This Policy has been prepared with due regard to the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013 (as amended) and constitutes an integral part of the Public Offer (User Agreement) of the Toptar service.
1. General Provisions and Terms
1.1. This Policy establishes the procedure for the collection, processing, storage, protection, and other actions with respect to the personal data of Users of the Toptar service (hereinafter, the “Service”), as well as the rights of personal data subjects.
1.2. Personal data means information relating to an identified personal data subject, or a personal data subject identifiable on the basis of such information, recorded on an electronic, paper, and (or) other medium.
1.3. Subject means the User whose personal data is processed.
1.4. Operator means Plura LLP (Limited Liability Partnership), BIN 260640043859, which carries out the collection and processing of personal data.
1.5. Processing means actions involving the collection, recording, systematization, accumulation, storage, alteration, use, dissemination, depersonalization, blocking, and destruction of personal data.
1.6. Consent means the explicit, free, informed, and unambiguous expression of the Subject’s will by which the Subject permits the processing of their data for specific purposes. Consent may be withdrawn.
1.7. Capitalized terms not defined in this Policy (Account, Content, Segment, User, Service, and others) have the meanings established by the Public Offer.
2. Operator and Responsible Person
2.1. The operator of personal data is Plura LLP.
2.2. The person responsible for organizing the processing of personal data is the Director of Plura LLP. Contact for inquiries regarding personal data: support@toptar.kz.
2.3. Requests concerning the exercise of the Subject’s rights shall be sent to the address specified in clause 2.2 and may also be submitted through the functions of the Service (Account settings).
3. What Data We Process
3.1. Credentials Data
- email address (provided by the Google or Apple sign-in provider; when signing in with Apple, this may be a relayed address);
- Google and Apple sign-in identifiers (Sign-In);
- authorization tokens (JWT) and technical session identifiers.
3.2. Profile Data
- username, display name, avatar, description (bio);
- verification status, follower/following counters, privacy and notification settings.
3.3. Profile Survey (Demographic) Data
- gender — specified at registration;
- date of birth / age — specified at registration;
- country and city of residence — specified at registration;
- level of education — provided voluntarily;
- marital status — provided voluntarily.
3.4. Content and Activity
- created polls, answer options, images;
- votes (responses); comments, “likes,” reposts, bookmarks, views;
- follows (social graph); search queries and search history; reports (complaints).
3.5. Technical and Analytical Data
- device type and model, platform (iOS/Android), application version;
- session identifier, usage events (impressions, scrolls, actions), depersonalized for analytical purposes;
- push tokens of registered devices; error and crash data (diagnostics).
3.6. The Operator does not collect information that is not required for the purposes specified in Section 4. Gender, date of birth, and country and city of residence are specified by the User at registration (the date of birth also serving, among other things, to verify age requirements). The remaining Profile Survey Data is voluntary: failure to provide it does not block the use of the basic functions of the Service but may limit demographic analytics and targeting functions.
4. Purposes and Legal Grounds for Processing
4.1. The Operator processes data for the following purposes:
- registration, authentication, and provision of access to the Service;
- provision of the Service’s functions: creation and display of polls, voting, comments, feed, follows;
- generation of aggregated demographic analytics and targeting of polls to selected Segments;
- personalization of the feed and recommendations, including with the use of AI;
- delivery of notifications (in-app and push);
- promotion of the Service using publicly posted Content — within the scope of the license granted by the User under the Public Offer;
- ensuring security, preventing fraud and abuse, moderation;
- improvement of the Service, product analytics (based on depersonalized or aggregated data);
- compliance with the requirements of legislation.
4.2. The legal grounds for processing are: the Subject’s consent; performance of a contract (the Public Offer); compliance with the requirements of legislation; as well as other grounds provided for by the Law “On Personal Data and Their Protection.”
5. Consent and Withdrawal of Consent
5.1. Consent to the processing of personal data is granted by accepting this Policy upon registration and use of the Service.
5.2. The Subject has the right to withdraw consent at any time by sending a request to the Operator or by deleting the relevant data or the Account through the Service settings. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
5.3. Withdrawal of consent to the processing of data necessary for the provision of basic functions may result in the impossibility of using the Service.
6. Special Categories of Data
6.1. The Operator does not request from the User and does not include in the User’s profile information relating to special categories of personal data (including religious beliefs, political views, ethnicity, or state of health). The User’s responses in polls are not used by the Operator to profile the User on the basis of such characteristics.
7. Anonymity of Voting and Small Samples
7.1. The author of a poll may enable anonymity mode: in such a poll, the Users who have voted and their choices are not displayed to other Users. In polls without anonymity mode, the fact of the User’s participation may be displayed to other Users in accordance with the User’s privacy settings. In all cases, within the Operator’s systems the vote is technically linked to the Account of the voter. Poll results are displayed in aggregated form.
7.2. Demographic breakdowns of results are displayed in aggregated form. The Subject acknowledges that, where the number of respondents in a breakdown is small, aggregated indicators may indirectly characterize the responses of individual poll participants. The Operator has the right to apply additional measures of protection against the identification of Users through small samples (including setting minimum thresholds for displaying breakdowns).
7.3. Profile data (username, display name, avatar, description) and the User’s non-anonymous activity are displayed to other Users by the Subject’s own volition, in accordance with the Subject’s privacy settings.
8. Data Transfers and Engaged Services
8.1. Users’ personal data is stored and processed on the Operator’s infrastructure located in the territory of the Republic of Kazakhstan. The Operator does not transfer Users’ personal data to external services for their own purposes, does not sell data, and does not transfer it for advertising targeting by third parties.
8.2. The following is transferred to external AI services (Google Gemini): poll Content (question text, description, answer options) and aggregated (generalized) result data by segment. Google Gemini services are used for classifying polls, building recommendations (creating vector representations of Content), generating aggregated analytical overviews of results, and generating Segment descriptions. Individual demographic profiles, credentials data, and Users’ comments are not transferred to such services.
8.3. For the operation of certain basic functions, the transfer of a limited set of data to the respective providers is technically necessary — strictly to the extent required to perform the function:
- Hosting and storage (in the Republic of Kazakhstan) — Yandex Cloud (Republic of Kazakhstan region) and/or another data center in the Republic of Kazakhstan: placement of databases and files in the territory of the Republic of Kazakhstan.
- Traffic delivery and protection — Cloudflare: network traffic between the User’s device and the Operator’s servers passes in transit through Cloudflare’s infrastructure (attack protection, TLS encryption); Cloudflare processes technical connection data and transmitted data exclusively for the purposes of routing and protecting traffic.
- Sign-in via Google/Apple — registration and sign-in to the Service are carried out through these providers; the provider (Google, Apple) receives the minimum set of identification data necessary for authentication.
- Push notifications — delivery services (OneSignal, Apple APNs, Firebase Cloud Messaging (Google)) receive the device token and the content of the notification (which may include the username of the sender and fragments of the affected Content) exclusively for the delivery of the notification to the User’s device.
- Error monitoring — Sentry (hosted in the USA): technical diagnostic information about failures is transferred; the service is configured to exclude (mask) personal data from the information sent.
- Mobile application diagnostics — Firebase Crashlytics (Google): application crash reports and technical device metadata are transferred; Firebase Remote Config (Google): delivery of application configuration to Users’ devices.
- App stores and payments (for the future) — Apple App Store, Google Play (only when paid functions are used; full payment details are not transferred to the Operator).
8.4. The engaged providers act on the Operator’s instructions and under conditions of confidentiality, with the exception of the platform services of Google and Apple (authentication, delivery of push notifications, app stores), which act as independent operators and process data on the basis of their own privacy policies. The Operator has the right to disclose data upon a lawful request of authorized state bodies, as well as to protect the rights and safety of the Operator and Users.
9. Cross-Border Transfer
9.1. Users’ personal data is stored in the territory of the Republic of Kazakhstan. Cross-border transfer is carried out only to the minimum extent necessary for the functions specified in clauses 8.2–8.3: authentication via Google/Apple (where such sign-in is chosen); delivery of push notifications; transit of network traffic between the User’s device and the Operator’s servers through Cloudflare’s infrastructure; processing of poll Content and aggregated data by AI services (Google Gemini); transfer of technical diagnostic information to the error monitoring service (Sentry, USA); transfer of mobile application crash reports and receipt of its configuration (Firebase Crashlytics / Remote Config, Google).
9.2. Such transfer is carried out in compliance with Article 16 of the Law “On Personal Data and Their Protection”: to states that ensure the protection of personal data — on general grounds; to other states — with the Subject’s consent or on other grounds provided for by law.
9.3. By accepting this Policy and using the Service (including by choosing sign-in via Google/Apple and the receipt of push notifications), the Subject consents to the cross-border transfer of data to the extent necessary for the operation of the functions specified in clause 9.1.
10. Data Localization and Storage
10.1. The collection, processing, and storage of the personal data of citizens of the Republic of Kazakhstan are carried out using databases located in the territory of the Republic of Kazakhstan, in accordance with the localization requirements of legislation.
10.2. The storage infrastructure is hosted with the provider Yandex Cloud (Republic of Kazakhstan region), with the databases located in the territory of the Republic of Kazakhstan.
10.3. Only the minimum necessary volume of data is transferred outside the Republic of Kazakhstan for the functions specified in clause 9.1 — in the manner set out in Section 9.
11. Storage Periods
11.1. Personal data is stored for the period of use of the Account and until the purposes of processing are achieved.
11.2. Deletion of the Account is performed in stages: upon a deletion request, the Account is deactivated with a recovery period of 14 (fourteen) calendar days, upon the expiry of which the data is automatically deleted or depersonalized, with the exception of: (a) data whose retention is required by law; (b) data necessary for the resolution of disputes and the protection of rights; (c) backup copies deleted in accordance with the rotation schedule (within a period of up to 30 days); (d) depersonalized aggregated data that does not permit identification of the Subject. Content posted by the User (polls, votes, comments) is not deleted upon deletion of the Account but is depersonalized: it is retained in the Service without any link to the User. To delete the Content itself, the Content deletion functions should be used prior to deletion of the Account.
11.3. Upon withdrawal of consent, processing of the relevant data is terminated within the time limits established by legislation.
12. Data Protection
12.1. The Operator takes legal, organizational, and technical measures to protect personal data against unlawful access, alteration, disclosure, or destruction, including: encryption of transmission channels, secure storage of credentials secrets and tokens, differentiation of access rights, logging, backup, and incident monitoring.
12.2. The Operator restricts access to data to the circle of persons who require it to perform their duties, subject to confidentiality obligations.
12.3. No method of transmission or storage is absolutely secure; the Operator strives to apply measures commensurate with the level of risk.
13. Rights of the Personal Data Subject
13.1. The Subject has the right:
- to receive information about the processing of their personal data;
- to demand the amendment and supplementation of data where it is incomplete or inaccurate;
- to demand the blocking of data where grounds exist;
- to demand the destruction of data processed in violation of the law, and to withdraw consent;
- to object to processing and to appeal against the Operator’s actions to the authorized body and to the courts.
13.2. To exercise these rights, the Subject shall send a request to support@toptar.kz or use the Service settings. The Operator considers the request within the time limits established by legislation.
14. Data of Minors
14.1. The Service is intended for persons who have reached the age of 18 (eighteen) years. The Operator does not purposefully collect data of persons below the established age.
14.2. If data collected in violation of the age requirements is identified, such data is deleted.
15. Cookies and Similar Technologies
15.1. In the mobile application, instead of cookies, device identifiers, tokens, and local storage are used, as necessary for authentication, saving settings, and analytics.
15.2. Cookies may be used on the Operator’s web resources; they can be managed in browser settings.
16. Amendments to the Policy
16.1. The Operator has the right to amend this Policy. The current version is posted in the Service with an indication of its effective date. In the event of material changes, the Operator notifies Users by available means.
16.2. The Policy is published in the Kazakh and Russian languages. In the event of discrepancies between the language versions, the Russian-language version prevails.
17. Contacts and Authorized Body
17.1. For matters concerning the processing of personal data: Plura LLP, Republic of Kazakhstan, 050000, Almaty, Almaly district, Zhambyl street, 155, apt. 67, email: support@toptar.kz.
17.2. The Subject has the right to apply to the authorized body in the field of personal data protection — the Information Security Committee of the Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan.