Approved by Order No. 2P dated December 4, 2024 of the Director of JV LLC PII "IOKA TRAVEL" Zhumash Magzhan. Version 1.0, Tashkent, 2024.
1. Purpose
This Regulation establishes general requirements for the procedure for processing and protecting the personal data of personal data subjects processed by the Company.
The requirements of this Regulation apply to all employees of the Company.
2. Terms, definitions, abbreviations and designations
- Automated processing of personal data – the processing of personal data using computer technology.
- Website – one or several logically interconnected web pages (in this Regulation, the Website means the pages located at and associated with https://ioka.uz).
- Personal data information system – a combination of personal data contained in databases and the information technologies and technical means ensuring their processing.
- Company – Joint Venture Limited Liability Company with Foreign Investments "IOKA TRAVEL" (TIN 310792355).
- Counterparty – a legal entity or individual that has assumed, or intends to assume, any obligations under an agreement.
- Processing of personal data – any action (operation) or combination of actions (operations) performed on personal data, with or without the use of automation tools, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data.
- Personal data – any information relating to a directly or indirectly identified, or identifiable, natural person (personal data subject), including their last name, first name, patronymic, year, month, date and place of birth, address, marital, social and property status, education, profession, income, and other information.
- Employee – a natural person who has entered into an employment relationship with the employer.
- Personal data subject – a natural person to whom personal data directly or indirectly identifying them relates.
- Cross-border transfer of personal data – the transfer of personal data to the territory of a foreign state to a foreign government authority, a foreign natural person, or a foreign legal entity.
3. General provisions
This Regulation establishes the procedure and conditions for the collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of documents containing information classified as personal data of subjects whose personal data is processed by the Company, as well as the rules for protecting personal data.
4. Goals and objectives
The purposes of establishing this Regulation are to ensure that the procedure for processing personal data in the Company complies with the legislation of the Republic of Uzbekistan on personal data, as well as to develop a set of measures aimed at ensuring the protection of personal data processed by the Company.
The objectives of this Regulation are to define the principles of personal data processing, the conditions for their processing, methods of protection, as well as the rights of personal data subjects and the rights and obligations of the Company when processing personal data.
5. Concept and composition of personal data
The Company processes the personal data of the following categories of subjects: Company employees, including former employees; counterparties (representatives of client companies, representatives of companies with which the Company has contractual obligations, individual entrepreneurs, natural persons); job applicants; visitors and registered users of the Website.
The personal data subject independently decides to transfer their personal data to the Company.
6. Responsible persons
The person responsible for organizing the processing of personal data in the Company is a person appointed by order of the Director. In the absence of, or failure to appoint, such a person, their functions are performed by the Director on the basis of an order.
The person responsible for ensuring the security of personal data is the Head of the Information Technology Department.
7. Purposes of personal data processing
The purposes of processing the personal data of Company employees are: carrying out personnel, accounting and financial-economic activities; fulfilling the requirements of labor and pension legislation; keeping records of labor resources; optimizing communication between employees; managing employee performance; recruitment and personnel selection; preparing commercial proposals and reports; interaction under concluded agreements.
The purposes of processing counterparties' personal data are: monitoring current projects and sales plans; sending information to clients; conducting electronic auctions; interaction under concluded agreements.
The purposes of processing the personal data of job applicants are recruitment and personnel selection, and obtaining hiring approval.
The purposes of processing the personal data of visitors and registered users of the Website are: identification of parties within the scope of service provision; provision of personalized services; improvement of service quality; conducting statistical research based on depersonalized data; efficient execution of orders and agreements; registration of users for events.
8. Grounds for processing personal data
The processing of employees' personal data is carried out on the basis of the Labor Code of the Republic of Uzbekistan and written consent. The processing of counterparties' data is necessary for exercising the Company's rights and legitimate interests. The processing of the data of applicants and Website users is carried out on the basis of written or electronic consent.
9. Principles of personal data processing
The processing of personal data is carried out on a lawful and fair basis, is limited to the achievement of specific, predetermined purposes, does not permit the combination of databases with incompatible processing purposes, ensures the accuracy and relevance of data, and the data is subject to destruction or depersonalization upon achievement of the processing purposes.
10. Obtaining (collecting) personal data
Personal data is obtained and processed after the subject has signed a consent form or provided consent electronically on the Website. It is prohibited to collect data in a greater volume than provided for by law, as well as to request information about health status, political, religious, or other beliefs, except in cases provided for by the legislation of the Republic of Uzbekistan.
11. Regulation of access to and use of subjects' personal data
The Company has the right to entrust the processing of personal data to a third party, subject to compliance with the principles and rules of their processing. Government bodies are granted access rights only within the scope of their competence. Personal data is confidential information; all employees with access to it are required to sign a non-disclosure undertaking. An employee's access to personal data may be terminated upon transfer to another department, termination of the employment contract, or violation of non-disclosure obligations.
12. Specifics of processing the personal data of Company employees
An employee's personal data is submitted to the Human Resources Department and is supplemented throughout the entire period of employment. It is processed and stored in the Human Resources Department and the Finance Department for no longer than is necessary for the purposes of its collection. The personal data of former employees is subject to destruction after 75 years of storage, unless otherwise determined by the legislation of the Republic of Uzbekistan.
13. Rights of subjects to protect their personal data
The personal data subject has the right to complete information about their personal data, free access to it, the right to demand the destruction or correction of inaccurate data, the right to appeal unlawful actions of the Company in court, as well as other rights provided for by the legislation of the Republic of Uzbekistan.
14. Cross-border transfer of personal data
The cross-border transfer of employees' personal data is carried out in accordance with the legislation of the Republic of Uzbekistan and may be restricted. The transfer of the data of counterparties, applicants, and Website users abroad is not carried out, except in cases expressly provided for by law or by the subject's written consent.
15. Storage and destruction of personal data
Personal data is stored in a manner that excludes access by third parties and its loss. Personal data is destroyed upon expiration of the processing period, achievement of the processing purpose, upon the subject's request or withdrawal of consent, or by court decision. The destruction of documents and data is confirmed by the relevant acts.
16. Processing of personal data without the use of automation tools
Personal data processed without the use of automation tools is recorded on separate tangible media, taking into account the purposes of processing and the categories of data, ensuring separate and controlled processing.
17. Protection of personal data
The protection of personal data is ensured by a set of organizational and technical measures: the personal responsibility of employees, a permission-based access system, procedures for the storage and destruction of information, as well as non-disclosure agreements when interacting with third parties.
18. Obligations of persons authorized to process personal data
Employees authorized to process personal data undertake to know and comply with the requirements of this Regulation, to process data only for the established purposes and to the established extent, to maintain confidentiality, and to inform their supervisor of any violations or attempts at unauthorized access.
19. Liability for disclosure of personal data
Officials with access to personal data bear personal liability for violations of the regime for their protection in accordance with the legislation of the Republic of Uzbekistan, including disciplinary, material, civil, and administrative liability.