Privacy
Effective date: August 21, 2026
1. General provisions
1.1. This Policy sets out how personal data of visitors to bekkul.com (the "Site") is processed and protected.
1.2. The data controller — the person determining the purposes and means of processing personal data — is Bekkul Dzhekshenkulov (the "Controller"). Email: [email protected].
1.3. This Policy has been prepared in accordance with the Digital Code of the Kyrgyz Republic of July 31, 2025, No. 178 and other applicable legislation of the Kyrgyz Republic.
1.4. This Policy applies to personal data received through the Site, email, contact forms, and other channels indicated on the Site. It does not apply to third-party sites and services that may be linked from the Site.
1.5. Using the Site does not automatically imply consent to any processing of personal data. Where a specific operation requires consent, the Controller requests it separately, in a clear and accessible form.
2. What data may be processed
2.1. The Controller may process data that the user provides directly:
- first and last name;
- phone number and email address;
- organization name, position, and field of activity;
- the content of an inquiry, request, or proposal;
- documents and other materials attached or sent by the user;
- information needed to prepare a proposal, conclude, or perform a contract.
2.2. When the Site is visited, the following technical data may be processed automatically:
- IP address;
- browser type and version, operating system, and device type;
- date and time of the visit;
- pages viewed, referral source, and on-site activity;
- identifiers and information contained in cookies;
- technical logs needed for the stable and secure operation of the Site.
2.3. The Controller does not request special categories of personal data through the Site, including health data, biometric or genetic data, racial or ethnic origin, political opinions, religious beliefs, or trade union membership. Users should not send such information unless necessary and previously agreed.
2.4. If a user provides the personal data of another person, the user confirms having a lawful basis for such disclosure and undertakes to inform that person of the terms of this Policy.
3. Purposes of processing
Personal data may be processed for the following purposes:
- responding to inquiries and maintaining contact with the user;
- reviewing proposals for cooperation, partnership, investment, and other projects;
- preparing, concluding, and performing contracts;
- organizing meetings, consultations, and business correspondence;
- ensuring the operability and security of the Site and preventing abuse and technical failures;
- analyzing traffic and improving the content and structure of the Site, where the relevant tools are connected and their use has a lawful basis;
- fulfilling obligations established by law;
- establishing, exercising, or defending legal claims.
Personal data is not used for purposes incompatible with those listed above without a separate lawful basis.
4. Legal bases for processing
Depending on the situation, processing is carried out on one or more of the following bases:
- to take steps at the user's request before entering into a contract, and to conclude and perform a contract;
- to fulfil the Controller's obligations established by law;
- to pursue the legitimate interests of the Controller or a third party, provided such processing does not override the user's rights, freedoms, and legitimate interests;
- on the basis of the user's voluntary, specific, informed, and unambiguous consent, where no other basis applies or consent is expressly required by law.
The user may withdraw consent by the same means used to give it, or by a means no more complex. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn and does not stop processing if the Controller has another lawful basis.
5. How processing is carried out
5.1. Processing may include the collection, recording, organization, accumulation, storage, clarification, use, disclosure (in cases provided by law), restriction, de-identification, deletion, and destruction of personal data.
5.2. Processing is carried out with or without the use of automated means. Access to personal data is granted only to those who need it to perform their relevant tasks.
5.3. The Controller does not sell personal data and does not make it publicly available without a lawful basis or the user's separate consent.
5.4. Decisions that produce legal effects concerning a user, or otherwise significantly affect them, are not made solely on the basis of automated processing of personal data.
6. Cookies and analytics
6.1. The Site uses Google Analytics 4 to measure traffic and improve page content and structure. The service loads only after the user gives consent.
6.2. Google Analytics may receive pages viewed, referral source, device and browser type, approximate location, and interaction events. Contact-form contents, names, phone numbers, email addresses, and Site search text are not sent in analytics events.
6.3. Advertising signals and ad personalization are disabled. Google's processing is governed by the Google Privacy Policy and may involve cross-border transfers.
6.4. Users may accept, decline, or later change their consent. If consent is declined, Google Analytics does not load. The choice can be changed using the button below or by clearing Site data in the browser.
