[go: up one dir, main page]

Cookie Management
We use cookies. This is necessary to improve the site and platform. More details in our policy
Accept all
Settings

Data Processing Agreement

The use of the platform involves the collection and processing of personal data. When you provide your personal data, for example, during registration or tariff payment, we process it in accordance with the Privacy Policy.

If you place information about individuals on the website, use data collection forms, request management system, tools for creating online stores, training courses, as well as connect advanced statistics analysis, you become a controller of personal data of third parties as well as the owner of a database. We process such data as a third party.

This Data Processing Agreement (hereinafter referred to as the DPA) is an integral part of the Terms of Service (hereinafter referred to as the Agreement). All terms and definitions are used in the DPA in the same meaning as in the Agreement.Terms related to the processing of personal data shall be interpreted as provided for by the legislation of the Republic of Kazakhstan.
1. General Terms of Processing
1.1. Subject Matter. In order to fulfill the obligations under the Agreement, the User entrusts, and the Administration undertakes to process personal data of third parties collected or otherwise processed through the functionality of the Platform in the following scope:

Purpose

Categories of Personal Data

Posting information about individuals on Projects

The list is determined by the User independently based on the Platform’s functionalities and is not controlled by the Administration

Using data collection forms, Tilda CRM, creation of online stores and training courses through the Personal Account, shopping cart, payment systems and/or delivery services on the Projects

Depending on the functionality used and its settings, the personal data processed may include: name, e-mail address, phone number, address, last 4 digits of the bank card, expiry date of the bank card, information about orders, order history, information about purchased goods. Any other list is determined by the User independently based on the Platform’s functionalities and is not controlled by the Administration

Using internal statistics of Projects on the Platform provided that the simplified mode in the Project settings has been disabled by the Use

Redirection sources, IP, including country and city by IP. Statistics cookies previous URL, tildasid and tildauid, TILDAUTM

Integration with Third-Party Services, including analytics and statistics services

Cookies determined by the User and the owner of the Third-Party Service independently

Application of protection and security systems

IP addresses, essential cookies to protect the Project from DDoS attacks – __ddgN where N is any number, _ddgid and __ddgmark, and cookies to prevent unauthorized access


1.2. Data Processing Restrictions. The User independently assesses the lawfulness of personal data processing on the Platform, as well as the possibility of authorizing the Administration to process such data. User accepts and acknowledges that:
1) the Administration does not process biometric personal data;
2) the functional possibility of posting Content on the Projects is not intended for publishing images containing personal data, including photos of individuals and scanned copies of documents.

1.3. Actions Involving Personal Data. The Administration processes personal data by performing the following actions: collection, storage, modification, supplementation, use, dissemination, anonymization, blocking, and destruction of personal data.
2. User Responsibilities, Warranties and Representations
2.1. Organizing Personal Data Processing on the Platform. The User, being the data controller, independently organizes the processing of personal data of individuals on the Platform. The User determines the purposes and grounds for processing personal data, its composition, list of actions and operations to be performed.

2.2. Ensuring Legal Compliance. When processing personal data on the Project, the User shall independently ensure compliance with the legislation of the Republic of Kazakhstan. In particular, the User without the Administration involved:
1) establishes the procedure for collecting consents to the processing of personal data on the Project, including the use of data collection forms and/or analytics services;
2) publishes a document on the Project defining the personal data processing procedure;
3) appoints responsible persons and develops a set of internal documents regulating data processing.

2.3. Obtaining Consent for Processing. By processing personal data on the Platform, the User represents and warrants that they have obtained the consents of the subjects or other legal ground for processing the data and its transfer to the Administration under the DPA.

At the request of the Administration sent to the User's e-mail address specified in the Account, the User undertakes to provide documents confirming the existence of legal grounds for processing within 24 hours of receipt of the request.

2.4. Cross-Border Transfer. When using the Platform’s functionality, cross-border transfer of personal data of third parties may occur, in particular, when:
1) changing the User’s profile country;
2) granting access to a Project to a User whose profile country is any country other than the Republic of Kazakhstan;
3) transferring a Project to the Account of a User whose profile country is any country other than the Republic of Kazakhstan.

The User undertakes to independently ensure that there is a legal basis for cross-border transfer and ensure that such transfer complies with the legislation of the Republic of Kazakhstan.
2. User Responsibilities, Warranties and Representations
3.1. Storage of Personal Data. In accordance with the requirements of the law, the Administration stores personal data in databases hosted on the technical facilities of Internet Company PS LLP and SSR LLP, located in the Republic of Kazakhstan.

To ensure the preservation and restoration of data in case of loss, the Administration may store personal data on other servers, including those of Hetzner Online GmbH.

3.2. Transfer of Data to Third Parties. The Administration is entitled to fulfill the DPA both independently and by involving third parties, and remains responsible to the User for the proper fulfillment of obligations.

The Administration transfers Personal Data to Internet Company PS LLP and SSR LLP for the purpose of ensuring the storage of Personal Data in databases hosted on technical facilities located in the Republic of Kazakhstan.

An agreement has been concluded between the Administration and Tilda Platform Cloud Services Co. LLC, ensuring the lawful transfer of Personal Data to Hetzner Online GmbH for the purpose of hosting data on servers.

The Administration shall be also entitled to transfer personal data to third parties if such transfer is necessary to fulfill obligations provided for by the Agreement, is stipulated by international or national legislation, or occurs within the framework of assignment, transfer of debt and/or in the order of legal succession.
4. Connecting Third-Party Services
4.1. Data Processing with Third-Party Services. When using the Platform, the User may be offered to connect Third-Party Services that collect or otherwise process personal data, including data collection services, payment systems and/or delivery services.

Data processing by Third-Party Services is performed by their owners acting independently of the Administration and not acting in the name of and/or on behalf of the Administration. The Administration is not responsible for processing of personal data by owners of Third-Party Services.

4.2. Lawfulness of Processing. The User undertakes to independently ensure the lawfulness of personal data processing when connecting Third-Party Services, including issue of separate agreements for processing with their owners and organizing the processing using databases located in the territory of the Republic of Kazakhstan.
5. Privacy and Security
5.1. Privacy and Security. The Administration undertakes to ensure privacy of personal data and their security in accordance with the legislation of the Republic of Kazakhstan, including, but not limited to:
1) identifying business processes that contain personal data;
2) appointing a person responsible for organizing personal data processing;
3) defining the list of persons who collect and process Personal Data or have access to them;
4) establishing procedures for accessing personal data;
5) ensuring the installation of information security tools and software updates on technical systems that process personal data;
6) ensuring the transfer of personal data to other parties via secure communication channels or through encryption;
7) ensuring the use of cryptographic protection tools for the reliable storage of restricted-access personal data;
8) using identification and/or authentication tools when working with restricted-access personal data;
9) applying backup technologies.

5.2. Providing Information to the User. At the User’s request during the validity period of the DPA, the Administration shall provide documents and other information confirming the measures taken and their observance in order to fulfill the DPA. Such requests may be sent by the User no more than once every 3 months.

5.3. Security Breach. In case of a violation of the security of personal data, the Administration is obliged to notify the User within 1 business day from the moment of detection of such an incident, indicating the measures taken to eliminate the violation.

6. Achievement of the Purposes and Destruction of Personal Data
6.1. Ensuring the Rights of Subjects. The User undertakes to process personal data on the Platform until the processing purposes are fulfilled. If the consent to personal data processing is withdrawn, or the grounds allowing such processing are terminated, the User shall independently ensure the destruction of personal data.

6.2. Procedure for Personal Data Destruction. Upon receipt of a separate request of the User, the Administration undertakes to destroy personal data of third parties received from the User.

The Administration also destroys personal data if the period of their storage, established on the Platform or determined by the User itself, expires. In particular, when data collection forms are used on the Project, the data retention period is set through the relevant Project settings.

6.3. Blocks and Restrictions on the Platform. In case of violation or reasonable suspicion that the User has violated the Agreement and/or the applicable legislation, the Administration shall be entitled to block the User's account, as well as take other measures provided for by the Agreement.

The User understands and acknowledges that if the Administration takes administrative measures, the personal data processed under the DPA may be destroyed without the possibility of subsequent recovery.
7. Liability, Compensation for Losses
7.1. Liability of the Administration. The Administration is responsible for the execution of the DPA to the User. In this regard, the liability of the Administration cannot exceed the amount of the cost of the Plan paid by the User and valid during the period of occurrence of events that are the basis for the emergence of property liability of the Administration.

The Administration shall not be responsible for the actions of the User when processing personal data on the Platform. Any claims, demands or complaints of third parties related to the processing of their personal data should be resolved directly by the User without the Administration involved.

7.2. User’s Responsibility and Compensation for Losses. The User, being the data controller and owner of the database the legislation of the Republic of Kazakhstan, is individually responsible to the subjects of personal data for the lawfulness of personal data processing.

In the event that a judicial and/or administrative case is initiated against the Administration, a lawsuit is brought, or a claim is made from any party due to the User’s violation of the personal data processing procedure, the User is obliged to compensate the Administration for all losses, including, reasonable legal expenses..
Made on
Tilda