PRIVACY POLICY

August 29th, 2022

This policy defines the policy of Directorii LLC (hereinafter referred to as the Operator) regarding the processing of personal data and contains information about the requirements for the protection of personal data implemented by the Operator. This policy applies to all personal data processed through the Service which the Operator receives or can receive from the User.

1. GENERAL TERMS

1.1. Operator had defined that the following terms and definitions for the purposes of this policy have the following meanings:

''Personal data'' is any information related to a directly or indirectly identified or identifiable natural person ("personal data subject"); an identifiable natural person is a person who can be identified directly or indirectly, in particular, by reference to an identifier such as first name, last name, patronymic (if any), identification number, individual taxpayer number, bank details, year, month, date and place of birth, address, e-mail address, phone number, family, social, property status, education, profession, income, metadata that are transmitted to the Operator in the process of using the Service using the software installed on the User's device (including data location, HTTP headers, IP address, cookie data, information about the User's browser, technical characteristics of equipment and software used by the User, date and time of access to the Service, addresses of the requested pages of the Service and other similar information), one or several physical, physiological cultural, genetic, spiritual, economic, cultural factors or by referring to factors of social identity. For the purposes of this policy, personal data also includes information about the User, the processing of which is provided for by the Agreement governing the use of the Service. The personal data is classified as confidential information. The Operator collects only such personal data that is necessary for the execution of the Agreement.

''Operator'', ''Controller'' is Directorii LLC, legal address: 7600 Boone Ave N Suite 65, Brooklyn Park, MN 55428, processing personal data, as well as determining the purpose of personal data processing, the content of personal data to be processed, actions (operations) performed with personal data.

''User'' is any natural person with full capacity to act (sui juris) (subject of personal data) including acting on behalf of and in the interests of a legal entity or other natural person who may in the process of using the Service provide the Operator with the personal data, either independently or through a legal entity represented by him/her that has expressed consent with the terms and conditions set forth in the Agreement by signing it including electronically. In the context of this policy, the User also means persons whose personal data is processed by the Operator on behalf of the User contained in the Agreement. For minors under the age of 13 years old (according to the Children's Online Privacy Protection Act (COPPA)) or of other age, if it is provided by the country of residence of the User, the Operator processes personal data solely based on the prior consent of the parents.

''Service'',"Website" is a set of software and hardware, united by the domain name space titled either https://directorii.com/ and/or contractors.directorii.com, providing interaction between Users and representing a web portal for the offer and order of the construction and other service as provided by the Users. The Service includes a collection of information, other computer programs (components, modules), databases, program codes, underlying know-how, algorithms, design elements, fonts, logos, as well as text, graphics and other materials, as well as other results of intellectual activity, the rights to which belong to the Operator as a copyright holder or licensee on the basis of a law, agreement or other transaction. The Service can also be available as an application via the mobile application stores.

''Agreement'', “Terms of use” is a user agreement terms and conditions of which are applied to the relations between the User and the Operator, governing the use of the Service and containing the User's consent/order to the Operator to process personal data.

''Processing of personal data'', ''Personal data processing'' are actions (operations) with personal data, including collection, recording, systematization, accumulation, storage, clarification (update, change), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction.

''Processor'' is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of and at request of the Operator.

''Recipient'' is a natural or legal person, government agency, authority, or other body to which personal data is disclosed, regardless of whether they are third parties or not.

''Third party'' is a natural or legal person, government body, agency, or other body other than the data subject, controller, processor, as well as persons authorized to process personal data under the direct supervision of the Operator or Processor.

''Automated processing of personal data'' is the processing of personal data using computer technology.

''Non-automated processing of personal data'', ''Processing of personal data without the use of automation'' is the processing of personal data contained in the personal data information system or extracted from such a system in cases when such actions are with personal data as the use, refinement, dissemination, destruction of personal data in relation to each of the personal data subjects is performed with the direct participation of a person.

''Distribution of personal data'' are actions aimed at the disclosure of personal data to an indefinite circle of persons.

''Provision of personal data'' are actions aimed at transferring personal data to a specific person or a specific circle of persons.

''Blocking of personal data'' is a temporary termination of the personal data processing (except when processing is necessary to clarify personal data).

''Destruction of personal data'' are actions as a result of which it is impossible to restore the content of personal data in the personal data information system and (or) as a result of which material carriers of personal data are destroyed.

