Privacy Policy of JSC “Ukrainian railways”

  1. General provisions
    1. Joint Stock Company “Ukrainian railways” (hereinafter referred to as JSC “Ukrainian railways”), legal address: 03150, Kyiv, 5 Jerzy Giedroyc St., processes personal data of individuals – subjects of personal data and is the owner of this personal data.
    2. The Privacy Policy of JSC “Ukrainian railways” (hereinafter referred to as the Policy) is an internal regulatory document developed to inform subjects of personal data on the purpose and grounds for collection, composition of collected personal data, processing procedure, transfer of personal data and their rights pursuant to the requirements of the Law of Ukraine “On Personal Data Protection” (hereinafter referred to as the Law) when carrying out activities defined by the Charter of JSC “Ukrainian railways”.
    3. This Policy is mandatory to be used by JSC “Ukrainian railways” when processing personal data.
    4. Regional branches, branches of JSC “Ukrainian railways”, representative offices of JSC “Ukrainian railways” abroad may develop their own notifications on the processing of personal data taking into account the requirements of the Law, internal regulatory documents of JSC “Ukrainian railways”.
    5. This Policy shall be published on all official web resources of JSC “Ukrainian railways” and placed at each railway ticket office.
    6. This Policy shall be approved in accordance with the procedure established by JSC “Ukrainian railways” and come into force on the date of the decision of the Management Board of JSC “Ukrainian railways” on its approval, unless otherwise specified in this decision.
  2. Basic terminology
    1. In this Policy, the following terms are used in the following meaning:

      subjects of personal data means individuals whose personal data are processed – existing and potential consumers, service customers, users of electronic service channels, including for the processing of electronic travel / transport documents and additional railway services of JSC “Ukrainian railways”, persons who contacted the information line or sent an e-mail, persons who contacted JSC “Ukrainian railways” in the manner prescribed by the laws of Ukraine “On Citizens’ Appeals”, “On Access to Public Information”, “On Personal Data Protection”, “On the Bar and Advocacy”;

      electronic customer service channels means websites and mobile application of JSC “Ukrainian railways”, which are used in the provision of services to individuals while implementing activities specified in the Charter of JSC “Ukrainian railways”;

      website means a software placed on the Internet and used to provide services and to inform users in particular, but not limited to, on issuing and returning electronic travel / transport documents and additional services, obtaining information and reference services, other operations related to passenger service, ordering such services online;

      mobile application of JSC “Ukrainian railways” (hereinafter – the mobile application) means a software allowing users to make reservations, purchase and return electronic travel / transport documents, order additional services, and obtain reference information via official distribution channels (repositories), ensuring the functioning on mobile devices with Android and iOS operating systems;

      user means an individual who accesses the websites and mobile applications of JSC “Ukrainian railways” and uses them for their intended purpose.

    2. Other terms used in this Policy shall be construed in accordance with the Law and the Standard Procedure for Processing Personal Data, approved by the Order of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine “On Approval of Documents in the Field of Personal Data Protection” dated 08.01.2014 No. 1/02-14.
  3. Purpose and grounds for processing personal data
    1. JSC “Ukrainian railways” collects personal data for the purpose of carrying out the activities specified in the Charter of JSC “Ukrainian railways”.
      1. Provision of services for the issuance / return of electronic travel / transport documents in passenger traffic by rail in domestic and international traffic and provision of other services through electronic customer service channels, in particular:

        creation by subjects of personal data of accounts on the websites and in the mobile application for issuing electronic travel / transport documents;

        providing users with access to the websites and mobile application for issuing electronic travel / transport documents;

        ordering and processing services, managing orders for the provision of services via the websites and mobile application;

        using feedback functions on the website and mobile application;

        ensuring the exchange of information from the websites, mobile application via e-mail;

        ensuring user participation in surveys and promotions within the loyalty program of JSC “Ukrainian railways”;

        conducting research and analysis to improve the quality of passenger services;

        improving the websites and mobile application;

        providing information on services (newsletters, information about promotions, loyalty program);

        sending a travel / transportation document to the e-mail address specified at registration by the subject of personal data.

