm that may be caused to personal data subjects in the event of a violation of Law № 152‑FZ, as well as the relationship between this harm and the measures taken to ensure compliance with the obligations stipulated by Law № 152‑FZ.
9.1. The Company is obliged to:
9.2. The Company has the right to:
9.3. The subject of personal data has the right to:
This Policy comes into effect and becomes mandatory for all employees of the Company from the moment it is approved.
This Policy may be amended at any time at the Company’s discretion, including in cases of changes to the legislation of the Russian Federation or the Company’s local regulatory acts that determine the procedure for processing and protecting personal data.
If, for any reason, one or more provisions of this Policy are found to be invalid or without legal force, these circumstances will not affect the validity or applicability of the remaining provisions of the Policy.
The Company’s employees are responsible for non‑compliance with the requirements for the processing and protection of personal data, including for the disclosure or illegal use of personal data, in accordance with the procedure and upon the occurrence of the conditions provided for by the Labour Code of the Russian Federation, and may also be held liable under civil, administrative and criminal law in accordance with the applicable regulatory legal acts of the Russian Federation.
Monitoring compliance with the requirements of this Policy is carried out by the person responsible for organizing the processing of personal data.
The Company’s Personal Data Processing Policy is published on the Company’s website on the Internet at: https://vladisart.ru/en/personal-policy/. The Policy is available for unrestricted access.
Contact information
Any inquiries regarding the processing of personal data should be directed to the Company:
Email: info@vladisart.ru
Phone: +7 4922 37-72-80 / 8 800 30 10 700
Address: 600031, Vladimir, Dobroselskaya St., 188A