Leave your contact details and we will contact you
Personal Data Processing Policy
This Policy of Limited Liability Company Analytical Company “RNC Pharma” (hereinafter – the Operator, LLC AC “RNC Pharma”) regarding the Processing of Personal Data (hereinafter – the Policy) has been developed in compliance with subparagraph 2, paragraph 1, Article 18.1 of Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (hereinafter – the Personal Data Law) for the purpose of ensuring the protection of the rights and freedoms of individuals in the course of Processing their Personal Data, including protection of the right to privacy, personal and family secrecy.
The Policy serves as the basis for organizing the Processing and protection of Personal Data in LLC AC “RNC Pharma”, including for the development of internal documentation in the field of Personal Data Processing, and defines:
The Policy has been developed in accordance with the legislation of the Russian Federation in the field of Personal Data and applies to all Personal Data processed by LLC AC “RNC Pharma”.
The Policy applies to relations in the field of Personal Data Processing that have arisen after the approval of this Policy.
In accordance with paragraph 2, Article 18.1 of the Personal Data Law, this Policy is published for general access on the Internet in the information and telecommunications network at the Operator’s website.
Automated Processing of Personal Data – Processing of Personal Data with the use of computer technology.
Blocking of Personal Data – temporary cessation of Personal Data Processing (except where Processing is necessary for the clarification of Personal Data).
Legislation of the Russian Federation – the body of regulatory legal acts of the Russian Federation, which defines the cases and specific features of Personal Data Processing, as well as establishes requirements for Personal Data Processing.
Personal Data Information System – a set of Personal Data contained in databases and information technologies and technical means that ensure their Processing.
Other Personal Data – Personal Data that do not relate to Special Categories of Personal Data or to Biometric Personal Data.
Confidentiality of Personal Data – a mandatory requirement for LLC AC “RNC Pharma” or another person granted access to Personal Data not to permit their disclosure without the consent of the Data Subject or other lawful basis.
Depersonalization of Personal Data – actions as a result of which it becomes impossible, without the use of additional information, to determine whether Personal Data belong to a specific Data Subject.
Personal Data Processing / Processing – any action (operation) or set of actions (operations) performed with Personal Data with or without the use of automated means. Personal Data Processing includes, inter alia:
Processing of Personal Data without the use of automated means (non-automated Processing of Personal Data) – Processing of Personal Data carried out with the direct participation of a person.
Personal Data Operator (Operator) – a government authority, municipal authority, legal entity or natural person who, independently or jointly with others, organizes and/or carries out Personal Data Processing, as well as determines the purposes of Personal Data Processing, the composition of Personal Data to be processed and the actions (operations) performed with Personal Data; LLC AC “RNC Pharma”.
Person Responsible for the Organization of Personal Data Processing – a person appointed by order of the General Director who organizes the adoption of legal, organizational and technical measures in order to ensure proper performance of the functions related to the organization of Personal Data Processing at LLC AC “RNC Pharma” in accordance with the provisions of the legislation of the Russian Federation in the field of Personal Data.
Personal Data – any information relating to a directly or indirectly identified or identifiable individual (Data Subject).
Website Users – users of the Internet service of LLC AC “RNC Pharma” and of software provided by the Operator.
Provision of Personal Data – actions aimed at disclosure of Personal Data to a specific person or a specific circle of persons.
Employee – a person who has an employment relationship with LLC AC “RNC Pharma” under an employment contract.
Dissemination of Personal Data – actions aimed at disclosure of Personal Data to an indefinite circle of persons.
Roskomnadzor – the authorized authority for the protection of the rights of Personal Data Subjects.
Data Subject – an individual who is directly or indirectly identified or identifiable on the basis of Personal Data relating to him or her.
Special Categories of Personal Data – Personal Data concerning race, nationality, political views, religious or philosophical beliefs, state of health, intimate life, as well as information on criminal record.
Destruction of Personal Data – actions as a result of which it becomes impossible to restore the content of Personal Data in the Personal Data Information System and/or as a result of which tangible media containing Personal Data are destroyed.
Former Employee – an individual who previously had an employment relationship with LLC AC “RNC Pharma” under an employment contract.
List of regulatory documents:
Legal grounds for Personal Data Processing:
The set of legal acts in pursuance of and in accordance with which LLC AC “RNC Pharma” carries out Personal Data Processing:
Consent to Personal Data Processing, including the consent of applicants for vacant positions to the Processing of Personal Data, the consent of Employees to the Processing of Personal Data, the consent of clients to the Processing of Personal Data, the consent of Website Users, the consent of other Data Subjects.
Processing of Personal Data is necessary to achieve the purposes stipulated by an international treaty of the Russian Federation or by law, to exercise and perform functions, powers and obligations imposed on the Operator by the legislation of the Russian Federation.
Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is a party, beneficiary or guarantor, if Personal Data Processing is required for the conclusion of such contract or for the performance of obligations thereunder.
Processing of Personal Data is limited to the achievement of specific, predetermined and lawful purposes. Processing of Personal Data that is incompatible with the purposes of Personal Data collection is not permitted.
LLC AC “RNC Pharma” carries out Processing of Personal Data lawfully obtained and belonging to:
The Operator Processes Personal Data for the following purposes:
The list of Personal Data processed at LLC AC “RNC Pharma” is determined in accordance with the legislation of the Russian Federation and with the local acts of LLC AC “RNC Pharma”, taking into account the purposes of Personal Data Processing specified in Clause 5 of the Policy and in accordance with the notification on Personal Data Processing submitted by the Operator to Roskomnadzor.
The purposes of Personal Data Processing and the corresponding categories and lists of Personal Data processed, as well as categories of Data Subjects, are set out in Appendix 1 to this Policy, which forms its integral part.
Personal Data Processing by the Operator is carried out on the basis of the following principles:
Employees of the Operator authorized to Process Personal Data are obliged to:
The Operator has the right to:
The Operator is obliged to:
The Data Subject has the right to:
Personal Data Processing is carried out by the Operator in accordance with the requirements of the legislation of the Russian Federation.
Personal Data Processing is carried out with the consent of Data Subjects to the Processing of their Personal Data, as well as without such consent in cases provided for by the legislation of the Russian Federation.
LLC AC “RNC Pharma” carries out Personal Data Processing with the use of automated means and without the use of automated means, as well as mixed Processing, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (Provision, access) of Personal Data for the time necessary to achieve the purposes of Personal Data Processing.
Employees of the Operator whose job duties include Personal Data Processing are admitted to Personal Data Processing.
Disclosure and Dissemination of Personal Data to third parties without the consent of the Data Subject is not permitted, unless otherwise provided by federal law. When Personal Data are disclosed (provided) to third parties, the requirements for the protection of processed Personal Data are observed.
Consent to Personal Data Processing permitted by the Data Subject for Dissemination is formalized separately from other consents of the Data Subject to the Processing of his or her Personal Data.
Transfer of Personal Data to law-enforcement and investigative authorities, the Federal Tax Service and other authorized executive authorities and organizations is carried out in accordance with the requirements of the legislation of the Russian Federation.
Personal Data are stored in a form that makes it possible to identify the Data Subject for no longer than required by the purposes of Personal Data Processing, unless the period of Personal Data storage is established by federal law or by a contract to which the Data Subject is a party, beneficiary or guarantor.
Personal Data on paper media are stored at LLC AC “RNC Pharma” for the periods specified by the legislation on archiving in the Russian Federation for such documents.
The period of storage of Personal Data processed in Personal Data Information Systems corresponds to the period of storage of Personal Data on paper media.
The Operator ceases Personal Data Processing in the following cases:
Upon achieving the purposes of Personal Data Processing and also in the event of withdrawal by the Data Subject of consent to such Processing, the Operator ceases Processing of such Personal Data if:
When a Data Subject lodges a request with the Operator demanding that Personal Data Processing be ceased, Processing shall be stopped within a period not exceeding 10 working days from the date on which the Operator receives the relevant request, except in cases stipulated by the Personal Data Law. This period may be extended, but by no more than five working days, in which case the Operator must send to the Data Subject a reasoned notification specifying the reasons for the extension.
If inaccurate Personal Data are identified following a request from the Data Subject or his or her representative, or at their request, or following a request from Roskomnadzor, the Operator shall block the Personal Data relating to that Data Subject from the moment of such request or receipt of such request for the period of verification, provided that the Blocking of Personal Data does not violate the rights and legitimate interests of the Data Subject or third parties.
If the inaccuracy of Personal Data is confirmed, the Operator, on the basis of the information provided by the Data Subject or his or her representative or by Roskomnadzor, or other necessary documents, shall clarify the Personal Data within seven working days from the date the information is provided and shall remove the Blocking of Personal Data.
If unlawful Processing of Personal Data is identified following a request by the Data Subject or his or her representative or by Roskomnadzor, the Operator shall block the unlawfully processed Personal Data relating to that Data Subject from the moment of such request or receipt of such request.
