Personal Data Collection, Processing and Protection Policy
This policy explains what the SMM DRUG website processes, why it is needed, possible recipients and how data-subject rights can be exercised.
1. Personal-data controller
ИП «SMM DRUG», entrepreneur Маликов Олег Михайлович, IIN 000527501224, registered address: Республика Казахстан, г. Алматы, мкр. Алмагуль, 27.
For personal-data enquiries: smmdrug@gmail.com, +7 707 521 05 65.
2. Who and what this policy covers
This policy applies to visitors to smmdrug.kz who use the enquiry form, calculators, or otherwise interact with the website. After a visitor follows a link to WhatsApp, Telegram, Instagram, YouTube or another external platform, subsequent processing is also governed by that service's rules.
3. Data we process
- the name and surname, phone number or WhatsApp number, and optional task description entered by the user in the form;
- the selected service, parameters and result of the preliminary calculation, the page and source of the enquiry;
- the consent version, enquiry number, date and server time of acceptance;
- UTM tags, advertising click identifiers, the first page visited and external referrer;
- the IP address and a limited set of technical request data — to protect the form, limit spam and maintain security logs; the raw IP address is not sent to managers in Telegram;
- technical identifiers and visit information created by Yandex Metrica, by Google Tag Manager as the sole loader of one Google Analytics 4 property and Google Ads conversion-measurement tags, and by Meta Pixel for Instagram audiences and retargeting.
4. Purposes and legal grounds
Processing is based on the user's demonstrable consent, steps taken at the user's request before entering into a contract, a concluded contract and obligations expressly imposed by the laws of the Republic of Kazakhstan.
- to respond to an enquiry, clarify the task and prepare a proposal, calculation and draft contract;
- to perform a contract, process payments and prepare mandatory accounting documents;
- to provide the service context to a manager and make contact by the selected method;
- to assess advertising effectiveness using server-accepted enquiries and WhatsApp or phone clicks, and to improve the website;
- to ensure information security, prevent automated spam and protect the controller's lawful rights.
5. Processing operations and recipients
The controller may collect, organise, store, update, use, transfer, block and destroy data to the extent necessary for the stated purposes.
- The form uses the website server, and the primary enquiry database is hosted on server infrastructure in the Republic of Kazakhstan.
- The content of an enquiry may be sent to a closed Telegram workspace for prompt handling. This is a transfer to a third party and a possible cross-border transfer, for which separate, explicit consent is requested in the form.
- Google Tag Manager loads the single Google Analytics 4 property and Google Ads conversion-measurement tags on every page of the website; Yandex Metrica loads alongside it. Google receives only technical events for a server-accepted enquiry and WhatsApp or phone clicks — not the visitor's name, phone number or enquiry message. Google remarketing and Google enhanced conversions are not used.
- Meta Pixel (Main Dataset, ID 708928263783270) runs on production pages to build visitor audiences, show SMM DRUG ads on Instagram and measure results. Meta receives PageView and allowlisted action events, the IP address, user-agent, referrer and current URL, and may create _fbp/_fbc cookies. Names, phone numbers, enquiry text, calculations and advertising click IDs are not sent as Meta event parameters; Conversions API is not used. Processing under the providers' rules may be cross-border.
- Access is granted only to the entrepreneur, authorised employees and contractors who need the data to respond or perform a contract and who are required to maintain confidentiality.
- Data is not published in publicly available sources and is not sold. It is transferred to public authorities only where there is a lawful request.
6. Retention periods
- An enquiry that does not result in a contract, together with evidence of consent, is retained for no more than 12 months after the last meaningful contact and is then deleted or anonymised.
- Current-client data and accounting documents are retained for the term of the contract and the mandatory periods established by law.
- A technical pseudonym of the IP address used for rate limiting is needed for 10 minutes; server security logs must be rotated under an approved procedure.
- Advertising attribution and the _ga*, _ym*, _gcl_*, _fbp and _fbc cookies accessible to the website are removed when the specified period expires or browser data is cleared.
- Retention periods for external analytics services are determined by their settings and policies; collection can be limited with browser tools.
7. User rights
A request may be sent to smmdrug@gmail.com. To prevent disclosure to another person, the controller may request information reasonably needed to verify the requester's identity. Withdrawal does not invalidate processing that was already lawful and does not end retention required by law or contract.
- to obtain information about whether and how their data is processed;
- to request correction, blocking or deletion of inaccurate or unlawfully processed data;
- to withdraw consent to future processing;
- to challenge the controller's actions before the competent authority or a court.
8. Data security and incidents
The controller uses access controls, HTTPS, server-side form validation, rate limiting, storage of secrets outside the public website and other organisational and technical measures. Access permissions are reviewed and data is deleted after its purpose has been achieved. If a security breach is identified, the controller acts under the approved response plan and notifies the competent authority in the cases and within the timeframes required by law.
9. Minors and updates
The services are intended for adult business representatives. The controller does not knowingly request data from minors; a legal representative should submit an enquiry on their behalf.
The current version is published at this address. If the purposes, data categories or recipients change materially, new consent is requested where required by law.