1. Terms and definitions1.1. For the purposes of this document, the following terms are used in the following meaning:
- personal data operator, hereinafter referred to as the "Operator" - Limited Liability Company "KABS Consulting", INN 1800011620, OGRN 1241800000342, independently or jointly with other persons organizing and (or) carrying out the processing of personal data, as well as determining the purposes of processing personal data, the composition of personal data subject to processing, actions (operations) performed with personal data;;
- personal data - any information related to a directly or indirectly determined or determinable individual (subject of personal data);
- personal data processing – any action (operation) or set of actions (operations) performed with the use of automation tools or without the use of such tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data;
- distribution of personal data – actions aimed at disclosing personal data to an indefinite number of persons;
- provision of personal data – actions aimed at disclosing personal data to a specific person or a specific number of persons;
- blocking of personal data – temporary cessation of processing of personal data (except in cases where processing is necessary to clarify personal data);
- destruction of personal data – actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which tangible media of personal data are destroyed;
- depersonalization of personal data – actions as a result of which it becomes impossible to determine the ownership of personal data by a specific subject of personal data without the use of additional information;
- automated processing of personal data – processing of personal data using computer technology;
- personal data information system (PDIS) – a set of personal data contained in databases and information technologies and technical means that ensure their processing.
1.2. The Regulation may use terms that are not defined in paragraph 1.1. of the Regulation. In this case, the interpretation of such a term is carried out in accordance with the text of the Regulation. In the absence of an unambiguous interpretation of a term in the text of the Regulation, one should be guided by the interpretation of the term determined: first of all - by the Operator's Regulations, secondly - by the legislation of the Russian Federation, then - by the established (generally used) one on the Internet.
2. General Provisions2.1. This Policy on the Processing of Personal Data (hereinafter referred to as the Policy) has been drawn up in accordance with paragraph 2 of Article 18.1 of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data" and is the fundamental internal regulatory document of the Operator, defining the key areas of its activities in the field of processing and protecting personal data of which the Operator is the operator.
2.2. The Policy has been developed in order to implement the requirements of the legislation in the field of processing and protecting personal data and is aimed at ensuring the protection of the rights and freedoms of an individual and citizen when processing his personal data by the Operator, including the protection of the rights to privacy, personal, family and medical secrets.
2.3. The provisions of the Policy apply to relations on the processing and protection of personal data received by the Operator both before and after the approval of the Policy, except for cases when, for legal, organizational or other reasons, the provisions of the Policy cannot be extended to relations on the processing and protection of personal data received before its approval.
2.4. The Operator processes personal data in connection with the performance by the Operator of the functions stipulated by its constituent documents and determined by:
2.4.1. Federal Law of 08.02.1998 N 14-FZ (as amended on 08.08.2024) "On Limited Liability Companies";
2.4.2. The Labor Code of the Russian Federation (in the current version);
2.4.3. The Tax Code of the Russian Federation (in the current version);
2.4.4. The Operator's Charter and internal regulations.
2.4.5. Federal Law of July 27, 2006 No. 152-FZ "On Personal Data";
2.4.6. RF Government Resolution of September 15, 2008 No. 687 "On Approval of the Regulation on the Peculiarities of Personal Data Processing Carried Out Without the Use of Automation Tools";
2.4.7. RF Government Resolution of November 1, 2012 No. 1119 "On Approval of Requirements for the Protection of Personal Data When Processing Them in Personal Data Information Systems";
2.4.8. other regulatory legal acts of the Russian Federation.
In addition, the Operator processes personal data in the course of labor and other directly related relationships in which the Operator acts as an employer (Chapter 14 of the RF Labor Code), in connection with the implementation by the Operator of its rights and obligations as a legal entity.
2.5. The Operator has the right to make changes to this Policy. When making changes, the date of the last update of the version is indicated in the heading of the Policy. The new version of the Policy comes into force from the moment of its adoption, unless otherwise provided by the new version of the Policy.