If the Operator, Roskomnadzor or another interested party identifies an instance of unlawful or accidental transfer (Provision, Dissemination) of Personal Data (access to Personal Data) resulting in a violation of the rights of Data Subjects, the Operator shall:
Conditions and time periods for Personal Data Destruction by the Operator:
Upon achieving the purposes of Personal Data Processing, as well as in the event of withdrawal by the Data Subject of consent to such Processing, Personal Data are subject to Destruction if:
Personal Data Destruction is carried out by a commission established by an order of the General Director of LLC AC “RNC Pharma”.
Methods of Personal Data Destruction are established in the local regulations of the Operator.
Confirmation of the fact of Personal Data Processing by the Operator, the legal grounds and purposes of Personal Data Processing, as well as other information specified in paragraph 7, Article 14 of the Personal Data Law, are provided by the Operator to the Data Subject or his or her representative within 10 working days from the date of the request or receipt of the Data Subject’s or his or her representative’s request. This period may be extended, but by no more than five working days. To this end the Operator shall send to the Data Subject a reasoned notification specifying the reasons for extending the period for providing the requested information. The information provided shall not include Personal Data relating to other Data Subjects, unless there are lawful grounds for the disclosure of such Personal Data.
The Data Subject’s request must contain:
The Data Subject’s request may be submitted in the form of an electronic document signed with an electronic signature in accordance with the legislation of the Russian Federation.
The Operator provides the information specified in paragraph 7, Article 14 of the Personal Data Law to the Data Subject or his or her representative in the same form in which the corresponding request was made, unless otherwise specified in the request.
If the request of the Data Subject does not include all the information required under the Personal Data Law or if the Data Subject does not have the right of access to the requested information, the Data Subject shall be sent a reasoned refusal.
The Data Subject’s right of access to his or her Personal Data may be restricted in accordance with paragraph 8, Article 14 of the Personal Data Law, including when the Data Subject’s access to his or her Personal Data violates the rights and legitimate interests of third parties.
The Operator independently determines the composition and list of measures necessary and sufficient to ensure the performance of obligations stipulated by the Personal Data Law and by regulatory legal acts adopted pursuant thereto, unless otherwise provided by the Personal Data Law or other federal laws.
At LLC AC “RNC Pharma” the following measures are taken to ensure compliance with the obligations stipulated by the Personal Data Law in the field of Personal Data Processing:
The Personal Data protection system of LLC AC “RNC Pharma” comprises a set of legal, organizational and technical measures aimed at neutralizing current threats to Personal Data security during their Processing.
Measures to ensure the security of Personal Data during their Processing in Personal Data Information Systems of LLC AC “RNC Pharma” are determined and applied taking into account the established levels of security of Personal Data during their Processing in Personal Data Information Systems of LLC AC “RNC Pharma” in accordance with Decree of the Government of the Russian Federation No. 1119 of 01 November 2012 “On the Approval of Requirements for the Protection of Personal Data during their Processing in Personal Data Information Systems”. The selection and implementation of protection tools within the Personal Data protection system during their Processing in Personal Data Information Systems of LLC AC “RNC Pharma” are carried out in accordance with the requirements of the legislation of the Russian Federation in the field of Personal Data.
Protection of Personal Data during their Processing in Personal Data Information Systems of LLC AC “RNC Pharma” against unlawful or accidental access, Destruction, modification, Blocking, copying, Provision, Dissemination, as well as against other unlawful actions with respect to Personal Data, is ensured by the application of an interrelated set of measures and protection tools, in particular:
Control over compliance with the requirements of this Policy is exercised by the authorized person – the Person Responsible for the Organization of Personal Data Processing at the Operator.
Persons found guilty of violating the rules governing Personal Data Processing and the protection of Personal Data processed at LLC AC “RNC Pharma” bear liability as stipulated by the legislation of the Russian Federation.
APPENDIX 1
List of purposes of Personal Data Processing and the corresponding categories and list of Personal Data processed, and categories of Data Subjects whose Personal Data are processed
This Appendix defines the purposes of Personal Data Processing by the Operator and the corresponding categories and list of Personal Data processed, as well as the categories of Data Subjects whose Personal Data are processed.
The Operator may process Personal Data of the following categories of Data Subjects:
surname, first name, patronymic; year of birth; month of birth; date of birth; place of birth; marital status; social status; property status, income; gender; email address; home address; registered address; telephone number; SNILS (individual insurance account number); taxpayer identification number (INN); citizenship; identity document details; driving license details; identity document details valid outside the Russian Federation; details contained in a birth certificate; bank card details; current account number; personal account number; occupation; position; information about employment history (including years of service, current employment details with indication of the name and current account of the organization); military liability and military registration data; information about education.
