Top.Mail.Ru

Privacy Policy

regarding the processing of personal data

Websites: https://on1xcloud.com/ · https://on1x.kz/


Legal basis: the Civil Code of the Republic of Kazakhstan, the Law of the Republic of Kazakhstan “On Consumer Rights Protection” (to the extent applicable), the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”, the Digital Code of the Republic of Kazakhstan, and other applicable regulatory legal acts of the Republic of Kazakhstan.

Purpose of the document: to inform data subjects about the collection, processing, storage, and protection of personal data when using the websites, Personal Account, and ON1X Cloud services.

1. Operator and Scope

1.1. The personal-data operator is ON1X CLOUD LLP, operating under the ON1X Cloud brand. Until the required details have been completed, the Policy must not be published as final.

1.2. This Policy applies to the websites on1xcloud.com and on1x.kz, the Personal Account at my.on1x.cloud, support requests, payments, contractual relations, and other interactions with the Operator.

1.3. A data subject may contact [email protected] regarding personal data. Security incidents and data breaches must also be reported to [email protected].

1.4. This Policy does not govern Content independently hosted by the Client on a VPS, except in limited cases of technical access by the Operator. With respect to such Content, the Client is generally the independent owner and/or operator of personal data.

2. Processing Principles

  • lawfulness, fairness, and transparency;
  • collection only of data necessary and sufficient for predetermined purposes;
  • limitation of retention to achievement of the purposes or mandatory periods established by law;
  • accuracy and the possibility of updating;
  • confidentiality, integrity, and availability;
  • separation of the Operator’s Account data from the Client’s Content.

3. Categories of Data Subjects and Data

3.1. The Operator may process data relating to Clients, their representatives, website visitors, Account users, payers, complainants, and persons identified in communications.

3.2. Depending on the interaction, the following data may be processed:

  • full name, organisation name, position, and information on authority;
  • BIN/IIN and identity-document details only where necessary for an agreement, payment, accounting, anti-fraud checks, or compliance with law;
  • e-mail address, telephone number, address, and other contact details;
  • Account identifier, login, password hash, security settings, and activity history;
  • data on Orders, tariffs, invoices, payments, and refunds; the Operator does not store full bank-card details where payment is processed by an independent payment organisation;
  • IP address, request date and time, user agent, cookies, login events, panel logs, and network metadata;
  • the content of support requests, correspondence, attachments, and records of technical actions;
  • risk-assessment results and information on complaints, blocks, and incident investigations.

3.3. The Operator does not request special categories of data or biometric data unless expressly required by law. Such data should not be sent unless necessary.

4. Sources of Data

  • directly from the data subject during registration, placement of an Order, payment, and communications;
  • from an authorised representative of an organisation;
  • from banks, payment organisations, and anti-fraud services to the extent necessary to confirm payment;
  • from technical logs of the websites, panel, and infrastructure;
  • from competent authorities and complainants;
  • from publicly available sources only where there is a lawful basis.
  • Registration and agreement — creation of an Account, identification of the Client, conclusion and performance of the Offer, and management of Orders.
  • Payment and accounting — processing of payments and refunds, issuance of invoices and other documents, and maintenance of tax and accounting records.
  • Support — processing Client requests, diagnostics, troubleshooting, and administration on the Client’s instructions.
  • Security — protection of Accounts and infrastructure, prevention of fraud, spam, DDoS attacks, and malicious activity, and investigation of incidents.
  • Legal obligations — compliance with legal requirements, responses to lawful requests from public authorities, claims handling, and protection of the rights and legitimate interests of the Operator and third parties.
  • Communications — sending service notices and notifications of changes to Tariffs and documents. Marketing messages are sent only where the required consent has been obtained and an opt-out option is available.
  • Analytics — processing of anonymised statistics to improve the website, infrastructure, and quality of the Services.

5.1. The legal bases include the data subject’s consent, the necessity of entering into and performing an agreement, compliance with legal obligations, protection of legitimate interests to the extent permitted by law, and other bases provided by law.

6.1. Consent may be given by ticking a box in the interface, confirmation by e-mail or telephone, signing a document, using a digital signature, or another method that makes it possible to confirm its receipt and content.

6.2. The consent wording must contain information on the purposes, categories of data, possible disclosure to third parties, cross-border transfer, duration, and withdrawal procedure to the extent required by law.

6.3. A data subject may withdraw consent by sending a request to [email protected]. Withdrawal does not affect the lawfulness of prior processing and does not terminate processing necessary for compliance with law, performance of an agreement, or protection of rights.

7. Storage in the Republic of Kazakhstan

7.1. Accumulation and storage of the Operator’s Account personal data are carried out in a database located in the Republic of Kazakhstan in accordance with the law.

8. Cross-Border Transfer and Foreign Infrastructure

8.1. Certain suppliers, payment organisations, communications tools, and data centres may be located outside the Republic of Kazakhstan. Personal data is transferred abroad only where there is a legal basis and adequate protection as required by law.

8.2. If a country does not provide the required level of protection, the Operator obtains the data subject’s consent to the cross-border transfer or relies on another basis expressly provided by law.

8.3. A VPS may be located in countries selected by the Client. The Client’s placement of third-party personal data on such a VPS is an action of the Client; the Client must ensure the lawfulness of the cross-border transfer and inform the data subjects.

8.4. The Operator does not use the Client’s Content for its own purposes and accesses it only to the minimum extent necessary for support upon request, prevention of threats, compliance with law, or protection of rights.

9. Disclosure to Third Parties

9.1. Data may be disclosed to:

  • data centres and cloud and infrastructure contractors;
  • banks, payment organisations, accountants, and auditors;
  • providers of e-mail, SMS, ticketing systems, and analytics;
  • lawyers, insurers, and consultants subject to confidentiality obligations;
  • competent authorities on the basis and within the scope of a lawful request;
  • a successor in the event of reorganisation or sale of the business, subject to continued data-protection obligations.

9.2. Where required and applicable, the Operator concludes agreements with contractors that provide for confidentiality, purpose limitation, and protective measures.

10. Cookies and Analytics

10.1. The websites use necessary cookies for login, security, language settings, and the shopping cart. Analytics and marketing cookies are used subject to legal requirements and consent settings.

10.2. A User may restrict cookies in the browser, but certain Personal Account functions may stop working.

11. Retention Periods

  • Account data — for the duration of the agreement, unless a longer period is required by law;
  • financial and accounting documents — for the periods established by the laws of the Republic of Kazakhstan;
  • tickets and correspondence — for the periods established by the laws of the Republic of Kazakhstan;
  • security logs — for the periods established by the laws of the Republic of Kazakhstan;
  • marketing data — until consent is withdrawn or the purpose is achieved;
  • VPS Content — until termination of the Service and expiry of the technical deletion period specified in the Offer.

11.1. At the end of the retention period, data is deleted, destroyed, or anonymised unless there is a lawful basis for further retention.

12. Security Measures and Incidents

12.1. The Operator implements legal, organisational, and technical measures proportionate to the risks, including access controls, multi-factor authentication, encryption of communications, redundancy, logging, updates, antivirus and network protection, staff training, and confidentiality agreements.

12.2. Access is granted only to persons who need it for their work and is reviewed regularly.

12.3. In the event of a security breach, the Operator records the incident, limits its consequences, restores security, and fulfils notification obligations to data subjects and authorities where required by law.

13. Rights of the Data Subject

13.1. In the manner established by law, a data subject has the right to:

  • obtain information on whether and how their data is processed;
  • demand correction, supplementation, blocking, or destruction of unlawfully processed data;
  • object to marketing communications;
  • challenge the Operator’s actions before the authorised body or a court.

13.2. To protect data, the Operator may verify the applicant’s identity. A response is provided within the periods established by law.

14. Minors

14.1. Independent registration and ordering of paid Services are permitted for persons who possess the required legal capacity. Participation of a legal representative is required for a minor where provided by law.

14.2. If improperly collected data of a minor is identified, the Operator takes steps to delete it or obtain an appropriate legal basis.

15. Amendments to the Policy

15.1. The current version is published on on1xcloud.com and on1x.kz. Material amendments affecting the purposes or scope of processing are communicated to users and, where required, accompanied by renewed consent.

15.2. The new version applies from the stated date and does not legalise processing carried out without a proper legal basis before its publication.

Contacts