Personal Data Processing Policy of Trading House MIXT
This Personal Data Processing Policy (the Policy) of LIMITED LIABILITY COMPANY “TRADING HOUSE “MIXT” (OGRN 1237700164272, INN 9715443335, KPP 772401001; registered address: premises 9/11, Building 1, 2 Kirpichnye Vyemki Street, Chertanovo Yuzhnoye Municipal District, Moscow 117405, Russia; hereinafter the Operator) was prepared in accordance with Federal Law No. 152-FZ of 27 July 2006, On Personal Data. It sets out the main principles, purposes, procedures and conditions for processing personal data, the measures ensuring data security, the rights of data subjects and the obligations of the Operator.
- GENERAL PROVISIONS
1.1. This Policy is a public document of the Operator and defines its position and intentions concerning the processing and protection of personal data.
1.2. Its purpose is to protect human and civil rights and freedoms when personal data is processed, including the right to privacy and personal and family confidentiality.
1.3. This Policy applies to all processes of the Operator involving personal data processing.
1.4. Terms and definitions:
Personal data: Any information relating to a directly or indirectly identified or identifiable individual, the data subject.
Operator: Trading House MIXT LLC, which independently or jointly with others organises and/or performs personal data processing and determines its purposes, the data to be processed and the operations performed on that data.
Personal data processing: Any operation or set of operations, performed with or without automated tools, including collection, recording, organisation, accumulation, storage, clarification (updating or amendment), retrieval, use, transfer (dissemination, provision or access), anonymisation, blocking, deletion and destruction of personal data.
Data subject: The individual to whom the personal data relates.
Personal data confidentiality: The requirement for the Operator or anyone with access to personal data not to disseminate it without the data subject’s consent or another lawful basis.
Personal data information system: The personal data contained in databases together with the information technologies and technical tools used to process it.
- PERSONAL DATA PROCESSING PRINCIPLES
The Operator processes personal data on the following principles:
2.1. Lawfulness and fairness.
2.2. Restricting processing to specific, predetermined and lawful purposes. Processing incompatible with the purposes of collecting the data is not permitted.
2.3. Databases containing personal data processed for incompatible purposes must not be combined.
2.4. Only data relevant to the purposes of processing is processed.
2.5. The content and volume of processed data must match the stated purposes.
2.6. Data must be accurate, sufficient and up to date in relation to the processing purposes.
2.7. Data is stored in a form identifying the data subject no longer than required for the purposes of processing, unless a storage period is established by federal law or a contract under which the data subject is a party, beneficiary or guarantor.
2.8. Data is destroyed or anonymised when the processing purposes are achieved or no longer need to be achieved, unless federal law provides otherwise.
- PURPOSES OF PERSONAL DATA COLLECTION
The Operator collects and processes personal data for the following purposes:
3.1. Civil-law relationships:
- Concluding and performing contracts for the sale of goods or provision of services.
- Delivering goods, performing work and providing services.
- Identifying users and placing orders on tdmx.ru.
- Processing payments.
- Providing access to a user account on the Website.
3.2. Employment relationships:
- Supporting recruitment, employee education and career advancement.
- Ensuring employee safety and monitoring the quantity and quality of work performed.
- Protecting property.
- Complying with labour legislation and other regulations.
3.3. Marketing and promotion:
- Providing information about new goods, services, promotions and special offers with the data subject’s consent.
- Conducting marketing research and analysing user preferences.
- Personalising offers and content on tdmx.ru.
3.4. Feedback and user support:
- Responding to enquiries, requests and complaints.
- Providing technical support.
3.5. Security:
- Preventing fraud and abuse.
- Protecting the Operator’s information systems.
3.6. Compliance with Russian legislation: Performing obligations imposed on the Operator by federal laws.
- DATA SUBJECT CATEGORIES AND DATA PROCESSED
The Operator may process personal data concerning the following categories of data subjects:
4.1. Buyers, customers and users of tdmx.ru:
- Last name, first name and patronymic.
- Date of birth.
- Contact information, including telephone number and email address.
- Delivery address.
- Partial payment details; complete details are not stored.
- Order and purchase information.
- Website interaction information, including IP address, cookie data, browser, operating system and visited pages.
4.2. Employees and job applicants:
- Last name, first name and patronymic.
- Passport details and citizenship.
- Registered and residential addresses.
- Telephone number and email address.
- Education, qualifications, vocational training and professional development information.
- Employment history and previous employers.
- Marital status and family composition, where necessary and permitted by law.
- Military registration information.
- Health information where required by law.
- Taxpayer identification number (INN) and individual insurance account number (SNILS).
