AT IMPERIAL LLC PERSONAL DATA PROCESSING POLICY
1. General Provisions
1.1. The following terms are used in this Policy.
“Affiliates” means any person that directly or indirectly controls, is controlled by, or is under common control with the Company. A person is deemed to control another person if it owns more than 50% of the participation interests (shares or units) in the authorized capital of that other person or otherwise exercises management over that person.
“Customers” means individuals and legal entities to whom Services are provided.
“Personal Data Law” means Federal Law No. 152-FZ “On Personal Data” dated July 27, 2006.
“Suppliers” means individuals and legal entities that have civil-law relations with the Company involving the provision of services, performance of work, or supply of goods to the Company.
“Employees” means individuals who are or were in an employment relationship with the Company.
“Websites” means websites on the Internet owned or administered by the Company.
“Applicants” means individuals who apply or have applied for Employee vacancies.
“Services” means services provided by the Company and its Affiliates.
1.2. Terms not defined in this Policy have the meanings assigned to them by the laws of the Russian Federation, primarily the Personal Data Law.
2. Principles of Personal Data Processing
2.1. The Company strives to ensure the security of personal data in order to protect the rights and freedoms of personal data subjects, including the right to privacy and personal and family confidentiality, and to comply with Russian and international law. The Company processes personal data on the basis of the following principles:
- (a) lawfulness of the purposes and methods of personal data processing;
- (b) consistency of the purposes of personal data processing with the purposes predetermined and declared when the personal data was collected;
- (c) consistency of the scope and nature of the personal data processed and the methods of its processing with the purposes of personal data processing;
- (d) accuracy and relevance of personal data, sufficiency of the data for the purposes of processing, and prohibition of processing personal data that is excessive in relation to the purposes declared when it was collected;
- (e) prohibition of combining databases containing personal data that were created for mutually incompatible purposes.
2.2. The legal basis for personal data processing by the Company includes the Labor Code of the Russian Federation, the Tax Code of the Russian Federation, the Civil Code of the Russian Federation, Federal Law No. 402-FZ dated December 6, 2011 “On Accounting,” Order No. 236 of the Federal Archival Agency dated December 20, 2019 “On Approval of the List of Standard Administrative Archival Documents Generated in the Course of Activities of State Authorities, Local Government Bodies and Organizations, with Their Retention Periods,” other regulatory legal acts governing the Company’s activities, and the Company’s constituent documents.
3. Categories of Data Processed
3.1. The Company processes only personal data that:
- (a) is provided to the Company by personal data subjects themselves, including through feedback forms on the Websites, by email, or by other means;
- (b) is obtained by the Company with the consent of personal data subjects.
3.2. When personal data subjects visit the Websites, the following information may be collected automatically and used to evaluate the effectiveness of marketing campaigns:
- (a) technical information, including IP address, access data, browser type and version, time-zone settings, and operating system;
- (b) information about visits to the Websites, including URLs, navigation history to and from the Websites and other resources, search queries, page response times and download errors, the duration of visits to individual pages, and information about interaction with a page.
4. Purposes of Personal Data Processing
4.1. The Company processes the personal data of different categories of personal data subjects for different purposes.
If a personal data subject belongs to more than one category, their personal data may be processed for the purposes applicable to each such category.
4.2. The Company processes personal data of prospective, current, and former Customers and their representatives, including users of the Websites, for the following purposes:
- (a) entering into agreements with prospective Customers;
- (b) performing agreements entered into with Customers;
- (c) maintaining business contacts with prospective, current, and former Customers;
- (d) reviewing requests from prospective, current, and former Customers;
- (e) sending advertising and informational communications;
- (f) evaluating the effectiveness of marketing campaigns;
- (g) monitoring and evaluating the scope and quality of work performed by Employees and contractors under civil-law agreements.
4.3. The Company processes personal data of prospective, current, and former Suppliers and their representatives for the following purposes:
- (a) entering into agreements with prospective Suppliers;
- (b) performing agreements entered into with Suppliers;
- (c) maintaining business contacts with Suppliers.
4.4. The Company processes Employees’ personal data for the following purposes:
- (a) entering into and performing employment agreements with Employees, including the calculation and payment of salaries, other remuneration, and compensation;
- (b) monitoring and evaluating the scope and quality of work performed by Employees;
- (c) ensuring employee safety and the security of the Company’s property;
- (d) arranging access to corporate information resources;
- (e) providing interested parties with information about the Company’s employees.
4.5. The Company processes Applicants’ personal data for the following purposes:
- (a) recruitment;
- (b) creation and maintenance of a talent pool.
4.6. The Company processes the personal data of visitors to its office in order to ensure employee safety and the security of the Company’s property.
4.7. On the instructions of third parties, the Company may provide services involving personal data processing. In such cases, personal data is processed exclusively for the purposes specified in the relevant third-party instructions. The cases and procedure for processing personal data on Customers’ instructions are governed by separate agreements entered into with the Customers.
4.8. Any operations involving personal data, whether the processing of paper documents or data processing using automated systems, are performed by the Company solely for the purposes described above. The purposes of personal data processing specified in this section do not limit the Company’s right to process data relating to any category of personal data subjects in order to comply with applicable law or protect the Company’s rights and legally protected interests.
For the stated purposes, the Company may process personal data by performing the following operations: collection, recording, systematization, accumulation, storage, clarification (updating or modification), retrieval, use, transfer (provision, access, or dissemination), blocking, deletion, and destruction.
5. Transfer of Personal Data
5.1. When transferring personal data to third parties, the Company informs those parties that they must keep the personal data confidential and use it only for the purposes for which it was transferred. Where personal data is transferred to persons processing it on the Company’s instructions and in the Company’s interests, the agreement with such a person specifies, in particular:
- (a) the list of personal data transferred;
- (b) the list of actions or operations involving personal data to be performed by the processor;
- (c) the permitted purposes for which that person may process personal data;
- (d) that person’s obligation to maintain the confidentiality of personal data and ensure its security during processing;
- (e) specific requirements for protecting the personal data processed;
- (f) that person’s obligation to process the personal data of Russian Federation citizens using databases located in the Russian Federation;
- (g) that person’s obligation to take measures aimed at ensuring performance of the duties imposed on personal data operators by personal data law;
- (h) that person’s obligation to provide documents and other information confirming that measures have been taken and requirements have been met in accordance with personal data law and the Company’s instructions.
5.2. Applicants’ personal data may be transferred to the following persons:
| Recipients / categories of recipients | Type of recipient | Purpose of transfer |
|---|---|---|
| Contractors providing information-system maintenance and support services to the Company. | A person processing data on the Company’s instructions. | Provision of maintenance and support services for information systems used to keep records of Applicants. |
| Contractors providing information-system maintenance and support services to the Company. | A person processing data on the Company’s instructions. | Provision of maintenance and support services for information systems used to keep records of Applicants. |
| Affiliates. | Independent personal data operator. | Inclusion in the Affiliates’ talent pool. |
5.3. Employees’ personal data may be transferred to the following persons:
| Recipients / categories of recipients | Type of recipient | Purpose of transfer |
|---|---|---|
| Contractors providing information-system maintenance and support services to the Company. | A person processing data on the Company’s instructions. | Provision of technical maintenance and support services for information systems used for personnel records and work-process organization. |
| Credit institutions. | Independent personal data operator. | Settlement of payments. |
| Affiliates. | Independent personal data operator. | Facilitating interaction between group companies. |
| Counterparties. | Independent personal data operator. | Ensuring communication and operational interaction with the counterparty. |
| Government authorities and budgetary and extra-budgetary funds. | Independent personal data operator. | Performance of obligations imposed on the Company by law. |
5.5. Personal data of prospective and current Customers and their representatives may be transferred to the following persons:
| Recipients / categories of recipients | Type of recipient | Purpose of transfer |
|---|---|---|
| Contractors providing information-system maintenance and support services to the Company. | A person processing data on the Company’s instructions. | Provision of maintenance and support services for information systems used to keep records of interactions with Customers. |
| Contractors providing the Company with services for evaluating the effectiveness of marketing campaigns. | A person processing data on the Company’s instructions. | Provision of services related to evaluating the effectiveness of marketing campaigns using information collected during visits to the Company’s Websites. |
| Contractors and subcontractors engaged to perform individual projects. | A person processing data on the Company’s instructions. | Performance of work or provision of services in the Customer’s interests. |
| Affiliates. | Independent personal data operator. | Facilitating interaction between group companies. |
5.6. Personal data of visitors to the office may be transferred to the following persons:
| Recipients / categories of recipients | Type of recipient | Purpose of transfer |
|---|---|---|
| Owners of the office premises occupied by the Company and security organizations engaged by those owners or by the Company. | Independent personal data operator. | Organizing and enforcing access-control procedures at premises occupied by the Company. |
5.7. Detailed information about persons processing the personal data of a particular subject on the Company’s instructions may be provided to that subject in accordance with the procedure set out in Section 7 of this Policy.
5.8. Personal data is provided to government authorities in accordance with applicable law.
6. Storage and Protection of Personal Data
6.1. The Company takes full responsibility for protecting the personal data it processes. The Company has appointed a person responsible for organizing personal data processing who oversees all matters related to personal data processing and ensuring the rights of personal data subjects. The Company has also implemented a set of internal regulations governing the processing and protection of personal data.
6.2. When processing personal data, the Company implements organizational, legal, and technical safeguards that prevent unauthorized access by persons not authorized to process the data. These safeguards include, among other things:
- (a) assessing the harm that may be caused to personal data subjects if personal data law is violated and balancing that harm against the measures taken by the Company to ensure performance of its statutory obligations;
- (b) identifying threats to personal data security when personal data is processed in personal data information systems;
- (c) using information-security tools that have undergone the prescribed conformity-assessment procedure;
- (d) evaluating the effectiveness of personal data security measures before personal data information systems are put into operation;
- (e) keeping records of and safeguarding machine-readable personal data media;
- (f) detecting unauthorized access to personal data and taking appropriate measures, including measures to detect, prevent, and mitigate the consequences of cyberattacks against personal data information systems and to respond to computer incidents in those systems;
- (g) restoring personal data that was modified or destroyed as a result of unauthorized access;
- (h) establishing rules for access to personal data processed in personal data information systems and ensuring the registration and recording of all actions performed with personal data in those systems;
- (i) monitoring the measures taken to ensure personal data security and the protection levels of personal data information systems.
7. Rights of Personal Data Subjects
7.1. Personal data subjects have the right to:
- (a) obtain access to information concerning the processing of their personal data;
- (b) require the Company to clarify, block, or destroy personal data if the data is incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary for the stated purpose of processing;
- (c) challenge in court any unlawful acts or omissions by the Company in processing and protecting personal data and take other measures provided by law to protect their rights.
7.2. A personal data subject has the right to obtain the following information concerning the processing of their personal data:
- (a) the legal grounds and purposes for processing personal data;
- (b) the personal data processing methods used by the Company;
- (c) the Company’s name and location and information about persons who have access to personal data or to whom personal data may be disclosed under an agreement with the Company or under federal law;
- (d) the personal data being processed that relates to the relevant personal data subject and its source, unless another procedure for providing such data is established by federal law;
- (e) the periods for processing personal data, including its retention periods;
- (f) the procedure by which the personal data subject may exercise the rights provided by personal data law;
- (g) information about cross-border data transfers;
- (h) the names or surnames, given names, patronymics, and addresses of persons processing personal data on the Company’s instructions, if processing has been or will be entrusted to such persons;
- (i) information about the methods used by the Company to implement measures aimed at ensuring performance of the Company’s duties as a personal data operator;
- (j) other information provided by the Personal Data Law or other federal laws.
7.3. Information about personal data processing is provided to the personal data subject or their representative upon receipt of a request from the subject or representative. The request must state the number of the principal identity document of the personal data subject or their representative, the date of issue and issuing authority, information confirming the personal data subject’s participation in relations with the Company, or other information confirming that the Company processes the personal data. The request must also be signed by the personal data subject or their representative.
7.4. If a person contacting the Company with an inquiry or request is not authorized to receive information relating to personal data, the Company will refuse to disclose that information. The person who submitted the request will be notified of the refusal.
7.5. Responses to inquiries and requests for information disclosing details of personal data processing are sent within 10 (ten) business days after receipt by the Company.
7.6. If the Company receives an inquiry containing information that the Company is processing inaccurate personal data or processing personal data unlawfully, the person responsible for reviewing the request will immediately arrange for the relevant personal data to be blocked for the duration of the review. If inaccurate personal data processing is reported, the data will be blocked provided that doing so does not violate the rights and legitimate interests of the personal data subject or third parties.
7.7. If the inaccuracy of the personal data processed is confirmed on the basis of information provided by the personal data subject, their representative, or the authority responsible for protecting personal data subjects’ rights, the personal data will be corrected within 7 (seven) business days after that information is provided. If the data cannot be corrected within that period, it will be corrected as soon as reasonably possible. The data will be unblocked after it has been corrected.
7.8. If a review identifies unlawful personal data processing by the Company, the violation will be remedied within no more than 3 (three) business days after the unlawful processing is confirmed. If lawful processing cannot be ensured, the data will be destroyed within no more than 10 (ten) business days after the unlawful processing is identified. The personal data subject or their representative will be notified immediately that the violation has been remedied or the personal data destroyed. If the inquiry or request was submitted by the authority responsible for protecting personal data subjects’ rights, that authority will also be notified.
7.9. If a personal data subject withdraws consent to the processing of their data, the Company’s employees must stop processing and destroy the personal data within 10 (ten) business days. This clause does not apply if otherwise provided by an agreement to which the personal data subject is a party or beneficiary or by applicable law.
7.10. A personal data subject has the right to ask the Company not to process their personal data for marketing purposes. Such processing can be prevented by selecting the relevant options in the forms used to collect data. The subject may also exercise this right at any time by contacting the Company at info@itimperial.group.
8. Personal Data Processing Periods
8.1. As a general rule, personal data processing periods are determined by the consents provided to the Company by personal data subjects. In all cases, processing must cease once the purposes for processing the relevant data have been achieved or the grounds for personal data processing have ceased to apply, including where previously granted consent to personal data processing is withdrawn.
8.2. Personal data of prospective, current, and former Customers is processed for maintaining business contacts, sending advertising and informational communications, and evaluating the effectiveness of marketing campaigns until the Company ceases to exist as a legal entity or for 10 (ten) years from the date the relevant data was provided to the Company, whichever occurs first.
8.3. Applicants’ personal data is processed for 10 (ten) years from the date the Applicant provides their personal data or résumé to the Company.
9. CHANGES TO THIS POLICY
The Company may amend this Policy from time to time. Amendments to the Policy do not have retroactive effect. Information about the date of the latest amendment is displayed at the beginning of this Policy.
10. Contact Details
Questions concerning the application of this Policy or the Company’s personal data processing procedures may be sent to info@itimperial.group.