1. Introduction
Bronjoy (“we”, “us” or “our”) respects your privacy. This Privacy Policy explains what personal data we collect when you and your team use the Bronjoy provider dashboard, related APIs, mobile applications and Telegram tools (together, the “Service”), why we collect it, how we use it, with whom we share it and the rights you have over it.
This Privacy Policy is part of, and should be read together with, our Terms of Service.
2. Data controller
The controller of your personal data is:
- Bronjoy — the operator of the platform. The operating company is being incorporated in the Republic of Uzbekistan; its registered details will be published here once registration is complete.
- Operated from: Tashkent, Republic of Uzbekistan
- Privacy contact: [email protected]
3. Legal framework
We process personal data in accordance with the Law of the Republic of Uzbekistan No. ZRU-547 of 2 July 2019 “On Personal Data” (with subsequent amendments) and its implementing regulations. Where applicable, we additionally observe other data-protection rules — for example, the General Data Protection Regulation (GDPR) for users located in the European Economic Area.
4. Personal data we collect
4.1 Data you provide directly
- Identity & contact: name, email address, phone number, position, profile photo (optional).
- Organisation data: business name, address, taxpayer identification (INN/STIR), registration number, beneficial owners, services offered, working hours, team and staff details.
- Verification data: identity documents and additional KYC information requested by us or Stripe.
- Payout data: bank account details, settlement preferences (collected directly by Stripe under Stripe Connect).
- Communications: messages exchanged with our team or with Clients through the Service.
- Preferences: language, theme, notification settings, marketing consents.
4.2 Data collected automatically
- Device & browser: type, model, operating system, browser, screen size, locale.
- Network: IP address, approximate location derived from IP, time-zone.
- Usage: pages visited, features used, search queries, click and scroll events, audit-log entries.
- Diagnostics: crash reports, performance metrics, application logs.
- Cookies and similar technologies (see section 9).
4.3 Data we receive from third parties
- Stripe: verification status, transaction status, payout information, dispute notifications.
- Telegram (when you sign in via Telegram): Telegram user ID, first and last name, username, photo and language code.
- Email and SMS gateways: delivery and read status of verification codes.
- Publicly available sources — business directories and online maps, official registers, and a business's own website and public social-media pages. We use these to build and keep current the unclaimed business profiles described in our Terms of Service (name, address, contact details, opening hours, photographs, category). Where such information also identifies an individual — for example a sole proprietor whose business number is also their personal number — we process it on the basis of our legitimate interest in operating a complete catalogue of local businesses, and you can ask us to correct or delete it at any time.
5. How we use your personal data
We use personal data only for clearly defined purposes, with a corresponding legal basis under the Law “On Personal Data” of the Republic of Uzbekistan and other applicable laws:
- Account management — to register your Organisation, authenticate you and your team and ensure security (performance of contract; consent).
- Service operation — to operate the dashboard, process Bookings and run analytics for your business (performance of contract; legitimate interest).
- Verification (KYC) and compliance — to comply with anti-money-laundering, tax and licensing requirements (legal obligation).
- Payments and payouts — to process Client payments, refunds, chargebacks and your payouts (performance of contract; legal obligation).
- Communication — to send you operational notifications and important updates about the Service (performance of contract; legitimate interest).
- Customer support — to answer your questions and resolve issues (performance of contract; legitimate interest).
- Fraud prevention and security — to detect and prevent fraud, abuse, and security incidents (legitimate interest; legal obligation).
- Product analytics and improvement — to understand how the Service is used and to improve it (legitimate interest; consent where required).
- Marketing — to send promotional messages where you have given consent (consent).
- Legal claims — to establish, exercise or defend legal claims (legitimate interest; legal obligation).
7. International transfers and data localisation
The Personal Data Law of the Republic of Uzbekistan requires that personal data of Uzbek citizens be initially collected, accumulated and stored on servers located within Uzbekistan. We comply with this requirement and maintain a primary copy of such data in Uzbekistan.
Where strictly necessary for the operation of the Service (for example, to process a card payment via Stripe in the United States or to use cloud infrastructure in the European Union), we may transfer personal data outside Uzbekistan. Each such transfer is supported by appropriate safeguards — including contractual data-processing agreements, encryption in transit and at rest, and access controls — proportionate to the risk.
8. How long we keep your data
We keep personal data only for as long as is necessary for the purposes for which it was collected, after which it is securely deleted or irreversibly anonymised. The main retention periods are:
- Organisation and account data — while the Organisation is active, plus up to 36 months after closure (to handle disputes, regulatory requests and re-registration controls).
- Booking and transaction records — up to 5 (five) years from the date of the transaction, to comply with the accounting and tax legislation of the Republic of Uzbekistan.
- KYC and verification records — at least 5 (five) years after the end of the business relationship, in line with anti-money-laundering legislation.
- Authentication and audit logs — up to 24 months for security and fraud prevention.
- Customer support correspondence — up to 36 months from your last interaction.
- Marketing consent records — until you withdraw consent, plus 12 months for record-keeping.
10. Your rights
Under the Law of the Republic of Uzbekistan “On Personal Data” you have the right to:
- be informed about the processing of your personal data;
- access your personal data and obtain a copy in a structured, commonly used format (data portability);
- request correction of inaccurate or incomplete data;
- request deletion of your personal data, subject to our legal retention obligations;
- request restriction of, or object to, certain processing activities;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with the State Personalisation Centre of the Republic of Uzbekistan or another competent authority.
To exercise any of these rights, write to [email protected]. We will respond within 30 (thirty) calendar days. To protect your account, we may need to verify your identity before fulfilling certain requests.
11. Security
We apply technical and organisational measures appropriate to the risks, including TLS encryption in transit, encryption at rest for sensitive data, hardened server configurations, role-based access controls, regular vulnerability monitoring, encrypted backups and a documented incident-response procedure.
No system can be guaranteed to be 100% secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the competent authority in accordance with applicable law.
12. Automated decision-making
We do not use solely automated decision-making (including profiling) that produces legal or similarly significant effects on you.
We do use AI tools to support the Service — for example to write, translate and tidy up the business descriptions in our public catalogue, to improve search and recommendations, and to draft suggestions inside the Bronjoy dashboard. Suggestions that would affect a Booking, an account or money are always reviewed and approved by a person before they take effect, and you can ask us to explain any outcome by writing to [email protected].
13. Children
The provider Service is not directed to persons under 18 years of age. Members must be of legal working age in the Republic of Uzbekistan and authorised by the Organisation.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version is always available on the Service and the “Last updated” date at the top of this page indicates when it took effect. For material changes, we will give you at least 14 days' advance notice by email or through the dashboard before they take effect.
15. Contact us and complaints
If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact us:
- Privacy email: [email protected]
- Correspondence: by email at the address above, pending publication of a registered postal address.
You also have the right to file a complaint with the State Personalisation Centre of the Republic of Uzbekistan if you believe that your data-protection rights have been violated.