On this page
PERSONAL DATA PROCESSING POLICY
concerning users of the “HiMerce” Application
1. GENERAL PROVISIONS
1.1. This Personal Data Processing Policy for the “HiMerce” Application (hereinafter, the “Policy”) has been developed pursuant to the requirements of Clause 2, Part 1, Article 18.1 of Federal Law No. 152-FZ dated 27 July 2006 “On Personal Data” (hereinafter, the “Personal Data Law”) for the purpose of ensuring the protection of human and civil rights and freedoms during the processing of Personal Data, including the protection of the rights to privacy and personal and family confidentiality.
1.2. This Policy applies to Personal Data processed by Shenzhen Gaea Information Co., Ltd, incorporated under the laws of the People’s Republic of China (hereinafter, the “Operator”), in the “HiMerce” mobile application (hereinafter, the “Application”), which the Operator may receive from the Personal Data Subject.
1.3. This Policy applies to relations in the field of Personal Data processing that arose with the Operator both before and after the approval of this Policy.
1.4. Pursuant to the requirements of Part 2 of Article 18.1 of the Personal Data Law, this Policy is published in free access on the Internet at the following link: https://www.cosori.cloud/privacy/.
1.5. The Operator does not verify the accuracy of Personal Data received from the Personal Data Subject.
1.6. The Operator ensures the protection of processed Personal Data against unauthorized access and disclosure, unlawful use, or loss in accordance with the requirements of the Personal Data Law.
1.7. The Personal Data Subject agrees to this Policy by providing consent to the processing of Personal Data.
2. TERMS AND DEFINITIONS
2.1. For the purposes of application and interpretation of this Policy, the principal terms defined below shall be used (unless expressly stated otherwise in the Policy). In the text of the Policy, these terms may be used with an uppercase or lowercase letter, in the singular or plural, and in abbreviated form.
2.1.1. Personal Data means any information relating directly or indirectly to an identified or identifiable individual (Personal Data Subject);
2.1.2. Personal Data Operator means Shenzhen Gaea Information Co., Ltd, a company incorporated under the laws of the People’s Republic of China, Unified Social Credit Code (USCC): 91440300MA5HB76T6K, registered address: Room 1408, 14F, Tianjian Chuangye Building, No.7 Shangbao Road, Shiling Community, Lianhua Sub-district, Futian District, Shenzhen, Guangdong Province, China, which owns the Application and independently or jointly with other persons organizes and/or carries out the processing of Personal Data, and also determines the purposes of Personal Data processing, the composition of Personal Data subject to processing, and the actions (operations) performed with Personal Data;
2.1.3. Subject, Personal Data Subject means an individual using the Application whose Personal Data is processed by the Operator or by a third party on behalf of the Operator;
2.1.4. Application means a computer program in the form of a mobile application named “HiMerce”, made available through the official RuStore platform for the distribution of such computer programs, the primary functionality of which includes:
- registration, login, and account management;
- discovery, addition, connection, binding, unbinding, management, and control of smart devices;
- connection of smart devices to networks, network configuration, status viewing, and status synchronization;
- firmware updates, update status checks, and error notifications;
- browsing recipes and other content, adding items to favorites, and using other related content services;
- submission of feedback, issue reports, obtaining assistance, and customer support.
2.1.5. Processing of Personal Data means any action (operation) or set of actions (operations) with Personal Data performed using automation tools or without the use of such tools. Processing of Personal Data includes, inter alia:
2.1.5.1. collection;
2.1.5.2. recording;
2.1.5.3. systematization;
2.1.5.4. accumulation;
2.1.5.5. storage;
2.1.5.6. clarification (updating, modification);
2.1.5.7. extraction;
2.1.5.8. use;
2.1.5.9. transfer (provision to a limited group of persons; access by a limited group of persons);
2.1.5.10. dissemination;
2.1.5.11. anonymization;
2.1.5.12. blocking;
2.1.5.13. deletion;
2.1.5.14. destruction.
2.1.6. Storage of Personal Data means a process involving the retention of Personal Data in a systematized form at the disposal of the Operator.
2.1.7. Collection of Personal Data means a targeted process of obtaining Personal Data by the Operator directly from Personal Data Subjects.
