Connection not protectedNot protected, Your IP IP 216.73.217.178 — see the details
Nash
My accountAccount

Document

Personal data processing policy

How Nash processes personal data: on what legal basis, how we protect it and what rights you have.

Updated
Sections
5
Reading time
≈ 6 min
  • Updated
  • 5 sections
  • ≈ 6 min read

This document (the “Policy”) sets out the purposes and general principles of personal data processing and the security measures implemented by the personal data controller for the Nash service associated with https://nashconnect.me (the “Operator”, “Nash”). The Policy is a public document and is available for review by anyone.

The Policy remains in effect indefinitely after approval until replaced by a new version. Terms are used in line with Federal Law of the Russian Federation No. 152-FZ of 27 July 2006 “On Personal Data” (“152-FZ”), to the extent applicable to the processing of Nash users’ data.

The Operator processes personal data in accordance with this Policy and applicable personal data and information security law.

Processing is carried out lawfully and fairly, including on the basis of the following instruments, where Russian law applies to the relationship:

  • Constitution of the Russian Federation;
  • Labour Code of the Russian Federation;
  • Civil Code of the Russian Federation;
  • Tax Code of the Russian Federation;
  • Federal Law No. 152-FZ of 27 July 2006 “On Personal Data”;
  • Federal Law No. 63-FZ of 6 April 2011 “On Electronic Signature”;
  • Federal Law No. 99-FZ of 4 May 2011 “On Licensing Certain Types of Activity”;
  • Federal Law No. 126-FZ of 7 July 2003 “On Communications”;
  • Federal Law No. 27-FZ of 1 April 1996 “On Individual (Personalised) Accounting in the Mandatory Pension Insurance System”;
  • Federal Law No. 125-FZ of 22 October 2004 “On Archival Affairs in the Russian Federation”;
  • Federal Law No. 273-FZ of 29 December 2012 “On Education in the Russian Federation”.

Additionally, for users in the EEA and the United Kingdom, provisions of the GDPR and applicable data protection law (including the UK GDPR and the Data Protection Act 2018) apply to the extent required by applicable law.

The Operator processes personal data using a combination of automated and non-automated means.

The following operations may be performed: collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission (provision, access), anonymisation, blocking, erasure or destruction of personal data.

Data are kept accurate, adequate and relevant to the purposes of processing. Inaccurate or incomplete data are updated when identified.

Where required by 152-FZ or other applicable law, personal data are collected and processed with the data subject’s consent unless the law provides otherwise. Consent may be given in a form equivalent to a wet-ink signature, including a qualified electronic signature, or by clear affirmative actions on the Website (acceptance of the offer, ticking boxes, completing forms) where permitted by applicable law.

The Operator does not process special categories of data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, or sex life, except where expressly required by law.

Biometric data are not processed except where separate written consent exists if such processing is ever required and permitted by law.

Personal data are processed and stored no longer than necessary for the purposes of processing, unless further processing is required by law.

Processing under contracts and other agreements with the Operator, and under processing instructions, follows those instruments. Where not expressly provided by law or contract, processing is carried out after obtaining the subject’s consent or on another lawful basis.

The Operator implements appropriate legal, organisational and technical measures to protect personal data, including:

  • appointing persons responsible for organising processing and data security;
  • confidentiality safeguards in agreements with contractors;
  • internal policies, training and staff instructions;
  • access restrictions and segregation of duties for personal data and systems;
  • threat assessment and security tools (including antivirus, firewalls, encryption in transit);
  • media control, backups and internal compliance monitoring;
  • response to information security incidents.

The data subject may withdraw consent to processing by sending a request to the Operator at support@nashconnect.me and/or via the support section on the Website, or by other means provided by applicable law.

The data subject has the right to obtain information about the processing of their personal data to the extent provided by 152-FZ and other applicable law, including confirmation of processing, legal bases and purposes, methods of processing, the identity and address of the controller, categories of recipients, the data processed and their source, retention periods, information on cross-border transfers, the identity and address of processors acting on the controller’s behalf, and other information required by law.

The subject may request rectification, blocking or erasure of personal data if they are incomplete, outdated, inaccurate, unlawfully obtained or no longer necessary for the stated purposes, and may take other remedies provided by law.

If the subject believes that the Operator processes personal data in violation of 152-FZ or otherwise infringes their rights, they may lodge a complaint with the competent supervisory authority (for the Russian Federation, Roskomnadzor) or in court.

The data subject has the right to protect their rights and legitimate interests, including seeking damages and/or compensation for non-pecuniary harm in court where provided by applicable law.

The Operator’s rights and obligations are determined by applicable law and by agreements with data subjects and contractors. Compliance with this Policy is overseen by a designated person responsible for organising personal data processing.

Liability of persons processing personal data on the Operator’s instructions for unlawful use of data is governed by the civil contract or confidentiality agreement between the Operator and the contractor.

Persons who violate rules governing the processing and protection of personal data may bear material, disciplinary, administrative, civil or criminal liability as provided by federal law, internal policies and the Operator’s agreements.

The Policy is prepared by the person responsible for organising personal data processing and takes effect after approval. Comments and proposals may be sent to support@nashconnect.me. The Policy is reviewed at least annually and updated as needed. Information about the Operator (name, address, contacts) is published on the “Contacts” on the Website.

The terms of use of Nash are also set out in the “Terms of Service” at https://nashconnect.me/terms.

Nash — Personal data processing policy