1. General ProvisionsThis personal data processing policy is compiled in accordance with the requirements of Federal Law No. 152-FZ dated July 27, 2006 “On Personal Data” (hereinafter referred to as the “Law on Personal Data”) and defines the procedure for processing personal data and measures to ensure the security of personal data undertaken by Easytrip Inc. (hereinafter referred to as the “Operator”).
1.1. The Operator considers the observance of human and civil rights and freedoms in the processing of their personal data, including the protection of the right to privacy, personal and family secrets, as its most important goal and condition for conducting its activities.
1.2. This Policy applies to all information that the Operator may obtain about visitors of the website
https://easytripus.com.
2. Basic Terms Used in the Policy2.1.
Automated processing of personal data — processing of personal data using computer technology.
2.2.
Blocking of personal data — temporary suspension of the processing of personal data (except when processing is necessary to clarify the data).
2.3.
Website — a set of graphic and information materials, software, and databases accessible at
https://easytripus.com.
2.4.
Information system of personal data — a set of databases and IT tools for processing personal data.
2.5.
Depersonalization of personal data — actions making it impossible to identify a subject without additional information.
2.6.
Processing of personal data — any action or set of actions performed with or without automation, including collection, recording, storage, updating, use, transfer, depersonalization, blocking, and destruction.
2.7.
Operator — a person or entity processing personal data and determining the purposes and scope of data processing.
2.8.
Personal data — any information relating directly or indirectly to a specific or identifiable User of
https://easytripus.com.
2.9.
Personal data permitted for distribution — data made publicly accessible by the User via consent, in accordance with the Law on Personal Data.
2.10.
User — any visitor of the website
https://easytripus.com.
2.11.
Provision of personal data — disclosure of data to a specific person or group.
2.12.
Dissemination of personal data — disclosure of data to the general public, including via media or networks.
2.13.
Cross-border data transfer — transfer of personal data to foreign states, authorities, or individuals.
2.14.
Destruction of personal data — actions rendering personal data permanently unrecoverable.
3. Rights and Obligations of the Operator3.1. The Operator has the right to:
- Receive accurate data and documents from the data subject.
- Continue processing without consent if legally justified (as per the Law).
- Define its own list of data protection measures unless otherwise stated by law.
3.2. The Operator is obliged to:
- Provide data subjects with information upon request.
- Process data according to Russian legislation.
- Respond to data subject inquiries.
- Cooperate with the authorized data protection authority.
- Publish this Policy.
- Protect data from unauthorized access or distribution.
- Cease processing when required by law.
4. Rights and Obligations of Personal Data Subjects4.1. Data subjects have the right to:
- Access information about the processing of their data (with exceptions under federal law).
- Demand corrections or deletion of incorrect or outdated data.
- Require consent for marketing purposes.
- Withdraw consent and request cessation of processing.
- Appeal unlawful actions to the authorities or courts.
4.2. Data subjects must:
- Provide accurate personal data.
- Inform the Operator about changes to their data.
4.3. Individuals who submit false information or third-party data without consent bear liability under Russian law.
5. Principles of Personal Data Processing5.1. Processing must be lawful and fair.
5.2. Data is processed for specific, legitimate purposes only.
5.3. Databases with different processing goals must not be merged.
5.4. Only data relevant to the processing goals is subject to processing.
5.5. Data must be adequate and not excessive.
5.6. The Operator ensures accuracy and relevance, and updates/corrects inaccurate data.
5.7. Data is stored no longer than necessary for processing purposes and must be destroyed or anonymized when no longer needed, unless otherwise provided by law.
6. Purposes of personal data processingPurpose of processing | conclusion, execution and termination of civil law contracts |
Personal data | last name, first name, patronymic phone numbers |
Legal grounds | the statutory (constituent) documents of the Operator |
Types of personal data processing | collection, recording, systematization, accumulation, storage, destruction and depersonalization of personal data |
7. Conditions for Personal Data Processing7.1. Personal data is processed with the consent of the data subject.
7.2. Processing of personal data is necessary to achieve goals established by an international treaty of the Russian Federation or by law, or to perform functions, powers, and duties imposed on the Operator by Russian legislation.
