PERSONAL DATA PROCESSING POLICY

By using the mobile application Win-win trade (www.win-win-trade.con), you: provide your personal data to the data controller agree to the data controller’s processing of the same in accordance with the procedures set forth in this policy and agree to the terms and conditions of this policy.

INTRODUCTION

1. This document (“Policy”) (i) defines the policy of Win-win Trade, a company registered at Vynogradna street, 3, Ivano-Frankivsk, Ivano-Frankivsk region, 76493, Ukraine, with Identification Number 41627475 (“Data Controller”), with respect to processing of personal data which the Data Controller collects using the Internet, and (ii) contains information on personal data protection requirements implemented.

2. The Policy applies to personal data which the Data Controller may receive from the Mobile App’s user (“you” or “App User”) when you use Mobile App for various purposes. In any such case, please send your request in any form by email at support@win-win-trade.

3. Please feel free to contact the Data Controller any time with any questions regarding your personal data processing or to request that your personal data be modified (updated, supplemented, or revised), or to revoke your consent to the personal data processing within the scope and for the purposes referred to in the Policy.

In any such case, please send your request in any form by email at support@win-win-trade.

DEFINITIONS

4. Below are the main terms used in this Policy:
– “Data Controller”means Win-win Trade with its office at Vynogradna street, 3, Ivano-Frankivsk, Ivano-Frankivsk region, 76493, Ukraine, which arranges for and conducts personal data processing and defines purposes of the personal data processing, the scope of personal data to be processed, and actions/operations to be carried out with personal data;
-“Mobile App” means Win-win Trade.
– “PD Regulations” mean Federal Law No. 152-FZ On Personal Data dated July 27, 2006, any regulations adopted in pursuance of such law, General Data Protection Regulation, or any other applicable laws governing the protection of personal data;
– “personal data processing” means any action/operation or a set of actions/operations with personal data carried out with or without the use of any automation tools; a list of actions carried out by the Data Controller with your personal data is given in clause 14 below;
– “personal data” means any information directly or indirectly related to an identified or identifiable individual (personal data subject), i.e., information that directly identifies you (such as your name or email address) and information that does not identify you directly, but may be used in one way or another for identification (e.g., your mobile device details);
– “you” or “App User” mean any individual using the Mobile App.

5. The Data Controller shall provide unrestricted access to this Policy by posting its current version in the Privacy Policy section in the Mobile App, and a hard copy of the same shall be kept in the Data Controller’s office and may be provided to you at your request or otherwise under the PD Regulations.

6. This Policy shall be revised or updated if the Data Controller’s data processing procedures are modified, or the PD Regulations are amended.

DATA CONTROLLER’S PERSONAL DATA PROCESSING PRINCIPLES, TERMS, AND CONDITIONS

7. The Data Controller will process your personal data in accordance with the procedures stipulated by the PD Regulations on a fair and lawful basis.

8. The Data Controller will process your personal data strictly for the purposes defined in this Policy and such processing will be limited to the attainment of such specific, pre-defined, and lawful purposes. The Data Controller undertakes not to allow any personal data processing that is inconsistent with the purposes for which such data is collected as listed in this Policy. The personal data that the Data Controller collects in the Mobile App is not excessive relative to the declared purposes for which the same is processed.

9. The Data Controller will store your personal data in a form that makes it possible to identify you as a personal data subject for no longer than the purposes of personal data processing require unless the PD Regulations require otherwise. Unless the PD Regulations require otherwise, the Data Controller will destroy your personal data once the purposes of processing are achieved in accordance with the procedures stipulated by clause 29 of this Policy, or if processing of your personal data for such purposes is no longer necessary.

LEGAL REASONS FOR DATA CONTROLLER’S PERSONAL DATA PROCESSING

10. The Data Controller will process your personal data solely and exclusively subject to there being legal reasons under the PD Regulations, and such legal reasons are as follows:

– eyour consent for personal data processing with respect to marketing and research activities between the Data Controller and you (such as promotion of Win-win Trade products or other marketing interaction and studies);
– your consent for personal data processing with respect to your personal data shared though the Mobile App or otherwise;
– compliance with applicable laws, including, without limitation, those that assign the Data Controller’s functions, powers, and duties;
– exercise of rights and legitimate interests of the Data Controller or third parties in compliance with the PD Regulations.

PROCESSED PERSONAL DATA SCOPE AND PURPOSES

11. This Policy describes procedures used by the Data Controller to process personal data of the Site Visitors.

12. When you use the Site as a Site Visitor, the Data Controller collects data passively. The content, purposes, and scope of personal data collected in such event is further described in clauses 14 and 15 of this Policy.

13. Also, if you contact the Data Controller using the contact form on the Site or, in accordance with clause 3 of this Policy, the Data Controller will also process personal data you share, which may include your name, email address, telephone number, message subject and body, and other data shared by you. The Data Controller will use such data to process your query (e.g., to respond to your questions or requests, e.g., to send you requested documents or information).

14. The Data Controller will use personal data shared by the Site Visitors for the following purposes:

− to administer and protect our business and this Site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data);
− to deliver relevant Site content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you;
− to use data analytics to improve our Site, products/services, marketing, customer relationships and experiences; and
− to make suggestions and recommendations to you about goods or services that may be of interest to you.

INTERACTIVE DATA COLLECTION TECHNOLOGIES

15. To collect the Site browsing and user behavior data, such technologies as cookies (browser cookies and Flash cookies) and web beacons are used on the Site. The Data Controller and third-party vendors, acting under an agreement with the Data Controller, passively collect and use data variously, including:

−Via a browser: certain data is collected by most browsers, e.g., your Media Access Control (MAC) address, computer type and operating system version, Internet browser type and version, and Visitor location. The Data Controller may collect such information as, for example, your device type and identifier, if you access the Site from a mobile device. Such information is shared with the Data Controller when a Visitor accesses the Site.
−Using Cookies: Cookies are small text files stored on your computer. Cookies allow the Data Controller to collect such information as the browser type, time spent on the Site, web pages viewed, and language preferences. For visitors in Europe and the UK, we will request consent to use non-essential cookies, such as analytical cookies, and these will not be placed unless and until consent is provided by you.
The Data Controller and third-party vendors use this data to improve the Site operation, ensure security, facilitate browsing, display information more efficiently, and customize your experience of using the Site.
The Data Controller also uses cookies to identify your computer or device which makes it easier for you to use the Site.
Also, the Data Controller uses cookies to collect the Site statistics and analytics for ongoing improvements of its design and functionality, to better understand how individual visitors use the Site, and to assist in addressing any issues of concern (including for the Data Controller’s arrangements with third parties). Specifically, the Data Controller uses Google Tag Manager.Third-party vendors of the Data Controller, and, in particular, Google Display Network, may use cookies for online advertising purposes. Your relationships with such third-party vendors are governed by terms of use of such third-party vendors (https://policies.google.com/technologies/ads?hl=en-US).
If you share any information from the Site on any social media, such social media cookies may also be used.
You may disable cookies following the appropriate instructions of your browser. To learn more about cookies, please go to www.allaboutcookies.org.
If you disable cookies, certain Site features may work incorrectly.
−IP address: IP address is a numerical label your Internet provider assigns to your computer automatically. The IP address is identified and logged in the Data Controller’s server files each time a Site Visitor accesses the Site; web pages viewed, and time spent on the Site are also logged. Collection of IP addresses is a common Internet practice with many websites collecting such data automatically. The Data Controller uses IP addresses for such purposes as, for example, to assess the Site traffic, for server diagnostics and Site administration.
−Device Information: The Data Controller may collect your mobile device data, e.g., the unique device identifier.

PERSONAL DATA PROCESSING PROCEDURES, TERMS, AND CONDITIONS

16. This Policy applies to collection, recording, classification, capture, storage, revision (updating, modification), retrieval, use, transfer (sharing, accessing), cross-border transfer, blocking, deletion, and destruction of personal data collected by the Data Controller on the Site with the use of automation tools. The source of your personal data is you. We do not collect personal data about you from a third-party.

17. The Data Controller processes your personal data automatically without making any decisions that have any legal implications or otherwise affect your rights and legitimate interests based solely on personal data automated processing.

18. The Data Controller will ensure that databases used for collection, recording, classification, capture, storage, revision (updating, modification) and retrieval of personal data are in compliance with the PD Laws.

19. The Data Controller will keep your personal data collected on the Site confidential.

20. The Data Controller may delegate the processing of your personal data to a third party, subject to the PD Laws.

21. The Data Controller will transfer your personal data collected on the Site in the following events:

− you have authorized such transfer;
− such transfer is required to achieve any purposes of an international treaty or a law, or to fulfill and discharge any functions, powers, and duties of the Data Controller under applicable laws; or
− such transfer is required to perform an agreement to which you are party.

22. The Data Controller will share personal data collected on the Site only if the Data Controller has entered into an agreement with the recipient of personal data under which such third party receiving personal data from the Data Controller undertakes to keep personal data confidential and to adhere to the personal data processing principles and rules defined by the PD Laws and agreement with the Data Controller.

23. The Data Controller will share personal data (including by cross-border transfer to countries that do or do not provide an adequate level of protection of personal data subjects’ rights) with the following third parties:
− affiliates of the Data Controller;
− third-party vendors of such services as website hosting and administration, data analytics, infrastructure maintenance, IT services, services delivered by email or regular mail, audit services, and other services, if such data is needed for such persons to be able to provide the same; and
− in the event of restructuring, merger, sale, creation of a joint venture, or winding up of the Data Controller, transfer of its assets or shares in full or in part (including in connection with bankruptcy or court proceedings).

− affiliates of the Data Controller;
− third-party vendors of such services as website hosting and administration, data analytics, infrastructure maintenance, IT services, services delivered by email or regular mail, audit services, and other services, if such data is needed for such persons to be able to provide the same; and
− in the event of restructuring, merger, sale, creation of a joint venture, or winding up of the Data Controller, transfer of its assets or shares in full or in part (including in connection with bankruptcy or court proceedings).

24. The Data Controller will share personal data collected on the Site within the scope which the Data Controller may in its discretion deem necessary or appropriate:

− to effectively achieve purposes listed in clause 14 above;
− spursuant to requirements of the laws applicable to the Data Controller;
− to protect the Data Controller’s and its affiliates’ business;
− in response to requests from the government authorities;
− to facilitate any court proceedings; or
− to protect your rights and rights of the Data Controller, confidentiality, security, or property and/or rights, confidentiality, security, or property of the Data Controller and its affiliates.

25. When processing personal data, the Data Controller will make sure that personal data is accurate (assuming such data is true without having to verify the same), sufficient, and, where necessary, and fit for purpose. The Data Controller will take appropriate measures to delete or update incomplete or inaccurate data, including in the events referred to in this Policy.

26. The Data Controller will apply required managerial, technical, and administrative arrangements to protect personal data received on the Site in accordance with the PD Laws.

PERSONAL DATA PROCESSING TERM AND TERMINATION

27. The Data Controller will store personal data collected on the Site for as long as necessary for the purposes of this Policy unless longer storage is necessary or permitted by the laws applicable to the Data Controller.

28. The Data Controller may terminate personal data processing once the purposes of such processing have been attained or where such processing is found to be illegitimate.

29. If processing of personal data collected on the Site is found to be illegitimate (on receipt of your or your representative’s query, on receipt of a request from an authorized agency, or following an internal audit) or if personal data is found to be inaccurate, the Data Controller will block or procure the blocking of such personal data that is processed illegitimately on receipt of such query or request for as long as such personal data processing is verified:

− if the inaccuracy of personal data is confirmed based on the information you, your authorized representative, or an authorized agency may provide in any form in writing or based on any other documents pursuant to PD Laws, the Data Controller shall update such personal data or procure the same to be updated within seven (7) business days of receipt of such data and unblock the same;
− if the illegitimate personal data processing is confirmed, the Data Controller shall terminate such illegitimate processing within three (3) business days of confirmation of the illegitimate processing or delete such personal data within ten (10) business days of confirmation of the illegitimate processing. The Data Controller shall notify you, or your representative, or the authorized agency, if the legitimacy of processing was verified at the request of such agency, of remedying any such violations.

30. If you revoke your consent, the Data Controller shall terminate personal data processing immediately, except when continued processing of such personal data is required by the laws applicable to the Data Controller, and in any event the Data Controller shall notify you of the outcome of such revocation.

31. If the purposes for which personal data collected on the Site have been attained, the Data Controller shall terminate personal data processing and destroy personal data within thirty (30) days of when the purposes of processing have been attained, unless your consent received by the Data Controller provides for a different deadline. If personal data collected on the Site may not be destroyed by such deadline, the Data Controller will block such personal data and ensure that the same destroyed within six (6) months, unless the laws applicable to the Data Controller, your consent for personal data processing, or an agreement to which you are a party, require otherwise.

Exit mobile version