Policy on the processing of personal data
Version dated 21 September 2026
This Policy on the processing of personal data (hereinafter, the “Policy”) applies to all information that the Service or the Operator receives about the User during the use of the Service, its programs and its services.
This Policy designates ИП «Maestro Group» as the Operator that carries out the processing and protection of personal data received from Users of the Service in accordance with the requirements of the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 «О персональных данных и их защите» (On Personal Data and Their Protection) (hereinafter, the “Personal Data Law”).
The purpose of the Policy is to ensure proper protection of Users’ personal data against unauthorised access and disclosure.
1Terms and definitions
2General provisions
2.1. Use of the Service, completion of feedback forms, and also the purchase of the Services means consent to this Policy and to the terms of processing of personal data.
2.2. If the User does not agree with the provisions of the Policy, the User must immediately stop using the Service.
2.3. The Operator does not verify the accuracy of the personal data provided by the User upon registration.
2.4. When processing personal data, the Operator acts reasonably and in good faith, proceeding on the basis that the User:
- confirms that the data provided belong to the User personally;
- confirms that the User holds all the rights necessary to use the Service;
- confirms that the User acts voluntarily and in the User’s own interests;
- confirms the accuracy of the information provided;
- expresses full consent to this Policy.
2.5. Given the nature of the Service, the Operator transfers the User’s messenger correspondence to a third party (the platform into which the Service is integrated). The Operator does not collect, process, control or disseminate any data contained in the User’s correspondence.
3Subject matter of the Policy
3.1. This Policy establishes the obligations of the Operator and the User regarding non-disclosure and the maintenance of a regime protecting the confidentiality of personal data.
3.2. The personal data permitted for processing are provided by the User by completing forms on the Service and include:
- surname, first name, patronymic;
- contact telephone number;
- email address (e-mail);
- any other data transferred for the purpose of using the Service.
3.3. Consent to the processing of personal data is given by ticking the corresponding box at the moment of registration.
3.4. The Service collects Cookies in order to provide personalised functions, for statistical and research purposes, and also to improve the Service.
3.5. In order to ensure the functionality of the Service, the following are automatically collected and stored:
- messages (correspondence) received and sent by means of the Service;
- contact details of the User’s employees, counterparties and customers.
3.6. The Operator does not process personal data concerning racial or ethnic origin, political views or religious beliefs.
4Purposes of collecting personal data
4.1. The User’s personal data are used for the purposes of:
- registering the User on the Service;
- identifying and authorising the User;
- providing personalised services;
- fulfilling obligations under concluded contracts;
- establishing feedback with the User;
- providing customer support;
- carrying out marketing campaigns;
- carrying out statistical research based on depersonalised data;
- resolving disputes;
- preventing unlawful actions.
4.2. Cookies are used for recognition at login, for tracking settings, for carrying out research, for preventing fraud and for strengthening security.
5Legal grounds for processing
5.1. The legal grounds for the processing of personal data are:
- the Constitution of the Republic of Kazakhstan;
- the Civil Code of the Republic of Kazakhstan;
- the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 «О персональных данных и их защите» (On Personal Data and Their Protection);
- contracts and agreements between the Operator and the User;
- consent to the processing of personal data.
6Methods and periods of processing
6.1. Personal data are processed without any time limit (until the purpose of processing is achieved or until consent is withdrawn), by any lawful means, including in information systems using automation tools.
6.2. The Operator has the right to transfer personal data to third parties in the following cases:
- the User has consented to such actions;
- the transfer is necessary as part of the use of the functionality of the Service;
- the transfer is required in order to fulfil the User’s requests;
- in connection with the transfer of the Service into the ownership of a third party;
- to protect the rights and legitimate interests of the Operator;
- to affiliated persons that comply with the requirements of the Policy;
- to authorised state authorities of the Republic of Kazakhstan on the grounds established by law.
6.3. Messages are delivered through WhatsApp (a service owned by Meta), and its servers are located outside Kazakhstan. This is how the messenger itself works: any WhatsApp conversation goes through them, whether you use WazzaBee or the regular app on your phone.
6.4. The Operator takes the necessary organisational and technical measures to protect personal information against unlawful access, destruction, alteration, blocking, copying and dissemination.
7Rights and obligations of the parties
The User has the right to:
- make a free decision on providing their personal data;
- independently update and supplement the information provided;
- demand that the processing of personal data be stopped;
- request information about the processing of their personal data;
- demand the clarification, blocking or destruction of personal data.
The Operator is obliged to:
- use the information received solely for the stated purposes;
- keep confidential information stored in secret;
- take precautions to protect personal data;
- block personal data upon request for the period of verification;
- notify the authorised body in the event of an unlawful transfer of personal data.
8Clarification and destruction of personal data
8.1. If the fact that personal data are inaccurate, or that their processing is unlawful, is confirmed, the personal data are subject to updating or the processing must be stopped.
8.2. Upon the User’s written request, the Operator is obliged to provide information about the processing of the User’s personal data within ten business days.
8.3. The User may change the personal data provided at any time in the Personal account.
8.4. The User has the right to withdraw consent to the processing of personal data by sending an application to the Operator’s email address.
8.5. Once the purposes of processing have been achieved, or upon withdrawal of consent, personal data are subject to destruction within a period of no more than thirty days.
8.6. If use of the Service is discontinued, personal data are blocked and stored for up to six months, after which they are destroyed.
9Protection of personal data
9.1. The Operator takes the necessary organisational and technical measures to protect personal data against unlawful access.
9.2. The measures applied include:
- appointment of persons responsible for working with personal data;
- limitation of the range of persons who have access to personal data;
- organisation of the recording, storage and handling of data carriers;
- differentiation of user access to information resources;
- use of antivirus protection tools;
- use of encrypted storage.
9.3. The User undertakes to keep the data of their account confidential and to notify the Operator immediately of any unauthorised access.
10Data from Google accounts
10.1. The Service connects to a User’s Google account only if the User has turned on the Google Sheets integration in the CRM (Settings → Integrations → Google Sheets) and given consent on the Google screen.
10.2. When connected, the Service receives:
- the email address of the Google account, to show the User which account is connected;
- access to the User’s Google Sheets (scope https://www.googleapis.com/auth/spreadsheets).
10.3. Access to Google Sheets is used only for features the User has turned on:
- creating a spreadsheet when the User clicks the button and writing rows about CRM deals into it: date, event, deal number and title, client name, phone, email, pipeline, stage, amount, currency, responsible person, source;
- reading new rows from the spreadsheet the User has specified in order to create clients and deals in that same User’s CRM.
10.4. The Service does not open, read or change any other spreadsheets or files of the User. The Google access token is kept in encrypted storage. The Service does not store spreadsheet contents, except the data of the rows from which clients and deals were created in the User’s CRM.
10.5. Data received from Google is not sold, not transferred to third parties, and not used for advertising or for training artificial intelligence models. Operator staff do not view this data unless the User has asked for it for technical support, it is needed to protect against abuse, or it is required by law.
10.6. The Service’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
10.7. The User can revoke access at any time: in the CRM (Settings → Integrations → Google Sheets → “Disconnect”) or in the Google account settings. After disconnection the access token is deleted immediately. Google account access settings: https://myaccount.google.com/permissions
11Liability of the parties
11.1. The Operator is liable for losses in connection with the unlawful use of personal data in accordance with the legislation of the Republic of Kazakhstan.
11.2. The Operator is not liable if the information:
- became public knowledge before it was disclosed;
- was received from a third party;
- was disclosed with the User’s consent.
11.3. The User bears full responsibility for compliance with the requirements of the legislation of the Republic of Kazakhstan.
12Dispute resolution
12.1. Disputes are considered in accordance with the applicable legislation of the Republic of Kazakhstan.
12.2. The legislation of the Republic of Kazakhstan applies to this Policy.
13Contact information
Operator
ИП «Maestro Group»
Address
Республика Казахстан, г. Каскелен, ул. Айтей Батыра
An application on paper must contain the number of the identity document, information about the date of its issue, and the signature of the User or of the User’s representative.
14Final provisions
14.1. The Policy comes into force from the moment it is published on the Service and is valid indefinitely.
14.2. The Operator has the right to make changes to the Policy at any time unilaterally and without prior notice.
14.3. Users must refer to the Policy independently and regularly in order to familiarise themselves with the current version.
14.4. The current Policy is published at: https://wazzabee.com/privacy