2.1.8. Automated Processing of Personal Data means processing of Personal Data with the use of computer technology;
2.1.9. Non-Automated Processing of Personal Data means processing of Personal Data contained in a Personal Data information system or extracted from such system, which is deemed to be carried out without the use of automation tools (non-automated) if such actions with Personal Data as use, clarification, dissemination, and destruction of Personal Data in relation to each Personal Data Subject are carried out with the direct participation of a person;
2.1.10. Mixed Processing of Personal Data means processing by a person with the assistance of computer technology;
2.1.11. Provision of Personal Data means actions aimed at disclosing Personal Data to a specific person or a specific group of persons;
2.1.12. Blocking of Personal Data means the temporary suspension of the processing of Personal Data (except where processing is necessary to clarify Personal Data);
2.1.13. Destruction of Personal Data means actions as a result of which it becomes impossible to restore the content of Personal Data in the Personal Data information system and/or as a result of which material media containing Personal Data are destroyed;
2.1.14. Anonymization of Personal Data means actions as a result of which it becomes impossible, without the use of additional information, to determine whether Personal Data belongs to a specific Personal Data Subject;
2.1.15. Personal Data Information System (hereinafter, “PDIS”) means a set of Personal Data contained in databases and information technologies and technical means ensuring their processing.
2.1.16. Cross-Border Transfer of Personal Data means the transfer of Personal Data to the territory of a foreign state, to an authority of a foreign state, a foreign individual, or a foreign legal entity.
3. CONDITIONS OF PERSONAL DATA PROCESSING
3.1. Processing of the Subject’s Personal Data by the Operator is carried out by means using automation tools or without such tools for the periods necessary to achieve the processing purposes. A condition for termination by the Operator of processing of Subjects’ Personal Data may be the achievement of the purposes of such processing, withdrawal by the Subject of consent to the processing of their Personal Data, withdrawal of consent to dissemination of Personal Data, termination of the Operator’s activities (reorganization or liquidation), closure of the Application, termination of the agreement between the Operator and the Subject, dismissal of the Operator’s employee, or identification of the fact of unlawful processing thereof.
3.2. The Operator’s policy regarding the processing of Subjects’ Personal Data is that Personal Data must be processed only in cases established by law, based on the Operator’s principal areas of activity and taking into account the balance of interests of the Operator and the Subject. Processing of Personal Data by the Operator is carried out taking into account the need to ensure the protection of the rights and freedoms of the Subject, including the protection of the right to privacy and personal and family confidentiality, based on the following principles:
3.2.1. Personal Data shall be processed by the Operator on a lawful and fair basis;
3.2.2. Personal Data processing shall be limited to the achievement of specific, predetermined, and lawful purposes;
3.2.3. Personal Data processing incompatible with the purposes of collecting Personal Data shall not be permitted;
3.2.4. only Personal Data that meets the purposes of its processing shall be subject to processing;
3.2.5. the content and scope of processed Personal Data shall correspond to the stated processing purposes; excessive processed Personal Data in relation to the stated purposes of its processing shall not be permitted;
3.2.6. Personal Data shall be stored in a form that permits identification of the Subject for no longer than required by the purposes of Personal Data processing. Processed Personal Data shall be destroyed upon achievement of the processing purposes or in the event of loss of the need to achieve such purposes, unless otherwise provided by law.
3.3. Personal Data shall be processed by the Operator in compliance with the principles and rules provided for by the Personal Data Law in the following cases:
3.3.1. with the consent of the Personal Data Subject to the processing of their Personal Data;
3.3.2. where Personal Data processing is necessary for the performance of an agreement to which the Personal Data Subject is a party, beneficiary, or guarantor;
3.3.3. in cases where Personal Data processing is necessary for the Operator to exercise and perform functions, powers, and duties imposed by the legislation of the Russian Federation;
3.3.4. where Personal Data processing is necessary to protect the life, health, or other vital interests of the Personal Data Subject, if obtaining the consent of the Personal Data Subject is impossible.
3.4. The Operator has no right to obtain and process the Subject’s Personal Data containing information on racial or ethnic origin, political opinions, religious or philosophical beliefs, or health condition, except with the written consent of the Subject.
3.5. The Operator does not process special categories of Personal Data or biometric data.
3.6. Subjects familiarize themselves with this Policy in the Application when providing consent.
3.7. Provision of the Subject’s Personal Data upon request of state authorities (local self-government authorities) shall be carried out in accordance with the procedure provided for by the legislation of the Russian Federation.
3.8. Compliance with the requirements of this Policy shall be monitored by an authorized person responsible for organizing Personal Data processing at the Operator.
3.9. The Operator’s liability for violation of the requirements of the legislation of the Russian Federation in the field of processing and protection of Personal Data shall be determined in accordance with the legislation of the Russian Federation.
3.10. Only employees of the Operator whose job duties include Personal Data processing shall be permitted to process Personal Data. The list of employees permitted to process Personal Data shall be established by the Operator.
3.11. Disclosure to third parties and dissemination of Personal Data without the consent of the Personal Data Subject shall not be permitted unless otherwise provided by federal law. Consent to the processing of Personal Data permitted by the Personal Data Subject for dissemination shall be executed separately from other consents of the Personal Data Subject to the processing of their Personal Data.
3.12. Procedure for obtaining Personal Data:
3.12.1. Collection of Personal Data, except for publicly available Personal Data, shall be carried out by the Operator directly from Personal Data Subjects or from persons duly authorized to represent the interests of the Subjects; if the Subject’s Personal Data can be obtained only from a third party, the Subject must be notified thereof or their written consent must be obtained.
3.12.2. When obtaining Personal Data, the Operator shall inform the Personal Data Subject of:
3.12.2.1. the purposes for which the Operator obtains Personal Data;
3.12.2.2. the list of Personal Data requested by the Operator;
3.12.2.3. the list of actions that the Operator intends to perform with Personal Data;
3.12.2.4. the period during which the Personal Data Subject’s consent to the processing of Personal Data remains valid;
3.12.2.5. the procedure for withdrawal of consent to Personal Data processing;
3.12.2.6. the consequences of the Personal Data Subject’s refusal to provide the Operator with consent to obtain and process Personal Data.
3.13. Documents containing Personal Data are created by:
3.13.1. copying original documents (passport of a citizen of the Russian Federation, education document, taxpayer identification number certificate, pension certificate, SNILS, etc.);
3.13.2. entering information into accounting forms;
3.13.3. obtaining originals of necessary documents (passport of a citizen of the Russian Federation, income certificate, employment record book, medical report, reference letter, etc.).
3.14. Processing of Personal Data for each processing purpose specified in Clauses 5.3-5.5 of the Policy shall be carried out by:
3.14.1. receiving Personal Data orally, in writing, and electronically directly from the Subjects;
3.14.2. entering Personal Data into the Operator’s logs, registers, and information systems;
3.14.3. using other methods of Personal Data processing depending on the Personal Data processing action.
4. RIGHTS AND OBLIGATIONS
4.1. Obligations of the Operator:
4.1.1. To organize Personal Data processing in accordance with the requirements of the Personal Data Law;
4.1.2. To respond to requests and inquiries of Personal Data Subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
4.1.3. To provide the authorized authority for the protection of the rights of Personal Data Subjects (the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor)), upon request of that authority, with the necessary information within 10 business days from the date of receipt of such request. This period may be extended, but by no more than five business days. For this purpose, the Operator must send Roskomnadzor a reasoned notice stating the reasons for extending the period for providing the requested information;
4.1.4. In accordance with the procedure determined by the federal executive authority authorized in the field of security, to ensure interaction with the state system for detecting, preventing, and eliminating the consequences of computer attacks on information resources of the Russian Federation, including informing the authorized authority of computer incidents that have resulted in unlawful transfer (provision, dissemination, access) of Personal Data.
4.1.5. In cases where Personal Data has not been obtained from the Personal Data Subject, to notify the Personal Data Subject of the fact that Personal Data has been received by the Operator.
4.1.6. In case of refusal to provide Personal Data, to explain to the Personal Data Subject the consequences of such refusal.
4.1.7. To publish or otherwise provide unrestricted access to the document defining the Operator’s policy regarding the processing of Personal Data.
4.1.8. To take necessary legal, organizational, and technical measures, or ensure that such measures are taken, to protect Personal Data against unlawful or accidental access thereto, destruction, modification, blocking, copying, provision, and dissemination of Personal Data, as well as against other unlawful actions with respect to Personal Data.
4.2. The Operator has the right to:
4.2.1. Independently determine the composition and list of measures necessary and sufficient to ensure fulfillment of the obligations provided for by the Personal Data Law and regulatory legal acts adopted in accordance therewith, unless otherwise provided by the Personal Data Law or other federal laws;
4.2.2. Entrust Personal Data processing to another person. The person processing Personal Data on behalf of the Operator shall comply with the principles and rules of Personal Data processing provided for by the Personal Data Law.
4.2.3. If the Subject withdraws consent to the processing of Personal Data, the Operator shall have the right to continue processing Personal Data without the Subject’s consent where grounds specified in the Personal Data Law exist.
4.3. The Subject has the right to:
4.3.1. Receive information concerning the processing of their Personal Data, except in cases provided for by federal laws. Information shall be provided to the Personal Data Subject by the Operator in an accessible form and shall not contain Personal Data relating to other Personal Data Subjects, except where lawful grounds exist for disclosure of such Personal Data. The list of information and the procedure for obtaining it are established by the Personal Data Law. The information may include:
4.3.1.1. Confirmation of the fact of processing of Personal Data by the operator;
4.3.1.2. Legal grounds and purposes of Personal Data processing;
4.3.1.3. The purposes and methods of Personal Data processing applied by the operator;
4.3.1.4. The name and location of the operator, information on persons (except employees of the operator) who have access to Personal Data or to whom Personal Data may be disclosed on the basis of an agreement with the operator or on the basis of federal law;
4.3.1.5. Processed Personal Data relating to the relevant Personal Data Subject and the source from which it was obtained, unless another procedure for provision of such data is established by federal law;
4.3.1.6. The periods of Personal Data processing, including the periods of storage thereof;
4.3.1.7. The procedure for the Personal Data Subject to exercise the rights provided for by this Federal Law;
4.3.1.8. Information on any completed or contemplated cross-border data transfer;
4.3.1.9. The name or surname, first name, patronymic, and address of the person processing Personal Data on behalf of the operator, if processing has been or will be entrusted to such person;
4.3.1.10. Other information provided for by the Personal Data Law or other federal laws.
4.3.2. Give prior consent to the processing of Personal Data for the purposes of promoting goods, works, and services on the market;
4.3.3. Require the operator to clarify the Subject’s Personal Data, block or destroy it if the Personal Data is incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated processing purpose, and also take measures provided by law to protect their rights.
4.3.4. Appeal to Roskomnadzor or in court against unlawful actions or omissions of the Operator when processing the Subject’s Personal Data.
5. PURPOSES OF PERSONAL DATA PROCESSING, CATEGORIES OF SUBJECTS, CATEGORIES OF PERSONAL DATA PROCESSED, AND METHODS OF PROCESSING THEREOF
5.1. Personal Data processing shall be limited to the achievement of specific, predetermined, and lawful purposes. Personal Data processing incompatible with the purposes of collecting Personal Data shall not be permitted.
5.2. Only Personal Data that meets the purposes of its processing shall be subject to processing.
5.3. Purpose of Personal Data processing: Registration of the User in the Application.
Categories of Personal Data processed:
- email address;
- accountId, UID, or other account identifiers;
- information related to login credentials;
- deviceId, CID, or other unique device identifiers.
Categories of Subjects: Users of the Application.
Legal basis for Personal Data processing:
Personal Data processing is carried out with the consent of the Personal Data Subject to the processing of their Personal Data.
List of Personal Data processing actions:
- collection;
- recording;
- systematization;
- accumulation;
- storage;
- clarification (updating, modification);
- extraction;
- use;
- transfer (provision to a limited group of persons; access by a limited group of persons);
- anonymization;
- blocking;
- deletion;
- destruction.
Methods of processing: automated; without transmission over the internal network of a legal entity; with transmission over the Internet.
Period (and conditions for termination) of Personal Data processing and storage:
- Duration of consent.
A condition for termination of Personal Data processing may be achievement of the purposes of processing, withdrawal of consent to Personal Data processing, termination of the Operator’s activities (reorganization or liquidation), closure of the Application, identification of unlawful processing, or expiration of processing periods.
5.4. Purpose of Personal Data processing: Use of the functional capabilities of the Application and smart devices.
Categories of Personal Data processed:
- email address;
- accountId, UID, or other account identifiers;
- information related to login credentials;
- deviceId, CID, or other unique device identifiers.
Categories of Subjects: Users of the Application.
Legal basis for Personal Data processing:
Personal Data processing is carried out with the consent of the Personal Data Subject to the processing of their Personal Data.
List of Personal Data processing actions:
- collection;
- recording;
- systematization;
- accumulation;
- storage;
- clarification (updating, modification);
- extraction;
- use;
- transfer (provision to a limited group of persons; access by a limited group of persons);
- anonymization;
- blocking;
- deletion;
- destruction.
Methods of processing: automated; without transmission over the internal network of a legal entity; with transmission over the Internet.
Period (and conditions for termination) of Personal Data processing and storage:
- Duration of consent.
A condition for termination of Personal Data processing may be achievement of the purposes of processing, withdrawal of consent to Personal Data processing, termination of the Operator’s activities (reorganization or liquidation), closure of the Application, identification of unlawful processing, or expiration of processing periods.
5.5. Purpose of Personal Data processing: Contacting customer support.
Categories of Personal Data processed:
- email address;
- accountId, UID, or other account identifiers;
- information related to login credentials;
- deviceId, CID, or other unique device identifiers;
- personal data contained in the request and attachments thereto.
Categories of Subjects: Users of the Application.
Legal basis for Personal Data processing:
Personal Data processing is carried out with the consent of the Personal Data Subject to the processing of their Personal Data.
List of Personal Data processing actions:
- collection;
- recording;
- systematization;
- accumulation;
- storage;
- clarification (updating, modification);
- extraction;
- use;
- transfer (provision to a limited group of persons; access by a limited group of persons);
- anonymization;
- blocking;
- deletion;
- destruction.
Methods of processing: automated; without transmission over the internal network of a legal entity; with transmission over the Internet.
Period (and conditions for termination) of Personal Data processing and storage:
- Duration of consent.
A condition for termination of Personal Data processing may be achievement of the purposes of processing, withdrawal of consent to Personal Data processing, termination of the Operator’s activities (reorganization or liquidation), closure of the Application, identification of unlawful processing, or expiration of processing periods.
6. PROCESSING OF OTHER TECHNICAL DATA
6.1. Other technical data is processed in the Application:
6.1.1. User account data:
- Consent records, including the time of consent, Policy version, client version, channel source, and other similar information;
6.1.2. Smart device identification data:
- Smart device model, configModel, deviceRegion, connectionType;
- Firmware version, plugin version, update status;
- Information on binding of the smart device to the account.
6.1.3. Data related to network connection and the network environment:
- Wi-Fi network name (SSID);
- Router MAC, BT MAC, MAC address of the smart device;
- RSSI;
- IP address;
- User region;
- Network condition, initialization status, and error codes, logs, and timestamps related to network diagnostics.
6.1.4. Smart device status and remote-control data:
- Information on the smart device being online, information on operating status, mode, time, temperature, and other status data;
- Initiated control commands, results of their execution, confirmation statuses, and error codes;
- Key operation logs necessary for audit, dispute resolution, and service security purposes.
6.1.5. Data on firmware updates and technical maintenance of the smart device:
- Current firmware version of the smart device and the version available for update;
- Update requests, update status, update results, and information related to troubleshooting.
6.1.6. Customer support request data:
- Content of the request;
- Screenshots, images, videos, log files, and other attachments enclosed with the request;
- Account identifiers, smart device identifiers, error codes, and diagnostic information directly related to identifying the cause of the issue.
6.1.7. System operation and security data:
- Application version, operating system version, smart device model;
- Information on login anomalies, security alerts, records of access token revocation;
- Minimum necessary logs required to ensure service stability and security.
7. TRANSFER OF PERSONAL DATA
7.1. The Operator transfers Personal Data to third parties in the following cases:
7.1.1. consent to such actions has been obtained from the Personal Data Subject;
7.1.2. the transfer is provided for by Russian or other applicable law within the procedure established by law.
7.2. The list of persons to whom Personal Data is transferred shall be established by the consent to Personal Data processing provided by the Personal Data Subject or by mandatory provisions of applicable law.
7.3. Provision of the Subject’s Personal Data upon request of state authorities (local self-government authorities) shall be carried out in accordance with the procedure provided for by the legislation of the Russian Federation.
7.4. When collecting Personal Data, including through the Internet, the Operator ensures processing of Personal Data of citizens of the Russian Federation using databases located in the territory of the Russian Federation, except in cases specified in the Personal Data Law.
7.5. The Operator does not carry out cross-border transfer of Personal Data.
8. UPDATING, CORRECTION, DELETION, AND DESTRUCTION OF PERSONAL DATA; RESPONSES TO SUBJECTS’ REQUESTS FOR ACCESS TO PERSONAL DATA
8.1. Procedure for considering Subjects’ requests:
8.1.1. Confirmation of the fact of Personal Data processing by the Operator, the legal grounds and purposes of Personal Data processing, as well as other information specified in Part 7 of Article 14 of the Personal Data Law, shall be provided by the Operator to the Subject or their representative within 10 business days from the moment of the request or receipt of the request of the Personal Data Subject or their representative. This period may be extended, but by no more than five business days. For this purpose, the Operator should send the Subject a reasoned notice stating the reasons for extending the period for providing the requested information.
8.1.2. The information provided shall not include Personal Data relating to other Subjects, except where lawful grounds exist for disclosure of such Personal Data.
8.1.3. The request must contain data allowing identification of the Subject and the signature of the Subject; if the request is signed by the Subject’s representative, it must include a document confirming the representative’s authority.
8.1.4. The request may be sent in the form of an electronic document and signed with an electronic signature in accordance with the legislation of the Russian Federation.
8.1.5. The Operator shall provide the information specified in Part 7 of Article 14 of the Personal Data Law to the Subject or their representative in the form in which the relevant inquiry or request was sent, unless otherwise specified in the inquiry or request. If the Subject’s inquiry (request) does not contain all information required in accordance with the Personal Data Law or the Subject does not have access rights to the requested information, the Subject shall be sent a reasoned refusal.
8.1.6. The Subject’s right of access to their Personal Data may be restricted in accordance with Part 8 of Article 14 of the Personal Data Law, including where the Subject’s access to their Personal Data violates the rights and lawful interests of third parties.
8.2. If inaccurate Personal Data is identified upon the inquiry of the Subject or their representative, or upon their request, or upon the request of Roskomnadzor, the Operator shall block the Personal Data relating to that Subject from the moment of such inquiry or receipt of the specified request for the verification period, unless blocking of Personal Data violates the rights and lawful interests of the Subject.
8.3. If the fact of inaccuracy of Personal Data is confirmed, the Operator, on the basis of information provided by the Subject or their representative, Roskomnadzor, or other necessary documents, shall clarify the Personal Data within seven business days from the date of provision of such information and shall lift the blocking of the Personal Data.
8.4. If unlawful processing of Personal Data is identified upon the inquiry (request) of the Subject or their representative, or Roskomnadzor, the Operator shall block the unlawfully processed Personal Data relating to that Personal Data Subject within three business days from the moment of such inquiry or receipt of the request.
8.5. If the Operator, Roskomnadzor, or another interested person identifies the fact of unlawful or accidental transfer (provision, dissemination) of Personal Data (access to Personal Data), resulting in violation of the Subject’s rights, the Operator shall:
8.5.1. within 24 hours, notify Roskomnadzor of the incident, the presumed causes that resulted in violation of the Subjects’ rights, the presumed harm caused to the Subjects’ rights, and the measures taken to eliminate the consequences of the incident, and shall also provide information on the person authorized by the Operator to interact with Roskomnadzor on matters related to the incident;
8.5.2. within 72 hours, notify Roskomnadzor of the results of the internal investigation of the identified incident and provide information on the persons whose actions caused the incident (if any).
8.6. Destruction of Personal Data:
8.6.1. Upon achievement of the purpose of Personal Data processing, as well as in the event of withdrawal by the Personal Data Subject of consent to processing, Personal Data shall be destroyed if:
8.6.1.1. otherwise is not provided by an agreement to which the Subject is a party, beneficiary, or guarantor;
8.6.1.2. the Operator is not entitled to carry out processing without the consent of the Personal Data Subject on the grounds provided for by the Personal Data Law or other federal laws;
8.6.1.3. otherwise is not provided by the legislation of the Russian Federation.
8.7. Personal Data on electronic media shall be destroyed by erasing it from computer memory or formatting computer memory.
8.8. Destruction of documents (paper media) containing Personal Data shall be carried out by burning, crushing (shredding), chemical decomposition, or transforming into a shapeless mass or powder. A shredder may be used to destroy paper documents.
8.9. Destruction of Personal Data shall be carried out by a commission established by order of the Operator’s General Director.
8.10. The period for destruction of Personal Data shall be 10 business days from the occurrence of one of the events specified in Clause 8.6 of this Policy.
9. MEASURES TAKEN BY THE OPERATOR TO PROTECT PERSONAL DATA
9.1. In accordance with the requirements of regulatory documents, the Operator has created a Personal Data protection system consisting of legal, organizational, and technical protection subsystems.
9.2. The legal protection subsystem is a set of legal, organizational-administrative, and regulatory documents that ensure the creation, functioning, and improvement of Personal Data protection systems.
9.3. The organizational protection subsystem includes organization of the management structure of the Personal Data protection system, the authorization system, and information protection when working with employees, partners, and third parties.
9.4. The technical protection subsystem includes a set of technical, software, and hardware-software tools ensuring the protection of Personal Data.
9.5. The main Personal Data protection measures used by the Operator are:
9.5.1. Appointment of a person responsible for Personal Data processing who organizes Personal Data processing, training and instruction, and internal control over compliance by the Operator and its employees with Personal Data protection requirements.
9.5.2. Identification of current threats to the security of Personal Data during processing in Personal Data information systems and development of measures and activities for the protection of Personal Data.
9.5.3. Development of this Policy.
9.5.4. Establishment of rules for access to Personal Data processed in Personal Data information systems, as well as ensuring registration and accounting of all actions performed with Personal Data in Personal Data information systems.
9.5.5. Establishment of individual employee passwords for access to the information system in accordance with their work duties.
9.5.6. Application of information protection tools that have undergone conformity assessment procedures in the established manner.
9.5.7. Certified antivirus software with regularly updated databases.
9.5.8. Compliance with conditions ensuring the safekeeping of Personal Data and excluding unauthorized access thereto.
9.5.9. Detection of unauthorized access to Personal Data and taking measures.
9.5.10. Restoration of Personal Data modified or destroyed as a result of unauthorized access thereto.
9.5.11. Instruction of the Operator’s employees directly involved in Personal Data processing on the application of the provisions of the legislation of the Russian Federation on Personal Data, including Personal Data protection requirements, documents defining the Operator’s policy regarding Personal Data processing, and local acts on Personal Data processing matters.
9.5.12. Implementation of internal control and audit.
9.5.13. Employees holding positions that involve Personal Data processing shall be permitted to process such data after signing a non-disclosure obligation.
9.5.14. The job descriptions of the Operator’s employees who process Personal Data shall include, in particular, provisions on the need to report any cases of unauthorized access to Personal Data.
9.6. When processing Personal Data, the Operator ensures:
9.6.1. implementation of measures aimed at preventing unauthorized access to Personal Data and/or transfer of Personal Data to persons who do not have the right of access to such information;
9.6.2. timely detection of unauthorized access to Personal Data;
9.6.3. prevention of impact on technical means of automated Personal Data processing that may result in disruption of their functioning;
9.6.4. the ability to promptly restore Personal Data modified or destroyed as a result of unauthorized access thereto;
9.6.5. continuous control over ensuring the level of protection of Personal Data.
9.7. The Operator conducts internal investigations in the following situations:
9.7.1. in the event of unlawful or accidental transfer (provision, dissemination, access) of Personal Data resulting in violation of the rights of Personal Data Subjects;
9.7.2. in other cases provided for by legislation in the field of Personal Data.
9.8. The employee responsible for organizing Personal Data processing shall exercise internal control over compliance by employees authorized to process Personal Data with the requirements of legislation in the field of Personal Data and local regulations, and over compliance of such acts with the requirements of legislation in the field of Personal Data.
9.8.1. Internal scheduled audits shall be carried out on the basis of an annual plan approved by the Operator’s General Director.
9.8.2. Internal unscheduled audits shall be carried out by decision of the employee responsible for organizing Personal Data processing. The basis for such audits shall be information on a violation of legislation in the field of Personal Data received orally or in writing.
9.8.3. Based on the results of an internal audit, a memorandum shall be prepared addressed to the Operator’s General Director. If violations are identified, the document shall specify a list of measures for their elimination within the relevant timeframes.
9.9. The Operator uses technical means and software equipment for processing and protecting Personal Data.
9.10. The above technical means and software equipment for processing and protecting Personal Data shall be located in the office and premises of the Operator or in the premises of other persons engaged by the Operator.
9.11. All persons permitted to work with Personal Data, as well as persons involved in the operation and technical support of the PDIS, have familiarized themselves with this Policy.
9.12. The Operator has organized a process for training in the use of protection tools operated by the Operator. Training in this area has been completed by persons who have permanent access to Personal Data, persons who operate technical and software tools of the PDIS and PDIS protection tools, and persons responsible for the operation of information protection tools of the PDIS.
9.13. Employees shall immediately report to the relevant officer of the Operator any loss or shortage of media containing information constituting Personal Data, as well as the causes and conditions of a possible Personal Data leak. If unauthorized persons attempt to obtain from an employee Personal Data processed by the Operator, the employee shall immediately notify the relevant officer of the Operator thereof.
9.14. When working with software tools of the Operator’s automated system that implement functions for viewing and editing Personal Data, it is prohibited to display screen forms containing such data to persons who do not have the appropriate access authorization.
9.15. Storage of Personal Data:
9.15.1. Personal Data of Subjects may be received, further processed, and transferred for storage both on paper media and in electronic form.
9.15.2. Personal Data on paper media shall be stored by the Operator for the storage periods for documents for which such periods are provided by the archival legislation of the Russian Federation (Federal Law No. 125-FZ dated 22 October 2004 “On Archival Affairs in the Russian Federation”, List of standard management archival documents generated in the course of activities of state authorities, local self-government authorities, and organizations, indicating their storage periods (approved by Order of Rosarkhiv No. 236 dated 20 December 2019)).
9.15.3. Personal Data of Subjects recorded on paper media shall be stored in locked cabinets or in locked premises with restricted access rights.
9.15.4. Personal Data of Subjects processed using automation tools shall be processed and stored in compliance with the requirements established by Decree of the Government of the Russian Federation No. 1119 “On Approval of Requirements for the Protection of Personal Data During Processing in Personal Data Information Systems” dated 1 November 2012. The storage period for Personal Data processed in Personal Data information systems shall correspond to the storage period for Personal Data on paper media.
9.15.5. Storage and placement of documents containing Personal Data in open electronic directories (file-sharing systems) in Personal Data information systems shall not be permitted.
9.15.6. Personal Data shall be stored in a form allowing identification of the Subject for no longer than required by the purposes of Personal Data processing, unless the storage period for Personal Data is established by federal law or an agreement to which the Subject is a party, beneficiary, or guarantor.
10. LIABILITY OF THE OPERATOR
10.1. The management of the Operator shall be liable for failure to ensure the confidentiality of Personal Data and failure to comply with the rights and freedoms of Subjects with respect to their Personal Data, including the rights to privacy and personal and family confidentiality.
10.2. Employees of the Operator shall bear personal liability for failure to comply with the requirements for processing and ensuring the security of Personal Data in accordance with the legislation of the Russian Federation.
10.3. An employee of the Operator may be held liable in the following cases:
10.3.1. Intentional or negligent disclosure of Personal Data;
10.3.2. Loss of material media containing Personal Data;
10.3.3. Violation of the requirements of this Policy and other regulatory documents of the Operator regarding access to and work with Personal Data.
10.4. In cases of violation of the established procedure for processing and ensuring the security of Personal Data, unauthorized access to Personal Data, disclosure of Personal Data, and causing material or other damage to the Operator, its employees, counterparties, and other Subjects, the guilty persons shall bear civil, criminal, administrative, disciplinary, and other liability provided for by the legislation of the Russian Federation.
10.5. The Operator informs the Subject that this Policy applies only to Personal Data processed by the Operator. The Operator does not control and shall not be liable for the use of third-party websites which the Subject may access at their own discretion and risk via links posted in the Application or on other websites administered by the Operator.
10.6. The Operator shall not be liable for the accuracy of the Subject’s Personal Data.
11. FINAL PROVISIONS
11.1. This Policy shall enter into force upon approval, shall be enacted by order of the Operator, and shall remain in effect indefinitely (until canceled or replaced by a new version of the Policy).
11.2. The requirements of this Policy shall apply to all employees of the Operator who have access to Personal Data, as well as to all Subjects.
11.3. The Operator has the right to unilaterally amend and/or supplement this Policy. In the event of amendments affecting the rights of Subjects, the Operator has the right, but is not obliged, to send information on such amendments to the Subjects using their contact details or to notify them of the amendments by other means.
12. OPERATOR DETAILS
Operator: Shenzhen Gaea Information Co., Ltd
Unified Social Credit Code (USCC): 91440300MA5HB76T6K
Address: Room 1408, 14F, Tianjian Chuangye Building, No.7 Shangbao Road, Shiling Community, Lianhua Sub-district, Futian District, Shenzhen, Guangdong Province, China
Email address: legal@cosori.cloud.
Manage your personal data
Review consent terms, request account deletion, or contact us about privacy questions related to the HiMerce app.