Personal data processing policy
Policy OOO "CLUB CRUISES" in relation to the processing of personal data
The purpose and scope of document
"The politics of OOO "CLUB CRUISES" (hereinafter also - the company) in relation to the processing of personal data" (hereinafter – the Policy) determines the position and intentions of Companies in the field of processing and protection of personal data, with the goal of respecting and protecting the rights and freedoms of each person and, in particular, the right to inviolability of private life, personal and family secret, protection of honour and good name.
The policy is strictly enforced by managers and employees of all structural subdivisions and branch OOO "CLUB CRUISES".
The Policy applies to all personal data of the subjects treated in Society with the use of automation tools and without the use of such funds.
This Policy has access to any personal data subject.
Definition
Personal data - any information relating to an identified or identifiable natural person (citizen). Ie to such information, in particular, include: full name, year, month, date and place of birth, address, information about family, social, property status, education, profession, income, data on health status, and other information.
Personal data processing - any action (operation) or set of actions (operations) with personal data, committed with use of means of automation or without use of such funds. Such actions (transactions) include: collection, receipt, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (distribution, granting, access), depersonalization, blocking, deletion, destruction of personal data.
The personal data subjects, OOO "CLUB CRUISES" processes personal data for the following persons:
employees of OOO "CLUB CRUISES";
entities, which have signed contracts of civil-legal nature;
candidates for vacant positions, OOO "CLUB CRUISES";
the clients of "CLUB CRUISES";
registered users of the website of "CLUB CRUISES"
representatives of legal entities;
providers (individual entrepreneurs).
The principles and conditions of personal data processing
Under the security of personal data of LLC "CLUB CRUISES" understands the protection of personal data against wrongful or casual access to them, destruction, change, blocking, copying, granting, distribution of personal data, as well as other unlawful actions in relation to personal data and shall take the necessary legal, organizational and technical measures to protect personal data.
Processing and security of personal data in OOO "CLUB CRUISES" is carried out in accordance with the requirements of the Constitution of the Russian Federation, Federal law № 152-FZ "On personal data", regulations, and other defining cases and features of processing of personal data Federal laws of the Russian Federation, guidelines and methodical documents FSTEK Russia and FSB of Russia.
In processing the personal data of OOO "CLUB CRUISES" adheres to the following principles:
law and fair basis;
restrict the processing of personal data by the specified, explicit and legitimate purposes;
prevent the processing of personal data, incompatible with the objectives of collecting personal data;
prevent the merging of databases containing personal data the processing of which is carried out for the purposes incompatible with each other;
the processing of personal data that meet the purposes of processing;
content compliance.
The society processes personal data only in the presence of at least one of the following conditions:
the processing of personal data is carried out with the consent of personal data subject to the processing of personal data;
the processing of personal data necessary to achieve the purposes stipulated by law, to implement and fulfill the legislation of the Russian Federation to the operator functions, powers and duties;
the processing of personal data necessary for the execution of the contract to which either the beneficiary or the guarantor which is the subject of personal data, as well as for the contract at the initiative of the personal data subject or of the contract under which the data subject will be the beneficiary or surety;
the processing of personal data necessary for the implementation of the rights and legitimate interests of the company or third parties or to achieve important public purposes, provided that doing so does not violate the rights and freedoms of the data subject;
the processing of personal data, access of an unlimited circle of persons to which is provided by the personal data subject or on request;
the processing of personal data subject to publication or mandatory disclosure in accordance with Federal law.
OOO "CLUB CRUISES" is entitled to entrust the processing of personal data to third parties, on the basis of concluded with these persons of the agreement.
The person carrying out the processing of personal data on behalf of OOO "CLUB CRUISES" and agree to adhere to the principles and rules of processing and protection of personal data stipulated by the Federal law № 152-FZ "On personal data". For each person identified list of actions (operations) with personal data that is to be performed by the legal person carrying out the processing of personal data, purpose of processing, the obligation of such persons to observe confidentiality and to ensure the security of personal data during their processing, and includes requirements for the protection of personal data processed.
In the cases established by the legislation of the Russian Federation, OOO "CLUB CRUISES" have the right to transfer personal data of citizens.
For the purpose of information security in Companies can be created and publicly available sources of personal data of employees, including directories and address books. In public sources of personal data with the consent of the employee may include his surname, name, patronymic, date and place of birth, position, contact telephone numbers, e-mail address. Information about the employee should be at any time excluded from the publicly available sources of personal data at the request of the employee or by court order or other public bodies.
Society destroys or depersonalizing personal data when the purposes of processing or in case of loss necessary to achieve the purpose of treatment.
