Personal Data Processing Policy1. General ProvisionsThis Personal Data Processing Policy regulates the processing of personal data by the website watchexp.org (hereinafter referred to as the "Operator").
1.1. The Operator's primary goal and condition for conducting its activities is to respect human rights and freedoms when processing personal data, including protecting the right to privacy and personal and family secrets.
1.2. This Personal Data Processing Policy (the "Policy") applies to all information that the Operator may receive about visitors to the website
https://watchexp.org.
2. Key Terms Used in the Policy2.1. Automated Personal Data Processing — processing of personal data using computer technology.
2.2. Blocking of Personal Data — temporary cessation of personal data processing (except in cases where processing is necessary to clarify personal data).
2.3. Website — a collection of graphical and informational materials, as well as software and databases, making them available on the internet at
https://watchexp.org.
2.4. Information System of Personal Data — a set of personal data contained in databases and the technologies and technical means ensuring their processing.
2.5. Anonymization of Personal Data — actions resulting in the inability to determine without additional information the personal data belonging to a specific User or other personal data subject.
2.6. Personal Data Processing — any action (operation) or set of actions (operations) performed with or without automation tools on personal data, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), retrieval, use, transfer (distribution, provision, access), anonymization, blocking, deletion, and destruction of personal data.
2.7. Operator — a government authority, municipal authority, legal entity, or individual, independently or jointly with others, organizing and/or performing personal data processing and determining the purposes of personal data processing, the composition of personal data to be processed, and the actions (operations) performed with personal data.
2.8. Personal Data — any information directly or indirectly related to a specific or identifiable User of the website
https://watchexp.org.
2.9. Personal Data Allowed for Distribution by the Data Subject — personal data to which unrestricted access has been granted by the data subject through consent for processing personal data permitted for distribution according to the Data Protection Law (hereinafter — personal data allowed for distribution).
2.10. User — any visitor to the website
https://watchexp.org.
2.11. Provision of Personal Data — actions aimed at disclosing personal data to a specific person or group of people.
2.12. Distribution of Personal Data — any actions aimed at disclosing personal data to an unspecified group of people (transferring personal data) or making personal data accessible to an unlimited number of people, including publication in mass media, placement in information and telecommunication networks, or providing access to personal data in any other way.
2.13. Cross-Border Transfer of Personal Data — transfer of personal data to the territory of a foreign state to a foreign authority, foreign individual, or foreign legal entity.
2.14. Destruction of Personal Data — any actions resulting in the irreversible destruction of personal data with the inability to restore the contents of personal data in the personal data information system and/or the destruction of physical carriers of personal data.
3. Key Rights and Obligations of the Operator3.1. The Operator has the right to:
- Receive accurate information and/or documents containing personal data from the data subject;
- Continue processing personal data without the data subject’s consent if the data subject withdraws consent or requests cessation of personal data processing, provided there are grounds specified in the Data Protection Law;
- Independently determine the composition and list of measures necessary and sufficient to ensure compliance with the Data Protection Law and the regulations adopted in accordance with it, unless otherwise provided by the Data Protection Law or other laws.
3.2. The Operator is obliged to:
- Provide the data subject with information regarding the processing of their personal data upon request;
- Organize the processing of personal data in accordance with the legislation of the Republic of Kazakhstan;
- Respond to requests and inquiries from data subjects and their legal representatives in accordance with the requirements of the Data Protection Law;
- Report to the authorized body for protection of data subjects' rights upon request of this body, providing the necessary information within 10 days from the date of such a request;
- Publish or otherwise ensure unrestricted access to this Personal Data Processing Policy;
- Implement legal, organizational, and technical measures to protect personal data from unauthorized or accidental access, destruction, alteration, blocking, copying, provision, distribution, and other unlawful actions regarding personal data;
- Cease the transfer (distribution, provision, access) of personal data, stop processing, and destroy personal data as provided by the Data Protection Law;
- Fulfill other obligations provided by the Data Protection Law.
4. Key Rights and Obligations of Data Subjects4.1. Data subjects have the right to:
- Receive information regarding the processing of their personal data, except in cases provided by law. Information is provided by the Operator in an accessible form and must not contain personal data related to other data subjects unless there are legal grounds for disclosing such personal data. The list of information and the procedure for obtaining it are established by the Data Protection Law;
- Request the Operator to clarify, block, or destroy their personal data if it is incomplete, outdated, inaccurate, illegally obtained, or unnecessary for the stated purpose of processing, and take legal measures to protect their rights;
- Condition the processing of their personal data on prior consent for the purpose of marketing goods, works, and services;
- Withdraw consent for personal data processing and request cessation of personal data processing;
- Challenge unlawful actions or inactions of the Operator in processing their personal data with the authorized body for data subjects' rights protection or in court;
- Exercise other rights provided by the legislation of the Republic of Kazakhstan.
4.2. Data subjects are obliged to:
- Provide the Operator with accurate data about themselves;
- Notify the Operator of any updates (changes) to their personal data.
4.3. Individuals who provided the Operator with inaccurate information about themselves or about another data subject without their consent are liable according to the legislation of the Republic of Kazakhstan.
5. Principles of Personal Data Processing5.1. Personal data processing is carried out on a lawful and fair basis.
5.2. Personal data processing is limited to achieving specific, predetermined, and lawful purposes. Processing of personal data that is incompatible with the purposes of collection is not allowed.
5.3. It is not allowed to combine databases containing personal data processed for incompatible purposes.
5.4. Only personal data that meets the purposes of processing is processed.
5.5. The content and volume of processed personal data correspond to the stated purposes of processing. Excessive processing of personal data in relation to the stated purposes is not allowed.
5.6. Personal data processing ensures the accuracy, adequacy, and, where necessary, relevance of personal data concerning the purposes of processing. The Operator takes necessary measures and/or ensures their implementation to remove or correct incomplete or inaccurate data.
5.7. Personal data is stored in a form that allows identifying the data subject no longer than is necessary for the purposes of processing, unless otherwise provided by law, contract, or any other legal agreements with the data subject. Processed personal data is destroyed or anonymized upon achieving the processing purposes or when there is no longer a need to achieve those purposes, unless otherwise provided by the legislation of the Republic of Kazakhstan.
6. Purpose of Processing- Informing the User via email.
Personal Data:- Surname, first name, patronymic
- Email address
- Phone numbers
Legal Grounds:- Law of the Republic of Kazakhstan No. 94-V of May 21, 2013, "On Personal Data and Its Protection" considering the General Data Protection Regulation (GDPR) of the European Union of April 27, 2016, other legislative acts of the Republic of Kazakhstan, and local regulatory legal acts.
Types of Personal Data Processing:- Collection, recording, systematization, accumulation, storage, destruction, and anonymization of personal data
- Sending informational emails to the email address
7. Conditions for Processing Personal Data7.1. Personal data processing is carried out with the consent of the data subject for processing their personal data.
7.2. Processing of personal data is necessary to achieve the goals defined by an international treaty of the Republic of Kazakhstan or the law, to perform functions, powers, and duties imposed on the Operator by the legislation of the Republic of Kazakhstan.
7.4. Processing of personal data is necessary to fulfill a contract to which the data subject is a party or the beneficiary or guarantor, or to enter into a contract at the data subject's initiative, or a contract where the data subject will be a beneficiary or guarantor.
7.5. Processing of personal data is necessary to achieve the rights and legitimate interests of the Operator or third parties or for public purposes provided that the rights and freedoms of the data subject are not violated.
7.6. Processing of personal data accessible to an unlimited number of people by the data subject or upon their request (hereinafter — publicly available personal data) is carried out.
7.7. Processing of personal data required for publication or mandatory disclosure according to the law of the Republic of Kazakhstan is carried out.
8. Procedures for Collecting, Storing, Transmitting, and Other Types of Personal Data ProcessingThe security of personal data processed by the Operator is ensured by implementing legal, organizational, and technical measures necessary to fully comply with the requirements of current legislation in the field of personal data protection.
8.1. The Operator ensures the safety of personal data and takes all possible measures to prevent unauthorized access to personal data.
8.2. Personal data of the User will not be transferred to third parties under any conditions, except in cases related to the enforcement of current legislation or if the data subject has consented to the Operator transferring data to third parties for fulfilling obligations under a civil law contract.
8.3. In case of identifying inaccuracies in personal data, the User can update it independently by sending a notification to the Operator's email address
[email protected] with the subject "Updating Personal Data."
8.4. The processing period of personal data is determined by achieving the purposes for which the personal data was collected unless a different period is specified by the contract or current legislation. The User can withdraw their consent for processing personal data at any time by sending a notification to the Operator’s email address
[email protected] with the subject "Withdrawal of Consent for Processing Personal Data."
8.5. Information collected by third-party services, including payment systems, communication tools, and other service providers, is stored and processed by these entities (Operators) in accordance with their User Agreement and Privacy Policy. The Operator is not responsible for the actions of third parties, including those mentioned in this clause.
8.6. Restrictions set by the data subject on the transfer (except for access provision), as well as on processing or processing conditions (except for access), of personal data allowed for distribution do not apply to cases of personal data processing in state, public, and other public interests as defined by the legislation of the Republic of Kazakhstan.
8.7. The Operator ensures the confidentiality of personal data during processing.
8.8. The Operator stores personal data in a form that allows identifying the data subject no longer than is necessary for the purposes of processing, unless the storage period is established by law, contract, or any other legal agreements with the data subject.
8.9. Conditions for stopping personal data processing may include achieving the processing purposes, expiration of the data subject’s consent, withdrawal of consent by the data subject, or a requirement to stop processing personal data, as well as identification of unlawful processing of personal data.
9. Actions Performed by the Operator with Received Personal Data9.1. The Operator performs collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), anonymization, blocking, deletion, and destruction of personal data.
9.2. The Operator performs automated processing of personal data with or without receiving and/or transmitting the obtained information through information and telecommunication networks.
10. Cross-Border Transfer of Personal Data10.1. The Operator must notify the authorized body for protection of data subjects' rights of its intention to carry out cross-border transfer of personal data (this notification is submitted separately from the notification of intent to process personal data).
10.2. Before submitting the above-mentioned notification, the Operator must obtain the relevant information from the authorities of the foreign state, foreign individuals, or foreign legal entities to whom the cross-border transfer of personal data is planned.
11. Confidentiality of Personal DataThe Operator and other persons who have gained access to personal data must not disclose or distribute personal data to third parties without the consent of the data subject unless otherwise provided by law.
12. Final Provisions12.1. The User can obtain any clarifications on issues related to the processing of their personal data by contacting the Operator via email at
[email protected].
12.2. This document will reflect any changes in the Operator’s Personal Data Processing Policy. The Policy is effective indefinitely until replaced by a new version.