User Agreement

Policy on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller

 

Contents

  1. General Definitions and Scope of Application
  2. List of Personal Data Databases
  3. Purpose of Personal Data Processing
  4. Procedure for Processing Personal Data: Obtaining Consent, Notification of Rights, and Actions Taken with the Personal Data of a Data Subject
  5. Location of the Personal Data Database
  6. Conditions for Disclosure of Personal Data to Third Parties
  7. Protection of Personal Data: Methods of Protection, Responsible Person, Employees Who Directly Process and/or Have Access to Personal Data in Connection with the Performance of Their Official Duties, Retention Period for Personal Data
  8. Rights of the Personal Data Subject
  9. Procedure for Handling Requests from a Personal Data Subject
  10. State Registration of the Personal Data Database

 

1. General Definitions and Scope of Application

1.1. Definitions of terms:

personal data database — a named collection of organised personal data in electronic form and/or in the form of personal data filing systems;

responsible person — a designated individual who organises work related to the protection of personal data during their processing, in accordance with the law;

personal data database owner — a natural or legal person who is granted the right to process such data by law or with the consent of the personal data subject, who establishes the purpose of personal data processing in this database, determines the composition of such data and the procedures for processing it, unless otherwise provided by law;

State Register of Personal Data Databases — a unified state information system for the collection, accumulation and processing of information on registered personal data databases;

publicly available sources of personal data — directories, address books, registers, lists, catalogues and other systematised collections of open information that contain personal data posted and published with the knowledge of the personal data subject. Social networks and internet resources where data subjects post their personal data are not considered publicly available sources of personal data (except where the data subject has explicitly stated that the personal data are made available for free distribution and use);

consent of the personal data subject — any documented, voluntary expression of intent by a natural person authorising the processing of their personal data for a specified purpose;

anonymisation of personal data — the removal of information by which an individual may be identified;

processing of personal data — any action or set of actions performed wholly or partially within an information (automated) system and/or in personal data filing systems, relating to the collection, registration, accumulation, storage, adaptation, modification, updating, use and dissemination (distribution, disclosure, transfer), anonymisation, or destruction of information about a natural person;

personal data — information or a set of information about a natural person who is identified or can be specifically identified;

personal data database administrator — a natural or legal person who is granted the right to process such data by the personal data database owner or by law. A person entrusted by the owner and/or administrator of a personal data database to perform technical operations on the personal data database without access to the content of the personal data is not considered a personal data database administrator;

personal data subject — a natural person in respect of whom personal data are processed in accordance with the law;

third party — any person, other than the personal data subject, the owner or administrator of the personal data database, and the authorised state body for personal data protection, to whom personal data are transferred by the owner or administrator of the personal data database in accordance with the law;

special categories of data — personal data concerning racial or ethnic origin, political, religious or philosophical beliefs, membership in political parties and trade unions, as well as data relating to health or sexual life.

1.2. This Policy is binding on the responsible person and the Seller's employees who directly process and/or have access to personal data in connection with the performance of their official duties.

 

2. List of Personal Data Databases

2.1. The Seller is the owner of the following personal data databases:

  • counterparty personal data database.

 

3. Purpose of Personal Data Processing

3.1. The purpose of personal data processing within the system is to support the performance of civil-law relationships, including the making, receipt and settlement of payments for purchased goods and services, in accordance with the Tax Code of Ukraine and the Law of Ukraine "On Accounting and Financial Reporting in Ukraine".

 

4. Personal Data Processing Procedure: Obtaining Consent, Notification of Rights, and Actions Regarding the Personal Data of a Data Subject

4.1. The consent of a data subject must be a voluntary expression of will by a natural person granting permission for the processing of their personal data in accordance with the stated purpose of such processing.

4.2. The consent of a data subject may be provided in the following forms:

  • a paper document containing the requisite details that enable the identification of both the document and the natural person;
  • an electronic document that must contain mandatory details enabling the identification of both the document and the natural person. The voluntary expression of will by a natural person granting permission for the processing of their personal data should preferably be certified by the electronic signature of the data subject;
  • a mark on an electronic page of a document or in an electronic file processed within an information system on the basis of documented software and technical solutions.

4.3. The consent of a data subject is provided at the time of formalising civil-law relations in accordance with applicable law.

