— Legal
Privacy Policy
Last updated
This Privacy Policy is issued by Oriental Expedition LLP, with its registered seat at 050026, Republic of Kazakhstan, Almaty, st. Dzhumalieva, building 86, in fulfilment of the information obligations set out in Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the applicable provisions of the law of the Republic of Kazakhstan, including the Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V “On Personal Data and Their Protection”.
Table of Contents
- Data Controller
- Categories of Personal Data Processed
- Mobile Applications
- Purposes of Processing and Legal Basis
- Recipients of Personal Data
- Data Retention Period
- Rights of the Data Subject
- Cookies and Similar Technologies
- Technical and Organizational Security Measures
- International Transfers of Personal Data
- Right to Lodge a Complaint with the Supervisory Authority
- Amendments to this Policy
- Contact Information
1. Data Controller
This Privacy Policy (the “Policy”) sets out the manner in which Oriental Expedition LLP (the “Company,” “Oriental Expedition,” or “the Controller”) collects, processes, stores, and protects personal data in connection with the operation of its website and the provision of related services. The Company acts as the data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, “GDPR”), and is accordingly responsible for ensuring that all processing of personal data is conducted in accordance with applicable law.
| Entity | Oriental Expedition LLP |
|---|---|
| Registered seat | 050026, Republic of Kazakhstan, Almaty, st. Dzhumalieva, building 86 |
| Correspondence regarding data protection | support@oriental-expedition.org |
The Company has assessed that, in view of the nature, scope, and purposes of its data processing activities, it is not required to designate a Data Protection Officer (“DPO”) pursuant to Article 37 GDPR. Notwithstanding the foregoing, all enquiries, requests, or concerns relating to the processing of personal data should be directed to the correspondence address set out above, and will be handled by the Company’s designated personnel responsible for data protection matters.
2. Categories of Personal Data Processed
The Company processes personal data solely to the extent that such data is voluntarily provided by the data subject (the “User” or “you”), for instance when the User contacts the Company by email, and to the extent of the technical data recorded in the web server’s logs described in Section 2.2. The Company does not currently employ cookies, analytics services, tracking pixels, or any comparable technologies on the website.
2.1 Enquiries sent by email
In connection with an enquiry sent to the Company by email, the Company processes the following categories of personal data:
- Given name and surname, where provided by the User
- Electronic mail (email) address
- The substantive content of the message submitted by the User
2.2 Server logs
When the website is accessed, the web server automatically records standard technical information in its access logs: the IP address of the device, the date and time of the request, the requested address, the response status and the amount of data transferred, the referring page, and the browser’s user-agent string. This information is used solely to deliver the website, to maintain its security, and to diagnose technical errors, and is not used to identify or profile Users.
Apart from the server logs described in Section 2.2, no personal data is, at present, collected automatically through the website. In the event the Company subsequently introduces analytics, tracking, or similar technologies, this Policy shall be amended accordingly, and, where required under applicable law, the prior consent of the User shall be obtained.
3. Mobile Applications
This Section applies to the mobile applications published by the Company on the Apple App Store and Google Play (each, an “App”). The specific data an individual App processes depends on its features; where an App processes data beyond what is described here, this is disclosed within the App and in its store listing. The other Sections of this Policy (data controller, your rights, complaint, and contact) apply to the Apps.
On-device data and accounts
Most of the Company’s Apps operate without a user account and do not require registration or sign-in. Where this is the case, the Company does not collect an e-mail address or login credentials through the App.
- Data you enter in an App — for example, profile or onboarding information and your preferences — together with content generated as you use it, such as usage history, is stored locally on your device.
- Unless an App expressly states otherwise, this data is not copied to the Company’s servers, and the App’s core features are computed on the device, including offline.
Optional inputs and permissions
- Certain inputs are optional and are used only to personalize the experience.
- Any free-text you type (for example, a place name) is treated as text you provide; it is not device location and not GPS.
- The Apps do not access location/GPS, camera, contacts or photos unless a specific feature requires it and you grant the corresponding permission.
Technical data
Depending on the App’s features, the following limited technical data may be processed:
- A push notification token (Apple Push Notification service), to deliver notifications you have enabled.
- A timestamp of your last App open, used to schedule notifications.
