GENERAL PROVISIONS
1.1. The regulation on the procedure for processing personal data of GRADUS RESEARCH PLUS LLC (hereinafter referred to as the Regulation) has been developed in accordance with the European legislation, the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679) and the legislation of Ukraine regarding ensuring the protection of personal data, taking into account the requirements:
– Constitution of Ukraine;
– Economic Code of Ukraine;
– Civil Code of Ukraine;
– Law of Ukraine “On personal data protection”;
– Law of Ukraine “On information”;
– Standard procedure for processing personal data approved by Order No. 1/02-14 of the Verkhovna Rada Commissioner for Human Rights on 08.01.2014;
1.2. The regulation defines the requirements of GRADUS RESEARCH PLUS LLC (hereinafter referred to as the Company) for the processing and procedure for ensuring the protection of personal data of personal data subjects at all stages of their processing, including through organizational and technical measures.
1.3. The Regulation applies to an indefinite range of persons – subjects of personal data who enter into or may enter into any relations with the Company.
1.4. The Regulation is published on the Company’s official website (http://gradus.app) on the Internet for the purpose of familiarizing the subjects of personal data, whose data is processed by the Company during the implementation of its statutory activities.
1.5. The Regulation defines the list of measures aimed at the security of personal data, taking into account the requirements of legislation in the fields of personal data protection and information security.
DEFINITION OF TERMS AND ABBREVIATIONS
2.1. Personal data database – a named set of ordered personal data in electronic form and/or in the form of personal data files;
2.2. Biometric data – personal data obtained as a result of special technical processing related to physical, physiological or behavioral characteristics of a natural person, such as a face image or fingerprint data that allow unambiguous identification or confirm the unambiguous identification of a natural person;
2.3. Owner of personal data – a natural or legal person who determines the purpose of processing personal data, establishes the composition of this data and the procedures for their processing, unless otherwise specified by law;
2.4. Health data – personal data related to the state of physical or mental health of a natural person, including the provision of medical services that reflect information about his or her health status;
2.5. Controller means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; if the purposes and means of such processing are determined by Union or Member State law, the controller or special criteria for its appointment may be provided for by Union or Member State law (in accordance with European legislation, the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679));
2.6. Use of pseudonyms – processing of personal data in such a way that personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is stored separately, and it is subject to the use of technical and organizational tools to ensure that personal data is not attributed to a natural person who is identified or can be identified;
2.7. Genetic data – personal data concerning the innate or acquired genetic characteristics of a natural person, providing unique information about the physiology or health of such a natural person and those that are obtained, in particular, as a result of the analysis of a biological sample taken from the relevant natural person;
2.8. Consent of the personal data subject – any freely provided, specific, informed and unambiguous indication of the wishes of the data subject, by which he or she, by making an application or by showing clear affirmative actions, confirms consent to the processing of his or her personal data;
2.9. Depersonalization of personal data – withdrawal of information that allows to directly or indirectly identify a person;
2.10. Information system – hereinafter referred to as IS) is a set of Information Resources, data transmission environment, service personnel and organizational measures used by the Company to meet its information needs;
2.11. Information – any information and/or data that can be stored on Tangible Media or displayed in electronic form;
2.12. Personal data (hereinafter referred to as PD) – any information relating to a natural person who is identified or can be identified (the “data subject”); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by identifiers such as a name, an identification number, location data, an online identifier or by one or more factors determining the physical, physiological, genetic, mental, economic, cultural or social identity of such a natural person;
2.13. Categories – generalized groups of personal data of relevant subjects;
2.14. Client (User) – a personal data subject (a natural person or a representative of such a person) who acts as a participant in sociological and marketing research based on depersonalized data and can also be a recipient of remuneration for participation in surveys provided by the Company and whose personal data is processed by the Company when providing such services;
2.15. Counterparty – a subject of personal data (a natural person, an individual entrepreneur, a representative of a legal entity acting in civil and economic relations with the Company;
2.16. Confidential information (hereinafter referred to as CI) – information that is subject to a non-disclosure. The CI includes information about a natural person, as well as information, access to which is restricted by a natural or legal person, except for subjects of public authorities. CI may be distributed at the request (consent) of the relevant person in accordance with the procedure determined by it in accordance with the conditions provided for by it, as well as in other cases determined by law;
2.17. User – a person engaged by the Company to perform relevant functions or an employee of the Company who uses the information resources of the Company’s IS to perform official duties;
2.18. Processing of personal data means any operation or series of operations with personal data or sets of personal data, with or without automated means, such as collection, registration, organization, structuring, storage, adaptation or modification, retrieval, examination, use, disclosure by transmission, dissemination or otherwise, arrangement or combination, restriction, erasure or destruction;
2.19. Restriction of processing – designation of stored personal data in order to restrict their processing in the future;
2.20. Transaction – any agreement to which the Company is a party, regardless of its form and subject matter, including appendices, additions to it, agreements on amendments to it, documents confirming actions aimed at concluding, executing, modifying and terminating any of these transactions;
2.21. Employee – a natural person who directly performs an employment function by his own work in accordance with an employment contract (agreement) concluded with the Company and/or a natural person who performs cash operations for the Company on the basis of an agreement concluded with another business entity on the provision of Personnel Services;
2.22. Personal data protection breach – a security breach that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data that is transmitted, stored or otherwise processed;
2.23. Profiling – any form of automated processing of personal data, consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects relating to the data subject’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movement;
2.24. Personal data administrator – a natural or legal person who is granted the right by the owner of personal data or by law to process this data on behalf of the owner;
2.25. Processor – a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller (in accordance with European legislation on the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679);
2.26. Personal data subject is a natural person whose personal data is processed;
2.27. Personal data processing period means the period during which the Company processes personal data of the personal data subject, which is calculated from the moment the Company receives personal data and consent to the processing of personal data and does not exceed the period necessary to achieve the purpose of processing and the period determined by the legislation of Ukraine in the field of archiving and record keeping;
2.28. Third party is a natural or legal person, public authority, agency or body that is not a data subject, controller, processor and persons who, under the direct supervision of the controller or processor, are authorized to process personal data;
MAIN PART
3.1. Processing of personal data in the Company.
3.1.1.PD processed by the Company is classified as confidential information.
3.1.2. The Company is the owner of the PD, and in cases stipulated by the current legislation of Ukraine, and/or on the basis of concluded contracts with Ukrainian and foreign companies, the Company is the manager of the PD.
3.1.3. In accordance with European legislation on the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679) the company is a PD controller, and/or on the basis of concluded contracts with Ukrainian and foreign companies, the Company is a PD processor.
3.1.4. The company processes PD accumulated in PD databases.
3.1.5. The procedure for processing PD in the Company is determined by this Regulation on the basis of the current legislation of Ukraine and European legislation on General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
3.1.6. The primary sources of information about a natural person are documents issued in his/her name, documents signed by him/her, and information that the person provides about himself/herself.
3.1.7. Processes (subprocesses, procedures) of PD processing are part of the Company’s business processes of data processing can be automated or non-automated.
3.1.8. The Company processes PD that can be combined into PD databases.
3.1.9. The Company may entrust the processing of PD to the PD manager in accordance with a written agreement. The PD manager can process the PD only for the purposes and to the extent specified in the contract.
3.1.10. In all cases not regulated by this Regulation, it is necessary to follow the current legislation of Ukraine and the European legislation on the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
3.2. Requirements and grounds for PD processing
3.2.1 PD is processed in a legal, lawful and transparent manner in relation to the data subject (legality, lawfulness and transparency).
3.2.2. PD are collected for specific, clear and legitimate purposes and is not further processed in a way that is incompatible with such purposes. Further processing to achieve public interest purposes, scientific or historical research purposes or statistical purposes cannot be considered incompatible with the original purposes (purpose limitation).
3.2.3 The Company processes PD that are considered sufficient and appropriate and limited to the extent of their necessity in view of the purposes of processing (data minimization).
3.2.3. Personal data is considered accurate and, if necessary, updated to ensure that inaccurate personal data, given the purposes for which it is processed, is erased or corrected without delay (accuracy).
3.2.4 The Company stores PD in a form that allows the identification of data subjects no longer than necessary for the purposes of their processing (storage restrictions).
3.2.5. The composition and content of PD processed by the Company must be appropriate, adequate and not excessive in relation to the specific purpose of their processing.
3.2.6. The term of PD processing is set by the Company depending on the category of PD subjects, the purpose of PD processing and is determined by the current legislation of Ukraine and European legislation on the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
3.2.7. The grounds for processing personal data are:
3.2.7.1. Consent of the PD subject to the processing of his/her personal data;
3.2.7.2. The permission to process the PD granted to the owner (controller) of the PD in accordance with the law solely for the exercise of its powers;
3.2.7.3. Conclusion and execution of a transaction to which the PD subject is a party or which is concluded in favor of the PD subject or for the implementation of measures preceding the conclusion of the transaction at the request of the PD subject;
3.2.7.3. Protection of vital interests of the PD subject;
3.2.7.4. The need to fulfill the obligation of the owner (controller) of the PD, which is provided for by law;
3.2.7.5. The need to protect the legitimate interests of the owner (controller) of the PD or a third party to whom the PD is transferred, unless the need to protect the fundamental rights and freedoms of the PD subject in connection with the processing of his/her data outweighs such interests.
3.3. Categories of PD subjects
3.3.1. The Company processes PD of the following categories of PD subjects:
– clients (natural persons and representatives of such persons);
– counterparties (entities that are in civil and economic relations with the Company – representatives of a legal entity, individual entrepreneurs or natural persons without the status of an economic entity);
– employees.
3.4. PD using
3.4.1.The use of PD involves any actions of the Company regarding the processing of these data, their protection, as well as granting partial or full right to process PD to other subjects of relations related to PD, carried out with the consent of the PD subject or in accordance with the Law of Ukraine “On Personal Data Protection” and European legislation on General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
3.4.2 For the proper use of PD, the Company has created conditions for their protection.
3.5. Collection of PD
3.5.1. The collection of PD is a component part of the process of their processing, which involves actions to select or organize information about the subject of personal data.
3.5.2. The subject of personal data is notified in the manner provided for in this Regulation about the owner (controller) of the PD, the composition and content of the collected PD, their rights defined by the current legislation of Ukraine and the European legislation on the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679), the purpose of collecting PD and the persons to whom his/her personal data is transferred.
3.5.3. Obtaining the consent of the PD subject and notifying him/her about the processing of the PD is not performed if the PD was collected from publicly available sources.
3.6. Procedure for access to the PD for the subject of relations related to the PD
3.6.1. The procedure for access to the personal data of third parties is determined by the law of Ukraine “On personal data protection” and the European legislation on the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
3.6.2. The Company provides the PD subject with information about the processing of his/her PD free of charge, except in cases established by law.
3.6.3.The PD subject has the right to receive his/her PD, which he/she has provided to the Company, in a structured, commonly used and easily machine-readable format and has the right to transfer such data to another controller/manager (processor)
3.7. PD deleting or destroying
3.7.1. PD is deleted or destroyed in accordance with the procedure established in accordance with the requirements of current legislation.
3.7.2. PD is subject to deletion or destruction in the event of:
– expiration of the data storage period determined by the consent of the PD subject to the processing of this data, unless otherwise provided by law;
– termination of legal relations between the subject of PD and the Company, unless otherwise provided by law;
– issuance of the relevant order of the Supervisory Authority or its designated officials;
– entry into legal force of a court decision on deletion or destruction of the PD.
3.7.7. Personal data that does not correspond to reality must be immediately changed or destroyed.
3.7.8. Deletion and destruction of PD is carried out in a way that excludes the possibility of their renewal.
3.8. Distribution of PD
3.8.1. Distribution of PD provides for actions to transfer information about a natural person with the consent of the subject of PD.
3.8.2. Distribution of PD without the consent of the PD subject or a person authorized by it is allowed in cases defined by law, and only (if necessary) in the interests of national security, economic well-being and Human Rights.
3.8.3. Compliance with the requirements of the established PD protection regime is ensured by the party that distributes this data.
3.8.4. The party to which the PD is transferred must first take measures to ensure the requirements of the current legislation.
3.8.5. The transfer of PD to foreign subjects of relations related to PD is carried out only if the relevant state ensures proper protection of PD in cases established by law or an international treaty of Ukraine.
3.8.6. PD may not be distributed for a purpose other than the one for which they were collected.
3.8.7. PD may be transferred to foreign subjects of relations related to PD, also in the case of:
– providing an unambiguous consent to such transfer by PD subject;
– the need to conclude or execute a transaction between the owner (controller) of the PD and a third party – the subject of the PD in favor of the subject of the PD;
– the need to protect the vital interests of PD subjects;
– the need to protect the public interest, establish, comply with and ensure the legal requirement;
– provision by the owner (controller) of the PD of appropriate guarantees regarding non-interference in the personal and family life of the subject of the PD.
3.9. PD transfer
3.9.1. The Company has the right to transfer the PD of PD subjects included in the categories “clients”, “counterparties” and “employees” to such third parties (including, but not exclusively):
– enterprises, institutions and organizations of all forms of ownership, state authorities or local self-government bodies, individual entrepreneurs who have been granted or will be granted the right to process personal data by the Company or the current legislation;
– third parties involved by the Company and / or participating in the Company’s provision of Sociological and Marketing Research Services;
– archival institutions and other persons providing the Company with information and document storage services and related services;
– participants, affiliates of the Company, persons having material shareholder in the Company and/or exercising control over the Company;
– to other natural persons and organizations to ensure the performance by the latter of their functions or provision of services to the Company / by theCompany in accordance with the transactions concluded between such persons (organizations) and the Company.
3.10. Notification of PD transfer
3.10.1. The Company notifies the subject of the PD of the transfer of the PD to a third party within ten business days, except in the following cases:
– transfer of PD on requests when performing tasks of Active Search or counterintelligence activities, combating terrorism;
– performance by state authorities and local self-government bodies of their powers provided for by law;
– implementation of PD processing for historical, statistical or scientific purposes;
– the PD subject was notified of the possibility of such a transfer at the time of collecting the PD
3.11. Providing PD protection
3.11.1. Ensuring the safety of PD in the Company is based on the following fundamental principles:
– the principle of minimum powers: access to the PD should be organized in such a way as to grant only those powers that are sufficient to perform official tasks and duties;
– the principle of explicit authorization of actions: actions of the Company’s employees related to PD, that are not directly provided for by the Company’s internal organizational, administrative or regulatory documents, are prohibited;
– the principle of legality: the Company takes into account the requirements of the current legislation of Ukraine related to the security of personal data;
– principle of responsibility: the Company’s management, as well as employees, business partners and any third parties who have or have had access to personal data, must comply with the requirements of regulatory documents and legislation of Ukraine and European legislation on General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
– the principle of comprehensiveness and consistency: the protection of personal data in the Company is ensured at the legal, administrative, organizational, software and hardware levels, as well as through the integrated use of information security tools and the interaction of all departments of the Company with each other.
3.11.2. The Company takes measures to ensure the protection of PD at all stages of their processing through organizational and technical measures.
3.11.3. PD Protection provides for measures aimed at preventing their accidental loss or destruction, illegal processing, including illegal destruction or access to PD.
PROCESSING OF PERSONAL DATA OF SUBJECTS OF THE CATEGORY “CLIENTS (USERS)”
4.1. In the category “Clients” (Users), the Company processes the PD of PD subjects (natural persons and their authorized representatives) who are participants in sociological and marketing research provided by the Company.
4.2. PD of subjects of the category “Clients” (Users) are processed for the purposes of conducting sociological and marketing research based on depersonalized data, as well as providing the participant with remuneration for participation in surveys
4.3. The company and compliance with the requirements of the legislation of Ukraine and European legislation on the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679).
4.4. The purpose of processing the PD of subjects of this category is:
● ensuring the registration of the Client (User) in the Company’s mobile application and on the Company’s official website (https://gradus.app/uk/ );
● improving the functioning of the Company’s Mobile App;
● creating, selecting, and sending surveys/testing and suggestions to express their own opinion to the Client (User) by the mobile app;
● analysis of survey/testing results and identification of one’s own opinion in order to summarize the indicators of various Clients (Users) to illustrate a particular point of view in society and transmit such results to the persons who ordered the analysis;
● prevention of fraud and other illegal actions of Customers (Users);
● conducting surveys/tests and sending suggestions to identify their own opinion, in particular with the involvement of third parties;
● send news messages in the Company’s Mobile App
● ability to use a phone to communicate and provide incentives;
● providing communication with Clients (Users);
● communication with the Client( User), including sending messages, requests and information related to the use of the Company’s official website (https://gradus.app/uk/) and / or a mobile app, newsletters and advertising information about Products, Services, Special Offers;
● sending service messages (for example, to restore the password for accessing the Client’s (User’s) account) in the Company’s mobile application or on the company’s official website (https://gradus.app/uk/ );
● preparation of statistical, administrative and other reporting information on the Company’s activities in accordance with the requirements of the legislation;
● compliance with tax legislation requirements;
4.5. Composition of PD processed by the Company in the “Clients” category (including, but not limited to):
● email address for registration in the Company’s mobile app and on the Company’s official website (https://gradus.app/uk/ );
● name and / or nickname;
● photo (in case of authorization via a social network);
● gender;
● date of birth;
● age;
● region and / or locality of residence;
● device and / or operating system of the Client (User);
● phone number;
● geolocation of the Client (User);
● data from the contact list, if the user has given permission to access it;
● The IP address from which the Company’s mobile application and/or official website were accessed (https://gradus.app/uk/ );
NOTIFICATION ON THE RIGHTS OF THE PERSONAL DATA SUBJECT
5.1. The Company notifies personal data subjects of their rights as personal data subjects stipulated in Article 8 of the law of Ukraine “On personal data protection” and the European legislation of the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679), including:
– know about the sources of collection, the location of their PD, the purpose of their processing, the location or place of residence (stay) of the owner (controller) or administrator (processor) of the PD, or give appropriate instructions to obtain this information to persons authorized by them, except in cases established by law;
– receive information about the conditions for granting access to PD, in particular information about third parties to whom their PD is transferred;
– to access to their PD;
– receive no later than thirty calendar days from the date of receipt of the request, except in cases provided for by law, a response on whether their PD are processed, as well as the content of such PD;
– submit a reasoned request to change or destroy their PD by any owner (controller) and administrator (processor) of the PD, if this data is processed illegally or is unreliable;
– to protect their personal data from illegal processing and accidental loss, destruction, damage due to deliberate concealment, failure to provide or untimely provision of them, as well as to protect them from providing information that is unreliable or discredits the honor, dignity and goodwill of a natural person;
– right to file a complaint with the Supervisory Authority;
– apply legal remedies in case of violation of the legislation on the protection of PD;
– make reservations regarding the restriction of the right to process their PD when giving consent;
– the right to erase their PD, which must be carried out by the Administrator (Controller) without any unjustified delay;
– withdraw consent to the processing of PD, except in the case of processing of PD in connection with the Fulfillment by the owner (controller) of the PD of the obligation provided for by law;
– know the mechanism of automatic processing of their PD;
– to protect against an automated decision that has legal consequences for them.
FINAL PROVISIONS
The Company takes measures to ensure the protection of PD at all stages of their processing.
The Company independently determines the list and composition of measures aimed at the safety of PD processing, taking into account the requirements of legislation in the areas of PD protection and information security.
Protection of PD includes measures aimed at preventing their accidental loss or destruction, illegal processing, including illegal destruction or access to PD.
PD, depending on the method of their storage (paper, electronic media), should be processed in such a way as to exclude access to them by unauthorized persons.
This regulation (its subsequent revisions) is published on the Company’s official website at: https://gradus.app/uk/