1. General Provisions
This Privacy Policy (hereinafter — "Policy") establishes the procedure for processing and protecting the personal data of users of the website aslraqam.uz and ASL RAQAM services, operated by ASL RAQAM Limited Liability Company.
By using the Website and Services, the user unconditionally consents to this Policy and the terms of personal data processing. If the user disagrees with the terms of this Policy, they must cease using the Website and Services.
This Policy has been developed in accordance with Law of the Republic of Uzbekistan No. ZRU-547 dated 2 July 2019 "On Personal Data", Cabinet of Ministers Resolution No. 570 dated 5 October 2022, the Law "On Informatisation", and other regulatory acts of Uzbekistan.2. Key Definitions
- Personal data — information recorded on an electronic, paper, or other material medium that relates to an identified or identifiable natural person.
- Data subject — the natural person to whom the personal data relates.
- Controller (Operator) — ASL RAQAM LLC, which organizes and carries out the processing of personal data.
- Processing of personal data — actions of collection, systematization, storage, modification, supplementation, use, provision, distribution, transfer, anonymization, and destruction of personal data.
- Consent — the voluntary expression of will by the data subject to the processing of their personal data.
- User — a person visiting the Website or using the Services.
- Client — a legal entity or individual entrepreneur that has entered into a service agreement with the Controller.
3. About the Controller
| Full name | ASL RAQAM Limited Liability Company |
|---|---|
| Short name | ASL RAQAM LLC / «ASL RAQAM» MChJ |
| Tax ID (STIR) | 312 114 436 |
| Registered address | Republic of Uzbekistan, Tashkent, Gulkhani 11B |
| Enquiry email | info@aslraqam.uz |
| Phone | +998 90 929-57-75 |
4. Data We Process
4.1. Data provided voluntarily by the user
- Full name;
- Job title and employer;
- Contact details: phone number, email, messaging accounts (Telegram, etc.);
- Legal entity details (name, tax ID, address, bank account information);
- Personal ID number (PINFL) of the EDS holder (when an EDS is transferred for service execution);
- EDS certificate data (serial number, validity period);
- Content of inquiries, requests, and correspondence.
4.2. Data collected automatically
- IP address, internet service provider information;
- Browser and operating system type and version;
- Screen parameters, language settings;
- Referring page URL, pages visited, time spent on the website;
- Cookie and local storage identifiers;
- Session and activity data in the Service personal account;
- System action logs (for security and incident investigation purposes).
4.3. Client data in the Service (personal account)
- Product cards, SKUs, GTINs, barcodes;
- Order volumes, warehouse stock levels, shipments;
- Integration data with the Client's ERP, WMS, and 1C systems;
- Labelling code orders, aggregation logs.
4.4. Payment data
When making online payments via Click, Payme, Uzum Bank, and other aggregators:
- Payment amount, date, and transaction identifier;
- Masked card number (e.g.,
****1234) — solely for payment identification in the event of a refund; - Payer's email and phone number for receipt delivery.
What the Controller does NOT collect: full bank card number, CVV/CVC code, PIN code, card expiry date, or 3D-Secure data. This information is processed exclusively by payment aggregators certified to the PCI DSS standard and never reaches the Controller's servers.
Important. The Controller does not request or process special categories of personal data (racial or ethnic origin, political opinions, health data, biometric data, etc.).
5. Purposes of Processing
- Service delivery in the field of digital product labelling;
- Concluding and performing agreements with Clients;
- Interaction with government systems — "ASL BELGISI", State Tax Committee, EDI (DIDOX, etc.);
- Communication with the user — handling inquiries and responding to questions;
- Sending information about new services and pricing changes (only with consent);
- Accounting and tax reporting in accordance with the laws of Uzbekistan;
- Information security — incident investigation and fraud prevention;
- Improving the Website and Services (using anonymized data);
- Compliance with the laws of Uzbekistan and execution of government authority requests.
6. Legal Bases for Processing
- Consent of the data subject — obtained in written or electronic form;
- Performance of a contract to which the data subject is a party;
- Compliance with legal obligations imposed on the Controller by the laws of Uzbekistan;
- Protection of the legitimate interests of the Controller and third parties.
7. Processing Methods
Personal data is processed both with and without automated means, including: collection, recording, systematization, accumulation, storage, clarification, retrieval, use, transfer, anonymization, blocking, deletion, and destruction.
The Controller does not make decisions that produce legal effects concerning a data subject based solely on automated processing.
8. Disclosure to Third Parties
The Controller does not sell or transfer personal data to third parties for commercial purposes.
8.1. Transfer for contract performance
- The national labelling operator "ASL BELGISI" — for product registration and code ordering;
- The State Tax Committee of Uzbekistan (STC) — for IKPU registration;
- EDI operator DIDOX — for electronic invoice and certificate circulation;
- Payment aggregators Click, Payme, Uzum Bank — for online payment processing;
- The Controller's bank — for financial settlements;
- Accredited certification authorities — for EDS operations.
8.2. Transfer to processors (subcontractors)
The Controller may engage third parties (hosting providers, mailing services, analytics providers) under agreements obligating them to maintain confidentiality and comply with personal data legislation.
8.3. Transfer under legal requirements
The Controller transfers data to authorized state bodies (law enforcement, tax, judicial) upon substantiated requests within the framework of the laws of Uzbekistan.
9. Data Localization and Cross-border Transfer
In accordance with Article 271 of Law No. ZRU-547 "On Personal Data", databases of personal data of citizens of the Republic of Uzbekistan are stored on servers physically located within the territory of the Republic of Uzbekistan.
Cross-border transfer of personal data to foreign countries is not carried out without the data subject's separate consent or other grounds stipulated by the laws of Uzbekistan.
Where foreign analytics services are used, only anonymized data incapable of identifying a specific individual is transferred.
11. Retention Periods
| Data category | Retention period |
|---|---|
| Client data under the agreement | Agreement term + 3 years |
| Accounting documents | 5 years |
| Inquiry data (email, form submissions) | Up to 1 year from the last contact |
| Analytics cookies | Up to 12 months |
| Service activity logs | Up to 1 year |
| Client EDS data | Only for the duration of service delivery; then destroyed |
Upon expiry of retention periods, data is destroyed or anonymized in a manner that precludes recovery.
12. Security Measures
The Controller implements the following technical and organizational measures to protect personal data:
- Encryption of data in transit over networks (TLS/HTTPS);
- Access control and restriction for employees on a least-privilege basis;
- Regular encrypted backups;
- Server infrastructure protection (firewalls, anti-virus systems, intrusion detection);
- Regular security audits and penetration tests;
- Employee training on information security and signing of NDAs;
- Appointment of a personal data processing officer.
In the event of a security incident resulting in unauthorized access to data, the Controller will notify affected data subjects and the competent authority within the timeframes established by the laws of Uzbekistan.
13. Data Subject Rights
Under Law of Uzbekistan No. ZRU-547, data subjects have the right to:
- Obtain information from the Controller about the processing of their personal data;
- Request correction, blocking, or deletion of data that is incomplete, outdated, inaccurate, unlawfully obtained, or no longer necessary for the stated purpose;
- Withdraw consent to personal data processing at any time;
- Receive a copy of their personal data in a machine-readable format;
- Lodge a complaint with the competent authority (State Inspection for Control in the Field of Informatisation and Telecommunications under the Ministry of Digital Technologies of Uzbekistan) or a court.
How to exercise your rights. Send a request in any form to info@aslraqam.uz, stating your full name, contact details, and the nature of the request. The Controller must process the request within 15 business days of receipt.
14. Minors
ASL RAQAM services are intended exclusively for legal entities and individual entrepreneurs engaged in commercial activity. The Controller does not direct its activities toward the collection of personal data from minors. If such data is found to have been obtained without the consent of legal representatives, it will be deleted immediately.
15. Policy Updates
The Controller may update this Policy. The current version is permanently published at aslraqam.uz/privacy.
Material changes affecting the rights of data subjects take effect no earlier than 14 calendar days after publication. The Controller notifies registered users of such changes by email or through their personal account.
Continued use of the Website or Services following changes to this Policy constitutes acceptance of the new version.
16. Contact for Personal Data Enquiries
ASL RAQAM LLC
Registered address: Tashkent, Gulkhani 11B
Email: info@aslraqam.uz
Phone: +998 90 929-57-75
Telegram: @aslraqam
The competent authority for personal data protection in Uzbekistan — the State Inspection for Control in the Field of Informatisation and Telecommunications under the Ministry of Digital Technologies of the Republic of Uzbekistan: uzcert.uz