Policy of YUKON RU Limited Liability Company Regarding the Processing of Personal Data

Chapter 1. General Provisions

1.1. This Policy has been prepared pursuant to the third paragraph of Clause 3 of Article 17 of Law of the Republic of Belarus No. 99-Z dated May 7, 2021, “On Personal Data Protection” (hereinafter referred to as the “Law”) and defines the procedure for processing personal data by YUKON RU Limited Liability Company (hereinafter referred to as the “Company”), including the purposes of such processing, the rights of personal data subjects and the mechanism for exercising them, as well as the measures taken by the Company to ensure personal data protection.

1.2. This Policy applies to all personal data processing operations involving personal data received by the Company concerning a personal data subject.

1.3. The purpose of this Policy is to ensure the proper protection of personal data against unauthorized access and disclosure and to safeguard the rights and freedoms of citizens when processing their personal data.

1.4. By providing personal data to the Company, the personal data subject confirms their consent to the processing of the relevant information under the terms set forth in this Policy and confirms that they have read the Policy and agree to its terms.

1.5. For the purposes of this Policy, terms and their definitions shall have the meanings assigned to them by the Law.

Chapter 2. Purposes and Legal Grounds for Personal Data Processing

2.1. The Company, acting as a personal data controller, processes the personal data of its employees and other personal data subjects who are not in an employment relationship with the Company.

2.2. Personal data processing at the Company is carried out with due regard for the need to protect the rights and freedoms of the Company’s employees and other personal data subjects, including the right to privacy and personal and family confidentiality, based on the following principles:

  • personal data processing is organized and/or carried out lawfully and fairly with respect to all persons whose personal data is processed by the Company;
  • personal data processing is transparent. In accordance with the procedure and under the conditions established by the Law, the personal data subject is provided with relevant information concerning the processing of their personal data, unless otherwise stipulated by legislative acts;
  • personal data processing is proportionate to the stated purposes of such processing and ensures a fair balance between the interests of the parties concerned at all stages of processing. Personal data processing that is incompatible with the originally stated purposes is not permitted;
  • personal data processing is organized and/or carried out with the consent of the personal data subject, except in cases provided for by the Law and other legislative acts;
  • personal data processing is limited to achieving specific, predetermined, lawful purposes. Processing personal data in a manner incompatible with the initially stated purposes of their processing is not permitted;
  • the content and scope of the personal data being processed correspond to the stated purposes of their processing. The personal data being processed is not excessive in relation to the stated purposes of its processing;
  • the company takes measures to ensure the accuracy of the personal data it processes and updates it when necessary;
  • personal data is stored in a form that allows the personal data subject to be identified for no longer than required by the stated purposes of personal data processing.

2.3. Personal data is processed by the company for the following purposes:

  • ensuring compliance with the Constitution of the Republic of Belarus, legislative and other regulatory legal acts, and the company’s local legal acts;
  • performing the functions, powers, and duties assigned to the company by law;
  • reviewing requests from citizens, including individual entrepreneurs, and legal entities, as well as requests from government authorities (in relation to the persons specified in the requests);
  • regulating labor relations with the company’s employees and job applicants, including attracting and selecting candidates for employment at the company, maintaining personnel records, and organizing employee record-keeping;
  • carrying out administrative procedures;
  • maintaining individual (personalized) records of insured persons;
  • military registration records;
  • accounting and tax records;
  • calculation and payment of wages, assignment and payment of benefits;
  • completion and submission of required reporting forms to government authorities and other authorized organizations;
  • processing of personal data for pension purposes;
  • conducting business activities;
  • preparation, conclusion, performance and termination of contracts with counterparties;
  • ensuring access control and internal security regimes;
  • preparation of reference materials for internal information support of the Company’s activities;
  • enforcement of court rulings and acts of other authorities or officials that are enforceable in accordance with enforcement proceedings legislation;
  • for other lawful purposes.

2.4. The Company does not organize or carry out the processing of special categories of personal data concerning race, political views, religious or other beliefs, sex life, or biometric and genetic personal data.

Chapter 3. Procedure and Conditions for Personal Data Processing

3.1. The Enterprise may process the personal data of the following personal data subjects:

  • job applicants, employees, including former employees, their spouses and close relatives;
  • persons who are candidates for the management personnel reserve;
  • persons who are not employees when the Enterprise processes award-related documents;
  • persons who have arrived at the Enterprise for practical training, internships, tours, negotiations, inspections, etc.;
  • counterparties who are individuals, including potential counterparties (under contracts);
  • visitors to Internet resources;
  • persons who have provided personal data to the Enterprise by other means.

3.2. Personal data processing is permitted only in compliance with the requirements of the Law and other legislative acts.

A personal data subject may withdraw their consent to personal data processing at any time in accordance with the procedure established by Article 14 of the Law.

3.3. Processed personal data shall be stored no longer than required for the purposes specified in Clause 2.3 of this Policy:

  • on paper media;
  • in electronic documents;
  • in computer files;
  • in information systems (resources) that ensure automated processing and storage of information.

Access to personal data processed by the enterprise is granted to the enterprise’s employees in accordance with their job duties.

3.3. Personal data may be processed on behalf of or in the interests of the enterprise by an authorized person in accordance with legislative acts and/or an agreement concluded with such person, subject to the requirements of personal data legislation.

3.4. If the enterprise entrusts the processing of personal data to an authorized person, the enterprise shall be liable to the personal data subject for the actions of that person. The authorized person shall be liable to the enterprise.

The enterprise takes the necessary measures to ensure that an authorized person who has gained access to personal data complies with the obligation not to disclose such data to third parties or distribute it without the consent of the personal data subject, unless otherwise provided by law.

3.5. Personal data processing shall cease when the purposes of personal data processing have been achieved, when the consent has expired and/or when the personal data subject withdraws consent to its processing, except in cases stipulated by law.

3.6. The enterprise may process the following technical information:

  • IP address;
  • browser information;
  • cookie data;
  • address of the requested page;
  • access time.

3.7. The Enterprise transfers personal data:

  • to the personal data subject in relation to their own personal data — without restrictions, except in cases expressly provided for by law;
  • to third parties — in cases provided for by law.

3.8. The Enterprise shall be liable, as provided for by legislative acts, for actions (inaction) resulting in unlawful access by third parties to information constituting personal data, for the unlawful use of personal data, and for the disclosure of personal data.

Chapter 4. Cross-Border Data Transfer

4.1. The Enterprise carries out cross-border transfers of personal data to ensure continuous communication with users of social networks and messaging services, including job applicants (Instagram, TikTok, Telegram, YouTube video hosting, Facebook, LinkedIn, VKontakte), etc.

4.2. The Enterprise may transfer personal data across borders to the territory of a foreign state if:

  • the foreign state ensures an adequate level of protection for the rights of personal data subjects — without restrictions where there are legal grounds provided for by the Law;
  • the foreign state does not ensure an adequate level of protection for the rights of personal data subjects — in the cases provided for by Article 9 of the Law, including:
    • when the personal data subject has given consent, provided that the personal data subject has been informed of the risks arising from the lack of an adequate level of protection;
    • when posting information about its activities on the global computer network Internet;
    • when the processing of personal data is necessary for the performance of duties (powers) stipulated by legislative acts.

Chapter 5. Rights of the Personal Data Subject and Their Exercise

5.1. Unless otherwise stipulated by legislative acts, the personal data subject has the right to:

  • obtain information concerning the processing of their personal data by the enterprise;
  • obtain information from the enterprise concerning the disclosure of their personal data to third parties in cases stipulated by law;
  • appeal against actions, omissions, or decisions of the enterprise related to the processing of their personal data;
  • withdraw their consent to the processing of personal data in cases stipulated by the Law and other legislative acts;
  • apply to the enterprise to amend personal data that is incomplete, outdated, or inaccurate in cases stipulated by law;
  • exercise other rights stipulated by the Law and other legislative acts.

5.2. To exercise their rights related to the processing of personal data by the enterprise, the personal data subject may submit an application to the enterprise in writing or as an electronic document in accordance with the procedure established by Article 14 of the Law.

5.3. If the personal data subject withdraws consent to the processing of personal data, the Company may continue to process the personal data without the consent of the personal data subject if there are grounds provided for by the Law and other legislative acts.

Chapter 6. Rights and Obligations of the Company

6.1. The Company has the right to:

  • obtain from the personal data subject reliable information and/or documents containing personal data;
  • request information from the personal data subject regarding the relevance and accuracy of the personal data provided;
  • if the personal data subject withdraws consent to the processing of personal data, continue to process the personal data without the consent of the personal data subject if there are grounds specified in the Law;
  • if necessary to achieve the purposes of personal data processing, transfer such data to third parties in compliance with legal requirements;
  • independently determine the scope and list of measures necessary and sufficient to ensure fulfillment of the obligations provided for by the Law and the regulatory legal acts adopted pursuant thereto, unless otherwise provided for by the Law.

6.2. The Company is obligated to:

  • explain to the personal data subject their rights related to the processing of personal data;
  • obtain the personal data subject’s consent to the processing of personal data, except in cases provided for by the Law and other legislative acts;
  • ensure the protection of personal data during its processing;
  • provide the personal data subject with information about their personal data, as well as about the disclosure of their personal data to third parties, except in cases provided for by the Law and other legislative acts;
  • make changes to personal data that is incomplete, outdated, or inaccurate, except where a different procedure for making changes to personal data is established by legislative acts or where the purposes of the personal data do not provide for subsequent changes to such data;
  • cease the processing of personal data and delete or block such data (ensure that the authorized person ceases the processing of personal data and deletes or blocks such data) where there are no grounds for processing personal data as provided for by the Law and other legislative acts;
  • notify the authorized body for the protection of personal data subjects’ rights of any breaches of personal data protection systems immediately, but no later than three business days after the enterprise becomes aware of such breaches, except in cases specified by the authorized body for the protection of personal data subjects’ rights;
  • amend, block, or delete inaccurate or unlawfully obtained personal data of a personal data subject at the request of the authorized body for the protection of personal data subjects’ rights, unless a different procedure for amending, blocking, or deleting personal data is established by legislative acts;
  • comply with other requirements of the authorized body for the protection of personal data subjects’ rights concerning the elimination of violations of personal data legislation;
  • perform other duties provided for by the Law and other legislative acts.

Chapter 7. Final Provisions

7.1. The enterprise and other persons who have obtained access to personal data must not disclose such data to third parties or disseminate it without the consent of the personal data subject, unless otherwise provided for by the Law.

7.2. The security of personal data processed by the enterprise is ensured through the implementation of legal, organizational, and technical measures necessary to fully comply with the requirements of personal data protection legislation.

7.3. The enterprise has the right to amend this Policy unilaterally without prior approval from or subsequent notification of the personal data subject.

Matters concerning the processing of personal data that are not addressed in this Policy are governed by legislation.

7.4. This Policy is a publicly available document. Public availability is ensured by posting it freely on the official websites: https://yukonru.by/, https://yukonru.ru/, https://yukonru.com/.