Privacy Policy of the "Beeline Cloud" Service

1. Personal Data Subject

The user of the "Beeline Cloud" service.

2. Personal Data Processing Operator (Company)

PJSC "VimpelCom"; location: Russian Federation, 127083, Moscow, 8 Marta St., 10, Building 14.

This privacy policy is developed in accordance with the "Personal Data Processing" policy of PJSC "VimpelCom" and other local regulatory acts. The contents of these documents can be found at beeline.ru

3. Purpose of Personal Data Processing

To enable the User to use the "Beeline Cloud" application, to improve the "Beeline Cloud" service and monitor the quality of services provided, and to provide the User (including via direct communication through communication means) with information about VimpelCom's products and services and those of its partners (including advertising offers from VimpelCom and its partners).

4. List of Personal Data

Phone number, location information (for the automatic upload of photos and videos in the background on iOS), Google account identifier (email or login). Users can opt out of location data collection in the app and restrict "Beeline Cloud" service access to location data in the settings on the mobile device where the service's mobile app is installed. In case of data uploads by the user, the Company only receives file names and their characteristics. The Company does not have access to file contents. The User is fully responsible for all uploaded, sent, or published files and ensures that these files do not violate the rights of third parties or current legislation. If a backup of the contact list is created from the device, the Company does not receive details of numbers and names stored in the phone book or call history.

5. List of Actions with Personal Data

The Company processes personal data, including collection, use, storage, update, systematization, blocking, deletion, and destruction.

The Company performs automated, non-automated, and mixed personal data processing. General descriptions of personal data processing methods: non-automated – processing of personal data involving human participation; automated – processing of personal data through computing devices.

6. Data Retrieval from Google Drive when Using Data Import Functionality

The service requests the Google account identifier (email or login) solely to inform and display to the "Beeline Cloud" user which account they intend to use for data import.

The "Beeline Cloud" service receives Read-only access to files and folders in the user's Google Drive account through the Google API. The list of data includes only object names and their characteristics. The Company does not have access to the contents of the files. The service uploads files and folders from Google Drive only at the user's request. The uploaded data is placed in the Service's cloud storage and is accessible only to the user; it is not available to other users or third parties. The use of information obtained from the Google API is regulated by Google's API Services User Data Policy, including information usage restriction requirements.

The User is fully responsible for all uploaded, sent, or published files, ensuring that these files do not violate the rights of third parties or applicable law.

7. Data protection mechanisms for sensitive data

To protect the confidentiality of your data stored in the "Beeline Cloud" service, the following security methods are applied:

- your data is transmitted over open communication channels only in encrypted form (during import, upload, or download);

- the service provides access to your data only for your user account;

- the service does not share your data with third parties;

- access audit is applied – any attempt to access your data in the service is logged.

8. Processing Duration

1 year, but no less than the period of use of the "Beeline Cloud" service.

9. Withdrawal of Consent

The withdrawal of consent for personal data processing is submitted by the personal data subject via email to the Company at cloud@beeline.ru.