4.4. Notification to the data subject regarding the inclusion of their personal data in the personal data database, the rights defined by the Law of Ukraine "On Personal Data Protection", the purpose of data collection, and the persons to whom their personal data are transferred is carried out at the time of formalising civil-law relations in accordance with applicable law.

4.5. The processing of personal data concerning racial or ethnic origin, political, religious, or ideological beliefs, membership in political parties and trade unions, as well as data relating to health or sexual life (special categories of data) is prohibited.

 

5. Location of the Personal Data Database

5.1. The personal data databases specified in Section 2 of this Policy are located at the seller's address.

 

6. Conditions for Disclosing Information on Personal Data to Third Parties

6.1. The procedure for third-party access to personal data is determined by the terms of the data subject's consent granted to the personal data controller for the processing of such data, or in accordance with the requirements of the law.

6.2. Access to personal data shall not be granted to a third party if that party refuses to undertake an obligation to comply with the requirements of the Law of Ukraine "On Personal Data Protection" or is unable to ensure such compliance.

6.3. A person involved in personal data relations submits an access request (hereinafter — the request) for personal data to the personal data controller.

6.4. The request shall specify:

  • the surname, first name and patronymic, place of residence (place of stay), and details of the identity document of the natural person submitting the request (for an individual applicant);
  • the name and registered address of the legal entity submitting the request, the position, surname, first name and patronymic of the person certifying the request; confirmation that the content of the request falls within the powers of the legal entity (for a legal entity applicant);
  • the surname, first name and patronymic, as well as any other information enabling the identification of the natural person in respect of whom the request is made;
  • information about the personal data database to which the request relates, or information about the controller or processor of that personal data database;
  • the list of personal data being requested;
  • the purpose and/or legal grounds for the request.

6.5. The period for reviewing the request in order to determine whether it can be fulfilled may not exceed ten working days from the date of its receipt. Within this period, the personal data database controller shall inform the person submitting the request that the request will be fulfilled or that the relevant personal data are not subject to disclosure, stating the grounds set out in the applicable regulatory act. The request shall be fulfilled within thirty calendar days from the date of its receipt, unless otherwise provided by law.

6.6. A deferral of access to personal data is permitted where the necessary data cannot be provided within thirty calendar days from the date of receipt of the request. In such a case, the total period for resolving the matters raised in the request may not exceed forty-five calendar days.

6.7. The notification of deferral shall be provided in writing to the third party that submitted the request, together with an explanation of the procedure for challenging such a decision.

6.8. The notification of deferral shall specify:

  • the surname, first name and patronymic of the official;
  • the date the notification was sent;
  • the reason for the deferral;
  • the period within which the request will be fulfilled.

6.9. A refusal of access to personal data is permitted where access to such data is prohibited by law.

6.10. The notice of refusal shall specify:

  • the surname, first name, and patronymic of the official denying access;
  • the date the notice was sent;
  • the reason for refusal.

6.11. A decision to defer or deny access to personal data may be appealed in court.

 

7. Protection of personal data: methods of protection, responsible person, employees who directly carry out processing and/or have access to personal data in connection with the performance of their official duties, personal data retention period

7.1. The personal data database owner is equipped with system, software-technical, and communication tools that prevent loss, theft, unauthorised destruction, alteration, forgery, or copying of information, and that comply with the requirements of international and national standards.

7.2. The responsible person organises work related to the protection of personal data during its processing, in accordance with the law. The responsible person is appointed by order of the personal data database owner.

The duties of the responsible person with regard to organising work related to the protection of personal data during its processing are set out in the job description.

7.3. The responsible person is obliged to:

  • be familiar with Ukrainian legislation in the field of personal data protection;
  • develop procedures for employee access to personal data in accordance with their professional, official, or employment duties;
  • ensure that employees of the personal data database owner comply with the requirements of Ukrainian legislation in the field of personal data protection and with internal documents governing the activities of the personal data database owner with respect to the processing and protection of personal data in personal data databases;
  • develop procedures for internal monitoring of compliance with the requirements of Ukrainian legislation in the field of personal data protection and with internal documents governing the activities of the personal data database owner with respect to the processing and protection of personal data in personal data databases, including provisions specifying the frequency of such monitoring;
  • notify the personal data database owner of any violations by employees of the requirements of Ukrainian legislation in the field of personal data protection and of internal documents governing the activities of the personal data database owner with respect to the processing and protection of personal data in personal data databases, no later than one business day from the moment such violations are discovered;
  • ensure the storage of documents confirming that the personal data subject has consented to the processing of their personal data and that the said subject has been informed of their rights.

7.4. In order to fulfil their duties, the responsible person has the right to:

  • obtain the necessary documents, including orders and other administrative documents issued by the personal data database owner, related to the processing of personal data;
  • make copies of obtained documents, including copies of files and any records stored in local computer networks and standalone computer systems;
  • participate in discussions concerning the discharge of their duties in organising work related to the protection of personal data during its processing;
  • submit for consideration proposals for improving operations and refining working methods, and raise observations and options for remedying identified deficiencies in the personal data processing workflow;
  • obtain explanations on matters relating to the processing of personal data;
  • sign and initial documents within the scope of their authority.

7.5. Employees who directly carry out processing and/or have access to personal data in connection with the performance of their official (employment) duties are obliged to comply with the requirements of Ukrainian legislation in the field of personal data protection and with internal documents concerning the processing and protection of personal data in personal data databases.

7.6. Employees who have access to personal data, including those who process it, are obliged not to disclose in any manner personal data that has been entrusted to them or that has become known to them in connection with the performance of their professional, official, or employment duties. This obligation continues after they cease any activities involving personal data, except in cases established by law.

7.7. Persons who have access to personal data, including those who process it, shall be held liable in accordance with Ukrainian legislation in the event of a violation of the requirements of the Law of Ukraine "On Personal Data Protection".

7.8. Personal data must not be stored for longer than is necessary for the purpose for which such data is stored, but in any case no longer than the data retention period specified in the personal data subject's consent to the processing of such data.

 

8. Rights of the Personal Data Subject

8.1. The personal data subject has the right to:

  • know the location of the personal data database containing their personal data, its purpose and name, and the location and/or place of residence (stay) of the owner or controller of that database, or to give a corresponding instruction to persons authorised by them to obtain such information, except in cases established by law;
  • receive information on the conditions for granting access to personal data, including information about third parties to whom their personal data contained in the relevant personal data database are transferred;
  • access their personal data contained in the relevant personal data database;
  • receive, no later than thirty calendar days from the date of receipt of the request, except in cases provided for by law, a response as to whether their personal data are stored in the relevant personal data database, and also to receive the content of their personal data that are stored;
  • submit a reasoned demand objecting to the processing of their personal data by state authorities and local self-government bodies in the exercise of their powers provided for by law;
  • submit a reasoned demand for the modification or destruction of their personal data by any owner or controller of that database, if such data are being processed unlawfully or are inaccurate;
  • protection of their personal data against unlawful processing and accidental loss, destruction, or damage in connection with intentional concealment, failure to provide, or untimely provision thereof, as well as protection against the provision of information that is inaccurate or that damages the honour, dignity, and business reputation of the individual;
  • apply to state authorities and local self-government bodies, within whose competence the protection of personal data falls, regarding the protection of their rights with respect to personal data;
  • use legal remedies in the event of a breach of personal data protection legislation.

 

9. Procedure for Handling Requests from the Personal Data Subject

9.1. The personal data subject has the right to obtain any information about themselves from any party to personal data relations, without stating the purpose of the request, except in cases established by law.

9.2. Access by the personal data subject to data about themselves is provided free of charge.

9.3. The personal data subject submits a request for access (hereinafter — request) to personal data to the owner of the personal data database.

The request shall specify the following:

  • last name, first name and patronymic, place of residence (place of stay), and details of the identity document of the personal data subject;
  • other information enabling identification of the personal data subject;
  • information about the personal data database to which the request relates, or information about the owner or controller of that database;
  • the list of personal data being requested.

9.4. The period for examining a request for the purpose of determining whether it can be satisfied shall not exceed ten working days from the date of its receipt. Within this period, the owner of the personal data database shall notify the personal data subject either that the request will be satisfied or that the relevant personal data are not subject to disclosure, stating the grounds set out in the applicable regulatory legal act.

9.5. A request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

 

10. State Registration of the Personal Data Database

10.1. State registration of personal data databases is carried out in accordance with Article 9 of the Law of Ukraine "On Personal Data Protection".