> This translation is provided for convenience only. The legally binding version is the Russian text; in case of any discrepancy, the Russian version prevails.
Edition of 31 August 2026
Effective date: 31 August 2026
This Privacy and Personal Data Processing Policy (the "Policy") explains what information the ADVIN digital platform collects and processes, for what purposes, to whom it may be transferred, and how a User may exercise their rights.
The Policy applies together with the ADVIN User Agreement, the Consent to the Collection and Processing of Personal Data, and other specific documents relating to particular features of the Platform.
1. Owner and operator of personal data
1.1. The owner and operator of the database containing the personal data of ADVIN Users is:
Smart Advertising Systems Limited Liability Partnership
BIN: 260640021998
Registered address: Republic of Kazakhstan, Astana, Syganak street, building 47, floor 8, office 16, postal code 010000
Email for personal data matters: privacy@advin.kz
Phone: +7 707 108 68 93
Official website: https://advin.kz
1.2. In this Policy, Smart Advertising Systems LLP is also referred to as the "Administration", "we" or the "Operator".
1.3. The person responsible for organising the processing of personal data: the director of the LLP; contact: privacy@advin.kz. The full name of the responsible person is not publicly disclosed; enquiries are accepted through the operating official channel.
2. Scope and key concepts
2.1. The Policy applies to the ADVIN website, web application, mobile applications, administrative panel and other official interfaces.
2.2. The terms "Platform", "Account", "User", "Customer", "Provider", "Designer", "Order", "Response", "Response Chat", "Working Chat", "Content", "Profile Verification" and "AI Features" are used with the meanings given in the User Agreement.
2.3. The Policy applies to the personal data of natural persons, including Users, representatives of legal entities and sole traders, as well as persons whose details have been lawfully submitted by a User in materials on the Platform.
2.4. Information about a legal entity is not in itself personal data; however, data concerning its director, employee, representative, a sole trader or another natural person is protected to the extent provided by law.
3. Principles and grounds for processing
3.1. The Administration processes data lawfully, in good faith and proportionately to predetermined purposes, and does not collect information that is objectively unnecessary for the operation of ADVIN.
3.2. The principal grounds for processing are:
- the data subject's consent, obtained in a manner allowing its provision to be confirmed;
- acceptance and performance of the User Agreement and other contracts with the User;
- fulfilment of obligations expressly provided for by the legislation of the Republic of Kazakhstan;
- protection of the rights and legitimate interests of the Administration and other persons, within the limits permitted by law;
- other grounds provided for by the legislation of the Republic of Kazakhstan.
3.3. Where the law requires special, separate or additional consent for a particular operation, that operation is not carried out on the basis of registration or acceptance of the User Agreement alone.
3.4. The Administration approves and maintains an internal list of personal data that is necessary and sufficient for each processing task.
4. What data we process
4.1. Registration and identification data
- surname, first name and patronymic, if stated in the identity document;
- email address;
- the role selected;
- Account identifier;
- information confirming the email;
- authorisation data and protected technical identifiers;
- where sign-in is via Google or Apple — the identifier, email, name and other information actually transferred by the selected service within the scope of the User's permission.
The password is stored as a cryptographically protected value. The Administration must not store passwords in clear text.
4.2. Profile data
- personal or brand name;
- name of the LLP or sole trader;
- city and region of operation;
- profile photograph or logo;
- description of activity;
- categories of works and services;
- portfolio and information about completed work;
- rating, reviews, replies to reviews and profile status;
- contact details, which are disclosed to the selected party after the selection is confirmed;
- information about the organisation's representative and their authority.
4.3. Profile Verification data
Depending on the role, the organisational form and the reasonably necessary scope of verification, the Administration may process:
- the IIN of a natural person or sole trader;
- the BIN of a legal entity;
- information on the state registration of a legal entity;
- a notification, receipt or other document evidencing registration of a sole trader;
- an identity document or the information contained in it, where it is otherwise impossible to reliably identify the applicant by a means permitted by law;
- information about the director or representative;
- an order, resolution, power of attorney or other document evidencing authority;
- licences, permits, certificates and documents relating to the declared activity;
- the source, date, outcome and scope of the verification carried out;
- information about discrepancies identified, re-verification and the decision on the profile status.