2.6. The current version is stored at the location of the Operator at the address: Udmurtia, Izhevsk, Rodnikovaya St., 72/1, apt. 6, the electronic version of the Policy is on the website at: http://cabsgroup.ru/officially#rec1059396086
3. Principles of Ensuring the Security of Personal Data3.1. The main objective of ensuring the security of personal data when processed by the Operator is to prevent unauthorized access to them by third parties, to prevent deliberate software, hardware and other influences with the aim of stealing personal data, destroying (destroying) or distorting them during processing.
3.2. To ensure the security of personal data, the Operator is guided by the following principles:
- legality - the protection of personal data is based on the provisions of regulatory legal acts and methodological documents of authorized state bodies in the field of processing and protecting personal data;
- systematicity: the processing of personal data by the Operator is carried out taking into account all interconnected, interacting and time-varying elements, conditions and factors that are significant for understanding and solving the problem of ensuring the security of personal data;
- comprehensiveness: the protection of personal data is built using the functional capabilities of information technologies implemented in the Operator's information systems and other security systems and tools available to the Operator;
- continuity: the protection of personal data is ensured at all stages of their processing and in all modes of operation of personal data processing systems, including during repair and maintenance work;
- timeliness: measures to ensure an adequate level of security of personal data are taken before they are processed;
- Continuity and continuity of improvement: modernization and expansion of measures and means of personal data protection is carried out based on the results of the analysis of the Operator's personal data processing practices, taking into account the identification of new methods and means of implementing threats to the security of personal data, domestic and foreign experience in the field of information protection;
- personal responsibility: responsibility for ensuring the security of personal data is assigned to Employees within the limits of their duties related to the processing and protection of personal data;
- minimization of access rights: access to personal data is provided to Employees only to the extent necessary to perform their job responsibilities;
- flexibility: ensuring the performance of personal data protection functions when the operating characteristics of the Operator's personal data information systems change, as well as the volume and composition of the personal data processed;
- specialization and professionalism: measures to ensure the security of personal data are implemented by Employees who have the necessary qualifications and experience;
- efficiency of personnel selection procedures: the Operator's personnel policy provides for careful selection of personnel and motivation of Employees, allowing to exclude or minimize the possibility of them violating the security of personal data;
- observability and transparency: measures to ensure the security of personal data must be planned so that the results of their application are clearly observable (transparent) and can be assessed by the persons exercising control;
- continuity of control and assessment: procedures for continuous control of the use of personal data processing and protection systems are established, and the results of the control are regularly analyzed.
3.3. The Operator does not process personal data in a way that is incompatible with the purposes of their collection. Unless otherwise provided by federal law, upon completion of the processing of personal data by the Operator, including upon achievement of the purposes of their processing or the loss of the need to achieve these purposes, the personal data processed by the Operator will be destroyed.
3.4. When processing personal data, their accuracy, sufficiency, and, if necessary, relevance in relation to the purposes of processing are ensured. The Operator takes the necessary measures to delete or clarify incomplete or inaccurate personal data.
4. Processing of personal data4.1. Receipt of personal data.
4.1.1. All PD should be obtained from the subject. If the subject's personal data can only be obtained from a third party, the subject must be notified of this or consent must be obtained from him in accordance with the form in Appendix 1,
4.1.2. The operator must inform the subject of the purposes, intended sources and methods of obtaining personal data, the nature of the personal data to be obtained, the list of actions with personal data, the period during which consent is valid and the procedure for its revocation, as well as the consequences of the subject's refusal to give written consent to receive them.
4.1.3. Documents containing personal data are created by:
a) copying original documents (passport, education document, TIN certificate, pension certificate, etc.);
b) entering information into accounting forms;
c) obtaining originals of the necessary documents (work record book, medical report, power of attorney, characteristics, etc.).
The procedure for access of the personal data subject to his personal data processed by the Operator is determined in accordance with the legislation and is defined by the internal regulatory documents of the Operator.
4.2. Processing of personal data.
4.2.1. Processing of personal data is carried out:
- with the consent of the personal data subject to the processing of his personal data;
- in cases where the processing of personal data is necessary for the implementation and performance of the functions, powers and duties imposed by the legislation of the Russian Federation;
- in cases where personal data is processed, access to which is provided to an unlimited number of persons by the personal data subject or at his request (hereinafter - personal data made publicly available by the personal data subject).
