Privacy Policy
1. General provisions
This Privacy Policy is prepared in accordance with the requirements of the Federal Law of 27.07.2006 No. 152-FZ "On Personal Data" (hereinafter referred to as the Personal Data Law) and establishes the procedure for processing personal data and the measures taken by VaccineGo (hereinafter referred to as the Operator) to ensure the security of personal data.
1.1. The Operator sets the protection of the rights and freedoms of individuals as its primary goal and condition for carrying out its activities in relation to the processing of personal data, including the protection of the rights to privacy, personal and family secrets.
1.2. This Operator's Policy regarding the processing of personal data (hereinafter referred to as the Policy) applies to all information that the Operator may obtain about visitors to the website https://vaccinego.app/.

2. Key concepts used in the Policy
2.1. Automated processing of personal data refers to the processing of personal data using computer technology.
2.2. Blocking of personal data is the temporary suspension of the processing of personal data, except in cases where processing is necessary for clarifying the personal data.
2.3. A website is a collection of graphical and informational materials, as well as computer programs and databases, providing their availability on the Internet at the network address https://vaccinego.app/.
2.4. Information system of personal data refers to the set of personal data contained in databases and the information technologies and technical means that ensure their processing.
2.5. Anonymization of personal data refers to actions that make it impossible to determine, without the use of additional information, the association of personal data with a specific User or other subject of personal data.
2.6. Processing of personal data includes any action (operation) or a combination of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transmission (distribution, provision, access), anonymization, blocking, deletion, and destruction of personal data.
2.7. Operator refers to a state body, municipal body, legal entity, or individual who independently or jointly with others organizes and/or performs the processing of personal data, determines the purposes of personal data processing, the composition of personal data subject to processing, and the actions (operations) performed with personal data.
2.8. Personal data includes any information directly or indirectly related to a specific or identifiable User of the website https://vaccinego.app/.
2.9. Personal data authorized by the subject of personal data for distribution refers to personal data to which an unlimited number of persons have access, granted by the subject of personal data through consent for the processing of personal data authorized for distribution in the manner provided by the Personal Data Law (hereinafter referred to as personal data authorized for distribution).
2.10. User refers to any visitor of the website https://vaccinego.app/.
2.11. Provision of personal data refers to actions aimed at disclosing personal data to a specific person or a specific group of individuals.
2.12. Distribution of personal data includes any actions aimed at disclosing personal data to an indefinite number of individuals (data transmission) or acquainting an unlimited number of individuals with personal data, including publication of personal data in mass media, placement in information and telecommunication networks, or providing access to personal data by any other means.
2.13. Cross-border transfer of personal data refers to the transfer of personal data to the territory of a foreign state, to a foreign state authority, or to a foreign individual or legal entity.
2.14. Destruction of personal data includes any actions that result in the irreversible destruction of personal data, making it impossible to restore the content of personal data in the information system of personal data and/or the physical destruction of the storage media of personal data.

3. Main rights and obligations of the Operator
3.1. The Operator has the right to:
  • receive reliable information and/or documents containing personal data from the data subject;
  • in case of withdrawal of consent by the data subject or receipt of a request to cease processing personal data, the Operator has the right to continue processing personal data without the consent of the data subject, based on the grounds specified in the Personal Data Law;
  • independently determine the scope and list of measures necessary and sufficient to ensure compliance with the obligations provided by the Personal Data Law and other regulatory legal acts adopted in accordance with it, unless otherwise provided by the Personal Data Law or other federal laws.
3.2. The Operator is obliged to:
  • provide the data subject, upon request, with information regarding the processing of their personal data;
  • organize the processing of personal data in accordance with the current legislation of the Russian Federation;
  • respond to inquiries and requests from data subjects and their legal representatives in accordance with the requirements of the Personal Data Law;
  • provide the necessary information to the authorized body for the protection of the rights of data subjects within 10 days from the date of receiving such a request;
  • publish or otherwise ensure unrestricted access to this Policy regarding the processing of personal data;
  • take legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, alteration, blocking, copying, provision, distribution, and other unlawful actions against personal data;
  • terminate the transfer (distribution, provision, access) of personal data, cease processing, and destroy personal data in the manner and cases provided by the Personal Data Law;
  • fulfill other obligations stipulated by the Personal Data Law.

4. The basic rights and obligations of personal data subjects
4.1. Personal data subjects have the right to:
  • Obtain information regarding the processing of their personal data, except in cases provided by federal laws. The information should be provided to the personal data subject by the Operator in an accessible form and should not contain personal data related to other personal data subjects, except when there are legal grounds for disclosing such personal data. The list of information and the procedure for obtaining it are established by the Law on Personal Data.
  • Request the Operator to clarify their personal data, block or delete it if the personal data is incomplete, outdated, inaccurate, unlawfully obtained, or not necessary for the stated purpose of processing, as well as take legal measures to protect their rights.
  • Specify the condition of obtaining prior consent for the processing of personal data for marketing purposes.
  • Withdraw their consent to the processing of personal data and submit a request to cease the processing of personal data.
  • Appeal to the authorized body for the protection of the rights of personal data subjects or file a lawsuit against the Operator for unlawful actions or inaction in the processing of their personal data.
  • Exercise other rights provided by the legislation of the Russian Federation.
4.2. Personal data subjects are obliged to:
  • Provide the Operator with accurate information about themselves.
  • Inform the Operator about the clarification (update, change) of their personal data.
4.3. Individuals who provide the Operator with false information about themselves or information about another personal data subject without their consent bear responsibility in accordance with the legislation of the Russian Federation.

5. Principles of personal data processing
5.1. The processing of personal data is carried out on a lawful and fair basis.
5.2. The processing of personal data is limited to the achievement of specific, predefined, and lawful purposes. Processing of personal data that is incompatible with the purposes of data collection is not allowed.
5.3. The merging of databases containing personal data, the processing of which serves incompatible purposes, is not allowed.
5.4. Only personal data that corresponds to the purposes of their processing shall be subject to processing.
5.5. The content and scope of processed personal data shall correspond to the stated purposes of processing. The processing of personal data shall not be excessive in relation to the stated purposes.
5.6. Accuracy, sufficiency, and, where necessary, relevance of personal data are ensured during their processing. The Operator takes necessary measures and/or ensures their implementation to delete or rectify incomplete or inaccurate data.
5.7. Personal data shall be stored in a form that allows identifying the data subject for no longer than is necessary for the purposes of personal data processing, unless the storage period is established by federal law, a contract with the data subject as a party, beneficiary, or guarantor. Processed personal data shall be destroyed or depersonalized upon achieving the purposes of processing or when the need to achieve these purposes is no longer present, unless otherwise provided by federal law.

6. Purposes of personal data processing
7. Conditions of personal data processing
7.1. Processing of personal data is carried out with the consent of the data subject for the processing of their personal data.
7.2. Processing of personal data is necessary for the purposes stipulated by an international treaty of the Russian Federation or by law, for the performance of functions, powers, and duties imposed on the operator by the legislation of the Russian Federation.
7.3. Processing of personal data is necessary for the administration of justice, execution of a court judgment, an act of another authority or official, subject to enforcement under the legislation of the Russian Federation on enforcement proceedings.
7.4. Processing of personal data is necessary for the performance of a contract to which the data subject is a party, or for the performance of a contract in favor of the data subject or at the initiative of the data subject, or for the conclusion of a contract where the data subject will be a beneficiary or a guarantor.
7.5. Processing of personal data is necessary for the protection of the rights and legitimate interests of the operator or third parties, or for the achievement of socially significant objectives, provided that the rights and freedoms of the data subject are not violated.
7.6. Processing of personal data is carried out when access to such data is provided by the data subject or at their request (hereinafter referred to as publicly available personal data).
7.7. Processing of personal data is carried out when the publication or mandatory disclosure of such data is required by federal law.

8. Procedure for the collection, storage, transmission, and other types of processing of personal data
The security of personal data processed by the Operator is ensured through the implementation of legal, organizational, and technical measures necessary to fully comply with the requirements of the current legislation on the protection of personal data.
8.1. The Operator ensures the security of personal data and takes all possible measures to prevent unauthorized access to personal data.
8.2. The User's personal data will never be transferred to third parties under any circumstances, except as required by applicable law or with the consent of the data subject to transfer the data to a third party for the performance of obligations under a civil contract.
8.3. In case of inaccuracies in personal data, the User may update them independently by sending a notification to the Operator at the Operator's email address info@vaccinego.app with the subject "Update of personal data."
8.4. The period for processing personal data is determined by the achievement of the purposes for which the personal data were collected, unless otherwise provided by the contract or applicable legislation.
The User may revoke their consent to the processing of personal data at any time by sending a notification to the Operator via email to the Operator's email address info@vaccinego.app with the subject "Revocation of consent to the processing of personal data."
8.5. All information collected by third-party services, including payment systems, communication tools, and other service providers, is stored and processed by those entities (Operators) in accordance with their User Agreement and Privacy Policy. The data subject should familiarize themselves with these documents. The Operator is not responsible for the actions of third parties, including service providers mentioned in this section.
8.6. Prohibitions on transfer (except for providing access) or processing conditions (except for obtaining access) of personal data imposed by the data subject do not apply in cases of processing personal data in the public interest as defined by the legislation of the Russian Federation.
8.7. The Operator ensures the confidentiality of personal data during their processing.
8.8. The Operator stores personal data in a form that allows identifying the data subject for no longer than necessary for the purposes of processing the personal data, unless the storage period is established by federal law, a contract to which the data subject is a party, a beneficiary, or a guarantor.
8.9. The termination of personal data processing may occur when the purposes of processing personal data are achieved, the consent of the data subject expires or is revoked, or there is a requirement to terminate the processing of personal data or when the unlawful processing of personal data is discovered.

9. List of actions performed by the Operator with the obtained personal data
9.1. The Operator collects, records, organizes, accumulates, stores, clarifies (updates, changes), retrieves, uses, transfers (distributes, provides, grants access), depersonalizes, blocks, deletes, and destroys personal data.
9.2. The Operator carries out automated processing of personal data with or without the use of information and telecommunication networks, obtaining and/or transmitting the received information.

10. Cross-border transfer of personal data
10.1. Before commencing the activities related to the cross-border transfer of personal data, the Operator must notify the authorized body for the protection of the rights of data subjects of their intention to carry out cross-border transfer of personal data (such notification is separate from the notification of intention to process personal data).
10.2. Before submitting the above notification, the Operator must obtain relevant information from the authorities of the foreign state, foreign individuals, or foreign legal entities to whom the cross-border transfer of personal data is planned.

11. Confidentiality of personal data
The Operator and other persons who have access to personal data are obliged not to disclose or distribute personal data to third parties without the consent of the data subject, unless otherwise provided by federal law.

12. Final provisions
12.1. The User can obtain any clarifications regarding the processing of their personal data by contacting the Operator via email at info@vaccinego.app.
12.2. Any changes to the Operator's policy for the processing of personal data will be reflected in this document. The policy remains in effect indefinitely until replaced by a new version.
12.3. The current version of the Policy is freely available on the Internet at https://vaccinego.app/privacy-policy/.