Date of effect: September 1, 2023
Last updated: August 28, 2023
We've developed this Privacy Notice ("Privacy Notice") to explain to you how we collect, use, disclose, and store personal data.
This Privacy Notice applies to Toloka AI AG and its relevant affiliates listed in section 16 ("Toloka", "we", "us", "our")("Toloka affiliates").
When Does This Privacy Notice Apply?
This Privacy Notice applies to personal data that Toloka handles as a Controller. This includes when you:
PLEASE BE AWARE THAT IF YOU ARE RUSSIAN RESIDENT THE PRIVACY NOTICE, THAT IS APPLICABLE TO YOU, IS PUBLISHED AT: https://toloka.ai/legal/confidential/. PLEASE, READ IT CAREFULLY BEFORE YOU CONTINUE RENDERING THE SERVICES WITH THE USE OF THE TOLOKA WEB SITE.
After you carefully review this Privacy Notice, please make sure to check the country-specific provisions in the end of the Privacy Notice, which may be applicable to the processing of Your data in the country of Your residence. Such country-specific provisions supplement this Privacy Notice or, if the law requires, may prevail over contradicting parts of the Privacy Notice.
This Privacy Notice refers to provisions of the General Data Protection Regulation (GDPR), Swiss Law on Personal Data (Federal Act of 19 June 1992 on Data Protection (FADP)) the US privacy legislation (including but not limited to California Consumer Privacy Act (CCPA), California Privacy Rights Act of 2020, California Online Privacy Protection Act (COPPA), Health Insurance Portability and Accountability Act (HIPAA), Virginia Consumer Data Protection Act, Colorado Privacy Act, Nevada SB 220) and other laws as in force on the date of the last update of this Privacy Notice.
Toloka is a controller of personal data processed under this Privacy Notice. It means that Toloka determines the purposes and means of the processing of these personal data.
You can contact Toloka on any questions relating to the processing of Your personal data by either of the following methods:
Postal address: Werftestrasse 4, 6005 Luzern, Switzerland
The tables below set out the categories of personal data Toloka collects and processes. Toloka collects personal data primarily from the data subjects themselves (e.g., Your contact requests through the Toloka Platform). In addition, personal data may also be obtained from third parties as listed in the table below. Please use horizontal scroll to navigate across the table.
|Sending newsletters for marketing purposes via Email||Marketing e-newsletter Subscribers:|
|Analysis of website users' behavior||Our website users:|
IP address; Browser type and language used; The Internet service provider information; sending and exiting web pages that were sent and exited; Operating system information; date and time checks; website visits information
|Limited by the validity period of cookies (specified in the Cookie List)||Consent||Controller||Yandex.Metrica;|
|Tolokers (Users) onboarding and data integration; Further improvement of user experience||Our Tolokers (Users):|
External User ID
|3 months||Legitimate interest to improve Toloka services||Controller||AppsFlyer;|
|Tracking fraudulent activities||Our Tolokers (Users):|
User's device ID;
Location (IP address, phone number);
Mouse cursor movement and scrolls tracking;
Photo or video of the User holding the ID data page next to their face
|Tolokers (Users) Registration||Our Tolokers (Users):|
Date of birth;
|Within the term of the contract||Contract (with Tolokers (Users))||Controller||Toloka affiliates||Joint controller||N/A|
|Customer Registration||Our Customers:|
Company information (company name, industry, country, city, postal address, postal code; TIN)
|Within the term of the contract||Contract (with Customers)||Controller||Toloka affiliates||Joint controller||N/A|
|Remuneration to Tolokers (Users) by Toloka||Our Tolokers (Users):|
|Within the term of the contract||Contract (with Tolokers (Users))||Controller||Toloka affiliates||Processor||N/A|
|Withdrawal from the wallet by Tolokers (Users)||Our Tolokers (Users):|
Information of performed tasks;
|Within the term of the contract||Contract (with Tolokers (Users))||Controller||Toloka affiliates;|
|Authorization on Toloka||Our Tolokers (Users) and our customers:|
|Provision of technical support||Our Tolokers (Users) and our customers:|
User's device ID;
|Within the term of the contract||Contract (with Tolokers (Users) and Customers)||Controller||Toloka affiliates; ZenDesk||Processor||ZenDesk Privacy Notice|
|Notification of Tolokers (Users) of their actions on the Toloka||Our Tolokers (Users):|
|Within the term of the contract||Contract (with Tolokers (Users))||Controller||Toloka affiliates||Processor||N/A|
|Notification of Tolokers (Users) of their actions on the Toloka via SMS||Our Tolokers (Users):|
|Tolokers (Users) verification for large withdrawals||Our Tolokers (Users):|
Taxpayer Identification Number photo;
Photo of the User showing the number generated by Toloka next to their face;
