1. General Provisions
This personal data processing policy is drawn up in accordance with the requirements of the Federal Law of 27.07.2006. No. 152-FZ "On Personal Data" (hereinafter referred to as the Personal Data Law) and defines the procedure for processing personal data and measures to ensure the security of personal data undertaken by the company (hereinafter referred to as the Operator). This personal data processing policy is drawn up in accordance with the requirements of the Federal Law of 27.07.2006. No. 152-FZ "On Personal Data" (hereinafter referred to as the Personal Data Law) and defines the procedure for processing personal data and measures to ensure the security of personal data undertaken by the company (hereinafter referred to as the Operator).
- 1.1. The Operator sets as its most important goal and condition for the implementation of its activities the observance of human and civil rights and freedoms in the processing of their personal data, including the protection of rights to privacy, personal and family secrets.
- 1.2. This Operator's policy regarding the processing of personal data (hereinafter referred to as the Policy) applies to all information that the Operator may receive about visitors to the website https://getyourphuket.com/en/.
2. Basic Concepts Used in the Policy
- 2.1. Automated processing of personal data - processing of personal data using computer technology.
- 2.2. Blocking of personal data - temporary cessation of processing of personal data (except in cases where processing is necessary to clarify personal data).
- 2.3. Website - a set of graphic and informational materials, as well as computer programs and databases, ensuring their availability on the Internet at the network address https://getyourphuket.com/en/.
- 2.4. Information system of personal data - a set of personal data contained in databases and information technologies and technical means ensuring their processing.
- 2.5. Depersonalization of personal data - actions as a result of which it is impossible to determine without the use of additional information the belonging of personal data to a specific User or other subject of personal data.
- 2.6. Processing of personal data - any action (operation) or a set of actions (operations) performed using automation tools or without using such tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, changing), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction of personal data.
- 2.7. Operator - a state body, municipal body, legal or natural person, independently or jointly with other persons organizing and (or) carrying out the processing of personal data, as well as determining the purposes of processing personal data, the composition of personal data to be processed, actions (operations) performed with personal data.
- 2.8. Personal data - any information relating directly or indirectly to a specific or identifiable User of the website https://getyourphuket.com/en/.
- 2.9. Personal data permitted by the subject of personal data for dissemination - personal data, access to which is provided to an unlimited number of persons by the subject of personal data by giving consent to the processing of personal data permitted by the subject of personal data for dissemination in the manner prescribed by the Personal Data Law (hereinafter referred to as personal data permitted for dissemination).
- 2.10. User - any visitor to the website https://getyourphuket.com/en/.
- 2.11. Provision of personal data - actions aimed at disclosing personal data to a specific person or a specific circle of persons.
- 2.12. Dissemination of personal data - any actions aimed at disclosing personal data to an indefinite circle of persons (transfer of personal data) or at familiarizing with personal data of an unlimited circle of persons, including the publication of personal data in the media, placement in information and telecommunication networks or providing access to personal data in any other way.
- 2.13. Cross-border transfer of personal data - transfer of personal data to the territory of a foreign state to a foreign state authority, a foreign natural or foreign legal person.
- 2.14. Destruction of personal data - any actions as a result of which personal data are destroyed irrevocably with the impossibility of further restoration of the content of personal data in the personal data information system and (or) material carriers of personal data are destroyed.
3. Basic Rights and Obligations of the Operator
- 3.1. The Operator has the right to:
- receive from the subject of personal data reliable information and/or documents containing personal data;
- in case of withdrawal by the subject of personal data of consent to the processing of personal data, as well as sending a request to stop processing personal data, the Operator has the right to continue processing personal data without the consent of the subject of personal data if there are grounds specified in the Personal Data Law;
- independently determine the composition and list of measures necessary and sufficient to ensure the fulfillment of obligations provided for by the Personal Data Law and adopted in accordance with it regulatory legal acts, unless otherwise provided by the Personal Data Law or other federal laws.
- 3.2. The Operator is obliged to:
- provide the subject of personal data at his request with information regarding the processing of his personal data;
- organize the processing of personal data in the manner prescribed by the current legislation of the Russian Federation;
- respond to requests and inquiries from subjects of personal data and their legal representatives in accordance with the requirements of the Personal Data Law;
- notify the authorized body for the protection of the rights of subjects of personal data at the request of this body of the necessary information within 10 days from the date of receipt of such a request;
- publish or otherwise provide unrestricted access to this Policy regarding the processing of personal data;
- take legal, organizational and technical measures to protect personal data from unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination of personal data, as well as from other unlawful actions in relation to personal data;
- stop the transfer (distribution, provision, access) of personal data, stop processing and destroy personal data in the manner and cases provided for by the Personal Data Law;
- fulfill other obligations provided for by the Personal Data Law.