Privacy and Personal Data Processing Policy
Draft
This is a draft that has not been reviewed by a lawyer. Before publication, all fields in square brackets must be completed, a “First and last name” field must be added to the application form (the consent checkbox is already there), a decision must be made on where the website and database will be hosted (in Kazakhstan or abroad), and the text must be handed to a lawyer before ticket sales begin.
1General Provisions
1.1. This Privacy and Personal Data Processing Policy (the “Policy”) explains what personal data [organiser's name] (the “Organiser”) collects through the DAYINN FEST festival website [website address] (the “Website”), why it is needed, how the Organiser stores and protects it, and what rights the person whose data is processed has.
1.2. The Policy has been developed in accordance with Law of the Republic of Kazakhstan No. 94-V dated 21 May 2013 “On Personal Data and Their Protection” (the “Personal Data Law”) and other legal acts of the Republic of Kazakhstan. The Organiser has approved it as the document setting out its policy on the collection, processing and protection of personal data.
1.3. The Policy applies to all personal data that the Organiser receives through the Website: from the application form, when tickets are ordered and paid for (once sales open), and from enquiries made through the contact details shown on the Website.
1.4. DAYINN FEST (the “Festival”) is a three-day open-air festival of music and Kazakh culture (Kazakhstan Outdoor Experience). It will take place on 4–6 June 2027 in the Almaty Region of the Republic of Kazakhstan. The exact venue will be announced separately.
1.5. The Policy is published in Russian, Kazakh and English. [Order of precedence of the language versions — to be determined by the Organiser.]
1.6. Version No. 1. Date of approval and publication on the Website: [date].
2Personal Data Operator
2.1. The owner and operator of the database containing personal data is the Organiser:
name: [organiser's name];
BIN/IIN: [BIN/IIN];
registered address: [registered address];
email: [email];
phone, WhatsApp, Telegram: +7 707 906 90 61;
Instagram: @dayinn.fest;
website: [website address].
2.2. Person responsible for organising the processing of personal data: [full name and contact details of the responsible person].
2.3. The Organiser's contact person for Festival matters is Sultan Imanbek, founder and producer of DAYINN FEST.
3Definitions
3.1. The following terms are used in this Policy:
Personal data — information relating to an individual (data subject) who is identified or identifiable on the basis of that information, recorded on electronic, paper and/or other tangible media.
Processing of personal data — actions aimed at the accumulation, storage, modification, supplementation, use, dissemination, depersonalisation, blocking and destruction of personal data.
User (data subject) — an individual whose data is processed by the Organiser: a Website visitor, an applicant or a ticket buyer.
Application — a message that the User sends through the form on the Website so that the Organiser contacts them when ticket sales open. An Application is not a purchase or reservation of a ticket.
Electronic ticket — a unique code (QR code or number) that the Organiser sends to the buyer after payment and that is used for admission to the Festival.
Payment organisation — [payment organisation], which accepts payment by bank card and by other methods indicated on the payment page.
Cross-border transfer — transfer of personal data to the territory of foreign states.
Authorised body — the state body responsible for personal data protection (clause 12.4).
4Data Collected by the Organiser
4.1. Application. Tickets are not on sale yet. Through the application form, the Organiser receives:
first and last name;
phone number;
email address;
a comment — at the User's discretion;
service information about the application, which is saved automatically: the Website language, the section of the Website from which the form was sent, the date and time of sending, and information about consent (clause 6.3).
Please do not include unnecessary information about yourself or other people in the comment (for example, IIN, identity document details or health information).
4.2. Ticket purchase. Once sales open, when an order is placed the Organiser will receive the buyer's data needed to issue and send the electronic ticket: last and first name, phone number and email address, as well as order data (ticket category and quantity, amount, order number and date, payment status, electronic ticket code) [specify the list of buyer and order data once the order form has been designed]. From the payment organisation, the Organiser receives information on the payment result to the extent provided by [payment organisation]: [list].
4.3. Bank card data. The User enters the card number, expiry date and CVV2/CVC2 code only on the secure page of the payment organisation. The Website and the Organiser do not receive, see or store this data.
4.4. On-site accommodation. Accommodation (tents, campers) is provided by the Organiser; the terms will be announced when ticket sales open. If additional data is needed for this, the Organiser will state in advance exactly what data and for what purpose.
4.5. Technical data. When the User opens pages of the Website, the server hosting the Website and the services from which page elements are loaded (clause 7.1) automatically receive technical information: IP address, browser and device type, and the date and time of the request. This information is needed to operate and protect the Website and is not used to identify the User. Where this information is stored and to whom it is transferred is set out in section 8.
4.6. The Organiser does not collect biometric data, health information, IIN or other data not needed for the purposes set out in section 5.
4.7. The application form and ticket purchase are intended for persons aged 18 and over. An application or order on behalf of a minor is made by the minor's legal representative, who provides their own data and gives consent. If the Organiser learns that a minor's data has been obtained without the consent of the legal representative, it destroys that data within one business day.
5Purposes of Processing
5.1. The Organiser processes personal data only for the following purposes:
to accept an application, contact the User (by phone, email, WhatsApp or Telegram) when ticket sales open, and answer questions from the comment — last and first name, phone, email, comment;
to process an order, accept payment through the payment organisation, and issue an electronic ticket and a document confirming the purchase — buyer and order data;
to admit the visitor to the Festival using the electronic ticket code — ticket code and order data;
to send service messages about the order, changes to the programme, postponement or cancellation of the Festival, and the refund procedure — phone, email;
to handle enquiries, claims and refund requests — data from the enquiry and the order;
to fulfil obligations under the legislation of the Republic of Kazakhstan (accounting and tax records, responses to requests from state bodies) — order and payment data;
to ensure the operation and security of the Website — technical data.
5.2. The Organiser sends advertising and informational mailings unrelated to an application or order only with the User's separate consent.
5.3. For new purposes, the Organiser requests new consent.
6Legal Grounds and Consent
6.1. The main ground for processing is the User's consent (Articles 7 and 8 of the Personal Data Law). Buyer data is also processed to perform the ticket purchase contract (public offer) and to fulfil obligations established by the legislation of the Republic of Kazakhstan. Without consent, data is processed only in cases expressly provided for by law.
6.2. How consent is given. [Before publication: the consent checkbox must be added to the application form and verified on the server; until then, do not publish this clause.] In the application form, and once sales open also in the order form, next to the submit button there is a checkbox “I give [organiser's name], [BIN/IIN], consent to the collection and processing of my personal data (last and first name, phone, email, comment), to its transfer to third parties and to its cross-border transfer on the terms of the Privacy Policy (version No. 1)” with a link to this Policy. The checkbox is not pre-ticked. The User gives consent by ticking the checkbox and submitting the form. The form cannot be submitted unless the checkbox is ticked.
6.3. The Organiser keeps the confirmation of consent together with the User's last and first name: the date and time the form was submitted [and other stored consent information, such as the Policy version number — specify once the form has been finalised].
6.4. By giving consent, the User accepts the following terms (paragraph 4 of Article 8 of the Personal Data Law):
operator — [organiser's name], [BIN/IIN];
data subject — the person whose last and first name are entered in the form;
the list of data collected is set out in section 4, and the purposes in section 5;
data may be transferred to the third parties listed in section 7;
cross-border transfer of data takes place in the cases specified in section 8;
data is not disseminated in publicly available sources;
consent is valid until the purposes of processing are achieved, within the periods specified in section 9, or until it is withdrawn.
6.5. Withdrawal of consent. The User may withdraw consent at any time by writing to [email] or by sending a message via WhatsApp or Telegram to +7 707 906 90 61 from the number given in the application. Within 15 business days, the Organiser stops processing and destroys the data, or sends a reasoned refusal if the legislation of the Republic of Kazakhstan requires the data to be retained (paragraph 7 of Article 8 of the Personal Data Law). Consent cannot be withdrawn if this would contradict the laws of the Republic of Kazakhstan or if there is an unfulfilled obligation.
6.6. After consent is withdrawn, the Organiser will not be able to contact the User regarding the application. If a ticket has already been purchased, the order data is kept for as long as needed for admission to the Festival, refunds and compliance with legal requirements.
7Transfer to Third Parties
7.1. The Organiser does not sell or publish personal data. Data is transferred only to the following recipients and only to the extent needed for the stated purpose:
[payment organisation] — to accept payments and make refunds: order data and the buyer's contact details to the extent needed to process the payment and send the receipt;
banks and payment systems involved in processing the payment — in accordance with the rules of the payment organisation;
hosting providers: [provider], [city], Republic of Kazakhstan — hosting of the Website, the database and technical logs; [Vercel Inc. (USA) — hosting of the Website, if it remains on this platform];
Google LLC (Google Fonts, USA) — loading of fonts when Website pages are opened: IP address and browser information [remove if the fonts are hosted on the Website's server];
[Organiser's email service and SMTP provider, country] — notifications to the Organiser about new applications: last and first name, phone, email, comment;
[email and messaging service, if used] — to send electronic tickets and service messages (once sales open);
the WhatsApp (Meta Platforms, Inc., USA) and Telegram (UAE) messengers — if the Organiser contacts the User using the number from the application or replies to the User's enquiry: phone number, name, correspondence;
[person who maintains the Website on the Organiser's behalf and has access to the database or admin panel — specify, if any] — technical support of the Website;
state bodies — upon their requests, in the cases and in the manner established by the legislation of the Republic of Kazakhstan.
7.2. The Organiser transfers data only to the extent necessary for the stated purpose; recipients process it under the terms of their own contracts and policies [links to recipients' contracts and policies; confidentiality agreements — specify, if concluded]. The Organiser keeps records of transfers of data to third parties and of cross-border transfers [recording method — specify once it has been set up].
7.3. If the User writes to the Organiser via WhatsApp, Telegram or Instagram on their own initiative, the correspondence passes through these services and is processed by them under their own rules.
8Place of Storage and Cross-Border Transfer
8.1. By law, personal data is stored in a database and/or digital object located in the territory of the Republic of Kazakhstan (paragraph 2 of Article 12 of the Personal Data Law).
8.2. The Website, the database of applications and orders, and the web server's technical logs are hosted on a server of [provider], [city], Republic of Kazakhstan. [Complete once the Website and database have been moved to the Republic of Kazakhstan; do not publish the Policy until then. If the database remains abroad, state the country and classify its storage as a cross-border transfer in clause 8.3.]
8.3. Cross-border transfer of personal data takes place in the following cases:
[if the Website remains on the Vercel platform:] Vercel Inc. (USA), request-processing region [region] — hosting of the Website. When the User opens the Website or submits a form, the data passes through this platform's servers outside the Republic of Kazakhstan, and technical information (clause 4.5) is stored in its logs for no longer than [period];
Google LLC (Google Fonts, USA) — when Website pages are opened, the User's browser loads fonts from Google's servers and transmits the IP address and browser information to them [remove if the fonts are hosted on the Website's server];
[Organiser's email service and SMTP provider, country] — notifications to the Organiser about new applications: last and first name, phone, email, comment [specify if the service's servers are located outside the Republic of Kazakhstan];
WhatsApp (Meta Platforms, Inc., USA) and Telegram (UAE) — correspondence between the Organiser and the User: phone number, name, message content;
international payment systems — for card payments (clause 8.5).
8.4. Cross-border transfer is permitted to states that ensure the protection of personal data and, to other states, in particular with the consent of the data subject (Article 16 of the Personal Data Law). The Organiser transfers application and order data in the cases set out in clauses 8.3 and 8.5 on the basis of the consent that the User gives in the manner set out in clause 6.2. [For the lawyer: visitors' technical data (clause 4.5) is sent to Vercel and Google when a page is opened, before consent is given. Before publication, move the Website and fonts to the Republic of Kazakhstan or determine another legal basis.]
8.5. For card payments, payment data may be transferred abroad to international payment systems under the rules of the payment organisation and of those systems.
8.6. If the countries or recipients to which data is transferred change, the Organiser will update the Policy before such transfer begins.
9Retention Periods
9.1. Data is kept no longer than necessary for the purposes of processing (paragraph 2 of Article 12 of the Personal Data Law).
9.2. Retention periods:
applications — until the end of ticket sales for the Festival, but no longer than 6 months after the Festival ends, or until consent is withdrawn;
order and payment data — 5 years from the date of the transaction (contract with the payment organisation, tax and accounting requirements);
enquiries, claims and refund requests — [period] after they have been handled;
records of consent — for as long as the data to which they relate is stored, and for [period] thereafter;
technical logs — no more than 12 months.
9.3. Once the retention period expires or consent is withdrawn, the data is destroyed unless the law requires it to be kept longer.
10Data Protection
10.1. The Organiser takes legal, organisational and technical measures to protect personal data against unlawful access, modification, destruction and dissemination (Article 22 of the Personal Data Law), including:
the Website operates only over the secure HTTPS protocol;
access to the database is limited to persons who need it for their work and is password-protected;
bank card data is not entered or stored on the Website;
masking and hashing methods are used where applicable;
[database backups — specify if set up and where the copies are stored; if outside the Republic of Kazakhstan, disclose this in section 8];
transfers of data to third parties are recorded (clause 7.2).
10.2. In the event of a personal data security breach, the Organiser notifies the authorised body within one business day and takes measures to eliminate its consequences. The Organiser also notifies the Users whose data is affected.
11Cookies
11.1. Cookies are small files that the Website saves in the User's browser. Other browser storage (for example, localStorage) is treated in the same way as cookies.
11.2. The Website uses only strictly necessary cookies and browser storage — to ensure that the pages and the form work properly. The Website does not use analytics or advertising cookies, counters or trackers. The Website's fonts are loaded from Google Fonts servers (clause 8.3) [remove if the fonts are hosted on the Website's server].
11.3. Strictly necessary cookies are not used to identify the User. They can be deleted or blocked in the browser settings, but some Website functions may then not work properly.
11.4. If the Organiser adds analytics or advertising tools, it will update the Policy in advance and will request the User's consent before using them.
12User Rights
12.1. The User has the right (Article 24 of the Personal Data Law):
to know whether the Organiser processes their data and to receive, free of charge, information on the purposes, sources, methods of collection and processing, the list of data and the retention periods;
to demand that their data be modified and supplemented where there are grounds confirmed by documents;
to demand that their data be blocked if there is information on a breach of the conditions for its collection and processing;
to demand the destruction of data collected and processed in breach of the law, and in other cases established by law;
to withdraw consent to the collection and processing of data, its transfer to third parties and its cross-border transfer (clause 6.5);
to protect their rights, including by claiming compensation for non-pecuniary and pecuniary damage;
to appeal against the Organiser's actions to the authorised body or to a court.
12.2. How to make a request. A request is sent to [email] or by message via WhatsApp or Telegram to +7 707 906 90 61. To avoid disclosing data to an unauthorised person, the Organiser may ask for confirmation that the request was sent by the owner of the data, for example by writing from the same email address or phone number given in the application.
12.3. Response times: information about data — within 3 business days, unless another period is established by law (Rules for the Collection and Processing of Personal Data, approved by Order of the Acting Minister of Digital Development, Innovation and Aerospace Industry of the Republic of Kazakhstan No. 395/НҚ dated 21 October 2020); modification, blocking or destruction of data upon a justified request — within one business day; cessation of processing after withdrawal of consent — within 15 business days.
12.4. The authorised body for personal data protection is the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan (Information Security Committee). If the User believes that their rights have been violated, they may apply to that body or to a court.
13Changes to the Policy and Contacts
13.1. The Organiser may amend the Policy. A new version is published on the Website with its number and date and takes effect from the date stated in it. The Organiser provides previous versions on request.
13.2. If the purposes of processing, the scope of data, the recipients or the place of storage change, the Organiser gives advance notice by email or phone using the contact details provided in the application or order, and requests new consent where required by law.
13.3. Questions about personal data and this Policy may be sent to:
email: [email];
phone, WhatsApp, Telegram: +7 707 906 90 61;
Instagram: @dayinn.fest;
postal address: [registered address];
person responsible for organising the processing of personal data: [full name and contact details of the responsible person].
[organiser's name], [BIN/IIN], [website address].


