1Office publishes this Personal Data Processing Agreement (the “DPA”) to govern the confidentiality and processing of personal data arising in the course of providing the Service. The DPA is an integral part of the Master Agreement under Article 1.5 of the Agreement and becomes automatically binding on the Customer as soon as the Customer signs the Agreement or starts using the Service, with no separate document required for each Customer.
In this DPA, “1Office” or “the data processor” means 1Office Joint Stock Company; “Customer” or “the data controller” means the Customer identified in the Agreement.
On the basis of compliance with the Personal Data Protection Law 2025, this DPA (hereinafter the “DPA” or the “Commitment”) sets out the confidentiality and personal data processing provisions on the specific terms and conditions below:
Article 1. Definitions and interpretation
1.1. Personal data
- Digital data or information in another form that identifies or helps identify a specific person, comprising basic personal data and sensitive personal data. Data that has been de-identified is no longer personal data.
- The personal data referred to in this agreement may be data of the Customer's own customers, of representatives or employees of either Party, and/or of any individual connected with the Agreement and this DPA whose data the parties may exchange or transfer to each other while signing, performing and implementing this Agreement.
1.2. Basic personal data
Basic personal data is data reflecting common identity and background details regularly used in transactions and social relations, within the list issued by the Government, comprising:
- Surname, middle name and given name at birth, and any other name (if any);
- Date of birth; date of death or disappearance;
- Sex;
- Place of birth, place of birth registration, permanent residence, temporary residence, current residence, place of origin and contact address;
- Nationality;
- Images of the individual;
- Phone number, personal identification number, passport number, driving licence number and vehicle registration number;
- Marital status;
- Family relationship information (parents, children, spouse);
- Information about the individual's digital accounts;
- Other information attached to or helping to identify a specific person, as understood under Decree 356 and other applicable laws.
1.3. Sensitive personal data
Personal data tied to an individual's privacy which, if infringed, directly affects the individual's lawful rights and interests, within the list issued by the Government, comprising:
- Data revealing racial or ethnic origin;
- Political, religious or belief views;
- Information about private life, personal secrets and family secrets;
- Health status;
- Biometric data and genetic characteristics;
- Data revealing an individual's sex life or sexual orientation;
- Data on crimes and criminal conduct collected and stored by law enforcement agencies;
- The individual's location as determined through location services;
- Username and password for an individual's electronic identification account, and images of identity cards, citizen identity cards and ID cards;
- Bank account usernames and passwords; bank card information and bank account transaction history; financial and credit information and information on customers' financial, securities and insurance activity and transaction history at credit institutions, foreign bank branches, payment intermediary service providers, securities and insurance organisations and other licensed organisations;
- Data tracking behaviour and use of telecommunications services, social networks, online communication services and other services in cyberspace;
- Other personal data that the law requires to be kept secret or to be subject to strict security measures.
1.4. Processing of personal data / processing
Any operation affecting personal data, comprising one or more of the following: collecting, analysing, aggregating, encrypting, decrypting, editing, deleting, destroying, de-identifying, providing, publishing and transferring personal data, and other operations affecting personal data.
1.5. Data subject
The person to whom the personal data relates.
1.6. Data controller
The agency, organisation or individual that determines the purposes and means of processing personal data.
1.7. Personal data processor
The agency, organisation or individual that processes personal data at the request of the personal data controller under the Agreement/DPA or an arrangement with the data controller.
1.8. Third party
An organisation or individual other than the data subject, the personal data controller or the personal data processor that takes part in processing personal data as provided by law.
1.9. Data breach incident
An event that exposes, loses, gives unauthorised access to, unlawfully alters or destroys personal data; or other conduct breaching personal data protection rules.
1.10. Technical data (system logs)
Data arising from use of the service for the purposes of operation, information security, measurement and service improvement.