- Biometric personal data, with consent and where permitted by law, for example for access-control systems.
4.3. Counterparties: representatives of legal entities:
- The representative’s last name, first name and patronymic.
- Job title.
- Contact information, including telephone and email.
- Documents confirming authority.
- PROCESSING PROCEDURES AND CONDITIONS
5.1. Legal grounds for processing:
- The Constitution of the Russian Federation.
- Federal Law No. 152-FZ of 27 July 2006, On Personal Data.
- Federal Law No. 149-FZ of 27 July 2006, On Information, Information Technologies and Information Protection.
- Other Russian regulations governing personal data processing.
- The charter of Trading House MIXT LLC.
- Contracts between the Operator and data subjects.
- Data subjects’ consent to processing their personal data.
5.2. Processing conditions:
- Personal data is processed with the data subject’s consent, except where consent is not required under Federal Law No. 152-FZ.
- Processing may be automated or non-automated.
- Non-automated processing complies with the requirements established by the Russian Government.
- Processing in personal data information systems complies with Russian legislation.
5.3. Processing periods:
- Processing periods depend on the processing purposes, contract terms, data subjects’ consents and Russian legal requirements.
- Data must be destroyed when processing purposes are achieved, processing periods expire or consent is withdrawn, unless Russian legislation provides otherwise.
5.4. Transfer to third parties:
- The Operator does not disclose or disseminate personal data to third parties without the data subject’s consent, except as provided by Federal Law No. 152-FZ and other federal laws.
- With the data subject’s consent, the Operator may engage third-party data processors under contracts specifying the processing purposes, operations, confidentiality obligations and security requirements. Such parties may include payment systems, delivery services, hosting providers and analytics services.
- Cross-border transfer of personal data to a foreign country is permitted only in compliance with Federal Law No. 152-FZ.
- PERSONAL DATA SECURITY MEASURES
The Operator takes the necessary legal, organisational and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination and other unlawful actions. These measures include:
6.1. Appointing a person responsible for organising personal data processing.
6.2. Adopting internal policies on processing and protecting personal data.
6.3. Familiarising employees directly processing personal data with Russian personal data legislation, data protection requirements and internal policies, and training those employees.
6.4. Identifying security threats when personal data is processed in information systems.
6.5. Applying the organisational and technical security measures necessary to meet personal data protection requirements.
6.6. Assessing the effectiveness of security measures before commissioning a personal data information system.
6.7. Maintaining records of electronic media containing personal data.
6.8. Detecting unauthorised access and taking appropriate measures.
6.9. Restoring data altered or destroyed through unauthorised access.
6.10. Establishing access rules and logging and recording all operations performed on personal data in information systems.
6.11. Monitoring security measures and the protection level of personal data information systems.
6.12. Using SSL encryption on tdmx.ru to protect transmitted data.
- RIGHTS OF DATA SUBJECTS
The data subject has the right to:
7.1. Obtain information about the processing of their personal data in accordance with Federal Law No. 152-FZ.
7.2. Require clarification, blocking or destruction of incomplete, outdated, inaccurate or unlawfully obtained data, or data unnecessary for the stated processing purpose.
7.3. Withdraw consent to personal data processing. On withdrawal, the Operator ceases processing unless Russian legislation provides otherwise.
7.4. Require unlawful processing to cease.
7.5. Challenge the Operator’s actions or omissions before the authorised data protection authority, Roskomnadzor, or a court.
7.6. Protect their rights and legitimate interests, including seeking damages and/or compensation for non-pecuniary harm through the courts.
To exercise these rights, the data subject may contact the Operator using the details in section 9 of this Policy.
- LIABILITY
Persons responsible for violating the rules governing personal data processing and protection are subject to disciplinary, administrative, civil or criminal liability under the legislation of the Russian Federation.
- FINAL PROVISIONS
9.1. This Policy is an internal document of the Operator and must be published on tdmx.ru.
9.2. The Operator may amend this Policy. When amendments are made, the date of the latest update is indicated in the Policy heading. The revised Policy takes effect upon publication on the Website, unless the revised version provides otherwise.
9.3. Compliance with Russian personal data legislation and this Policy is monitored by the person responsible for organising personal data processing at Trading House MIXT LLC.
Operator details and contacts:
LIMITED LIABILITY COMPANY “TRADING HOUSE “MIXT”
Registered address: premises 9/11, Building 1, 2 Kirpichnye Vyemki Street, Chertanovo Yuzhnoye Municipal District, Moscow 117405, Russia.
OGRN: 1237700164272
INN: 9715443335
KPP: 772401001
Email: INFO@TDMX.ru