PERSONAL DATA PROCESSING POLICY
1. General Provisions
This Personal Data Processing Policy (the "Policy") has been developed in accordance with Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" ("FZ-152") and the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Strasbourg, 28 January 1981).
This Policy sets out the procedure for processing personal data and the measures for ensuring the security of personal data at Int Line LLC (the "Operator"). Its purpose is to protect the rights and freedoms of individuals and citizens when their personal data is processed, including the right to privacy and to personal and family secrecy.
The website https://hotelpms.ru and the "HotelPMS" mobile application for Android (ru.hotelpms.mobile.app) are owned and operated by the same owner, Andrey Ponomarev.
This Policy applies to:
the website https://hotelpms.ru/;
the "HotelPMS" mobile application for Android (ru.hotelpms.mobile.app), available on Google Play.
The following key terms are used in this Policy:
automated processing of personal data means the processing of personal data using computer technology;
blocking of personal data means the temporary suspension of personal data processing (except where processing is necessary to clarify the personal data);
personal data information system means the set of personal data contained in databases, together with the information technologies and technical means used to process it;
anonymization of personal data means actions that make it impossible, without additional information, to determine which specific data subject the personal data belongs to;
processing of personal data means any action (operation) or set of actions (operations) performed on personal data, with or without automation, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), anonymization, blocking, deletion and destruction of personal data;
operator means a state body, municipal body, legal entity or individual that, alone or jointly with others, organizes and/or carries out the processing of personal data and determines the purposes of processing, the scope of personal data to be processed, and the actions (operations) performed on personal data;
personal data means any information relating to a directly or indirectly identified or identifiable individual (personal data subject);
personal data authorized by the data subject for dissemination means personal data to which the data subject has granted access to an unlimited number of persons by giving consent to the processing of personal data authorized for dissemination, in the manner prescribed by law;
provision of personal data means actions aimed at disclosing personal data to a specific person or a specific group of persons;
dissemination of personal data means actions aimed at disclosing personal data to a specific person or a specific group of persons;
functional features:
The mobile application provides access to the same services and functionality as the web version of the website;
The application may display website content within its interface;
No third-party content is distributed or used.
cross-border transfer of personal data means the transfer of personal data to the territory of a foreign state, to a foreign government authority, or to a foreign individual or legal entity;
destruction of personal data means actions that make it impossible to restore the content of personal data in a personal data information system and/or that result in the destruction of physical media containing personal data.
The Operator must publish this Personal Data Processing Policy or otherwise ensure unrestricted access to it in accordance with Part 2 of Article 18.1 of FZ-152.
2. Principles of Personal Data Processing
2.1. The Operator processes personal data on the basis of the following principles:
– lawfulness and a fair basis;
– limiting processing to the achievement of specific, predetermined and lawful purposes;
– preventing processing that is incompatible with the purposes for which the personal data was collected;
– preventing the merging of databases containing personal data processed for mutually incompatible purposes;
– processing only personal data that meets the purposes of processing;
– ensuring that the content and scope of the personal data processed correspond to the stated purposes of processing;
– preventing processing of personal data that is excessive in relation to the stated purposes;
– ensuring the accuracy, sufficiency and relevance of personal data in relation to the purposes of processing;
– destroying or anonymizing personal data once the purposes of processing have been achieved, or if achieving those purposes is no longer necessary, or if the Operator is unable to remedy violations committed in relation to the personal data, unless otherwise provided by federal law.
3. Rights and Obligations of the Personal Data Subject
3.1. Personal data subjects or their legal representatives have the right to:
– receive full information about their personal data and its processing (including automated processing);
– have free access to their personal data at no charge, including the right to obtain copies of any record containing the subject's personal data, except as provided by the federal laws of the Russian Federation;
– demand the exclusion or correction of inaccurate or incomplete personal data, as well as data processed in violation of Russian law;
– if the Operator or a person authorized by it refuses to exclude or correct the subject's personal data, state their disagreement in writing, with appropriate justification;
– require the Operator or a person authorized by it to notify all persons to whom inaccurate or incomplete personal data of the subject was previously disclosed of all corrections or exclusions made;
– challenge in court any unlawful actions or omissions of the Operator or a person authorized by it in the processing and protection of the subject's personal data.
