Privacy policy

Personal Data Processing Policy

DOSTAR COFFEE LLP

Version dated 07 August 2026

Website: https://coffeeboom.kz

1. General Provisions

1.1. This Personal Data Processing Policy (the Policy) defines which personal data DOSTAR COFFEE LLP processes, the purposes and legal grounds for processing, the recipients to whom the data may be transferred, the measures used to protect the data, and the rights of the User.

1.2. This Policy applies to the website https://coffeeboom.kz, its subdomains, and related web forms (the Website).

1.3. The personal data operator is DOSTAR COFFEE LLP, Business Identification Number (BIN) 170440034527, registered address: 63/1 Seifullin Street, Baikonyr District, Astana, Republic of Kazakhstan (the Company).

1.4. The Company processes personal data in accordance with the laws of the Republic of Kazakhstan on personal data and its protection, including the Law of the Republic of Kazakhstan On Personal Data and Their Protection and applicable secondary legislation.

1.5. When registering on the Website, the User consents to the collection and processing of personal data by selecting a checkbox or using another confirmation method provided through the Website interface.

1.6. If the User does not agree to this Policy, the User must discontinue use of the Website. The Company may nevertheless continue to process certain data where necessary to comply with the law, maintain accounting or tax records, fulfil an order already placed, review claims, prevent violations, or protect the rights of the Company.

2. Terms and Definitions

2.1. The following terms are used in this Policy:

  • User means an individual who uses the Website, registers on it, places orders, receives notifications, participates in the loyalty program, or contacts customer support;
  • Personal Data means information relating to an identified or identifiable User;
  • Processing of Personal Data means any operation performed on personal data, including collection, storage, use, alteration, supplementation, transfer, dissemination, blocking, anonymization, deletion, and destruction;
  • Collection of Personal Data means actions aimed at obtaining personal data;
  • Transfer of Personal Data means providing personal data to a specific person or a specific group of persons;
  • Dissemination of Personal Data means actions as a result of which personal data become available to an indefinite group of persons;
  • Blocking of Personal Data means the temporary suspension of operations involving personal data;
  • Anonymization of Personal Data means actions as a result of which personal data can no longer be attributed to a specific User;
  • Destruction of Personal Data means actions as a result of which personal data cannot be restored;
  • Service Notifications means messages required for registration, account login, security, order placement, payment, delivery, cancellation or return, and operation of the Website;
  • Marketing Notifications means push notifications and other messages about discounts, promotions, promotional codes, restaurants, brands, categories, the loyalty program, and special offers that the User may enable, configure, or disable on the Website;
  • Advertising Materials means banners, cards, selections, special offers, and other advertising or informational placements displayed through the Website interface;
  • Corporate Customer means a legal entity or other organization that has entered into an agreement with the Company to provide certain individuals with access to the corporate catering program on the Website;
  • Corporate Catering Program Participant means a User or other person whom the Corporate Customer permits to place orders on the Website within the terms, limits, or rules established for the corporate catering program. Such person may be an employee, contractor, individual entrepreneur, service provider under a civil-law agreement, or another person designated by the Corporate Customer.
  • registration data: first name, last name, mobile telephone number, email address, login, or another account identifier;
  • account data: profile data, Website settings, login history, loyalty program participation, bonuses, and promotional codes;
  • order data: selected restaurants, stores, goods or dishes, order contents, order value, date and time, order status, order history, order comments, and information about cancellations, returns, and claims;
  • address and delivery data: delivery address, entrance, floor, intercom details, courier instructions, and other information supplied by the User for order placement and fulfilment;
  • payment data: payment method, payment amount and status, transaction identifier, refund information, and the last digits of the payment card or payment token where such data are supplied by the payment organization. The Company does not store the full bank card number, CVV/CVC code, or other complete payment credentials;
  • communications data: customer support requests, correspondence, reviews, complaints, inquiries, claims, survey responses, and other communications from the User;
  • technical data: IP address, device type and model, operating system, Website version, device language, device identifiers, push tokens, crash data, log files, and the date and time of Website use;
  • Website usage data: sections viewed, actions performed on the Website, clicks, selected offers, and interactions with push notifications, banners, cards, selections, and other materials on the Website;
  • marketing settings: information about enabled, disabled, or modified push notifications, including the restaurants, brands, categories, or offers for which the User wishes to receive notifications;
  • consent and settings data: the date, time, and method of consent, the applicable version of the Policy, and information about withdrawal of consent or changes to settings;
  • corporate catering program data: information about the User's affiliation with a corporate catering program; the Corporate Customer's name; the User's identifier in that program; corporate email address or telephone number; participation status; applicable limits; available balance or reimbursement amount; use of limits; order date and time, amount, and status; restaurant or supplier; and information required for settlements, reporting, confirmation of services, and dispute resolution.
  • directly from the User during registration, order placement, profile completion, contact with support, or participation in promotions, surveys, or the loyalty program;
  • automatically when the Website is used, including as technical data, logs, push tokens, crash data, and actions performed on the Website;
  • from payment organizations, banks, or payment aggregators to the extent necessary to confirm payment, refund, or payment status;
  • from restaurants, stores, couriers, customer support, or other persons involved in fulfilling an order where necessary to process an order, refund, complaint, or claim;
  • from other lawful sources where necessary to comply with the law, protect the Company's rights, or prevent violations;
  • from a Corporate Customer where it provides the Company with information about Corporate Catering Program Participants who are to receive access to the relevant Website functionality, limits, payment terms, or other rules of the corporate catering program.
  • registration and account management - creating an account, authorization, identification of the User, access recovery, and maintenance of the profile and Website settings;
  • service provision and order fulfilment - placement, confirmation, assembly, payment, delivery, cancellation, return, and support of orders, as well as transfer of necessary data to persons involved in fulfilling an order;
  • payments, bonuses, and refunds - processing payments, confirming payments, issuing refunds, and applying promotional codes, bonuses, and other payment terms;
  • service notifications and support - sending messages about order status, payment, delivery, account security, and changes to the service, and processing User inquiries, complaints, reviews, claims, and requests;
  • loyalty program and personalization - accruing and using bonuses, applying promotional codes, and displaying recommendations, selections, special offers, and settings within the Website;
  • marketing notifications selected by the User - sending push notifications and other informational messages about discounts, promotions, promotional codes, news, restaurants, brands, categories, and special offers selected by the User in the Website settings;
  • advertising materials on the Website - displaying banners, cards, selections, special offers, and other advertising or informational materials from restaurants, brands, partners, or advertisers through the Website interface;
  • analytics, development, and service quality - analyzing Website performance, diagnosing errors, and improving the interface, range of goods and services, service quality, customer experience, loyalty program, and advertising placements;
  • security and prevention of violations - protecting accounts, the Website, and the Company's information systems and preventing fraud, abuse, unauthorized access, technical failures, and other incidents;
  • legal compliance and protection of rights - complying with legal requirements, maintaining accounting and tax records, responding to lawful requests from public authorities, resolving disputes, and protecting the rights and legitimate interests of the Company, Users, and third parties;
  • corporate catering program - providing Corporate Catering Program Participants with access to a dedicated section or functionality of the Website, verifying eligibility, applying limits and conditions established by the Corporate Customer, placing orders within those limits, settling accounts among the Corporate Customer, restaurants, couriers, and the Company, confirming services, preparing reports, and resolving disputes.
  • the User's consent;
  • the need to process data to provide the service, place and fulfil an order, or perform actions requested by the User;
  • the need to comply with legal requirements;
  • the need to protect the rights and legitimate interests of the Company, the User, or third parties;
  • other grounds provided by law.
  • employees of the Company and persons who require access to the data to perform their duties;
  • restaurants, stores, and suppliers of goods or services - for order placement, assembly, and fulfilment;
  • order pickers, couriers, and delivery services - to deliver an order to the User;
  • payment organizations, banks, and payment aggregators - to process payments and refunds;
  • providers of IT services, hosting, technical support, analytics, error diagnostics, information security, SMS, email, push notifications, and other communication services;
  • advertising, analytics, or technical contractors - only to the extent necessary to display, configure, or assess the effectiveness of advertising materials on the Website, without granting them the right to send independent communications to the User;
  • the Company's consultants and contractors where necessary to operate the service, protect the Company's rights, or comply with the law;
  • public authorities, courts, law-enforcement agencies, and other authorized persons where required by law;
  • Corporate Customers, where the User is a Corporate Catering Program Participant, to the extent necessary to confirm participation, apply limits, pay for orders, make settlements, prepare reports, confirm services, and resolve disputes.
  • account data - for the period during which the account is used;
  • order, payment, refund, and accounting-document data - for the periods required by law;
  • customer support inquiries - for the period necessary to review the inquiry, monitor quality, and resolve potential disputes;
  • technical logs and security data - for the period necessary to protect the Website, investigate incidents, and prevent violations;
  • marketing settings and consent records - for the purpose of confirming the settings selected by the User and any modification or withdrawal thereof.
  • identifying business processes in which personal data are processed;
  • identifying persons who have access to personal data;
  • appointing a person responsible for organizing personal data processing;
  • approving internal documents governing personal data processing and protection;
  • segregating access rights to personal data;
  • hosting the Company's computing resources and databases in the infrastructure of the Amazon Web Services (AWS) cloud provider using isolated virtual network environments, including Amazon EKS and Amazon RDS, thereby limiting direct unauthorized access to system components from the public Internet;
  • designing the network architecture according to the principle of segmentation, under which external network access is limited to a strictly defined list of public interfaces and administrative access by employees to internal infrastructure resources is available only through a secure virtual private network (VPN);
  • using built-in automated network-level protection mechanisms provided by AWS to protect web applications and the network perimeter against distributed denial-of-service (DDoS) attacks;
  • encrypting external and internal network traffic using secure TLS cryptographic protocols to ensure confidentiality and integrity of data in transit;
  • centrally and securely storing configuration data, passwords, API keys, and other critical authentication information in a dedicated secrets-management system with role-based access control (RBAC);
  • integrating automated security control tools into the continuous integration and delivery (CI/CD) process, including static application security testing (SAST), to identify and remediate potential vulnerabilities during development;
  • automatically backing up databases at the AWS RDS cloud-infrastructure level to ensure regular creation and retention of backups, data recovery capability, and service continuity in emergencies;
  • engaging independent specialist organizations to conduct regular external security assessments of the infrastructure, including vulnerability scanning and external perimeter penetration testing.
  • operation of the Website;
  • account authorization and security;
  • retaining the User's settings;
  • Website usage analytics and error diagnostics;
  • improving the interface and service quality;
  • displaying offers, recommendations, and advertising materials within the Website;
  • sending push notifications in accordance with the User's settings;
  • assessing the effectiveness of advertising and informational materials;
  • preventing abuse, technical failures, and unauthorized access.
  • know whether the Company holds the User's personal data;
  • receive information about the collection and processing of the User's personal data, including the purposes, sources, processing methods, list of data, and processing and retention periods;
  • receive information about persons to whom the User's personal data are or may be transferred, where such information may be provided under applicable law;
  • request alteration, supplementation, correction, or updating of personal data that are incomplete, outdated, inaccurate, or unreliable;
  • request blocking of personal data where there is evidence of a violation of the requirements governing their collection or processing;
  • request destruction of personal data where their collection or processing violates the law and in other cases provided by law;
  • withdraw consent to the collection, processing, transfer to third parties, cross-border transfer, or dissemination of personal data, except where the Company may continue processing without consent in accordance with the law;
  • give or refuse consent to dissemination of the User's personal data in publicly available sources where such processing applies;
  • change marketing settings, disable push notifications for particular restaurants, brands, categories, or offers, or disable all marketing notifications;
  • request termination of unlawful processing of personal data;
  • apply to the Company, the authorized body, or a court to protect the User's rights;
  • claim compensation for damage in the cases provided by law;
  • receive information where the User's personal data were obtained by the Company from a Corporate Customer under the corporate catering program and contact the Company to clarify, correct, block, or delete such data in the cases provided by law.

