Русская версия
Privacy Policy regarding the processing of personal data of site visitors
- General provisions
- This Policy regarding the processing of personal data (hereinafter referred to as the Policy) has been prepared in accordance with Clause 2.1 of Article 18.1 of the Federal Law of the Russian Federation "On Personal Data" No. 152-FZ of July 27, 2006 (hereinafter referred to as the Law) and defines the position of the Site Administration (hereinafter referred to as the Site Administration) in the field of processing and protection of personal data (hereinafter referred to as Data), respect for the rights and freedoms of every person and, in particular, the right to privacy, personal and family secrets.
- Scope of application
- This Policy applies to Data received both before and after the entry into force of this Policy.
- Understanding the importance and value of Data, as well as taking care of the observance of the constitutional rights of citizens of the Russian Federation and citizens of other states, the site Administration ensures reliable data protection.
- Definitions
- Data refers to any information related directly or indirectly to a specific or identifiable individual, i.e. such information, in particular, includes: surname, first name, patronymic, email address, location, link to a personal website or social networks, ip address.
- Data processing is understood as any action (operation) or a set of actions (operations) with Data performed using automation tools and/or without the use of such tools. Such actions (operations) include: collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of Data.
- Data Security refers to the protection of Data from unlawful and/or unauthorized access to them, destruction, modification, blocking, copying, provision, distribution of Data, as well as from other illegal actions with respect to Data.
- Legal grounds and purposes of data processing
- Processing and ensuring data security by the Site Administration is carried out in accordance with the requirements of the Constitution of the Russian Federation, the Law, the Labor Code of the Russian Federation, by-laws, other defining cases and features of data processing of federal laws of the Russian Federation, guidelines and methodological documents of the FSTEC of Russia and the FSB of Russia.
- The subjects of the Data processed by the Site Administration are:
- Users and visitors of the site https://zaka-zaka.com owned by the Site Administration, including for the purpose of placing an order on the Site https://zaka-zaka.com.
- The site administration processes the Data of the subjects for the following purposes:
- implementation of the functions, powers and duties assigned to the Site Administration by the legislation of the Russian Federation in accordance with federal laws,
- Users for the purposes of:
- - providing information on goods/services, ongoing promotions and special offers;
- - analyzing the quality of the service provided and improving the quality of customer service;
- - informing about the order status;
- - execution of the contract, including the contract of sale, including concluded remotely on the Website, paid provision of services; provision of services, as well as accounting for services rendered to consumers for mutual settlements;
- - delivery of the ordered Goods to the User who made the order on the Website, return of the goods.
- Principles and conditions of data processing.
- When processing Data, the site Administration adheres to the following principles: data processing is carried out on a legal and fair basis; Data is not disclosed to third parties and is not distributed without the consent of the Data subject, except in cases requiring disclosure of Data at the request of authorized state bodies, legal proceedings; determination of specific legitimate purposes prior to processing (including collection) of Data; only those Data that are necessary and sufficient for the stated purpose of processing are collected; combining databases containing Data that are processed for purposes incompatible with each other is not allowed; data processing is limited to achieving specific, predetermined and legitimate goals; processed Data is subject to destruction or depersonalization upon achievement of processing goals or in in case of loss of the need to achieve these goals, unless otherwise provided by federal law.
- The site administration may include the Data of subjects in publicly available data sources, while the site Administration takes the written consent of the subject to the processing of his Data, or by expressing consent through the form of the site (checkbox), by clicking which the subject of personal data expresses his consent.
- The site administration does not process Data concerning race, nationality, political views, religious, philosophical and other beliefs, intimate life, membership in public associations, including trade unions.
- In order to fulfill the terms of the agreement, to pay for the order the Subject enters the payment data on the side of the payment service provide which takes the obligation to process the payment. The site Administration does not process nor save any payment information, the credit card credentials included.
- Biometric Data (information that characterizes the physiological and biological characteristics of a person, on the basis of which it is possible to establish his identity and which are used by the operator to establish the identity of the Data subject) are not processed by the site Administration.
- The site administration carries out cross-border data transfer. The administration of the website confirms that the foreign state to whose territory the transfer of personal data is carried out ensures adequate protection of the rights of personal data subjects in accordance with the security level defined by the Council of Europe Convention on the Protection of Individuals with Automated Processing of Personal Data.
- In cases established by the legislation of the Russian Federation, the Site Administration has the right to transfer Data to third parties (the federal tax service, the state pension fund and other state bodies) in cases provided for by the legislation of the Russian Federation.
- The site administration has the right to entrust the processing of Data of Data subjects to third parties with the consent of the Data subject, on the basis of an agreement concluded with these persons, including in agreement with the user agreement and the policy of processing personal data posted on the site.
- Persons who process Data on the basis of a contract concluded with the Site Administration (operator's instructions), undertake to comply with the principles and rules of data processing and protection provided for by Law. For each third party, the contract defines a list of actions (operations) with Data that will be performed by a third party engaged in data processing, the purposes of processing, establishes the obligation of such a person to respect confidentiality and ensure data security during their processing, specifies the requirements for the protection of processed Data in accordance with the Law.
- In order to fulfill the requirements of their contractual obligations, Data processing in the Site Administration is carried out both with and without the use of automation tools. Such actions (operations) include: collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of Data.
- The site Administration is prohibited from making decisions based solely on automated data processing that generate legal consequences against the Data subject or otherwise affect his rights and legitimate interests.
- Rights and obligations of data subjects, as well as the Site Administration in terms of data processing
- The subject whose Data is processed by the Site Administration has the right to:
- receive from the site Administration:
- confirmation of the fact of data processing and information about the availability of Data related to the relevant data subject;
- information about the legal grounds and purposes of data processing;
- information about the methods of data processing used by the Site Administration;
- the list of processed Data related to the data subject and information about the source of their receipt;
- information about the terms of data processing, including the terms of their storage;
- information on the procedure for the exercise of these rights by the subject;
- other information provided by Law or other regulatory legal acts of the Russian Federation;
- demand from the site Administration:
- clarification of their Data, their blocking or destruction if the Data is incomplete, outdated, inaccurate, illegally obtained or are not necessary for the stated purpose of processing;
- revoke your consent to data processing at any time; demand the elimination of illegal actions of the site Administration in relation to its Data;
- to protect their rights and legitimate interests, including compensation for damages and/or compensation for moral damage.
- The site administration in the process of data processing is obliged to:
- provide the Data subject, upon his request, with information concerning the processing of his personal data, or to legally provide a refusal within thirty days from the date of receipt of the request of the Data subject or his representative;
- explain to the Data Subject the legal consequences of refusing to provide Data if the provision of Data is mandatory in accordance with federal law;
- take the necessary legal, organizational and technical measures or ensure their adoption to protect Data from unauthorized or accidental access to them, destruction, modification, blocking, copying, provision, dissemination of Data, as well as from other illegal actions with respect to Data;
- publish on the Internet and provide unrestricted access using the Internet to the document defining its data processing policy, to information about the implemented data protection requirements;
- provide data subjects and/or their representatives with the opportunity to familiarize themselves with the Data free of charge when making a corresponding request within 30 days from the date of receipt of such a request;
- block illegally processed Data related to the Data subject, or to ensure their blocking (if Data processing is carried out by another person acting on behalf of the Site Administration) from the moment of the request or receipt of the request for the verification period, in case of detection of illegal data processing when the Data subject or his representative or at the request of the Data subject or his representative or the authorized body for the protection of the rights of personal data subjects;
- clarify the Data or to ensure their clarification within 7 working days from the date of submission of the information and to remove the blocking of the Data, in case of confirmation of the fact of inaccuracy of the Data on the basis of the information provided by the data subject or his representative;
- stop the unlawful processing of Data or to ensure the termination of the unlawful processing of Data;
- terminate Data processing or ensure its termination and destroy Data or ensure their destruction upon achieving the purpose of data processing, unless otherwise provided by the contract to which the Data subject is a party, beneficiary or guarantor, in case of achieving the purpose of data processing;
- terminate data processing or ensure its termination and destroy Data or ensure their destruction in case the Data subject withdraws consent to data processing, if the Site Administration does not have the right to process Data without the consent of the Data subject;
- Data protection Requirements
- When processing Data, the site Administration takes the necessary legal, organizational and technical measures to protect Data from unlawful and/or unauthorized access to them, destruction, modification, blocking, copying, provision, dissemination of Data, as well as from other illegal actions with respect to Data.
- Such measures in accordance with the Law, in particular, include:
- appointment of the person responsible for the organization of data processing and the person responsible for ensuring data security;
- development and approval of local acts on data processing and protection;
- application of legal, organizational and technical measures to ensure data security:
- identification of data security threats during their processing in personal data information systems;
- application of organizational and technical measures to ensure data security during their processing in personal data information systems necessary to meet data protection requirements;
- the use of information security tools that have passed the compliance assessment procedure in accordance with the established procedure;
- evaluation of the effectiveness of the measures taken to ensure data security prior to the commissioning of the personal data information system;
- accounting of machine data carriers, if data storage is carried out on machine media;
- detection of unauthorized access to Data and taking measures to prevent such incidents in the future;
- recovery of data modified or destroyed due to unauthorized access to them;
- establishing rules for access to Data processed in the personal data information system, as well as ensuring registration and accounting of all actions performed with Data in the personal data information system.
- control over the measures taken to ensure data security and the level of security of personal data information systems;
- assessment of the harm that may be caused to data subjects in case of violation of the requirements of the Law, the ratio of this harm and the measures taken by the Site Administration aimed at ensuring compliance with the obligations provided for by Law;
- compliance with the conditions that exclude unauthorized access to material data carriers and ensure the safety of Data;
- Terms of data processing (storage)
- The terms of Data processing (storage) are determined based on the purposes of data processing, in accordance with the validity period of the contract with the data subject, the requirements of federal laws, the requirements of data operators on whose behalf the site Administration processes Data, the basic rules of the archives of organizations, the statute of limitations.
- The data whose processing (storage) period has expired must be destroyed. Data storage after the termination of their processing is allowed only after their depersonalization.
- Procedure for obtaining clarifications on data processing issues
- Persons whose Data is processed by the Site Administration can get clarifications on the processing of their Data by contacting the Site Administration via the feedback form.
- Features of processing and protection of Data collected by the Site Administration using the Internet
- The site administration processes the Data received from the Site users from the resource: https://zaka-zaka.com (hereinafter collectively referred to as the Site), as well as incoming to the Site's email address: support@zaka-zaka.com , via the feedback form located at: https://zaka-zaka.com/faq/feedback/, and when going directly to checkout.
- Data Collection There are two main ways in which the site Administration receives Data via the Internet:
- Provision of Data (independent data entry):
- surname
- name
- patronymic
- Email
- link to a personal website or social networks
- The data subjects by sending to the e-mail address of the site Administration: support@zaka-zaka.com , through the feedback form of the site Administration, located at: https://zaka-zaka.com/faq/feedback/.
- Automatically collected information The site administration may collect and process information that is not personal data:
- location determination
- ip address
- information about the interests of Users on the Site based on the entered search queries of Site users about the goods being sold and offered for sale in order to provide up-to-date information to users when using the Site, as well as generalization and analysis of information about which sections of the Site and products are in the greatest demand among Site customers;
- processing and storage of Site users' search queries for the purpose of summarizing and creating client statistics on the use of Site sections. The site administration automatically receives some types of information obtained during user interaction with the Site, correspondence by e-mail, etc. We are talking about technologies and services, such as web protocols, cookies, web tags, as well as applications and tools of the specified third party. At the same time, web tags, cookies and other monitoring technologies do not make it possible to automatically receive Data. If the user of the Site provides his Data at his discretion, for example, when filling out a feedback form or when sending an email, then only then the processes of automatic collection of detailed information are started for the convenience of using the Site and / or to improve interaction with Users.
- Use of Data The Site Administration has the right to use the provided Data in accordance with the stated purposes of their collection with the consent of the Data subject, if such consent is required. The data obtained in a generalized and depersonalized form can be used to better understand the needs of buyers of goods and services sold by the site Administration and to improve the quality of service.
- Data Transfer The Site Administration may entrust Data processing to third parties solely with the consent of the Data subject. The Data may also be transferred to third parties in the following cases: a) as a response to legitimate requests of authorized state bodies, in accordance with laws, court decisions, etc. b) Data may not be transferred to third parties for marketing, commercial and other similar purposes, except in cases of obtaining the prior consent of the Data subject.
- The Site contains links to other web resources, where there may be useful and interesting information for Site users. At the same time, this Policy does not apply to such other sites. Users who click on links to other sites are advised to familiarize themselves with the data processing policies posted on such sites.
- The Site User can withdraw his consent to data processing at any time by sending a message to the following email address: support@zaka-zaka.com , via the feedback form located at: https://zaka-zaka.com/faq/feedback/. Upon receipt of such a message, the processing of the User's Data will be terminated and his Data will be deleted, except in cases where processing can be continued in accordance with the law.
- Final provisions
- This Policy is a local regulatory act of the Site Administration. This Policy is publicly available. The general availability of this Policy is ensured by publication on the Website. This Policy may be revised in any of the following cases:
- when changing the legislation of the Russian Federation in the field of personal data processing and protection;
- in cases of receiving instructions from the competent state authorities to eliminate inconsistencies affecting the scope of the Policy;
- by the decision of the site Administration;
- when changing the goals and deadlines of data processing;
- when changing the organizational structure, the structure of information and/or telecommunication systems (or introducing new ones);
- when using new technologies for data processing and protection (including transmission, storage);
- if there is a need to change the data processing process related to the Site's activities.
- An integral part of this Policy is the Consent to the processing of personal data posted on the Website.
- This Policy applies directly and is interrelated with the User Agreement posted on the Site.
Updated "01" July 2018