''Anonymization of personal data'' are actions as a result of which it is impossible to determine whether personal data belongs to a specific owner without using additional information. Within the meanings of the GDPR it's called “pseudonymisation”.

''Use of personal data'' are actions (operations) with personal data committed for the purpose of making decisions, transactions, or other actions that give rise to legal consequences related to the subjects of personal data or otherwise affect their rights and freedoms or the rights and freedoms of others persons.

''Sale of personal data'' are actions as a result of which information and databases with personal data of persons are transferred from the Operator to third parties by completing a transaction.

''Publicly available personal data'' is personal data access to an unlimited circle of persons to which is granted with the consent of the subject or to which, in accordance with the applicable legislation, the requirement of confidentiality does not apply.

''Confidentiality of personal data'' is a requirement upon a person who has access to personal data not to allow its distribution without the consent of the subject or other legal basis.

“Device”, “User`s device” is a computer, mobile device, or virtual machine running a Service-compatible operating system with a compatible web browser installed.

''Statistics'' is information about the use of the Service, as well as the viewing by the Users of individual elements of the Service (pages, dialogs, interactive elements frames, content, etc.), collected using Counters, Trackers, cookies, beacons, and other similar technologies.

''Cookies'', ''cookie'' is a small piece of data sent by the web server and stored on the User's device. Cookies contain small pieces of text and are used to store information about how browsers work. They allow you to store and receive identification information and other information on computers, smartphones, phones, and other devices. Cookie specifications are described in RFC 2109 and RFC 2965. Other technologies are used for the same purposes, including data stored by browsers or devices, identifiers associated with devices, and other software. In this policy, all of these technologies are referred to as "cookies".

"Token" is a unique set of characters that identifies the User's Device without determining his personal data. The Token is generated at the time of the first use of the Service (for example, at the time of the first launch of the mobile application on the Device).

''Cookies'', ''cookie'' is a small piece of data sent by the web server and stored on the User's device. Cookies contain small pieces of text and are used to store information about how browsers work. They allow you to store and receive identification information and other information on computers, smartphones, phones, and other devices. Cookie specifications are described in RFC 2109 and RFC 2965. Other technologies are used for the same purposes, including data stored by browsers or devices, identifiers associated with devices, and other software. In this policy, all of these technologies are referred to as "cookies".

''Web beacons'' are images in electronic form (single-pixel (1x1) or empty GIF images). Web beacons can help the Operator recognize certain types of information on the User’s device, for example, cookies, the time and date of viewing the page, and the description of the page where the web beacon is located.

''Counter'', “Tracker” is part of the Service, a computer program that uses a piece of code that is responsible for analyzing cookies, collecting statistical and personal data of Users. Personal data is collected in anonymized form.

''IP-address'' is a number from the numbering resource of a data network built based on the IP protocol (RFC 791) which uniquely identifies a terminal (computer, smartphone, tablet, other device) when providing telematic communication services, including Internet access, other device or means of communication included in the information system and owned by the User.

''HTTP header'' is a row in the HTTP message that contains a colon-separated name-value pair. The HTTP header format follows the common ARPA network text message header format described in RFC 822.

"Messenger" is an information system and / or computer program (mobile application, web service, web application, etc.) that is designed and / or used to receive, transmit, deliver and / or process electronic messages from Internet users (for example, Skype, WhatsApp, Facebook Messenger, etc.).

"Applicable Law", “Applicable Legislation” is the law of the country in which the Operator is registered or a resident of which he is. In some cases, applicable law may be understood as the law of the country in which the User lives or is a resident of which he is, if such legislation establishes the priority of its rules over the rules of this policy.

1.2. All other terms and definitions found in the text of this policy are interpreted by the Parties in accordance with applicable law, current recommendations (RFC) of international standardization bodies on the Internet, and the usual rules for the interpretation of relevant terms on the Internet.

1.3. Terms and definitions used in this Agreement can be used both in the singular and in the plural, depending on the context, the terms can be spelled both in uppercase and lowercase letters.

1.4. The names of the headings (articles), as well as the design of this document, are intended only for the convenience of using the text of the Agreement and have no literal legal value.

1.5. This policy has been developed in accordance with requirements of the international legislation and Applicable Law.

1.6. This policy defines the procedure and conditions for the processing of personal data by the Operator, including the procedure for transferring personal data to third parties, the features of manual processing of personal data, the procedure for accessing personal data, the system for protecting personal data, the procedure for organizing internal control and liability for violations in the processing of personal data, and also other issues.

1.7. This policy takes effect from the moment it is approved by the Operator and is valid indefinitely until it is replaced with a new policy.

1.8. The Operator has the right to make changes to this policy without the consent of the User. All changes to the policy are made by the regulatory act of the Operator.

1.9. This policy applies to all stages of the personal data processing performed using the Service without using automation tools. The Operator does not control and is not responsible for websites owned by third parties which the User can access by clicking on the links posted on the Service.

2. LEGAL GROUNDS FOR PERSONAL DATA PROCESSING

2.1. The Operator's processing of the User's personal data is guided by the international acts in the field of personal data protection, acts of applicable law, as well as, in relation to Users located in the territory:

– Minnesota State, United States of America: Minnesota Statutes and other applicable federal legislation.

2.2. The User's personal data is processed on the basis and in pursuance of the Agreement governing the use of the Service, and other transactions, agreements, or contracts concluded between the User and the Operator or based on the User's separate consent to such processing.

2.3. The User's personal data is processed by the Operator only if the User reached the age of 16. In case the User is under 16 years old, then the obligatory consent of the legal representatives of the User is required, otherwise the Operator upon detecting a discrepancy in age with the required one shall remove the Personal Data of such User from the Service.

3. PURPOSES FOR COLLECTION OF THE PERSONAL DATA

3.1. The Operator processes only the personal data necessary for using the Service or executing transactions, agreements, and contracts with the User, except for cases when the legal norms of the Applicable Law provide for the mandatory storage of personal information for a period specified by law, in particular, in accordance with the legislation on accounting and the rules for organizing state archives.

3.2. When processing personal data, the Operator does not combine databases containing personal data which is to be processed for incompatible purposes.

3.3. The Operator processes the personal data of the User for the following purposes:

  • using personal data for the purpose of concluding and executing the Agreement or any other transaction with the Operator;
  • using personal data for the purpose of proper operation of the Service in accordance with the expectations of Users in particular for correct identification of Users or for the correct provision of the functionality of the Service, if the result depends on the data provided;
  • placing customized advertising and/or other information in any section of the Service and interrupting the use of the Service with advertising information;
  • conducting marketing programs, various offers, promotions, and advertising events related to the Service;
  • conducting statistical and other studies of the use of the Service based on anonymized data;
  • compliance with the mandatory requirements of the Applicable Legislation.

4. VOLUME AND CATEGORIES OF PERSONAL DATA BEING PROCESSED, CATEGORIES OF PERSONAL DATA OWNERS

4.1. The Operator can receive the User's personal data from various sources, in particular:

  • from the Service in the course of their operation;
  • in process of usage of the Service by the User;
  • when the User contacts the technical support;
  • as part of the User's participation in marketing programs, various offers, promotions, and advertising activities of the Operator related to the Service.

4.2. Personal data allowed to be processed in accordance with this policy and provided by Users who are physical persons using the Service by filling in the appropriate input fields when using the Service may include the following information:

  • Full Name;
  • Address;
  • E-mail address;
  • Phone number;
  • Personal photo;

4.3. Personal data processed in accordance with this policy and automatically transferred to the Operator in the process of using the Service including the software installed on the User's device may include the following information:

  • HTTP headers;
  • IP address of the Device;
  • data collected by Counters;
  • data collected by Web beacons;
  • information about the browser;
  • technical specifications of the device and software;
  • technical data on the operation of the Service, including the dates and times of use and access to the Service;
  • addresses of requested pages of the Service website;
  • geolocation data;
  • cookie data, cookie identifiers.

4.4. In accordance with this policy, the Operator processes the personal data of persons belonging to the following categories of personal data owners:

  • physical persons using the Service in accordance with the Agreement on its use;
  • physical persons using the services of the Operator on the basis of the Agreement, other agreements and transactions;
  • physical persons who do not use the Operator's services and do not use the Service, but visit the public pages of the Operator's Website.

4.5. Certain categories of personal data of Users are processed with the following features:

  • User's information. A number of data is used to provide the functionality of the Service related to the User's personal data, in particular, last name, first name, middle name, email address and other data. The token assigned to the User can be used to send messages and notifications to the User's Device (for example, messages with important warnings).
  • Information about the use of the Service. Such information is processed in order to study the activity of the Service and it`s interaction with the User, in particular, how long it took the Service to perform one or another operation at the request of the User, what functionality is used by Users more often than others, the type of action performed via Service (click, hover, etc.), date and time of the action; URL of the page, Referer, screen resolution, class of the clicked HTML element, data on the number of page views of the Service, clicks on selected hyperlinks, data on the facts of filling out forms on the Service, including errors when filling them out, data on using the Service interface (opening dialog boxes, transitions, launches, crashes, etc.). Such information helps the Operator to solve problems in the operation of the Service, prevent fraudulent activities, improve the Service, increase it`s performance and make it more convenient to use.
  • Technical characteristics of the User's device including its IP address, and its software. Information such as the type of Device, operating system, IP address, method of connecting to the network, etc., may be needed in order for the Operator to be able to take into account the specifics of the operation of the Service on various devices, in various networks and ensure its compatibility with third-party software security.
  • Information about the approximate location of the User. Both in the active state and in the background, the Service can collect data about the User's location provided to him by the User's device hardware for the purposes of provision of Services to the User and information relating to it`s location.
  • Data collected by counters and cookie data. The processing of this data helps the Operator to study the activity of the Service and its website using third-party software tools, determine the number of downloads, installations, deletions of the Service from the User's device, the sources of transition to the download page. Such information helps the Operator to better understand the behavior of Users and improve the distribution channels of the Service.

5. TERMS AND PROCEDURES OF PERSONAL DATA PROCESSING

5.1. The Operator has the right to process the personal data of the User without notice to the authorized body for the protection of the rights of personal data subjects.

5.2. The Operator processes the User's personal data using the Service without using automation tools in accordance with the laws, statutes, codes, rules, regulations, and requirements of the Applicable Legislation that establish requirements for ensuring the security of personal data during its processing and for observing the rights of personal data subjects. Such actions with personal data as the use, refinement, distribution, destruction of personal data of the User are performed with the direct participation of the Operator's employees.

5.3. The Operator processes and stores the User's personal data for a period determined in accordance with the Agreement on the use of the Service, or about which the Operator informed the User upon receipt of the User's consent to the processing of the personal data in another way (in a check-box, a text message, in email, etc.).

5.4. Concerning the personal data of the User, its confidentiality is maintained, except for cases when the User voluntarily provides information about himself/herself for general access to an unlimited circle of persons.

5.5. The Operator has the right to transfer the User's personal data to Processor, Recipient, third parties using modern methods of connection encryption via the secure HTTPS protocol in the following cases:

  • the User has requested such a transfer from the Operator;
  • there is the User's consent to such actions;
  • the transfer is necessary for the User in order to use certain functions of the Service (for example, for authorization through accounts on social networks) or for the execution of a certain agreement, contract, or transaction with the User;
  • the transfer is provided for by the Applicable Legislation or other legal norms as part of the procedure established by laws, statutes, codes, rules, regulations, and requirements;
  • in the event of a transfer of rights to the Service, it is necessary to transfer personal data to the acquirer simultaneously with the transfer of all obligations to comply with the terms of this policy in relation to the received personal data received;
  • to ensure the protection of the rights and legitimate interests of the Operator or third parties when the User violates this policy or the Agreement on the use of the Service;
  • in other cases provided for by laws, statutes, codes, rules, regulations, and requirements.

5.6. The Processors can be:

  • website hosting provider;
  • operator of an electronic platform distributing the Service or services provided with it`s help (Apple AppStore, Google Play);
  • other persons entrusted with the processing of personal data on behalf of the Operator.

5.8. In case a violation of personal data protection can create a high degree of risk for the rights and freedoms of individuals, the Operator notifies the User about the leakage of personal data without unreasonable delay. A communication to the data subject is not required if any of the following conditions are met: (a) The Operator has taken appropriate technical and organizational protective measures to personal data affected by the leak, including measures that display personal data in an incomprehensible form for any person who does not have the right to access it, including cryptographic protection; (b) the Operator has taken subsequent measures to ensure that the high risk to the rights and freedoms of data subjects is no longer able to get realized; (c) a disproportionate effort is required. In this case, instead, a communication is made to the public or a similar measure is taken by which the data subjects are equally informed.

5.9. The Operator shall take the necessary organizational and technical measures to protect the User’s personal data from unauthorized or accidental access, destruction, alteration, blocking, copying, distribution, as well as from other unlawful actions of third parties. In particular, all processed data is transmitted using modern methods of connection encryption via the secure HTTPS protocol.

5.10. The Operator together with the User takes all necessary measures to prevent losses or other negative consequences caused by the loss or unauthorized disclosure of the User’s personal data.

5.11. The Operator has the right to transfer personal data to the bodies of inquiry and investigation, other authorized bodies on the grounds stipulated by laws, statutes, codes, rules, regulations, and requirements.

5.12. When collecting personal data, the Operator records, systematizes, accumulates, stores, clarifies (updates, changes), extracts personal data of Users who are citizens of the respective country using databases located on the territory of such country or another country, if this is permissible in accordance with Applicable Law.

5.13. The Operator stops processing the personal data of the Users (which is processed with their consent) upon expiration of the User's consent to the processing or upon withdrawal of the User's consent to the processing of the personal data, as well as in the event of unlawful processing of personal data or the liquidation of the Operator.

6. PROCEDURE OF COLLECTION OF THE PERSONAL DATA USING WEB BEACONS, COUNTERS AND COOKIES

6.1. Data received from the Counters and the Cookies transmitted from the Operator to the User's Device and from the User to the Operator may be used by the Operator to achieve the purposes of processing Personal data in accordance with the privacy policy and personal data processing.

6.2. The Operator uses various types of Counters in the Service, which serve for different purposes and, depending on the type, can be classified into one of the following categories:

- “Required”, i.e. data received from the Counters, which is strictly necessary for the functioning of the critical components of the Service, identification of the technical characteristics of the User's Device and the software used, as well as authorization and payment by the User;

- "Analytical", i.e. data received from the Counters that allows the Service to recognize Users, count their number and collect information about their transactions within the Service, including information about actions performed within the Service;

- "Technical", i.e. data received from the Counters, which allows to collect information about the interaction of Users with the Service in order to identify errors and test new features to improve the performance of the Service;

- "Functional", i.e. data received from the Counters that allows the User to receive certain functions of the Service, interact with the interface of the Service and use its capabilities, record information about the actions performed in the Service and customize the Service in accordance with the needs of the User in order to remember the information entered by the User, save the preferred language, location, etc.;

- “Third party”, i.e. data received from the Counters that collects information about the User, traffic sources, the User's actions and the advertising displayed for the User, as well as the advertising that the User has made within the Service, in order to display advertising that may be of interest to the User, based on the analysis of the collected information. The indicated data of the Counters is also used for statistical and research purposes.

6.3. The Operator does not explicitly request for consent when receiving mandatory data from the Counters. Disabling required Counters is technically impossible, since they are part of the Service code. Disabling the Counters that collect functional and analytical data is also technically impossible.

6.4. The Counters placed by the Operator within the Service can be used by the Operator to analyze and collect personal data on the use of the Service in order to improve the quality of the Service, the level of convenience of it`s use, and improve the Service in general. The technical parameters of the operation of the Counters are determined by the Operator and may change without prior notice to the User.

6.5. The Operator may use Web beacons, either alone or in combination with other tools, to collect information about the use of the Service. The User has the right to block Web beacons when using the Service by prohibiting the download of images in the settings of his software (browser).

6.6. The Operator may use Cookies to customize User`s experience while using the Service. Such Cookies allow the Service to remember choices the User have made in the past, collect information about how the User uses a Service. Cookies created on the User`s computer by using the Service do not contain personally identifying information and do not compromise User`s privacy or security. The User shall be entitled to refuse the cookie or delete the cookie file from your computer or browser by using any of the widely available methods. Cookies may also be set by an organization other than the Operator, such as Facebook, or other social media services for which we have implemented “plug-ins.” Information on their cookie policies can be found on these sites directly.

6.7. The Operator also uses Google Analytics to analyze traffic to our site. Google uses Cookies to provide this service to the Operator. Google’s cookies are used to store information, such as what time the User`s visit occurred, whether the User had been to the Service before.

7. ACCESS TO PERSONAL DATA

7.1. The right to access the personal data of the User is reserved only to the Operator’s and/or the Processor's employees who are allowed by their work duties to work with the User's personal data based on a list of persons authorized to work with personal data which is approved by the Operator and/or the Processor.

7.2. It's prohibited for third parties who are not employees of the Operator and/or the Processor, or persons contracted to perform services for Operator which require access to personal data to perform said services, to access the personal data of the User without the consent of the User, except for cases established by laws, statutes, codes, rules, regulations, and requirements.

7.3. The access of the Operator’s and/or the Processor's employee or contracted persons as described in subsection 7.3 to the personal data of the User ceases from the date of termination of the employment relationship or contract relationship or from the date the employee loses the right to access the personal data of the User in connection with changed job duties, position or other circumstances in accordance with the procedure established by the Operator and/or the Processor. In the event of termination of employment, all media with the User’s personal data that were at the disposal of the dismissed employee of the Operator and/or the Processor are transferred to a higher-ranking employee in the manner established by the Operator and/or the Processor.

8. UPDATE, CORRECTION, DELETION, AND DESTRUCTION OF PERSONAL DATA

8.1. The User may at any time change, update, supplement, or delete the personal data provided to them or part thereof using the Service interface.

8.2. If the Operator independently identifies that the personal data is incomplete or inaccurate and notifies the Operator of the same in writing, the Operator shall take all possible measures to update personal data and make appropriate corrections.

8.3. If it is impossible to update incomplete or inaccurate personal data of the User, the Operator takes measures to delete it.

8.4. If it becomes known that the processing of the User's personal data is unlawful, the processing by the Operator shall stop, and the personal data shall be deleted.

8.5. If the Service interface is inoperative or the Service does not have a function for changing, updating, supplementing, or deleting the personal data by the User, as well as in any other cases, the User has the right to demand in writing from the Operator the clarification of his/her personal data, its blocking or destruction if personal data is incomplete, outdated, inaccurate, illegally obtained or is not necessary for the stated processing purpose.

8.6. The Operator makes the necessary changes to the personal data that are incomplete, inaccurate, or irrelevant in a period not exceeding seven business days from the date the User provides information confirming that the personal data is incomplete, inaccurate, or outdated unless Operator reasonably determines that more time is needed to verify the User’s claim.

8.7. The Operator destroys the User’s personal data illegally obtained or not necessary for the stated processing purpose within a period not exceeding seven business days from the date the User submits information confirming that such personal data is illegally obtained or is not necessary for the stated processing purpose.

8.8. The Operator notifies the User of the changes made and measures taken and takes reasonable measures to notify third parties to whom the personal data of this User was transferred.

8.9. User's rights to change, update, supplement, or delete personal data may be limited in accordance with the requirements of laws, statutes, codes, rules, regulations, and requirements. Such restrictions, in particular, may provide for the Operator's obligation to save personal data changed, updated, supplemented, or deleted by the User for a period specified by laws, statutes, codes, rules, regulations, and requirements and to transfer such personal data in accordance with the established procedure to state authorities.

9. RESPONSES TO USER'S REQUESTS FOR ACCESS TO PERSONAL DATA AND ITS DELETION

9.1. The User has the right to receive information from the Operator regarding the processing of his/her personal data, including:

  • confirmation of the fact that personal data is processed by the Operator;
  • legal grounds and purposes for processing personal data;
  • methods of processing personal data used by the Operator;
  • the name and location of the Operator, information about persons (except for the employees or contracted persons of the Operator) who have access to personal data or to whom personal data may be disclosed based on an agreement with the Operator or based on laws, statutes, codes, rules, regulations, and requirements;
  • processed personal data related to the respective User, the source of its receipt, unless otherwise provided for by laws, statutes, codes, rules, regulations, and requirements;
  • terms for processing personal data, including periods for its storage;
  • the procedure for the User to exercise the rights provided for by applicable laws, statutes, codes, rules, regulations, and requirements in the field of personal data;
  • information on completed or suspected cross-border data transfer;
  • name or surname, name, middle name, and address of the person who processes personal data on behalf of the Operator, if the processing is or will be entrusted to such a person;
  • other information provided by laws, statutes, codes, rules, regulations, and requirements.

9.2. The Operator provides free of charge the opportunity to familiarize yourself with the personal data processed and stored in the Operator’s information system within thirty calendar days from the date of receipt of a written request from the User.

