1. GENERAL PROVISIONS.
    1.1. This Policy of the limited liability company «Ayubooking» on the processing of personal data (hereinafter — the «Policy») has been developed in pursuance of the requirements of clause 2, part 1, article 18.1 of Federal Law No. 152-FZ of 27.07.2006 «On Personal Data» (hereinafter — the Personal Data Law) in order to ensure the protection of the rights and freedoms of the individual and citizen in the processing of their personal data, including the protection of the rights to privacy and to personal and family confidentiality.
    1.2. The Policy applies to all personal data processed by the limited liability company «Ayubooking» (hereinafter — the «Operator»), which the Operator may obtain from the personal data subject (a participant or other customer) who is a party to contractual relations connected with the sale of the product and the provision of services forming part of the product, as well as from a personal data subject who is in a relationship with the Operator governed by labour law (hereinafter — the «Employee»).
    1.3. The Policy applies to relations in the field of personal data processing that arose for the Operator both before and after the approval of this Policy.
    1.4. In fulfilment of the requirements of Part 2 of Article 18.1 of the Personal Data Act, this Policy is published in the public domain on the Internet information and telecommunications network on the website: https://panchakarma.club/ (hereinafter — the «Site») at the following link: https://panchakarma.club/politika-v-otnoshenii-obrabotki-personalnyh-dannyh-klientov-i-polzovatelej-sajta/.
    1.5. The Operator does not verify the accuracy of the Personal data received from the Personal data subject.
    1.6. The Operator ensures the protection of the personal data processed against unauthorised access and disclosure, unlawful use or loss in accordance with the requirements of Federal Law No. 152-FZ «On Personal Data» of 27 July 2006.
    1.7. The Subject agrees to this Policy by giving consent to the processing of personal data:
    1.7.1. by clicking the «Go to chat» button when moving to a chat in WhatsApp with +7 958 111-08-33;
    OR
    1.7.2. by clicking the «Send» or «Book» button in the special widgets.
  1. TERMS AND ADOPTED ABBREVIATIONS.
    2.1. For the purposes of applying and interpreting this Policy, the main terms defined below are used (unless the Policy expressly states otherwise). In the text of the Policy these terms may be given with a capital or small letter, in the singular or plural, and also in the form of abbreviations.
    2.1.1. Personal data — any information relating directly or indirectly to an identified or identifiable natural person (the Personal data subject);
    2.1.2. Personal data operator — OOO «Ayubooking» (address: 121352, Russian Federation, Moscow, Slavyansky Boulevard 9/6 – 44, INN/KPP 9731005392 / 773101001, OGRN 1187746639453) is the owner of the Site and, independently or jointly with other persons, organises and (or) carries out the processing of Personal data, and also determines the purposes of processing Personal data, the composition of the Personal data to be processed, and the actions (operations) performed with the Personal data;
    2.1.3. Personal data subject — a natural person whose Personal data is processed by the Operator or by a third party on the Operator’s instructions;
    2.1.4. Processing of personal data — any action (operation) or set of actions (operations) with Personal data performed with or without the use of automation tools. The processing of Personal data includes, among other things:
    2.1.4.1. collection;
    2.1.4.2. recording;
    2.1.4.3. systematisation;
    2.1.4.4. accumulation;
    2.1.4.5. storage;
    2.1.4.6. clarification (updating, modification);
    2.1.4.7. extraction;
    2.1.4.8. use;
    2.1.4.9. transfer (provision to a limited circle of persons; access for a limited circle of persons);
    2.1.4.10. anonymisation;
    2.1.4.11. blocking;
    2.1.4.12. deletion;
    2.1.4.13. destruction.
    2.1.5. Storage of personal data — a process involving the presence of Personal data in a systematised form at the Operator’s disposal.
    2.1.6. Collection of personal data — a purposeful process of the Operator obtaining Personal data directly from the Subjects.