Other Personal Data – information about family composition; social benefits; information about additional guarantees and compensations on grounds provided for by the legislation of the Russian Federation; information about previous workplaces; information about business trips; data on transfers; information about dismissal (termination of an employment contract); data on incentive decisions and disciplinary actions; data on vacations; working schedule and conditions; data on qualification or special knowledge, including professional development and retraining; knowledge of foreign languages; data on awards, honorary titles; information on hours worked; information on vacation payments; information on temporary incapacity; sick-leave certificate data; information on the amount of temporary incapacity benefits; information on participation in legal entities; information on alimony and other financial obligations; information on briefings; messenger address; social network profile address.
surname, first name, patronymic; year of birth; month of birth; date of birth; place of birth; marital status; social status; property status, income; gender; email address; home address; registered address; telephone number; SNILS; INN; citizenship; identity document details; driving license details; identity document details valid outside the Russian Federation; details contained in a birth certificate; occupation; position; information about employment history (including years of service, current employment details with indication of the name and current account of the organization); military liability and military registration data; information about education.
Other Personal Data – data on qualification or special knowledge, including professional development and retraining; knowledge of foreign languages; social benefits; information about additional guarantees and compensations on grounds provided for by the legislation of the Russian Federation; information about previous workplaces; information about business trips; employment record book data; data on incentive decisions and disciplinary actions; information about dismissal; working schedule and conditions at previous workplaces; data on transfers at previous workplaces; data on awards, honorary titles; messenger address; social network profile address; information on professional and other personal qualities of an evaluative nature; data on hobbies/interests.
surname, first name, patronymic; year of birth; month of birth; date of birth; place of birth; marital status; income; gender; email address; home address; registered address; telephone number; SNILS; INN; citizenship; identity document details; occupation; position.
surname, first name, patronymic; month of birth; date of birth; year of birth; income; gender; home address; SNILS; INN; citizenship; identity document details; information about employment history (including years of service, current employment details with indication of the name and current account of the organization).
surname, first name, patronymic; year of birth; month of birth; date of birth; place of birth; gender; email address; home address; registered address; telephone number; SNILS; INN; citizenship; identity document details; position.
Other Personal Data – place of work; information on voluntary medical insurance; compulsory medical insurance policy; birth certificate data; marriage certificate data; policy type; insurance contract details.
surname, first name, patronymic; year of birth; month of birth; date of birth; gender; identity document details; position; driving license details; vehicle data.
surname, first name, patronymic; year of birth; month of birth; date of birth; place of birth; marital status; social status; property status, income; gender; email address; home address; registered address; telephone number; SNILS; INN; citizenship; identity document details; driving license details; identity document details valid outside the Russian Federation; details contained in a birth certificate; bank card details; current account number; personal account number; occupation; position; information about employment history (including years of service, current employment details with indication of the name and current account of the organization); military liability and military registration data; information about education.
Other Personal Data – place of work, structural subdivision; information contained in a power of attorney; messenger address; social network profile address; details of registration as an individual entrepreneur in the Unified State Register of Individual Entrepreneurs; information on affiliation, including family composition; data from documents on education, qualification or special knowledge, including professional development and retraining; knowledge of foreign languages; tax return data; tax payment data; information on tax deduction; information on the amount of accrued and paid insurance contributions for compulsory pension insurance; information on contributions to the Federal Tax Service; information on the person performing the duties of an accountant; information on licenses; information on participation in legal entities; information on pending court cases; data from a certificate of self-employed status; data contained in a civil-law contract and in additional agreements thereto: amount of remuneration, schedule and conditions for performing work or providing services; information on professional and other personal qualities of an evaluative nature.
surname, first name, patronymic; year of birth; month of birth; date of birth; place of birth; income; gender; email address; home address; registered address; telephone number; SNILS; INN; citizenship; identity document details; position; information about employment history (including years of service, current employment details with indication of the name and current account of the organization).
surname, first name, patronymic; year of birth; month of birth; date of birth; gender; bank card details; current account number; personal account number; occupation; position; information about employment history (including years of service, current employment details with indication of the name and current account of the organization).
surname, first name, patronymic; year of birth; month of birth; date of birth; gender; email address; home address; registered address; telephone number; SNILS; INN; citizenship; identity document details; occupation; position; information about employment history (including years of service, current employment details with indication of the name and current account of the organization); information about education.
surname, first name, patronymic; email address; telephone number.
surname, first name, patronymic; specialty; work experience in the specialty; place of work; position; date of commencement of work; duration of work; address of place of work; business telephone; business email.
The Operator does not Process Special Categories of Personal Data concerning race, nationality, political views, religious or philosophical beliefs, state of health or intimate life.
Leave your contact details and we will contact you