9.3. In case the Operator refuses to provide information on the availability of personal data about the User or personal data to the User upon his/her request or upon receipt of a request from the User, the Operator shall provide in writing a reasoned response, which is the basis for such a refusal, within a period not exceeding thirty calendar days from the date of receipt of the User's request.

9.4. The Operator provides an opportunity to send a request for deletion of personal data (information about which was received by the User) by sending a request to the email address of the Operator as indicated in this Privacy Policy.

9.5. If the User sends a request the Operator shall delete his/her personal data within thirty calendar days from the receipt of such a written request from the User.

10. INFORMATION ON THE REQUIREMENTS FOR THE PROTECTION OF PERSONAL DATA AND THEIR IMPLEMENTATION

10.1. The security of personal data during its processing in the information system is ensured by a personal data protection system that neutralizes current threats.

10.2. The personal data protection system used by the Operator includes legal, organizational, technical, and other measures to ensure the security of personal data, defined taking into account current threats to the security of personal data and information technologies used in information systems.

10.3. With regard to personal data (which the User has given consent to being processed by the Processor) the Operator based on an agreement has the right to attract the Processor ensuring the security of such personal data when being processing in the information system.

10.4. When processing personal data in the information system, the Operator ensures:

  • taking measures aimed at preventing unauthorized access to the personal data of the User and/or transferring them to persons who do not have the right to access such information;
  • timely detection of unauthorized access to personal data;
  • avoidance of impact on technical means involved in the processing of personal data, as a result of which their functioning may be impaired;
  • ability to immediately restore personal data modified or destroyed due to unauthorized access to it;
  • continuous monitoring of the security level of personal data.

10.5. In order to comply with security requirements and implement a personal data security system, the Operator has implemented a private model of security threats to the personal data information system.

10.6. The Operator has determined the level of protection of personal data when processing it in the personal data information system owned by the Operator.

10.7. Based on the level of personal data security determined by the Operator when processing it in the personal data information system without using automation, the Operator developed and implemented a set of measures to protect and ensure the security of personal data.

10.8. The Operator uses hardware and software for processing and protecting personal data.

10.9. All employees or contractors of the Operator authorized to work with personal data, as well as those associated with the operation and maintenance of the personal data information system, are familiar with the Operator’s internal documents regulating the procedure for working with personal data.

10.10. The Operator has organized the process of training employees in the use of personal data protection equipment managed by the Operator. The training is held by employees with constant access to personal data, and employees associated with the operation and maintenance of the personal data information system and personal data protection facilities.

10.11. The internal documents of the Operator established that employees must immediately inform the appropriate official of the Operator about the loss, damage, or shortage of information carriers containing personal data, as well as about attempts to unauthorized disclosure of personal data, its reasons, and conditions.

11. Consent to personal data processing

11.1. The User decides to provide his/her personal data and agrees to its processing freely, voluntarily, of his/her own free will, and for his/her benefit.

11.2. Consent to the processing of personal data provided by the User is specific, informed, and explicit and given by his/her free will.

11.3. In case the User's personal data is processed on the basis and in pursuance of the Agreement governing the use of the Service, and other transactions, agreements or contracts concluded between the User and the Operator using the Service, such processing of the User's personal data does not require separate consent.

11.4. In case the User's personal data is processed based on a separate consent to such processing, expressed directly when using the Service by clicking on the appropriate button, by ticking the indicator of the corresponding check-box, sending an SMS message or email, such consent to the processing of personal data is provided by the User in the form of an electronic document signed with a simple electronic signature in accordance with the Agreement governing the use of the Service.

11.5. Consent to the processing of personal data may be revoked by the User following the procedure established by laws, statutes, codes, rules, regulations, and requirements.

12. FINAL PROVISIONS

12.1. If the User starts using the Service it means his/her acceptance of the terms of this policy. If the User disagrees with the terms of this policy, he/she should immediately stop using the Service.

12.2. This Policy and the relationship between the User and the Operator arising in connection with the application of this Policy are subject to the Applicable Law.

12.3. This policy is always publicly available at the following link: privacy-policy

12.4. The User can send all suggestions or questions regarding this policy to the Operator’s customer support service by sending an electronic message to the following email address [email protected].

13. DETAILS

Directorii LLC

Address: 7600 Boone Ave N Suite 65, Brooklyn Park, MN 55428

Email: [email protected]

Сontact us
Terms of Use
Privacy Policy