Notifications
Where you enable them, the Apps send notifications. On iOS, delivery uses the Apple Push Notification service and the stored push token. Notifications are typically scheduled locally on your device; an App may also use a server-side trigger to send a generic reminder. You can turn notifications off at any time in the App or in your system settings.
Subscriptions and payments
Where an App offers paid features, purchase and payment are handled entirely by the App Store (Apple) or Google Play (Google). The Company does not receive or store your payment card data. Terms of payment, renewal and refunds are governed by the rules of the relevant app store.
Advertising and tracking
The Apps contain no advertising and no advertising SDKs. The Company does not sell your data and does not carry out cross-app or cross-site advertising tracking. No App Tracking Transparency prompt is shown, because the Apps perform no such tracking.
Data deletion
Because App data is stored on your device, uninstalling an App — or using an in-App “delete data” option where one is provided — removes it. Requests concerning data may also be sent to the contact address in this Policy.
Children
The Apps are not directed at children, and the Company does not knowingly collect data from children under the applicable age of digital consent. If you believe a child has provided data, please contact the Company and it will be deleted.
4. Purposes of Processing and Legal Basis
| Purpose of processing | Legal basis under the GDPR |
|---|---|
| Receipt, evaluation, and response to enquiries sent by email | Article 6(1)(f) GDPR — legitimate interest of the Controller in responding to business enquiries; or, where applicable, Article 6(1)(b) GDPR — processing necessary for steps taken at the request of the data subject prior to entering into a contract |
| Operation and security of the website, including the recording of server logs | Article 6(1)(f) GDPR — legitimate interest of the Controller in ensuring the operation, security, and integrity of the website |
The Company shall not process personal data for any purpose incompatible with that for which it was originally collected, save where an additional, specific legal basis applies, including the separately obtained consent of the data subject or an applicable statutory obligation.
5. Recipients of Personal Data
The Company does not sell, rent, or otherwise commercially trade in personal data. Personal data is disclosed only to the following categories of recipients, and only to the extent strictly necessary for the operation of the website and the handling of User enquiries:
| Recipient | Purpose of disclosure |
|---|---|
| The Company’s hosting (server infrastructure) provider | Provision of website hosting infrastructure; storage of server logs |
| The Company’s electronic mail service provider | Delivery and storage of email correspondence with the Company |
| Apple Inc. and Google LLC (mobile application distribution platforms) | Where a User installs a mobile application of the Company through the Apple App Store or Google Play, certain data necessary for distribution, such as device and account identifiers, download and installation records, and, where applicable, in-app purchase information, is processed by the respective platform operator. See Section 10 below for further detail |
This Policy also serves as the privacy policy for any mobile application published by the Company on the Apple App Store and Google Play, as both platforms require every listed application to link to a publicly accessible privacy policy maintained by its publisher. The Company’s mobile applications do not maintain a separate privacy policy; they instead link to this Policy in fulfilment of that platform requirement. The data processed by the Apps themselves is described in Section 3; the data necessarily processed by Apple and Google in their capacity as distribution platforms is described in the table above and in Section 10 below.
Should the processing carried out by an App change in the future, this Policy will be updated accordingly to describe such processing before it takes place, and the relevant application’s own listing (the App Privacy section on the App Store, or the Data Safety section on Google Play) will be updated to reflect the same.
The Company does not disclose personal data to advertising networks, data brokers, or any third party for marketing purposes, and shall not do so in the future without first amending this Policy and, where required, obtaining the prior consent of the data subject.
6. Data Retention Period
| Category of data | Retention period |
|---|---|
| Enquiries sent by email (name and surname where provided, email address, message content) | A period of up to twelve (12) months from the date of submission, or until final resolution of the relevant enquiry, whichever period is longer |
| Server logs (IP address, date and time of the request, requested address, user-agent string) | Up to fourteen (14) days from the date of recording, after which they are deleted automatically |
Where a data subject requests earlier erasure of their personal data, the Company shall comply with such request within thirty (30) days, save where retention for a longer period is mandated by applicable law (including, without limitation, accounting or tax-related retention obligations arising from an actual commercial engagement).
7. Rights of the Data Subject
Pursuant to Chapter III of the GDPR, every data subject is entitled to exercise the following rights with respect to their personal data:
- Right of access (Art. 15) — to obtain confirmation of, and access to, the personal data processed by the Controller
- Right to rectification (Art. 16) — to request the correction of inaccurate or the completion of incomplete personal data
- Right to erasure (Art. 17) — to request erasure of personal data under the circumstances specified therein
- Right to restriction of processing (Art. 18) — to request that the Controller limit the processing of personal data
- Right to data portability (Art. 20) — to receive personal data in a structured, commonly used, machine-readable format
- Right to object (Art. 21) — to object, on grounds relating to one’s particular situation, to processing based on the Controller’s legitimate interest
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent, to withdraw such consent at any time, without affecting the lawfulness of processing carried out prior to its withdrawal
Any of the foregoing rights may be exercised by submitting a written request to support@oriental-expedition.org. The Company shall respond without undue delay and, in any event, within one (1) month of receipt of the request, in accordance with Article 12(3) GDPR.
8. Cookies and Similar Technologies
The website does not, as of the date of this Policy, employ cookies, web beacons, analytics services, or any comparable tracking technology. Accordingly, no monitoring of User browsing behaviour is undertaken by the Company through this website.
Should the Company introduce cookies at a future date (for instance, for the purpose of website analytics), this Section shall be amended accordingly, a cookie consent banner shall be implemented, and the prior consent of the User shall be obtained before any non-essential cookie is placed on the User’s device.
9. Technical and Organizational Security Measures
In accordance with Article 32 GDPR, the Company implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including, in particular:
- Encrypted transmission of data (HTTPS/TLS) across the entirety of the website
- Restriction of internal access to personal data received by email to authorized personnel only
- Reliance on reputable infrastructure providers maintaining their own security and regulatory compliance standards
In the event of a personal data breach giving rise to a risk to the rights and freedoms of natural persons, the Company shall notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 GDPR, and shall communicate the breach to the affected data subjects where required under Article 34 GDPR.
10. International Transfers of Personal Data
The Company is established in the Republic of Kazakhstan, and the website is hosted on server infrastructure used by the Company. Where personal data of Users located in the European Economic Area is processed outside of the European Economic Area, the Company applies the safeguards required under Chapter V GDPR, to the extent applicable, so as to ensure that the data subject’s personal data continues to benefit from a level of protection substantially equivalent to that guaranteed within the European Union.
By virtue of distributing applications through the Apple App Store and Google Play, certain data, such as device and account identifiers, download and installation records, and, where applicable, in-app purchase information, is necessarily processed by Apple Inc. and Google LLC, respectively, in their capacity as the operators of those platforms, both entities established in the United States. This processing is governed by each platform’s own privacy policy, available at:
apple.com/legal/privacy
policies.google.com/privacy
Should the Company’s mobile applications begin independently collecting additional personal data in the future, this Section and Section 3 above will be updated accordingly before such collection takes place.
11. Right to Lodge a Complaint with the Supervisory Authority
Without prejudice to any other administrative or judicial remedy, every data subject who considers that the processing of personal data relating to them constitutes an infringement of the GDPR has the right to lodge a complaint with a supervisory authority, in particular with the supervisory authority of the Member State of their habitual residence, place of work, or place of the alleged infringement. Data subjects may also lodge a complaint with the authorized body of the Republic of Kazakhstan in the field of personal data protection.
The Company respectfully requests that, prior to lodging any such complaint, the data subject afford the Company a reasonable opportunity to address the matter directly, by contacting support@oriental-expedition.org.
12. Amendments to this Policy
The Company reserves the right to amend this Policy from time to time, including, without limitation, where it introduces new functionalities, technologies (such as cookies or analytics tools), or services. Any such amendment shall be published on this page together with an updated revision date set out at the head of this Policy. Data subjects are advised to consult this page periodically in order to remain informed of the then-current version of this Policy.
13. Contact Information
All enquiries concerning this Policy or the Company’s processing of personal data should be directed as follows:
| Entity | Oriental Expedition LLP |
|---|---|
| Electronic mail | support@oriental-expedition.org |
| Registered seat | 050026, Republic of Kazakhstan, Almaty, st. Dzhumalieva, building 86 |