This Privacy Policy sets out the procedure for the collection, processing, use, storage, transfer, and protection of personal data when using the memleket.kz online resource, including its pages, services, and functionality.
This Policy applies to Website visitors, registered Users, subscribers, persons submitting requests, and other individuals whose personal data is processed in connection with the operation of the Website.
By using the Website and providing personal data through its forms and services, the User confirms that they have read this Policy.
Where applicable law requires consent to the collection and processing of personal data, such consent will be requested separately through the relevant form, checkbox, Account settings, or another method provided by the Website.
1. Definitions
The following terms are used in this Policy:
Website means the memleket.kz online resource, including its language versions, pages, sections, software components, and related services.
Administration means the Website Owner and persons authorized to manage, maintain, and develop the Website.
User means an individual who visits the Website, registers an Account, subscribes to notifications, submits a request, or otherwise uses the Website.
Personal Data means information relating to an identified individual or an individual who can be identified on the basis of such information, recorded in electronic, paper, or another material form.
Processing of Personal Data means actions involving the collection, accumulation, storage, modification, supplementation, use, distribution, anonymization, blocking, or destruction of Personal Data.
Publicly Available Personal Data means Personal Data that is freely accessible on the basis of applicable law, the consent of the data subject, or publication in official or other lawfully accessible sources.
Account means a set of User data required to identify the User and provide access to certain Website functions.
Cookies means small data files stored by the User’s browser when visiting the Website.
2. Personal Data Owner and Operator
The owner and operator of Personal Data processed through memleket.kz is:
Individual Entrepreneur Мұстафин Қ. Б. (Mustafin K. B.)
Individual Identification Number: 950505350297
For questions regarding the processing and protection of Personal Data, please contact:
3. Scope of the Policy
3.1. This Policy applies to Personal Data obtained by the Administration:
when the User visits the Website;
when the User registers or uses an Account;
when the User signs in through a third-party service;
when the User subscribes to notifications;
when the User uses bookmarks, comments, or other User functions;
when the User submits questions, applications, complaints, or other requests;
when the User communicates with the Administration by email;
through the Website’s analytical, technical, and security systems;
from official and other lawfully accessible public sources.
3.2. This Policy does not govern the processing of data by third-party online resources that the User may access through links published on memleket.kz.
3.3. The owners of third-party resources independently determine how they process data in accordance with their own privacy policies.
4. Personal Data That May Be Processed
Depending on the functions used by the User, the Administration may process the following categories of data.
4.1. Data provided by the User
first name, last name, and display name;
email address;
telephone number, where provided by the User;
information included in the User’s profile;
the content of requests, questions, comments, and messages;
documents, images, and files uploaded by the User;
selected language;
subscription topics;
other information voluntarily provided by the User.
4.2. Account data
User identifier;
email address;
password hash;
registration date;
date and time of sign-in;
email verification status;
Account settings;
saved Materials and bookmarks;
subscriptions and preferences;
history of actions associated with the use of Account functions.
The Administration does not store the User’s password in plain text.
4.3. Third-party authentication data
When the User signs in through Google, Apple, Telegram, or another external service, the Website may receive information authorized by the User and provided by the relevant service, including:
a unique Account identifier;
name;
email address;
profile image;
other data within the scope of the permission granted by the User.
The User’s password for the third-party service is not provided to the Administration.
4.4. Technical data
The following data may be collected automatically when the User visits the Website:
IP address;
date and time of access;
address of the requested page;
address of the page from which the User accessed the Website;
browser type and version;
device type;
operating system;
browser language;
session identifier;
Cookies;
information about actions performed on the Website;
technical logs and error messages;
approximate location determined from the IP address;
information about suspicious or automated activity.
4.5. Analytics data
The following data may be processed to analyze the operation of the Website:
pages viewed;
duration of the visit;
navigation sequence;
traffic source;
search queries entered on the Website;
interaction events involving interface elements;
device and browser type;
approximate region;
parameters of advertising and informational campaigns;
aggregated Website usage indicators.
4.6. Data from publicly available sources
The Website’s informational and reference Materials may include information published in official or other lawfully accessible sources, including:
first name, last name, and patronymic;
position and place of work;
professional and official biography;
information about public officials and executives of organizations;
official contact details;
photographs published by an official source;
information from public registers;
information contained in regulatory legal acts, official statements, press releases, and responses from government authorities;
links to original sources.
The Administration aims not to publish information that is unrelated to the informational purpose of the relevant publication.
5. Sources of Personal Data
Personal Data may be obtained:
directly from the User;
automatically when the User uses the Website;
from authentication services with the User’s permission;
from providers of analytical and technical services;
from official online resources of government authorities;
from publicly accessible government information systems;
from public registers and databases;
from official statements and press releases;
from regulatory legal acts;
from mass media;
from other lawfully accessible public sources.
6. Purposes of Personal Data Processing
The Administration processes Personal Data for the following purposes:
ensuring the operation of the Website;
creating and maintaining an Account;
identifying and authenticating the User;
providing access to Website functions;
saving bookmarks and User settings;
processing questions, messages, complaints, and other requests;
providing technical support;
sending subscriptions, notifications, and service messages;
restoring access to an Account;
ensuring the security of the Website and its Users;
detecting and preventing fraud, spam, attacks, and misuse;
maintaining technical logs;
analyzing Website traffic and usage;
improving the Website’s content, structure, and functionality;
correcting technical errors;
generating anonymized statistics;
publishing and updating informational and reference Materials;
verifying, correcting, and updating information obtained from public sources;
complying with the laws of the Republic of Kazakhstan;
protecting the rights and legitimate interests of the Administration, Users, and third parties;
reviewing requests from authorized government authorities;
resolving disputes and establishing, exercising, or defending legal claims.
Personal Data must not be processed in a volume that is excessive in relation to the stated purposes.
7. Legal Grounds for Processing Personal Data
Personal Data may be processed on the basis of:
the User’s consent;
the need to perform the User Agreement;
actions performed at the User’s request;
the requirements of the laws of the Republic of Kazakhstan;
the need to fulfil the obligations of the owner or operator of Personal Data;
the need to protect the rights and legitimate interests of the Administration, Users, or third parties, where permitted by law;
other grounds provided by the laws of the Republic of Kazakhstan.
Where processing is based on consent, the User may withdraw that consent unless such withdrawal is prohibited by law or another lawful basis exists for continuing the processing.
Withdrawal of consent does not affect the lawfulness of processing carried out before the Administration received the withdrawal request.
8. User Consent
8.1. Consent to the collection and processing of Personal Data may be provided through:
selecting the relevant checkbox;
submitting a form;
registering an Account;
changing profile settings;
subscribing to notifications;
connecting a third-party authentication service;
submitting an electronic request;
another action that clearly confirms the User’s intention, where such a method is permitted by law.
8.2. Before consent is provided, the User must be given access to information about the purposes of processing and this Policy.
8.3. The User confirms that the Personal Data they provide belongs to them or that they have a lawful basis for providing it.
8.4. The User must not submit Personal Data of third parties through the Website without their consent or another lawful basis.
8.5. Consent to informational and advertising communications is provided separately and may be withdrawn at any time.
9. Cookies
9.1. The Website may use Cookies and similar technologies for the following purposes:
maintaining the User’s session;
saving language and other settings;
authenticating the User;
protecting against fraud and technical attacks;
distributing server load;
analyzing Website traffic;
evaluating the effectiveness of the interface and Materials;
remembering the User’s consent preferences;
displaying and measuring the effectiveness of advertising, where applicable.
9.2. The Website may use the following categories of Cookies:
Strictly necessary Cookies ensure the basic operation of the Website, security, authentication, and session maintenance.
Functional Cookies save the User’s language, interface settings, and preferences.
Analytics Cookies help assess Website traffic and usage.
Advertising Cookies may be used to display advertisements, limit their frequency, and evaluate their effectiveness.
9.3. The User may delete or restrict Cookies through their browser settings.
9.4. Disabling strictly necessary Cookies may cause certain Website functions to operate incorrectly.
9.5. Where consent is required for a particular category of Cookies, those Cookies will be activated only after the relevant consent has been obtained.
10. Analytics Systems and Third-Party Technologies
10.1. Third-party services may be used to analyze Website traffic, ensure security, and improve the Website, including:
web analytics systems;
error-monitoring systems;
content delivery networks;
systems for protection against automated requests and attacks;
email and notification services;
authentication services;
advertising systems.
10.2. In particular, the Website may use Google Analytics, Google Tag Manager, Cloudflare, and other services connected by the Administration.
10.3. Such services may receive technical information, Cookies, device identifiers, IP addresses, and information about the User’s interaction with the Website.
10.4. Third-party providers process information in accordance with their own terms and privacy policies.
10.5. Where possible, the Administration limits the amount of data transmitted and uses settings intended to improve User privacy.
11. Personal Data Processing Procedures
The Administration may perform the following actions involving Personal Data:
collection;
recording;
organization;
accumulation;
storage;
verification and updating;
amendment and supplementation;
retrieval;
use;
anonymization;
blocking;
transfer in the cases provided by this Policy;
deletion;
destruction.
Processing may be carried out by automated, non-automated, or combined means.
The Administration does not make decisions that produce legal consequences for the User solely on the basis of automated data processing unless otherwise expressly permitted by law and the User has been properly informed.
12. Transfer of Personal Data to Third Parties
12.1. The Administration does not sell Users’ Personal Data.
12.2. Personal Data may be transferred to third parties only to the extent necessary for a specific purpose, including to:
hosting and server infrastructure providers;
cloud and backup service providers;
content delivery and attack-protection services;
web analytics providers;
email and notification providers;
authentication services;
technical contractors and developers;
consultants, auditors, and legal representatives;
authorized government authorities;
other persons where required or permitted by law.
12.3. Persons granted access to Personal Data for the purpose of providing services to the Administration must use it only for agreed purposes and comply with confidentiality and security requirements.
12.4. The Administration may disclose data without the User’s consent where such disclosure:
is expressly required by law;
is necessary to comply with a lawful request from an authorized authority;
is necessary to protect the life, health, rights, or legitimate interests of the User or other persons;
is necessary to prevent fraud, a security breach, or unlawful activity;
is permitted on another basis established by the laws of the Republic of Kazakhstan.
12.5. If the Website Owner changes or the project is transferred to another person, Personal Data may be transferred to a legal successor, provided that the purposes of processing and data-protection requirements are preserved.
13. Cross-Border Data Transfers
13.1. The use of certain analytics, cloud, email, advertising, or technical services may involve the transfer of certain data outside the Republic of Kazakhstan.
13.2. Cross-border transfers are carried out only where there is a lawful basis and in compliance with the requirements of the laws of the Republic of Kazakhstan.
13.3. Before transferring data, the Administration takes reasonable measures to assess the necessity of the transfer, the amount of data involved, and the conditions of its protection.
13.4. Where separate User consent is required for a cross-border transfer, it will be requested before such transfer takes place.
13.5. The User may refuse to provide separate consent; however, certain functions dependent on the relevant service may then be unavailable.
14. Location and Retention Periods
Infrastructure Location and Use of Cloudflare
The Website’s primary database containing Users’ Personal Data is hosted on the server infrastructure of Internet Company PS LLP (ТОО «Интернет-компания PS») in the kz-ast-1 data center located in Astana, Republic of Kazakhstan.
Cloudflare infrastructure is used to protect the Website against network attacks, filter malicious traffic, improve availability, and accelerate content delivery.
When a User accesses the Website, Cloudflare may process the User’s IP address, information about the request, browser, device, traffic routing, security events, and other technical data necessary to provide the relevant services.
Certain technical data may be processed through Cloudflare infrastructure outside the Republic of Kazakhstan. However, the Website’s primary database intended for storing Users’ Personal Data is located within the territory of the Republic of Kazakhstan.
14.1. Personal Data is retained no longer than necessary for the purposes for which it is processed, unless a longer retention period is required by law, an agreement, or the need to establish, exercise, or defend legal claims.
14.2. When determining retention periods, the following factors are taken into account:
the purpose of processing;
the nature of the data;
the duration of Account use;
the existence of an active subscription;
the need to review a request;
the applicable periods for establishing and defending legal claims;
accounting, tax, and other legal requirements;
information security requirements.
14.3. Account data may be retained for the entire period during which the Account exists.
14.4. After an Account is deleted, the relevant data will be deleted, anonymized, or blocked unless continued retention is required by law or another lawful basis.
14.5. Technical logs and backup copies may temporarily retain certain data until the applicable update and deletion cycle is completed.
14.6. Information obtained from publicly available sources and published in the Website’s informational Materials may be retained until it becomes outdated, is removed from the original source, a justified request is satisfied, or the lawful basis for its processing ceases to apply.
15. Protection of Personal Data
15.1. The Administration takes necessary legal, organizational, and technical measures to protect Personal Data against:
unlawful or accidental access;
alteration;
copying;
distribution;
blocking;
deletion;
destruction;
loss;
other unlawful actions.
15.2. Security measures may include:
access-control restrictions;
use of individual Accounts for employees and contractors;
use of secure HTTPS connections;
password hashing;
protection of servers and databases;
backup procedures;
access and error logging;
software updates;
request-rate limitations;
use of attack-protection systems;
control over access to administrative functions;
internal Personal Data handling rules;
termination of access when the relevant authority or duties end.
15.3. Access to Personal Data is granted only to persons who require it to perform their duties.
15.4. Despite the measures taken, no method of transmitting or storing information can guarantee absolute security.
15.5. If a security breach is identified, the Administration takes measures to limit its consequences, restore security, and fulfil any obligations imposed by law.
16. User Rights
The User or their legal representative may, in accordance with the procedure established by law:
obtain confirmation as to whether the Administration holds their Personal Data;
receive information about the purposes, methods, and periods of processing;
receive information about the sources from which the data was obtained;
request access to their Personal Data;
request the correction or supplementation of inaccurate or incomplete data;
request the blocking of data where lawful grounds exist;
request the termination of processing;
request the deletion or destruction of data where lawful grounds exist;
withdraw previously provided consent;
unsubscribe from informational and advertising communications;
submit a request to correct published information;
receive a reasoned response to a request;
protect their rights and legitimate interests;
challenge the actions or inaction of the Administration in accordance with the laws of the Republic of Kazakhstan.
The exercise of certain rights may be restricted where continued processing is required by law or is carried out on another lawful basis.
17. Procedure for Submitting Requests
17.1. To exercise their rights, the User may submit a request to:
17.2. The request should preferably include:
first name, last name, and patronymic;
contact email address;
the substance of the request;
a link to the relevant Website page where the request concerns published Material;
a description of the Personal Data involved;
the action requested;
information allowing the Administration to confirm the identity or authority of the applicant;
supporting documents, where necessary.
17.3. The Administration may request additional information for the purpose of:
confirming the applicant’s identity;
preventing disclosure of data to an unauthorized person;
confirming the authority of a representative;
locating the relevant data;
verifying the validity of the request.
17.4. The User should not send a copy of an identity document, an Individual Identification Number, or other excessive data unless separately requested by the Administration and identification cannot reasonably be completed through a less risky method.
17.5. Requests will be reviewed within the time limits established by the laws of the Republic of Kazakhstan.
17.6. Following review, the Administration may:
fulfil a lawful and justified request;
request additional information;
provide a reasoned refusal stating the applicable grounds.
17.7. Deletion of information from an Account does not automatically result in the deletion of Materials obtained independently from lawfully accessible public sources. Requests concerning such Materials are reviewed separately.
18. Data Relating to Minors
18.1. The Website is not specifically intended to collect Personal Data from minors.
18.2. Where required by law, minor Users should provide Personal Data with the involvement of their legal representative.
18.3. If a legal representative believes that a minor has provided data without the required consent, they may contact the Administration at [email protected].
18.4. After reviewing the request, the Administration will take the measures required by law.
19. Informational and Advertising Communications
19.1. The User will receive news, digests, updates, and advertising messages only where the relevant consent or another lawful basis exists.
19.2. The User may unsubscribe:
by using the unsubscribe link in the message;
through the Account settings;
by submitting a request to [email protected].
19.3. Unsubscribing from advertising and informational communications does not prevent the User from receiving necessary service messages relating to:
Account security;
email verification;
access recovery;
amendments to important terms;
processing of a request;
operation of a service used by the User.
20. Amendments to the Policy
20.1. The Administration may amend this Policy due to:
changes in applicable law;
development of Website functions;
connection of new services;
changes in data-processing methods;
improvement of security measures.
20.2. A new version becomes effective upon publication on the Website unless another date is specified.
20.3. The date of the latest update is stated at the beginning of the document.
20.4. Where significant changes are made, the Administration may additionally notify registered Users through the Website, the Account, or email.
20.5. Users are advised to periodically review the current version of the Policy.
21. Final Provisions
21.1. This Policy is governed by the laws of the Republic of Kazakhstan.
21.2. This Policy forms an integral part of the memleket.kz User Agreement.
21.3. If any provision of this Policy is found to be invalid, the remaining provisions will remain valid.
21.4. In the event of any discrepancy between translations of this Policy, the Russian-language version shall prevail unless otherwise required by law or provided by a separate agreement.
22. Contact Information
Owner and Operator of the Database Containing Personal Data:
Individual Entrepreneur Мұстафин Қ. Б. (Mustafin K. B.)
Individual Identification Number: 950505350297
Email: [email protected]
Website: memleket.kz