Access of persons to the personal data being processed is carried out in accordance with their job responsibilities and the requirements of the internal regulatory documents of the Operator.
Persons authorized to process personal data are familiarized with the organization's documents establishing the procedure for processing personal data, including documents establishing the rights and obligations of specific persons, against signature.
The Operator eliminates the identified violations of the legislation on the processing and protection of personal data.
4.2.2. Purposes of personal data processing:
- ensuring activities in accordance with the purposes specified in the Operator's Charter;
- implementation of labor relations;
- implementation of civil law relations.
4.2.3. Categories of personal data subjects.
The Operator processes personal data of the following subjects:
- individuals in labor relations with the Operator;
- individuals who are close relatives of the Operator's employees;
- individuals who have terminated their employment relations with the Operator,
- individuals who are applicants for the Operator's vacancies,
- individuals in civil law relations with the Operator;
- individuals intending to be in civil law relations with the Operator;
- individuals who have contacted the Operator for information.
4.2.4. Personal data processed by the Operator:
- obtained in the course of labor relations;
- obtained for the selection of candidates for employment by the Operator;
- received in the course of civil law relations;
- received when receiving information.
The full list of personal data is presented in the list of personal data approved by the General Director of the Operator.
4.2.5. Personal data is processed:
- using automation tools;
- without the use of automation tools.
4.3. Storage of personal data.
4.3.1. Personal data of subjects may be received, undergo further processing and transferred for storage both on paper and in electronic form.
4.3.2. Personal data recorded on paper are stored in locked cabinets.
4.3.3. Personal data of subjects processed using automation tools for different purposes are stored in different folders (tabs).
4.3.4. Storage and placement of documents containing personal data in open electronic directories (file sharing services) in the ISPD is not permitted.
4.3.5. Personal data shall be stored in a form that allows the identification of the subject of personal data for no longer than is required by the purposes of their processing, and they shall be destroyed upon achievement of the purposes of processing or in the event of loss of the need to achieve them.
4.4. Destruction of personal data.
4.4.1. Documents (media) containing personal data shall be destroyed by crushing (shredding). A shredder shall be used to destroy paper documents.
4.4.2. Personal data on electronic media shall be destroyed by erasing or formatting the media.
4.4.3. Destruction is performed by the commission. The fact of destruction of personal data is confirmed by a documented act on destruction of media signed by the members of the commission.
4.5. Transfer of personal data.
4.5.1. The Operator transfers personal data to third parties in the following cases:
- the subject has expressed their consent to such actions;
- the transfer is provided for by Russian or other applicable legislation within the framework of the procedure established by law.
4.5.2. The list of third parties to whom personal data is transferred:
- Pension Fund of the Russian Federation for accounting (on legal grounds);
- Tax authorities of the Russian Federation (on legal grounds);
- Social Insurance Fund of the Russian Federation (on legal grounds);
- Ministry of Justice of the Russian Federation (on legal grounds);
- Operator's counterparties (on the basis of an agreement);
- banks for accrual of salaries (on the basis of an agreement);
- judicial and law enforcement agencies in cases established by law;
- other authorized bodies on the grounds stipulated by the current legislation of the Russian Federation.
5. Protection of personal data5.1. In accordance with the requirements of the Operator's regulatory documents, a personal data protection system (PDPS) has been created, consisting of legal, organizational and technical protection subsystems.
5.2. The legal protection subsystem is a set of legal, organizational, administrative and regulatory documents ensuring the creation, functioning and improvement of the PDPS.
5.3. The organizational protection subsystem includes the organization of the PDPS management structure, the permit system, information protection when working with employees, partners and third parties, information protection in the open press, publishing and advertising activities, analytical work.
5.4. The technical protection subsystem includes a set of technical, software, software and hardware tools that ensure the protection of personal data.
5.5. The main measures to protect personal data used by the Operator are:
5.5.1. Appointment of a person responsible for personal data processing, who organizes the processing of personal data, training and instruction, internal control over compliance by the institution and its employees with personal data protection requirements.
5.5.2. Identification of current threats to the security of personal data when processing them in the ISPD and development of measures and activities to protect personal data.
