← Back to home

PRIVACY POLICY AND PERSONAL DATA PROCESSING POLICY OF THE KMAIL DIGITAL SERVICE

Revision date: May 20, 2026

1. GENERAL PROVISIONS

1.1. This Privacy Policy and Personal Data Processing Policy (hereinafter — the "Policy") governs the relationship between the Kmail Digital Service (hereinafter — the "Service") and the User related to the processing of information in the course of using the digital service available through the web interface and mobile applications.

1.2. This Policy has been developed in accordance with the Digital Code of the Kyrgyz Republic and other regulatory legal acts of the Kyrgyz Republic governing legal relations in the field of digital technologies and information protection.

1.3. The Service does not pursue profit-making objectives. Data processing is aimed at ensuring secure electronic communication and developing users' digital literacy.

1.4. Registration or authorization in the Service constitutes the User's unconditional consent to the terms of processing of their information described in this Policy.

2. LIST OF INFORMATION COLLECTED AND PURPOSES OF PROCESSING

2.1. The Service collects and processes information only to the extent necessary for the technical provision of mail services and fulfillment of the agreement with the User.

2.1.1. Account data

  • Full name, date of birth, gender, phone number, email address (backup), country and city of residence.

2.1.2. Technical data when using the web interface

  • IP address, information about browser type and version, cookie files, interface language settings, operating system information, time zone, and screen resolution.

2.1.3. Mobile application data (Android and iOS)

  • Mobile device type and model, OS version, unique device identifiers (Device ID), name of the telecommunications operator, type and stability of the internet connection.

2.1.4. Communication and address book data

  • Email addresses of contacts entered by the User, number of contacts, recipient addresses to which messages were previously sent, as well as message metadata (send time, file size).

2.1.5. Verification and security data

  • Confirmation codes sent in text messages.

2.1.6. Activity information

  • Information about clicks, navigation through menu elements, and use of internal mail management tools.

2.2. The purposes of processing are:

  • Providing access to the functionality of the Service (receiving, transmitting, and storing electronic messages).
  • Ensuring the information security of the Service, preventing unauthorized access to accounts, and suppressing the spread of malicious software and spam.
  • Compliance with the requirements of the Digital Code of the Kyrgyz Republic regarding user identification and storage of metadata about communication sessions.
  • Providing technical support to users.

3. COOKIE FILES AND TRACKING TECHNOLOGIES

3.1. The Service uses cookie files to maintain the User's active session (so that a password does not need to be entered each time the page is refreshed) and to analyze preferences (language selection, theme settings).

3.2. The User may disable cookies in browser settings; however, this may result in the inability to use certain features of the Service.

4. CORRESPONDENCE PRIVACY AND AUTOMATED PROCESSING

4.1. The Service ensures the privacy of correspondence. The content of messages is confidential.

4.2. The User agrees to the application of automated analysis algorithms (without human involvement) to the content of messages and attachments solely for:

  • Recognizing and blocking spam mailings.
  • Checking files for viruses and malicious software.

4.3. Service employees do not have access to the content of the User's messages, except in cases where the User themselves has contacted support with the appropriate permission to resolve a technical issue.

5. TRANSFER OF DATA TO THIRD PARTIES

5.1. The Service does not sell or transfer Users' personal data to advertising agencies or other third parties not provided for by the legislation of the Kyrgyz Republic.

5.2. Transfer of data to third parties is possible only in the following cases:

  • As required by law: The User's personal data may be disclosed or transferred exclusively in cases and in the manner directly provided for by the legislation of the Kyrgyz Republic, including upon a substantiated request from authorized government bodies, subject to the appropriate legal basis (for example, a court order, an order of a supervisory authority, or a requirement arising from an international obligation).
  • Cross-border transfer: Carried out only if necessary to deliver an electronic message to a recipient located in another jurisdiction.

5.3. When transferring personal data across borders, the Service ensures a level of protection no lower than that provided for by the legislation of the Kyrgyz Republic and, if necessary, conducts a legal and technical risk assessment related to such data transfer.

5.4. The Service is not liable for cases of disclosure of personal data that occurred as a result of the User's own actions, including intentional transfer of information to third parties or careless handling of account access, as a result of which personal data became known to unauthorized persons. The Service recommends that Users observe digital hygiene measures and ensure the confidentiality of their authorization credentials.

6. STORAGE AND PROTECTION OF INFORMATION

6.1. Storage of personal data of citizens of the Kyrgyz Republic is carried out on servers.

6.2. The Service may implement the following protection measures:

  • Two-factor authentication (2FA) as a standard access protection measure.
  • Regular security system audits for vulnerabilities.
  • Use of intrusion detection and prevention systems.
  • Appointment of a responsible person for organizing the processing and ensuring the security of personal data.
  • Adoption and observance of necessary measures, including legal, organizational, and technical measures, to protect personal data in accordance with the legislation of the Kyrgyz Republic.
  • Compliance with the legislation of the Kyrgyz Republic on personal data, their confidentiality, and their protection.

6.3. Data is stored for the entire duration of the Account.

6.4. After deletion of the Account, information is stored for 30 days. Account recovery is possible during this period.

6.5. After the expiration of 30 days, the Account and all data associated with it are deleted without the possibility of recovery.

6.6. Messages sent or received by the User may be stored in the system longer than the duration of the Account in order to ensure the integrity of correspondence of other users.

7. USER RIGHTS

7.1. In accordance with the legislation of the Kyrgyz Republic, the User has the right to:

  • Receive information about the terms and methods of processing their data.
  • Request clarification, modification, or correction of their data.
  • Data portability (export in a machine-readable format).
  • Withdraw consent at any time and delete their account together with all associated information.

8. CHANGES TO THE POLICY

8.1. The Service has the right to make changes to this Policy. The new version takes effect from the moment of its publication on the Service website.

8.2. The User undertakes to independently monitor changes. Continued use of mail after the Policy is updated constitutes consent to the new terms.

Appendix No. 1: Electronic Consent Form

By confirming registration in the Service __________, I, acting in accordance with Article 79 of the Digital Code of the Kyrgyz Republic, give my consent to the automated processing of my personal data, including metadata and the content of electronic correspondence, on the terms set forth in this Policy. I have been informed of my right to access, modify, and delete my data, as well as of the guarantees of compliance with the privacy of my correspondence.