      2. Provision of services for the transportation of cargo, luggage, freight luggage and mail by rail in domestic and international traffic.
      3. Performance of contractual terms and obligations to connect to the electricity distribution system networks.
      4. Fulfillment of conditions and obligations under agreements concluded by JSC “Ukrainian railways” with individuals with regard to the provision of services provided for by the Charter.
      5. Implementation of legitimate interests of JSC “Ukrainian railways”.
      6. Fulfillment by JSC “Ukrainian railways” of the requirements and obligations specified by the legislation.
      7. Implementation of the rights of individuals to receive information pursuant to the procedure established by the Laws of Ukraine “On Citizens’ Appeals”, “On Personal Data Protection”, “On Access to Public Information”, “On the Bar and Advocacy”.
    2. The legal grounds for processing personal data of JSC “Ukrainian railways” are:

      informed consent of the subject of personal data to process personal data;

      performance by JSC “Ukrainian railways” of obligations defined by the Laws of Ukraine “On Citizens’ Appeals”, “On Access to Public Information”, “On the Bar and Advocacy”;

      conclusion and execution of transactions to which an individual is a party, or which are concluded for the benefit of an individual;

      implementation of the legitimate interests of JSC “Ukrainian railways” or a third party, except in cases where the needs to protect the fundamental rights and freedoms of subject of the personal data in connection with the processing of his data prevail over such interests.

  4. Composition of personal data collected and processed by JSC “Ukrainian railways”
    1. JSC “Ukrainian railways” collects and processes the following personal data:
      1. When issuing electronic travel / transport documents in passenger traffic and providing services through electronic customer service channels: last name, first name, mobile phone number, e-mail address, data from the document certifying the right to a privilege, which are used when issuing preferential travel documents.
      2. When issuing travel / transport documents in passenger traffic at the railway ticket office: last name, first name, data from the document certifying the right to a privilege, which are used when issuing preferential travel / transport documents.
      3. When ordering a car carrier: last name, first name, mobile phone number, e-mail address, vehicle type.
      4. When ordering group travel documents: full name, mobile phone number, e-mail address.
      5. When placing an order for a station assistant: full name, mobile phone number, e-mail address, data from a document certifying the right to a privilege.
      6. When placing a special order for travel documents for military personnel: full name, mobile phone number, e-mail address.
      7. When ordering a special rail car: full name, mobile phone number, e-mail address, data from a document certifying the right to a privilege, a scanned copy or photo of a document certifying the right to a privilege.
      8. When ordering a lounge: name, mobile phone number, e-mail address.
      9. When ordering a service for finding lost items: name, mobile phone number, e-mail address.
      10. When filing a claim form for the return of travel documents: full name, mobile phone number, e-mail address, date of birth, place of residence, taxpayer registration identification card number (RNOKPP), IBAN account number, photo or scanned copy of a document confirming the circumstances of the claim return.
      11. When providing feedback via electronic customer service channels: information contained in any messages that the subject of personal data sends to JSC “Ukrainian railways”, including the content of the message and metadata.
      12. When drawing up contracts for the provision of services related to the standard connection of electrical networks of distribution systems, non-standard connection of electrical networks of distribution systems with the design of the linear part of the connection to be done by the consumer: full name, series, number, date of issue of the passport, place of registration, taxpayer registration identification card number (RNOKPP), data on the right of ownership or use of the real estate object, mobile phone number, e-mail address.
      13. Data of telephone calls of the subject of personal data to service numbers of JSC “Ukrainian railways”: the start and end time of the call, conversation recording, phone number.
      14. Data from chatbot chats: date and time of the request, name of the subject of personal data in the chat, phone number, content of the session.
      15. Data from SMS requests from subjects of personal data: time of request, phone number, content of response to request.
      16. Data when creating accounts for electronic customer service channels: last name, first name, photographic data, mobile phone number, e-mail address, date and time of entry to electronic customer service channels, information on the device used by the subject of personal data, in particular, but not limited to (IP address, type and version of browser and operating system).
      17. Data of persons applying pursuant to the procedure specified by the Laws of Ukraine “On Citizens’ Appeals”, “On Personal Data Protection”, “On Access to Public Information”, “On the Bar and Advocacy”: full name (if available); place of residence; availability of benefits that are the basis for priority consideration of the application; information on communication means; other data related to the person and provided by this person for consideration of the application, request.
  5. Use of cookies
    1. JSC “Ukrainian railways” uses cookies to optimize the operation of websites of JSC “Ukrainian railways” and to improve service provision quality.
    2. Cookies store information on a computer at the moment when the subject of personal data starts using them.
    3. By selecting the “Accept and close” option, the subject of personal data consents to the processing of personal data that may be obtained from cookies.
    4. By selecting the “Reject and close” option, the subject of personal data does not consent to the processing of personal data that may be obtained from cookies.
  6. Procedure for processing personal data
    1. Personal data processing at JSC “Ukrainian railways” shall be carried out in accordance with the legislation on personal data protection.
    2. Way of personal data collection.
      1. Collection of users’ personal data through the electronic customer service channels of JSC “Ukrainian railways” shall be made automatically when creating accounts, authorizing them (electronic authentication) in the electronic customer service channels, sending e-mails, and any other information containing personal data.
      2. Collection of personal data of persons applying to JSC “Ukrainian railways” pursuant to the procedure specified by the Laws of Ukraine “On Citizens’ Appeals”, “On Personal Data Protection”, “On Access to Public Information”, “On the Bar and Advocacy” shall be carried out by such persons providing their personal data, information in applications and requests for information, lawyer requests.
    3. The provided personal data shall be accumulated and stored in the data centers of the Branch “Main Informational and Computing Centre” of JSC “Ukrainian railways” on the territory of Ukraine.
    4. Making changes to personal data, removal or destruction of it.
      1. Changes to personal data shall be made on the basis of:

