Personal Data Regulation
1. General Provisions
1.1. This Regulation establishes the procedure for processing and protecting personal data of clients (and other individuals) of BRAINWAVES ENGINEERING LLC (hereinafter – the Company).
1.2. This Regulation is governed by the Constitution of the Russian Federation, Federal Law No. 149-FZ of July 27, 2006 "On Information, Information Technologies and Information Protection," Federal Law No. 152-FZ of July 27, 2006 "On Personal Data" (hereinafter – the Federal Law), Decree of the Government of the Russian Federation No. 1119 of November 1, 2012 "On Approval of Requirements for Personal Data Protection During Their Processing in Personal Data Information Systems," Decree of the Government of the Russian Federation No. 687 of September 15, 2008 "On Approval of the Regulation on the Specifics of Personal Data Processing Carried Out Without the Use of Automation Tools," and other regulatory legal acts.
1.3. Basic concepts used in the Regulation:
- Personal Data — any information relating directly or indirectly to a specific or identifiable individual (personal data subject (hereinafter – PD Subject));
- Operator — Brainwaves Engineering Limited Liability Company;
- Processing of Personal Data — any action (operation) or set of actions (operations) performed with or without the use of automation tools with personal data, including collection, recording, systematization, accumulation, storage, updating (refreshing, changing), extraction, use, transfer (distribution, provision, access), anonymization, blocking, deletion, destruction of personal data;
- Automated Processing of Personal Data — processing of personal data using computer technology;
- Protection of Personal Data — the Company's activities to ensure the confidentiality of information through local regulation of the personal data processing procedure and organizational and technical measures;
- Distribution of Personal Data — actions aimed at disclosing personal data to an indefinite circle of persons;
- Provision of Personal Data — actions aimed at disclosing personal data to a specific person or a specific circle of persons;
- Blocking of Personal Data — temporary cessation of personal data processing (except for cases where processing is necessary to clarify personal data);
- Destruction of Personal Data — actions that make it impossible to restore the content of personal data in the personal data information system and/or as a result of which the physical media of personal data are destroyed;
- Anonymization of Personal Data — actions that make it impossible, without the use of additional information, to determine the ownership of personal data to a specific personal data subject;
- Personal Data Information System — a set of personal data contained in databases and information technologies and technical means ensuring their processing;
- Cross-border Transfer of Personal Data — transfer of personal data to the territory of a foreign state to a foreign government authority, a foreign individual, or a foreign legal entity.
1.4. The purpose of this Regulation is to ensure the protection of human and civil rights and freedoms when processing their personal data. This Regulation establishes mandatory general requirements and rules for all Company employees regarding work with all types of information media containing personal data of PD Subjects.
1.5. This Regulation is approved by the Head of the Company and is mandatory for all employees who have access to personal data of PD Subjects.
2. Principles of Personal Data Processing
2.1. Personal data processing is carried out in compliance with the principles and rules stipulated by this Regulation and the legislation of the Russian Federation.
2.2. To ensure human and civil rights and freedoms, the Operator, when processing personal data of a PD Subject, must comply with the following general requirements:
2.2.1. Processing of personal data of a PD Subject must be carried out on a legal and fair basis.
2.2.2. When determining the scope and content of processed personal data, the Operator must be guided by the Constitution of the Russian Federation and other regulatory legal acts.
2.2.3. Personal data processing must be limited to achieving specific, predetermined, and legitimate purposes. Processing of personal data incompatible with the purposes of collecting personal data is not allowed.
2.2.4. Merging databases containing personal data processed for purposes incompatible with each other is not allowed.
2.2.5. Only personal data that meets the purposes of their processing is subject to processing.
2.2.6. The content and scope of processed personal data must correspond to the stated purposes of processing. Processed personal data must not be excessive in relation to the stated purposes of their processing.
2.2.7. When processing personal data, the accuracy of personal data, their sufficiency, and, where necessary, their relevance in relation to the purposes of personal data processing must be ensured. The Operator must take necessary measures or ensure they are taken to delete or clarify incomplete or inaccurate data.
2.2.8. Personal data should be obtained directly from the PD Subject.
2.2.9. It is prohibited to obtain and process personal data of a PD Subject concerning their political, religious, and other beliefs, private life, membership in public associations, or trade union activities, except for cases provided for by the legislation of the Russian Federation.