The Administration does not use the facial image from an identity document for biometric identification unless such a feature is separately implemented on a lawful basis and disclosed to the User in advance.
4.4. Order and interaction data
- the description of the Order, city, deadlines, the price offered by the Customer (in the interface, "Your price") and technical parameters;
- photographs, logos, layouts, technical specifications and other files;
- Responses, Proposals, questions and messages;
- the history of Response Chats and Working Chats;
- information confirming the selected Provider or Designer;
- Order and chat statuses, and the date and time of actions;
- complaints, reviews, ratings and case materials.
Users must not submit through ADVIN excessive personal data of third parties, state secrets, banking passwords, payment card details, medical information or other restricted information that is not required for the specific feature.
4.5. Subscription and settlement data with ADVIN
Once paid subscriptions are enabled, the Administration may process the selected plan, period, amount, currency, status and payment identifier, and information for issuing documents and processing refunds. Full payment card details must be processed by the payment provider and not transferred to ADVIN unless expressly disclosed otherwise before payment.
ADVIN does not process payments between a Customer and the selected Provider or Designer.
4.6. Technical data
- IP address;
- device type, operating system, application version and language;
- session and push notification identifiers;
- date, time and duration of use;
- logs of sign-ins, requests, errors, security events and consent actions;
- cookies and similar technologies in the web version;
- diagnostic information necessary for the stability and protection of the Platform.
4.7. Support enquiries
The Administration processes the content of the enquiry, attached materials, Account information, the response history and the data necessary to verify the claimant's authority.
5. Purposes of processing
Data is processed only for one or more of the following purposes:
1. creation, confirmation, protection and maintenance of the Account;
2. identification of the User and recording of the consents given;
3. provision of the Orders, Responses, chats, selection, reviews and portfolio features;
4. disclosure of contact details only after final confirmation of the selected Provider or Designer;
5. Verification of the profile, registration details and authority;
6. provision and accounting of the Subscription;
7. sending mandatory service notifications;
8. handling of enquiries, complaints, disputes and violations;
9. prevention of fraud, circumvention of the Platform, spam and security threats;
10. moderation of Content and enforcement of the Platform Rules;
11. compliance with legal requirements and lawful requests from authorised bodies;
12. accounting and tax records of transactions with ADVIN;
13. diagnostics, error correction, and ensuring stability and information security;
14. development and improvement of features based on aggregated or anonymised information;
15. provision of an AI Feature after the conditions of section 11 have been met;
16. advertising and marketing communications — only where separate voluntary consent has been given.
6. Sources of data
6.1. The Administration obtains data:
- directly from the User;
- automatically when the Platform is used;
- from Google or Apple, where the User selects the corresponding sign-in;
- from representatives of an organisation;
- from lawfully accessible state, open and commercial sources as part of Profile Verification;
- from contractors providing technical or payment services;
- from other Users, in complaints, reviews and interaction materials;
- from authorised state bodies in the cases provided for by law.
6.2. Where information is obtained other than from the data subject, the Administration verifies that there is a lawful basis and uses it only for the stated purpose.
7. Publicly available and withheld information
7.1. After a professional profile has been expressly completed and published, the following may be shown to other Users:
- the brand name;
- the official name of the LLP or sole trader;
- the profile photograph or logo;
- the city and activity categories;
- the description and portfolio of completed work;
- the rating and reviews;
- the status and a limited description of the Profile Verification outcome.
7.2. The following are not published or made available to all Users:
- the IIN;
- the image of the identity document and its details;
- documents on registration, authority and licences, and certificates, except for information the User has separately selected for public display;
- internal Profile Verification materials;
- email, phone number and other direct contact details, until the selection is finally confirmed;
- private correspondence;
- technical logs and security information.
7.3. The BIN and certain registration details may be displayed only after this feature has been separately disclosed and where there is a lawful basis. The fact that information is public in a state source does not in itself constitute automatic consent to any re-dissemination through ADVIN.
7.4. The User selects portfolio materials themselves and confirms that they hold the rights to publish them. The use of a profile, review or portfolio in ADVIN's advertising requires separate voluntary consent.