3.2. Personal data subjects or their legal representatives must:
– provide the Operator with truthful personal data;
– promptly notify the Operator of any changes to their personal data.
4. Rights and Obligations of the Operator
4.1. The Operator may process personal data provided there are lawful grounds, and that the processing corresponds to the stated purposes and complies with the laws of the Russian Federation, this Policy and the Operator's other internal regulations.
4.2. The Operator must:
– at its own expense, protect personal data against misuse or loss in the manner established by Russian law;
– at the request of the personal data subject, provide information about the processing of their personal data, or refuse on lawful grounds;
– provide the subject with free access to their personal data at no charge, including the right to obtain copies of any record containing their personal data, except as provided by Russian law;
– at the request of the personal data subject, clarify, block or delete the personal data being processed if it is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing;
– maintain a Log of Requests from Personal Data Subjects, recording subjects' requests for personal data and the instances in which personal data was provided in response to such requests;
– notify the personal data subject of the processing of their personal data if the data was obtained from someone other than the subject;
– once the purpose of processing has been achieved, immediately stop processing the personal data and destroy it within thirty days of the date the purpose was achieved, unless otherwise provided by the federal laws of the Russian Federation;
– if the subject requests that processing of their personal data be stopped, stop processing and destroy the personal data within ten working days of receiving the request. This period may be extended by no more than five working days if the Operator sends the personal data subject a reasoned notice stating the reasons for the extension. The Operator may continue processing personal data in the cases provided for in Clauses 2–11 of Part 1 of Article 6, Part 2 of Article 10 and Part 2 of Article 11 of FZ-152;
– provide the subject's personal data only to authorized persons, and only to the extent necessary for them to perform their job duties in accordance with these Regulations and the laws of the Russian Federation.
5. Procedure and Conditions for Processing Personal Data
5.1. The Operator obtains all personal data directly from the personal data subject, from the subject's representative, or from the person who has instructed the Operator to process the personal data, except as provided by Russian law.
5.2. Personal data is processed with the consent of the personal data subject, except as provided by Russian law. Consent may be expressed in any form that allows confirmation that it was obtained, including by conclusive (implied) actions, in writing as a separate document, or as part of a document signed by the subject. Consent may be given by the subject's representative upon presentation of proof of their authority.
5.3. The personal data subject may withdraw consent to the processing of personal data. In cases provided for by Russian law, processing may continue even after the subject has withdrawn consent.
5.4. When making decisions affecting the subject's interests, the Operator never relies on personal data obtained solely through automated processing or by electronic means.
5.5. Personal data is not used to cause property and/or moral damage to citizens or to hinder the exercise of the rights and freedoms of citizens of the Russian Federation.
5.6. Access to personal data is granted to those employees of the Operator who need it to perform their job duties.
5.7. Personal data of the Operator's employees is transferred to third parties only with the subject's written consent, except as provided by Russian law.
5.8. The Operator may transfer personal data to inquiry and investigation bodies and other authorized bodies on the grounds provided for by the current laws of the Russian Federation.
5.9. The Operator may create publicly available sources of personal data, which may include the subject's personal data with their written consent.
5.10. The subject's personal data is not transferred for commercial purposes without their written consent.
5.11. If the Operator needs to transfer personal data to third parties, it does so only after the Operator and the third party have signed a non-disclosure agreement, except as provided by Russian law.
5.12. Personal data is processed both with and without the use of computer technology.
5.13. The periods for which the Operator processes personal data are generally determined by: the periods established by FZ-152; the term of the relevant agreement; the periods specified in the instruction to process personal data; the document retention periods established by Federal Law No. 125-FZ "On Archiving in the Russian Federation" and Rosarkhiv (Federal Archival Agency) Order No. 236 of 20 December 2019 "On Approval of the List of Standard Administrative Archival Documents Generated in the Course of Activities of State Bodies, Local Self-Government Bodies and Organizations, Indicating Their Retention Periods"; the limitation period; the term of the consent given by the personal data subject; and other requirements of the laws of the Russian Federation.
