Personal Data Processing Policy of SOHOWARE LLC

This policy describes the procedure for processing and protecting personal data at SOHOWARE LLC.

Engineers discussing a project drawing

Translation status

This English text is provided for information only. The Russian original published on sohoware.ru has priority for legal interpretation.

Operator

SOHOWARE LLC, Saint Petersburg.

Company details

TIN 7802943813, KPP 780201001, OGRN 1237800095895.

How to contact us

For questions about personal data processing, write to or use the contacts page.

Saint Petersburg

Personal Data Processing Policy of SOHOWARE LLC

This Personal Data Processing Policy (the Policy) is prepared under the Constitution of the Russian Federation, Convention ETS No. 108, the Civil Code of the Russian Federation, Federal Law No. 152-FZ on Personal Data, Federal Law No. 149-FZ on Information, Information Technologies and Information Protection, Federal Law No. 126-FZ on Communications, and other applicable Russian regulations.

This Policy defines the procedure for processing personal data and the safeguards used by SOHOWARE LLC (the Operator).

1. Definitions

Key terms used in this Policy:

Personal data
any information relating to an identified or identifiable individual (personal data subject), including biometric personal data where applicable.
Operator
a public authority, municipal authority, legal entity or individual that organizes and/or performs personal data processing and determines processing purposes, data scope and operations.
Personal data processing
any operation or set of operations performed with personal data, with or without automation, including collection, recording, organization, storage, updating, retrieval, use, transfer, anonymization, blocking, deletion and destruction.
Automated personal data processing
processing of personal data using computing tools.
Personal data dissemination
actions aimed at disclosing personal data to an indefinite circle of persons.
Personal data provision
actions aimed at disclosing personal data to a specific person or group of persons.
Personal data blocking
temporary suspension of personal data processing, except where processing is needed to clarify the data.
Personal data destruction
actions that make it impossible to restore personal data in an information system and/or destroy physical media containing personal data.
Personal data anonymization
actions that make it impossible to identify a specific data subject without additional information.
Cross-border transfer of personal data
transfer of personal data to a foreign state, foreign authority, foreign individual or foreign legal entity.
Personal data information system
a set of personal data contained in databases together with information technologies and technical tools used for processing.

2. Processing purposes and categories of personal data

2.1. Processing purposes

The Operator may process personal data to perform rights and obligations under contracts with data subjects, comply with laws and other regulations, and protect other lawful interests of the Operator or data subjects.

Personal data is collected and used only to the extent justified by processing purposes. Where practical and appropriate, the Operator seeks to use anonymized data.

Achievement of the processing purposes may be a basis for terminating processing.

The Operator may treat the following information as personal data, among other categories:

  • last name, first name and patronymic;
  • date of birth;
  • identity document details, issue date and issuing authority;
  • registered address;
  • email address;
  • phone number;
  • biometric personal data where applicable, such as a digital photographic image;
  • cookies, web beacons, pixel tags, IP addresses, browser information or other software data used for website or advertising access.

3. Principles and procedure for personal data processing

3.1. Processing principles

The Operator processes personal data based on the following principles:

  • lawfulness and fairness;
  • limiting processing to specific, pre-defined and lawful purposes;
  • preventing processing incompatible with collection purposes;
  • preventing database combination where processing purposes are incompatible;
  • processing only personal data relevant to processing purposes;
  • ensuring processed data scope and content match declared purposes;
  • preventing processing of personal data excessive in relation to the stated processing purposes;
  • ensuring accuracy, sufficiency and relevance of personal data in relation to processing purposes;
  • destroying or anonymizing personal data once processing purposes are achieved or no longer necessary, unless federal law provides otherwise.

3.2. Processing procedure

The personal data processing procedure applies to the purposes listed in section 2.1 of this Policy.

The data subject independently decides whether to provide personal data and gives the Operator consent freely, voluntarily and in their own interest.

The Operator ensures personal data protection and takes all possible measures to prevent unauthorized access.

The data subject's personal data is not transferred to third parties except where required by applicable law or where the data subject consents to transfer for performance of civil-law obligations.

Personal data processing by the Operator is carried out in compliance with principles and conditions established by Russian personal data legislation.

Operator employees who access personal data must not disclose it to third parties or otherwise distribute it without consent unless applicable Russian law directly provides otherwise.

The Operator may delegate personal data processing to another person with consent unless applicable Russian law provides otherwise.

The Operator processes the data subject's personal data from the moment consent is provided until it is withdrawn under Russian law or until the purposes for which the data was collected are achieved.

The Operator does not verify the accuracy of personal data or documents provided by the data subject, their representative, or third-party sources.

