Privacy Policy

This document outlines the Data Controller’s policy regarding the processing of personal and other confidential data, types of personal data, rights and obligations of the Operator and Personal Data Subjects as parties to personal data processing.

1. Terms and Definitions

1.1. For the purpose of this Policy, the following terms have the meanings set forth below:

i. Personal (Confidential) Data means any information relating to an identified personal data subject or a personal data subject identifiable by such information, which is stored on electronic, paper-based and/or other physical media.

ii. Data Controller (BellFast LLP (Business Identification Number (BIN) 130240017651)) means an entity that independently collects, processes, and protects personal data, as well as exercises, in accordance with the laws of the Republic of Kazakhstan, the rights of ownership, use, and disposal over a database containing personal data.

iii. Processing of Personal Data means actions directed at the accumulation, storage, modification, supplementation, use, dissemination, de-identification, blocking, and destruction of personal data.

iv. Provision of Personal Data means actions resulting in granting access to personal data by any other means.

v. Blocking of Personal Data means actions directed at the temporary suspension of the collection, accumulation, modification, supplementation, use, dissemination, de-identification, and destruction of personal data.

vi. Destruction of Personal Data means actions that render any restoration of personal data impossible.

vii. Personal Data Information System means a set of personal data contained in databases, together with the information technologies and technical facilities that ensure its processing.

viii. Dissemination of Personal Data means actions resulting in the transfer of personal data, including through the mass media, or the granting of access to personal data by any other means.

ix. Mobile Application. The term “Mobile Application” means the following computer programs:

– “TaxSee,” a computer program designed for Android or iOS operating systems that is installed on the User’s device and automates the placement of service orders.

– “Taxsee Driver,” a computer program designed for Android or iOS operating systems that is installed on the User’s device and automates the User’s access to information regarding existing orders for specific services.

x. Website means a set of computer programs and other information contained in an information system, which is accessed via the Internet by domain names and/or network addresses that allow the identification of websites on the Internet.

The addresses of the websites where the Data Controller collects and subsequently processes personal data are: https://soft-taxi.com/, and other web sites with domain names derived from https://soft-taxi.com/.

xi. Personal Data Subject means a natural person to whom the personal data relates.

xii. Cookies mean data fragments sent by the Website and stored on the computer, mobile phone, or other device which the User utilizes to visit the Website, used to store information regarding the User’s actions on the Website.

xiii. Device Identifier means unique data that enable the identification of the User’s device on which the Mobile Application is installed, which is either provided by the device itself or generated by the Mobile Application.

2. General Provisions

2.1. The processing of personal data is carried out by the Data Controller in accordance with the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013 (hereinafter also referred to as Law No. 94-V) and other requirements of the legislation of the Republic of Kazakhstan in the field of personal data.

2.2. Categories of personal data subjects whose data is processed by the Data Controller in accordance with this Policy are as follows:

  1. Users: Partners and Clients. For the purposes of this Policy, Partner means a user of the “Taxsee Driver” mobile application who independently and through their own efforts provides services to the Client. For the purposes of this Policy, Client means a user who uses the “TaxSee” mobile application and the Website to order services from Partners.

  2. Natural persons who are or have been in an employment relationship with the Data Controller, as well as persons intending to enter into such relationships (job applicants, candidates for vacant positions).

  3. Natural persons who are or have been in civil law relationships with the Data Controller, as well as persons intending to enter into such relationships.

  4. Visitors to the Website and other information resources of the Data Controller.

  5. Natural persons completing internships from at the Data Controller through educational institutions.

  6. Natural persons who have contacted the Data Controller with requests, messages, applications, complaints, or proposals using the contact information or feedback collection tools on the Website.

  7. Natural persons participating in interviews, surveys, and analytical and marketing research related to the Data Controller’s business activities.