        a motivated written request of the subject of personal data;

        an order of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine or officials designated by him of the Secretariat of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine;

        an appeal from other parties to a relationship related to personal data, if there is the consent of the subject of personal data;

        a court decision that came into effect.

      2. Personal data shall be subject to deletion or destruction in the following cases:

        expiration of the specified period of storage of personal data;

        termination of legal relations between the subject of personal data and JSC “Ukrainian railways”, unless otherwise provided by law;

        issuance of a relevant order of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine or officials designated by him of the Secretariat of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine;

        a court decision on the deletion or destruction of personal data that has entered into force.

      3. Personal data shall be deleted or destroyed in a manner prescribed by law.
  7. Personal data protection measures
    1. JSC “Ukrainian railways” shall take measures aimed at the protection of personal data at all stages of its processing through organizational and technical measures.
    2. JSC “Ukrainian railways” shall take technical measures to protect personal data in order to ensure integrity, availability and confidentiality.
    3. Processing of personal data in information (automated) systems of JSC “Ukrainian railways” shall be carried out taking into account the requirements of legislation in the field of information protection in information and communication systems.
    4. JSC “Ukrainian railways” shall manage the employees’ level of access to personal data. Each employee has access only to those personal data (parts thereof) of subjects of personal data that are necessary for him / her in connection with the performance of his official and labor duties.
    5. To control access to information systems through which personal data is processed in JSC “Ukrainian railways”, authentication and authorization, including the use of complex passwords, shall be applied.
    6. Employees of JSC “Ukrainian railways” who have access to personal data shall sign an obligation not to disclose personal data that has been entrusted to them or that has become known to them in connection with the performance of their official or labor duties.
    7. JSC “Ukrainian railways” shall provide regular training for employees who work with personal data at least once a year.
    8. Facts of violations of the process of personal data processing and protection shall be documented and reported to Chairman of the Management Board for necessary measures to be taken.
    9. JSC “Ukrainian railways” shall not be responsible for the accuracy and content of the personal data specified by the user when registering an account and ordering services through the electronic customer service channels.
    10. JSC “Ukrainian railways” shall not be responsible for accidental or unlawful destruction, loss, change, unauthorized disclosure of personal data or access to personal data that occurred as a result of the user’s active actions or omissions.
  8. Terms of personal data processing
    1. Personal data shall be processed in a form that allows identification of an individual to whom it relates for no longer than is necessary in accordance with the purpose of its processing, unless otherwise provided by law.
    2. Personal data may be stored after the purpose of processing specified in this Policy has been achieved in cases:

      when required by the legislation of Ukraine;

      to exercise or protect the legal rights and interests of JSC “Ukrainian railways”.

