Personal Data Processing and Protection Policy

Revision of August 20, 2026

This Personal Data Processing and Protection Policy (hereinafter, the Policy) has been prepared by ООО «2REELS AGENCY» (hereinafter, the Operator or the Company) in accordance with Law No. ZRU-547 of the Republic of Uzbekistan of July 2, 2019 "On Personal Data," the Law "On Principles and Guarantees of Freedom of Information," and the Law "On Informatization," and establishes the procedure for processing personal data in the Erkatooy.ERP information system (hereinafter, the Information System).

The Operator processes personal data as the operator and owner of the personal data database within the meaning of the Law "On Personal Data." Organizations (preschool educational organizations) using the Information System independently determine the scope of data entered about their children and legal representatives, and must have a lawful basis for providing it to the Operator — in particular, the consent of the child's legal representative, obtained by the Organization itself or through the consent mechanism built into the Information System, described in Section 4 of this Policy.

Use of the Information System — and, for Parents, also confirming consent in the Personal Account upon registration — means that the user has fully reviewed this Policy and agrees to the processing of personal data on the terms set out herein.

Ensuring the confidentiality and security of personal data processing through the Information System is one of the priority objectives of ООО «2REELS AGENCY».

1. Scope of Application

1.1. This Policy applies to personal data processed by the Operator through the Information System, regardless of whether it was obtained before or after this version takes effect.

1.2. This Policy applies to the personal data of Organizations' Staff Members, Parents, and children.

2. Terms and Definitions

2.1. The following terms are used in this Policy:

  • personal data — information relating to an identified natural person or allowing such a person to be identified, recorded in electronic form, on paper, and/or on another physical medium;
  • subject of personal data (subject) — a natural person to whom personal data relates;
  • personal data database — the database of the Information System containing personal data;
  • processing of personal data — the collection, systematization, storage, modification, supplementation, use, disclosure, dissemination, transfer, de-identification, and destruction of personal data;
  • personal data database operator (Operator) — ООО «2REELS AGENCY», which carries out the collection, systematization, storage, and other actions with personal data through the Information System;
  • personal data database owner — ООО «2REELS AGENCY» as the party that holds the right to possess, use, and dispose of the Information System's personal data database;
  • Organization — a preschool educational organization that uses the Information System and enters into it data about its children and their legal representatives;
  • confidentiality of personal data — the mandatory requirement not to disclose or disseminate personal data without the subject's consent or in the absence of another lawful basis;
  • blocking (restriction) of personal data — the temporary suspension of processing, except where processing is necessary to correct the data;
  • user — a Staff Member of the Organization or a Parent who has been granted access to the Information System.

3. Legal Grounds and Purposes of Processing

3.1. Data is processed through the Information System in accordance with the Constitution of the Republic of Uzbekistan, the Law "On Personal Data," the Civil and Tax Codes, and other legislative acts of the Republic of Uzbekistan.

3.2. Personal data is processed in the following cases:

  • the subject has consented to the processing of the data;
  • processing is necessary for the performance of an agreement to which the subject is a party, or to take steps at the subject's request before entering into such an agreement;
  • processing is necessary for the Operator to fulfill obligations established by legislation;
  • processing is necessary to protect the legitimate interests of the subject or another person;
  • processing is necessary to exercise the rights and legitimate interests of the Operator or a third party, or to achieve socially significant purposes, provided the rights of the subject are not violated;
  • the data is processed for statistical or other research purposes, subject to mandatory de-identification;
  • the data was obtained from publicly available sources.

3.3. The subject of personal data independently decides whether to provide their data and gives consent freely, of their own will and in their own interest.

4. Legal Representative's Consent to Process a Child's Data

4.1. The processing of a child's (minor's) personal data is permitted only with the written consent of their legal representative — a parent, guardian, or custodian — or, in their absence, the guardianship and custodianship authority, in accordance with the Law "On Personal Data."

4.2. Consent is given as an electronic document by means of a checkbox in the Parent's Personal Account upon first logging in to the Information System, and is recorded together with the date, time, and version of the text of this Policy to which consent was given. Access to the functions of the Parent's Personal Account is not granted until this action is completed.

4.3. If this Policy is materially amended, consent is requested again.

4.4. Consent to publish photographs and videos of a child in the Information System's news feed and reports is separate and not mandatory. A Parent may give or withdraw such consent at any time in the Personal Account.

5. Categories of Personal Data Processed

5.1. Data of legal representatives (Parents):

  • full name; date and year of birth; gender; citizenship; city;
  • email address and/or phone number;
  • identity document data;
  • information on education, profession, and qualifications — where entered by the Parent.

5.2. Data of a child:

  • full name; date and year of birth; gender; citizenship;
  • identity document details (birth certificate);
  • a photograph — for identification purposes when recording attendance (see Clause 5.3);
  • health information entered in the Organization's medical log (allergies, chronic conditions, medical-observation notes) — processed with enhanced protective measures and available only to authorized Staff Members of the Organization;
  • information on academic performance and development, entered by the Organization's teachers;
  • other data necessary for the Organization to provide its services.

5.3. Data related to access control and facial recognition. Where the Organization uses access-control terminals, facial recognition itself is performed by the terminal's hardware: the biometric template is generated and stored exclusively on the terminal and is not transmitted to the Information System. The Information System receives: the reference photograph of the child or Staff Member submitted for registration on the terminal, and pass events (date, time, direction, result), and, where the terminal is technically capable, an event snapshot. Event snapshots are stored for 3 (three) calendar months from creation and are automatically deleted once this period expires; the reference photograph is stored until the child or Staff Member is removed from the access-control system.

5.4. Financial data: information on charges, payments, and transaction history, including data transmitted to the payment aggregator when a Parent pays for the Organization's services.

6. Principles of Processing

  • observance of the constitutional rights and freedoms of individuals and citizens;
  • the lawfulness of the purposes and methods of processing personal data;
  • the accuracy and reliability of personal data;
  • the confidentiality and protection of personal data;
  • the equal rights of subjects, owners, and operators;
  • the security of personal data processing in accordance with the requirements of national legislation.

7. Recipients of Data and Cross-Border Transfer

7.1. The Operator does not disclose personal data to third parties, except as established by the legislation of the Republic of Uzbekistan or for the purpose of providing the Services, to the following parties, which process data on the Operator's instructions:

  • Payme (payment system operator, Republic of Uzbekistan) — for accepting payments for the Organization's services;
  • Google LLC, the Firebase Cloud Messaging service — for delivering push notifications to users' mobile devices;
  • Google LLC, the Gemini API — for transcribing Staff Members' voice notes and for automated-analysis features when a Staff Member uses the relevant functions of the Information System; children's photographs and videos are not transmitted for this processing;
  • Telegram FZ-LLC — for sending service notifications on the Operator's behalf, and, where the Organization has independently enabled this feature, for the Organization's correspondence with persons who contact it through the Telegram account the Organization has linked;
  • the Information System's hosting provider.

7.2. Some of the recipients listed above are located outside the Republic of Uzbekistan. Such transfers are carried out only to the extent necessary for the corresponding function of the Information System to operate, and do not extend to biometric templates (Clause 5.3), which never leave the access-control terminal.

7.3. The Operator must not disclose or disseminate personal data to third parties without the subject's consent, except as established by legislation.

8. Data Protection Requirements

8.1. When processing data, the Operator takes the necessary legal, organizational, and technical measures to protect it from unlawful access, destruction, modification, blocking, copying, dissemination, and other unlawful actions.

8.2. Such measures include, in particular:

  • appointing a person responsible for organizing data processing and a person responsible for data security;
  • developing and approving internal documents on data processing and protection;
  • identifying threats to data security during processing and taking measures to eliminate them;
  • detecting instances of unauthorized access to data and preventing similar cases in the future;
  • restoring data modified or destroyed as a result of unauthorized access;
  • preventing unauthorized access to physical data carriers.

9. Data Processing (Retention) Periods

9.1. Specific retention periods for personal data by category:

  • Parents' data — for the term of the Organization's agreement with the Parent and 3 years after its termination (in accordance with the requirements of tax legislation);
  • children's data — for the duration of their enrollment with the Organization and 3 years after graduation;
  • access-control facial-recognition event snapshots — 3 months from creation, then automatic deletion (Clause 5.3);
  • health information — for the duration of the child's enrollment with the Organization, unless a different period is established by archival legislation;
  • financial data — at least 5 years, in accordance with the tax legislation of the Republic of Uzbekistan.

9.2. Data whose retention period has expired must be destroyed, unless legislative acts provide for a different procedure. After processing ends, data may be retained only after it has been de-identified.

9.3. Personal data is subject to destruction, in particular:

  • when the purpose of processing has been achieved;
  • when the subject withdraws their consent;
  • upon expiry of the processing period specified in the subject's consent;
  • when a court decision enters into legal force.

10. Rights of the Data Subject and Procedure for Requests

10.1. A subject whose data is processed by the Information System has the right to receive from the Operator:

  • confirmation that their data is being processed, and information on whether data relating to them exists;
  • information on the legal grounds and purposes of processing;
  • information on the methods of data processing;
  • information on the Operator's name and location;
  • information on the persons who have access to the data or to whom it may be disclosed;
  • a list of the data being processed and information on the source from which it was obtained;
  • information on the conditions of processing, including retention periods;
  • the right to require the data to be corrected, blocked, or destroyed if it is incomplete, outdated, inaccurate, unlawfully obtained, or unnecessary for the stated purpose;
  • the right to withdraw consent to processing at any time;
  • the right to require the Operator to remedy unlawful actions with respect to their data.

10.2. The Operator reviews a data subject's request and provides a response within 15 (fifteen) calendar days of receiving it.

10.3. An official request must include:

  • the full name of the data subject or their representative;
  • the identity document details of the data subject or their representative;
  • information confirming the data subject's connection to the Organization;
  • contact details for sending a response;
  • the signature of the data subject or their representative; for a request submitted electronically, an electronic signature in accordance with the legislation of the Republic of Uzbekistan.

11. Localization and Registration of the Personal Data Database

11.1. The Operator ensures the collection, systematization, and storage of the personal data of citizens of the Republic of Uzbekistan on technical equipment physically located in the Republic of Uzbekistan, to the extent established by legislation, including biometric data, for which the localization requirement applies in full regardless of the category of other personal data.

11.2. Personal data in the Information System is processed in compliance with the requirements for registering personal data databases in the State Register of Personal Data Databases established by the legislation of the Republic of Uzbekistan.

12. Confidentiality of Personal Data

12.1. The confidentiality of personal data is a mandatory requirement, binding on the Operator or any other person who has obtained access to the data, not to disclose or disseminate it without the subject's consent or in the absence of another lawful basis.

12.2. The Operator must not disclose or disseminate personal data to third parties without the subject's consent, except as established by legislation.

13. Final Provisions

13.1. This Policy is public. Public access to it is ensured by its publication on the Operator's website.

13.2. This Policy may be revised, in particular:

  • when the legislation of the Republic of Uzbekistan on personal data changes;
  • at the direction of an authorized government body;
  • by decision of the Operator's management;
  • when the purposes and conditions of data processing change;
  • when the technologies used for processing and protecting data change.

13.3. For non-compliance with the provisions of this Policy, the Operator and its employees are liable in accordance with the legislation of the Republic of Uzbekistan.

13.4. Compliance with the requirements of this Policy is monitored by the persons within the Company responsible for organizing data processing and for data security.

14. Feedback

14.1. Questions or objections regarding the Policy may be sent to the email address support@erkatooy.uz.

15. Amendments to the Policy

15.1. The Operator may amend the Policy. The subject of personal data must review the text of the Policy each time they use the Information System or enter into a new agreement.

15.2. A new version of the Policy takes effect from the moment it is posted in the Information System. Continued use of the Information System after a new version is published constitutes full and unconditional acceptance of it. If the subject disagrees with the terms of the Policy, they must stop using the Information System.

The official text of this document is in Russian. In the event of a discrepancy in interpretation between language versions, the Russian version prevails.

Privacy Policy — Erkatooy