Personal Data Protection and Processing Policy
Revision of 01.07.2025
1. General Provisions
1.1. This Policy regarding the processing of personal data (hereinafter referred to as the "Policy") has been drawn up in accordance with paragraph 2 of Article 18.1 of the Federal Law "On Personal Data" No. 152-FZ of July 27, 2006, as well as other regulatory legal acts of the Russian Federation in the field of personal data protection and processing, and applies to all personal data (hereinafter referred to as "data") that the organization (hereinafter referred to as the "Operator", "Company", "Website") may receive from a personal data subject who is a party to a civil law contract, from an Internet user (hereinafter referred to as the "User") while using any of the sites, services, programs, products or services of motoram.ru, as well as from a personal data subject who is in a relationship with the Operator governed by labor law (hereinafter referred to as the "Employee").
1.2. The Operator ensures the protection of processed personal data from unauthorized access and disclosure, unlawful use or loss in accordance with the requirements of Federal Law No. 152-FZ of July 27, 2006 "On Personal Data".
1.3. The Operator has the right to amend this Policy. When amendments are made, the date of the last update of the revision is indicated in the header of the Policy. The new version of the Policy comes into force from the moment it is posted on the website, unless otherwise provided by the new version of the Policy.
2. Terms and Abbreviations
- Personal data — any information relating directly or indirectly to a specific or definable natural person (personal data subject).
- Processing of personal data — any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data.
- Automated processing of personal data — processing of personal data using computer technology.
- Personal data information system (PDIS) — a set of personal data contained in databases and information technologies and technical means that ensure their processing.
- Publicly available personal data — data that is made accessible by the personal data subject or at his request.
- Blocking of personal data — temporary suspension of the processing of personal data.
- Destruction of personal data — actions that make it impossible to restore the content of personal data.
- Operator — an organization that independently or jointly with other persons organizes the processing of personal data.
3. Processing of Personal Data
3.1. Obtaining Personal Data
3.1.1. All personal data should be obtained from the subject himself. If data is obtained from third parties, the subject must be notified.
3.1.2. The subject is informed of the purposes, sources, methods of obtaining data, a list of actions with them, the term of validity of the consent and the consequences of refusal.
3.1.3. Documents containing personal data are created by copying originals, entering information into forms, obtaining originals.
3.2. Data Processing
3.2.1. Data processing is possible:
- with the consent of the subject;
- in accordance with the legislation of the Russian Federation;
- if the data is made publicly available by the subject.
3.2.2. Processing purposes:
- labor and civil law relations;
- communication with website users;
- statistical processing of anonymized data.
3.2.3. Categories of subjects:
- employees and job applicants;
- website users;
- contractors under contracts.
3.2.4. Processed data categories:
- information obtained during labor and civil law relations;
- data obtained from motoram.ru users.
3.2.5. Processing can be carried out both with and without automation.
3.3. Data Storage
3.3.1. Storage — on paper and in electronic form.
3.3.2. Paper documents are stored in rooms with limited access.
3.3.3. Electronic data is stored in separate folders by purpose.
3.3.4. Documents with personal data are not placed in open directories.
3.3.5. Data is destroyed upon reaching the processing goals or loss of necessity.
3.4. Data Destruction
3.4.1. Destruction of paper media: burning, shredding, chemical treatment.
3.4.2. Electronic media: erasing, formatting.
3.5. Data Transfer
3.5.1. Data is transferred:
- with the consent of the subject;
- on the grounds established by law.
3.5.2. Data recipients:
- Pension Fund of the Russian Federation;
- Tax authorities;
- FSS;
- FOMS;
- Medical insurance organizations;
- Banks (for payroll);
- Internal Affairs bodies;
- Counterparties (anonymized data of website users).
4. Protection of Personal Data
4.1. A personal data protection system (PDPS) has been created, including legal, organizational and technical subsystems.4.2. Legal protection — a set of regulatory documents.4.3. Organizational protection — management structure, access rules, work with personnel.4.4. Technical protection — software and hardware protection tools.
Basic protection measures:
- Appointment of a person responsible for the processing of personal data;
- Assessment of current threats and implementation of protection measures;
- Development and compliance with the data processing policy;
- Rules for access to the PDIS, registration of actions;
- Individual access passwords;
- Use of certified information security tools;
- Antivirus protection with regular updates;
- Counteraction to unauthorized access and data recovery;
- Training of personnel on the processing and protection of personal data;
- Internal control and audit.
5. Rights of Subjects and Obligations of the Operator
5.1. Rights of the Subject
The subject has the right:
- to access their data;
- to information about processing, purposes, terms, sources of data;
- to information about persons who have access to data;
- to contact the Operator;
- to appeal against the actions of the Operator.
5.2. Obligations of the Operator
The operator is obliged:
- to inform the subject when collecting data;
- to notify the subject if the data was not received from him;
- to explain the consequences of refusing to provide data;
- to publish the data processing policy;
- to ensure the protection of data from illegal actions;
- to respond to requests from subjects and authorized bodies.