Content:

  1. General concepts and scope.
  2. List of personal data databases.
  3. Purpose of personal data processing.
  4. Procedure for processing personal data: obtaining consent, notification of rights and actions with personal data of the subject of personal data.
  5. Location of the personal data database.
  6. Conditions for disclosure of information about personal data to third parties.
  7. Protection of personal data: methods of protection, responsible person, employees who directly process and/or have access to personal data in connection with the performance of their official duties, period of storage of personal data.
  8. Rights of the personal data subject.
  9. Procedure for working with requests from the subject of personal data.
  10. State registration of the personal data database.

 

  1. General concepts and scope.

1.1. Definition of terms:

personal data database – a named set of ordered personal data in electronic form and/or in the form of personal data files;

responsible person – a designated person who organizes work related to the protection of personal data during their processing, in accordance with the law;

personal data owner – an individual or legal entity that is granted the right to process this data by law or with the consent of the personal data subject, which approves the purpose of personal data processing, establishes the composition of this data and the procedures for their processing, unless otherwise determined by law;

The State Register of Personal Data Databases is a unified state information system for collecting, accumulating and processing information about registered personal data databases;

publicly available sources of personal data – directories, address books, registers, lists, catalogs, other systematized collections of open information that contain personal data posted and published with the knowledge of the subject of personal data.

Social networks and Internet resources in which the subject of personal data leaves his/her personal data are not considered publicly available sources of personal data (except for cases when the subject of personal data expressly states that personal data are posted for the purpose of their free distribution and use).

consent of the subject of personal data – any documented, voluntary expression of will of an individual to grant permission to process his/her personal data in accordance with the stated purpose of their processing;

depersonalization of personal data – removal of information that allows you to identify a person;

personal data processing – any action or set of actions performed in whole or in part in the information (automated) system and/or in personal data files related to the collection, registration, accumulation, storage, adaptation, change, update, use and distribution (distribution, sale, transfer), depersonalization, destruction of information about an individual;

personal data – information or a set of information about an individual who is identified or can be specifically identified;

Administrator of the personal data database – an individual or legal entity to whom the owner of the personal data database or the law has been granted the right to process this data.

A person who is entrusted by the owner and/or manager of the personal data database to carry out technical work with the personal data database without access to the content of personal data is not a manager of a personal data database.

personal data subject – an individual in respect of whom his/her personal data is processed in accordance with the law;

third party – any person, except for the subject of personal data, the owner or manager of the personal data database and the authorized state body for personal data protection, to whom the owner or manager of the personal data base transfers personal data in accordance with the law;

Special categories of data – personal data on racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data relating to health or sex life.

1.2. This Regulation is mandatory for application by the responsible person and employees of the seller who directly process and/or have access to personal data in connection with the performance of their official duties.

 

  1. List of personal data databases.

2.1. The Seller is the owner of the following personal data databases:

Database of personal data counterparties.

 

  1. Purpose of personal data processing.

3.1. The purpose of processing personal data in the system is to store and maintain the data of counterparties in accordance with Articles 6, 7 of the Law of Ukraine "On Personal Data Protection".

3.2. The purpose of personal data processing is to ensure the implementation of civil law relations, the provision / receipt and payment for purchased goods / services in accordance with the Tax Code of Ukraine, the Law of Ukraine "On Accounting and Financial Reporting in Ukraine".

 

  1. Procedure for processing personal data: obtaining consent, notification of rights and actions with personal data of the subject of personal data.

4.1. The consent of the personal data subject must be a voluntary expression of the individual's will to grant permission to process his/her personal data in accordance with the stated purpose of their processing. The consent of the personal data subject can be provided in the following forms:

4.2. The consent of the personal data subject is provided when formalizing civil law relations in accordance with the current legislation.

4.3. Notification of the subject of personal data about the inclusion of his/her personal data in the personal data database, the rights determined by the Law of Ukraine "On Personal Data Protection", the purpose of data collection and the person to whom his/her personal data is transferred is carried out when formalizing civil law relations in accordance with the current legislation.

4.4. The processing of personal data on racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and trade unions, as well as data related to health or sex life (special categories of data) is prohibited.

 

  1. Location of the personal data database.

5.1. The personal data bases specified in Section 2 of this Regulation are located at the seller's address.

 

  1. Conditions for disclosure of information about personal data to third parties.

6.1. The procedure for access to personal data of third parties is determined by the terms of the consent of the personal data subject provided to the owner of the personal data base for the processing of this data, or in accordance with the requirements of the law.

6.2. Access to personal data is not provided to a third party if the specified person refuses to undertake obligations to ensure compliance with the requirements of the Law of Ukraine "On Personal Data Protection" or cannot provide them.

6.3. The subject of relations related to personal data submits a request for access (hereinafter referred to as the request) to personal data to the owner of the personal data database.

6.4. The request shall indicate:

6.5. The term of study of the request for its satisfaction may not exceed ten working days from the date of its receipt.

During this period, the owner of the personal data base informs the person submitting the request that the request will be satisfied or the relevant personal data is not subject to provision, indicating the basis specified in the relevant regulatory legal act.

The request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law.

6.6. All employees of the owner of the personal data base are obliged to comply with the confidentiality requirements regarding personal data and information on securities and securities accounts.

6.7. Postponement of access to personal data of third parties is allowed if the necessary data cannot be provided within thirty calendar days from the date of receipt of the request. At the same time, the total term for resolving the issues raised in the request may not exceed forty-five calendar days.

6.8. The notification of the postponement shall be brought to the attention of the third party who submitted the request in writing with an explanation of the procedure for appealing such a decision.

6.9. The notice of postponement shall indicate:

6.10. Denial of access to personal data is allowed if access to them is prohibited by law.

6.11. The notice of refusal shall indicate:

6.12. The decision to postpone or deny access to personal data may be appealed to the authorized state body for personal data protection, other state authorities and local self-government bodies, whose powers include the protection of personal data, or in court.

 

  1. Protection of personal data: methods of protection, responsible person, employees who directly process and/or have access to personal data in connection with the performance of their official duties, period of storage of personal data.

7.1. The owners of the personal data database are equipped with system, software and hardware and means of communication that prevent loss, theft, unauthorized destruction, distortion, forgery, copying of information and meet the requirements of international and national standards.

7.2. The responsible person organizes work related to the protection of personal data during their processing in accordance with the law. The responsible person is determined by the order of the owner of the personal data base.

The responsibilities of the responsible person regarding the organization of work related to the protection of personal data during their processing are specified in the job description.

7.3. The responsible person is obliged to:

 

  1. Deletion and editing of personal data:

8.1. We have the opportunity for users to edit or delete their data, it is not necessary to delete their account.

8.2. To edit personal data, please log in to your personal account on the website or app and go to the "My personal data" tab.

8.3. If you wish to request the deletion of your data, please contact us at [email protected] or by phone numbers: +38 080 033 20 60, +38 095 902 80 80, +38 098 902 80 80, +38 093 902 80 80. 

8.4. Types of data that can be deleted or edited: name, date of birth, email, phone, delivery address, password for the account, email subscription settings, personal reviews.

Data retention periods: indefinitely.

 

Item added to cart prod