3. Personal Data Processed by the Company

3.1. The Company may process the following categories of the User's personal data:

3.2. The Company may collect the User's geolocation data where the User provides such data.

3.3. The Website may use SDKs, device identifiers, push tokens, analytics tools, and diagnostic tools referred to in Section 12 of this Policy.

3.4. The Company does not request special categories of personal data, including information about health, religion, political views, biometric data, or other sensitive data, unless separately required for a specific service and processed in accordance with the law.

3.5. The Company processes only the personal data required for the purposes stated in this Policy or required by law.

4. Sources of Personal Data

4.1. The Company obtains personal data:

5. Purposes and Legal Grounds for Processing

5.1. The Company processes personal data for the following purposes:

5.2. The Company processes personal data on the following grounds:

5.3. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and does not terminate processing where processing is required by law, to fulfil an order, resolve a dispute, prevent violations, or protect the Company's rights.

6. Service Notifications, Marketing, and Advertising

6.1. The Company may send the User service notifications required for operation of the Website and fulfilment of an order, including messages about registration, account login, security, order status, payment, delivery, cancellation, return, technical changes, and other matters related to use of the Website.

6.2. Service notifications form part of the Website's operation and are not marketing communications.

6.3. The Company may send the User marketing push notifications and other informational messages only in accordance with the settings selected by the User on the Website.

6.4. In the Website settings, the User may select the restaurants, brands, categories, or offers for which the User wishes to receive push notifications. The User may also disable such notifications entirely.

6.5. Disabling marketing notifications does not affect receipt of service notifications required for operation of the Website and fulfilment of an order.

6.6. The Company may display advertising and informational materials through the Website interface, including banners, cards, selections, special offers, and other advertising placements from restaurants, brands, partners, or advertisers.

6.7. The Company does not transfer Users' personal data to restaurants, brands, partners, or advertisers for their own advertising or marketing communications without the User's separate consent.

6.8. The Company may record the enabling, modification, or disabling of marketing settings in order to confirm the User's choice and correctly apply the User's settings.

7. Transfer of Personal Data to Third Parties

7.1. The Company transfers personal data only to the extent necessary for a specific purpose.

7.2. Personal data may be transferred to the following categories of recipients:

7.4. Data are transferred to restaurants, couriers, payment organizations, and technical providers for operation of the Website, order fulfilment, delivery, payment, support, security, and other purposes stated in this Policy.

7.5. Such transfer does not grant restaurants, brands, partners, or advertisers the right to use the User's personal data for their own marketing without the User's separate consent.

7.6. The Company takes measures to ensure that third parties receiving personal data maintain confidentiality, apply appropriate safeguards, and process the data only for agreed purposes.

7.7. When transferring data to a Corporate Customer, the Company limits the transfer to the minimum data necessary, such as participation status, use of a limit, order amount, order date, order status, and data required for settlements and reporting. The Company does not provide the Corporate Customer with excessive information about the User or the User's orders unless such transfer is required to perform the agreement, confirm services, resolve a dispute, or comply with legal requirements.

8. Data Localization and Cross-Border Transfers

8.1. The principal personal data databases contained in the Company's digital resources are located and stored in the Republic of Kazakhstan where required by the laws of the Republic of Kazakhstan.

8.2. In certain cases, personal data may be transferred outside the Republic of Kazakhstan, for example where the Company uses foreign providers of technical, communication, analytics, diagnostic, cloud, or other services.

8.3. A cross-border transfer is made only where there is a legal basis, including the User's consent, the need to fulfil an order or agreement, compliance with legal requirements, protection of the Company's rights, or other circumstances provided by law.

8.4. For cross-border transfers, the Company applies necessary safeguards, including data minimization, contractual confidentiality and security obligations, secure communication channels, encryption, and other applicable measures.

8.5. If a Corporate Customer is located outside the Republic of Kazakhstan, certain personal data of Corporate Catering Program Participants may be transferred to that Corporate Customer outside the Republic of Kazakhstan to the extent necessary to administer the corporate catering program, apply limits, make settlements, prepare reports, confirm services, and resolve disputes. Such transfer is made where there is a legal basis and with contractual, organizational, and technical safeguards, including confidentiality obligations.

9. Retention, Blocking, Anonymization, and Destruction

9.1. The Company retains personal data no longer than necessary for the processing purposes stated in this Policy, unless a longer period is required by law or necessary to protect the Company's rights.

9.2. Retention periods depend on the data category and processing purpose, including:

9.3. Once the processing purposes have been achieved, personal data are deleted, destroyed, blocked, or anonymized unless further retention is required by law or necessary to protect the Company's rights.

9.4. If the User reports a violation of the requirements governing the collection or processing of personal data, the Company blocks the relevant personal data in the cases and manner prescribed by law until a decision is made on the report.

9.5. Anonymized or aggregated data may be used for statistics, analytics, service improvement, evaluation of advertising effectiveness, and business reporting, provided that such data do not identify a specific User.

10. Security Measures and Incidents

10.1. The Company applies organizational and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, dissemination, loss, disclosure, and other unlawful actions.

10.2. Such measures include:

10.3. Access to personal data is granted only to persons who require it to perform their duties.

10.4. Where providers of IT services, hosting, analytics, push notifications, support, or other services are used, the Company takes measures to contractually establish confidentiality, security, and processing requirements limited to agreed purposes.

10.5. In the event of a personal data security breach, the Company takes measures to contain and remedy the incident and minimize its consequences.

10.6. In the cases prescribed by law, the Company notifies the authorized body of a personal data security breach within the prescribed period.

11. SDKs, Device Identifiers, and Similar Technologies

11.1. The Website may use SDKs, device identifiers, push tokens, analytics tools, diagnostic tools, and similar web technologies.

11.2. Such technologies may be used for:

12. User Rights

12.1. The User has the right to:

12.2. To exercise these rights, the User may use the available Website functions or send a request by email to info@coffeeboom.kz.

12.3. The Company reviews User requests within the periods established by applicable law. If a request cannot be fulfilled in whole or in part, the Company provides a reasoned response in the cases and manner prescribed by law.

13. Amendments to the Policy and Contact Details

13.1. The Company may amend this Policy following changes in legislation, Website functions, business processes, suppliers, data-protection measures, or other circumstances.

13.2. The current version of the Policy is posted on the Website or on the Company's website. In the event of material changes, the Company may notify Users through the Website, push notification, email, SMS, or another available method.

13.3. For matters concerning personal data processing and protection, the User may contact the Company at:

DOSTAR COFFEE LLP

Business Identification Number (BIN): 170440034527

Registered address: 63/1 Seifullin Street, Baikonyr District, Astana, Republic of Kazakhstan

Correspondence address: 63/1 Seifullin Street, Baikonyr District, Astana, Republic of Kazakhstan

Email for personal data matters: info@coffeeboom.kz