7.3. Processing of personal data is necessary for the administration of justice, execution of a court decision or a decision of another authorized body in accordance with Russian legislation on enforcement proceedings.
7.4. Processing of personal data is necessary for the performance of a contract to which the data subject is a party, beneficiary, or guarantor, or for the conclusion of such a contract at the initiative of the data subject.
7.5. Processing of personal data is necessary for the realization of legitimate interests of the Operator or third parties, or for purposes of public significance, provided that such processing does not infringe on the rights and freedoms of the data subject.
7.6. Processing is carried out for personal data made publicly available by the data subject or at their request (hereinafter — publicly accessible personal data).
7.7. Processing of personal data is carried out when such data is subject to publication or mandatory disclosure under federal law.
8. Procedure for Collecting, Storing, Transmitting, and Other Processing of Personal DataThe security of personal data processed by the Operator is ensured through legal, organizational, and technical measures that meet all applicable legal requirements.
8.1. The Operator ensures the security of personal data and takes all reasonable measures to prevent unauthorized access.
8.2. User personal data will never, under any circumstances, be disclosed to third parties, except when required by law or when the User gives explicit consent for such disclosure to fulfill a civil contract.
8.3. If inaccuracies in personal data are discovered, the User may update their data by sending a notification to the Operator’s email address:
takhirjon22@gmail.com with the subject “Update of Personal Data.”
8.4. The duration of data processing is determined by the purposes for which the data was collected, unless otherwise provided by law or contract.
The User may withdraw their consent to data processing at any time by sending a request to
takhirjon22@gmail.com with the subject “Withdrawal of Consent to Personal Data Processing.”
8.5. Any data collected by third-party services (including payment systems, communication tools, and other providers) is stored and processed by these providers in accordance with their own Terms of Use and Privacy Policies. The Operator is not responsible for actions of third parties, including those named in this paragraph.
8.6. Any restrictions imposed by the data subject on data transfer (other than access provision), or on processing conditions (other than data access), for publicly available data do not apply in cases of processing for public, state, or other interests as defined by Russian law.
8.7. The Operator ensures the confidentiality of personal data during processing.
8.8. The Operator stores personal data in a format that allows identification of the data subject only for as long as necessary to fulfill the processing purpose, unless otherwise required by law or contract.
8.9. Grounds for termination of data processing may include: the achievement of processing purposes, expiration of consent validity, withdrawal of consent by the data subject, a request to stop processing, or identification of unlawful processing.
9. List of Actions Performed by the Operator with Personal Data9.1. The Operator collects, records, organizes, accumulates, stores, updates (modifies), retrieves, uses, transfers (distributes, provides, grants access to), anonymizes, blocks, deletes, and destroys personal data.
9.2. The Operator performs automated processing of personal data, with or without data transmission via telecommunication networks.
10. Cross-Border Transfer of Personal Data10.1. Before engaging in cross-border data transfers, the Operator must notify the authorized data protection authority of its intention (this notice is separate from the general notification of data processing).
10.2. Prior to submitting this notice, the Operator must obtain the necessary information from the foreign authority, entity, or individual receiving the personal data.
11. Confidentiality of Personal DataThe Operator and any other person who gains access to personal data must not disclose or distribute such data to third parties without the consent of the data subject, unless required by federal law.
12. Final Provisions12.1. The User may contact the Operator at
takhirjon22@gmail.com for clarification on any matter related to personal data processing.
12.2. Any changes to this Policy will be reflected in this document. The Policy is valid indefinitely until replaced by a new version.
12.3. The current version of the Policy is publicly available at
https://easytripus.com/privacy.