Policy on the Processing and Protection of Personal Data in Personal Data Databases Owned by the Seller
Contents
- General Terms and Scope
- List of Personal Data Databases
- Purpose of Personal Data Processing
- Procedure for Personal Data Processing: Obtaining Consent, Notification of Rights, and Actions Regarding Personal Data
- Location of Personal Data Databases
- Conditions for Disclosure of Personal Data to Third Parties
- Personal Data Protection: Protection Methods, Responsible Person, Employees with Access, and Data Retention Period
- Rights of the Personal Data Subject
- Procedure for Handling Requests from Personal Data Subjects
- State Registration of Personal Data Databases
1. General Terms and Scope
1.1. Definitions:
personal data database — a named collection of structured personal data in electronic form and/or in the form of personal data files;
responsible person — a designated individual who organizes activities related to personal data protection during processing in accordance with the law;
owner of the personal data database — an individual or legal entity that is granted the right to process personal data by law or by the consent of the data subject, determines the purpose of processing, the composition of the data, and the procedures for processing, unless otherwise provided by law;
State Register of Personal Data Databases — a unified state information system for collecting, storing, and processing information on registered personal data databases;
publicly available sources of personal data — directories, address books, registers, lists, catalogs, and other systematized collections of open information containing personal data published with the knowledge of the data subject. Social networks and internet resources where personal data is provided by the data subject are not considered publicly available sources unless explicitly stated otherwise;
consent of the personal data subject — any documented, voluntary expression of will by an individual granting permission for the processing of their personal data for a specified purpose;
anonymization of personal data — removal of information that allows identification of a person;
processing of personal data — any action or set of actions performed fully or partially in an information system and/or personal data files, including collection, registration, accumulation, storage, adaptation, modification, updating, use, dissemination (distribution, transfer), anonymization, and destruction of personal data;
personal data — information or a set of information about an individual who is identified or can be specifically identified;
processor of a personal data database — an individual or legal entity authorized by the owner or by law to process personal data;
personal data subject — an individual whose personal data is processed;
third party — any person other than the data subject, the data owner/processor, or authorized public authority to whom personal data may be transferred;
special categories of data — data revealing racial or ethnic origin, political, religious or philosophical beliefs, membership in political parties or trade unions, and data concerning health or sex life.
1.2. This Policy is mandatory for the responsible person and employees of the Seller who process or have access to personal data in the course of their duties.
2. List of Personal Data Databases
2.1. The Seller owns the following personal data databases:
- database of counterparties.
3. Purpose of Personal Data Processing
3.1. Personal data is processed to ensure civil-law relations, provision and receipt of services, and settlement of payments for goods and services in accordance with the Tax Code of Ukraine and the Law of Ukraine “On Accounting and Financial Reporting in Ukraine”.
4. Procedure for Personal Data Processing
4.1. Consent must be voluntary and provided for a clearly defined purpose.
4.2. Consent may be given in the following forms:
- written document;
- electronic document (preferably signed with an electronic signature);
- checkbox or confirmation in an electronic system.
4.3. Consent is obtained during the establishment of civil-law relations.
4.4. The data subject is informed about their rights, purpose of data collection, and data recipients at the time of data collection.
4.5. Processing of special categories of personal data is prohibited.
5. Location of Personal Data Databases
5.1. Personal data databases are located at the Seller’s registered address.
6. Disclosure of Personal Data to Third Parties
6.1. Access is granted based on consent or legal requirements.
6.2. Access is denied if the third party cannot ensure compliance with data protection law.
6.3–6.11. Requests for access must include identifying information, purpose, and legal basis. Requests are reviewed within 10 working days and fulfilled within 30 calendar days unless otherwise required by law. Access may be postponed or denied in accordance with legal provisions.
7. Personal Data Protection
7.1. The Seller implements technical and organizational measures to protect personal data.
7.2–7.7. A responsible person is appointed, and employees must comply with data protection laws and confidentiality obligations.
7.8. Personal data is retained only as long as necessary for processing purposes.
8. Rights of the Personal Data Subject
8.1. The data subject has the right to:
- access their personal data;
- receive information about processing;
- request correction or deletion;
- object to processing;
- protect their data from unlawful processing;
- apply to authorities or courts for protection of their rights.
9. Requests from Personal Data Subjects
9.1–9.5. Data subjects may submit requests free of charge. Requests are processed within 10 working days and fulfilled within 30 calendar days.
10. State Registration of Personal Data Databases
10.1. Registration is carried out in accordance with Ukrainian law.