POLICY
of Individual Entrepreneur Vyalov Sergei Sergeevich regarding the processing of personal data and information on the implemented requirements for the protection of personal data
Moscow
“01” January 2023
1. General provisions
1.1 “Policy of Individual Entrepreneur Vyalov S.S. regarding the processing of personal data and information on the implemented requirements for the protection of personal data” (hereinafter referred to as the “Policy”) defines the general principles and procedure for processing personal data and measures to ensure their security when using the websites https://www.vyalov.com, https://vyalov.ru, https://gastro.getcourse.ru, and during the execution of the Public Offer posted on the website https://gastro.getcourse.ru for the paid provision of services for additional adult education.
The purpose of the Policy is to ensure the protection of human and civil rights and freedoms when processing their personal data, including the protection of rights to privacy, personal and family secrets, clear and strict compliance with the requirements of Russian legislation in the field of personal data (hereinafter referred to as the legislation).
1.2 The Policy is developed in accordance with the provisions of Federal Law No. 152-FZ of July 27, 2006 “On Personal Data”, other legislative and regulatory legal acts defining the procedure for working with personal data and requirements for ensuring their security.
1.3 The following terms and definitions are used in the Policy:
automated processing of personal data — processing of personal data using computer technology;
personal data database — an organized set of personal data, regardless of the type of material information carrier and the means used for its processing (including electronic databases);
blocking of personal data — temporary cessation of processing of personal data (except for cases where processing is necessary to clarify personal data);
data center — a specialized organization providing services for the placement of server and network equipment, rental of servers (including virtual ones), as well as for connection to the Internet;
counterparty — a party to an agreement with Individual Entrepreneur Vyalov S.S., who is not an employee of Individual Entrepreneur Vyalov S.S.;
confidentiality of personal data — the obligation of persons who have gained access to personal data not to disclose them to third parties and not to distribute personal data without the consent of the personal data subject, unless otherwise provided by law;
depersonalization of personal data — actions as a result of which it becomes impossible to determine the belonging of personal data to a specific personal data subject without the use of additional information;
processing of personal data — any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data;
publicly available personal data — personal data to which an unlimited number of persons have access with the consent of the personal data subject or at their request, as well as data that are subject to mandatory disclosure or publication in accordance with the requirements of the law;
operator — a state body, municipal body, legal entity or individual that independently or jointly with other persons organizes and (or) carries out the processing of personal data, and also determines the purposes of processing personal data, the composition of personal data to be processed, actions (operations) performed with personal data. In the Policy, the operator means Individual Entrepreneur Vyalov S.S.;
personal data — any information relating to a directly or indirectly identified or identifiable individual (personal data subject);
provision of personal data — actions aimed at disclosing personal data to a specific person or a specific circle of persons;
distribution of personal data — actions aimed at disclosing personal data to an unlimited number of persons;
personal data subject — an individual to whom the personal data relates, using the websites https://www.vyalov.com, https://vyalov.ru, https://gastro.getcourse.ru;
cross-border transfer of personal data — transfer of personal data to the territory of a foreign state to a foreign state authority, foreign individual or foreign legal entity;
destruction of personal data — actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which the material carriers of personal data are destroyed.
2 Status of Individual Entrepreneur Vyalov S.S. and categories of subjects whose personal data is processed by the Operator
Individual Entrepreneur Vyalov S.S. is an operator of personal data in relation to the personal data of the following individuals:
- end consumers of services provided by Individual Entrepreneur Vyalov S.S. for additional adult education, who have provided their personal data for processing and other persons who have applied to Individual Entrepreneur Vyalov S.S. in any available way and provided their personal data in connection with the application (hereinafter referred to as Clients);
- counterparties — individuals and individual entrepreneurs, representatives of counterparties of Individual Entrepreneur Vyalov S.S. — legal entities and individual entrepreneurs, including employees, owners, including beneficial owners, representatives acting on the basis of a power of attorney and other representatives of counterparties with whom Individual Entrepreneur Vyalov S.S. has contractual relations or with whom Individual Entrepreneur Vyalov S.S. intends to enter into contractual relations, or who intend to enter into contractual relations with Individual Entrepreneur Vyalov S.S.
- users of the websites of Individual Entrepreneur Vyalov S.S. https://www.vyalov.com, https://vyalov.ru, https://gastro.getcourse.ru who have filled out web forms of registration and (or) appeals on the pages of the website (hereinafter referred to as Website Users);
- anonymous (unauthorized) visitors to the websites of Individual Entrepreneur Vyalov S.S. on the Internet https://www.vyalov.com, https://vyalov.ru, https://gastro.getcourse.ru; (hereinafter referred to as Website Visitors).
A personal data subject may simultaneously belong to several categories listed above, for example, be a Client, Website User and Website Visitor, etc.
