This Policy has been developed in accordance with the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013 (as amended) and constitutes an integral part of the Public Offer (User Agreement) of the Toptar service.
1. General Provisions and Terms
1.1. This Policy establishes the procedure for the collection, processing, storage, protection, and other actions with respect to the personal data of Users of the Toptar service (hereinafter, the “Service”), as well as the rights of personal data subjects.
1.2. Personal data means information relating to an identified personal data subject, or a personal data subject identifiable on the basis of such information, recorded on an electronic, paper, and (or) other medium.
1.3. Subject means the User whose personal data is processed.
1.4. Operator means PLYURA, TOO (Limited Liability Partnership «Plyura»), BIN 260640043859, which carries out the collection and processing of personal data.
1.5. Processing means actions involving the collection, recording, systematization, accumulation, storage, alteration, use, dissemination, depersonalization, blocking, and destruction of personal data.
1.6. Consent means the explicit, free, informed, and unambiguous expression of the Subject’s will by which the Subject permits the processing of their data for specific purposes. Consent may be withdrawn.
1.7. Capitalized terms not defined in this Policy (Account, Content, User, Service, and others) have the meanings established by the Public Offer.
2. Operator and Responsible Person
2.1. The operator of personal data is PLYURA, TOO.
2.2. The person responsible for organizing the processing of personal data is the Director of PLYURA, TOO. Contact for inquiries regarding personal data: support@toptar.kz.
2.3. Requests concerning the exercise of the Subject’s rights shall be sent to the address specified in clause 2.2 and may also be submitted through the functions of the Service (Account settings).
3. What Data We Process
3.1. Credentials Data
- email address (provided by the Google or Apple sign-in provider; when signing in with Apple, this may be a relayed address);
- Google and Apple sign-in identifiers (Sign-In);
- authorization tokens (JWT) and technical session identifiers.
3.2. Profile Data
- username, display name, avatar, description (bio);
- verification status, follower/following counters, privacy and notification settings.
3.3. Profile Survey (Demographic) Data
- gender — specified at registration;
- date of birth — specified at registration;
- country and city of residence — specified at registration;
- level of education — provided voluntarily;
- marital status — provided voluntarily.
3.4. Content and Activity
- created polls, answer options, images;
- votes (responses); comments, “likes,” reposts, saved polls, views;
- follows (social graph); search queries and search history; reports (complaints);
- lists of blocked Users; saved sets of demographic breakdown criteria (“Groups”); information about submitted reports and the decisions taken on them, and about the blocking of the Account.
3.5. Technical and Analytical Data
- device type and model, platform (iOS/Android), application version;
- session identifier; usage events (impressions, scrolls, actions), linked to the technical identifier of the Account and used in aggregated (depersonalized) form for product analytics;
- IP address and technical network connection data (processed when routing traffic and in security logs); device language (locale);
- push tokens of registered devices; error and crash data (diagnostics);
- consent journal: date and time, versions of the accepted documents, language, platform and app version, a hash of the email address (the address itself is not stored in the journal).
3.6. The Operator does not collect information that is not required for the purposes specified in Section 4. Gender, date of birth, and country and city of residence are specified by the User at registration (the date of birth also serving, among other things, to verify age requirements). The remaining Profile Survey Data is voluntary: failure to provide it does not block the use of the basic functions of the Service but may limit demographic analytics functions.
4. Purposes and Legal Grounds for Processing
4.1. The Operator processes data for the following purposes:
- registration, authentication, and provision of access to the Service;
- provision of the Service’s functions: creation and display of polls, voting, comments, feed, follows;
- generation of aggregated demographic analytics of poll results;
- personalization of the feed and recommendations, including with the use of AI;
- delivery of notifications (in-app and push);
- promotion of the Service using publicly posted Content — within the scope of the license granted by the User under the Public Offer;
- ensuring security, preventing fraud and abuse, moderation;
- improvement of the Service, product analytics (based on depersonalized or aggregated data);
- compliance with the requirements of legislation.
4.2. The legal grounds for processing are: the Subject’s consent; performance of a contract (the Public Offer); compliance with the requirements of legislation; as well as other grounds provided for by the Law “On Personal Data and Their Protection.”
5. Consent and Withdrawal of Consent
5.1. Consent to the processing of personal data is granted by accepting this Policy upon registration and use of the Service. The Operator records the granting and withdrawal of consent in a consent journal (date and time, versions of the accepted documents, language, platform, and app version). Consent is valid for the entire period of use of the Account and until the purposes of processing are achieved (Section 11). Journal entries are immutable and, after Account deletion, are retained without the email address and other profile data — only with a cryptographic hash of the address that allows the Operator to evidence, in a dispute or an inspection, that consent was obtained from a specific person (Articles 8 and 25 of the Law) — for the period necessary for such evidence.
5.2. The Subject has the right to withdraw consent at any time by sending a request to the Operator or by deleting the relevant data or the Account through the Service settings. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
5.3. Withdrawal of consent to the processing of data necessary for the provision of basic functions may result in the impossibility of using the Service.
6. Special Categories of Data
6.1. The Operator does not request from the User and does not include in the User’s profile information relating to special categories of personal data (including religious beliefs, political views, ethnicity, or state of health). The Operator does not derive from the User’s responses, and does not store, characteristics relating to special categories of personal data, and does not use such characteristics for selecting Content, restricting functions, or advertising. The recommendation system takes into account the topics of the polls the User has interacted with, in aggregate (clause 10.3 of the Public Offer).
7. Display of Votes and Small Samples
7.1. The fact of the User’s participation in a poll may be displayed to other Users in accordance with the User’s privacy settings. Within the Operator’s systems, the vote is technically linked to the Account of the voter. Poll results are displayed in aggregated form.
7.2. Demographic breakdowns of results are displayed in aggregated form. The Subject acknowledges that, where the number of respondents in a breakdown is small, aggregated indicators may indirectly characterize the responses of individual poll participants. The Operator applies measures of protection against the identification of Users through small samples, including minimum thresholds for displaying breakdowns and information about the participation of individual Users; the threshold values are set by the Operator.
7.3. Profile data (username, display name, avatar, description) and the User’s activity are displayed to other Users by the Subject’s own volition, in accordance with the Subject’s privacy settings. In the settings, the User may hide from other Users: gender, date of birth, country, city, education, marital status, the list of saved polls, the list of polls they have taken part in, and the lists of followers and follows. By default, this data is visible to other Users; the fact of participation in a poll is shown only when the setting for displaying polls taken is enabled.
7.4. Publicly available data. The name, username, avatar, verification status, number of followers, number of polls created and number of responses, as well as the polls published by the User (text, answer options, number of votes, author), are publicly available: they are displayed to other Users in the Service and to anyone on the Service’s web pages (toptar.kz/@username, toptar.kz/poll/…), including without signing in to the Service, and may be indexed by search engines. By filling in the profile and publishing Content, the Subject consents to the dissemination of this data in publicly available sources. Profile Survey Data, votes, saved polls, follows, and search history are not displayed on the web pages. The User may stop the dissemination by deleting the relevant Content or the Account (Section 11).
8. Data Transfers and Engaged Services
8.1. The Service’s main databases and files containing Users’ personal data are hosted and processed on the Operator’s infrastructure in the territory of the Republic of Kazakhstan (Section 10). The limited data sets listed in clauses 8.2–8.3 are processed, and may be temporarily stored, by the specified providers outside the Republic of Kazakhstan in the manner set out in Section 9. The Operator does not transfer Users’ personal data to external services for their own purposes, does not sell data, and does not transfer it for advertising targeting by third parties.
8.2. The following is transferred to external AI services (Google Gemini): poll Content (question text, description, answer options) and aggregated (generalized) result data in demographic breakdowns. Google Gemini services are used for classifying polls, building recommendations (creating vector representations of Content), generating aggregated analytical overviews of results, and generating textual descriptions of demographic audience breakdowns. Individual demographic profiles, credentials data, and Users’ comments are not transferred to such services.
8.3. For the operation of certain basic functions, the transfer of a limited set of data to the respective providers is technically necessary — strictly to the extent required to perform the function:
- Hosting and storage (in the Republic of Kazakhstan) — Yandex Cloud (Republic of Kazakhstan region) and/or another data center in the Republic of Kazakhstan: placement of databases and files in the territory of the Republic of Kazakhstan.
