Positive Technologies
Who we are National sovereignty Products & services GISEC offer
Book a meeting at GISEC
← Back to main page
Legal

Terms, policies and consents

The documents below govern how we handle personal data and how this website may be used.

Data controller: Positive Technologies. To exercise your rights or withdraw a consent, write to privacy@ptsecurity.com.

Documents

  • Marketing communications consentOctober 1, 2024
  • Personal data processing consentOctober 1, 2024
  • Vulnerability disclosure policySeptember 1, 2020
  • Terms of useOctober 1, 2024
  • Privacy PolicyOctober 1, 2024
  • Data processing agreement
Document version dated: October 1, 2024

Consent to Receive Marketing and Information Communications

In accordance with applicable laws and acting of my own free will and in my own interest, I hereby give Positive Technologies consent to send me marketing and information communications about the products, services, content, promotions, and events of Positive Technologies and (or) its affiliated parties and partners.

The contact information I provided to Positive Technologies will be used for sending such communications (phone number, email, Telegram messenger account). Communications can be sent as test messages, emails, messages in messengers, push notifications, and by phone.

Positive Technologies has the right to perform the following actions (operations) with my personal data: collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, and transfer (provision, access) to affiliated persons of Positive Technologies and its partners; depersonalization, blocking, deletion, and destruction. Positive Technologies also has the right to process personal data using automation tools, as well as to carry out mixed processing of my personal data.

Consent is given for a period of 10 (ten) years from the date of its provision.

I take responsibility for the accuracy of the specified data.

Consent can be withdrawn by: (a) pressing the "unsubscribe" button (a link to which is contained in written communications from Positive Technologies) or (b) emailing Positive Technologies a written request to: privacy@ptsecurity.com

Document version dated: October 1, 2024

Consent to Personal Data Processing

Hereby, in compliance with the applicable laws and acting of my own free will and in my own interest, I consent to the processing of my personal data specified in the web form by Positive Technologies.

As part of the processing of personal data based on this consent, Positive Technologies has the right to collect, record, systematize, accumulate, store, clarify (update, modify), extract, use, and transfer (provide, access) to affiliated persons and partners of Positive Technologies; depersonalize, block, delete, and destroy my personal data. Positive Technologies also has the right to process personal data using automation tools, as well as carry out mixed processing of my personal data.

Consent is valid until the purpose of processing personal data is achieved, after which the personal data, in the absence of other legal grounds for processing it by Positive Technologies, will be deleted.

Consent can be withdrawn by sending Positive Technologies a written request by email to privacy@ptsecurity.com.

Document version dated: September 1, 2020

Positive coordinated vulnerability disclosure policy

At Positive Technologies, system security is our top priority. We are dedicated to making this technology-driven world a safer place. We take great care to safeguard our partners' and customers' systems and digital infrastructure, and sometimes in the course of our work, we may discover vulnerabilities in the systems of third parties. When this happens, we take all necessary steps to notify the affected third party (also referred to here as "you") in compliance with the vulnerability disclosure policy found on that party's website. In those cases when the party does not have a vulnerability disclosure policy on its website, we follow the procedure specified below. No matter what, we aim to report our vulnerability findings to you as quickly as possible so that you can take appropriate measures to protect your systems.

Here are the steps we take after discovering a vulnerability:

  • We notify you in compliance with the vulnerability disclosure policy on your website. If we cannot find a vulnerability disclosure policy, we will contact you via email or another contact method indicated on your website.
  • Once we have notified you, we expect you to release a patch or other appropriate fix for the vulnerability within 90 days. If the default 90 days are not enough for you to fix the vulnerability, an extension is possible, provided that communication and efforts are ongoing.
  • As an additional measure, we will send a reminder email on the thirtieth (30th) and sixtieth (60th) days after the initial notification.
  • If we do not receive a response from you within 90 days, we reserve the right to publicly disclose our findings in a limited format that does not contain information that would enable other parties to exploit the vulnerability.
  • If you release a patch or other fix for the vulnerability before the ninetieth (90th) day, we may publicly disclose our findings immediately after you release the patch or fix.

We will keep our findings in confidence for 90 days and will not disclose them without your permission. Exceptions to this may occur in case of law enforcement demands or legal proceedings.

We would like to play an active role as researchers and would appreciate your mentioning Positive Technologies in any publications you decide to make regarding the vulnerability.

Please feel free to contact us at info@ptsecurity.com for any matters related to vulnerability disclosure.

Document version dated: October 1, 2024

Terms of use

These Terms

The following Terms form an agreement between you (User) and us (Positive Technologies, we). Please read these Terms carefully before you use https://global.ptsecurity.com/ (Website). By accessing or using the Website, you acknowledge that you have read, understand, and agree to be bound by these Terms and to comply with all applicable laws and regulations. If you do not agree to these Terms, please do not use the Website.

The Terms can be accepted by clicking ‘accept' or ‘agree' to the Terms where this option is made available to you by Positive Technologies, and/or acknowledgment of any consent document; and/or continuous use of the Website. You accept and agree that Positive Technologies will treat your continued use of the Website as implied acceptance of the Terms.

Your use of the Website is also subject to any applicable terms, policies or rules that we may post or provide links to. This includes the Privacy Policy and consent documents. All such applicable terms, policies and rules are considered part of these Terms.
Some elements of the Website (both existing and new) may be subject to additional terms and/or conditions. When you first use these elements, we will bring this to your attention. In the event of any conflict between such additional terms and these Terms, the additional terms control.

From time to time we may change these Terms and the Website to reflect changes in relevant laws, regulatory requirements or changes in our technology, commercial practice, behaviours. We may also change these Terms and the Website to implement minor technical adjustments and improvements, which will not affect your use of the Website. When changes are made, Posititve Technologies will make a new version of these Terms available on the Website. You acknowledge and agree that if you use the Website after the date on which these Terms have changed, we will treat your use as acceptance of the updated Terms. Any revised version of the Terms will be effective immediately upon its publication on the Website.

Eligibility

You may not use the Website and may not accept the Terms, either on behalf of yourself or those for whom you have the legal authority to accept, if:

  • you cannot enter a legally enforceable contract with Positive Technologies (whether due to age, capacity or otherwise); or
  • it is not lawful to access the Website in your current jurisdiction.

When accessing or using the Website:

  • you are indicating that you have read and understood the information contained in these Terms;
  • you acknowledge that you have willingly accepted these Terms under the laws applicable to your country of residence;
  • you are eligible to access and use the Website under the Terms in accordance with the laws applicable to your country of residence.

Use of Personal Data

Personal Data is information that can be used to identify a natural person, either alone or in combination with other information. You can find out how we collect and process Personal Data in our https://global.ptsecurity.com/policies/consent. The Privacy Policy forms part of these Terms and it is important that you read and understand it.

Our Website

The Website has been designed to provide information about Positive Technologies, our products and services. Information available through the Website is subject to variation at any time without notice and we do not give any warranty that any such information will be accurate or complete at any particular time or at all.

The Website and any information or other material contained in it are made available strictly on the basis that you accept it on an ‘as is' and ‘as available' basis. Where you rely on any information or other material contained in it, you do so entirely at your own risk, and you accept that all warranties, conditions, and undertakings, express or implied, whether by common law, statute, trade usage, course of dealings, or otherwise in respect of the Website are excluded to the fullest extent permitted by law.

You agree to evaluate and understand all the risks associated with content use, including accuracy or usefulness of the content.

We cannot guarantee that this Website will always be available to users. We may at our sole discretion, suspend or terminate access to any aspect of the Website to any user at any time. Positive Technologies has the right, but not the obligation, to review, modify, pre-screen or remove any portion of the Website and any content that is available through the Website.

Mention of third-party products or services is for informational purposes only and constitutes neither an endorsement nor a recommendation.

Because international information is provided on the Website, not all products or programs mentioned will be available in your country. Please contact local sales representative for information as to products and services available in your country.

The Website provides links to other websites and resources on the Internet. Positive Technologies has no control over these websites and resources. Positive Technologies cannot be held responsible or liable for any damage or loss caused by or in connection to the use of this content that might be available through the links to such third-party websites and resources. We do not endorse any linked websites or resources.

Prohibited Conduct

When using the Website, you must comply with all applicable laws and regulations of your jurisdiction, and laws regarding the transmission of technical data. We reserve the right to investigate and take appropriate action against anyone who, in our sole discretion, is suspected of violating any applicable law, including, without limitation, reporting you to law enforcement authorities.

When using our Website, you explicitly agree not to:

  • use the Website (as well as any portion of it) in any manner not permitted by these Terms, any guidelines provided by us or the applicable law;
  • use the Website (as well as any portion of it) in an unlawful manner or in any manner that could damage or interfere with the provision of access to the Website to any person;
  • violate intellectual property rights of Positive Technologies or others;
  • send, upload or share any inaccurate, defamatory, discriminatory, obscene, shocking, hateful, threatening or otherwise inappropriate information;
  • send, post or share any unsolicited or unauthorized advertising, ‘spam,' ‘junk mail,' ‘pyramid schemes,' ‘chain letters,' or any other form of solicitation that is unauthorised;
  • threaten, harass, stalk, defame, or defraud any person or entity, abuse, harm, or interfere with the privacy of another person;
  • use information gained from the Website to identify or contact other users;
  • rent, sell, lease, loan, or trade access to the Website or related data;
  • engage in ‘framing,' ‘mirroring,' or otherwise simulating the appearance or function of the Website;
  • disguise the origin of content shared via the Website through manipulation of headers or identifiers or otherwise;
  • send deceptive or false source-identifying information, including "spoofing" or "phishing";
  • engage in identity theft, impersonate any natural or legal person or misrepresent your affiliation with Positive Technologies or any other person;
  • override, or attempt to override, and security features of the Website;
  • attack, abuse, interfere with, intercept, disrupt, or exploit any users, systems, or services, including but not limited to Denial of Service (DoS), monitoring, crawling, spamming, using bots or scripts, crawlers or distributing malware (such as viruses, Trojans, worms, spyware, or adware);
  • authorize, permit, enable, induce, or encourage any third party to do any of the above.

If you violate these Terms, Positive Technologies has the right to suspend or terminate your access to the Website at its sole discretion immediately without notice and with no further obligation to provide access to the Website to you in the future.

Intellectual Property Rights

Intellectual Property Rights means patents, rights to inventions, copyright and related rights, trademarks, trade names and domain names, rights in get-up, rights in goodwill or to sue for passing off, rights in designs, rights in computer software, database rights, rights in confidential information (including know-how and trade secrets) and any other intellectual property rights, in each case whether registered or unregistered and including all applications (or rights to apply) for, and renewals or extensions of, such rights and all similar or equivalent rights or forms of protection which may now or in the future subsist in any part of the world.

You hereby understand, agree and acknowledge that Positive Technologies and/or its licensors are the owner of all Intellectual Property Rights in the Website. You agree not to remove, alter or obscure any copyright, trademark, service mark or other proprietary rights notices incorporated in or accompanying the Website or any objects available at or via the Website.

Positive Technologies grants you a non-exclusive, non-transferable, limited permission to access, view and display the Website as a customer or potential customer of Positive Technologies for personal use or internal circulation within your organization provided you comply with these Terms, and all copyright, trademark, and other proprietary notices remain intact. The use authorized under these Terms is non-commercial in nature (e.g., you may not sell the content you access on or through this Web site).

Except for the limited permission in the preceding paragraph, we do not grant you any express or implied Intellectual Property Rights. You may not mirror any of the content from the Website on another website or in any other media. Any software and other materials that are made available for downloading, access, or other use from the Website with their own license terms will be governed by such terms, conditions, and notices. Your failure to comply with such terms or any of the terms on this Website will result in automatic termination of any rights granted to you, without prior notice, and you must immediately destroy all copies of downloaded materials in your possession, custody or control. Other than pursuant to our limited license or another agreement, you agree not to distribute, publish, duplicate, copy, create, sell, modify, reverse-engineer or create derivative works of our Intellectual Property Rights or information found on the Website. All rights not expressly granted are reserved and Users must seek prior permission before making any other use of material available through the Website.

Positive Technologies' logos, domain names, products and service names are registered and unregistered trademarks of Positive Technologies (Positive Technologies Marks). You are not permitted to use any of the Positive Technologies Marks, attempt to secure any rights that are confusingly similar to any Positive Technologies Marks or suggest an affiliation with Positive Technologies, without our prior consent in writing. When using the Website, you shall also not use the trademarks of any third party without our prior consent in writing.

You acknowledge that to the extent that you receive or obtain access to non-public or confidential information relating to Positive Technologies or any other third party as a result of accessing the Website, you cannot disclose this information without our prior consent in writing or the consent of the applicable third party.

User Content

By submitting any information (User Content) to Positive Technologies through the Website, you hereby grant Positive Technologies, and its affiliated companies, sublicensees, successors and assigns a non-exclusive, perpetual, royalty-free, irrevocable, worldwide license to use, reproduce, adapt, translate, modify, reproduce, publish, publicly perform, display, and distribute User Content.

You cannot post, modify, distribute, or reproduce in any way copyrighted or other proprietary materials without obtaining the prior written consent of the owner of such materials. Any information you provide to us must be truthful and accurate. We may, in our sole discretion, retain, reject or remove any User Content. We do not endorse or assume responsibility for user conduct or User Content.

All User Content is considered nonconfidential and public. Please do not submit any confidential or private information.

If you provide us with any feedback or ideas, you authorize us to use your feedback for any purpose, without any restriction or limitation. However, we will not release your name or otherwise publicize the fact that you submitted materials or other information to us unless: (a) we obtain your permission to use your name; or (b) we first notify you that the materials or other information you submit to a particular part of this site will be published or otherwise used with your name on it; or (c) we are required to do so by law.

Indemnification

You agree that you will indemnify and hold harmless Positive Technologies and its officers, employees, contractors, agents, partners, successors, and assigns and those of its affiliates, from any damages, liability, or claims (including attorney's fees), derived from or attributable to your violation any portion of these Terms.

You agree to indemnify, defend and hold harmless Positive Technologies and its officers, employees, contractors, agents, partners, successors, and assigns and those of its affiliates, from any damages, liability, or claims (including attorney's fees), made by any third party from information that you submitted or shared through the Website, your use of the Website, your Website connection, your Terms violations, or any other rights violation(s).

Disclaimer of Warranties

While Positive Technologies agrees to provide access to the Website with reasonable skill and care, the following disclaimers apply:

  • POSITIVE TECHNOLOGIES CANNOT GUARANTEE THAT YOUR ACCESS TO THE WEBSITE WILL BE UNINTERRUPTED, RELIABLE, ERROR-FREE, WILL MEET YOUR EXPECTATIONS, OR THAT ANY COMMUNICATIONS MADE VIA THE WEBSITE WILL BE SECURE. THEREFORE, POSITIVE TECHNOLOGIES CANNOT ACCEPT LIABILITY FOR ANY LOSS, DAMAGE OR INCONVENIENCE ARISING AS A CONSEQUENCE OF INABILITY TO USE OUR WEBSITE, USE ANY INFORMATION ON OUR WEBSITE, OR DATA BREACH, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW.
  • WE ARE NOT RESPONSIBLE FOR CLAIMS BROUGHT BY THIRD PARTIES ARISING FROM YOUR USE OF OUR WEBSITE OR BREACH OF THESE TERMS.
  • WE DO NOT ACCEPT LIABILITY IN THE EVENT THAT YOUR COMPUTER, SOFTWARE OR DATA IS DAMAGED. YOU ARE ADVISED TO BACK UP ANY OF YOUR DATA INDEPENDENTLY AND TAKE SECURITY PRECAUTIONS INCLUDING INSTALLATION OF ANTIVIRUS SOFTWARE.
  • WE DO NOT HAVE AN OBLIGATION TO VERIFY THE IDENTITY OF USERS OF THE WEBSITE AND THEREFORE SHALL HAVE NO LIABILITY IN THE EVENT OF DAMAGES OR MISUSE OF YOUR DATA DUE TO IDENTITY THEFT.
  • WE CANNOT CONTROL USER CONTENT UPLOADED OR TAKE RESPONSIBILITY FOR THE CONDUCT OF USERS OR ANY USER CONTENT THEY UPLOAD.
  • WE DO NOT ACCEPT RESPONSIBILITY FOR ANY OF YOUR ACTIONS AS A RESULT OF USING OUR WEBSITE. YOU ARE REPONSIBLE FOR TAKING CARE WHEN PROVIDING ACCESS TO PERSONAL DATA AND CONFIDENTIAL INFORMATION TO THIRD PARTIES.
  • TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE WARRANTIES AND REMEDIES PROVIDED IN THESE TERMS ARE EXCLUSIVE AND IN LIEU OF ALL OTHER WARRANTIES, TERMS AND CONDITIONS, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING, BUT NOT LIMITED TO, ANY IMPLIED WARRANTY OR TERMS AND CONDITIONS OF MERCHANTIBILITY, ACCURACY, FITNESS FOR A PARTICULAR PURPOSE OR SATISFACTORY QUALITY AND NONINFRINGEMENT, ALL OF WHICH ARE, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EXPRESSLY DISCLAIMED BY POSITIVE TECHNOLOGIES.
  • WE DO NOT GUARANTEE AND DO NOT PROMISE ANY SPECIFIC RESULTS FROM USE OF THE WEBSITE OR ANY RELATED SERVICES OR CONTENT.
  • ALL USE OF THE WEBSITE IS AT YOUR OWN RISK.

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, POSITIVE TECHNOLOGIES AND ITS AFFILIATES, DIRECTORS, CONSULTANTS, AGENTS, SUB-CONTRACTORS OR EMPLOYEES SHALL NOT BE LIABLE FOR ANY INCIDENTAL, SPECIAL, PUNITIVE, INDIRECT, OR CONSEQUENTIAL DAMAGES OF ANY KIND, OR FOR ANY LOST PROFITS, LOST REVENUES, AND LOSS OF BUSINESS OPPORTUNITY, COSTS OF REPLACEMENT GOODS, OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THE WEBSITE OR ANY RELATED SERVICES OR CONTENT, OR DAMAGES RESULTING FROM USE OF OR RELIANCE ON THE INFORMATION PRESENT,WHETHER OR NOT POSITIVE TECHNOLOGIES WAS AWARE OR SHOULD HAVE BEEN AWARE OF THE POSSIBILITY OF THESE DAMAGES AND WHETHER THE SAME ARISE IN CONTRACT, TORT (INCLUDING NEGLIGENCE) OR OTHERWISE.

POSITIVE TECHNOLOGIES ASSUMES NO RESPONSIBILITY FOR THE USE OF THE WEBSITE AND ANY PART OF IT OUTSIDE THESE TERMS OR OTHER APPLICABLE TERMS.

How to contact us / How we may contact you

You can contact us by email at privacy@ptsecurity.com. If we have to contact you, we will do so by email at the email address you provided to us through the Website or otherwise (if any). Notices by email shall be deemed to be received at the time of transmission unless the email is notified as undelivered.

Please note that any interaction between us via social media will not be recorded as part of our quality systems and that any questions or complaints about these terms or the Website should be submitted to us by email.

How to tell us about problems

If you have any questions or complaints about the Website or any information provided via the Website, please contact us by email specified in the previous section of the Terms.

If you believe that your copyright or other rights have been infringed, please provide a written notice with the following information:

  • An electronic or physical signature of the person authorized to act on behalf of the owner of the copyright or other interest;
  • A description of the copyrighted work or other work that you claim has been infringed;
  • A description of where the material that you claim is infringing is located on our Website;
  • Your address, telephone number, and email address;
  • A written statement by you that you have a good faith belief that the disputed use is not authorized by the copyright owner, its agent, or the law;
  • A statement by you, made under penalty of perjury, that the above information in your notice is accurate and that you are the copyright owner or authorized to act on the copyright owner's behalf.

Other important terms

If you violate these Terms and we take no immediate action, this in no way limits or waives our rights, such as our right to take action in the future or in similar situations.

Any provision of these Terms that expressly or by implication is intended to come into or continue in force on or after termination of these Terms shall remain in full force and effect.

We may assign our rights and obligations under these Terms to another organization. You may only assign your rights or your obligations under these Terms to another person if we agree to this in writing.

Each clause of these Terms operates separately. If any court or relevant authority decides that any of them are unlawful or unenforceable, the remaining clauses will remain in full force and effect.

Document version dated: October 1, 2024

Privacy Policy

This Privacy Policy ("Privacy Policy") provides data subjects with information on the processing of their personal data (any information relating to them) by Positive Technologies ("we" or "us" or "our"). We protect companies and government entities ("Customers") from non-tolerable events using the latest cybersecurity technology through our own legal entities and our authorized partners ("Partners"). We also believe in the importance of education, which is why we conduct training and offer educational courses and programs for individuals and representatives of legal entities ("Participants"). By Participants we also mean those who participate in various events and contests held by us.

This Privacy Policy contains important information about the collection and use of personal data, the legal grounds for the processing of personal data, the disclosure of personal data to third parties, and the use of cookies by Positive Technologies. The Privacy Policy also covers the processing of personal data on our website https://global.ptsecurity.com/ ("Website").

This Privacy Policy is based on the provisions of data protection laws applicable in the country of your residence.

1. Controller

This Privacy Policy applies when we act as a data controller with regard to your personal data.

Data subjects can contact us with any questions relating to the processing of their personal data under this Privacy Policy by email: privacy@ptsecurity.com.

2. Categories of processed personal data

We may process the following personal data depending on the circumstances of our interaction with you. The table below sets out the categories of personal data we process.

Category of dataDescription
Data required to provide our services to Customers, Partners, and ParticipantsFull name, phone number, email address, identifiers in messengers and social networks, job title, structural unit and current place of employment, personal identifiers; data on technical means (devices) such as IPs; information automatically received from our services, including cookies, and information received as a result of your actions, including information about comments, requests, feedback, and questions you send us
Marketing dataFull name, phone number, email, identifiers in messengers, job title, and structural unit and current place of employment
Feedback dataFull name, phone number, email, identifiers in messengers, and information about comments, requests, reviews, and questions you send us
Data automatically collected by our WebsiteCookies

3. Purposes and legal basis for processing

We only process your personal data when we have a legal basis as follows:

3.1. Performance of an agreement. We may process your personal data to provide you with our services under an agreement between you/your company.
3.2. Legitimate Interest. We may process your personal data when we (or a third party) have an interest in using your personal data in a certain way that is necessary and justified considering the potential risks.
3.3. Consent. When required by applicable laws, we will process your personal data based on your consent.
3.4. Legal obligations. When we must process your personal data to comply with the law.
3.5. Other. We can also process your personal data to exercise our legal rights or on other legal bases provided by applicable law.

The table below sets out:

  • Positive Technologies purposes for processing personal data
  • Positive Technologies legal basis for each purpose under the law
  • Categories of personal data that Positive Technologies uses for each purpose
Purpose of processingLegal basisCategories of personal data used
To provide our services to our Customers, Partners, and ParticipantsContract / Legitimate interestData required to provide our services to Customers, Partners, and Participants
To market, promote, and advertise our servicesConsent / Legitimate interestData required to provide our services to Customers, Partners, and Participants; marketing data
To process feedback from youContract / Legitimate interest / ConsentFeedback data
To improve our services, including to train ML modelsLegitimate interestAll data
To comply with legal obligations and law enforcement requestsLegal obligation / Legitimate interestAll data
To establish, exercise, or defend legal claimsLegitimate interest / OtherAll data
To detect and prevent fraudLegitimate interestAll data
To provide securityLegitimate interestAll data
To conduct research, contests, and surveysContract / Legitimate interest / ConsentData required to provide our services to Customers, Partners, and Participants; marketing data, feedback data

We do not process your personal data for other purposes that are not covered by this Privacy Policy.

4. Recipients and sources of personal data

4.1. We disclose certain personal data to the following recipients to the extent required or permitted by law and/or based on their legitimate and reasonable requests:

  • Payment service providers
  • ales and marketing service providers
  • Service providers otherwise assisting in the provision of our services and achievement of other purposes mentioned in Section 3 of the Privacy Policy
  • Affiliate entities of Positive Technologies that are part of the same group of companies
  • Governmental and regulatory bodies, including law enforcement authorities, in connection with enquiries, proceedings, or investigations by such parties or to enable Positive Technologies to comply with its legal and regulatory requirements

4.2. We obtain personal data in any information you provide to us directly or through information provided by third parties. Below is a list of ways in which we collect your personal data.

Personal data collected from you directly, including:

  • When you use our Website
  • When you contact us for any enquiries, complaints, or for any other reason.

Personal data collected from other sources, including:

  • Through third parties, including in a manner that is permitted

5. Transfers to third countries

We may transfer the personal data of data subjects to third countries that do not provide the same level of data protection as in the country of your residence. When doing so, we ensuret the implementation of security measures to protect your personal data in an appropriate manner.

You can obtain more information on the methods of transfer to third countries by Positive Technologies by sending us a request using the contact details specified in Section 1 of this Privacy Policy.

6. Storage periods

We store personal data for as long as it is required to achieve the purposes of the processing specified in Section 3 of this Privacy Policy unless there are specific periods defined by law.

If you wish to have personal data removed from our databases, please contact us by sending a request using the contact details specified in Section 1 of this Privacy Policy.

7. Basic rights of data subjects

Your rights and their descriptions are available in this table. Please note that the list of available rights may vary depending on the law as regards the relationship between you and Positive Technologies.

RightDescription
AccessYou can ask us to confirm whether or not we process your personal data. If we process your personal data, you can access the personal data and ask us to explain certain details of its processing.
RectificationYou can ask us to correct inaccurate personal data concerning you. If it complies with the purposes of processing, you can ask us to rectify incomplete or inaccurate personal data.
Erasure ("right to be forgotten")You can ask us to erase personal data concerning you under applicable law. For example, this applies if (1) the personal data is no longer necessary in relation to the purposes for which they were processed, (2) you withdraw consent to processing and there is no other legal ground for its processing, (3) the personal data has been unlawfully processed.
Restriction on processingYou can ask us to mark the stored personal data to limit its processing in the future under applicable law. This applies if (1) you contest the accuracy of the personal data, (2) you ask us to restrict the use of the personal data when its processing is unlawful, (3) you need personal data to protect your rights when our services no longer need the personal data, (4) you have objected to processing based on the legitimate interests pursued by us or a third party.
Objection to processingYou can object on grounds relating to your particular situation at any time to the processing of personal data concerning you based on the legitimate interests pursued by Positive Technologies or a third party. We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for its processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
PortabilityWhen the processing is based on your consent or in an agreement with you, you can receive the personal data that you have provided to us in a structured, commonly used and machine-readable format and can freely transmit the data to another controller. Where technically feasible, the data subject can also ask us to transmit the personal data directly to another controller.

To exercise these rights, you can contact us using the contact details specified in Section 1 of this Privacy Policy.

8. Withdrawal of consent

Where processing is based on consent (or explicit consent), you have the right to withdraw consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. We can continue to process your personal data if we have another legal basis to do so. To withdraw consent, you can contact us using the contact details specified in section 1 of this Privacy Policy.

9. Right to submit a complaint to a supervisory authority

You have the right to submit a complaint to a supervisory authority for data protection in the country of your residence.

10. Cookies

Type of cookiesDescription
Strictly necessaryThese cookies are necessary for the functioning of our websites and cannot be disabled. They are usually activated only in response to your actions similar to requesting services, such as setting a privacy level, logging in, or filling out forms. You can configure your browser to block these cookies or notify you about their use, but it is possible that some sections of our websites will no longer work or not work correctly.
TargetingThese cookies are configured through our websites by our advertising partners. They can be used by these companies to collect data about your interests and display relevant advertisements for you on other websites. If you do not approve of the use of these cookies, you will not be shown our targeted advertising on various websites.
OperationalThese cookies allow us to count the number of visits and traffic sources to evaluate and improve the performance of our websites. Thanks to these cookies, we know which pages are the most and least popular, and we see how visitors navigate through our websites.
FunctionalThese cookies allow us to provide improved functionality and personalization, for example, for online chats and videos. They can be configured by us or third-party providers whose services are contained on our pages. If you do not approve of the use of these cookies, it is possible that some or all of these functions will not work properly.

To opt out of the use of certain cookies, you have the right to use the features of our Website intended for this purpose. You also have the right to use your browser settings to disable the use of cookies. Detailed instructions on how to disable cookies are available at the following external links:

  • Google Chrome
  • Safari
  • Microsoft Edge
  • Mozilla Firefox

11. Children's privacy

We do not knowingly or intentionally collect personal data through our services from children under 18 (eighteen) years of age. If you are under 18 (eighteen) years of age or another age recognized in your jurisdiction as sufficient for the use of our services, do not attempt to register on or use our services, and do not provide us any personal data about yourself unless you have parental consent. If you are a parent or guardian and you are aware that your child has violated this Privacy Policy and provided us personal data, please contact us using the contact details specified in Section 1 of this Privacy Policy. If we become aware that a minor has provided us personal data or we otherwise process their personal data in violation of the Privacy Policy, we will take steps to remove that information.

12. Changes to this Privacy Policy

We may periodically amend this Privacy Policy at our sole discretion. If so, we may notify data subjects about these changes by an appropriate method. If there is no explicit notification, data subjects may read the up-to-date version of this Privacy Policy.

Data processing agreement

This Data Processing Agreement (the "DPA") is an integral part of the agreement or other document that contains a reference to the DPA.

1. TERMS AND DEFINITIONS

The following terms are used in the DPA:

  1. Agreement — an agreement or other document that contains a reference to the DPA.
  1. Service — a product and/or service listed on the following pages:
  • https://positivegisec.com

The Service may also refer to a product and/or service not listed on the above pages, if such product and/or service are named in the Agreement.

  1. User — a person who has entered into a service agreement, a license agreement for the use of the Services, or another agreement with the Positive or its authorized representative (such as a distributor or partner).
  1. Positive — one of the legal entities named in the Agreement:
  • Joint Stock Company Positive Technologies, 107061, Moscow, Preobrazhenskoye Municipal District, Preobrazhenskaya sq., 8, room 60, OGRN (Primary State Registration Number): 1127746201087;
  • Joint Stock Company Positivnye Technologii, 107061 Moscow, Preobrazhenskoye Municipal District, Preobrazhenskaya sq., 8, room 60, OGRN (Primary State Registration Number) 1127746201087;
  • Public Joint Stock Company Positive Group, 107061 Moscow, Preobrazhenskoye Municipal District, Preobrazhenskaya sq., 8, room 60, OGRN (Primary State Registration Number): 5177746006510.
  • Joint Stock Company TRIZTECH, 107061 Moscow, Preobrazhenskoye Municipal District, Preobrazhenskaya sq., 8, room 62, OGRN (Primary State Registration Number): 1257700453075.
  • Joint Stock Company NNS, 107061 Moscow, Preobrazhenskoye Municipal District, Preobrazhenskaya sq., 8, room 60, OGRN (Primary State Registration Number): 1257700533727.
  1. Parties — the Positive and the User.

The terms "data controller," "personal data," "data subject", "special categories of personal data" and "biometric personal data" are used within the meanings provided by Federal Law No. 152-FZ *On Personal Data* of July 27, 2006 or other applicable data protection legislation.

The term "sensitive data" refers to special categories of personal data and biometric personal data.

Any reference to a law or regulation is a reference to it, as amended or modified from time to time.

In the event of uncertainty about the meaning of a term in the DPA, the interpretation of the term should be determined first by applicable law, secondly by the website https://positivegisec.com/, and then by the established (generally used) interpretation on the internet.

2. GENERAL PROVISIONS

2.1. Subject matter of the Agreement: the DPA governs the processing of personal data when providing Services to the User under the Agreement. It comes into effect upon commencement of the provision of the Service to the User and supersedes any terms previously applicable to the processing of personal data when providing the Service to the User.

2.2. The DPA applies to any personal data processed during the Positive's interactions with the User and/or processed when providing Services to the User.

2.3. The DPA does not apply to the processing of personal data unless the relevant Agreement contains a reference to this DPA.

2.4. The terms for personal data processing for Users from the Republic of Belarus are contained in the Section 6 of the DPA.

3. PERSONAL DATA PROCESSING

### 3.1. Personal data processing by independent data controllers.

For the following purposes, the Parties are recognized as independent data controllers:

Purpose of personal data processingConclusion and execution of contracts with counterparties of the Positive
Legal basis for processingPerformance of a contract to which the data subject is a party; legitimate interest.
Categories of data subjectsData subjects whose personal data are processed in connection with the provision of the Service to the User, including: Counterparties of the Positive and (or) their authorized representatives.
Categories of personal dataLast name, first name, phone number, email address, messenger identifiers, job position, company name, information about interactions with the Positive. For counterparties, which are natural persons, additionally: passport details, registration and residential addresses, insurance number (such as SNILS), taxpayer identification number (INN), and bank account details.
Processing operationsCollection, recording, systematization, accumulation, storage, clarification (updating or changing), extraction, use, transfer (provision, or access), anonymization, blocking, deletion, and destruction.
Retention periodUntil the purposes of processing have been achieved, unless a different retention period is provided by the Agreement, applicable law, or other relevant document.
Purpose of personal data processingProvision of the Service to the User: PT Fusion
Legal basis for processingPerformance of a contract to which the data subject is a party, consent; legitimate interest
Categories of data subjectsData subjects whose personal data is processed as part of providing the Service to the User, including: the User's employees; representatives of the User's counterparties; other data subjects whose data may be accessed by the Positive in the course of providing the Service to the User.
Categories of personal dataFirst name, last name, email address, and other information contained in files uploaded by the User to the Service that constitutes personal data under applicable law (e.g., phone number, photo, messaging identifiers, job position, place of employment).
Processing operationsCollection, recording, systematization, receipt, accumulation, storage, clarification (updating or changing), electronic copying, extraction, use, anonymization, blocking, deletion, and destruction.
Retention periodDuring the User's use of the Service, unless otherwise specified in the Agreement.
Purpose of personal data processingAuthorization and registration of the User's representatives in the Services (in particular, through the use of the Positive portal) (https://myportal.ptsecurity.com/)
Legal basis for processingPerformance of a contract to which the data subject is a party; legitimate interest
Categories of data subjectsSubjects whose personal data is processed as part of providing access to the Positive portal (https://myportal.ptsecurity.com/) or to the functionality of a specific Service: employees and other representatives of the User.
Categories of personal dataLast name, first name, patronymic, job position, company name, email address, phone number, location of the personal data subject.
Processing operationsCollection, recording, systematization, receipt, accumulation, storage, clarification (updating or changing), electronic copying, extraction, use, anonymization, blocking, deletion, and destruction.
Retention periodDuring the User's use of the relevant Service, and after the expiration of such use, for three (3) years after termination of the relevant Agreement, unless otherwise provided by applicable law.

3.1.1. When transferring personal data from one Party to another, the responsibility for ensuring the legal basis for processing of the personal data, including obtaining consent in due form and notifying data subjects of the terms of processing of their personal data, is on the disclosing such personal data Party. Upon request by the receiving Party, the disclosing Party undertakes to provide confirmation of compliance with the aforementioned obligations.

3.1.2. When processing personal data, the Parties shall take the necessary legal, organizational, and technical measures in accordance with applicable law or ensure their implementation to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, disclosure, distribution, and other illegal actions.

3.1.3. Information regarding the processing of personal data by the Positive as an independent personal data controller is contained in the Policy available at: https://ptsecurity.com/legal/privacy-policy/.

### 3.2. Processing under the authority of the User as a data controller (the Positive is a processor)

3.2.1. Except as otherwise provided in Clause 3.1 of this DPA, the Positive shall process personal data on behalf of the User for the purpose of providing the Services under the Agreement, subject to the following terms:

Purpose of processing of personal data on behalf of the User and further processing by the PositiveProvision of the Service to the User (except as specified in Clause 3.1 of this DPA)
Categories of the data subjects whose personal data is processed on behalf of the UserData subjects whose personal data is processed in connection with the provision of the Services to the User (including the User's employees, contractors, and other data subjects)
Categories of personal data processed on behalf of the UserLast name, first name, patronymic, place of employment, email address, job position Information relating to the activities of Data Subjects (log data) Other personal data, the scope of which depends on the nature of the relationship between the User and the Positive and may be further specified in the Agreement
Processing operationsCollection, recording, systematization, accumulation, storage, clarification (updating or changing), extraction, use, transfer (provision, or access), anonymization, blocking, deletion, destruction, receipt, search, copying, comparison (comparison), unification (linking) of personal data.
Duration of processing of personal data by the Positive on behalf of the UserUntil the purposes of processing of personal data have been achieved.

3.2.2. The Positive shall delete personal data processed on behalf of the User under this DPA in the cases provided for in the Agreement and as required by applicable law.

#### 3.2.3. Engagement of Sub-processors

3.2.3.1. The Positive shall process personal data under this DPA either independently or can engage third parties to process personal data (hereinafter referred to as "Sub-processors") on the basis of agreements concluded with such Sub-processors, without prior notice to or approval from the User. The Positive shall remain fully liable to the User for the performance of its obligations under this DPA and for any acts or omissions of its Sub-processors. In particular, such Sub-processors include:

  • Limited Liability Company Yandex.Oblako, 119021, Moscow, Leo Tolstoy Street 16, Premises 528, OGRN (Primary State Registration Number): 1187746678580;
  • Limited Liability Company Svyaz VSD, 127083, Moscow, Marta Street 8, Building 1, OGRN (Primary State Registration Number): 1037713010444;
  • Joint Stock Company Data Storage Center, 127282, Moscow, Chermyansky Passage 5A, Building 1, OGRN (Primary State Registration Number): 1247700651461.

3.2.3.2. The Sub-processors shall be bound by data protection obligations no less protective than those set out in this DPA and shall comply with the applicable data protection laws and regulations, including obligations relating to the confidentiality and security of personal data.

3.2.4. The User shall:
a. Ensure the existence and validity of appropriate legal bases for the processing of personal data, as required under applicable law, sufficient to allow the Positive to process personal data in the scope and for the duration specified in this DPA. This includes, without limitation, obtaining all necessary consents and duly informing data subjects whose personal data are processed in connection with the provision of the Service to the User.

b. Ensure the accuracy of personal data processed, as well as their adequacy and relevance in relation to the purposes of processing, and keep such personal data up to date.

c. Respond to requests and inquiries from data subjects relating to the processing and protection of personal data, in accordance with applicable data protection laws.

d. Independently respond to requests and inquiries from competent supervisory authorities relating to the processing and protection of personal data under this DPA.

e. Establish and maintain appropriate technical and organizational measures to ensure the security of personal data, in accordance with applicable law, including Article 19 of Federal Law No. 152-FZ *"On Personal Data"* of July 27, 2006.

f. Refrain from taking any actions that may result in the Positive obtaining access to special categories of personal data or other categories of restricted information, including information constituting legally protected secrets (such as state secrets or banking secrecy), as defined under applicable law, including Federal Law No. 149-FZ "On Information, Information Technologies and Information Protection" of July 27, 2006.

g. Provide the Positive, within no later than ten (10) business days from receipt of the Positive's request, with information and/or documentation confirming the existence of valid legal grounds for instructing the Positive to process personal data in accordance with this DPA, including, where required under applicable law, duly obtained consents from data subjects authorizing the Positive to process their personal data. The scope and content of such information and/or documentation shall be determined by the Parties in accordance with applicable law and with due regard to the rights and legitimate interests of data subjects, the Parties, and other relevant persons.

3.2.5. The Positive shall:

a. Process personal data in accordance with the User's instructions.

b. Comply with the principles and rules for processing personal data stipulated by Federal Law No. 152-FZ *"On Personal Data"* of July 27, 2006.

c. Maintain the confidentiality of personal data and ensure its security.

d. Process personal data using databases located within the Russian Federation.

e. To the extent provided by law, ensure the application of the measures specified in Articles 18.1 and 19 of Federal Law No. 152-FZ *"On Personal Data"* of July 27, 2006. Depending on the method and context of personal data processing, the Positive applies the following measures:

  • appointing a person responsible for organizing the processing of personal data;
  • issuing documents defining the Positive's policy regarding the processing of personal data, the Positive's local regulations on personal data processing, defining for each purpose of personal data processing the categories and list of personal data to be processed, the categories of subjects whose personal data is processed, the methods and timeframes for processing and storage, the procedure for the destruction of personal data upon achieving the processing objectives or upon the occurrence of other legal grounds, as well as local regulations establishing procedures aimed at preventing and identifying violations of personal data legislation and eliminating the consequences of such violations;
  • implementing internal control and/or auditing of personal data processing compliance with applicable personal data legislation, personal data protection requirements, and local regulations of the Positive;
  • assessing the harm, in accordance with the requirements established by the authorized body for the protection of the rights of personal data subjects in the Russian Federation, that may be caused to subjects in the event of a violation of the requirements of applicable personal data legislation;
  • familiarizing persons engaged (admitted) by the Positive to process personal data with the requirements of applicable personal data legislation, including personal data protection requirements, and local regulations on personal data processing, and (or) training such persons;
  • identifying threats to the security of personal data that may arise during their processing in personal data information systems;
  • applying organizational and (or) technical measures to ensure the security of personal data during their processing, including in personal data information systems, necessary to ensure the ongoing confidentiality, integrity, availability, and sustainability of processes and/or systems related to the processing of personal data;
  • the use of information security tools that have undergone the established compliance assessment procedure, when the use of such tools is necessary to neutralize current threats to the security of personal data and information technologies used in personal data information systems;
  • prohibiting the merging of databases with personal data information systems or the recording of personal data on a single tangible medium if the processing of personal data is carried out for incompatible purposes;
  • detecting instances of unauthorized access to personal data information systems and taking appropriate measures, including measures to detect, prevent, and mitigate the consequences of computer attacks on personal data information systems related to the processing of personal data, and to respond to computer incidents in them;
  • restoring personal data modified or destroyed due to unauthorized access to them or another incident;
  • establishing rules for access to personal data processed in personal data information systems, as well as ensuring the registration and accounting of all actions performed with personal data in personal data information systems;
  • monitoring the measures taken to ensure the security of personal data and the level of protection of personal data information system;
  • establishing and approving the list of persons (positions) involved (admitted) by the Positive in the automated and/or non-automated processing of personal data, including in personal data information systems, and restricting access to personal data for other persons;
  • organizing a security regime for premises where personal data is processed and/or where software and hardware used for processing personal data are located;
  • creating a structural unit responsible for ensuring the security of personal data in the Positive's information systems, or assigning functions for ensuring such security to one of the existing structural units.

f. Upon the User's request, during the validity period of the DPA, including prior to processing personal data, provide documents and other information confirming the implementation of the measures stipulated by the DPA.

g. Without undue delay, notify the User of the cases specified in Part 3.1 of Article 21 of Federal Law No. 152-FZ *"On Personal Data"* of July 27, 2006 namely the establishment of an unlawful or accidental transfer (provision, distribution, or access) of personal data, resulting in a violation of the rights of personal data subjects and occurring through the fault of the Positive. The Positive will provide the User with the necessary and sufficient information and support related to such an event, which may be necessary for the User to fulfill their legal obligations, as well as to mitigate the negative consequences that may arise from such an event. Under no circumstances will the Positive's notifications and provision of such information and support to the User be construed by the Parties as an acknowledgement or confirmation of the Positive's liability for unauthorized access (to third parties), transfer (to third parties), or distribution (to third parties) of personal data processed by the Positive on behalf of the User under the DPA. To the extent permitted by applicable law, the Positive will not, without the User's prior permission, notify the relevant authorized bodies and/or entities of the relevant incident or make any public statements or otherwise notify any persons of such incident without first taking reasonable steps to consult with the User. If this is not possible, the Positive will not, without the User's prior permission, use the name of the User and/or its affiliates in such notification or in any public statements.

h. In the event of requests from a personal data subject for the information specified in Part 7 of Article 14 of Federal Law No. 152-FZ *"On Personal Data"* of July 27, 2006 or requests from a subject to clarify their personal data, block it, or destroy it if the personal data is incomplete, outdated, inaccurate, illegally obtained, or is not necessary for the stated purpose of processing, or other requests from personal data subjects, forward these requests to the User (unless otherwise provided by law).

i. No later than 5 (five) business days from the date of receipt of the User's request regarding the personal data specified in this request, processed by the Positive within the DPA, perform or ensure (if third parties are involved in the processing of the personal data by the Positive) the clarification (updating, modification), transfer (provision, access), blocking, deletion, or destruction. These actions in accordance with this section of the DPA are assumed to be performed, and the Positive is not obligated to notify the User of the results of these actions.

j. Allow its employees, contractors, and other third parties access to processed personal data only when strictly necessary for the processing of personal data under the DPA, and when appropriate steps have been taken to ensure compliance with security and confidentiality measures.