3 Principles of processing personal data
The processing of personal data by Individual Entrepreneur Vyalov S.S. is carried out in accordance with the following principles:
3.1 Legality and fair basis for the processing of personal data. Individual Entrepreneur Vyalov S.S. takes all necessary measures to comply with the requirements of the law, does not process personal data in cases where this is not permitted by law, does not use personal data to the detriment of subjects.
3.2 Limitation of the processing of personal data to the achievement of specific, predetermined and lawful purposes. The purposes of processing personal data by Individual Entrepreneur Vyalov S.S. are:
- in relation to Clients — registration of a personal account on the website https://gastro.getcourse.ru, fulfillment of obligations under the Public Offer posted on the website https://gastro.getcourse.ru, sending informational and marketing materials (with the consent of the Subject), preparation of responses to appeals and requests;
- in relation to Representatives of counterparties — compliance with the norms of the Civil Code of the Russian Federation governing contractual work, conclusion and execution of contracts with counterparties;
- in relation to Website Users — providing the opportunity to use information located on the website https://gastro.getcourse.ru and visible only after registration, feedback forms with Individual Entrepreneur Vyalov S.S.
- in relation to Website Visitors — informing about the services provided by Individual Entrepreneur Vyalov S.S. and services provided using the websites https://www.vyalov.com, https://vyalov.ru, https://gastro.getcourse.ru.
3.3 Processing only those personal data that meet the previously declared purposes of their processing. Compliance of the content and volume of processed personal data with the stated purposes of processing. Prevention of processing of personal data that is incompatible with the purposes of collecting personal data, as well as excessive in relation to the stated purposes of their processing. Individual Entrepreneur Vyalov S.S. does not collect or process personal data that is not required to achieve the purposes specified in clause 3.2 of the Policy, does not use personal data of subjects for any purposes other than those indicated above.
3.4 Prevention of combining databases containing personal data, the processing of which is carried out for purposes that are incompatible with each other.
3.5 Ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of processing personal data. Individual Entrepreneur Vyalov S.S. takes all reasonable measures to maintain the relevance of the processed personal data, including, but not limited to, the implementation of the right of each subject to access their personal data and require Individual Entrepreneur Vyalov S.S. to clarify, block or destroy them if the personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purposes of processing.
3.6 Storage of personal data in a form that allows identifying the subject of personal data, no longer than required by the purposes of processing personal data, unless the storage period for personal data is established by law, an agreement to which the subject of personal data is a party.
3.7 Destruction or depersonalization of personal data upon achieving the stated purposes of their processing or in case of loss of the need to achieve these goals, if Individual Entrepreneur Vyalov S.S. is unable to eliminate the violations of the established procedure for processing personal data permitted by law, withdrawal of consent to processing by the personal data subject, unless otherwise provided by law or agreements with the subjects.
4 Conditions of processing personal data
4.1 The processing of personal data by Individual Entrepreneur Vyalov S.S. is allowed in the following cases:
1 If there is consent of the personal data subject to the processing of his personal data.
2 The processing of personal data is necessary for the implementation and performance of the functions, powers and duties imposed on Individual Entrepreneur Vyalov S.S. by law.
3 For the execution of a contract to which the personal data subject is a party, for the conclusion of a contract on the initiative of the personal data subject. Such contracts include, but are not limited to:
4 Public Offer agreements concluded by Individual Entrepreneur Vyalov S.S. with clients when selling services for additional adult education via the Internet;
5 Civil law contracts with counterparties who are individuals and individual entrepreneurs.
6 The processing of personal data is necessary for the exercise of the rights and legitimate interests of Individual Entrepreneur Vyalov S.S. or third parties or for the achievement of socially significant goals, provided that the rights and freedoms of personal data subjects are not violated.
7 The processing of personal data is carried out for statistical or other research purposes, provided that the personal data is necessarily depersonalized.
8 Access of an unlimited number of persons to personal data is provided by the personal data subject by giving consent to the processing of personal data permitted by the subject for distribution.
4.2 Individual Entrepreneur Vyalov S.S. does not disclose to third parties and does not distribute personal data without the consent of the personal data subject, unless otherwise provided by law, an agreement with the personal data subject, or indicated in the consent received from him for the processing of personal data.
4.3 Individual Entrepreneur Vyalov S.S. does not process personal data relating to special categories and concerning racial and ethnic origin, political views, religious or philosophical beliefs, health status, intimate life, membership in public associations or their trade union activities, except in cases expressly provided for by law.
4.4. Individual Entrepreneur Vyalov S.S. does not carry out cross-border transfer of personal data.
4.5 Individual Entrepreneur Vyalov S.S. does not make decisions that give rise to legal consequences in relation to the personal data subject or otherwise affect the rights and legitimate interests of the subject, based solely on automated processing of personal data. Data that has legal consequences or affects the rights and legitimate interests of the subject is subject to verification by Individual Entrepreneur Vyalov S.S. before its use.