2.3. The processing of personal data may be carried out after obtaining the consent of the Personal Data Subject to the processing of personal data in the manner established by the current legislation of the Republic of Kazakhstan, in writing, as well as in the form of the Personal Data Subject performing conclusive actions, including:

  1. installation of the Mobile Application by the User on their device or use of the Mobile Application in any other manner, as well as use of the Website;

  2. acceptance of the terms and conditions of the public offer agreement, license agreement, or rules for using the information resources and software products of the Data Controller;

  3. continued use of the applications, services, information resources, and Websites of the Data Controller, and interaction with their user interfaces after being notified about the processing of personal data, including the submission of requests, messages, applications, complaints, or proposals by an individual to the Data Controller using the contact information or feedback collection tools on the Website;

  4. granting the necessary permissions to the Mobile Application upon request at the time of installation or use;

  5. maintaining electronic correspondence that addresses the processing of personal data;

  6. entering the territory of the Data Controller after becoming acquainted with the warning signs and notices;

  7. other actions performed by the Personal Data Subject which can infer their expression of intent regarding consent to the processing of personal data.

2.4. In some cases, if the Personal Data Subject refuses to provide their personal data in the necessary and sufficient volume, the Data Controller will be unable to take the necessary actions to achieve the relevant processing purposes. In particular, in such a case, the User’s registration in the software product may not be completed, services under the agreement may not be rendered, and work may not be performed.

2.5. The processing of personal data that the Personal Data Subject has permitted for dissemination is carried out in accordance with the requirements stipulated in the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013.

The dissemination of personal data of contact persons posted on the Data Controller’s Website in the “Contacts” section is carried out with the consent of said persons. No prohibitions or conditions have been established regarding the processing by an unlimited circle of persons of personal data that the Personal Data Subject has permitted for dissemination.

3. Partner’s Personal Data Processing

3.1. The purpose of collecting and processing the Partner’s personal data is to enter into and perform the agreement granting the Partner the right to use the “Taxsee Driver” Mobile Application. When collecting and processing personal data, the Data Controller pursues no purposes other than those related to the performance of the said agreement.

3.2. The Data Controller may collect and process the following categories of the Partner’s personal data:

  1. data identifying the Partner;

  2. geolocation data;

  3. payment data;

  4. data regarding the mobile network operator;

  5. data regarding the Partner’s device;

3.3. Data Identifying the Partner

This category includes data directly relating to the Partner’s identity:

  1. last name, first name, and patronymic;

  2. date of birth;

  3. gender;

  4. identity document details;

  5. details of the document certifying the right to drive a vehicle;

  6. details of the document confirming the right of ownership of a vehicle;

  7. details of the Partner’s vehicle (make, model, color, vehicle registration number);

  8. telephone number;

  9. photographic image.

3.4. Geolocation Data.

3.4.1. The Data Controller receives data on the location of the Partner's device (geolocation data) via the “Taxsee Driver” Mobile Application. Geolocation data is transmitted to the Data Controller only during the use of the Mobile Application.

3.4.2. For the purpose of providing services to the Client, the Data Controller may provide the Client with data on the Partner’s location.

3.5. Payment Data.

3.5.1. To enable the payment of the license fee for the use of the “Taxsee Driver” Mobile Application via cashless payment using bank cards, the Partner may link a bank card to their ID number. The bank card is linked by the Partner independently in the Mobile Application by entering the following details:

1) bank card number;

2) bank card expiration date;

3) last name and first name of the bank cardholder;

4) bank card security code.

3.5.2. Cashless payments using bank cards are processed in accordance with the rules of international payment systems, adhering to the principles of transaction confidentiality and security. The security of the data provided by the Partner is ensured by the compliance of procedures with the requirements of the Payment Card Industry Data Security Standard (PCI DSS), and no one, including the Data Controller, can access or obtain this data. Bank card details are entered on the secure payment page of the acquiring bank, which enables cashless payment for the services.

3.5.3. To withdraw funds held in the account, the Partner provides the Data Controller with details of an account opened at a credit institution, as well as other information necessary for the transfer of funds, namely:

1) the recipient’s account number at the credit institution;

2) the recipient’s last name, first name, and patronymic;

3) debit or credit (bank) card number.

3.5.4. The data provided by the Partner for the purpose of withdrawing funds from the account does not allow the Data Controller to perform any operations other than crediting funds to the Partner’s bank account.

3.6. Data regarding the mobile network operator.

3.6.1. The Data Controller, via the Mobile Application, receives data regarding the mobile network operator providing the Partner with mobile (cellular) communication services.

3.6.2. The collected data regarding the mobile network operator do not contain the Partner’s personal data.

3.6.3. The purpose of collecting information about the mobile network operator is to automatically determine, within the Mobile Application settings, the country of the Partner’s location and the language of the Mobile Application interface.

3.7. Data regarding the Partner’s device.

3.7.1. The Data Controller, via the Mobile Application, receives data regarding the Partner’s device, the applications installed on it, and the Internet connection. This category includes information about the device model, operating system, browser data, IP address, and device identifiers.

3.7.2. The collected data regarding the Partner’s device does not contain the Partner’s personal data.

3.7.3. The purpose of collecting information about the Partner’s device is the internal accounting of Mobile Application users, as well as the improvement of its operation.

4. Client’s Personal Data Processing

4.1. The purpose of collecting and processing the Client’s personal data is to enter into and perform the agreement, the subject matter of which is defined in the Data Controller’s Public Offer posted on the Website. When collecting and processing personal data, the Data Controller pursues no purposes other than those related to the performance of the said agreement.

4.2. The Data Controller may collect and process the following personal data of the Client:

  1. data identifying the Client;

  2. geolocation data;

  3. payment data;

  4. data regarding the mobile network operator;

  5. data regarding the Client’s device.

4.3. Data Identifying the Client.

4.3.1. This category includes data directly relating to the Client's identity:

  1. last name, first name, and patronymic;

  2. date of birth;

  3. gender;

  4. telephone number;

  5. email address.

4.3.2. The personal data listed below may be provided to the Data Controller at the Client’s discretion, and may also be changed and/or deleted by the Client at any time. The Data Controller does not verify the accuracy of this data; however, failure to provide it may render some services provided by the Data Controller unavailable:

  1. last name, first name, and patronymic;

  2. date of birth;

  3. gender;

  4. email address.

4.4. Geolocation data.

The Data Controller receives data on the location of the Client’s device (geolocation data) via the “TaxSee” Mobile Application. Geolocation data is transmitted to the Data Controller only during the use of the “TaxSee” Mobile Application. The Client may, at their discretion, prohibit the transmission of geolocation data by changing the relevant settings on their device.

4.5. Payment Data.

4.5.1. To enable the payment for the Partners’ services via cashless payment using bank cards, the Client may link a bank card to their personal account. The bank card is linked by the Client independently by entering the following details:

  1. bank card number;

  2. bank card expiration date;

  3. last name and first name of the bank cardholder;

  4. bank card security code.

4.5.2. Cashless payments using bank cards are processed in accordance with the rules of international payment systems, adhering to the principles of transaction confidentiality and security. The security of the provided data is ensured by the compliance of procedures with the requirements of the Payment Card Industry Data Security Standard (PCI DSS), and no one, including the Data Controller and the Partners, can access or obtain this data. Bank card details are entered on the secure payment page of the acquiring bank, which enables cashless payment for the services.

4.6. Data regarding the mobile network operator.

4.6.1. The Data Controller, via the Mobile Application, receives data regarding the mobile network operator providing the Client with mobile (cellular) communication services.

4.6.2. The collected data regarding the mobile network operator do not contain the Client’s personal data.

4.6.3. The purpose of collecting information about the mobile network operator is to automatically determine, within the Mobile Application settings, the country of the Client’s location and the language of the Mobile Application interface.

4.7. Data regarding the Client’s device.

4.7.1. The Data Controller, via the Mobile Application, receives data regarding the Client’s device, the applications installed on it, and its Internet connection. This category includes information about the device model, operating system, browser data, IP address, and device identifiers.

4.7.2. The collected data regarding the device does not contain the Client’s personal data.

4.7.3. The purpose of collecting information about the device is the internal accounting of Mobile Application users, as well as the improvement of its operation.

5. Processing of personal data of natural persons who are or have previously been in an employment relationship with the Data Controller, as well as persons intending to enter into such relationships (job applicants, candidates for vacant position substitutes).

5.1. Personal data is processed for the following purposes:

  1. considering employment and the suitability of the candidate for available vacancies;

  2. entering into and regulating employment and other relationships directly related thereto;

  3. carrying out pre-employment activities necessary for hiring, including the preparation of draft employment agreements and other HR documents for the first day of employment, as well as the processing of benefits and deductions provided for by current legislation;

  4. granting access to the Data Controller’s information system for electronic document management in the field of employment relations, including the creation of a personal account in the Data Controller’s information system (in cases where the Data Controller uses such an information system).

5.2. List of personal data subject to processing:

  1. last name, first name, and other given names;

  2. gender;

  3. date and place of birth;

  4. citizenship;

  5. identity document details (a foreign national’s residence permit of the Republic of Kazakhstan, or a stateless person’s certificate, or a refugee certificate, applicable to foreign nationals and stateless persons permanently residing in the territory of the Republic of Kazakhstan);

  6. birth certificate details;

  7. registered address and actual residential address;

  8. Individual Identification Number (IIN);

  9. military registration status;

  10. telephone number;

  11. email address;

  12. education, profession, qualification, and vocational training document details, as well as information on advanced training;

  13. details contained in the employment record book and information on the employee’s employment history;

  14. marital status and family composition details that may be required by the employer to provide benefits stipulated by labor and tax legislation;

  15. information about work experience, previous places of employment, and income from previous places of employment;

  16. information about standard, social, and property tax deductions;

  17. health information related to the ability to perform employment duties;

  18. photographic and video images;

  19. bank card and bank account details.

6. Processing of personal data of natural persons who are or have been in a civil law relationship with the Data Controller, as well as persons intending to enter into such relationships

6.1. The processing of personal data is carried out for the purpose of concluding and regulating civil law and other relationships directly related thereto.

6.2. List of personal data subject to processing:

  1. last name, first name, and patronymic;

  2. gender;

  3. date and place of birth;

  4. citizenship;

  5. identity document details (a foreign national’s residence permit in the Republic of Kazakhstan, or a stateless person’s certificate, or a refugee certificate, applicable to foreign nationals and stateless persons permanently residing in the territory of the Republic of Kazakhstan);

  6. birth certificate details;

  7. registered address and actual residential address;

  8. Individual Identification Number (IIN);

  9. telephone number;

  10. email address;

  11. photographic image;

  12. bank card and bank account details.

7. Processing of personal data of visitors to the Web Site and other information resources of the Data Controller

7.1. The Data Controller may collect electronic user data on its Websites automatically, without the Personal Data Subject's involvement or any action on their part to transmit the data. The accuracy of electronic data collected in this manner is not verified by the Data Controller; the information is processed “as is” exactly as it was received from the Personal Data Subject's device.

7.2. Visitors to the Websites may be shown pop-up notifications regarding the collection and processing of data via cookies, containing a link to this Policy and buttons to close the notification. Such notifications indicate that when visiting and using the Websites, information resources, and web applications of the Data Controller, a technology for storing and retrieving data using the Personal Data Subject’s device will be utilized (e.g., storing and retrieving cookie data). This technology enables the subsequent identification of the Personal Data Subject or their device, remembering the session, or saving specific settings and preferences for these particular Websites. Once stored in the browser, such information will be transmitted with every subsequent request to the Website from which it was stored, along with the request itself for processing on the Data Controller's end, until its expiration or deletion from the device.

7.3. The processing of cookie data is necessary for the Data Controller to ensure the proper functioning of the Websites, specifically for functions related to registered users' access to the Data Controller’s software products, services, works, and resources; personalization for Website users; and enhancing the efficiency and convenience of using the Websites.

7.4. In addition to processing cookies set by the Data Controller’s own Websites, cookies relating to third-party websites may be set for Personal Data Subjects, for example, in cases where third-party components and software are used on the Data Controller’s websites. The processing of such cookies is governed by the policies of the respective third-party websites to which they relate, and may change without notice to the users of the Data Controller’s Websites. Such cases may include the placement on the websites of:

  1. visit counters, the Google Analytics analytical and statistical service, and other similar services for collecting Website visit statistics;

  2. widgets of auxiliary services for collecting feedback, organizing chats, and other types of communications;

  3. contextual advertising systems, banner, and other marketing networks;

  4. authorization buttons for logging into websites using social media accounts;

  5. other third-party components used by the Data Controller on its Websites.

7.5. Accepting the cookie processing terms or closing the pop-up notification constitutes the Personal Data Subject’s consent to the processing of cookie data on the Data Controller’s Websites, as well as consent to the processing of personal data to the extent of the information collected in accordance with this Policy using cookies.

7.6. If the Personal Data Subject does not consent to the processing of cookies, they assume the risk that the functions and features of the Websites may be available only to a limited extent, and must then choose one of the following options:

  1. independently configure their browser in accordance with its documentation or help section to permanently block the receipt and transmission of cookie data for all websites, or specifically for the Data Controller’s Website or a third-party component website;

  2. switch to the browser's special “incognito” mode, which limits the website’s use of cookies until the browser window is closed or normal mode is restored;

  3. leave the website to avoid further processing of cookies.

8. Processing of personal data of natural persons who have contacted the Data Controller with requests, messages, applications, complaints, or proposals using the contact information or feedback collection tools on the Website.

8.1. A natural person may send the Data Controller requests, messages, applications, complaints, or proposals (hereinafter referred to as “inquiries”), which contain the following personal data:

  1. last name, first name, and patronymic (if any);

  2. telephone number;

  3. email address;

  4. postal address.

Submitting an inquiry means that the natural person submitting it provides the Data Controller with specific, pertinent, informed, conscious, and unambiguous consent to the processing of the personal data specified in the inquiry, in accordance with the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013 and under the terms of this Policy.

8.2. The purpose of processing the personal data of natural persons who have contacted the Data Controller with inquiries is for the Data Controller to consider the inquiry and provide the Personal Data Subject with a substantive response regarding the subject matter of such inquiry.

8.3. Depending on the nature of the inquiry, the Personal Data Subject may provide the Data Controller with additional personal data. In this case, the scope of the provided personal data is determined at the discretion of such Personal Data Subject. Submitting such personal data constitutes the Personal Data Subject’s consent to its processing by the Data Controller.

8.4. If an inquiry contains the personal data of third parties, the Personal Data Subject must independently obtain the consent of such third parties for the processing of their personal data by the Data Controller. In this case, the Data Controller presumes that such third parties have given their consent to the processing of their personal data.

9. Processing of personal data of natural persons participating in interviews, surveys, and analytical and marketing research related to the Data Controller’s business activities.

9.1. Personal data is processed for the purpose of the Data Controller conducting interviews, surveys, and analytical and marketing research related to its business activities, in order to improve the quality of the services provided and expand the scope of its activities.

9.2. List of personal data subject to processing:

  1. last name, first name, and patronymic (if any);

  2. date of birth;

  3. gender;

  4. registered address (city, district) and actual residential address (city, district);

  5. telephone number;

  6. photographic image;

  7. email address.

Measures for the protection of personal data

10.1. The Data Controller takes necessary and sufficient legal, organizational, and technical measures to ensure the security of personal data by protecting it from unauthorized (including accidental) access, destruction, modification, blocking of access, and other unauthorized actions. Such measures include, in particular:

  1. the appointment of persons responsible for organizing the processing and ensuring the security of personal data;

  2. the issuance of internal policies and regulations regarding personal data processing and information security, and familiarizing employees with them;

  3. training employees on personal data processing and ensuring information security during the processing of personal data;

  4. restricting and differentiating the access of employees and other persons to personal data and processing facilities, and monitoring actions involving personal data;

  5. identifying threats to the security of personal data during their processing in personal data information systems, developing information security threat models based on them, and defining and implementing personal data protection measures to neutralize information security threats;

  6. the use of security tools (antivirus software, firewalls, unauthorized access protection tools, and cryptographic information protection tools), including, where necessary, those that have undergone the conformity assessment procedure in the prescribed manner;

  7. the accounting and storage of storage media containing personal data in a manner that precludes their theft, substitution, unauthorized copying, and destruction;

  8. information backup to enable data recovery;

  9. conducting internal control over compliance with established procedures, verifying the effectiveness of the measures taken, and responding to incidents;

  10. verifying the presence of, and if necessary, including in agreements, clauses on ensuring the confidentiality and security of personal data;

  11. other measures in accordance with the Data Controller's internal policies and regulations.

11. Procedure for Withdrawing Consent to the Processing of Personal Data

11.1. The Personal Data Subject may withdraw their consent to the collection, processing, dissemination in publicly available sources, transfer to third parties, and cross-border transfer of personal data, except in cases stipulated by the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013, including in the presence of an unfulfilled obligation. The request is sent to the Data Controller or its authorized representatives by mail, submitted in person, or sent by another method that allows confirmation of the request’s receipt.

11.2. Where technically feasible, the Data Controller provides the User with the opportunity to withdraw their consent to the processing of personal data by filling out an electronic application form posted on the Website, as well as via the “Delete Account” function in the Mobile Application.

12. Periods for Processing and Storage of Personal Data

12.1. The processing and storage of personal does not exceed the period necessary to fulfill the purposes of personal data processing, or until the Personal Data Subject withdraws their consent to the processing of personal data, except in cases where the processing and storage of personal data are determined by the agreement of the parties or current legislation.

12.2. Personal data is stored for the retention periods of documents for which such periods are provided for by the legislation of the Republic of Kazakhstan.

12.3. In the event of the achievement of the processing purpose, withdrawal of consent to the processing of personal data, or termination of the processing of personal data on other grounds, the Data Controller may continue processing personal data if this is provided for by an agreement between the Personal Data Subject and the Data Controller, or a contract to which the Personal Data Subject is a party, beneficiary, or guarantor, as well as in cases established by the current legislation of the Republic of Kazakhstan.

13. Personal Data Destruction Procedure

13.1. Personal data shall be destroyed in the following cases:

  1. upon the expiration of the retention period in accordance with the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013;

  2. upon termination of legal relations between the Personal Data Subject, the owner, and (or) the Data Controller, as well as a third party;

  3. upon a court decision entering into legal force;

  4. upon the discovery of the collection and processing of personal data without the consent of the Personal Data Subject or their legal representative, except in cases provided for by the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013;

  5. in other cases established by the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” dated May 21, 2013 and other normative legal acts of the Republic of Kazakhstan.

13.2. The destruction of personal data is carried out in a manner that precludes further processing of such personal data and any possibility of subsequent data recovery.

If permitted by the physical medium, the destruction of personal data may be carried out in a manner that precludes further processing of such personal data while preserving the ability to process other data stored on such physical medium.

13.3. The destruction of personal data contained on paper media may be carried out by shredding it into small pieces using a paper shredder.

13.4. The destruction of personal data stored on personal computers (PCs) and/or on rewritable removable machine-readable media used for storing information outside of PCs (flash drives, external hard drives, CD-ROMs, and other devices) may be carried out using standard tools of information and operating systems.

13.5. The destruction of personal data contained on machine-readable media which cannot be destroyed using standard information and operating system tools, may be carried out by inflicting irreparable physical damage on the media, thereby precluding their use and any possibility of data recovery, including through deformation or disruption of the media’s physical integrity.

13.6. If it is impossible to destroy personal data within the time limit established by law, the Data Controller shall block such personal data or ensure its blocking (if the processing of personal data is carried out by another person acting on behalf of the Data Controller), and shall ensure the destruction of the personal data within the time limits established by the current legislation.

13.7. Confirmation of the destruction of personal data is carried out in accordance with the requirements established by the current legislation.



This website uses cookie technology and sends the information it collects to web analytics services. The information about your use of this website collected through the use of cookie technology will be shared with third parties. By continuing to use our website, you agree to the use of cookie technology. Learn more