Website policy regarding the processing of personal data
1. General provisions
1.1 This policy for on processing of personal data was elaborated in accordance with requirements of the Federal Law No. 152-FZ dated 27.07.2006. «On Personal Data» (hereinafter referred to as the Law on personal data) and defines the procedure for processing personal data and measures to ensure safety of personal data taken by AO KMZ (hereinafter referred to as the Operator).
1.2 The Operator defines observance of the rights and freedoms of men and citizens when processing their personal data, including the protection of rights to privacy, personal and family secrets, as its most important goal and condition when carrying out its business activities.
1.3 This Operator policy regarding the processing of personal data (hereinafter referred to as the Policy) applies to all information on visitors of the https://kmz-ural.com/ website that the Operator may obtain.
2. Basic concepts used in the Policy
2.1 Automated processing of personal data means the processing of personal data by means of computers.
2.2 Blocking of personal data means a temporary cessation of processing of personal data (except for cases when such processing is necessary to clarify any personal data).
2.3 Website means a set of graphic and information materials, as well as computer programs and databases that ensure their availability on the Internet at the following network address: https://kmz-ural.com/.
2.4 Personal data information system means a set of personal data contained in databases, as well as information technology and hardware that ensure their processing.
2.5 Depersonalization of personal data means actions making it impossible to determine without the use of additional information the ownership of personal data by a specific User or other personal data subject.
2.6 Processing of personal data means any action (operation) or set of actions (operations) performed with or without automation tools in relation to personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data.
2.7 Operator means a government agency, municipal agency, legal or physical person that independently or jointly with other persons organizes and/or carries out the processing of personal data, as well as determines the purposes of processing personal data, composition of personal data subject to processing, and actions (operations) performed with personal data.
2.8 Personal data means any information related directly or indirectly to a specific or determinable User of the https://kmz-ural.com/ website.
2.9 User means any visitor to the https://kmz-ural.com/ website.
2.10 Provision of personal data means actions aimed at disclosing personal data to a specific person or a specific group of persons.
2.11 Dissemination of personal data means any actions aimed at disclosing personal data to an indefinite group of persons (transfer of personal data) or familiarizing an unlimited number of persons with personal data, including disclosure of personal data in the media, its posting on information and telecommunications networks or providing access to personal data in any other way.
2.12 Cross-border transfer of personal data means transfer of personal data to the territory of a foreign state for the benefit of a foreign government authority, foreign individual or foreign legal entity.
2.13 Destruction of personal data means any actions that result in personal data being irrevocably destroyed, making subsequent recovery of the content of personal data in the personal data information system impossible and/or the destruction of tangible media that holds the personal data.
3. Main rights and obligations of the Operator
3.1 The Operator is entitled to:
— receive reliable information containing personal data from the personal data subject;
— in the event that the personal data subject revokes consent to the processing of personal data, or sends a request to stop the processing of personal data, the Operator has the right to continue processing personal data without the consent of the personal data subject when there are grounds defined in the Law on personal data;
— independently determine the composition and list of measures necessary and sufficient to ensure the fulfillment of obligations stipulated by the Law on personal data and regulations adopted under it, unless the Law on personal data or other federal laws provide otherwise.
3.2 The Operator is obliged to:
— provide the personal data subject, at his request, with information on the processing of the subject's personal data;
— organize the processing of personal data in the manner established by the current legislation of the Russian Federation;
— respond to inquiries and requests from personal data subjects and their legal representatives in accordance with the requirements of the Law on personal data;
— convey to the privacy authority, upon its request, the necessary information within 10 days after receiving the corresponding request;
— publish or otherwise provide unlimited access to this Policy on processing of personal data;
— take legal, organizational and technical measures to protect personal data against unauthorized or accidental access, destruction, modification, blocking, copying, provision, distribution or other illegal actions in relation to it;
— stop the transfer of (distribution, provision, access to) personal data, its processing, and destroy the personal data in the manner and cases stipulated by the Law on personal data;
— fulfill other obligations stipulated by the Law on personal data.
4. Basic rights and obligations of personal data subjects
4.1 Personal data subjects are entitled to:
— receive information regarding the processing of their personal data. The list of information and the procedure for obtaining it are established by the Law on personal data;
— to demand from the Operator to correct, block or destroy the personal data if it is incomplete, outdated, inaccurate, was illegally obtained or is not necessary for the stated purpose of data processing, as well as to take measures provided by law to protect the subject’s rights;
— to require prior consent to processing of personal data for the purpose of promoting goods, works and services on the market;
— to revoke consent to processing of personal data, as well as to request to stop the processing of personal data;
— to exercise other rights provided for by the legislation of the Russian Federation.
4.2 Subjects of personal data are obliged to:
— provide the Operator with reliable data about themselves;
— notify the Operator about the need to correct (update, change) their personal data.
4.3 Persons providing the Operator with inaccurate information on themselves or on another subject of personal data without the consent of the latter, are liable in accordance with the legislation of the Russian Federation.
5. Principles of personal data processing
5.1 Personal data is processed on a legal and fair basis.
5.2 The processing of personal data is limited to achieving specific, predetermined and legitimate purposes. It is not allowed to process personal data in a way that is incompatible with the purposes for which the personal data is collected.
5.3 It is not allowed to combine databases containing personal data, which is processed for purposes that are incompatible with each other.
5.4 Only personal data that conforms with the purposes of its processing may be processed.
5.5 The content and volume of the processed personal data are to correspond to the stated purposes of processing. It is not allowed to process personal data in excess of the stated purposes of its processing.
5.6 When processing personal data, its accuracy, sufficiency, and, where necessary, relevance in relation to the purposes of processing are to be ensured. The Operator is to take the necessary measures and/or ensure their adoption to delete or clarify any incomplete or inaccurate data.
5.7 Personal data shall be kept in a form that allows the subject of personal data to be identified, and for no longer than is required for the purposes of processing personal data, unless the personal data safekeeping period is established by a federal law or an agreement to which the subject of personal data is a party, beneficiary or guarantor. The processed personal data is to be destroyed or depersonalized upon achieving the purpose of its processing or in the event of loss of the need to achieve such a purpose, unless the federal legislation provides otherwise.
6. The Operator may process the following personal data of the User
6.1 Last name, first name, patronymic;
6.2 E-mail address;
6.3 Phone numbers;
6.4 CV for a job application;
6.5 Other information entered in the «Comments» field of the «Contact us» section;
6.6 The website also collects and processes depersonalized data on its visitors (e.g. cookies) using Internet statistics services (Yandex Metrica, Google Analytics, etc.);
6.7 The above data are hereinafter referred to as the Personal data.
7. Purposes of personal data processing
7.1. Purpose of processing the User's personal data:
— informing about goods and services and carrying out activities to promote them;
— collecting and processing of new orders, building of contractual relations;
— considering the possibility of further interaction within a contractual context;
— reviewing CVs and selecting candidates for vacant positions;
— requesting the User by e-mail to clarify order details.
7.2. The Operator is also entitled to send the User notifications about new products and services, special offers and various events. The User can always opt out of receiving such informational messages by sending an email to the Operator at vacancy@kmz-ural.com with the subject line «Opt-out of notifications about new products and services and special offers».
7.3. Depersonalized User data collected using Internet statistics services is used to collect information about the actions of Users on the site, improve the quality of the site and its content.
8. Terms of personal data processing
Personal data is processed subject to consent of the subject of personal data to such processing of his personal data.
9. Legal grounds for personal data processing
9.1 The Operator processes the User's personal data only if they are filled in and/or sent by the User independently through special forms posted on the https://kmz-ural.com/ website. By filling in the relevant forms and/or sending his personal data to the Operator, the User expresses his consent to this Policy.
9.2 The Operator processes depersonalized data of the User if this is permitted in the User's browser settings (i.e. the storage of cookies and the use of JavaScript technology are enabled).
10. Procedure for collecting, safekeeping, transferring and other types of processing of personal data
10. Procedure for collecting, safekeeping, transferring and other types of processing of personal data
The safety of personal data processed by the Operator is ensured by implementing legal, organizational and technical measures necessary to fully comply with the requirements of the current legislation in the field of personal data protection.
10.1 The Operator ensures the safety and confidentiality of personal data and takes all possible measures to prevent unauthorized persons from accessing personal data.
10.2 The User's personal data will never, under any circumstances, be transferred to third parties, except in cases related to compliance with current legislation.
10.3 In the event of detecting any inaccuracies in the personal data, the User can update his personal data independently by sending a notification to the Operator's e-mail vacancy@kmz-ural.com with an «Updating personal data» subject line.
10.4 The time period for processing of personal data is unlimited. The User may at any time revoke his consent to the processing of personal data by sending a notification to the Operator's e-mail vacancy@kmz-ural.com with a «Revocation of consent to processing of personal data» subject line.
11. Cross-border transfer of personal data
11.1 Before commencing any cross-border transfer of personal data, the Operator is to ensure that the foreign state to which the personal data is to be transferred ensures reliable protection of the rights of personal data subjects.
11.2 Before submitting the above notification, the Operator is to obtain relevant information from the foreign authorities, foreign individuals, or foreign legal entities to which the cross-border transfer of personal data is planned.
12. Final provisions
12.1 The User may obtain any clarifications on issues regarding the processing of his personal data by contacting the Operator at vacancy@kmz-ural.com.
12.2 This document will reflect any changes to the Operator's personal data processing policy that may be introduced. This Policy has no expiration period and remains valid until it is replaced by a new version.
12.3 The Policy's most current version is posted at https://kmz-ural.com/