    2.1.7. Automated processing of personal data — the processing of personal data using computer technology;
    2.1.8. Non-automated processing of personal data — the processing of personal data contained in a personal data information system or extracted from such a system is considered to be carried out without the use of automation tools (non-automated) if such actions with personal data as the use, clarification, dissemination or destruction of personal data in respect of each of the Personal data subjects are carried out with the direct participation of a human being;
    2.1.9. Mixed processing of personal data — processing by a human with the involvement of computer technology;
    2.1.10. Provision of personal data — actions aimed at disclosing personal data to a specific person or a specific circle of persons;
    2.1.11. Blocking of personal data — the temporary suspension of the processing of personal data (except in cases where processing is necessary to clarify personal data);
    2.1.12. Destruction of personal data — actions as a result of which it becomes impossible to restore the content of personal data in the personal data information system and (or) as a result of which the material media of personal data are destroyed;
    2.1.13. Anonymisation of personal data — actions as a result of which it becomes impossible, without the use of additional information, to determine that personal data belong to a specific Personal data subject;
    2.1.14. Personal data information system (hereinafter — the «PDIS») — the totality of personal data contained in databases and the information technologies and technical means that ensure their processing.
    2.1.15. Cross-border transfer of personal data — the transfer of personal data to the territory of a foreign state, to an authority of a foreign state, to a foreign natural person or to a foreign legal entity.
    2.1.16. Customer (including — participant) — a natural person who is legally capable and has reached the age of 18, or a legal entity, who has approached OOO «Ayubooking» in order to purchase a product and/or an additional service, for themselves and for participants, acting on behalf of the latter. Participant — the customer and/or the persons in respect of whom the contract is concluded, who use or intend to use the services.
    2.1.17. Service, product — a service or set of services for organising a wellness programme and Ayurvedic procedures provided by OOO «Ayubooking».
  1. CONDITIONS FOR PROCESSING PERSONAL DATA
    3.1. The processing of the Subject’s Personal data by the Operator is carried out by means with or without the use of automation tools for the periods necessary to achieve the purposes of processing. A condition for the Operator to cease processing the Subjects’ Personal data may be the achievement of the purposes of their processing, the withdrawal of the Subject’s consent to the processing of their Personal data, the cessation of the Operator’s activity (reorganisation or liquidation), the closure of the Site, the termination of the contract between the Operator and the Subject, the dismissal of the Employee, or the detection of the fact of their unlawful processing.
    3.2. The Operator’s policy on the processing of the Subjects’ Personal data is that Personal data must be processed only in cases established by law, on the basis of the Operator’s main areas of activity and taking into account the balance of the interests of the Operator and the Subject. The processing of Personal data by the Operator is carried out taking into account the need to ensure the protection of the Subject’s rights and freedoms, including the protection of the right to privacy and to personal and family confidentiality, on the basis of the following principles:
    3.2.1. the processing of Personal data is carried out by the Operator on a lawful and fair basis;
    3.2.2. the processing of Personal data is limited to the achievement of specific, predetermined and lawful purposes;
    3.2.3. the processing of Personal data that is incompatible with the purposes of collecting the Personal data is not allowed;
    3.2.4. only Personal data that meet the purposes of their processing are subject to processing;
    3.2.5. the content and volume of the Personal data processed correspond to the stated purposes of processing; excessiveness of the Personal data processed in relation to the stated purposes of their processing is not allowed;
    3.2.6. the storage of Personal data is carried out in a form that allows the Subject to be identified for no longer than the purposes of processing the Personal data require. The Personal data processed are destroyed upon achievement of the purposes of processing or in the event that the need to achieve these purposes is lost, unless otherwise provided by law.
    3.3. The processing of personal data is carried out by the Operator in compliance with the principles and rules provided for by 152-FZ «On Personal Data» of 27 July 2006, in the following cases:
    3.3.1. with the consent of the personal data subject to the processing of their personal data;
    3.3.2. the processing of personal data is necessary for the performance of a contract for the sale of the product to which the personal data subject is a party, beneficiary or guarantor;
    3.3.3. in cases where the processing of personal data is necessary for the Operator to exercise and perform the functions, powers and obligations imposed by the legislation of the Russian Federation;
    3.3.4. the processing of personal data is necessary to protect the life, health or other vital interests of the personal data subject, if obtaining the consent of the personal data subject is impossible.
    3.4. The Operator does not have the right to obtain and process the Subject’s Personal data containing information about racial or ethnic origin, political views, religious and philosophical beliefs, or state of health, other than with the Subject’s consent.
    3.5. The Operator does not process special categories of Personal data or biometric data.
    3.6. A User of the Site, by providing data through the Site, confirms that they have familiarised themselves with this Policy and have given consent to the processing of Personal data.
    3.7. Other categories of Subjects familiarise themselves with the Policy upon the conclusion of the contract and the Customer’s provision of consent.
    3.8. The provision of the Subject’s Personal data at the request of state bodies (local self-government bodies) is carried out in the manner provided for by the legislation of the Russian Federation.
    3.9. Control over compliance with the requirements of this Policy is carried out by the authorised person responsible for organising the processing of personal data at the Operator.
    3.10. Liability for a violation of the requirements of the legislation of the Russian Federation by the Operator in the field of the processing and protection of personal data is determined in accordance with the legislation of the Russian Federation.
    3.11. Only the Operator’s employees whose job duties include the processing of personal data, and third parties engaged by the Operator, are admitted to the processing of personal data.
    3.12. Procedure for obtaining personal data:
    3.13. The obtaining of personal data, except for publicly available personal data, is carried out by the Operator directly from the Personal data subjects, or from persons who have duly executed powers to represent the interests of the Personal data subjects when transferring personal data to the Operator. If the subject’s personal data can be obtained only from a third party, then the subject must be notified of this, or consent must be obtained from them.
    3.14. The collection of the personal data of the Site’s users is carried out by the Operator when they are entered by the Subject on their own initiative.
    3.15. Upon obtaining personal data, the Operator is obliged to inform the personal data subject:
    3.15.1. of the purposes for which the Operator obtains personal data;
    3.15.2. of the list of personal data requested by the Operator;
    3.15.3. of the list of actions that the Operator intends to perform with the personal data;
    3.15.4. of the period during which the personal data subject’s consent to the processing of personal data is valid;
    3.15.5. of the procedure for withdrawing consent to the processing of personal data;
    3.15.6. of the consequences of the personal data subject’s refusal to give the Operator consent to the obtaining and processing of personal data.
    3.16. Documents containing personal data are created by:
    3.16.1. copying the originals of documents;
    3.16.2. entering information into registration forms;
    3.16.3. obtaining the originals of the necessary documents.
    3.17. The processing of personal data for each purpose of processing specified in clauses 5.3 – 5.5 of the Policy is carried out by:
    3.17.1. Obtaining personal data in oral, written and electronic form directly from the Subjects;
    3.17.2. Entering personal data into the Operator’s logs, registers and information systems;
    3.17.3. Using other methods of processing personal data depending on the action for processing the Personal data.
  1. RIGHTS AND OBLIGATIONS
    1. Obligations of the Operator:
    4.1.1. To organise the processing of personal data in accordance with the requirements of the Personal Data Law;
    4.1.2. To respond to requests and enquiries from personal data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
    4.1.3. To provide the authorised body for the protection of the rights of personal data subjects (the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)), at that body’s request, the necessary information within 10 working days from the date of receipt of such a request. This period may be extended, but by no more than five working days. To do so, the Operator must send Roskomnadzor a reasoned notification stating the reasons for extending the period for providing the requested information;
    4.1.4. In the manner determined by the federal executive body authorised in the field of security, to ensure interaction with the state system for detecting, preventing and eliminating the consequences of computer attacks on the information resources of the Russian Federation, including informing it of computer incidents that resulted in the unlawful transfer (provision, dissemination, access) of personal data.
    4.1.5. In cases where the personal data were obtained not from the personal data subject, to notify the personal data subject of the fact that the Operator obtained the personal data.
    4.1.6. In the event of a refusal to provide personal data, to explain to the personal data subject the consequences of such a refusal.
    4.1.7. To publish or otherwise ensure unrestricted access to the document defining the Operator’s policy on the processing of personal data.
    4.1.8. To take, or ensure the taking of, the necessary legal, organisational and technical measures to protect personal data against unlawful or accidental access to it, destruction, modification, blocking, copying, provision or dissemination of personal data, as well as against other unlawful actions in respect of personal data.
    4.2. The Operator has the right:
    4.2.1. To independently determine the composition and list of measures necessary and sufficient to ensure the fulfilment of the obligations provided for by the Personal Data Law and the regulatory legal acts adopted in accordance with it, unless otherwise provided by the Personal Data Law or other Federal laws;
    4.2.2. To entrust the processing of Personal data to another person. A person carrying out the processing of Personal data on the Operator’s instructions is obliged to comply with the principles and rules for the processing of Personal data provided for by the Personal Data Law.
    4.2.3. In the event that the Subject withdraws consent to the processing of personal data, the Operator has the right to continue the processing of Personal data without the Subject’s consent if there are grounds specified in the Personal Data Law.
    4.3. The Subject has the right:
    4.3.1. To receive information concerning the processing of their personal data, except in the cases provided for by federal laws. The information is provided to the personal data subject by the Operator in an accessible form and must not contain personal data relating to other personal data subjects, except where there are lawful grounds for disclosing such personal data. The list of information and the procedure for obtaining it are established by the Personal Data Law. The information may contain:
    4.3.1.1. Confirmation of the fact of the processing of personal data by the operator;
    4.3.1.2. The legal grounds and purposes of the processing of personal data;
    4.3.1.3. The purposes and methods of processing personal data used by the operator;
    4.3.1.4. The name and location of the operator, information about the persons (other than the operator’s employees) who have access to personal data or to whom personal data may be disclosed on the basis of a contract with the operator or on the basis of a federal law;
    4.3.1.5. The personal data being processed relating to the relevant personal data subject, the source of their receipt, unless another procedure for presenting such data is provided for by a federal law;
    4.3.1.6. The periods of processing personal data, including the periods of their storage;
    4.3.1.7. The procedure for the personal data subject to exercise the rights provided for by this Federal Law;
    4.3.1.8. Information about a cross-border data transfer that has been carried out or is intended;
    4.3.1.9. The name or surname, first name, patronymic and address of the person carrying out the processing of personal data on the operator’s instructions, if the processing is or will be entrusted to such a person;
    4.3.1.10. Other information provided for by the Personal Data Law or other federal laws.
    4.3.2. To require the operator to clarify their personal data, to block it or destroy it if the personal data are incomplete, out of date, inaccurate, unlawfully obtained or not necessary for the stated purpose of processing, and also to take the measures provided for by law to protect their rights.
    4.3.3. To give prior consent to the processing of personal data for the purposes of promoting goods, works and services on the market.
    4.3.4. To appeal to Roskomnadzor or through the courts against the Operator’s unlawful actions or inaction in the processing of their personal data.
    4.4. Obligations of the Subject (participant or customer of the product):
    4.4.1. The Customer (participant) is obliged to provide the Company with sufficient, accurate, documented personal data, the full composition of which is established in the contracts for the sale of the product.
    4.4.2. The Customer (participant) must, without undue delay, inform the Agent of any change in their personal data.
  1. PURPOSES OF PROCESSING PERSONAL DATA, CATEGORIES OF SUBJECTS, CATEGORIES OF PERSONAL DATA PROCESSED AND METHODS OF THEIR PROCESSING.
    5.1. The processing of personal data is limited to the achievement of specific, predetermined and lawful purposes. The processing of personal data that is incompatible with the purposes of collecting the personal data is not allowed.
    5.2. Only personal data that meet the purposes of their processing are subject to processing.
    5.3. Purpose of processing personal data: preparation, conclusion and performance of a civil-law contract:
    Categories of Personal data processed:
    ∙ surname, first name, patronymic;
    ∙ floor;
    ∙ year of birth;
    ∙ month of birth;
    ∙ date of birth;
    ∙ place of birth;
    ∙ email address;
    ∙ residential address;
    ∙ registration address;
    ∙ telephone number;
    ∙ INN;
    ∙ OGRNIP;
    ∙ identity document details;
    ∙ current account number;
    ∙ position;
    ∙ information collected by means of recommendation technologies.
    Categories of Subjects: counterparties; representatives of counterparties.
    Legal basis for the processing of personal data:
    ∙ the processing of personal data is carried out with the consent of the personal data subject to the processing of their personal data;
    ∙ the processing of personal data is necessary for the performance of a contract to which the personal data subject is a party, beneficiary or guarantor, and also for the conclusion of a contract on the initiative of the personal data subject or a contract under which the personal data subject will be a beneficiary or guarantor. The contract concluded with the personal data subject may not contain provisions restricting the rights and freedoms of the personal data subject.
    List of actions for processing Personal data:
    ∙ collection;
    recording;
    ∙ systematisation;
    ∙ accumulation; storage;
    ∙ clarification (updating, modification);
    ∙ extraction;
    ∙ use;
    ∙ anonymisation;
    ∙ blocking;
    removal;
    ∙ destruction;
    transmission.
    Methods of processing: mixed; with transfer via the legal entity’s internal network; with transfer via the Internet.
    Period of processing and storage of Personal data:
    ∙ the validity period of the consent;
    ∙ the validity period of the contract.
    5.4. Purpose of processing personal data: carrying out civil-law relations connected with the fulfilment of obligations under contracts for the sale of the product or service and ensuring the provision of the services forming part of the product being sold.
    Categories of Personal data processed:
    • surname, first name, patronymic in Russian;
    • surname and first name in Latin transcription, as indicated in the international passport;
    • year, month and day of birth;
    • place of birth;
    • current citizenship (if necessary — citizenship at birth);
    • gender;
    • details of the general civil passport of the Russian Federation (series and number of the all-Russian passport, its date of issue, the name of the body that issued the passport, the validity period of the all-Russian passport or of the birth certificate);
    • details of the international passport of the Russian Federation (series and number of the international passport, its date of issue, the name of the body that issued the passport, the validity period);
    • details of the birth certificate (for minor citizens);
    • registration address;
    • actual address of residence;
    • email address;
    • home and mobile telephone numbers;
    • data of recommendation technologies.
    • additional information provided at the subject’s own wish, other personal data required by OOO «Ayubooking» in accordance with the applicable legislation of the Russian Federation in the field of personal data.
    • Additional information requested by the consular services of the embassy of the country of planned visit, if a visa needs to be obtained in the interests of the customer at the embassy of the country of planned stay:
    father’s surname and first name; mother’s surname and first name;
    details of the employer and employment (name, address and telephone of the employer, current position, salary amount);
    details of the educational institution — for schoolchildren and students (name, address and telephone of the educational institution);
    image (photograph) of the customer;
    dates of past trips to the country of planned visit or to a group of certain countries;
    information about past deportations from the country of planned visit or other violations of the legislation of foreign states;
    other required information determined by the consular services of the embassy of the country of planned visit.
    Categories of Subjects: Users of the Site (Customers of the product — a participant or another person ordering the product on behalf of the participant, including the legal representative of a minor participant).
    Legal basis for the processing of personal data:
    ∙ the processing of personal data is carried out with the consent of the personal data subject to the processing of their personal data;
    ∙ the processing of personal data is necessary for the performance of a contract to which the personal data subject is a party, beneficiary or guarantor, and also for the conclusion of a contract on the initiative of the personal data subject or a contract under which the personal data subject will be a beneficiary or guarantor. The contract concluded with the personal data subject may not contain provisions restricting the rights and freedoms of the personal data subject.
    List of actions for processing Personal data:
    ∙ collection;
    recording;
    ∙ systematisation;
    ∙ accumulation; storage;
    ∙ clarification (updating, modification);
    ∙ extraction;
    ∙ use;
    ∙ anonymisation;
    ∙ blocking;
    removal;
    ∙ destruction;
    ∙ transfer (provision, access).
    Methods of processing: mixed; without transfer via the legal entity’s internal network; with transfer via the Internet.
    Period of processing and storage of Personal data:
    ∙ the validity period of the consent;
    ∙ the validity period of the contract.
    5.5. Purpose of processing personal data: sending advertising and informational messages.
    Categories of Personal data processed:
    · surname, first name, patronymic;
    · telephone number;
    · email.
    Categories of Subjects: Users of the Site. Legal basis for the processing of personal data:
    · the processing of personal data is carried out with the consent of the personal data subject to the processing of their personal data. List of actions for processing Personal data:
    · collection;
    · recording;
    · systematisation;
    · accumulation; storage;
    · clarification (updating, modification);
    · extraction;
    · use;
    · anonymisation;
    · blocking;
    · deletion;
    · destruction;
    · transfer (provision, access).

    Methods of processing:
    — mixed;
    — with transfer via the Internet

    Period of processing and storage of Personal data:
    — the validity period of the consent

  1. TRANSFER OF PERSONAL DATA
    6.1. The Operator transfers personal data to third parties in the following cases:
    6.1.1. consent to such actions has been obtained from the Personal data subject;
    6.1.2. the transfer is provided for by Russian or other applicable legislation within the framework of a procedure established by law.
    6.2. List of persons to whom personal data are transferred:
    6.2.1. Third parties to whom personal data are transferred in the course of fulfilling obligations connected with the sale and performance of the services forming part of the product:
    6.2.1.1. contractors forming the product;
    6.2.1.2. direct providers of the services forming part of the product, or providing individual services (accommodation facilities, consulates and embassies of foreign states that arrange visas, etc.).
    6.2.2. Third parties to whom personal data are transferred in the course of fulfilling obligations connected with labour relations:
    6.2.2.1. Bodies of the Ministry of Internal Affairs of Russia in cases established by law;
    6.2.2.2. Other state bodies in cases established by law.
    6.3. The provision of the Subject’s Personal data at the request of state bodies (local self-government bodies) is carried out in the manner provided for by the legislation of the Russian Federation.
    6.4. When collecting personal data, including via the information and telecommunications network Internet, the Operator ensures the processing of the personal data of citizens of the Russian Federation using databases located in the territory of the Russian Federation, except in the cases specified in the Personal Data Law.
    6.5. The Operator carries out cross-border transfer of personal data.
    6.6. For purposes connected with the sale of the product and the provision of the services forming part of the product, cross-border transfer of personal data may be carried out. Cross-border transfer of personal data is carried out taking into account the requirements established by article 12 of Federal Law No. 152-FZ «On Personal Data» of 27 July 2006.
    6.7. The Subject (user of the Site), when giving consent to the processing of personal data, gives consent to their cross-border transfer.
    6.8. Cross-border transfer of the personal data of other categories of subjects is not carried out.
  1. UPDATING, CORRECTION, DELETION, DESTRUCTION OF PERSONAL DATA, RESPONSES TO SUBJECTS’ REQUESTS FOR ACCESS TO PERSONAL DATA
    7.1. Procedure for considering Subjects’ requests:
    7.1.1. Confirmation of the fact of the processing of personal data by the Operator, the legal grounds and purposes of the processing of personal data, as well as other information specified in part 7 of article 14 of the Personal Data Law, are provided by the Operator to the Subject or their representative within 10 working days from the moment of the request or receipt of the request of the Personal data subject or their representative. This period may be extended, but by no more than five working days. To do so, the Operator should send the Subject a reasoned notification stating the reasons for extending the period for providing the requested information.
    7.1.2. The information provided does not include personal data relating to other Subjects, except where there are lawful grounds for disclosing such personal data.
    7.1.3. The request must contain data allowing the Subject to be identified, and the Subject’s signature, and, where the request is signed by the Subject’s representative, a document confirming their authority.
    7.1.4. The request may be sent in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
    7.1.5. The Operator provides the information specified in part 7 of article 14 of the Personal Data Law to the Subject or their representative in the form in which the relevant request was sent, unless otherwise indicated in the request. If the Subject’s request does not reflect, in accordance with the requirements of the Personal Data Law, all the necessary information, or the Subject does not have access rights to the requested information, a reasoned refusal is sent to them.
    7.1.6. The Subject’s right to access their Personal data may be restricted in accordance with part 8 of article 14 of the Personal Data Law, including where the Subject’s access to their personal data violates the rights and legitimate interests of third parties.
    7.2. In the event that inaccurate Personal data are detected upon the request of the Subject or their representative, or at their request or at the request of Roskomnadzor, the Operator blocks the Personal data relating to that Subject from the moment of such a request or the receipt of the said request for the period of the check, if the blocking of personal data does not violate the rights and legitimate interests of the Subject.
    7.3. In the event of confirmation of the fact of the inaccuracy of personal data, the Operator, on the basis of information provided by the Subject or their representative or by Roskomnadzor, or other necessary documents, clarifies the Personal data within seven working days from the day such information is presented and lifts the blocking of the Personal data.
    7.4. In the event that unlawful processing of Personal data is detected upon the request (enquiry) of the Subject or their representative or of Roskomnadzor, the Operator blocks the unlawfully processed Personal data relating to that personal data subject within three working days from the moment of such a request or the receipt of the enquiry.
    7.5. Destruction of personal data:
    7.5.1. Upon the achievement of the purpose of processing personal data, and also in the event of the withdrawal by the Personal data subject of consent to their processing, the personal data are subject to destruction if:
    7.5.1.1. it is not otherwise provided for by a contract to which the Subject is a party, beneficiary or guarantor;
    7.5.1.2. the Operator is not entitled to carry out the processing without the consent of the personal data subject on the grounds provided for by the Personal Data Law or other federal laws;
    7.5.1.3. it is not otherwise provided for by the legislation of the Russian Federation.
    7.6. Personal data on electronic media are destroyed by erasing them from computer memory or formatting the computer memory.
    7.7. The destruction of documents (paper media) containing personal data is carried out by burning, shredding (grinding), chemical decomposition, or turning into a shapeless mass or powder. A shredder may be used to destroy paper documents.
    7.8. The period for the destruction of personal data is 10 working days from the moment of the occurrence of one of the events provided for in clause 7.5 of this Policy.
  1. MEASURES TAKEN BY THE OPERATOR TO PROTECT PERSONAL DATA
    8.1. In accordance with the requirements of the regulatory documents, the Operator has created a personal data protection system consisting of subsystems of legal, organisational and technical protection.
    8.2. The legal protection subsystem is a set of legal, organisational-administrative and normative documents ensuring the creation, functioning and improvement of personal data protection systems.
    8.3. The organisational protection subsystem includes the organisation of the management structure of personal data protection systems, of the authorisation system, and of information protection when working with employees, partners and outside persons.
    8.4. The technical protection subsystem includes a set of technical, software, and software-and-hardware means ensuring the protection of personal data.
    8.5. The main personal data protection measures used by the Operator are:
    8.5.1. Appointment of a person responsible for the processing of personal data, who organises the processing of personal data, training and briefing, and internal control over compliance by the institution and its employees with the requirements for the protection of personal data.
    8.5.2. Determination of the current threats to the security of personal data during their processing in personal data information systems and the development of measures and activities to protect personal data.
    8.5.3. Development of a policy on the processing of personal data.
    8.5.4. Establishment of rules of access to the personal data processed in personal data information systems, as well as ensuring the registration and recording of all actions performed with personal data in personal data information systems.
    8.5.5. Establishment of individual access passwords for employees to the information system in accordance with their production duties.
    8.5.6. Use of information protection tools that have undergone the conformity assessment procedure in the established manner.
    8.5.7. Certified antivirus software with regularly updated databases.
    8.5.8. Compliance with the conditions ensuring the safety of personal data and excluding unauthorised access to it.
    8.5.9. Detection of facts of unauthorised access to personal data and the taking of measures.
    8.5.10. Restoration of personal data modified or destroyed as a result of unauthorised access to it.
    8.5.11. Training of the Operator’s employees directly carrying out the processing of personal data in the provisions of the legislation of the Russian Federation on personal data, including the requirements for the protection of personal data, the documents defining the Operator’s policy on the processing of personal data, and local acts on personal data processing matters.
    8.5.12. Carrying out internal control and audit.
    8.6. When processing personal data, the Operator ensures:
    8.6.1. the carrying out of activities aimed at preventing unauthorised access to personal data and/or its transfer to persons who do not have the right of access to such information;
    8.6.2. the timely detection of facts of unauthorised access to personal data;
    8.6.3. the prevention of any impact on the technical means of automated processing of personal data that could disrupt their functioning;
    8.6.4. the possibility of immediate restoration of personal data modified or destroyed as a result of unauthorised access to it;
    8.6.5. constant monitoring of the level of protection of personal data.
    8.7. The Operator uses technical means and software for processing and protecting personal data.
    8.8. The above technical means and software for processing and protecting personal data are located in the Operator’s office and premises or on the premises of other persons engaged by the Operator.
    8.9. All persons admitted to work with personal data, as well as those connected with the operation and technical support of the PDIS, have familiarised themselves with this Policy.
    8.10. The Operator has organised a process of training in the use of the protection tools operated by the Operator. Training in this area has been undergone by persons with permanent access to personal data, persons operating the technical and software means of the PDIS and the PDIS protection tools, and persons responsible for operating the PDIS information protection tools.
    8.11. Employees are obliged to immediately inform the relevant official of the Operator of the loss or shortage of media containing information that constitutes personal data, as well as of the reasons for and conditions of a possible leak of personal data. In the event of an attempt by outsiders to obtain from an employee personal data processed by the Operator, they must immediately notify the relevant official of the Operator of this.
    8.12. When working with the software of the Operator’s automated system that implements the functions of viewing and editing personal data, it is prohibited to display screen forms containing such data to persons who do not have the appropriate clearance.
    8.13. Storage of personal data:
    8.13.1. The Subjects’ personal data may be obtained, undergo further processing and be transferred for storage both on paper media and in electronic form.
    8.13.2. The Subjects’ personal data recorded on paper media are stored in lockable cabinets or in lockable premises with a restricted right of access.
    8.13.3. The Subjects’ personal data processed using automation tools are processed and stored in compliance with the requirements established by Resolution of the Government of the Russian Federation No. 1119 «On the approval of requirements for the protection of personal data during their processing in personal data information systems» of 01.11.2012.
    8.13.4. The storage and placement of documents containing personal data in open electronic catalogues (file-sharing services) in personal data information systems is not allowed.
    8.13.5. The storage of personal data must be carried out in a form that allows the Subject to be identified for no longer than the purposes of processing the personal data require, unless the storage period for the personal data is established by a federal law or by a contract to which the Subject is a party, beneficiary or guarantor.
  1. DATA OF MINORS
    9.1. The Operator does not knowingly collect the personal data of minor Subjects without the consent of their legal representatives. If you are the legal representative of a minor Subject and know that the minor Subject has provided the Operator with their personal data without your consent, please contact the Operator using the contact details specified in section 13 of this Policy.
    9.2. The Operator obtains data about minor subjects only from their legal representatives and with their consent.
  1. RECOMMENDATION TECHNOLOGIES
    10.1. The Site uses recommendation technologies to keep statistics of visits, determine the level of interest and display content in accordance with the interests of the Subject (user of the Site).
  1. LIABILITY OF THE OPERATOR
    11.1. The Operator’s management bears responsibility for failure to ensure the confidentiality of Personal data and for non-compliance with the rights and freedoms of Subjects in respect of their Personal data, including the rights to privacy and to personal and family confidentiality.
    11.2. The Operator’s employees bear personal responsibility for non-compliance with the requirements for the processing and ensuring of the security of personal data in accordance with the legislation of the Russian Federation.
    11.3. An employee of the Operator may be held liable in the following cases:
    11.4. Intentional or negligent disclosure of personal data;
    11.5. Loss of the material media of personal data;
    11.6. Violation of the requirements of this Policy and other regulatory documents of the Operator concerning matters of access to and work with personal data.
    11.7. In cases of violation of the established procedure for the processing and ensuring the security of personal data, unauthorised access to personal data, disclosure of personal data and the causing of material or other damage to the Operator, its employees, counterparties and other Subjects, the guilty persons bear civil, criminal, administrative, disciplinary and other liability provided for by the legislation of the Russian Federation.
    11.8. The Operator informs the Subject that this Policy applies only to Personal data processed by the Operator. The Operator does not control and is not responsible for the use of third-party sites to which the Subject may, at their own discretion and at their own risk, navigate via the links placed on the Site.
    11.9. The Operator is not responsible for the accuracy of the Subject’s Personal data.
  1. FINAL PROVISIONS
    12.1. The Operator does not knowingly collect the personal data of minor Subjects without the consent of their legal representatives. If you are the legal representative of a minor Subject and know that the minor Subject has provided the Operator with their personal data without your consent, please contact the Operator using the contact details specified in section 13 of this Policy.
    12.2. This Policy comes into force from the moment of its approval, is put into effect by order of the Operator and is valid for an unlimited period (until it is cancelled or replaced by a new version of the Policy).
    12.3. The requirements of this Policy apply to all of the Operator’s employees who have access to personal data, as well as to all Subjects.
    12.4. The Operator has the right unilaterally to make changes and (or) additions to this Policy. The new version of the Policy comes into force from the moment of its publication (placement) on the Site on the Internet at the address https://panchakarma.club/soglasie-na-obrabotku-personalnyh-dannyh, unless otherwise provided by the new version of the Policy. In the event of changes affecting the rights of Subjects, the Operator has the right, but is not obliged, to send information about these changes to Subjects using their contact details or to notify them of the changes in another way. If, after a change to this Policy, the Subject (user of the Site) continues to use the Site or does not withdraw their consent to the processing of personal data within 5 working days, then the Subject (user of the Site) agrees to the changes made; the other categories of Subjects are notified of the changes made to the Policy.
  1. OPERATOR’S DETAILS
    Company: OOO «AYUBOOKING»
    Legal address: 121352, Russian Federation, Moscow, Slavyansky Boulevard 9/6 — 44
    Postal and actual address: 121352, Russian Federation, Moscow, Slavyansky Boulevard 9/6 — 44
    INN/KPP 9731005392 / 773101001
    OGRN 1187746639453
    Contact telephone: +7 (495) 777-96-39
    e-mail: info@panchakarma.club
    https://panchakarma.club/