2.3. Personal data processing is carried out with the consent of personal data subjects to the processing of their personal data, as well as without such consent in cases provided for by the legislation of the Russian Federation.
3. Purposes of Collection, Scope, and Categories of Processed Personal Data
3.1. Processing of personal data in the Company is carried out through collection, recording, systematization, accumulation, storage, updating (refreshing, changing), extraction, use, transfer (provision, access), blocking, deletion, destruction of personal data solely to ensure compliance with federal legislation and other regulatory legal acts, aligning with the purposes predetermined and stated during the collection of personal data.
3.2. The Operator processes personal data for the following purposes:
3.2.1. Provision of services under contracts with clients (counterparties) in the field of scientific research and development in biotechnology.
3.2.2. Ensuring timely and comprehensive consideration of oral and written requests from the personal data subject.
3.2.3. Fulfilling requests from authorized state and municipal bodies, including operational-investigative bodies.
3.2.4. Maintaining personnel and accounting records.
3.2.5. Recruiting personnel (candidates) for vacant positions of the PD Operator.
3.2.6. Ensuring compliance with labor, tax, and pension legislation.
3.2.7. Creation and operation of a social network.
3.3. For the purposes specified in clause 3.2.1, the Operator processes the following categories of PD Subjects:
- Counterparties;
- Representatives of counterparties;
- Clients, including users and visitors of information platforms, devices, and other information spaces created by the Operator;
- Legal representatives;
- Users of the information platform, including bloggers, content authors;
- Persons in civil-law relations with the Operator;
- Persons whose personal data is processed in connection with the performance of functions, powers, and duties assigned to the Operator by the legislation of the Russian Federation.
For this category of PD Subjects, the Operator processes the following categories of personal data:
General categories of personal data:
- Last name, first name, patronymic;
- Year, month, date of birth;
- Place of birth;
- Marital status;
- Income;
- Gender;
- Residential address;
- Registration address;
- Phone number;
- Email address;
- SNILS (individual insurance account number);
- INN (taxpayer identification number);
- Citizenship;
- Identity document data;
- Data of an identity document for travel outside the Russian Federation;
- Driver's license data;
- Data from a birth certificate;
- Bank card details;
- Bank account number;
- Personal account number;
- Profession;
- Position;
- Employment history information;
- Attitude to military service, military registration information;
- Data collected via metric programs;
- Education information;
Special categories of personal data:
- Health status information;
Other categories of personal data:
- Information about marriage (dissolution);
- Information from title documents for real estate.
3.4. The legal basis for processing personal data for the purposes specified in clause 3.2.1 is:
- The Constitution of the Russian Federation, the Civil Code of the Russian Federation, the Tax Code of the Russian Federation, Federal Law No. 402-FZ of December 6, 2011 "On Accounting," Federal Law No. 115-FZ of August 7, 2001 "On Counteracting the Legalization (Laundering) of Proceeds from Crime and the Financing of Terrorism," and other regulatory legal acts regulating relations related to the Company's activities;
- Founding documents of the Company;
- Contracts concluded between the Company and the PD Subject;
- Consent to the processing of personal data (in cases not directly provided for by the legislation of the Russian Federation but consistent with the Operator's powers).
3.5. For the purposes specified in clause 3.2.2, the Operator processes the following categories of PD Subjects: Persons who have contacted the Operator with an appeal or complaint.
For this category of PD Subjects, the Operator processes the following categories of personal data:
- Last name, first name, patronymic;
- Other personal data specified in the appeal, as well as those that became known during the consideration of the appeal.
3.6. The legal basis for processing personal data for the purposes specified in clause 3.2.2 is that the processing of personal data is necessary for the implementation and performance of the functions, powers, and duties assigned to the Operator by the legislation of the Russian Federation.
3.7. For the purposes specified in clause 3.2.3, the Operator processes the following categories of PD Subjects: Persons whose personal data is processed in connection with the execution of a request.
For this category of PD Subjects, the Operator processes the following categories of personal data:
- Personal data specified in the request of an authorized state or municipal body, including operational-investigative bodies, as well as those that became known during the execution of the request.
3.8. The legal basis for processing personal data for the purposes specified in clause 3.2.3 is that the processing of personal data is necessary for the implementation and performance of the functions, powers, and duties assigned to the Operator by the legislation of the Russian Federation.
3.9. For the purposes specified in clauses 3.2.4–3.2.6, the Operator processes the following categories of PD Subjects:
- Last name, first name, patronymic;
- Year of birth;
- Month of birth;
- Date of birth;
- Place of birth;
- Social status;
- Income;
- Gender;
- Email address;
- Registration address;
- SNILS;
- INN;
- Citizenship;
- Identity document data.
3.9.1. Within the scope of the purpose specified in clause 3.2.7 (social network), the Operator processes the following special categories of personal data:
1. Data provided by the User:
- Name (not necessarily real, not unique), Username (not necessarily real, unique);
- Contact details: Email address;
- Account password;
- Date of birth;
- Images: photos (avatar, feed photos), video recordings with a person's facial image, voice messages;
- Country of residence;
- User's profession;
- List of interests;
- Links to other social networks;
- Additional data that is not identifying and reflects the user's interests (work experience, salary, position).
2. Automatically generated data (Technical):
- Cookies: (Technical, analytical, advertising);
- Device data: IP address, browser type and version, operating system, device model, unique identifiers (IDFA, GAID);
- Location data.
3. Activity data (Behavioral):
- User content (post texts, comments, private messages);
- Information about subscriptions, likes, reposts;
- Search query history;
- List of friends, subscriptions, and followers.
3.10. The Operator processes personal data for the purposes specified in clauses 3.2.1–3.2.7 using a mixed method (using automation tools and without using them).
3.11. The Operator does not carry out cross-border transfer of personal data of PD Subjects.
3.12. Terms of processing and storage of personal data:
3.12.1. Processing of personal data in the Company ceases in the following cases:
- When a fact of unlawful processing of personal data is identified;
- When the purposes of their processing are achieved;
- Upon expiration of the validity period or upon withdrawal by the PD Subject of consent to the processing of their personal data, subject to the conditions provided for in Article 21 of the Federal Law;
- When the PD Subject requests the Operator to cease processing personal data, except for the cases provided for in Part 5.1 of Article 21 of the Federal Law.
3.12.2. Personal data is stored in a form that allows identifying the personal data subject no longer than required by the purposes of their processing, except for cases where the storage period for personal data is established by federal law or a contract to which the personal data subject is a party.
3.12.3. Personal data of PD Subjects on paper is stored in the Company for the storage periods of documents for which these periods are stipulated by the legislation on archiving in the Russian Federation (Federal Law No. 125-FZ of October 22, 2004 "On Archiving in the Russian Federation," the List of standard managerial archival documents generated in the activities of state bodies, local self-government bodies, and organizations, indicating their storage periods (approved by Order of the Federal Archive Agency No. 236 of December 20, 2019)).
3.12.4. The storage period for personal data of a PD Subject processed in personal data information systems corresponds to the storage period for personal data on paper.
4. Organization of Personal Data Protection
4.1. Protection of personal data of a PD Subject from unlawful use or loss is ensured by the Operator in accordance with the procedure established by the legislation of the Russian Federation.
4.2. When processing personal data, the Operator:
- Ensures a security regime for premises where the information system is located, preventing the possibility of uncontrolled entry or stay of persons without access rights in these premises;
- Ensures the safety of personal data media;
- Approves the list of employees whose access to personal data processed in the information system is necessary for them to perform their official (labor) duties;
- Uses information security means that have passed the conformity assessment procedure to the requirements of the legislation of the Russian Federation in the field of information security assurance;
- Appoints an official (employee) responsible for ensuring the security of personal data in the information system.
4.3. Information about PD Subjects is stored on paper in the Company's premises. Specially equipped cabinets and safes are used to store media, which are locked, sealed, and handed over for security.
4.4. Personal data of a PD Subject in electronic form is stored in the Operator's local computer network, in electronic folders and files on the personal computers of the Operator and employees authorized to process personal data of PD Subjects and protected by an individual password. Disclosure of the access password to an Operator employee's personal computer is not allowed.
4.5. All confidentiality measures during the collection, processing, and storage of personal data apply to both paper and electronic (automated) information media.
4.6. Only Operator employees who are authorized to work with personal data of PD Subjects and have signed a non-disclosure agreement regarding personal data of PD Subjects may have access to the processing of personal data of a PD Subject.
4.7. Operator employees who have access to personal data of PD Subjects perform actions related to the processing of personal data according to business necessity and their assigned functions within the framework of their job descriptions.
4.8. The following are subject to protection:
4.8.1. Information about personal data of the PD Subject.
4.8.2. Paper documents containing personal data of the PD Subject.
4.8.3. Personal data contained on electronic media.
4.9. The Operator takes necessary legal, organizational, and technical measures or ensures their adoption to protect personal data of a PD Subject from unlawful or accidental access, destruction, alteration, blocking, copying, provision, distribution of personal data, as well as from other unlawful actions regarding personal data in accordance with Article 19 of the Federal Law, in particular:
1) Identifies threats to the security of personal data during their processing in personal data information systems;
2) Applies organizational and technical measures to ensure the security of personal data during their processing in personal data information systems, necessary to meet the requirements for the protection of personal data, the implementation of which ensures the levels of personal data protection established by the Government of the Russian Federation;
3) Applies information security tools that have undergone the conformity assessment procedure in the established manner;
3.1) Applies information security tools for the destruction of personal data that have undergone the conformity assessment procedure in the established manner, in which the information destruction function is implemented;
4) Assesses the effectiveness of measures taken to ensure the security of personal data before putting the personal data information system into operation;
5) Maintains records of machine-readable personal data media;
6) Searches for facts of unauthorized access to personal data and takes measures, including measures to detect, prevent, and eliminate the consequences of computer attacks on personal data information systems and to respond to computer incidents in them;
7) Restores personal data modified or destroyed due to unauthorized access;
8) Establishes rules for access to personal data processed in the personal data information system, and also ensures registration and recording of all actions performed with personal data in the personal data information system;
9) Monitors the measures taken to ensure the security of personal data and the level of protection of personal data information systems.
4.10. The Operator carries out internal control and/or audit of the compliance of personal data processing with the Federal Law and regulatory legal acts adopted in accordance with it, personal data protection requirements, the Operator's policy regarding personal data processing, and the Operator's local acts.
4.11. Responsible persons of the relevant departments storing personal data of PD Subjects on paper and machine-readable information media ensure their protection from unauthorized access and copying in accordance with the "Regulation on the Specifics of Personal Data Processing Carried Out Without the Use of Automation Tools," approved by Decree of the Government of the Russian Federation No. 687 of September 15, 2008.
4.12. Responsible persons of structural divisions processing personal data of PD Subjects in personal data information systems and on machine-readable information media ensure protection in accordance with the Requirements for the Protection of Personal Data during their Processing in Personal Data Information Systems, approved by Decree of the Government of the Russian Federation No. 1119 of November 1, 2012.
5. Transfer of Personal Data
5.1. When transferring personal data of a PD Subject, the Company complies with the following requirements:
- Does not disclose personal data of the PD Subject to a third party without their written consent, except when necessary to prevent a threat to the life and health of the PD Subject, as well as in other cases established by federal laws;
- Does not disclose personal data of the PD Subject for commercial purposes without their written consent;
- Warns persons receiving personal data of the PD Subject that this data may only be used for the purposes for which it was disclosed, and requires these persons to confirm that this rule is observed;
- Persons receiving personal data of the PD Subject must maintain confidentiality;
- Allows access to personal data of the PD Subject only to specifically authorized persons, and these persons must have the right to receive only that personal data of the PD Subject necessary to perform specific functions;
- Does not request information about the health status of the PD Subject.
5.2. All information about the transfer of personal data of a PD Subject is recorded to monitor the legality of the use of this information by the persons who received it.
5.3. Transfer of personal data upon requests from third parties, if such transfer is not directly provided for by the legislation of the Russian Federation, is permitted only with the consent of the PD Subject to the processing of their personal data in terms of their provision or consent to the distribution of personal data.
5.4. Transfer of information containing personal data of a PD Subject by phone, due to the impossibility of identifying the person requesting the information, is prohibited.
6. Obligations of the Operator and the PD Subject
6.1. The Operator undertakes to:
6.1.1. Ensure at its own expense the protection of personal data of the PD Subject from unlawful use or loss in accordance with the procedure established by the legislation of the Russian Federation.
6.1.2. Process personal data of the PD Subject solely for the purpose of providing lawful services to the PD Subject.
6.1.3. Take measures necessary and sufficient to ensure the fulfillment of duties provided for by the Federal Law and regulatory legal acts adopted in accordance with it. Such measures include, in particular: 1) Appointment by the Operator of a person responsible for organizing the processing of personal data; 2) Issuance by the Operator of documents defining its policy regarding the processing of personal data, local acts on the processing of personal data; 3) Application of legal, organizational, and technical measures to ensure the security of personal data; 4) Implementation of internal control and/or audit of compliance of personal data processing with the Federal Law; 5) Assessment of harm that may be caused to personal data subjects; 6) Familiarization of the Operator's employees directly involved in the processing of personal data with the provisions of the legislation of the Russian Federation on personal data.
6.1.4. Obtain personal data of the PD Subject directly from themselves. If personal data of the PD Subject can only be obtained from a third party, the PD Subject must be notified of this in advance and their written consent must be obtained.
6.1.5. Explain to the PD Subject the legal consequences of refusing to provide their personal data and/or give consent to their processing, if, in accordance with the Federal Law, the provision of personal data and/or obtaining the Operator's consent to the processing of personal data is mandatory.
6.1.6. Not receive or process personal data of the PD Subject concerning their racial or national origin, political views, religious or philosophical beliefs, health status, intimate life, except for cases provided for by law.
6.1.7. In the event of termination of the Operator's activities, ensure the recording and safety of documents, the procedure for their transfer to state storage in accordance with the rules provided for by the current legislation of the Russian Federation.
6.1.8. Upon request of the PD Subject or their legal representative, provide complete information about their personal data and the processing of this data.
6.2. To ensure the accuracy of personal data, the PD Subject undertakes to: When concluding a contract with the Company, provide the Company with complete and accurate data about themselves; In case of changes in the information constituting the PD Subject's personal data, provide this information to the Company within 14 calendar days.
7. Rights of the PD Subject to Protect Their Personal Data
7.1. The PD Subject, in order to protect their personal data stored by the Operator, has the right to:
- Full information about their personal data and the processing of this data, including: confirmation of the fact of personal data processing; legal grounds and purposes of personal data processing; purposes and methods of personal data processing used by the Operator; terms of personal data processing, including storage periods; information about the carried out or intended cross-border data transfer; the name or last name, first name, patronymic, and address of the person processing personal data on behalf of the Operator;
- Free access to their personal data, including the right to receive copies of any record containing the PD Subject's personal data, except for cases provided for by federal law;
- Determine their representatives to protect their personal data;
- Demand the exclusion or correction of incorrect or incomplete personal data, as well as data processed in violation of the requirements of the Federal Law;
- Demand that the organization notify all persons to whom incorrect or incomplete personal data of the PD Subject was previously communicated of all exclusions, corrections, or additions made to them;
- Appeal in court any unlawful actions or inaction of the Operator during the processing and protection of personal data.
7.2. The PD Subject has the right to protect their rights and legitimate interests, including compensation for losses and/or compensation for moral damage in court.
8. Procedure for Destruction and Blocking of Personal Data
8.1. In the event of unlawful processing of personal data being identified upon a request from the PD Subject, the Operator is obliged to block the unlawfully processed personal data relating to this PD Subject, or ensure their blocking, from the moment of such request for the period of verification.
8.2. In the event of inaccurate personal data being identified upon a request from the PD Subject, the Operator is obliged to block the personal data relating to this PD Subject, or ensure their blocking, from the moment of such request for the period of verification, if blocking the personal data does not violate the rights and legitimate interests of the PD Subject or third parties.
8.3. Upon confirmation of the fact of inaccuracy of personal data, the Operator, based on information provided by the PD Subject or other necessary documents, is obliged to clarify the personal data, or ensure their clarification, within seven working days from the date of submission of such information, and unblock the personal data.
8.4. In the event of unlawful processing of personal data being identified, carried out by the Operator, the Operator is obliged to cease the unlawful processing of personal data within a period not exceeding three working days from the date of this identification.
8.5. If it is impossible to ensure the lawfulness of personal data processing, the Operator is obliged to destroy such personal data within a period not exceeding ten working days from the date of identification of the unlawful processing of personal data. The Operator is obliged to notify the PD Subject of the elimination of the violations or the destruction of the personal data.
8.6. In the event of an established fact of unlawful or accidental transfer (provision, distribution, access) of personal data resulting in a violation of the rights of the PD Subject, the Operator is obliged to notify the authorized body for the protection of the rights of personal data subjects of the incident within 24 hours, and within 72 hours, report the results of the internal investigation of the identified incident.
8.7. Upon achieving the purpose of processing personal data, the Operator is obliged to cease processing the personal data and destroy the personal data within a period not exceeding thirty days from the date of achieving the purpose of processing personal data, unless otherwise provided by the contract to which the PD Subject is a party, beneficiary, or guarantor.
8.8. Upon withdrawal by the PD Subject of consent to the processing of their personal data, the Operator is obliged to cease their processing, or ensure the cessation of such processing, and if the retention of personal data is no longer required for the purposes of personal data processing, destroy the personal data within a period not exceeding thirty days from the date of receipt of said withdrawal, unless otherwise provided by the contract to which the PD Subject is a party, beneficiary, or guarantor, by another agreement between the Operator and the PD Subject, or if the Operator is not entitled to process personal data without the consent of the PD Subject on the grounds provided for by the Federal Law.
8.9. In the event of a request from the PD Subject to the Operator to cease processing personal data, the Operator is obliged, within a period not exceeding ten working days from the date of receipt of the relevant request, to cease their processing, or ensure the cessation of such processing, except for cases provided for by the Federal Law. This period may be extended, but by no more than five working days, if the Operator sends a reasoned notification to the PD Subject indicating the reasons for extending the period for providing the requested information.
8.10. If it is impossible to destroy personal data within the period specified in clauses 8.4–8.9 of this Regulation, the Operator blocks such personal data and ensures the destruction of personal data within a period not exceeding six months, unless a different period is established by federal laws.
8.11. After the expiration of the standard storage period for documents containing personal data of a PD Subject, or upon the occurrence of other legal grounds, the documents are subject to destruction.
8.12. For these purposes, the Operator creates an expert commission, the composition of which is determined by the Head of the Company.
8.13. The commission draws up a list indicating the documents, other physical media, and/or information in information systems containing personal data that are subject to destruction.
8.14. The destruction of personal data must be carried out in a manner that excludes the possibility of restoring these personal data on the medium: Personal data on paper is destroyed by shredding; Personal data on electronic media is destroyed by mechanically breaking the integrity of the medium, preventing the reading or restoration of personal data, as well as by deleting data from electronic media using methods and means of guaranteed deletion of residual information.
8.15. The fact of destruction of personal data, according to the Requirements for Confirmation of Destruction of Personal Data, approved by Order of Roskomnadzor No. 179 of October 28, 2022, is confirmed by an act of destruction of personal data and an extract from the event log in the personal data information system.
8.16. The act may be drawn up on paper or in electronic form signed with an electronic signature.
8.17. The act of destruction of personal data and the extract from the log are subject to storage for 3 years from the date of destruction of the personal data.
8.18. The form of the act and the extract from the log, taking into account the information that must be contained in these documents, is approved by order of the Head of the Company.
9. Responsibility for Violation of Norms Regulating Personal Data Processing
9.1. The Company is responsible for the personal information in its possession and establishes personal responsibility of employees for compliance with the established confidentiality regime.
9.2. Each employee who receives a document containing personal data of a PD Subject for work bears sole responsibility for the safety of the medium and the confidentiality of the information.
9.3. Any person may contact the Operator with a complaint about a violation of the norms of this Regulation and applicable legislation on personal data protection. Complaints and statements regarding compliance with data processing requirements are considered within ten days from the date of their receipt.
9.4. Persons guilty of violating the norms regulating the receipt, processing, and protection of personal data of a PD Subject bear disciplinary, administrative, civil, or criminal liability in accordance with federal laws.
10. Final Provisions
10.1. This Regulation comes into force from the moment of its approval.
10.2. This Regulation is subject to adjustment in case of changes in the legislation of the Russian Federation, regulatory bodies in the field of personal data protection, or internal documents of the Company in the field of confidential information protection.
10.3. In case of changes in the legislation of the Russian Federation in the field of personal data protection, the provisions of the Regulation that contradict the legislation shall not apply until they are brought into compliance.
10.4. The Company ensures unlimited access to this document.
10.5. This Regulation is communicated to all employees of the Company who have access to personal data of PD Subjects, personally against signature.
