This Policy explains how personal data is handled in connection with Apps-EcoSystem, a platform for creating and hosting business applications, managing business records and using optional AI features. It distinguishes the data we handle for our own business from data we process on behalf of businesses using the platform.
Takhir Kabilov, a sole proprietor registered in the Republic of Tajikistan, operates Apps-EcoSystem.
Privacy contact: [email protected].
We act as a controller for personal data used to manage our customer accounts, provide support, administer our own billing, protect the platform and meet our legal obligations.
When a business uses our Service to manage its clients' personal data, that business ordinarily acts as controller and we act as its processor for hosting and operating the application on its behalf. Section 9 explains this relationship.
| Category | Examples |
|---|---|
| Account and sign-in data | Email address, name, business name and identifiers returned by the sign-in method you choose |
| Preferences | Language, time zone and country |
| Application and account content | Business name and description, application configuration, catalogue entries, schedules, stored files and generated promo materials |
| Billing records | Purchased credits, subscription periods, transaction identifiers, amounts, currencies, status and billing information supplied by you or returned by the transaction provider |
| Support records | Your messages, information you provide to investigate a request and our replies |
| Technical and security data | IP address, device and browser information, access logs, errors and service events used for operation and security |
We receive information from you, from your use of the Service and from integrations you choose, such as a sign-in service. Payment and transaction services provide information needed to associate a payment or refund with your account. We do not receive or store full payment-card numbers or card security codes.
Client names, contact details, bookings, lesson records and similar information entered into your Business App are addressed in Section 9.
Where laws such as the EU or UK GDPR apply, we use the legal basis appropriate to the particular processing:
Where we rely on legitimate interests, we consider the impact on individuals and applicable rights to object. We do not treat every purpose as covered by every legal basis.
Some account and billing information is needed to provide access, fulfil a purchase or comply with law. If you do not provide required information, we may be unable to create the account or complete the transaction. Optional profile content and optional integrations are your choice. We identify required fields where information is collected.
For automatic promo creation, the only user-supplied generation inputs are your business name and business description. The platform combines these with its own templates and instructions, selects the underlying model and settings, and transmits the information needed for generation to the AI services it uses. There is no model selector, separate free-form prompt field or reference-media upload. Images and other files stored in your application, and private client records, are not passed to the promo-generation workflow as references. Generated materials and task records are associated with your account so they can be delivered and accessed through the Service.
AI-assisted application setup uses the business information you provide during onboarding to prepare the starter application. Files stored later in your application are not automatically added to a promo-generation request.
AI service providers may also process request information for service security and abuse prevention under the terms applicable to our use of their services. Their retention and data-use arrangements depend on the service and configuration used. Contact us for information about the providers and arrangements relevant to your use.
A business name or description can itself contain personal information, for example the name of a sole proprietor. Provide only information you are authorised to use and that is needed to describe your own business. Do not include private client records, sensitive personal information, children's personal information or unrelated instructions in these fields. Our Terms contain additional content restrictions.
A provider's automated content controls may accept or reject a generation request. This Policy does not represent those controls as a guarantee that every input or output has been reviewed or is safe to publish.
We do not sell personal data or share it for third-party advertising. Relevant data may be disclosed to:
Providers acting as our processors are subject to applicable contractual data-protection obligations. Providers acting as independent controllers determine their own processing within their responsibilities. You can request information about relevant providers by emailing our privacy contact.
The Operator is based in the Republic of Tajikistan, and our service providers may process data in other countries. The countries and applicable protections depend on the infrastructure and services involved.
Where applicable law restricts a transfer, an appropriate legal transfer mechanism is required, such as an adequacy decision or approved contractual safeguards where applicable. Contact us for details of the destinations and safeguards relevant to your personal data and how to obtain information about them.
We retain personal data for the purposes for which it is processed. The criteria differ by category:
You may ask us for information about the retention periods applicable to a particular record or request deletion through our privacy contact. A request for deletion does not require us to erase records we must lawfully retain, but retained data remains limited to the reason for retention.
When you run a Business App, you determine what client information to collect and why. This may include client contact details, appointments, learning records, service history, messages and bookkeeping entries. We host and process that information on your behalf to provide the contracted features.
You must provide your clients with a privacy notice, establish the required lawful basis and configure access appropriately. You must obtain consent where required; simply registering with an application does not provide permission for every subsequent use or unrelated marketing.
Our processing on your behalf must be governed by the appropriate contractual arrangements, including a data-processing agreement where required by applicable law. This public Policy describes our practices and does not replace such an agreement. Contact support about the arrangements applicable to your account.
If you are a client or student of a business using Apps-EcoSystem, contact that business first about its records. Where appropriate, we will assist it with requests and forward requests received by us securely. For information we process independently for platform security or legal obligations, you may contact us directly.
We use technologies needed to keep users signed in, remember relevant preferences and protect the Service. Whether a technology requires consent depends on its purpose and applicable law.
Where consent is required for non-essential analytics, marketing or other technologies, they must remain inactive until that consent is obtained. You can use any consent controls provided to change your choice, and you can manage stored cookies through your browser. Blocking necessary cookies may prevent sign-in or other functions from working. Browser settings alone are not a substitute for consent where it is required.
Depending on the law that applies, you may have rights to access, correct, delete or obtain a portable copy of your personal data; restrict processing; object to processing based on legitimate interests; withdraw consent; and complain to a competent data-protection authority.
Withdrawal of consent does not affect the lawfulness of processing before withdrawal. Some requests are subject to legal exceptions, including required retention and the rights of other individuals.
Email [email protected] to make a request. We may ask for proportionate information to verify your identity or authority. We respond within the deadline required by applicable law and explain any permitted extension. Do not send payment-card security codes or account passwords.
Where we process data for a business customer as processor, we assist that business with the request rather than independently changing its records without authority.
We use technical and organisational measures appropriate to the nature and risks of processing, including secure transport, access restrictions and operational safeguards. No system can guarantee complete security. Protect your sign-in accounts and limit access to your Business App to authorised people.
Where a personal-data incident occurs, we assess it and notify affected controllers, individuals or authorities where required by applicable law and contractual obligations.
Purchasing accounts are intended for adults acting for their businesses. Some businesses, such as schools and tutors, may process minors' data through their applications. Those businesses are responsible for the lawful basis, appropriate notices, safeguards and parent or guardian authorisation where required. We process those records on their behalf as described in Section 9.
If you believe a child has registered as a purchasing account holder or that children's data is being used improperly, contact our privacy address.
We may update this Policy to reflect changes in the Service or data practices. We publish the effective date and notify account holders of material changes through the Service or their account contact. Where new consent is required, we will request it; continued use does not substitute for that consent.