BUDO.ASIA PRIVACY POLICY

Revision date: 9 September 2026

1. Scope

This Policy explains what personal data Budo.asia processes, why and on what basis, recipients, transfers and data-subject rights. It applies to visitors, users, coaches, clubs, federations, organisers, competitors, parents and legal representatives.

The database owner/operator is Sole Proprietor “AQYLDY SHESHIMDER”. Privacy requests may be sent to budo.asia@gmail.com.

2. Processing roles

For accounts, security, support and the Portal’s own functions, the Operator determines the purposes and means and performs the duties of a database owner and/or operator.

A coach, club, federation or organiser that selects participant data and enters it for an event is responsible for lawful initial collection, accuracy, notice and required consent. This does not release Budo.asia from protecting data processed through the Portal.

3. Data categories

Account data: name, contact details, language, role, club or organisation, protected password data and settings.

Athlete and participant data: name, date/year of birth, sex, weight and age category, country, city, club, coach, grade, entry, discipline, eligibility status, schedule, bracket, opponents, score, placing, rating and results.

Content: photographs, logos, images, captions and files uploaded by users. Identity documents, medical documents and other excessive data should not be uploaded unless expressly required by a Portal function.

Technical data: IP address, access time, device, browser, operating system, language, pages and actions, session identifiers, cookies, error and security logs.

Communications and commercial data: support messages, complaints, consent/action records and, after paid services launch, order, tariff, amount, currency, payment status and date. Full card details are not stored where the external payment provider PayLink.kz processes payment.

4. Purposes and legal bases

Purposes include registration and authentication; account functions; tournaments, entries, categories, brackets, schedules and results; coach and club pages; photographs; support; fraud and attack prevention; contracts and legal compliance; protection of rights; and Portal improvement.

Legal bases include consent of the data subject or legal representative, performance of a contract or pre-contract request, Kazakhstan law and other bases expressly permitted by law. Consent is captured in a verifiable form, including through the Portal interface, an electronic document or paper.

Names, clubs, categories, brackets, photographs and results are displayed publicly only to the extent needed for the public event function and covered by consent or another lawful basis.

5. Minors

A coach, club, federation or organiser representative entering a minor’s data must first obtain parental or legal-representative consent for the specific processing, including public photographs and results where applicable.

The person entering data must retain evidence for the necessary period and produce it on a justified request. That person is responsible for missing consent, exceeding its scope and inaccurate entries.

For independent registration by a minor, the Operator may request legal-representative consent and restrict publication, photo upload or other higher-risk functions until verified.

6. Cookies and external technologies

Necessary cookies and similar storage support login, sessions, language, security and stability. Disabling them may prevent account functions.

At this revision, a check of the public home page found no Google Analytics or Yandex Metrica; the site contains YouTube- and Telegram-related links or functions. Before analytics, advertising identifiers or optional cookies are enabled, this Policy and the user-choice mechanism must be updated.

An external service may receive IP, device and activity data when a user follows a link, plays embedded content or uses its feature under that service’s policy.

7. Recipients and disclosure

Access is limited to authorised Operator personnel and contractors, Hoster.KZ, technical support, email, security and backup providers and, after payments launch, the payment organisation PayLink.kz. Organisers, clubs, coaches, officials and participants receive data according to event roles and settings.

Public event data may be available to anyone and indexed by search engines. Before a minor’s data is published, the contributor must ensure consent covers public dissemination.

Data may be disclosed on a lawful government request, to protect rights or prevent harm. The Operator does not sell personal data. Sharing contact/profile data with advertisers for their own marketing requires a separate lawful basis.

8. Localisation and cross-border transfer

The primary personal-data database is hosted by Hoster.KZ in Almaty, Kazakhstan. Device-to-Portal traffic is protected by HTTPS.

YouTube, Telegram and other foreign services may involve cross-border transfer of technical or user data. Such transfer requires a lawful basis and compliance with Kazakhstan law; the interface informs users where transfer depends on their choice.

9. Retention

Account data is kept while active and afterward only as needed for claims, law and protection of rights. Event data and published results may be kept as a sports archive while a lawful purpose and basis remain.

When the purpose ends or consent is withdrawn, data is erased or anonymised unless retention is required by law, contract, dispute resolution or protection of rights. Backups are removed through restricted-access overwrite cycles.

The Operator reviews retention periodically. A user who supplied third-party data must keep it current and initiate erasure when the lawful basis ends.

10. Security

Measures include role-based access, encrypted transmission, account controls, event logging, software updates, backups and incident response.

No system is absolutely secure. Following a breach, the Operator limits harm and fulfils applicable legal notification duties to authorities and data subjects.

11. Data-subject rights

A data subject or legal representative may obtain processing information; seek correction, blocking or erasure where grounds exist; withdraw consent; object to unlawful processing; and seek protection from an authority or court.

Requests go to budo.asia@gmail.com. Reasonable identity and authority verification may be required. Withdrawal does not affect prior lawful processing and may be restricted where the law permits.

Where a coach or organiser supplied the data, the subject may contact either that person or Budo.asia directly; prior resolution with the coach is not required.

12. Changes and contact

The Policy may change with law, functions, recipients or technology. The current version and revision date are published on the Portal, with reasonable notice of material changes.

Operator: Sole Proprietor “AQYLDY SHESHIMDER”, Almaty, Republic of Kazakhstan. Email: budo.asia@gmail.com. Portal: https://budo.asia.

Platform owner details

Individual Entrepreneur “AQYLDY SHESHIMDER”

Individual Identification Number: 790520000010

State registration: 16 July 2026, Notification No. KZ52UWQ08714413

Registered address: 90 Latifa Khamidi Street, Zhetysu District, Almaty, Republic of Kazakhstan

Telephone: +7 776 066 4795

Email: budo.asia@gmail.com

Website: https://budo.asia/