    3. JSC “Ukrainian railways” shall store personal data:

      in the case of purchasing preferential travel / transport documents in passenger traffic at the railway ticket office – for a period of five years, subject to the completion of the audit by tax authorities and the state audit service;

      in the event of a claim or lawsuit against JSC “Ukrainian railways” – for the period necessary to consider the claim or lawsuit in court and for three years after the decision is made;

      of persons who applied in accordance with the procedure established by the Laws of Ukraine “On Citizens’ Appeals”, “On Personal Data Protection”, “On Access to Public Information”, and “On the Bar and Advocacy” – for a period of 5 years from the date of the last appeal;

    4. For statistical purposes, personal data may be stored in the archive in an anonymized form.
  9. Rights of subjects of personal data
    1. According to Article 8 of the Law, the subject of personal data has the right to:

      know about the sources of collection, the location of his / her personal data, the purpose of its processing, the location of the personal data controller or to give an appropriate instruction to obtain this information to persons authorized by him / her, except for cases established by law;

      receive information about the conditions for providing access to personal data, in particular information about third parties to whom personal data is transferred;

      access his / her personal data;

      receive a response no later than thirty (30) calendar days from the date of receipt of the request, except for cases provided for by law, on whether personal data is being processed, as well as to receive the content of such personal data;

      submit a reasoned request to the personal data controller with an objection to the processing of his / her personal data;

      submit a reasoned request to JSC “Ukrainian railways” to change or delete his / her personal data if this data is being processed illegally or is inaccurate;

      protect his / her personal data from unlawful processing and accidental loss, destruction, damage due to intentional concealment, failure to provide or untimely provision of such data, as well as to be protected from the provision of information that is unreliable or defames the honor, dignity and business reputation of an individual;

      file complaints about his / her personal data processing to the Commissioner for Human Rights of the Verkhovna Rada of Ukraine or to the court;

      apply remedies in case of violation of the legislation on personal data protection;

      apply remedies in case of violation of the legislation on personal data protection;

      make reservations regarding the restriction of the right to process his / her personal data when giving consent;

      withdraw consent to the processing of personal data;

      know the mechanism of automated processing of personal data;

      be protected against automated decision that has legal consequences for the subject of personal data.

    2. To exercise his / her rights, the subject of personal data may contact JSC “Ukrainian railways”:

      the “hotline” of JSC “Ukrainian railways”, “Quality and Service” Contact Center: 0-800-503-111;

      e-mail: [email protected], [email protected];

      via the mobile application;

      in chatbots;

      by letter to the address: 03150, Kyiv, 5 Jerzy Giedroyc Street.

  10. Bodies that protect the rights of subjects of personal data
    1. In Ukraine, control over compliance with the legislation on personal data protection within the limits of the powers provided for by law shall be carried out by:

      the Commissioner for Human Rights of the Verkhovna Rada of Ukraine;

      courts.

      Address and contact details of the Commissioner for Human Rights of the Verkhovna Rada of Ukraine: 01008, Kyiv, 21/8 Instytutska Street. Hotline: 0800-50-17-20 (free of charge). E-mail: [email protected]. >

  11. Information on the transfer of personal data to third parties
    1. JSC “Ukrainian railways” shall not transfer personal data of subjects of personal data to third parties without the consent of the subject of personal data, except for cases specified by the legislation of Ukraine or international treaties, the consent to binding nature of which has been provided by the Verkhovna Rada of Ukraine.
  12. Responsibility and control
    1. The responsibility for informing subjects of personal data about the provisions of this Policy shall rest with the heads of departments whose activities are related to the processing of personal data of the categories of subjects of personal data defined by this Policy.
    2. Control over compliance with the requirements of this Policy shall be entrusted to the Corporate Security Department of JSC “Ukrainian railways”.
  13. Final provisions
    1. The Policy shall be reviewed and updated as necessary, in the event of changes in business processes, improvement (modernization) of the information infrastructure of JSC “Ukrainian railways”, introduction of new information technologies.
    2. In the event of the adoption of new regulatory legal acts of Ukraine in the field of personal data protection, the Policy shall be immediately revised, and until then it shall be valid only in that part that does not contradict the legislation of Ukraine. Amendments and additions to the Policy shall be made in accordance with the procedure established by JSC “Ukrainian railways”.