7. Disclosure to third parties
7.1. Personal data may be disclosed only to the extent necessary for the stated purposes, to:
- hosting, technical support, cybersecurity, and Site administration providers;
- email, cloud storage, request-management, or analytics service providers, where such services are actually used;
- consultants and professional advisers bound by confidentiality;
- state authorities, local self-government bodies, courts, and other persons, where disclosure is required by law or necessary to defend a legal claim;
- other persons at the user's direction or with the user's consent.
7.2. Where processing is delegated to another party, the Controller defines the purposes, nature, and duration of processing, the categories of data, confidentiality requirements, and protective measures in a contract or other appropriate document.
8. Cross-border transfer
8.1. Using foreign hosting, email, cloud, or analytics providers may involve the transfer of personal data outside the Kyrgyz Republic.
8.2. Before any such transfer, the Controller verifies that a lawful basis exists and that the requirements of Article 89 of the Digital Code of the Kyrgyz Republic are met. Transfer to a state that does not ensure adequate protection of data subjects' rights is permitted only where a basis provided by law exists, including the user's consent, the necessity of concluding or performing a contract, or contractual guarantees of adequate protection.
9. Retention periods
9.1. Personal data is retained no longer than necessary to achieve the purposes of processing, unless a longer period is established by law or contract.
9.2. Inquiries and business correspondence may be retained for the duration of the interaction and thereafter for the period needed to confirm agreements and defend legal claims.
9.3. Data processed on the basis of consent is deleted or de-identified after consent is withdrawn, unless another lawful basis for its further processing exists.
9.4. The retention period for technical logs, analytics data, and cookies is determined by their purpose and the settings of the Site and the relevant service. The specific duration of each non-essential cookie is shown in the cookie management interface.
9.5. Once the purposes of processing have been achieved, data is deleted, destroyed, or de-identified, except where its continued retention is required by law or necessary to establish, exercise, or defend a legal claim.
10. User rights
The user has the right to:
- obtain information about, and access to, the processing of their personal data;
- request the correction or completion of inaccurate, incomplete, or outdated data;
- request deletion of data where grounds provided by law exist;
- object to processing carried out by certain means or for certain purposes;
- request restriction of processing in cases established by law;
- withdraw previously given consent;
- request data portability, where that right applies;
- appeal the Controller's actions or decisions to the State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic or to a court.
To exercise these rights, the user may write to [email protected]. The request should include the user's name, a contact for a reply, the substance of the request, and information confirming that the data relates to the requester. The Controller may ask for additional information solely to the extent necessary to verify identity and prevent third-party access to the data.
Requests are handled within the time limits established by the legislation of the Kyrgyz Republic. An objection to processing is reviewed within seven business days of receipt.
11. Data protection
11.1. The Controller takes reasonable and proportionate legal, organizational, and technical measures to protect personal data against unlawful or accidental access, alteration, disclosure, copying, loss, damage, deletion, or destruction.
11.2. The choice of protective measures takes into account the nature and volume of the data, the purposes of processing, the technologies used, and the potential risks to the user's rights.
11.3. No method of transmitting or storing data offers absolute security. If an incident is identified, the Controller takes measures to limit its consequences and fulfils any notification obligations required by law.
12. Children's data
The Site is not intended for the deliberate collection of children's personal data. If processing a child's data becomes necessary, it is carried out only where a basis provided by law exists, including the consent of a legal representative where required. Children who have reached the age of fourteen may give consent independently, within the limits of legal capacity established by civil law.
13. Links to third-party resources
The Site may contain links to third-party sites, social networks, and services. Such parties determine their own data-processing practices. Users should review the relevant privacy policies before using them.
14. Changes to this Policy
14.1. The Controller may amend this Policy if legislation, the set of services used, or data-processing practices change.
14.2. The current version is published at bekkul.com/en/privacy/, indicating its effective date. Where changes materially affect users' rights, the Controller takes reasonable steps to provide additional notice.
15. Contact
For questions about the processing and protection of personal data, please contact:
Controller: Bekkul Dzhekshenkulov
Email: [email protected]
Compliance with personal data legislation is overseen by the State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic.