PRIVACY POLICY OF THE “AKJET” PLATFORM

Publication date: May 1, 2026

1. General Provisions

1.1. This Policy has been prepared in accordance with the Law of the Republic of Kazakhstan No. 94-V dated May 21, 2013 “On Personal Data and Their Protection” (hereinafter, the “Personal Data Law”) and sets out the system of core principles applied to the processing of personal data carried out by AKJET LLP (BIN: 260240014227) (hereinafter, the “Operator”).

1.2. This Policy defines the general principles, purposes, procedure, and conditions for processing the personal data of Platform Users and users of the website https://akjet.kz/ within the information and telecommunication network “Internet”, as well as other persons whose personal data is processed by the Operator, in order to ensure the protection of human and civil rights and freedoms in the course of personal data processing.

1.3. This Policy applies to all processes involving the collection, recording, systematization, accumulation, storage, clarification, extraction, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of personal data, whether performed with or without automation tools.

1.4. This Policy applies to personal data obtained both before and after the effective date of the Policy. This Policy does not apply to software and mobile applications, as well as services of third-party developers, vendors, advertisers, sponsors, social networks, services accessible through or integrated with the Software, or links to such services. For example, when making a payment, you may be redirected to a payment system website. In such cases, data processing is outside the Operator’s control. Such Third-Party services act as independent data controllers under their own policies, and we recommend that you review them. We bear no responsibility whatsoever for the privacy policies of such Third-Party services, and you use them at your own risk.

1.5. This Policy may be amended and supplemented in the event of the adoption of new or modification of existing legislative and subordinate regulations concerning the processing and protection of personal data. A new version of the Policy enters into force from the moment it is published or otherwise made publicly available, unless otherwise provided in the new version of the Policy.

1.6. If you do not agree with this Policy, please do not use the Platform or the website.

2. Terms and Definitions

2.1. Blocking means the temporary suspension of Personal Data processing, except where processing is necessary to clarify Personal Data.

2.2. Information System means the aggregate of Personal Data contained in databases and the information technologies and technical means ensuring their Processing.

2.3. Depersonalization means actions that make it impossible to determine, without the use of additional information, whether Personal Data belongs to a specific Subject.

2.4. Processing of Personal Data (Processing) means any action or set of actions performed on Personal Data with or without automation tools, including collection, recording, systematization, accumulation, storage, clarification (updating, modification), extraction, use, transfer (dissemination, provision, access), depersonalization, blocking, deletion, and destruction of Personal Data.

2.5. Personal Data means any information relating to a directly or indirectly identified or identifiable individual (Personal Data Subject).

2.6. User means an individual who is a citizen of the Republic of Kazakhstan or another state, including a person having any entrepreneurial status or any other taxation regime permitted in the country of incorporation, and who is registered on the Platform.

2.7. Provision means actions aimed at disclosing Personal Data to a specific person or a specific group of persons.

2.8. Dissemination means actions aimed at disclosing Personal Data to an indefinite group of persons.

2.9. Personal Data Subject (Subject) means an individual who is directly or indirectly identified or identifiable by means of Personal Data. For the purposes of this Policy, the Subject means a Platform User and/or an Authorized Representative of a customer company.

2.10. Cross-Border Transfer means the transfer of Personal Data to the territory of a foreign state, to a foreign public authority, foreign individual, or foreign legal entity.

2.11. Destruction means actions resulting in the impossibility of restoring the content of Personal Data in the Information System and/or destruction of physical media containing Personal Data.

2.12. Cookies means information that may contain the following data about the Subject: device IP address, geolocation data, information about the software used to access the Platform, technical characteristics of the equipment and software used by the Subject, the date and time of access to the Platform, and other similar information.

2.13. Platform means the “AKJET” software (computer program), available at its permanent Internet address: https://akjet.kz/, the exclusive rights to which belong to the Contractor. The Platform allows the Customer to place Tasks for the provision of Services/performance of Works, including through an Engaged Party, withdraw such Tasks, amend Tasks before they are accepted, including by the Engaged Party, receive notifications of Task acceptance, including by the Engaged Party, track the status of Task performance, pay for Tasks using electronic payment means, and send notifications and messages to the Contractor’s support service. The Platform also enables the Engaged Party to accept or reject Tasks, conclude electronic Task Agreements, track Task status, send notifications and messages to the Contractor’s support service, and receive information regarding settlements. The Platform includes its interface, source code, audiovisual images, and other elements necessary for its proper functioning. The Contractor is the rightholder of the Platform. Other terms shall be interpreted in accordance with the User Agreement and the provisions of the Personal Data Law.

3. Principles of Personal Data Processing

3.1. Personal Data processing is based on the following principles:

3.1.1. Personal Data is processed on a lawful and fair basis;

3.1.2. Personal Data processing is limited to the achievement of specific, predetermined, and lawful purposes;

3.1.3. processing of Personal Data incompatible with the purposes of Personal Data collection is not permitted;

3.1.4. only Personal Data relevant to the purposes of Processing is subject to Processing;

3.1.5. the content and volume of the processed Personal Data correspond to the stated purposes of Processing, and the processed Personal Data is not excessive in relation to those purposes;

3.1.6. when processing Personal Data, the accuracy, sufficiency, and, where necessary, relevance of Personal Data in relation to the stated purposes of Processing are ensured;

3.1.7. Personal Data is stored in a form allowing identification of the Personal Data Subject for no longer than required by the purposes of Processing, unless a storage period is established by law or by an agreement to which the Personal Data Subject is a party, beneficiary, or guarantor;

3.1.8. the processed Personal Data is subject to destruction or depersonalization upon achievement of the purposes of Processing or where such purposes are no longer necessary, unless otherwise provided by law.

4. Legal Grounds for Personal Data Processing

The Operator performs Processing on the basis of the following acts:

4.1. legislation regulating the Operator’s activities;

4.2. the Operator’s constitutional and corporate documents;

4.3. agreements concluded between the Operator and the Subject, including the User Agreement;

4.4. consent to the Processing of Personal Data.

5. Purposes of Personal Data Processing

The Operator processes Personal Data for the following purposes:

5.1. conclusion of agreements with the Operator, performance of concluded agreements and mutual obligations, including but not limited to the User Agreement, under which the Authorized Person (representative of the counterparty) is a party or beneficiary between the Operator and the Personal Data Subject within the Platform;

5.2. registration and obtaining access to the full functionality of the Platform;

5.3. verification of the User’s reliability and trustworthiness;

5.4. processing requests submitted to the support service;

5.5. compliance with the requirements of the legislation of the Republic of Kazakhstan relating to personal data;

5.6. collection and publication of reviews on the Operator’s information resource, as well as distribution of information where the Subject has subscribed to newsletters.

6. Scope and Categories of Personal Data Processed

6.1. For the purposes specified in Section 5 of this Policy, the Operator processes the following Personal Data provided by the User:

In relation to individual entrepreneur Users (having any entrepreneurial status or any other type of taxation system permitted in the country of incorporation):

● surname, first name, patronymic (if any);
● passport details;
● photograph;
● citizenship;
● date of birth;
● place of birth;
● registration address;
● gender;
● telephone number;
● email address;
● type of employment;
● TIN;
● bank details;
● amount of remuneration;
● service act details;
● information on registration as self-employed;
● details contained in a document replacing an identity document;
● details contained in an identity document;
● details contained in a migration card;
● details contained in a work permit;
● information on temporary registration;
● details contained in a medical record book (data is collected for the purposes of service provision, namely for the protection of the rights and lawful interests of the Subject or other persons);
● data on compulsory medical insurance or additional medical insurance policy, or on an agreement for paid medical services (name of insurance company / name of company providing paid medical services, series and number of the policy/agreement, date of issue of the policy/date of conclusion of the agreement);
● certificate confirming education in an educational organization (professional educational organizations, higher education organizations or scientific organizations under educational programs of secondary vocational education, bachelor’s programs, specialist programs, master’s programs, residency programs, assistantship-internship programs having state accreditation, or programs for training scientific and scientific-pedagogical personnel in postgraduate studies);
● details contained in a foreign citizen’s temporary residence permit and residence permit.

In relation to Users who are individuals without a business status:

● full name;
● passport details;
● photograph;
● citizenship;
● date of birth;
● place of birth;
● registration address;
● gender;
● telephone number;
● email address;
● type of employment;
● TIN;
● bank details;
● amount of remuneration;
● service act details;
● details contained in a document replacing an identity document;
● details contained in an identity document;
● details contained in a migration card;
● details contained in a work permit;
● information on temporary registration;
● details contained in a medical record book (data is collected for the purposes of service provision, namely for the protection of the rights and lawful interests of the Subject or other persons);
● data on compulsory medical insurance or additional medical insurance policy, or on an agreement for paid medical services;
● certificate confirming education in an educational organization.

In relation to Authorized Representatives of customer companies (counterparties):

● full name;
● contact telephone number;
● TIN or IIN;
● citizenship;
● passport details.

Method of Personal Data processing: automated.

Processing and storage period for Personal Data: 5 years after expiration of the agreement term.

Procedure for destruction of Personal Data: deletion of personal data from information carriers in accordance with clauses 9.8–9.9 of this Policy.

7. Procedure and Conditions for Personal Data Processing

7.1. The Operator shall cease Processing upon achievement of the Processing purposes, upon expiration or withdrawal by the Subject of consent to Processing, or upon identification of unlawful Processing. The Operator has the right to continue Processing in cases provided for by the Personal Data Law.

7.2. Personal Data is stored and processed for the period necessary to achieve the stated Processing purposes.

7.3. Personal Data is collected, stored, and processed within the territory of the Republic of Kazakhstan.

7.4. Personal Data is processed by the Operator both with and without computer technology and may exist in both paper and electronic form. The Operator complies with all requirements for automated and non-automated Personal Data Processing established by the Personal Data Law and related regulations.

7.5. The Operator may entrust the Processing of Personal Data to another person on the basis of an agreement or other arrangement concluded with such person (hereinafter, the “Operator’s Instruction”). In such case, the Operator obliges the person processing Personal Data under the Operator’s Instruction to comply with the principles and rules of Personal Data Processing established by the Personal Data Law.

7.6. If the Operator entrusts Processing of Personal Data to another person, the Operator remains responsible to the Personal Data Subject for the actions of that person. The person processing Personal Data under the Operator’s Instruction is responsible to the Operator.

7.7. The Operator may transfer the Subject’s Personal Data without the Subject’s consent to the following persons:

7.7.1. state authorities, including inquiry and investigation bodies, and local self-government bodies upon their reasoned request;

7.7.2. in other cases expressly provided for by the Personal Data Law.

7.8. The Operator undertakes, and requires other persons who have gained access to Personal Data, not to disclose Personal Data to third parties and not to disseminate Personal Data without the consent of the Personal Data Subject, unless otherwise provided by the Personal Data Law.

7.9. Personal Data is received by the Operator directly from the Personal Data Subject. In doing so, the Operator complies with all requirements for the Processing of such data established by the Personal Data Law and ensures the security of the received Personal Data.

8. Rights of Personal Data Subjects Whose Data Is Processed by the Operator

8.1. The Personal Data Subject has the right to receive information relating to the Processing of his or her Personal Data, including:

8.1.1. confirmation of the fact that the Operator is Processing his or her Personal Data;

8.1.2. the purposes of Personal Data Processing;

8.1.3. information about persons (except for employees of the Operator) who have access to Personal Data on the basis of the Personal Data Law;

8.1.4. other information provided for by the Personal Data Law.

8.2. The Personal Data Subject has the right to obtain information relating to the Processing of the Subject’s Personal Data by sending a request to the Operator indicating his or her Personal Data (full name, TIN/IIN, passport/identity document, date of birth, address, etc.). The request may be sent in the form of an electronic document to hello@akjet.kz.

8.3. The right of the Personal Data Subject to access his or her Personal Data may be restricted in accordance with the Personal Data Law, including where such access would infringe the rights and lawful interests of third parties.

8.4. If the Personal Data Subject believes that the Operator processes his or her Personal Data in violation of legal requirements or otherwise violates his or her rights and freedoms, the Subject has the right to appeal the actions or omission of the Operator to the authorized body in the field of Personal Data or in court.

8.5. The Personal Data Subject has the right to withdraw consent to the Processing of Personal Data. If such consent is withdrawn, the Operator may continue Processing Personal Data without the Subject’s consent in cases provided for by the applicable legislation of the Republic of Kazakhstan.

9. Obligations of the Operator

In accordance with the requirements of the Personal Data Law and the regulations adopted pursuant thereto, the Operator shall:

9.1. upon application or receipt of a request from the Personal Data Subject or his/her representative, provide information relating to the Processing of his/her Personal Data, or provide a reasoned refusal to provide such information in the form, cases, and within the time limits provided for by the Personal Data Law;

9.2. make necessary amendments to Personal Data, destroy it, notify the Personal Data Subject or his/her representative of the amendments made and measures taken, and take reasonable steps to notify third parties to whom the Subject’s Personal Data was transferred, in accordance with the Personal Data Law;

9.3. provide the authorized body in the field of Personal Data, upon its request, with the necessary information within up to ten working days;

9.4. upon achievement of the purpose of Personal Data Processing, cease Processing and destroy the relevant Personal Data in accordance with the Personal Data Law;

9.5. where the Personal Data Subject withdraws consent to the Processing of his or her Personal Data, cease Processing or ensure cessation of such Processing (if carried out by another person acting on behalf of the Operator), and destroy the Personal Data or ensure its destruction in accordance with the Personal Data Law.

10. Measures to Ensure the Security of Personal Data During Processing

10.1. When processing Personal Data, the Operator takes the necessary legal, organizational, and technical measures to protect Personal Data from unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination, and other unlawful actions in relation to Personal Data.

10.2. Ensuring the security of Personal Data is achieved, in particular, through:

10.2.1. the application of organizational and technical measures to ensure the security of Personal Data when processed in Information Systems, necessary to comply with Personal Data protection requirements;

10.2.2. detection of unauthorized access to Personal Data and taking measures to eliminate identified violations;

10.2.3. restoration of Personal Data modified or destroyed as a result of unauthorized access;

10.2.4. establishment of access rules for Personal Data processed in the Information System, as well as ensuring registration and accounting of all actions performed with Personal Data in the Information System;

10.2.5. monitoring the measures taken to ensure the security of Personal Data and the level of protection of Personal Data during Processing in the Information System;

10.2.6. implementation of other measures in accordance with the Personal Data Law.

11. Liability for Violation of the Rules Governing Personal Data Processing

Persons guilty of violating the requirements of the Personal Data Law, for the implementation of which this Policy has been developed, shall bear liability as provided for by the legislation of the Republic of Kazakhstan.