1. General Provisions
This Privacy Policy on personal data processing has been developed in accordance with the requirements of Federal Law No. 152-FZ “On Personal Data” of 27 July 2006 (hereinafter — the Personal Data Law) and defines the procedure for processing personal data and the measures taken by ONH Systems LLC (hereinafter the Operator) to ensure the security of personal data.
1.1. The Operator considers respect for human and civil rights and freedoms to be a fundamental principle of its activities, including the right to privacy, personal and family confidentiality, when processing personal data.
1.2. This Policy applies to all information that the Operator may obtain about visitors to the website https://onhs.kz/en/.
2. Key Terms Used in this Policy
2.1. Automated processing of personal data — processing of personal data using computer technology.
2.2. Blocking of personal data — temporary suspension of personal data processing (except where processing is necessary to clarify personal data).
2.3. Website — a collection of graphic and information materials, software and databases that ensure their availability on the Internet at https://onhs.kz/en/.
2.4. Information system of personal data — a set of personal data contained in databases, together with information technologies and technical means that ensure their processing.
2.5. Depersonalisation of personal data — actions that make it impossible, without additional information, to determine whether the personal data belongs to a specific User or another subject of personal data.
2.6. Processing of personal data — any action (operation) or set of actions performed with or without the use of automation tools on personal data, including collection, recording, systematisation, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), depersonalisation, blocking, deletion, destruction.
2.7. Operator — a state or municipal authority, legal entity or individual that independently or jointly with others organises and/or carries out the processing of personal data, determines the purposes of processing, the composition of personal data to be processed, and the actions performed with personal data.
2.8. Personal data — any information relating directly or indirectly to a specific or identifiable User of the website https://onhs.kz/en/.
2.9. Personal data made publicly available by the data subject — personal data to which the data subject has granted access to an unlimited number of persons by giving consent in accordance with the Personal Data Law.
2.10. User — any visitor to the website https://onhs.kz/en/.
2.11. Provision of personal data — actions aimed at disclosing personal data to a specific person or group of persons.
2.12. Distribution of personal data — any actions aimed at disclosing personal data to an indefinite number of persons, including publication in mass media, posting on the Internet or granting access in any other way.
2.13. Cross-border transfer of personal data — transfer of personal data to the territory of a foreign state, to an authority of a foreign state, a foreign individual or a foreign legal entity.
2.14. Destruction of personal data — any actions resulting in the irreversible destruction of personal data with the impossibility of further recovery, or the destruction of physical media containing personal data.
3. Main Rights and Obligations of the Operator
3.1. The Operator has the right to:
- obtain reliable information and/or documents containing personal data from the data subject;
- continue processing personal data without the consent of the data subject if there are legal grounds specified in the Personal Data Law;
- independently determine the composition and list of measures necessary and sufficient to ensure compliance with the Personal Data Law, unless otherwise provided by the Law or other federal laws.
3.2. The Operator is obliged to:
- provide the data subject, upon request, with information regarding the processing of their personal data;
- organise the processing of personal data in accordance with the current legislation of the Russian Federation;
- respond to requests and enquiries from data subjects and their legal representatives in accordance with the Personal Data Law;
- provide the competent authority for the protection of data subjects’ rights with the necessary information within 30 days from the date of receipt of a request;
- publish or otherwise provide unrestricted access to this Policy on personal data processing;
- take legal, organisational and technical measures to protect personal data from unauthorised or accidental access, destruction, alteration, blocking, copying, provision, distribution, and other unlawful actions;
- cease the transfer (distribution, provision, access) and processing of personal data, and destroy such data in the manner and cases provided for by the Personal Data Law;
- fulfil other obligations established by the Personal Data Law.
4. Rights and Obligations of Data Subjects
4.1. Data subjects have the right to:
- obtain information regarding the processing of their personal data, except in cases provided for by federal law. The Operator shall provide such information in an accessible form, and it shall not include personal data of other individuals unless there are legal grounds for such disclosure. The scope of information and the procedure for obtaining it are established by the Personal Data Law;
- request that the Operator clarify, block, or delete their personal data if it is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary for the stated purposes of processing, as well as take legal measures to protect their rights;
- require prior consent for the processing of their personal data for marketing goods, works, and services;
- withdraw consent to the processing of personal data;
- lodge complaints with the competent authority for the protection of data subjects’ rights or bring legal action in court against unlawful acts or omissions by the Operator in relation to the processing of their personal data;
- exercise other rights provided by the legislation of the Russian Federation.
4.2. Data subjects are obliged to:
- provide the Operator with accurate information about themselves;
- inform the Operator of any clarification (updating or modification) of their personal data.
4.3. Persons who submit inaccurate personal data about themselves, or personal data of another individual without that individual’s consent, bear liability in accordance with the legislation of the Russian Federation.
5. Principles of Personal Data Processing
5.1. Processing of personal data shall be carried out on a lawful and fair basis.
5.2. Processing shall be limited to achieving specific, pre-defined, and legitimate purposes. Processing that is incompatible with collecting personal data is not permitted.
5.3. Databases containing personal data that are processed for incompatible purposes must not be merged.
5.4. Only personal data that meet the purposes of their processing shall be subject to processing.
5.5. The content and scope of processed personal data must correspond to the declared purposes of processing. Excessive personal data in relation to the stated purposes is not permitted.
5.6. Accuracy, sufficiency, and, where necessary, relevance of personal data to the purposes of processing shall be ensured. The Operator shall take measures to delete or correct incomplete or inaccurate data.
5.7. Personal data shall be stored in a form that allows identification of the data subject for no longer than required by the purposes of processing, unless a longer storage period is required by federal law or by contract with the data subject. Once the processing purposes are achieved, or such purposes are no longer relevant, personal data must be destroyed or anonymised, unless otherwise required by law.
6. Purposes of Personal Data Processing
- The purpose of processing User personal data is to:
- provide information to the User via email;
- conclude, perform, and terminate civil-law contracts;
- provide the User with access to services, information, and/or materials available on the website;
- promote the Operator’s goods, works, and services on the market by making direct contact with potential consumers through communication tools.
- The Operator may also send the User notifications about new products and services, special offers, and events; establish feedback channels with the data subject, including notifications, requests concerning the use of the Operator’s website, service provision, and processing of requests and applications.
The User may at any time opt out of receiving such messages by sending an email to info@onhs.ru with the subject line “Unsubscribe from product, service updates, and special offers.” - Anonymised data of Users collected via web analytics services is used to gather statistics on User behaviour on the website, to improve its quality and content.
Categories of personal data processed:
- surname, first name, patronymic;
- email address;
- phone numbers;
- job title.
The website also collects and processes anonymised data of visitors (including cookies) through web analytics services (e.g. Yandex.Metrica, Google Analytics, and others).
Legal grounds for processing:
- Personal data is processed only when the User independently fills out and/or submits it through forms available on https://onhs.kz/en/. By completing the relevant forms and/or submitting their personal data, the User expresses consent to this Policy.
- Anonymised data is processed if permitted in the User’s browser settings (e.g. cookies enabled).
- Visitors may disable cookies in their browser settings (see the Help section of the relevant browser). In such cases, only strictly necessary cookies required for the functioning of the website and its services will be used; however, disabling cookies may affect proper website functionality.
- Processing is also carried out where necessary to comply with legal obligations.
This Policy applies exclusively to this Website. The Operator does not control and is not responsible for third-party websites that the Visitor may access via links on the Website.
Types of processing performed:
- collection, recording, systematisation, accumulation, storage, destruction, and anonymisation of personal data;
- sending of informational emails to the User’s email address.
7. Conditions for Processing Personal Data
7.1. Processing of personal data shall be carried out with the consent of the data subject.
7.2. Processing is necessary to achieve purposes provided for by international treaties of the Russian Federation or by law, or to fulfil obligations imposed on the Operator by Russian legislation.
7.3. Processing is necessary for the administration of justice, or for the execution of judicial acts, or acts of other authorities or officials enforceable under Russian law.
7.4. Processing is necessary for the performance of a contract to which the data subject is a party, beneficiary, or guarantor, or to conclude a contract at the initiative of the data subject.
7.5. Processing is necessary to exercise the rights and legitimate interests of the Operator or third parties, or to achieve socially significant objectives, provided that this does not infringe the rights and freedoms of the data subject.
7.6. Processing of personal data made publicly available by the data subject or at their request (hereinafter — publicly available personal data) is permitted.
7.7. Processing of personal data subject to publication or mandatory disclosure in accordance with federal law is carried out.
8. Procedure for Collection, Storage, Transfer, and Other Types of Processing of Personal Data
The security of personal data processed by the Operator is ensured through legal, organisational, and technical measures necessary to fully comply with the requirements of applicable data protection legislation.
8.1. The Operator guarantees the protection of personal data and takes all possible measures to prevent unauthorised access.
8.2. User personal data shall never, under any circumstances, be transferred to third parties, except as required by law or when the data subject has provided consent for such transfer to fulfil obligations under a civil-law contract.
8.3. If inaccuracies in personal data are identified, the User may update the data by sending a notification to the Operator via email at info@onhs.ru with the subject line “Update of personal data.”
8.4. The duration of personal data processing is determined by the achievement of the purposes for which the data was collected, unless otherwise provided for by contract or applicable legislation. The User may at any time withdraw their consent to processing by sending a notification to the Operator via email at info@onhs.ru with the subject line “Withdrawal of consent to personal data processing.”
8.5. Any information collected by third-party services, including payment systems, communication providers, and other service operators, is stored and processed by those parties in accordance with their own Terms of Use and Privacy Policies. The Operator bears no responsibility for the actions of such third parties.
8.6. Restrictions imposed by the data subject on the transfer (other than granting access) or on processing conditions (other than access) of personal data permitted for dissemination do not apply where personal data is processed for state, public, or other public interests as defined by Russian law.
8.7. The Operator ensures the confidentiality of personal data during processing.
8.8. Personal data is stored in a form that allows identification of the data subject for no longer than required for processing purposes, unless a longer retention period is prescribed by federal law or by contract with the data subject.
8.9. Processing of personal data may be terminated upon achievement of processing purposes, expiration of the data subject’s consent, withdrawal of consent, request to cease processing, or detection of unlawful processing.
9. List of Actions Performed by the Operator with Personal Data
9.1. The Operator performs the collection, recording, systematisation, accumulation, storage, updating (revision, modification), retrieval, use, transfer (distribution, provision, access), anonymisation, blocking, deletion, and destruction of personal data.
9.2. The Operator performs automated processing of personal data, including the receipt and/or transmission of information via information and telecommunication networks, or without such networks.
10. Cross-Border Transfer of Personal Data
10.1. Before initiating cross-border transfer of personal data, the Operator must notify the competent authority responsible for the protection of data subjects’ rights of its intention (this notification is submitted separately from the general notification of intent to process personal data).
10.2. Before submitting such notification, the Operator must obtain relevant information from foreign authorities, individuals, or legal entities to whom the cross-border transfer is planned.
11. Confidentiality of Personal Data
The Operator and any other persons who gain access to personal data are obliged not to disclose or distribute it to third parties without the consent of the data subject, unless otherwise required by federal law.
12. Final Provisions
12.1. Users may obtain any clarification regarding the processing of their personal data by contacting the Operator via email at info@onhs.ru.
12.2. Any changes to the Operator’s personal data processing policy shall be reflected in this document. The Policy remains in effect until replaced by a new version.
12.3. The current version of the Policy is publicly available on the Internet at: https://onhs.kz/en/policy/.