Rights of the data subject
Citizen personal data is being processed, OOO "CLUB CRUISES" has the right to:
to "CLUB CRUISES":
confirmation of the processing of personal data by OOO "CLUB CRUISES";
legal basis and purpose of personal data processing;
information about applied OOO "CLUB CRUISES" the ways of personal data processing;
the name and location of OOO "CLUB CRUISES";
data on persons who have access to personal data or which may be disclosed personal data under the contract with OOO "CLUB CRUISES" or on the basis of the Federal law;
the list of processed personal data relating to a citizen, which received the request and the source of their receipt, unless a different procedure for the provision of such data is envisaged by the Federal law;
information about the timing of the processing of personal data, including terms of their storage;
information about the exercise of the citizen rights stipulated by the Federal law "On personal data" № 152-FZ;
information on ongoing or expected cross-border transfer of personal data;
the name and address of a person performing personal data processing on behalf of OOO "CLUB CRUISES";
other data envisaged by the Federal law "On personal data" № 152-FZ or other Federal laws;
to demand clarification of their personal data, their blocking or destruction in case personal data are incomplete, outdated, inaccurate, illegally obtained or are not necessary for the declared purpose of the processing;
to withdraw your consent to the processing of personal data;
to require the elimination of misconduct, OOO "CLUB CRUISES" in relation to his personal data;
to appeal against actions or omission of OOO "CLUB CRUISES" to the Federal service for supervision in the sphere of Telecom, information technologies and mass communications (Roskomnadzor) or in court if a citizen believes that the company "CLUB CRUISES" carries out the processing of personal data in violation of Federal law № 152-FZ "On personal data" or otherwise violates his rights and freedoms;
to protect their rights and legitimate interests, including on indemnification and/or compensation for moral harm in a judicial order.
Responsibility
In case of default of the provisions of this Policy, OOO "CLUB CRUISES" is responsible under applicable law of the Russian Federation.
PLEASE NOTE!
Clarification on matters concerning processing of Your personal data, contact person at OOO "CLUB CRUISES" or by sending a formal request by Mail of Russia to the address: 117218 Moscow, ul Novocheremushkinskaya, 23,141.
In the case of sending a formal request in OOO "CLUB CRUISES" in the query text must include:
- Name;
- a number of the basic document proving the identity of personal data subject or his representative, the date of issuance of the document and the issuing authority;
- information confirming Your participation in relations with OOO "CLUB CRUISES" or information otherwise confirming the fact of personal data processing, OOO "CLUB CRUISES";
- citizen's signature (or legal representative). If the request is sent electronically, it must be in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
On the website https://cruises-online.com/ published the current version "Policies "of "CLUB CRUISES" in relation to the processing of personal data".
Information about ongoing requirements for protection of personal data
OOO "CLUB CRUISES" in the processing of personal data shall take the necessary legal, organizational and technical measures to protect personal data against unauthorized or accidental access, destruction, alteration, blocking, copying, granting, distribution of personal data, as well as other unlawful actions in respect of personal data.
Such measures in accordance with Federal law No. 152-FZ "On personal data" include:
definition of threats to the security of personal data during their processing in personal data information systems;
the application of organizational and technical measures to ensure the security of personal data during their processing in personal data information systems necessary to meet the requirements of the protection of personal data, the execution of which ensures established by the Government of the Russian Federation the levels of protection of personal data;
the use of the past in the prescribed manner and procedure of conformity assessment of means of information protection;
evaluation of the effectiveness of the measures taken to ensure the security of personal data prior to commissioning of the information system of personal data;
detection of unauthorized access to personal data and taking measures;
recovery of personal data, modified or destroyed due to unauthorized access to them;
establishment of rules of access to personal data processed in personal data information systems, and also ensuring the registration and recording of all actions performed with personal data in the information system of personal data;
the monitoring of the measures taken to ensure the security of personal data and security level of personal data information systems;
accounting machine carriers of personal data;
the organization of admission to the territory of the community;
placement of technical means of personal data processing within a protected area;
maintenance of technical means of protection, alarm in constant readiness;
monitoring of user activity, conducting investigations of violations of the security of personal data
In order to coordinate actions to ensure the security of personal data in OOO "CLUB CRUISES", our Company implements the following requirements for the protection of personal data:
- organized security of the premises where the information system prevents the uncontrolled penetration or stay in these areas of persons not having right of access to the premises;
- implemented preservation of carriers of personal data;
- the head of the Company approved the document defining the list of persons whose access to personal data processed in the information system necessary to perform their official (job) duties;
- use of information protection tools, which have passed the conformity assessment procedure with the legislation of the Russian Federation in the field of information security;
- implemented the requirements set by the government of the Russian Federation from September, 15th, 2008 n 687 "About the Position statement about features of processing of personal data carried out without the use of means of automation".