PRIVACY POLICY OF DATA PRIVACY OFFICE LLC

Effective June 10, 2019

DPO LLC handles your data so that neither we nor anyone else can use them to harm your interests and rights, such as your right to privacy. We attach great importance to it as experts and opinion leaders in the field of personal data protection. We protect your interests by:

  • truthfully explaining why and how we use your information;
  • training and instructing our employees and regulating their access to your data;
  • deleting or limiting data as they are no longer needed for the purposes stated below; and
  • responding to your comments and requests promptly

The policy extends to:

  • our website data-privacy-office.com;
  • our email; and
  • our courses devoted to the protection of personal data.

Who are we and how can you contact us?

  • Limited Liability Company “Data Privacy Office”.
  • If you have any questions regarding the protection of your personal data, you can find our contact details on the Contact Us page.
  • We act as the controller of your personal data, as we independently decide for what purposes we need them and choose services and tools for their processing.
  • The National Research University “Higher School of Economics” (NRU HSE) will process your personal data if you enroll in the course “GDPR Data Privacy Professional” in Moscow. In this case, NRU HSE acts as a joint controller of your personal data which are required for NRU HSE based training and for obtaining a government continuing education certificate.

What data, for what purposes, based on what grounds and how long we process?

PURPOSE

LEGAL GROUND

PROCESSING DATA

STORAGE PERIOD

Providing you with requested services, satisfy your needs or answer your question

Contract with you or your company in your interest or your request before entering into a contractual relationship

Your name, middle name and surname

6 months after providing the service and, in case of a contract, for the period prescribed by the Belarusian legislation

Name of your company

Information about the price of the service and its payments

Your contact information

Aforementioned purposes

Aforementioned legal basis

Data in the messages you sent us

1 year after providing the service or the last communication

Results of your tests after the course

Offering you services that may be useful to you based on the services you previously purchased, including courses, software, consulting in the field of data protection or information management

Our legitimate interest to develop our business and satisfy our clients’ needs

Your name, middle name and surname

2 years after your last communication with our company, unless you have objected to such processing

Your contact information

Your position and the name of the company

Better understanding of our audience and their preferences

Legitimate interest to improve our service

Statistics about visits to our website, provided by services like Yandex Metrika or Google Analytics

14 months (more details)

Messages that you type in the chat window (both sent and unsent)

Adapting our courses to your needs

Legitimate interest to improve our service

Your name, middle name and surname

1 day after the end of the course

Your area of expertise or position

Confirming the authenticity of your certificate

Legitimate interest to prevent fraud and and maintaining high confidence in issued certificates

Your name, middle name, and surname, as well as data about the courses that you have attempted

25 years from the date of issue

Certificate details

Providing you with the opportunity to check your knowledge using online test. Informing you of the results. Providing you with recommendations

Contract

Your contact information

Results of your online test

2 weeks after the end of the test

 

Personal data that we process to enter into a contract are necessary to provide you with our services. For example, you can’t get a certificate or a government continuing education certificate (for courses organized jointly with NRU HSE) if you don’t provide us with your name.

Where did we get your data?

Information may come from:

  • directly from you (from our communication or forms that you filled);
  • from organization that sent you to the course;
  • from cookies stored in your browser by our website; and
  • from publicly available sources, including your company’s website or your public profiles in social media.

Who do we share your personal data with?

  • Location (business center, university, etc.) we use for the course may request your full name to arrange access to the site. As it would be impossible to provide you with the service without the transfer of these data, we transfer them based on our contractual relationship;
  • Services providing contextual advertising and remarketing such as Google Ads, Yandex Direct, Facebook Pixel or Google Tag Manager to show you advertising adapted to your interests, as well as statistical services from Google Analytics or Yandex Metrics to improve our website and advertising campaigns. Consequently, Yandex, Google Inc., and Facebook are provided with access to information about your visits to our website and actions that you perform on the pages you visit. We have access only to data that has been anonymized or aggregated (combined and mixed with data of other users).

Information about these companies and their data protection practices:

  • Yandex LLC (Russia). Address: Ulitsa Lva Tolstogo 16, Moscow, Russia 119021. For users based in EEC or in Switzerland Yandex represented by the company Yandex Oy with address: Moreenikatu 6, 04600 Mäntsälä, Suomi. Yandex Privacy policy. Unfortunately, Russia doesn’t ensure an adequate level of protection of personal data, so your data is protected by Standard Contractual Clauses, which are a part of Yandex.Metrica Data Processing Agreement (DPA) between us and Yandex Oy Limited Company.
  • “Oblachnyi hoster” LLC (Republic of Belarus). Our website is hosted by hoster.by (“Oblachnyi hoster” LLC). Data you leave on the website forms are accessible to the company. Address: Dzerzhinskogo av., 57, 8 floor. Subway station: Mihalovo. Hoster.by contacts. Unfortunately, Belarus doesn’t ensure an adequate level of protection of your personal data.
  • Facebook, Inc (USA). Address: 1601 Willow Road,  Menlo Park, CA 94025, USA / США (ATTN: Privacy Operations). If you are located in the EU, the EU-US “Privacy Shield” legal mechanism is used to transfer your data to Facebook to ensure that they are properly protected. Facebook Privacy policy.

Automated solutions

We neither use automated decision-making nor your personal data to automatically assess aspects of your personality (automated profiling).

Your rights

You have the right to access, correct, or delete your personal data and the right to restrict their processing, as well as the right to data portability.

If we process your data based on your consent, you have the right to withdraw your consent at any time. If you would like to exercise your right to withdraw your consent, please contact us.

In accordance with Article 77 of the GDPR, you as a data subject have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or of an alleged infringement of the GDPR.

If you have any questions about the protection of your personal data, you can contact us by using our contact details on the Contact page.