5 Methods of processing personal data
5.1 Individual Entrepreneur Vyalov S.S. carries out the processing of personal data using automation tools.
5.2 The Policy applies in full to the processing of personal data using automation tools.
6 Confidentiality of personal data
6.1 Individual Entrepreneur Vyalov S.S. ensures the confidentiality of personal data. Ensuring confidentiality is not required in relation to:
- personal data after their depersonalization;
- publicly available personal data.
6.2 Individual Entrepreneur Vyalov S.S. has the right, with the consent of the subject, to entrust the processing of personal data to another person, unless otherwise provided by law, on the basis of an agreement concluded with this person, which provides as an essential condition the obligation of the person processing personal data on behalf of Individual Entrepreneur Vyalov S.S. to comply with the principles and rules of personal data processing provided for by law. The volume of personal data transferred to another person for processing and the number of processing methods used by this person must be minimally necessary for the performance of his obligations to Individual Entrepreneur Vyalov S.S. The instruction of Individual Entrepreneur Vyalov S.S. must define the list of actions (operations) with personal data that will be performed by the person processing personal data, and the purposes of processing, the obligation of such person to maintain the confidentiality of personal data and ensure the security of personal data during their processing must be established, and the requirements for the protection of processed personal data in accordance with Article 19 of the Federal Law of July 27, 2006 No. 152-FZ “On Personal Data” must be indicated.
6.3 Individual Entrepreneur Vyalov S.S. has the right to place its personal data information systems in a data center or cloud computing infrastructure. If the agreement with the data center or cloud provider does not allow access of the data center (cloud provider) personnel to the personal data information system of Individual Entrepreneur Vyalov S.S. and the agreement provides for the obligation of the data center (cloud provider) to control compliance with this prohibition, such placement is not considered by Individual Entrepreneur Vyalov S.S. as entrusting the processing of personal data to the data center (cloud provider) and does not require the consent of personal data subjects.
6.4 If Individual Entrepreneur Vyalov S.S. entrusts the processing of personal data to another person, Individual Entrepreneur Vyalov S.S. is responsible to the personal data subject for the actions of this person. The person processing personal data on behalf of Individual Entrepreneur Vyalov S.S. is liable to Individual Entrepreneur Vyalov S.S.
7 Consent of the personal data subject to the processing of their personal data
7.1 The personal data subject makes a decision on providing his personal data to Individual Entrepreneur Vyalov S.S. and gives consent to their processing freely, by his own will and in his own interest. Consent to the processing of personal data must be specific, informed and conscious and can be provided by the subject in any form that allows confirming the fact of its receipt, unless otherwise established by law, including by accepting the Public Offer posted on the website https://gastro.getcourse.ru for the paid provision of services for additional adult education.
7.2 In case of receipt of personal data by Individual Entrepreneur Vyalov S.S. from a counterparty on the basis of an agreement concluded between them, the responsibility for the legality and reliability of personal data, as well as for obtaining the consent of subjects (their representatives) for the transfer of their personal data to Individual Entrepreneur Vyalov S.S. lies with the counterparty transferring the personal data, which is fixed in the text of the agreement with the counterparty.
7.3 Individual Entrepreneur Vyalov S.S., having received personal data from a counterparty, does not undertake the obligation to inform the subjects (their representatives) whose personal data has been transferred to him about the start of processing personal data, believing that they have been informed about this by the counterparty who transferred the personal data when concluding an agreement with the personal data subject and/or when obtaining consent for such transfer. This obligation of the counterparty is included in the agreement between him and Individual Entrepreneur Vyalov S.S.
7.4 The Client’s consent is given by checking the box in the web form when registering on the website https://gastro.getcourse.ru, when filling out a questionnaire, as well as in the form of conclusive actions when applying to Individual Entrepreneur Vyalov S.S. in any way and providing personal data necessary to consider the application.
7.5 Consent of Website Users to the processing of their personal data is given by checking the corresponding box in the web form on the website, which provides for the entry of personal data, or when accepting the Public Offer, which provides for the processing of personal data, as well as when indicating personal data in requests sent to Individual Entrepreneur Vyalov S.S. in written and electronic form, etc.
7.6 If it is necessary to obtain the subject’s consent to the processing of personal data in writing, such consent can be obtained in the form of an electronic document signed with an electronic signature in accordance with the requirements established by the legislation on electronic signatures.
7.7 The consent of subjects to provide their personal data is not required when Individual Entrepreneur Vyalov S.S. receives, within the established powers, motivated requests from the prosecutor’s office, law enforcement agencies, investigative and inquiry agencies, security agencies, and other authorities authorized to request information in accordance with the competence provided for by law.
A motivated request must include an indication of the purpose of the request, a reference to the legal grounds for the request, including those confirming the powers of the body that sent the request, as well as a list of the requested information.
7.8 In case of receipt of requests from organizations that do not have the appropriate powers, Individual Entrepreneur Vyalov S.S. is obliged to obtain the subject’s consent to provide his personal data and warn the persons receiving the personal data that this data can be used only for the purposes for which they were communicated, and also require these persons to confirm that this rule will be (was) observed.
7.9 Consent to the processing of personal data, the processing of which is not established by the requirements of the legislation of the Russian Federation or is not required for the execution of an agreement with Individual Entrepreneur Vyalov S.S., to which the personal data subject is a party, may be withdrawn by the personal data subject.
7.10 In all cases, the obligation to provide proof of obtaining the consent of the personal data subject to the processing of his personal data or proof of the existence of the grounds specified in the Federal Law of July 27, 2006 No. 152-FZ “On Personal Data” is assigned to Individual Entrepreneur Vyalov S.S.
8 Rights of personal data subjects
8.1 The personal data subject has the right to receive information relating to the processing of his personal data. The personal data subject has the right to require Individual Entrepreneur Vyalov S.S. to clarify his personal data, block or destroy them if the personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated purpose of processing, as well as take measures provided by law to protect his rights.
8.2 If the personal data subject believes that Individual Entrepreneur Vyalov S.S. processes his personal data in violation of the requirements of the law or otherwise violates his rights and freedoms, the personal data subject has the right to appeal the actions or inaction of Individual Entrepreneur Vyalov S.S. to the authorized body for the protection of the rights of personal data subjects or in court.
8.3 The personal data subject has the right to protect his rights and legitimate interests, including compensation for losses and (or) compensation for moral damage in court.
9 Information on the implemented requirements for the protection of personal data
9.1 The protection of personal data processed by Individual Entrepreneur Vyalov S.S. is ensured by the implementation of legal, organizational and technical measures necessary and sufficient to ensure the requirements of the legislation in the field of personal data protection.
9.2 Legal measures include:
- development of local acts of Individual Entrepreneur Vyalov S.S. implementing the requirements of the legislation, including the Policy regarding the processing of personal data;
- refusal of any methods of processing personal data that do not correspond to the purposes previously determined by Individual Entrepreneur Vyalov S.S.
9.3 Organizational measures include:
- regulation of personal data processing processes;
- determination of the type of threats to the security of personal data relevant to personal data information systems, taking into account the assessment of possible harm to personal data subjects that may be caused in case of violation of security requirements, determination of the level of personal data protection and requirements for the protection of personal data during their processing in information systems, the implementation of which ensures the established levels of personal data protection;
- placement of technical means of personal data processing within the protected territory of the data center;
9.4 Technical measures include:
- development based on the threat model of a personal data protection system for the levels of personal data protection established by the Government of the Russian Federation when processing them in information systems;
- assessment of the effectiveness of measures taken to ensure the security of personal data;
- protection of personal data transmitted by e-mail by using password-protected archives that meet the requirements of the password protection policy, containing personal data (files in zip, rar formats, etc.)
10 Final provisions
10.1 Other obligations and rights of Individual Entrepreneur Vyalov S.S. as an operator of personal data and a person organizing their processing on behalf of other operators are determined by the legislation of the Russian Federation in the field of personal data.
10.2 The Personal Data Processing Policy may be supplemented/changed by Individual Entrepreneur Vyalov S.S. at any time without sending any special notification to the Subject. The new version of the Personal Data Processing Policy comes into force from the moment it is posted on the Website https://gastro.getcourse.ru/. Regular familiarization with the current version of the Personal Data Processing Policy is the responsibility of the Subject.
10.3 Use of the functionality of the Website https://gastro.getcourse.ru/ after the new version of the Policy comes into force means the Subject’s agreement with it and the application of the provisions of the new version in full to him. The Subject is not allowed to use the functionality of the Website https://gastro.getcourse.ru/ if the Subject disagrees with the new version of the Policy in whole or in part.
10.4 The current version of the Policy was developed by the Operator on the basis of Federal Law No. 152-FZ of July 27, 2006 (as amended on July 29, 2017) “On Personal Data”.
11 Details
Individual Entrepreneur Vyalov Sergey Sergeevich OGRNIP 320774600155805,
INN 507301429625
109145, Moscow, Zhulebinsky Boulevard, 1, P.O. Box 9 Correspondence address: gastro@vyalov.com Account 40802810500001443279
in JSC “Tinkoff Bank” Cor. account 30101810145250000974
BIC 044525974
Personal data operator registration number 77-22-117486 (Order No. 258 dated 07.11.2022)