If inaccuracy or unlawful processing is confirmed, the Operator updates the personal data and terminates unlawful processing.

4. Confidentiality, delegated processing, storage and destruction

4.1. Personal data confidentiality

The Operator and other persons who access personal data must not disclose or disseminate it without the data subject's consent unless federal law provides otherwise.

The Operator may transfer personal data to inquiry, investigation or other authorized bodies on grounds provided by Russian law.

The Operator does not process special categories of personal data except biometric data where applicable.

4.2. Delegating processing to a third party

The Operator may delegate personal data processing to another person with the data subject's consent, unless federal law provides otherwise, under a contract. The processor must follow statutory personal data processing principles and rules, keep data confidential and ensure data security.

A person processing data on behalf of the Operator does not need to obtain separate consent from the data subject.

When the Operator delegates processing, the Operator remains responsible to the data subject for that person's actions, while the processor is responsible to the Operator.

4.3. Storage and destruction of personal data

The Operator ensures secure storage of personal data, including:

  • documents containing personal data are stored, assembled, recorded and used in a separate Operator archive;
  • personal data is stored in identifiable form no longer than required by processing purposes unless a longer period is set by law or contract.

Processed personal data is destroyed or anonymized when processing purposes are achieved or no longer relevant, unless federal law provides otherwise.

Personal data destruction is performed by a commission or authorized officer appointed by the Operator.

Personal data destruction is recorded by a relevant act confirming termination of processing.

5. Rights of the personal data subject

5.1. Consent to personal data processing

Consent to personal data processing must be specific, informed and conscious. Consent may be provided by the data subject or representative in any form that confirms its receipt unless federal law provides otherwise.

The data subject may withdraw consent. If consent is withdrawn, the Operator may continue processing without consent only where legal grounds under applicable law exist. The Operator bears the burden of proving consent or another legal basis.

5.2. Data subject rights

The data subject has the right to receive information from the Operator concerning processing of their personal data unless this right is limited by federal law.

The data subject may request clarification, blocking or destruction of personal data if it is incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the stated processing purpose.

Processing for direct marketing or political campaigning through communication channels is allowed only with prior consent of the data subject, unless the Operator proves that such consent was obtained.

Upon request, the Operator must immediately stop processing personal data for the above purposes.

Decisions based solely on automated processing that create legal consequences or otherwise affect rights and lawful interests are prohibited except as allowed by law or written consent.

The Operator responds to data subject requests within 10 business days from receipt.

6. Personal data security

The Operator protects personal data through legal, organizational and technical measures required by federal personal data protection legislation.

To prevent unauthorized access to personal data, the Operator applies organizational, technical and legal measures, including:

  • appointment of persons responsible for organizing personal data processing and protection;
  • limiting the persons who have access to personal data;
  • informing data subjects about federal legal requirements and this Policy;
  • organizing accounting, storage and handling of information media;
  • identifying personal data security threats and developing threat models;
  • developing a personal data protection system based on threat models;
  • checking readiness and effectiveness of information protection tools;
  • differentiating user access to information resources and processing tools;
  • logging and accounting for user actions in personal data information systems;
  • using antivirus and recovery tools for personal data protection systems;
  • using firewalls, intrusion detection, security analysis and cryptographic protection tools where necessary.

7. Cookie processing

By visiting the SOHOWARE LLC website, the personal data subject agrees that SOHOWARE LLC may use cookies and other data for subsequent processing by analytics systems such as Google Analytics, Yandex Metrica and others, and may transfer such data to third parties for research, work performance or service provision.

Cookies are small text files stored on a user device, such as a computer, laptop, tablet or phone, when visiting websites.

Depending on the browser and device, different sets of cookies may be used, including strictly necessary, operational, functional and analytical cookies.

When visiting the SOHOWARE LLC website, cookies may be used to:

  • ensure website operation and security;
  • improve website quality;
  • provide users with information about SOHOWARE LLC, its products and services;
  • improve products and/or services and develop new products and/or services.

The browser and/or device used by the data subject may allow cookies to be blocked, deleted or otherwise restricted.

To manage cookies through a browser or device, use the instructions provided by the browser developer or device manufacturer.

8. Final provisions

Other rights and obligations of the Operator as a personal data operator are determined by Russian personal data legislation.

Operator officials responsible for violating personal data processing and protection rules may bear material, disciplinary, administrative, civil or criminal liability as established by federal law.

This Policy may be changed by the Operator as legal requirements and organizational or technical protection measures evolve. Changes are made by replacing the published version with a new version or by publishing amendments.

Need to clarify data processing terms?