Photo of the User holding the ID data page next to their face
|Within the term of the contract||Contract (with Tolokers (Users))||Controller||Tax authorities; Toloka affiliates||Tax authorities – controllers; Toloka affiliates – processors||N/A|
|Verification of the conscientious completion of tasks by Tolokers (Users)||Our Tolokers (Users):|
Assessment of the task completion
|Within the term of the contract||Legitimate interest to improve the quality of provided services to customers||Controller||Toloka affiliates||Processor||N/A|
|Assessing skills based on test results, and determining location for language proficiency tests||Our Tolokers (Users):|
Actions in the system (logs);
Location (IP address, phone number)
|Within the term of the contract||Contract (with Tolokers (Users))||Controller||Toloka affiliates||Processor||N/A|
|Registration for Toloka Crash Course||Our Crash Course Students:|
Business email address;
Knowledge and experience level
|Within the term of the contract (1 year from the date of course completion)||Contract (with Crash Course Students)||Controller||Toloka affiliates||Processor||N/A|
|Storage of Tolokers' (Users') Data in order to comply with anti-money laundering laws||Our Tolokers (Users):|
Information about completed tasks;
|3 years from the date of account deletion||Legal obligation||Controller||Supervisory authorities; Toloka affiliates||Supervisory authorities – controllers; Toloka affiliates – processors||N/A|
|Registration for webinars, events, programs, and marketing or promotional activities of Toloka||Webinar participants:|
|1 year after the date of registration or in case of consent withdrawal||Consent||Controller||Toloka affiliates||Processor||N/A|
|Recording the meeting(s) on video or audio to enhance follow-up and coaching||Our Customers:|
Speaker's data that was disclosed during the course of the meeting
|Fixing bugs and implementing software improvements||Our Tolokers (Users) and our Customers:|
External user ID
|Dispatching transaction documents to Customers||Our Customers:|
Company information (name, post address, post code, state (if applicable))
|Conducting surveys||Our Tolokers (Users) who have decided to participate in Toloka's survey(s): |
|After 2 years from the date of participation in the survey or in case of consent withdrawal||Consent||Controller||Toloka affiliates||Processor||N/A|
|Informing Customers about changes in the list of sub-processors*|
*Available only for Customers of Toloka AI AG
|Customer relations management||Our Customers:|
|Customer relations management for Prospect Clients||Our Prospect Clients:|
|Invitation Tolokers (Users) to pass qualification tests and further follow-up with results of tests and selecting process||Our Tolokers (Users):|
Full name, telephone number and email address
|Concluding a contract with Tolokers that've passed the test||Our Tolokers (Users):|
Full name, telephone number and email address
|Within the term of the contract or until the moment when it becomes clear that the contract will not be concluded||In order to take steps at the request of the data subject prior to entering into the contract (with Customers)||Controller||Toloka affiliates||Processor||N/A|
Legitimate Interest. When Toloka (or a third party) has an interest in using Your personal data in a certain way, which is necessary and justified considering any possible risks to You. We conduct a Legitimate Interest Assessment (LIA) to protect your personal data. LIA is a type of light-touch risk assessment based on the specific context and circumstances of the processing. Conducting an LIA helps us ensure that processing is lawful. It helps us to think clearly and sensibly about us processing and the impact it could have on the individual.
Consent. When Toloka has requested You to actively indicate Your consent to Toloka's processing of Your personal data for certain purposes. The presence of the consent does not affect the right to use Toloka services or to provide services to Toloka.
Toloka does not further process Your personal data for other purposes than those described in this Privacy Notice.
You can get more information on a specific justification by sending a written request to the contact details specified in section 1 of this Privacy Notice.
Toloka may also be required to share Your personal data with competent authorities in accordance with the applicable legislation.
Toloka transfers personal data to countries which are considered as countries that does not provide for sufficient level of protection of data subjects’ rights under the GDPR or the Swiss law ("Third countries").
For the transfer of Your personal data to Third countries Toloka uses different tools to:
Toloka uses a variety of protections which are appropriate for each data transfer to Third countries, namely:
Data subjects can get more information on the mechanisms of transfers to third countries by Toloka by sending a request to the contact details specified in section 1 of this Privacy Notice.