5.14. Personal data processed without automation is kept separate from other information, in particular by recording it on separate physical media containing personal data ("physical media"), in special sections, or in fields of forms.
5.15. When personal data is recorded on physical media, personal data processed for clearly incompatible purposes must not be recorded on the same medium. For processing different categories of personal data without automation, a separate physical medium is used for each category.
5.16. Persons processing personal data without automation must be informed that they are processing personal data that the Operator processes without automation, of the categories of personal data processed, and of the specifics and rules of such processing.
5.17. When standard document forms are used that the personal data subject fills in by hand and whose nature implies or allows the inclusion of personal data ("standard forms"), the following conditions are met:
– the standard form or related documents (instructions for filling it in, cards, registers and logs) must contain information on the purpose of the non-automated processing of personal data; the name and address of the operator; the surname, first name, patronymic and address of the personal data subject; the source of the personal data; the processing periods; the list of actions to be performed with the personal data during processing; and a general description of the processing methods used by the operator;
– the standard form must include a field in which the personal data subject can mark their consent to non-automated processing of personal data, where written consent to processing is required;
– the standard form must be designed so that each personal data subject whose data is contained in the document can review their own personal data without violating the rights and legitimate interests of other personal data subjects; – the standard form must not combine fields intended for personal data processed for clearly incompatible purposes.
5.18. Personal data must be destroyed when the purposes of processing have been achieved, when achieving them is no longer necessary, when the retention period expires, when unlawful processing is detected, or at the request of the person who instructed the processing. Destruction takes place within ten working days of the date the purpose of processing was achieved or consent to processing was withdrawn. This period may be extended by no more than five working days if the Operator sends the personal data subject a reasoned notice stating the reasons for the extension. Destruction is carried out in the presence of a commission, and a certificate of destruction is drawn up.
5.19. The Operator carries out cross-border transfers to the following countries: the USA, Spain, Germany, Belarus, Kazakhstan, Israel and Ireland.
6. Ensuring the Security of Personal Data
6.1. The security of personal data processed by the Operator is ensured through the legal, organizational and technical measures necessary to meet the requirements of federal personal data protection legislation.
6.2. To prevent unauthorized access to personal data, the Operator applies the following organizational and technical measures:
– appointing officers responsible for organizing the processing and protection of personal data;
– issuing this Personal Data Processing Policy and other internal regulations on personal data processing. These regulations define, for each processing purpose, the categories and list of personal data processed, the categories of data subjects, the methods and periods of processing and storage, and the procedure for destroying personal data once the processing purposes are achieved or other lawful grounds arise. They also include internal regulations establishing procedures for preventing and detecting violations of Russian law and eliminating their consequences;
– limiting the number of persons with access to personal data;
– familiarizing subjects with the requirements of federal legislation and the Operator's regulatory documents on the processing and protection of personal data;
– organizing the recording, storage and handling of information media;
– identifying threats to the security of personal data during processing and developing threat models on that basis;
– using information security tools that have passed conformity assessment in the established manner;
– developing a personal data protection system based on the threat model;
– checking the readiness and effectiveness of information security tools;
– differentiating user access to information resources and to hardware and software used for information processing;
– logging and recording the actions of users of personal data information systems;
– using anti-virus software and tools for restoring the personal data protection system;
– using, where necessary, firewalls, intrusion detection, security analysis tools and cryptographic information protection tools;
– organizing access control to the Operator's premises and securing premises that house technical means of personal data processing.
7. Notification of the Start of Personal Data Processing
7.1. The Operator must notify the authorized body for the protection of the rights of personal data subjects of its intention to process personal data, either by completing a notification via the electronic portal provided by the authorized body or by sending a written notification.
