General provisions
The Operator's policy regarding the processing of personal data (hereinafter referred to as the "Policy") has been developed in accordance with Federal Law No. 152–FZ of 27.07.2006 "On Personal Data" (hereinafter referred to as "FZ-152").
This Policy defines the procedure for processing personal data and measures to ensure the security of personal data in the branch of the company of the Limited Liability Company "Mayt of Light" - INN 7841096920 (hereinafter referred to as the "Operator") in order to protect the rights and freedoms of man and citizen in the processing of his personal data, including the protection of the rights to privacy, personal and family secrets. Each of these persons individually is an independent Operator of personal data.
The following basic concepts are used in the Policy:
• automated processing of personal data – processing of personal data using computer technology;
• blocking of personal data - temporary termination of the processing of personal data (except in cases where processing is necessary to clarify personal data);
• personal data information system - a set of personal data contained in databases, and information technologies and technical means that ensure their processing;
• depersonalization of personal data - actions as a result of which it is impossible to determine, without the use of additional information, the ownership of personal data to a specific personal data subject;
• personal data processing - any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data;
• operator - a state body, municipal body, legal entity or individual, independently or jointly with other persons organizing and (or) processing personal data, as well as determining the purposes of processing personal data, the composition of personal data to be processed, actions (operations) performed with personal data;
• personal data – any information relating directly or indirectly to a specific or identifiable individual (subject of personal data);
• provision of personal data – actions aimed at disclosure of personal data to a certain person or a certain circle of persons;
• dissemination of personal data - actions aimed at disclosure of personal data to an indefinite circle of persons (transfer of personal data) or familiarization with personal data of an unlimited circle of persons, including the publication of personal data in the media, placement in information and telecommunications networks or providing access to personal data in any other way;
• cross-border transfer of personal data - transfer of personal data to the territory of a foreign state to the authority of a foreign state, a foreign individual or a foreign legal entity.
• destruction of personal data - actions as a result of which it is impossible to restore the content of personal data in the personal data information system and (or) as a result of which the material carriers of personal data are destroyed;
The Operator is obliged to publish or otherwise provide unrestricted access to this Policy in accordance with Part 2 of Article 18.1. FZ-152.

Principles of personal data processing
• legality and fair basis;
• restrictions on the processing of personal data to achieve specific, predetermined and legitimate goals;
• preventing the processing of personal data incompatible with the purposes of personal data collection;
• preventing the consolidation of databases containing personal data, the processing of which is carried out for purposes incompatible with each other;
• processing only those personal data that meet the purposes of their processing;
• compliance of the content and volume of the processed personal data with the stated purposes of processing;
• preventing the processing of personal data that is excessive in relation to the stated purposes of their processing;
• ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of personal data processing;
• destruction or depersonalization of personal data upon achievement of the purposes of their processing or in case of loss of the need to achieve these goals, if it is impossible for the Operator to eliminate the violations of personal data, unless otherwise provided by federal law.
Personal data processing conditions

The Operator processes personal data in the presence of at least one of the following conditions:
• processing of personal data is carried out with the consent of the personal data subject to the processing of his personal data;
• the processing of personal data is necessary to achieve the goals stipulated by an international agreement of the Russian Federation or a law, for the implementation and fulfillment of the functions, powers and duties assigned to the operator by the legislation of the Russian Federation;
• processing of personal data is necessary for the administration of justice, execution of a judicial act, an act of another body or official subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings;
• the processing of personal data is necessary for the execution of a contract to which the subject of personal data is a party or beneficiary or guarantor, as well as for the conclusion of a contract on the initiative of the subject of personal data or a contract under which the subject of personal data will be the beneficiary or guarantor;
• processing of personal data is necessary to protect the life, health or other vital interests of the subject of personal data, if obtaining the consent of the subject of personal data is impossible;
• processing of personal data is necessary for the exercise of the rights and legitimate interests of the operator or third parties, provided that the rights and freedoms of the personal data subject are not violated;
• processing of personal data authorized by the subject of personal data for distribution is carried out in compliance with the prohibitions and conditions provided for by FZ-152;
• processing of personal data subject to publication or mandatory disclosure in accordance with federal law is carried out.
Confidentiality of personal data
The operator and other persons who have gained access to personal data are obliged not to disclose to third parties and not to distribute personal data without the consent of the subject of personal data, unless otherwise provided by federal law.
Publicly available sources of personal data
In order to provide information, the Operator may create publicly available sources of personal data of personal data subjects, including directories and address books. The publicly available sources of personal data, with the written consent of the personal data subject, may include his surname, first name, patronymic, date and place of birth, position, contact phone numbers, email address and other personal data reported by the personal data subject.
Information on the personal data subject shall be at any time excluded from public sources of personal data at the request of the subject of personal data, the authorized body for the protection of rights of personal data subjects or in court.
Special categories of personal data
An Operator special categories of personal data relating to race, national origin, political opinions, religious or philosophical beliefs, health status, intimate life, is allowed in the following cases:
• the subject of personal data has given written consent to the processing of his personal data;
• processing of personal data authorized by the subject of personal data for distribution is carried out in compliance with the prohibitions and conditions provided for by FZ-152;
• processing of personal data is carried out in accordance with the legislation on state social assistance, labor legislation, the legislation of the Russian Federation on pensions for state pension provision, on labor pensions;
• processing of personal data is necessary to protect the life, health or other vital interests of the subject of personal data or the life, health or other vital interests of other persons and obtaining the consent of the subject of personal data is impossible;
• the processing of personal data is carried out for medical and preventive purposes, for the purpose of establishing a medical diagnosis, providing medical and medical and social services, provided that the processing of personal data is carried out by a person professionally engaged in medical activity and obliged in accordance with the legislation of the Russian Federation to maintain medical secrecy;
• the processing of personal data is necessary to establish or exercise the rights of the subject of personal data or third parties, as well as in connection with the administration of justice;
• processing of personal data is carried out in accordance with the legislation on mandatory types of insurance, with insurance legislation.
The processing of special categories of personal data carried out in the cases provided for in paragraph 4 of Article 10 of FZ-152 must be immediately terminated if the reasons for which their processing was carried out have been eliminated, unless otherwise established by federal law.
The processing of personal data on criminal record can be carried out by the Operator only in cases and in accordance with the procedure determined in accordance with federal laws.
Biometric personal data
Information that characterizes the physiological and biological characteristics of a person, on the basis of which it is possible to establish his identity - biometric personal data - can be processed by the Operator only with the consent of the subject of personal data in writing.
Personal data authorized by the subject of personal data for distribution
The operator processes personal data authorized by the subject of personal data for distribution on the basis of a consent formalized separately from other consents of the subject of personal data to the processing of his personal data. The operator is obliged to provide the subject of personal data with the opportunity to determine the list of personal data for each category of personal data specified in the consent to the processing of personal data authorized by the subject of personal data for distribution.
In consent to the processing of personal data authorized by the subject of personal data for distribution, the subject of personal data has the right to establish prohibitions on the transfer (except for granting access) of these personal data by the Operator to an unlimited number of persons, as well as prohibitions on processing or conditions for processing (except for obtaining access) of these personal data by an unlimited number of persons. The Operator's refusal to establish prohibitions and conditions by the subject of personal data is not allowed.
Personal data disclosed by the personal data subject himself to an indefinite circle of persons may be processed by the Operator only if the Operator can provide evidence of the legality of the processing of such personal data.
Assignment of personal data processing to another person
The operator has the right to entrust the processing of personal data to another person with the consent of the subject of personal data, unless otherwise provided by federal law, on the basis of a contract concluded with this person. The person processing personal data on behalf of the Operator is obliged to comply with the principles and rules of personal data processing provided for by FZ-152 and this Policy
Processing of personal data of citizens of the Russian Federation
In accordance with Article 2 of Federal Law No. 242-FZ of July 21, 2014 "On Amendments to Certain Legislative Acts of the Russian Federation in Terms of Clarifying the Procedure for Processing Personal data in Information and telecommunications Networks", when collecting personal data, including through the Internet information and telecommunications network, the operator is obliged to provide a record, systematization, accumulation, storage, clarification (updating, modification), extraction of personal data of citizens of the Russian Federation using databases, located on the territory of the Russian Federation, except for the following cases:
• the processing of personal data is necessary to achieve the goals provided for by an international treaty of the Russian Federation or by law, to carry out and fulfill the functions, powers and duties assigned to the operator by the legislation of the Russian Federation;
• processing of personal data is necessary for the administration of justice, execution of a judicial act, an act of another body or official subject to execution in accordance with the legislation of the Russian Federation on enforcement proceedings (hereinafter referred to as the execution of a judicial act);
• processing of personal data is necessary for the execution of the powers of federal executive bodies, bodies of state extra-budgetary funds, executive bodies of state power of the subjects of the Russian Federation, local self-government bodies and the functions of organizations involved in the provision of state and municipal services, respectively, provided for by Federal Law No. 210-FZ of July 27, 2010 "On the Organization of the provision of state and municipal services". municipal services", including registration of the subject of personal data on the unified portal of state and municipal services and (or) regional portals of state and municipal services;
• the processing of personal data is necessary for the professional activity of a journalist and (or) the legitimate activities of the mass media or scientific, literary or other creative activities, provided that the rights and legitimate interests of the subject of personal data are not violated.