Toloka processes Your personal data only as long as necessary to perform obligations under the Agreement and for Toloka's legitimate interests, such as:
Upon achieving data processing purposes, upon the termination of the Agreement, or upon Your request, Toloka will delete or anonymise Your personal data so it no longer identifies You, unless Toloka is required to keep some data or Toloka needs to use it for a legally justifiable reason, such as:
Please see Your rights and their descriptions in this table.
|Access||You can ask Toloka to confirm whether or not Toloka processes Your personal data. If so, You can access these personal data and can ask Toloka to explain certain details of the processing|
|Rectification||You can ask Toloka to correct inaccurate personal data concerning You. You can ask Toloka to rectify incomplete or inaccurate personal data.|
|Erasure ('right to be forgotten')||You can ask Toloka to erase personal data concerning You. For example, this applies if (1) the personal data are no longer necessary in relation to the purposes for which they were processed; (2) You withdraw consent to the processing and there is no other legal ground for the processing; (3) the personal data have been unlawfully processed|
|Restriction on processing||You can ask Toloka to mark the stored personal data with the aim to limit their processing in the future under applicable law. This applies if (1) You contest the accuracy of the personal data; (2) You ask to restrict the use of the personal data when their processing is unlawful; (3) You need personal data to protect their rights when Toloka no longer needs the personal data; (4) You have objected the processing based on the legitimate interests pursued by Toloka or by a third party|
|Objection to processing||You can object, on grounds relating to Your particular situation, at any time to processing of Your personal data which is based on the legitimate interests pursued by Toloka or by a third party or when personal data is processed for direct marketing purposes. Toloka shall no longer process the personal data unless Toloka demonstrates compelling legitimate grounds for the processing which override Your interests, rights and freedoms or for the establishment, exercise or defense of legal claims|
|Portability||When the processing is based on Your consent or on the Agreement with You, You can receive Your personal data, which You have provided to Toloka, in a structured, commonly used and machine-readable format and can freely transmit those data to another controller. Where technically feasible, the data subject can also ask Toloka to transmit the personal data directly to another controller|
To exercise Your rights, You can contact Toloka by using the contact details specified in section 1 of this Privacy Notice. Toloka may ask You to specify Your request in writing and to verify Your identity before processing the request. Toloka may also refuse to fulfil Your request on grounds set out in applicable data protection legislation.
We do not knowingly or intentionally collect personal data through Toloka from children under eighteen (18) years of age. If You are under eighteen (18) years of age, do not attempt to register on Toloka Platform and do not provide us any personal data about Yourself unless You have the requisite parental consent. If You are a parent or guardian and You are aware that Your child has violated this Privacy Notice and provided us personal data, please contact with the use of contact details specified in the section 1 of this Privacy Notice.
Pursuant to 47 U.S.C. Section 230(d), Toloka notifies You that parental control protections (such as computer hardware, software, or filtering services) are commercially available that may assist You in limiting access to minors. Information regarding providers of such protections may be found on the Internet by searching “parental control protection” or similar terms.
Where processing is based on consent (or explicit consent), You have the right to withdraw consent at any time. The withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal. To withdraw consent, You can contact Toloka by using the contact details specified in section 1 of this Privacy Notice or by using the toggle button in Your Profile (available to tolokers) and/or by using the unsubscribe link provided at the bottom of each email in direct marketing communications.
Toloka may, as a part of the personal data processing activities, perform automated profiling of data subjects and automated decision-making to monitor users' behavior on the Toloka platform to prevent and detect fraud.
Profiling and automated decision-making takes place by Toloka's anti-fraud system, and it is based on the information collected via user's activities on the Toloka platform, such as features, factors and statistics calculated from the user activity. If fraudulent activity is detected, the anti-fraud system may immediately restrict the user's access to task submission and agreements related to tasks may be terminated, or in case the fraudulent activity is detected from the task requester's account, access to Toloka may be restricted. In anti-fraud analysis such factors are used including but not limiting to user task submission logs, user actions in Toloka interface, cookies, CAPTCHA inputs, mobile device hardware and software info such as camera type.
You have, at all times, the right to object to profiling and automated decision-making and ask further information about the logic involved and the envisaged consequences of the profiling and automated decision-making by contacting Toloka by sending a request at email@example.com. Toloka may ask You to specify Your request in writing and to verify Your identity before processing the request.
You may, at all times, demand human intervention in the processing, obtain an explanation of the decision made, express Your own view and challenge the decision offered to You by contacting Toloka by sending a request at firstname.lastname@example.org. Toloka may ask You to specify Your request in writing and to verify Your identity. If the detected fraudulent activity is not severe and Your identity has been successfully verified, access to Toloka may be regranted to You. In case severe fraudulent activity is detected or You are unable to verify Your identity, Your access to Toloka may remain restricted.
Toloka reviews the algorithms and processed personal data irregularly based on anomalies detection in anti-fraud metrics in order to ensure that the decision-making process is functioning as intended and to ensure that the method of processing is fair, efficient and equal.
You have the right to lodge a complaint with the supervisory authority, in particular in the member state of the European Union of Your habitual residence or, respectively, Switzerland, place of work or place of an alleged infringement of applicable law.
If You reside in a different location, you have the right to lodge a complaint with a supervisory authority in the area of data protection in the country of your residence.
Toloka respects the confidentiality of Your personal data. We have implemented Information Security Management System (ISMS) compliant with international standard “ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems — Requirements” and Privacy Information Management System (PIMS) compliant with the requirements of the international standard «ISO/IEC 27701:2019 Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines». Toloka annually passes an audit performed by the independent external auditor to support continuous improvement of approaches and measures used to keep Your data secured.
Personal data may only be accessed by persons within our organization, or third parties identified in the Section 2 as set forth in this Notice.
Toloka also collects cookies data from all Toloka users based on their contracts with our company that stipulate that Toloka has to provide them with specified features of the Toloka service.
Toloka Web Site users or Toloka users can turn cookies off in the settings of their web browser or mobile device. However, certain Toloka features may become unavailable to Toloka users.
Toloka may share this data with other services to better analyze it and improve our website and service.
Toloka may change this Privacy Notice from time to time at its sole discretion but not less than 1 time per 12 months. If so, Toloka endeavors to carry out reasonable means to notify You about these changes and their effects by an appropriate method and in due time beforehand.
Toloka advises You to review this Privacy Notice located at https://toloka.ai/legal/confidential/ periodically and always after becoming aware of changes regarding the Privacy Notice. Any changes we make will be reflected in an update to the Privacy Notice and by revising the “last updated” date at the top of this Privacy Notice. Changes to this Privacy Notice are effective on the “Date of Effect”, which is not sooner than the date the changes were posted on this page.
In case of discrepancies between the English text of this Privacy Notice and its translations into other languages, the English text shall prevail.
Our Privacy Notice is designed to advise You about how Toloka collects, uses, protects, and discloses the personal data. However, Toloka may contain links to other sites that are not operated by us. Please note that this Privacy Notice does not govern the practices by any third parties. Information collected from You by others, such as third-party websites that You access through links on Toloka Platform, are governed by those entities' privacy policies. If you click a third-party link, you will be directed to that third party's site. We strongly advise You to review privacy policies of every site You visit.
WE HAVE NO CONTROL OVER AND ASSUME NO RESPONSIBILITY FOR THE CONTENT, PRIVACY POLICIES OR PRACTICES OF ANY THIRD-PARTY SITES AND SERVICES.
Individuals with disabilities who are unable to usefully access our Privacy Notice online may contact us at the above-listed contact information to inquire how they can obtain a copy of our notice in another, more easily readable format. Under no circumstances, we will collect or otherwise process information about your health or other sensitive data about You in connection with such request.
This section of the Privacy Notice applies only with regard to California residents. If You are California resident, this section shall prevail over all other parts of the Privacy Notice in case of discrepancies.
Personal information we collected directly from you:
|Categories of Data Collected||Data collected from you and why it was collected|
|Identifiers||Full name; Email; Phone number; Native language; Date of birth; Username; User ID; Company information.|
|Characteristic of protected classifications under California or Federal law.||We do not intentionally collect any information on Your protected classifications, but we may learn your protected classifications inadvertently (e.g. Your age).|
|Commercial information||Record of services with Toloka|
|Financial Information||E-Wallet number. Note that we use third party payment processors as set forth in Section 2 to facilitate Your payments and do not store Your payment card information.|
|Audio, electronic, visual, thermal, olfactory, or similar information||None.|
|Internet/Network Activity||Internet Protocol address (IP address), browser type and language, information about the Internet service provider, sending and exiting pages, information about the operating system, date and time stamps, information about visits; information about mouse movement, scrolls; screen recording; actions in the system (logs).|
|Professional or Employment-related Information||Area of activities or occupation|
|Education Information||Highest degree or level of education|
|Device Information||User's device ID.|
We do not sell Your personal information to third parties.
|Categories of Data Disclosed||Types of Entities to which Data was Disclosed||Reason for Disclosure of Data||Categories of Recipients|
|Identifiers, Commercial information, Financial information, Internet/Network Activity Professional or Employment-related Information, Education information, Device Information.||Please see section 2 with the detailed description.||Please see section 2 with the detailed description.||Please see section 2 with the detailed description.|
We do not sell Your personal information to third parties. Please note that “sale” of personal information does not include those instances when such information is part of a merger, acquisition, or other transaction involving all or part of Toloka business. If we sell all or part of Toloka business, make a sale or transfer of assets, or are otherwise involved in a merger or other business transaction, we may transfer Your personal information to a third party as part of that transaction. If such transaction materially affects the manner in which Your personal information is processed, we will notify you of such change prior to its implementation.
We have in place policies and procedures to facilitate the exercise of privacy rights available to California residents under applicable law. If you are a California resident, You are entitled to the rights as described in the Section 6 of this Privacy Notice. In addition, You may be entitled to the following:
Disclosure of Direct Marketers:
to have access upon simple request, and free of charge, the categories and names/addresses of third parties that have received personal information for direct marketing purposes. Toloka does not share your personal information with third parties for their direct marketing purposes.
Right to Information About Collecting, Selling, Sharing, or Disclosing Personal Information:
upon receipt of a verifiable request, you may obtain a list of:
Right to Opt-Out of the Sale of Personal Information:
California residents have the right to opt-out of the sale of their personal information under certain circumstances.
Right to Non-Discrimination
As defined under relevant law, You have a right to non-discrimination in Toloka services or quality of services You receive from us for exercising your rights.
Please contact with the use of contact details specified in section 1 of this Privacy Notice in relation to exercising these rights. Note that we may ask you to verify your identity - such as by requiring you to provide information about yourself - before responding to such requests.
Submitting a Verifiable Request under the CCPA
California residents have certain rights regarding their personal information under the California Consumer Privacy Act of 2018 ("CCPA"). Toloka will respond to an individual's "verifiable request" to exercise his or her rights under the CCPA - that is, where Toloka has received a request purporting to be from a particular individual, and Toloka has been able to verify the individual's identity. The need to verify an individual's identity is critical to protecting your information, and to ensuring that your information is not shared with anyone pretending to be you or someone who is not authorized to act on your behalf.
You may submit a verifiable request with the use of contact details specified in section 1 of this Privacy Notice. We will ask you to provide information about yourself so that we can verify your identity as part of this process. This information may include your name, address, whether you have an account with Toloka, and other information deemed necessary by us to reasonably verify your identity. Once we have your submission, we will compare the information you provided to the information we have about you to verify your identity. If necessary, we may ask for additional information if we have difficulty confirming your identity. We will not share your information or honor other requests in those situations where we are unable to confirm that a request for your information is a "verifiable request". We will not be able process your request if we cannot verify your identity.
Submitting a request through an authorized agent.
Under California law a California resident can appoint an “authorized agent” to make certain verifiable requests upon their behalf, such as the right to know what information we collect about the consumer or to request deletion of the consumer's information. An authorized agent may submit a request by following the steps outlined above. An authorized agent must identify the consumer he or she is submitting a request on behalf of, and provide the information requested by Toloka to verify the consumer's identity. We will also require the purported authorized agent to submit proof that he or she has been authorized by the consumer to act on the consumer's behalf.
Because the security and privacy of your information is paramount, we will ask that you identify and provide permission in writing for such persons to act as your authorized agent and exercise your applicable rights under California law in such situations. This may require us to contact you directly and alert you that an individual has claimed to be your agent and is attempting to access or delete your information. We will also independently verify your identity to ensure that an unauthorized person is not attempting to impersonate you and exercise your rights without authorization. We will not share your information or honor any other requests in those situations where you cannot or do not grant permission in writing for an identified authorized agent to act on your behalf, or where we cannot independently verify your identity.
Submitting a Request for Removal of Minor Information.
To request the removal of information about a minor by Toloka, parents or guardians may submit a request with the subject line "Removal of Minor Information". Such requests must come from the minor's parents or guardian; minors may not submit information to us via email. Your submission should include the following information:
If we become aware that a minor has provided us personal data or otherwise used Toloka Platform in violation of the Privacy Notice, we will take steps to remove that information.
We do not support Do Not Track. Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable "Do Not Track" by visiting the "Preferences" or "Settings" page of your web browser.
Third parties may collect data that relates to you. We cannot control third parties' responses to do-not-track signals or other such mechanisms. Third parties' use of data relating to you and responsiveness to do-not-track signals is governed by their respective privacy policies.
Unless that contradicts to the law of the state of your residence, provisions of the Chapter A "Privacy Information for California Residents" will apply to the processing of your data. Please contact us whenever you have questions related to your rights or any other questions under this Privacy Notice by either of the methods set forth in the Section 1.
TOLOKA AI AG (SWITZERLAND)
TOLOKA AI INC. (USA)
TOLOKA D.O.O. BEOGRAD (SRB)
Previous versions of the document: