regarding the processing of personal data
Websites: https://on1xcloud.com/ · https://on1x.kz/
Legal basis: the Civil Code of the Republic of Kazakhstan, the Law of the Republic of Kazakhstan “On Consumer Rights Protection” (to the extent applicable), the Law of the Republic of Kazakhstan “On Personal Data and Their Protection”, the Digital Code of the Republic of Kazakhstan, and other applicable regulatory legal acts of the Republic of Kazakhstan.
Purpose of the document: to inform data subjects about the collection, processing, storage, and protection of personal data when using the websites, Personal Account, and ON1X Cloud services.
1.1. The personal-data operator is ON1X CLOUD LLP, operating under the ON1X Cloud brand. Until the required details have been completed, the Policy must not be published as final.
1.2. This Policy applies to the websites on1xcloud.com and on1x.kz, the Personal Account at my.on1x.cloud, support requests, payments, contractual relations, and other interactions with the Operator.
1.3. A data subject may contact [email protected] regarding personal data. Security incidents and data breaches must also be reported to [email protected].
1.4. This Policy does not govern Content independently hosted by the Client on a VPS, except in limited cases of technical access by the Operator. With respect to such Content, the Client is generally the independent owner and/or operator of personal data.
3.1. The Operator may process data relating to Clients, their representatives, website visitors, Account users, payers, complainants, and persons identified in communications.
3.2. Depending on the interaction, the following data may be processed:
3.3. The Operator does not request special categories of data or biometric data unless expressly required by law. Such data should not be sent unless necessary.
5.1. The legal bases include the data subject’s consent, the necessity of entering into and performing an agreement, compliance with legal obligations, protection of legitimate interests to the extent permitted by law, and other bases provided by law.
6.1. Consent may be given by ticking a box in the interface, confirmation by e-mail or telephone, signing a document, using a digital signature, or another method that makes it possible to confirm its receipt and content.
6.2. The consent wording must contain information on the purposes, categories of data, possible disclosure to third parties, cross-border transfer, duration, and withdrawal procedure to the extent required by law.
6.3. A data subject may withdraw consent by sending a request to [email protected]. Withdrawal does not affect the lawfulness of prior processing and does not terminate processing necessary for compliance with law, performance of an agreement, or protection of rights.
7.1. Accumulation and storage of the Operator’s Account personal data are carried out in a database located in the Republic of Kazakhstan in accordance with the law.
8.1. Certain suppliers, payment organisations, communications tools, and data centres may be located outside the Republic of Kazakhstan. Personal data is transferred abroad only where there is a legal basis and adequate protection as required by law.
8.2. If a country does not provide the required level of protection, the Operator obtains the data subject’s consent to the cross-border transfer or relies on another basis expressly provided by law.
8.3. A VPS may be located in countries selected by the Client. The Client’s placement of third-party personal data on such a VPS is an action of the Client; the Client must ensure the lawfulness of the cross-border transfer and inform the data subjects.
8.4. The Operator does not use the Client’s Content for its own purposes and accesses it only to the minimum extent necessary for support upon request, prevention of threats, compliance with law, or protection of rights.
9.1. Data may be disclosed to:
9.2. Where required and applicable, the Operator concludes agreements with contractors that provide for confidentiality, purpose limitation, and protective measures.
10.1. The websites use necessary cookies for login, security, language settings, and the shopping cart. Analytics and marketing cookies are used subject to legal requirements and consent settings.
10.2. A User may restrict cookies in the browser, but certain Personal Account functions may stop working.
11.1. At the end of the retention period, data is deleted, destroyed, or anonymised unless there is a lawful basis for further retention.
12.1. The Operator implements legal, organisational, and technical measures proportionate to the risks, including access controls, multi-factor authentication, encryption of communications, redundancy, logging, updates, antivirus and network protection, staff training, and confidentiality agreements.
12.2. Access is granted only to persons who need it for their work and is reviewed regularly.
12.3. In the event of a security breach, the Operator records the incident, limits its consequences, restores security, and fulfils notification obligations to data subjects and authorities where required by law.
13.1. In the manner established by law, a data subject has the right to:
13.2. To protect data, the Operator may verify the applicant’s identity. A response is provided within the periods established by law.
14.1. Independent registration and ordering of paid Services are permitted for persons who possess the required legal capacity. Participation of a legal representative is required for a minor where provided by law.
14.2. If improperly collected data of a minor is identified, the Operator takes steps to delete it or obtain an appropriate legal basis.
15.1. The current version is published on on1xcloud.com and on1x.kz. Material amendments affecting the purposes or scope of processing are communicated to users and, where required, accompanied by renewed consent.
15.2. The new version applies from the stated date and does not legalise processing carried out without a proper legal basis before its publication.