1. Definitions
- Application / Service — the VisitKyrgyz mobile application and website.
- Company ("We", "Us", "Our") — Open Joint-Stock Company "Tunduk" (OJSC "Tunduk"), the operator of the platform and controller of Your Personal Data. Registered address: Kyrgyzstan, Bishkek, Ibraimova St., 24.
- Personal Data — any information relating to an identified or identifiable individual.
- Service Provider — a natural or legal person that processes Personal Data on behalf of the Company to deliver or support the Service.
- Partner Service — a state body or commercial organization that provides a specific service You request through the Application (e.g. an insurance company, a mobile operator, a transport operator) and processes Your data as an independent controller for that service.
- Usage Data — data collected automatically when You use the Service (e.g. IP address, device type, pages visited, time of visit).
- You / User — the individual accessing or using the Service.
2. Our Principles
- Purpose limitation — each category of data is collected for a specific service and its stated purpose. The technical possibility of collecting data is never, by itself, a reason to collect it.
- Two separated data circuits — anonymized aggregated analytics and personal profiles are separated at server level. Personal Data does not enter aggregated analytics in identifiable form.
- Logged access — every access to Your personal profile by an authorized state body is recorded in an append-only log that cannot be edited or deleted.
- No card data — Your full payment card details are not stored and are not displayed anywhere in the platform.
3. Data We Collect
3.1. Account data
When You register: first and last name, email address, mobile phone number, declared citizenship, date of birth. Citizenship and identity details are recorded as declared by You and are marked as unverified until state identity verification services become available to the platform.
3.2. Data collected for specific services
Depending on which services You use, We collect only the data required for that service:
- Route registration with the Ministry of Emergency Situations — contact details, address of residence, route details, lodging points, emergency exit routes, dates, communication equipment, group composition, insurance details.
- Border zone permits — application data required by the border service.
- Transport and bookings — trips, tickets and reservations made through the Application (buses, taxi, accommodation).
- Insurance — policy details processed with the relevant insurer.
- e-Sim and connectivity — data required by the mobile operator to activate service.
- Payments — transaction amounts, dates and statuses. Card details are processed by licensed payment providers; We receive only tokenized references and never store full card numbers.
3.3. Location data
With Your prior permission, We collect device location to show You on the map, support route tracking and enable emergency (SOS) features. You can disable location access at any time in Your device settings; SOS and route-tracking features may not work without it.
3.4. Usage data
Collected automatically: IP address, device and OS type, unique device identifiers, in-app actions, dates and times of use, diagnostic data.
4. How We Use Your Data
- To provide and maintain the Service and its features.
- To manage Your account and registration.
- To process the services You request (permits, registrations, bookings, insurance, e-Sim, payments) – which requires transmitting the necessary data to the relevant Partner Service.
- To contact You with service notifications (status of applications, bookings, security alerts) by push, SMS or email.
- To send You news and offers related to the Service – only where permitted by law, and You may opt out at any time.
- To analyze usage and improve the Service.
- To comply with legal obligations of the Company.
5. Data and State Bodies
As the national tourism platform, VisitKyrgyz processes data for two state purposes, kept strictly separate:
- Aggregated tourism analytics — The State Agency for Tourism receives anonymized, aggregated indicators of tourist flow (arrivals by declared citizenship, seasonality, popular regions and routes, average trip length and spending). These indicators do not identify You and are produced without Your Personal Data entering the analytics circuit in identifiable form.
- Access by authorized bodies — An authorized state body may access an individual profile only upon a documented legal basis. Each such access is recorded in an append-only audit log (date, time, official, legal basis) which cannot be edited or deleted by anyone, including administrators.
Beyond this, We may disclose Personal Data where required by the law of the Kyrgyz Republic or by a valid request of a competent authority.
7. Data Retention
We retain Personal Data only as long as necessary for the purposes above, after which it is deleted or anonymized. Unless the law requires otherwise:
- Account data — for the duration of Your account plus up to 24 months after closure.
- Support correspondence — up to 24 months from ticket closure.
- Usage data and server logs — up to 24 months.
- Payment transaction records and application records submitted to state bodies — for the periods required by the legislation of the Kyrgyz Republic.
Residual copies may remain in encrypted backups for a limited period and are not restored except for security, disaster recovery or legal compliance. Retention periods for the access audit log are established jointly with the legal counsel and applicable regulations.
8. Your Rights
Subject to the legislation of the Kyrgyz Republic on personal data, You have the right to access, correct, update or delete Your Personal Data, to withdraw consent, and to object to or restrict certain processing. You can manage most of Your data in the account settings of the Application, or contact Us using the details below. Note that We may need to retain certain information where We have a legal obligation to do so (e.g. records of applications submitted to state bodies).
9. Security
Access to data is segregated by role on the server side; personnel roles follow the principle of least privilege and separation of duties. Data is transmitted over secured channels, and access requires individual authentication. No method of transmission or storage is completely secure, but We apply organizational and technical measures appropriate to the sensitivity of the data.
10. Children
The Service is not directed to persons under the age of 16, and We do not knowingly collect their Personal Data. If You believe a child has provided Us with Personal Data, please contact Us and We will remove it.
11. Links to Other Websites
The Service may contain links to third-party websites that We do not operate. We are not responsible for their content or privacy practices; please review their policies.
12. Changes to This Policy
We may update this Policy. We will notify You via the Application and/or email before material changes take effect and update the "Last updated" date above.
13. Governing Law and Contact
This Policy is governed by the legislation of the Kyrgyz Republic, including the Law of the Kyrgyz Republic "On Personal Information".
Operator: OJSC "Tunduk", Kyrgyzstan, Bishkek, Ibraimova St., 24.