- Traffic delivery and protection — Cloudflare: network traffic between the User’s device and the Operator’s servers passes in transit through Cloudflare’s infrastructure (attack protection, TLS encryption); Cloudflare processes technical connection data (including the IP address) and transmitted data for the purposes of routing, caching, and protecting traffic; connection logs are retained by Cloudflare for the period it establishes.
- Sign-in via Google/Apple — registration and sign-in to the Service are carried out through these providers; the provider (Google, Apple) receives the minimum set of identification data necessary for authentication.
- Push notifications — delivery services (OneSignal — USA, Apple APNs, Firebase Cloud Messaging (Google)) receive the device token and the content of the notification (which may include the username of the sender and fragments of the affected Content) exclusively for the delivery of the notification to the User’s device.
- Error monitoring — Sentry (hosted in the USA): technical diagnostic information about failures is transferred; the service is configured to exclude (mask) personal data from the information sent.
- Mobile application diagnostics — Firebase Crashlytics (Google): application crash reports and technical device metadata are transferred; Firebase Remote Config (Google): delivery of application configuration to Users’ devices.
- App stores and payments (for the future) — Apple App Store, Google Play (only when paid functions are used; full payment details are not transferred to the Operator).
8.4. The engaged providers — Google Gemini, Firebase Crashlytics and Remote Config, OneSignal, Sentry, Cloudflare, and Yandex Cloud — process data on the Operator’s instructions under data processing and confidentiality agreements. The Google Sign-In and Apple Sign-In authentication services, the Apple APNs and Firebase Cloud Messaging notification delivery services, and the app stores act as independent operators: Google and Apple process data in them on the basis of their own privacy policies. The Operator has the right to disclose data upon a lawful request of authorized state bodies, as well as to protect the rights and safety of the Operator and Users.
9. Cross-Border Transfer
9.1. The Service’s main databases are hosted in the territory of the Republic of Kazakhstan. Cross-border transfer is carried out only to the minimum extent necessary for the functions specified in clauses 8.2–8.3: authentication via Google/Apple (Google LLC, Apple Inc., USA); delivery of push notifications (OneSignal Inc., USA; Apple Inc., USA; Google LLC, USA); transit of network traffic between the User’s device and the Operator’s servers through the infrastructure of Cloudflare, Inc. (USA and other countries where network nodes are located); processing of poll Content and aggregated data by the Google Gemini AI services (Google LLC, USA); transfer of technical diagnostic information to the Sentry error monitoring service (Functional Software, Inc., USA); transfer of mobile application crash reports and receipt of its configuration (Firebase Crashlytics / Remote Config, Google LLC, USA).
9.2. Such transfer is carried out in compliance with Article 16 of the Law “On Personal Data and Their Protection”: to states that ensure the protection of personal data — on general grounds; to other states — with the Subject’s consent or on other grounds provided for by law.
9.3. By registering in the Service and confirming acceptance of this Policy, the Subject consents to the cross-border transfer of their personal data to the providers and states specified in clause 9.1, including to states that do not ensure the protection of personal data (USA), exclusively to the extent necessary for the operation of the respective functions. Without such transfer, sign-in to the Service via Google/Apple, delivery of push notifications, and traffic protection are not possible. The Subject may withdraw consent in the manner set out in clause 5.2; withdrawal results in the impossibility of using the Service (clause 5.3).
10. Data Localization and Storage
10.1. The collection, processing, and storage of Users’ personal data are carried out using databases located in the territory of the Republic of Kazakhstan (Article 12 of the Law); transfer outside its territory is made only to the extent set out in Section 9.
10.2. The storage infrastructure is hosted with the provider Yandex Cloud (Republic of Kazakhstan region), with the databases located in the territory of the Republic of Kazakhstan.
10.3. Only the minimum necessary volume of data is transferred outside the Republic of Kazakhstan for the functions specified in clause 9.1 — in the manner set out in Section 9.
11. Storage Periods
11.1. Personal data is stored for the period of use of the Account and until the purposes of processing are achieved.
11.2. Deletion of the Account is performed in stages: upon a deletion request, the Account is deactivated with a recovery period of 14 (fourteen) calendar days, upon the expiry of which the data is automatically deleted or depersonalized, with the exception of: (a) data whose retention is required by law; (b) information about reports, moderation decisions, and Account blocks, as well as the consent journal (clause 5.1) — for the period necessary for the resolution of disputes and for evidencing the lawfulness of the Operator’s actions; (c) backup copies deleted in accordance with the rotation schedule (within a period of up to 30 days); (d) depersonalized aggregated data that does not permit identification of the Subject. Content posted by the User (polls, votes, comments) is not deleted upon deletion of the Account but is depersonalized: it is retained in the Service without any link to the User. To delete the Content itself, the Content deletion functions should be used prior to deletion of the Account.
11.3. Upon withdrawal of consent, the Operator terminates the processing of the relevant data within 15 (fifteen) business days or, within the same period, sends a reasoned refusal where processing is permitted without consent (for example, to comply with legislation or to protect the Operator’s rights).
12. Data Protection
12.1. The Operator takes legal, organizational, and technical measures to protect personal data against unlawful access, alteration, disclosure, or destruction, including: encryption of transmission channels, secure storage of credentials secrets and tokens, differentiation of access rights, logging, backup, and incident monitoring.
12.2. The Operator restricts access to data to the circle of persons who require it to perform their duties, subject to confidentiality obligations.
12.3. No method of transmission or storage is absolutely secure; the Operator strives to apply measures commensurate with the level of risk.
12.4. If a breach of the confidentiality of personal data (unauthorized access, leak) is identified, the Operator immediately notifies the affected Users by available means (in the Service, by push notification, or at the Account’s email address), and notifies the authorized body within the period established by Article 25 of the Law (no later than one business day from identification), indicating the contact details of the responsible person (clause 2.2).
13. Rights of the Personal Data Subject
13.1. The Subject has the right:
- to receive information about the processing of their personal data;
- to demand the amendment and supplementation of data where it is incomplete or inaccurate;
- to demand the blocking of data where grounds exist;
- to demand the destruction of data processed in violation of the law, and to withdraw consent;
- to approve or decline the dissemination of their data in publicly available sources (clause 7.4), including by deleting Content or the Account;
- to object to processing and to appeal against the Operator’s actions to the authorized body and to the courts.
13.2. Amending and supplementing profile data and Profile Survey Data, managing data visibility (clause 7.3), deleting search history and individual Content, blocking Users, and withdrawing consent by deleting the Account are performed in the Service settings; other requests are sent to support@toptar.kz. The Operator responds to a request within 15 (fifteen) business days from receipt, and complies with demands to amend, supplement, block, or destroy data collected in violation of the law within 1 (one) business day or, within the same period, sends a reasoned refusal (Article 25 of the Law).
14. Data of Minors
14.1. The Service is intended for persons who have reached the age of 18 (eighteen) years. The Operator does not purposefully collect data of persons below the established age.
14.2. If data collected in violation of the age requirements is identified, such data is deleted within 1 (one) business day of identification, and the Account is blocked.
14.3. The procedure for responding to material related to child sexual abuse and exploitation is set out in the Child Safety Standards.
15. Cookies and Similar Technologies
15.1. In the mobile application, instead of cookies, device identifiers, tokens, and local storage are used, as necessary for authentication, saving settings, and analytics.
15.2. The Operator’s web resources may use service cookies of the content delivery network (Cloudflare) for protection against attacks; the Operator does not use its own analytics cookies on its web resources. Cookies can be managed in browser settings.
16. Amendments to the Policy
16.1. The Operator has the right to amend this Policy. The current version is posted in the Service and on toptar.kz with the version number and effective date; previous versions are available in the archive. Changes affecting the Subject’s rights or the procedure for processing personal data take effect no earlier than 10 (ten) calendar days after posting; the Operator notifies Users of them in the Service and/or by push notification and, upon sign-in, asks the User to confirm acceptance of the new version. Editorial and technical clarifications take effect from the moment of posting.
16.2. The Policy is published in the Kazakh and Russian languages; for the convenience of Users, an English translation may be published. In the event of discrepancies between the language versions, the Russian-language version prevails.
17. Contacts and Authorized Body
17.1. For matters concerning the processing of personal data: PLYURA, TOO, Republic of Kazakhstan, 050000, Almaty, Almaly district, Zhambyl street, 155, apt. 67, email: support@toptar.kz.
17.2. The Subject has the right to apply to the authorized body in the field of personal data protection — the Information Security Committee of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan.