Privacy Policy
Effective date: 5 August 2026 · Last updated: 5 August 2026
This Privacy Policy explains how Individual Entrepreneur NAZERKE (“we”, “us”, “the Company”), registered in Kazakhstan under registration number KZ33UWQ07384206, collects, uses, stores, shares and deletes personal data in connection with the AITG advertising automation service (“the Service”), available at https://aitg.uz/.
The Company is the data controller for the data described in this policy, unless stated otherwise. For data that our business clients upload or make available to us in order to receive our services, the client is the controller and we act as a processor on that client's documented instructions.
1. Who this policy applies to
- Client users — employees and authorised representatives of the businesses that use the Service.
- Visitors — anyone who visits our website.
- Prospective clients — people who contact us through the website or by e-mail.
The Service is a business tool. It is not directed at, and not intended for use by, individuals under the age of 18. We do not knowingly collect data from children.
2. Data we collect
2.1 Data you give us directly
- Account data: full name, business e-mail address, phone number, job title, company name.
- Billing data: legal entity details, tax identification number, billing address, invoice history. Card details are handled by our payment provider and never reach our servers.
- Support data: the content of the messages, tickets and attachments you send us.
2.2 Data we receive from Meta technologies
When an authorised user of a client business connects that business's assets to the Service through Facebook Login, Meta provides us with data based on the permissions that user grants. We receive:
- the signing-in user's public profile (name, Meta user ID) and e-mail address;
- the identifiers and names of the Business Portfolios, advertising accounts, Pages and Instagram professional accounts the user is authorised to manage;
- campaign structure of the connected advertising accounts: campaigns, ad sets, ads, targeting settings, schedules, budgets and ad creatives;
- advertising performance data of the connected advertising accounts: spend, impressions, reach, clicks, conversions, cost per result and similar aggregated metrics;
- basic Page information and aggregated Page engagement metrics for the Pages used as the identity of the client's ads.
We do not request and do not receive the content of private messages, contact lists, friend lists, or the personal data of the individual people who see or click the client's ads. Advertising insights are received in aggregated form.
2.3 Data collected automatically
- Technical data: IP address, browser and device type, operating system, language.
- Usage data: the commands and actions performed through our bot, timestamps, error reports.
- Cookies: strictly necessary cookies for sign-in and security. We do not use advertising cookies or third-party tracking pixels on this website.
3. Why we process data, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the Service: identifying the client, creating and managing their advertisements, reporting the results | Account data, Meta data (2.2), usage data | Performance of a contract |
| Support and service communication | Account data, support data | Performance of a contract |
| Billing, accounting and tax reporting | Billing data | Legal obligation |
| Security, abuse prevention, audit logging | Technical data, usage data | Legitimate interest in keeping the service secure |
| Improving the Service (aggregated, non-identifying statistics) | Usage data | Legitimate interest in improving our product |
| Marketing e-mails to business contacts | Business contact data | Consent, withdrawable at any time |
4. How we use data obtained from Meta technologies
Data we receive through the Meta Marketing API and Facebook Login is used only to provide the features the client asked for: showing their campaigns, applying the changes their authorised users request, and producing their reports and alerts.
We do not:
- sell, rent, licence or otherwise monetise data obtained through Meta technologies;
- transfer it to data brokers, information resellers, ad networks or monetisation platforms;
- use it for our own advertising, retargeting or audience building;
- combine one client's data with another client's data, or build cross-client profiles;
- use it to determine eligibility for credit, insurance, housing, employment or education;
- use it for surveillance purposes, or provide it to any government surveillance programme;
- attempt to re-identify anonymised or aggregated data.
Our processing of this data is additionally governed by the Meta Platform Terms and the Meta Developer Policies, which we comply with in full.
5. Who we share data with
We do not sell personal data. We share it only with:
- Infrastructure and hosting providers that operate the servers and databases running the Service, under a written data processing agreement.
- Payment and invoicing providers for billing purposes.
- Meta Platforms, Inc. — requests we send to the Marketing API on the client's behalf.
- Professional advisers (accountants, auditors, lawyers) bound by confidentiality.
- Public authorities, where we are legally required to disclose data. Where the law permits, we notify the affected client first.
Every processor acts on our documented instructions, under confidentiality obligations, and may not use the data for its own purposes. A current list of our sub-processors is available on request at privacy@aitg.uz.
6. International transfers
Our infrastructure providers may process data outside Kazakhstan. Where data is transferred across borders, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses or an adequacy decision — and we apply the same protection described in this policy regardless of where the data is processed.
7. How long we keep data
| Category | Retention period |
|---|---|
| Account and profile data | For the life of the account; deleted within 30 days of account closure |
| Access tokens | Deleted immediately when the client disconnects the asset or closes the account |
| Campaign structure and creatives | Until disconnection or account closure; deleted within 30 days |
| Advertising insights | Up to 24 months, so that year-over-year comparison remains possible |
| Support correspondence | 24 months from the last message |
| Invoices and accounting records | As required by the tax law of Kazakhstan |
| Security and audit logs | 12 months |
8. Your rights
Subject to applicable law, you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, write to privacy@aitg.uz. We answer within 30 days. We may ask you to confirm your identity before we act on a request.
9. Deleting your data
You can disconnect your Meta assets and request deletion of all data at any time. The full procedure — including the callback we provide to Meta for user data deletion requests — is described on our Data deletion instructions page.
10. Security
We protect data with TLS 1.2+ encryption in transit, encryption at rest for credentials and access tokens, role-based access control, multi-factor authentication for administrative access, audit logging, regular backups and periodic review of access rights. No system is perfectly secure; if a personal data breach occurs that is likely to result in a risk to affected individuals, we notify the competent authority and the affected clients without undue delay.
11. Changes to this policy
We may update this policy. The effective date at the top always shows the current version. If a change materially affects how we handle personal data, we notify account holders by e-mail at least 14 days before the change takes effect.