Personal Data Processing Policy
General Provisions
1. General Provisions
This Policy defines the operator's policy with regard to the processing of personal data and contains information on the implemented requirements to the protection of personal data, and is available for review by an unlimited number of persons on the Internet.
The purpose of this Policy is to ensure the protection of human and civil rights and freedoms in the processing of personal data, including the protection of the rights to privacy, personal and family secrecy.
The requirements of this Policy are mandatory for familiarization and execution by all employees of the operator who process personal data.
By clicking the consent button in the Privacy Policy window or checking the corresponding checkbox you unconditionally agree to the terms and conditions of this Policy.
2. Key Terms
personal data is any information relating to a directly or indirectly defined or identifiable natural person (subject of personal data), allowing to identify an identity, financial, payment and accounting data, phone book, data on the device location and list of other applications on the device, microphone and camera data, as well as other confidential information about the device or its use;
personal data authorized by the subject of personal data for dissemination is personal data, access to which is provided by the subject of personal data to an unlimited number of persons by giving consent to the processing of personal data authorized by the subject of personal data for dissemination;
operator is a person who independently or jointly with other persons organizes and (or) carries out processing of personal data, as well as determines the purposes of personal data processing, content of personal data processed, actions (operations) performed with personal data;
processing of personal data is any action (operation) or set of actions (operations) on personal data performed with or without the use of automation means, including collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, destruction of personal data;
automated processing of personal data is processing of personal data by means of computer equipment;
dissemination of personal data is actions aimed at disclosure of personal data to an indefinite range of persons;
provision of personal data is actions aimed at disclosure of personal data to a certain person or a certain range of persons;
blocking of personal data is temporary cessation of personal data processing (except for cases when processing is necessary to clarify personal data);
destruction of personal data means actions resulting in the impossibility to restore the content of personal data in the personal data information system and (or) resulting in the destruction of material carriers of personal data;
depersonalization of personal data means actions resulting in the impossibility to determine the belonging of personal data to a particular subject of personal data without the use of additional information;
personal data information system is a set of information technologies and technical means contained in databases of personal data and ensuring their processing;
cross-border transfer of personal data is transfer of personal data to the territory of a foreign country to a foreign authority, a foreign natural person or a foreign legal entity;
mobile application is a computer program intended for installation and use on a mobile device (tablet, cell phone, smartphone, communicator, other device allowing to use the Mobile application according to its functional purpose), which allows the user to access the website and perform the actions provided for by the offer through the website;
personal account is an individual section of the user on the website or in the mobile application, protected by authorization parameters, which is accessed by entering identifying data (login and password). The personal account is registered to the user's e-mail address after the user has registered on the website or in the mobile application;
login and password are sets of Latin letters and digits required for access to the personal account, which in combination serve as the user's identification data. Actions performed in personal account with the use of the user login and password are recognized as user actions;
user is a legally capable natural person over 18 years of age, who uses the information systems of the owner of the website and mobile application;
website is a set of means and information, texts, graphic elements, design, images, photo and video materials, other results of intellectual activity, as well as computer programs, intended for publication on the Internet and displayed in certain text, graphic or sound forms, united under a unique electronic address Global-Ex.cc.
3. Processing of Personal Data on the Global-Ex.cc Website
The list of data processed on the website includes:
e-mail;
history of exchanges; API key;
account identifier;
bank card number;
history of cashback transactions;
merchant account information;
verification details;
name and surname;
phone number;
passport details (including a photo or scanned copy of the passport);
correspondence with the technical support service.
This information is processed for the purposes of creating an account, performing exchange operations and providing other program functions, informing about the operation of the service, providing cashback and technical support. These purposes are realized on the basis of the Global-Ex Terms of Use (https://global-ex.cc/en/pages/pravila-obmena).
Verification of users is carried out in order to provide additional functions of the personal account. To pass verification, the user independently applies to the services of third parties and provides them with necessary information to which the operator does not have access. The operator receives only information about the fact of verification at the will of the user.
The Global-Ex.cc website does not process biometric personal data or transfer personal data across borders to countries that do not adequately protect personal data.
The operator does not process information about the location, residence address or citizenship of users. Data storage is carried out on the territory of the Russian Federation.
4. Website and Mobile Application Identifiers
4.1 The operator collects data through the Internet in two main ways: data provision and automatically collected information.
4.2 Personal data is provided by filling in the relevant forms on the website and in the mobile application, by sending e-mails to the operator's corporate address.
4.3 Automatically collected information, which is collected and processed by the operator: information about the interests of users on the website on the basis of entered search queries about the implemented and offered services, generalization and analysis of information about which sections of the website are of the greatest interest; search queries of website users in order to generalize and create customer statistics on the use of website sections.
4.4 The Operator automatically receives certain types of information through technologies and services such as web protocols, cookies, web notes, as well as through mobile application and third party tools.
4.5 A cookie is a piece of data automatically located on the hard disk of your computer each time you visit a website. A cookie is therefore the browser's unique identifier for a website. Cookies allow information to be stored on a server and help you navigate the web more easily, as well as allowing you to analyze the site and evaluate the results. Most web browsers allow the use of cookies, but you can change your settings to refuse cookies or track the path they are sent. However, some resources may not function properly if cookies are disabled in your browser.
4.6 Web Tags. On certain web pages or e-mails, an operator may use a common technology on the Internet called "web tags" (also known as "tagging" or "precision GIF technology"). Web tags help analyze the effectiveness of websites, for example, by measuring the number of visitors to a website or the number of "clicks" made on key positions on a website page.
4.7 Web tags, cookies and other monitoring technologies do not automatically capture personal data. If a user of a website or mobile application provides their data at their own discretion, for example when filling out a feedback form or sending an email, only then are processes for automatically collecting detailed information triggered for the usability of the websites and/or to improve user interaction.
5. Rights and Obligations of Operators and Subjects of Personal Data
The operator is obliged not to disclose to third parties and not to distribute personal data without the consent of the subject of personal data, unless otherwise provided for by federal law.
If, in accordance with the law, the provision of personal data and (or) obtaining the operator's consent to the processing of personal data is mandatory, the operator is obliged to explain to the subject of personal data the legal consequences of refusal.
If personal data is not received from the subject of personal data, the operator shall provide the subject of personal data with the following information prior to the processing of such personal data:
name and address of the operator or its representative;
the purpose of personal data processing and its legal basis;
list of personal data;
intended users of personal data;
the rights of the subject of personal data established by the Federal Law "On Personal Data";
the source of obtaining personal data.
The Operator is not obliged to provide the information specified in clause 3.3 in the following cases:
the subject of personal data has been notified of the processing of their personal data by another operator;
personal data are obtained on the basis of law or in connection with the execution of a contract to which the subject of personal data is a party, beneficiary or guarantor;
processing of personal data authorized by the subject of personal data for dissemination, shall be carried out in compliance with the relevant prohibitions and conditions;
the operator processes personal data for statistical or other research purposes, to carry out the professional activity of a journalist or scientific, literature or other creative activity, if the rights and legitimate interests of the subject of personal data are not violated;
provision of this information violates the rights and legitimate interests of third parties.
The contract concluded with the subject of personal data may not contain provisions restricting the rights and freedoms of the subject, as well as provisions:
establishing the processing of personal data of minors (unless otherwise provided for by the legislation of the Russian Federation);
allowing inaction of the subject of personal data as a condition for concluding the contract.
Processing of personal data for the purposes of promotion of goods, works, services on the market through direct contacts with potential consumers (direct marketing) by means of communication means, as well as for political agitation purposes is allowed only with the prior consent of the personal data subject. The operator is obliged to prove that such consent was obtained. The operator is obliged to immediately stop processing of personal data for the specified purposes at the subject's request.
The operator is not entitled to make decisions giving rise to legal consequences in respect of the personal data subject or otherwise affecting their rights and legitimate interests, based solely on automated processing of personal data, without obtaining written consent, unless otherwise provided by law.
The operator is obliged to explain to the subject the procedure for making a decision on the basis of exclusively automated processing of their personal data and possible legal consequences of such a decision, provide an opportunity to appeal against such a decision, as well as explain the procedure of protection the rights and legitimate interests by the subject of personal data. The operator shall consider the subject's appeal within thirty days from the date of its receipt and notify the subject of the consideration results.
The subject of personal data has the right to appeal the actions or inaction of the operator to the authorized body for the protection of the rights of personal data subjects or in court.
The subject of personal data has the right to protect their rights and legitimate interests in court, including the compensation for losses and (or) compensation for moral damage.
6. Updating, correction, deletion and destruction of personal data
The subject of personal data has the right to demand from the operator to clarify their personal data, block or destroy it if the personal data is incomplete, outdated, inaccurate, illegally obtained or not necessary for the stated purpose of processing, as well as to take measures provided for by the law to protect their rights.
In case the fact of inaccuracy of personal data is confirmed, the operator shall actualize the data.
In case the fact of unlawfulness of personal data processing is confirmed, the operator shall stop processing the data.
Personal data shall be destroyed when the purposes of personal data processing are achieved, as well as in case of withdrawal of consent by the subject of personal data, if:
otherwise is not provided for in the contract to which the personal data subject is a party, beneficiary or guarantor;
the operator is not entitled to carry out the processing on other legal grounds.
Within seven working days from the date of submission by the subject of personal data or their representative of information confirming that the personal data is incomplete, inaccurate or irrelevant, the operator is obliged to make the necessary changes to it.
Within seven working days from the date of submission by the personal data subject or their representative of information confirming that such personal data are illegally obtained or are not necessary for the stated purpose of processing, the operator shall destroy such personal data.
The operator is obliged to notify the subject of personal data or their representative about the changes made and measures taken, and to take reasonable measures to notify third parties to whom the personal data of this subject have been transferred.
7. Procedure for the Requests of Subjects of Personal Data and Aauthorized Bodies
The subject of personal data has the right to receive the following information upon request:
confirmation of the fact of personal data processing by the operator;
legal grounds and purposes of personal data processing;
the purposes and methods of personal data processing applied by the operator;
name and location of the operator, information about persons (except for the operator's employees) who have access to personal data or to whom personal data may be disclosed on the basis of a contract with the operator or on the basis of federal law;
processed personal data related to the respective personal data subject, the source of their obtaining, unless another procedure for the submission of such data is provided for by the federal law;
the time periods of personal data processing, including the storage periods;
the procedure for exercising the rights provided for by the Federal Law "On Personal Data" by the subject of personal data;
information on realized or suspected cross-border data transfers;
the name or surname, first name, patronymic and address of the person who processes personal data on behalf of the operator, if the processing is or will be entrusted to such a person;
information on the ways in which the operator fulfills the obligations set forth in Article 18.1 of the Federal Law "On Personal Data";
other information stipulated by federal laws.
The operator has the right not to provide information at the subject's request, if in accordance with federal laws:
processing of personal data, including personal data obtained as a result of operative investigation, counterintelligence and intelligence activities, is carried out for the purposes of national defense, state security and law enforcement;
processing of personal data shall be carried out by the authorities that detained the subject of personal data on suspicion of committing a crime, or filed criminal charges against the subject of personal data, or applied a preventive measure to the subject of personal data before the charges were filed, except for cases provided for by the criminal procedural legislation of the Russian Federation, if familiarization of the suspect or the accused with such personal data is allowed;
processing of personal data is carried out in accordance with the legislation on counteraction to legalization (laundering) of proceeds of crime and financing of terrorism;
access of the subject of personal data to their personal data violates the rights and legitimate interests of third parties;
processing of personal data is carried out in cases stipulated by the legislation of the Russian Federation on transport security in order to ensure sustainable and safe functioning of the transport system, protection of interests of individuals, society and the state in the sphere of the transport system from acts of unlawful interference.
Information provided at the subject's request shall be provided in an accessible form. The information provided shall not contain personal data of third parties, unless there are legal grounds for disclosure of such personal data.
The data shall be provided within 10 working days from the date of receipt of the request. This term may be extended for no more than five working days, if the operator sends a motivated notification to the data address, indicating the reasons for extending the term.
The request must contain:
number of the main identity document of the subject or their representative;
information on the date of issue of the document and the issuing authority;
information confirming the participation of the subject of personal data in relations with the operator (contract number, date of contract conclusion, conventional verbal designation and (or) other information), or information otherwise confirming the fact of personal data processing by the operator;
signature of the personal data subject or their representative.
The request may be sent in the form of an electronic document and signed with an electronic signature. The request shall be sent in free form to the operator's e-mail or address. The operator does not provide recommended forms of requests. If the request is sent by the subject's representative, the request must be accompanied by a document confirming the representative's authorization.
The Operator shall provide information to the personal data subject or their representative in the form in which the relevant appeal or request was sent, unless otherwise specified in the appeal or request.
The subject of personal data is entitled to apply to the operator again not earlier than thirty days after the initial application. If the information was not provided to the subject in full, the subject has the right to reapply to the operator before the expiration of the specified period.
The operator has the right to reasonably refuse to fulfill a repeated request. The operator is obliged to provide grounds for refusal to fulfill a repeated request.
The operator is obliged to provide the subject of personal data or their representative with a free of charge opportunity to familiarize with the personal data related to this subject of personal data in a manner similar to the procedure of providing information at the subject's request. In case of refusal, the operator shall provide a reasoned response with reference to the legal provision that is the basis for the refusal. The answer on refusal shall be provided within 10 working days from the date of receipt of the request. This term may be extended for no more than five working days if the operator sends a motivated notification to the data address indicating the reasons for the extension of the term.
Within ten working days from the date of receipt of the request, the operator is obliged to provide the necessary information to the authorized body for the protection of the rights of subjects of personal data at the request of this body. This term may be extended, but not more than for five working days in case the operator sends to the authorized body for the protection of the rights of subjects of personal data a motivated notification indicating the reasons for extending the deadline for providing the requested information.
8. Implemented Requirements to the Protection of Personal Data
The Operator shall take measures necessary and sufficient to ensure the fulfillment of obligations stipulated by the Federal Law "On Personal Data" and regulatory legal acts adopted in accordance with it:
appointment of the person responsible for the organization of personal data processing;
issuance of personal data processing policy and local acts in the field of personal data processing, determining for each purpose of personal data processing (1) categories and list of processed personal data, (2) categories of subjects whose personal data are processed, (3) methods of personal data processing, (4) terms of personal data processing and storage, (5) procedure of personal data destruction, as well as local acts establishing procedures aimed at prevention, detection and elimination of consequences of personal data breach;
application of legal, organizational and technical measures to ensure the security of personal data;
internal control over compliance of personal data processing with the law and local acts of the operator;
assessment of the damage in accordance with the requirements established by the authorized body for the protection of the rights of subjects of personal data, which may be caused to subjects of personal data in case of violation of the Federal Law "On personal data", the correlation between the said damage and the measures taken by the operator to ensure the fulfillment of the obligations stipulated by the Federal Law "On personal data";
familiarization (or appropriate training) of employees directly involved in personal data processing with the provisions of the Russian legislation on personal data, including requirements to personal data protection, processing policy and other local acts on personal data issues, local acts on personal data processing;
processing of users' personal data is carried out in a secure manner using modern encryption methods.
The operator implements legal, organizational and technical measures to ensure the security of personal data, based on the levels of protection and current threats to the security of personal data:
identification of threats to the security of personal data during their processing in information systems;
application of organizational and technical measures to ensure the security of personal data based on the levels of personal data protection;
application of information protection means that have passed the conformity assessment procedure in accordance with the established procedure (if necessary);
assessment of the effectiveness of the measures taken to ensure personal data security before the information system is put into operation;
accounting of machine-readable personal data carriers;
detecting facts of unauthorized access to personal data and taking measures to detect, prevent and eliminate the consequences of computer attacks and incidents in information systems;
recovery of personal data after unauthorized access to them;
establishing rules of access to personal data, as well as ensuring registration and accounting of all actions performed with personal data in the information system;
control over measures to ensure personal data security and information system security levels;
interaction with the state system of detection, prevention and liquidation of consequences of computer attacks on information resources of the Russian Federation, including informing about computer incidents resulting in unlawful transfer (provision, distribution, access) of personal data, in accordance with the procedure established by the federal executive body authorized in the field of security.
9. Final provisions
9.1 This Policy is a local normative act of the operator and is publicly available.
9.2 This Policy may be revised in any of the following cases:
in case of changes in the legislation of the Russian Federation in the field of processing and protection of personal data;
in cases of receiving orders from relevant state authorities to eliminate non-compliances affecting the scope of this Policy;
as decided by the operator's management;
when changing the purposes and terms of personal data processing;
when changing the organizational structure, structure of information and/or telecommunication systems (or introducing new ones);
when applying new technologies for processing and protection of personal data, including transmission and storage;
other cases requiring a review of this policy.
9.3 This Policy comes into effect from the date of its posting on the website at Global-Ex.cc