Cross-border transfer of personal data
The operator is obliged to make sure that the foreign state to whose territory the transfer of personal data is supposed to be carried out provides adequate protection of the rights of personal data subjects before the start of such transfer.
The cross-border transfer of personal data on the territory of foreign states that do not provide adequate protection of the rights of personal data subjects may be carried out in the following cases:
• the written consent of the personal data subject to the cross-border transfer of his personal data;
• execution of the contract to which the subject of personal data is a party;
• protection of life, health, and other vital interests of the subject of personal data or other persons if it is impossible to obtain written consent of the subject of personal data.
Consent of the personal data subject to the processing of his personal data
The subject of personal data decides on the provision of his personal data and consents to their processing freely, of his own free will and in his own interest. Consent to the processing of personal data may be given by the subject of personal data or his representative in any form that allows to confirm the fact of its receipt, unless otherwise established by federal law.
Rights of the subject of personal data
The subject of personal data has the right to receive information from the Operator concerning the processing of his personal data, unless such right is restricted in accordance with federal laws. The subject of personal data has the right to require the Operator to clarify his personal data, block or destroy them if the personal data are incomplete, outdated, inaccurate, illegally obtained or are not necessary for the stated purpose of processing, as well as to take measures provided by law to protect their rights.
Processing of personal data for the purpose of promoting goods, works, services on the market by making direct contacts with the subject of personal data (potential consumer) by means of communication, as well as for the purposes of political agitation is allowed only with the prior consent of the subject of personal data.
The operator is obliged to immediately terminate, at the request of the personal data subject, the processing of his personal data for the above purposes.
It is prohibited to make decisions based solely on automated processing of personal data that generate legal consequences with respect to the subject of personal data or otherwise affect his rights and legitimate interests, except in cases provided for by federal laws, or with the written consent of the subject of personal data.
The subject of personal data has the right to request the Operator to stop the transfer (distribution, provision, access) of their personal data previously authorized by the subject of personal data for distribution. The operator is obliged to stop the transfer (distribution, provision, access) of personal data within three working days from the date of receipt of the request of the personal data subject.
If the personal data subject believes that the Operator processes his personal data in violation of the requirements of FZ-152 or otherwise violates his rights and freedoms, the personal data subject has the right to appeal the actions or inaction of the Operator to the Authorized Body for the Protection of the Rights of Personal Data subjects or in court.
The subject of personal data has the right to protect his rights and legitimate interests, including compensation for damages and (or) compensation for moral damage.
Ensuring the security of personal data
The security of personal data processed by the Operator is ensured by the implementation of legal, organizational and technical measures necessary to meet the requirements of federal legislation in the field of personal data protection.
To prevent unauthorized access to personal data by the Operator, the following organizational and technical measures are applied:
• appointment of officials responsible for organizing the processing and protection of personal data;
• limitation of the number of persons allowed to process personal data;
• familiarization of subjects with the requirements of federal legislation and regulatory documents of the Operator for the processing and protection of personal data;
• organization of accounting, storage and handling of media containing information with personal data;
• identification of threats to the security of personal data during their processing, the formation of threat models based on them;
• development of a personal data protection system based on the threat model;
• checking the readiness and effectiveness of the use of information security tools;
• differentiation of user access to information resources and hardware and software for information processing;
• registration and accounting of actions of users of personal data information systems;
• use of anti-virus tools and personal data protection system recovery tools;
• the use, where necessary, of means of inter-network shielding, intrusion detection, security analysis and cryptographic protection of information;
• organization of access control to the Operator's territory, protection of premises with technical means of personal data processing.
Final provisions
Other rights and obligations of the Operator in connection with the processing of personal data are determined by the legislation of the Russian Federation in the field of personal data.
The Operator's employees who are guilty of violating the norms governing the processing and protection of personal data bear material, disciplinary, administrative, civil or criminal liability in accordance with the procedure established by federal laws.