Privacy and Personal Data Processing Policy
This Privacy and Personal Data Processing Policy (hereinafter — the Policy) is an integral part of the Public Offer for concluding a public contract for the provision of SPA procedures and the purchase of Gift Certificates at the Thai massage and SPA salons "Imbir Thai Spa Classic" (hereinafter — the Offer). It applies to all information, including personal data, of the User of the Website www.imbir.kz (its sections and subdomains), and defines the procedure for the collection, processing and security measures for personal data undertaken by LLP "Imbir Group".
LLP "Imbir Group" (hereinafter — the Operator) sets as its most important goal and condition of its activities the observance of the rights and freedoms of the individual and citizen when processing their personal data, including the protection of the rights to privacy and to personal and family secrets.
This Policy is based on the Law of the Republic of Kazakhstan No. 94-V dated 21 May 2013 "On Personal Data and Its Protection" and applies to all information that the Operator may obtain about the User of the Website www.imbir.kz (its sections and subdomains).
The current version of this Policy is permanently available on the Website www.imbir.kz (its sections and subdomains).
All processed Personal Data is confidential, strictly protected information in accordance with the current legislation of the Republic of Kazakhstan.
Terms and definitions:
Operator of the database containing personal data (hereinafter — the Operator) — a state body, natural person and (or) legal entity that carries out the collection, processing and protection of personal data.
Personal data subject (hereinafter — the Subject) — a natural person to whom the personal data relates.
Personal data — information relating to a personal data subject who is identified or identifiable on its basis, recorded on electronic, paper and (or) other tangible media.
Collection of personal data — actions aimed at obtaining personal data.
Processing of personal data — actions aimed at the accumulation, storage, alteration, supplementation, use, dissemination, depersonalization, blocking and destruction of personal data.
Automated processing of personal data — the processing of personal data using computing equipment.
Dissemination of personal data — actions aimed at disclosing personal data to an indefinite range of persons.
Provision of personal data — actions aimed at disclosing personal data to a specific person or a specific range of persons.
Blocking of personal data — actions to temporarily suspend the collection, accumulation, alteration, supplementation, use, dissemination, depersonalization and destruction of personal data.
Accumulation of personal data — actions to systematize personal data by entering it into a database containing personal data.
Database containing Personal Data (hereinafter — the Database) — a set of ordered Personal Data of the User.
Storage of personal data — actions to ensure the integrity, confidentiality and availability of Personal Data.
Protection of Personal Data — a set of measures, including legal, organizational and technical ones, carried out for the purposes established by this Policy.
Destruction of personal data — actions as a result of which it becomes impossible to restore the Personal Data.
Personal data security breach — a breach of the protection of personal data resulting in unlawful dissemination, alteration and destruction, unauthorized dissemination of transmitted, stored or otherwise processed personal data, or unauthorized access to it.
General provisions
- The Policy defines any action (operation) or set of actions (operations) involving the collection, recording, systematization, accumulation, storage, clarification (updating, alteration), extraction, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion and destruction of personal data, as well as information on the implemented requirements for the protection of personal data.
Purposes of collecting personal data about the User
- Personal data is processed by the Operator for the following purposes:
— compliance with the lawfulness of personal data processing;
— identification of the User for acceding to the Public Offer for concluding a public contract for the provision of SPA procedures and the purchase of Gift Certificates at the Thai massage and SPA salons "Imbir Thai Spa Classic" (hereinafter — the Salon), posted on the Website www.imbir.kz (its sections and subdomains);
— establishing feedback with the User, including but not limited to sending notifications, SMS messages and requests concerning the use and processing of the Application/Booking for the Salon's Services from the Operator;
— confirmation of the completeness of the data provided by the User that is necessary to begin providing the Services;
— providing the User with effective customer and technical support in the event of problems related to the use of the Website www.imbir.kz (its sections and subdomains);
— fulfilling the requirements of the legislation on determining the procedure for processing and protecting the personal data of citizens who are Clients of the Salon;
— for the purpose of the Salon organizing and conducting loyalty programs, marketing and/or advertising campaigns, research and surveys;
— promoting the Salon's services on the market by making direct contact with the Salon's Clients using various means of communication, including but not limited to: by telephone using special messaging applications, SMS mailings and other non-prohibited methods;
— for other lawful purposes.
Composition, procedure and terms of processing Personal Data
- The Operator may process the following personal data: surname, first name, patronymic, telephone numbers, date of birth.
- All personal data processed by the Operator is confidential, strictly protected information in accordance with the legislation.
- The processing and storage of Personal Data is carried out in accordance with the requirements of the legislation of the Republic of Kazakhstan until the Operator ceases its activities or until the Website www.imbir.kz (its sections and subdomains) is liquidated (whichever event occurs later).
- Personal Data is stored in accordance with the current legislation of the Republic of Kazakhstan by any lawful means, including in personal data information systems using automation tools or without the use of such tools. The Operator takes the necessary and sufficient organizational and technical measures to protect Personal Data.
- The Operator undertakes to use Personal Data in accordance with the Law of the Republic of Kazakhstan "On Personal Data and Its Protection" and the Operator's internal documents.
- The Operator has the right to transfer Personal Data without the User's consent to law enforcement agencies, courts and other authorized state bodies of the Republic of Kazakhstan upon their reasoned request, as well as in other cases expressly provided for by the current legislation of the Republic of Kazakhstan.
- The transfer of personal data to third parties in other cases is possible only with the consent of the personal data subject and only for the purpose of fulfilling obligations to the personal data subject.
Procedure for the collection, storage, transfer and other types of processing of personal data
- The processing of personal data takes place by automated and non-automated means.
- The processing of personal data carried out without the use of automation tools is performed in such a way that, for each category of personal data, it is possible to determine the storage locations of the personal data (tangible media). The Operator has established a list of persons who process personal data or have access to it. Separate storage is ensured for personal data (tangible media) processed for different purposes. The Operator ensures the safety of personal data and takes measures excluding unauthorized access to personal data.
- The processing of personal data carried out using automation tools is performed subject to the following actions:
— the Operator carries out technical measures aimed at preventing unauthorized access to personal data and (or) its transfer to persons who do not have the right to access such information;
— protective tools are configured for the timely detection of instances of unauthorized access to personal data;
— the technical means of automated processing of personal data are isolated in order to prevent any impact on them that could disrupt their operation;
— the Operator performs data backups in order to be able to immediately restore personal data modified or destroyed as a result of unauthorized access to it;
— continuous monitoring of the level of personal data security is carried out.
- Only employees who have passed a certain admission procedure are allowed to process personal data, which includes:
— familiarization of the employee, against signature, with the local regulations governing the procedure and process of working with personal data;
— obtaining from the employee a signed non-disclosure undertaking regarding personal data when working with it;
— the employee obtaining and using in their work individual credentials for access to information systems containing personal data. At the same time, each employee is granted the minimum access rights to personal data information systems necessary to perform their job duties.
Employees with access to personal data receive only the personal data necessary to perform their specific job duties.
- Personal data is stored in paper and electronic form.
- When storing personal data, organizational and technical measures are observed to ensure its safety and exclude unauthorized access to it.
Basic rights and obligations of the Operator
- The Operator has the right to:
— receive from the Personal Data Subject accurate information and/or documents containing personal data and process it in accordance with this Policy.
- The Operator is obliged to:
— approve documents defining the Operator's policy regarding the collection, processing and protection of personal data;
— organize the processing of personal data in the manner established by the current legislation of the Republic of Kazakhstan;
— take and observe the necessary measures, including legal, organizational and technical ones, to protect personal data in accordance with the legislation of the Republic of Kazakhstan;
— provide the Personal Data Subject, upon their request, with information concerning the processing of their personal data;
— comply with the legislation of the Republic of Kazakhstan on personal data and its protection;
— fulfill other obligations provided for by the Law of the Republic of Kazakhstan "On Personal Data and Its Protection".
Basic rights and obligations of Personal Data Subjects
- Personal Data Subjects have the right to:
— know about the Operator holding their personal data, as well as to receive information containing: confirmation of the fact, purposes, sources and methods of collecting and processing personal data; a list of the personal data; the terms of processing personal data, including the terms of its storage;
— require the Operator to alter and supplement their personal data if the personal data is incomplete, outdated, inaccurate or unlawfully obtained;
— require the Operator to block their personal data in the event of information about a breach of the conditions for collecting and processing personal data;
— require the Operator to destroy their personal data whose collection and processing were carried out in violation of the legislation of the Republic of Kazakhstan, as well as in other cases established by the said Law and other regulatory legal acts of the Republic of Kazakhstan;
— withdraw consent to the collection and processing of personal data;
— give consent to (or refuse) the Operator disseminating their personal data in publicly available sources of personal data;
— protect their rights and legitimate interests, including compensation for moral and material harm;
— exercise other rights provided for by the said Law and other laws of the Republic of Kazakhstan.
- Personal Data Subjects are obliged to:
— provide the Operator with accurate data about themselves, as well as any changes (clarifications) to it;
— promptly provide the Operator with changes (clarifications) to their personal data.
Liability of the parties
- The Operator is liable for the intentional disclosure of Personal Data in accordance with the current legislation of the Republic of Kazakhstan, except for the cases provided for by the current legislation, as well as by clause 21 of this Policy.
- In the event of loss or disclosure of Personal Data, the Operator is not liable if the Personal Data:
— became public knowledge before its loss or disclosure;
— was received from a third party before the moment of its receipt from the User;
— was obtained by third parties through unauthorized access to the files of the Website www.imbir.kz (its sections and subdomains);
— was disclosed with the User's consent.
- Persons who have provided the Operator with inaccurate data about themselves, or with information about another Personal Data Subject without the latter's consent, bear liability in accordance with the current legislation of the Republic of Kazakhstan.
Dispute resolution
- The law of the Republic of Kazakhstan applies to this Policy and to the relations between the User and the Operator arising in connection with the application of the Policy.
- All possible disputes are subject to resolution in accordance with the current legislation at the place of registration of the Operator. Before applying to a court, the User must comply with the mandatory pre-trial procedure and send the Operator a corresponding claim in writing. The term for responding to a claim is 30 (thirty) calendar days.
Final provisions
- The Operator has the right, at its own discretion, to make changes to this Policy (in full or in part) without obtaining additional consent from the User, by publishing or posting the changes or the updated version on the Website www.imbir.kz (its sections and subdomains).
- If, for one reason or another, one or more provisions of the Privacy Policy are found to be invalid or unenforceable, this does not affect the validity or enforceability of the remaining provisions of the Privacy Policy.
- The User undertakes to independently monitor changes to the Privacy Policy by reviewing the current version.
- Changes made to the Privacy Policy take effect from the moment the amended Privacy Policy is posted on the Website www.imbir.kz (its sections and subdomains), unless a different procedure is provided for by the changes made.