8. Profile Verification and identity documents
8.1. Registration by email, Google or Apple does not constitute passing Profile Verification.
8.2. The Administration requests only those documents and fields that are objectively necessary for the specific level of verification. Where sufficient identification is available through integration with a state service or another less risky method, the Administration seeks not to collect a full copy of the identity document.
8.3. Before an identity document is uploaded, the interface must state the purpose, the composition of the data processed, the retention period and the available recipients. Fields not required for verification should be concealed by the User or technically masked, where this is permissible for the chosen verification method.
8.4. Access to the documents is available only to the director, or to an employee or contractor to whom the director has granted such authority, subject to a confidentiality undertaking, personal access and logging of actions.
8.5. Verification confirms only the information actually verified and is not a guarantee of the User's good faith, quality of work, or future performance of obligations.
9. Access to chats and moderation
9.1. Chats are not publicly available. Their participants, authorised employees of the Administration and engaged technical contractors have access only within the scope of their function.
9.2. An employee of the Administration may view the content of a specific conversation:
- following a complaint by a participant;
- where a technical signal is triggered regarding contact details, spam, fraud, a threat or another violation;
- where this is necessary to investigate a security incident, comply with the law, or protect the rights of Users and the Administration.
9.3. Arbitrary reading of correspondence out of curiosity or for general monitoring of employees is prohibited. Quality control is carried out primarily on anonymised or aggregated data. The use of identifiable correspondence for staff training, advertising or research requires a separate lawful basis and the necessary consent.
9.4. An automated match is not conclusive proof of a violation. A substantial sanction is applied taking into account the context and manual review, except for urgent measures to prevent harm.
10. Recipients and technical contractors
10.1. Data may be provided, to the extent necessary, to:
- the counterparty selected by the User, within the Platform's features;
- the server infrastructure and storage provider;
- providers of authorisation, email, push notifications, analytics, diagnostics, payments and AI — only after they have actually been connected and the list of recipients has been updated;
- employees and contractors of the Administration who require access for their work;
- advisers, auditors and representatives under a duty of confidentiality;
- a legal successor upon reorganisation or transfer of the Platform, in compliance with the law;
- a court, an authorised state body or another person, where the transfer is mandatory or permitted by law.
10.2. A contractor receives only the necessary volume of data, acts under a contract, applies protective measures, and may not use the information for its own incompatible purposes.
10.3. External services that are actually connected and those that are planned are recorded in the ADVIN Register of External Services. Before any transfer begins, the Register must state the exact legal entity, function, categories of data, place of processing, cross-border transfer and the conditions for launch.
10.4. An external service that is absent from the Register, or that has not been moved to "actually connected" status in it, must not receive personal data until the conditions have been verified, the applicable documents updated and, where required, additional consent obtained.
11. AI features and model training
11.1. Before materials are first transferred to an external AI provider, the interface must display the provider's name, the purpose, the list of data transferred, the state of processing, the retention period and the principal risks. Where a cross-border transfer takes place or additional consent is required, the feature is not launched until that consent is obtained.
11.2. Only the materials selected by the User and the minimum necessary technical information are transferred to the AI in order to perform a specific request. Profile Verification documents, identity documents and private chats are not transferred to AI by default.
11.3. The use of a User's materials to train or fine-tune a model does not form part of the processing that is mandatory for ADVIN to operate and is permitted only with separate voluntary consent. Refusal does not restrict ordinary registration or the Platform's core features.
11.4. Before enabling training, the Administration must determine the specific model and provider, the list of materials, the purpose, the period, whether a cross-border transfer takes place, the possibility of withdrawal, and the technical consequences of data deletion. General consent covering future unspecified providers and purposes is not used.
11.5. The following are not used for training: the IIN, the BIN in conjunction with a natural person, Profile Verification documents, identity documents, contact details, private correspondence, and third-party materials without a confirmed lawful basis.
11.6. Where possible, materials are anonymised before training. The Administration does not promise the ability to remove the influence of a specific material from an already trained model where this is technically impossible; such a risk must be clearly disclosed before separate consent is given. Until a lawful and technically manageable procedure has been implemented, training on user materials is not carried out.
11.7. AI does not make decisions without human involvement that create, alter or terminate a User's rights or legitimate interests. Should such a feature be introduced, the logic and consequences will be explained to the User before its launch, and the opportunity to object and to obtain human review will be provided in the manner prescribed by law.
12. Cross-border transfer
12.1. The main personal data database is hosted in a server facility or data centre within the territory of the Republic of Kazakhstan. ADVIN backups are not created in the current architecture. When they are introduced, copies containing personal data will be hosted within the territory of the Republic of Kazakhstan.
12.2. Resend, operated by Plus Five Five, Inc. (USA), is used to send confirmation codes and service emails. To the extent necessary, the recipient's email, their name where included in the message, the code or notification content, and information on sending and delivery are transferred to the USA. The use of other foreign services for authorisation, push notifications, analytics, diagnostics, payments or AI may likewise entail cross-border transfer. Such transfer is carried out only after verification of the lawful basis and protective conditions and after obtaining consent containing information about the existence of a cross-border transfer, where such consent is required.
12.3. Choosing to sign in via Google or Apple means using the provider selected by the User, but does not replace separate notification by ADVIN of the actual cross-border transfer.
12.4. Before each foreign service is enabled, the Register of External Services is updated to state the provider, function, categories of data, state of processing and the fact of cross-border transfer. The edition of the Register is recorded together with the User's consent.
13. Retention periods
13.1. Data is stored no longer than is necessary for the stated purposes, performance of the contract and mandatory legal requirements.
13.2. Where no special period is established by law or contract, the following indicative periods apply:
| Category | Period |
|---|---|
| Account and profile | Until the Account is deleted, then up to 30 calendar days for removal from the active system |
| Orders, Responses, selection and chats | 3 years after completion or the last activity relating to the Order |
| Reviews and rating | While the profile exists; after deletion — anonymisation or deletion, except for dispute materials |
| Original identity and verification documents | For the verification period and up to 90 calendar days after the decision; longer only in the case of re-verification, a dispute or a legal obligation |
| Record of Profile Verification without the original copy of the document | While the status is valid and 3 years after it ends |
| Complaints, violations and blocks | 3 years after the final decision, and in the case of a dispute — until it concludes |
| Technical logs | Up to 12 months, unless a longer period is needed to investigate an incident |
| Marketing consent | Until withdrawal, plus the period necessary to evidence that it was given or withdrawn |
| ADVIN's financial and accounting documents | For the period established by the legislation of the Republic of Kazakhstan |
| Backups | Not created in the current architecture; when introduced, the retention period and deletion cycle will be set before they begin to be created |
13.3. In the event of a well-founded dispute, investigation, request from a state body or security threat, the relevant information may be isolated and retained until the relevant procedure and the mandatory period have concluded.
13.4. Upon expiry of the period, data is deleted, destroyed or irreversibly anonymised.
14. Deletion of the Account
14.1. A User may initiate deletion of their Account themselves in the settings. Before deletion, the interface explains the consequences and, where necessary, confirms the identity of the owner.
14.2. Deletion of the Account ends ordinary use of the data but does not require immediate destruction of information that is necessary to perform an outstanding obligation, comply with the law, maintain accounting records, ensure security or resolve a dispute.
14.3. The public profile is hidden within a reasonable technical period. Reviews and interaction history are deleted or anonymised, taking into account the rights of other Users, the integrity of the history and mandatory retention periods.
14.4. If backups are introduced, deletion from backups will take place according to a pre-established overwrite cycle, taking into account legal requirements and incident investigations.
15. Rights of the data subject
15.1. Within the limits provided by law, the data subject has the right to:
- know whether the Administration holds their personal data;
- obtain information on the purposes, sources, methods and periods of processing;
- access their data free of charge;
- require the clarification, blocking or destruction of inaccurate, excessive or unlawfully obtained data;
- require the deletion, anonymisation or restriction of the processing of data in the digital environment, except where retention or processing is necessary on grounds provided for by the legislation of the Republic of Kazakhstan;
- withdraw consent, where withdrawal does not conflict with the law and there is no outstanding obligation preventing it;
- object to an automated decision and require human review in the applicable cases;
- opt out of marketing communications;
- apply to the authorised body or to a court.
15.2. A request is submitted through the Account settings or to privacy@advin.kz. The Administration may request reasonable confirmation of identity and authority, without collecting excessive information.
15.3. Following withdrawal of consent, the Administration ceases processing within the period established by the legislation of the Republic of Kazakhstan, unless further processing is required by law, by contract or by an outstanding obligation, or issues a reasoned refusal.
16. Marketing communications and notifications
16.1. Service messages concerning security, the Account, Orders, Responses, the selected provider, the Subscription, complaints and changes to documents are necessary for the relevant function and do not constitute marketing communications.
16.2. Marketing emails, marketing push notifications and personalised marketing offers are sent only after separate voluntary consent has been given.
16.3. Opting out of advertising must be available in the message or in the settings, and must not lead to deletion of the Account or to the disabling of mandatory service notifications.
17. Cookies, analytics and mobile identifiers
17.1. The web version may use strictly necessary cookies for sign-in, security, language and the operation of features.
17.2. Optional analytics, advertising or profiling technologies are not enabled until their list has been disclosed and consent obtained, where required.
17.3. The mobile application may use technical device identifiers and push tokens. The device advertising identifier is not collected without a separate necessity, disclosure and lawful basis.
18. Protective measures and localisation
18.1. The Administration applies organisational and technical measures appropriate to the risks and legal requirements, including:
- appointment of a responsible person;
- segregation of roles and least-privilege access;
- personal employee accounts and logging of actions;
- encryption of data transmission and secure storage of secrets;
- verification of the ability to restore operability; where backups are introduced — monitoring of their creation and restoration;
- vulnerability and update management;
- confidentiality undertakings for employees and contractors;
- incident response rules;
- periodic review of access and of the list of data processed.
18.2. The contract with the infrastructure provider must confirm that the main database is located in the Republic of Kazakhstan, the protective measures applied, and the procedures for access to, return of and destruction of data. When backups are introduced, the same requirements apply to the copies before they begin to be created.
18.3. No method of storage eliminates risk entirely. The Administration is not released from the obligation to take the measures prescribed by law and to respond to incidents in a timely manner.
19. Personal data security breaches
19.1. The Administration records and investigates the loss of, unlawful access to, alteration, disclosure or destruction of personal data.
19.2. Where a breach is identified, the Administration takes measures to contain it, preserve evidence, assess the risk and prevent recurrence.
19.3. The Administration notifies the authorised body of a personal data security breach within one business day of its discovery, providing the information prescribed by law. Affected data subjects are notified in the manner established by the legislation of the Republic of Kazakhstan. The Administration may also send them a direct notification where this is necessary to reduce risk and is not prohibited by law; such notification contains the available information on the nature of the incident, its likely consequences and the recommended actions.
20. Users under 18
20.1. ADVIN is intended for legally capable persons aged 18 and over and for duly authorised representatives of organisations.
20.2. If the Administration reasonably establishes that an Account has been created by a minor without the necessary lawful basis, access is suspended and the data is deleted or processed in accordance with the instructions of the legal representative and the requirements of the law.
21. Amendments to the Policy
21.1. The current version is published with the date of the edition. The previous version and information about its acceptance are retained to the extent necessary to evidence the processing terms.
21.2. Users are notified of material changes to the purposes, composition of data, public visibility, recipients, cross-border transfer, retention periods or AI processing before those changes are applied. Where new consent is required, continued use does not in itself replace it.
22. Applicable law and enquiries
22.1. The Policy is governed by the legislation of the Republic of Kazakhstan, including the Digital Code of the Republic of Kazakhstan, the Law of the Republic of Kazakhstan "On Personal Data and Its Protection" and the regulatory legal acts adopted pursuant to them.
22.2. Questions and requests are sent to privacy@advin.kz or to the Administration's address. A complaint may also be submitted to the authorised body or to a court.
22.3. The official versions of the Policy in Kazakh and Russian have equal force. The English version is intended for informational convenience unless expressly stated otherwise.
Annex 1. External recipients
The current list, legal entities, functions, categories of data, places of processing and cross-border transfers are set out in a separate document, the "ADVIN Register of External Services and Data Recipients". The Register is available to the User before the relevant consent is given, and its edition is recorded together with the evidence of consent.