3.2.6. The Positive shall not abuse the right set out in Clause 3.2.5(g) of this DPA and shall exercise such right solely where obtaining the relevant information and/or documentation is necessary to ensure timely and proper compliance with applicable law or to prevent potential violations thereof.

4. LIABILITY

### 4.1. Liability of the Parties for personal data processing as independent data controllers (Clause 3.1 of the DPA)

4.1.1. Each Party shall be independently liable for its own acts and omissions in connection with the processing of Personal Data.

4.1.2. Except as provided in Clause 3.1.1 of the DPA and in cases involving a breach by a Party of its obligations under the DPA, none of the Parties shall not be liable for the acts or omissions of each other. In the event of any claims, demands, or legal actions brought by third parties, including data subjects and supervisory authorities, each Party shall handle and resolve such matters independently without involving the other Party.

### 4.2. Liability of the Parties when the Positive is a processor and the User is a controller (Clause 3.2 of the DPA)

4.2.1. The Positive shall be liable to the User within the limits established by the Agreement and the DPA for any culpable actions related to the processing of personal data under the DPA including for the actions (or inactions) of its employees who have access to personal data processed on behalf of the User, resulting in the disclosure of such personal data. Positive's liability is limited to compensating the User for actual damages only. However, the Positive's total liability under the DPA shall under no circumstances exceed 100,000 (one hundred thousand) rubles (RUB) including any claims, damages, expenses and other types of liability.

4.2.2. The Positive shall not be liable for ensuring the lawfulness of personal data processing, which may include obtaining consent from personal data subjects and informing them of the terms of personal data processing as well as for determining the scope of personal data.

4.2.3. The User as the controller shall be liable to personal data subjects and regulatory government agencies for the actions taken by the Positive in executing the assignment. In particular, the User is responsible for responding to requests from personal data subjects and from regulatory authorities.

4.2.4. In the event that the Positive is presented with any claims, demands, or lawsuits from third parties, including personal data subjects and regulatory authorities, in connection with the execution of the order, which arose due to the User's violation of obligations under the DPA, as well as in connection with the User's violation of the statutory procedure for processing personal data (including failure to obtain consent for such processing), the User shall:

  • independently and at its own expense resolve such claims and legal actions, while keeping the Positive informed of the progress of such resolution and providing prior notice of any intended actions;
  • if the Positive's participation in the settlement of such claims, demands, or lawsuits is necessary, or if the Positive is held liable for violating any laws and regulations regarding personal data, upon the Positive's request, compensate Positive for property losses in accordance with Article 406.1. Civil Code of the Russian Federation or any other applicable law, and, at Positive's request, to participate in the settlement of such claims, demands, and suits.

4.2.5. Scope of indemnified losses.

The User's indemnification obligations in Clause 4.2.4 of the DPA shall include, without limitation, indemnification for:

  • the amount of fines, penalties, compensation, and other payments to any third parties that the Positive will be obligated to make in the event of such circumstances (including the amount of damages that may be recovered from Positive or third parties engaged by it to fulfill its obligations under the Agreement) based on a court decision, arbitration tribunal, or international commercial arbitration (including a settlement agreement approved by the said bodies), or a decision of a competent government agency;
  • the amount of legal and consulting costs incurred by the Positive to protect its rights and interests in connection with the occurrence of the circumstances specified in Clause 4.2.4 of the DPA.

The User shall reimburse Positive for any indemnified losses within ten (10) business days following receipt of Positive's written notice of the claim and reasonable supporting documentation evidencing such losses.

5. MISCELLANEOUS

5.1. The DPA shall be governed by, applied, and interpreted in accordance with, the laws of the Russian Federation, without regard to its conflict of law's provisions.

5.2. The Parties undertake to resolve any disputes that may arise between them in the manner and within the timeframes established by the relevant Agreement.

5.3. The current version of the DPA is posted online at the following permanent address: https://ptsecurity.com/legal/data-protection-agreement/.

5.4. The Positive reserves the right to unilaterally amend the DPA by publishing a new version of the DPA at the address specified in clause 5.3 of the DPA. The User undertakes to monitor the current status of the DPA. The User is deemed to have received notice on the date the new version is posted. The Positive reserves the right to notify the User of material changes to the DPA. Such changes shall take effect upon their publication at the address specified in clause 5.3 of the DPA.

6. JURISDICTION-SPECIFIC TERMS

### 6.1. DPA Terms for Users from the Republic of Belarus

6.1.1. Personal data processing by independent data controllers:
The Parties shall be considered independent data controllers with respect to the purposes of personal data processing specified in the clause 3.1 of this DPA. When carrying out such processing, the Parties shall comply not only with the terms of this DPA but also with the applicable data protection laws and regulations of the Republic of Belarus regarding personal data.

#### 6.1.2. Processing under the authority of the User as a data controller (the Positive is a processor)

a. The terms of Sections 1–5 of this DPA shall apply to the relationship between the Positive and User from the Republic of Belarus, to the extent they do not conflict with the personal data legislation of the Republic of Belarus.

b. The purposes of personal data processing and the list of actions to be performed with personal data by the Positive are specified in Clause 3.2 of the DPA.

c. The Positive undertakes to maintain the confidentiality of personal data. The Positive shall not disseminate and (or) provide personal data that became known to it in connection with the execution of the DPA and (or) the Agreement, including after the termination of processing, without a legal basis provided for by applicable laws.

d. The Positive shall implement appropriate technical and organizational measures to ensure the security of personal data as required under Article 17 of the Law of the Republic of Belarus No. 99-Z dated 7 May 2021 "On Personal Data Protection". More information regarding such security measures is set forth in Clause 4.2 of this DPA.

e. For the purpose of enabling the User to verify the Positive's compliance with personal data protection requirements pursuant to Article 17 of the Law of the Republic of Belarus No. 99-Z dated 7 May 2021 "On Personal Data Protection," the Positive shall, upon the User's request, provide information necessary to demonstrate the implementation of such measures within the timeframes agreed in connection with the relevant request.

f. If the Positive receives a request from a data subject to provide information as provided for under Chapter 3 of the Law of the Republic of Belarus No. 99-Z dated 7 May 2021 "On Personal Data Protection," the Positive shall forward such request to the User within a reasonable period after receipt. The User shall be solely responsible for responding to data subject requests relating to the processing and protection of personal data.

g. In order to enhance the protection of personal data during processing, the Positive may apply anonymization or de-identification measures using organizational and/or technical means that prevent the identification of a data subject without the use of additional information.

h. The Positive shall cease processing of personal data under this DPA and shall delete or block such personal data in the cases provided for under the Agreement and applicable legislation of the Republic of Belarus.