7.2. The Operator notifies the authorized body of the start of processing of the following categories of personal data:
data processed in accordance with labor legislation;
data obtained in connection with the conclusion of an agreement to which the personal data subject is a party (including any user of the information system, whether acting as the party publishing listings in the system or as the party making a booking based on a published listing);
if access control is introduced at the Operator's premises, data needed for one-time admission of the personal data subject to the premises where the Operator is located, or for other similar purposes.
8. Amendment, Deletion and Destruction of Personal Data
8.1. The Operator may enter, supplement, amend, block or delete personal data in accordance with the federal laws of the Russian Federation.
8.2. At the request of the personal data subject, the Operator must:
– provide information on whether the Operator holds the subject's personal data;
– allow the subject to review their personal data (subject to the exception in Part 5 of Article 14 of FZ-152) and provide information about the processing of their personal data in accordance with FZ-152;
– clarify inaccurate or changed personal data;
– block or destroy personal data if it was unlawfully obtained, is not necessary for the stated purpose of processing, or the subject has withdrawn consent.
8.3. A request from a personal data subject must be sent to the Operator on paper. It must contain the number of the main identity document of the personal data subject or their legal representative, the date of issue of that document and the issuing authority, and the handwritten signature of the personal data subject or their legal representative.
8.4. A request may also be sent electronically, signed with an electronic digital signature in accordance with the laws of the Russian Federation, to the email address: info@hotelpms.ru
8.5. Upon receiving a request from a subject, the responsible employee of the Operator must register it in the log of subjects' requests.
8.6. A response or a reasoned refusal must be sent within ten working days of receiving the request from the personal data subject. This period may be extended by no more than five working days if the Operator sends the personal data subject a reasoned notice stating the reasons for the extension. The response must be given in the same form in which the request was sent, unless the request specifies otherwise, and must contain specific and comprehensive information on the substance of the matter.
8.7. The Operator's other rights and obligations as a personal data operator are determined by the personal data legislation of the Russian Federation.
9. Changes to this Privacy Policy
9.1. Int Line LLC may amend this Privacy Policy from time to time at its own discretion. Where necessary, Int Line LLC notifies personal data subjects of such changes in the most appropriate way.
9.2. In the absence of explicit notice, data subjects can always review the updated version of this Personal Data Processing Policy on the operator's website at: https://hotelpms.ru.
9.3. All provisions of this Privacy Policy apply equally to the website and to the mobile application.
10. Consent of the Personal Data Subject When Accessing the Operator's Website or Mobile Application
10.1. By visiting the Operator's website (source of visit: https://hotelpms.ru) or the "HotelPMS" mobile application for Android (ru.hotelpms.mobile.app) available on Google Play, the personal data subject, of their own free will and in their own interest, consents to automated and non-automated processing of personal data, including through the internet services Google Analytics, Yandex.Metrica, LiveInternet, top.mail.ru, Google DoubleClick and Google Marketing Platform, covering the following:
surname, first name and order details, if an order is placed;
the source of the visit to https://hotelpms.ru (the "Operator's Website") and information from the search or advertising query;
data about the user's device (including screen resolution, version and other attributes characterizing the device);
user clicks, page views, form field entries, and banner and video impressions and views;
data characterizing audience segments;
session parameters;
visit time data;
the user identifier stored in a cookie,
for the purposes of raising awareness among visitors to the Operator's Website of the Operator's products and services, delivering relevant advertising information, and optimizing advertising.
10.2. The Operator may process personal data by the following methods: collection, recording, systematization, accumulation, storage, updating, modification and use.
10.3. This consent takes effect from the moment the Operator's Website is accessed and remains valid for the periods established by the current laws of the Russian Federation.
11. Contact Details
11.1. Email: info@hotelpms.ru
11.2. Postal address: Apt. 13, 18 Belibeyskaya St., Kaliningrad, Kaliningrad Region, 236043, Russia
11.3. Phone: +7 499 325-35-03