5.5.3. Development of a policy regarding the processing of personal data.
5.5.4. Establishing rules for access to personal data processed in the ISPD, as well as ensuring the registration and accounting of all actions performed with personal data in the ISPD.
5.5.5. Establishing individual passwords for employee access to the information system in accordance with their work responsibilities.
5.5.6. Use of information security tools that have undergone the established procedure for assessing the conformity of information, accounting for machine-readable media containing personal data, ensuring their safety.
5.5.7. Certified anti-virus software with regularly updated databases.
5.5.8. Compliance with the conditions that ensure the safety of personal data and prevent unauthorized access to them, assessment of the effectiveness of measures taken and implemented to ensure the security of personal data.
5.5.9. Establishing rules for access to processed personal data, ensuring the registration and accounting of actions performed with personal data, as well as detecting facts of unauthorized access to personal data and taking measures.
5.5.10. Restoring personal data modified or destroyed due to unauthorized access to them.
5.5.11. Training the members of the Operator directly involved in the processing of personal data in the provisions of the legislation of the Russian Federation on personal data, including the requirements for the protection of personal data, documents defining the Operator's policy regarding the processing of personal data, local acts on issues of processing personal data.
5.5.12. Implementation of internal control and audit.
6. Basic rights of the personal data subject and obligations of the Operator6.1. Basic rights of the personal data subject.
The personal data subject has the right to receive information regarding the processing of his personal data, including the following:
- confirmation of the fact of personal data processing by the operator;
- legal grounds and purposes of personal data processing;
- purposes and methods of personal data processing used by the operator;
- name and location of the operator, information about persons (except for the operator's employees) who have access to personal data or to whom personal data may be disclosed on the basis of an agreement with the operator or on the basis of federal law;
- processed personal data related to the relevant personal data subject, the source of their receipt, unless another procedure for submitting such data is provided for by federal law;
- timeframes for processing personal data, including the timeframes for storing them;
- procedure for the exercise by the personal data subject of the rights stipulated by the Law "On Personal Data";
- information on the completed or proposed cross-border transfer of data;
- the name or surname, first name, patronymic and address of the person processing personal data on behalf of the operator, if the processing has been or will be entrusted to such person;
- other information stipulated by this Law or other federal laws.
The subject of personal data has the right to demand that the operator clarify his personal data, block or destroy them if the personal data are incomplete, outdated, inaccurate, illegally obtained or are not necessary for the stated purpose of processing, and also to take measures provided by law to protect his rights.
To exercise his rights, the subject of personal data may contact the Operator with a written request at the address: Udmurtia, Izhevsk, Rodnikovaya St., 72/1, Apt. 6, or by e-mail: main.office@cabsgroup.ru
6.2. Duties of the Operator.
The Operator is obliged to:
- provide information on the processing of his personal data when collecting personal data;
- in cases where personal data was not received from the personal data subject, notify the subject;
- in case of refusal to provide personal data, the subject is informed of the consequences of such refusal;
- publish or otherwise provide unrestricted access to the document defining its policy regarding the processing of personal data, to information on the implemented requirements for the protection of personal data;
- take the necessary legal, organizational and technical measures or ensure their adoption to protect personal data from unauthorized or accidental access to them, destruction, modification, blocking, copying, provision, distribution of personal data, as well as from other illegal actions in relation to personal data;
- respond to requests and appeals from personal data subjects, their representatives and the authorized body for the protection of the rights of personal data subjects.
7. Use of cookies7.1. The Operator uses cookies to improve the operation of the Site and provide Users with a more personalized experience. Cookies help the Operator analyze the use of the Site, remember Users' preferences and display relevant content and advertising.
7.2. Types of cookies used: session, persistent, analytical, marketing.
7.3. The User can manage cookies through their browser settings. Disabling some types of cookies may affect the functionality of the Site and the availability of some of its services.
7.4. By continuing to use the Site without changing the cookie settings in their browser, the User expresses their consent to the Operator's use of cookies in accordance with this Policy. The User can revoke their consent to the use of cookies at any time by changing the settings of their browser or through a special consent management tool on the Site (if available).