Privacy Policy
Last updated: June 2026
In short
- Your data is used only to operate the service — not for advertising, not for sale.
- When you use AI features, some content is sent to Google LLC (USA).
- We do not see or store your bank card data — it is collected directly by БЦК Bank under their own privacy policy.
- You can download or delete your data at any time in Account settings.
- Any questions: studio@zhandarcompany.com
1. Who we are
Tezio is a web application for creating, editing, previewing and exporting business proposals using AI features. The personal data operator — the legal entity responsible for this service — is:
2. Who can use Tezio
Tezio is intended for legal entities, individual entrepreneurs and individuals aged 18 and over using the service for professional or business purposes. By registering, you confirm that you meet this requirement. If you are under 18, please do not register.
3. What data we collect
- Account data: Name, email address, password hash (not the password itself), interface language, avatar URL (if uploaded).
- Company profile: Name, description, history, contacts, social links, logo, brand colors, currency, team description, projects, cases.
- Client data: Client name, contact person, email, phone, industry, notes — entered by you and processed on your behalf.
- Business proposals: Section texts, prices, deadlines, terms, design settings.
- AI usage metadata: Action type, success/error status, date — without the prompts or AI responses themselves.
- Payment metadata: Payment status, amount, currency, transaction ID from БЦК Bank. We do not receive card data or CVV.
- Technical data: Session and language cookies; IP address in technical logs.
Passwords are stored only as a hash — neither we nor anyone else can read them in plain text.
4. Why and on what basis we process data
We process personal data on the following grounds under Article 7 of the Law of the Republic of Kazakhstan "On Personal Data and Their Protection" dated 21 May 2013 No. 94-V:
For service delivery:
- Account creation, login, session management
- Storing company profile, clients and proposals
- Preview and PDF export
- Payment processing for PDF export
Based on your consent:
- Transferring content to the AI provider (Google Gemini) when using AI features
- Cross-border data transfer to the USA (Google, Resend, DigitalOcean)
- Sending transactional emails via Resend
Based on legitimate interest (security and service quality):
- Maintaining technical logs for error diagnosis
- Tracking AI usage limits and preventing abuse
5. Who we share data with
We work only with the contractors necessary for the service to operate. We do not sell personal data.
| Service | Country | What is transferred | Purpose |
|---|---|---|---|
| Google LLC (Google Gemini) | USA | Brief text, proposal section content, company name and description, client name, generation language | AI text generation and improvement |
| Resend, Inc. | USA | Email address | Email verification and password reset letters |
| DigitalOcean, LLC | USA | All account data | Application and database hosting |
| Bank CenterCredit JSC (БЦК Bank) | Kazakhstan | Payment amount, currency, order ID | Payment processing for PDF export |
DigitalOcean stores data on servers physically located in Frankfurt, Germany.
6. AI features — Google Gemini
When you use AI Smart Fill, Generate or Rewrite, requests are sent to Google LLC (Google Gemini, USA). The following is included in the request:
- Brief text (if you filled it in)
- Content of the proposal section being edited
- Company data from your profile: name, description, history, team, experience, contact details (email, phone, website, address, contact person)
- Client name and proposal title
- Selected generation language
We do NOT send to Google: passwords, user email addresses, card data, pricing amounts, data of other clients.
We do not save the prompts or AI responses themselves. Only metadata is stored: action type, success/error status, and date.
By using AI features, you give explicit consent to the transfer of data to the USA under Article 22 of the Law of the Republic of Kazakhstan "On Personal Data and Their Protection". Google processes these requests under its Privacy Policy and the Gemini API Usage Policy.
7. Email service — Resend
We send only two types of transactional emails: email address verification on registration and password reset. For delivery we use Resend, Inc. (USA). Your email is transferred solely for this purpose. We do not send marketing emails.
8. Hosting — DigitalOcean
The application and database are hosted on servers of DigitalOcean, LLC (USA). The servers are physically located in the region: Frankfurt, Germany. DigitalOcean maintains access to the infrastructure for technical purposes but does not process your data for its own ends.
Uploaded files (e.g. your company logo) are stored on the same server, without transfer to external storage services (S3, Cloudinary, etc.).
9. Payments — БЦК Bank
PDF export payments are processed through the gateway of Bank CenterCredit JSC (БЦК Bank, Kazakhstan). When you pay, you are redirected to the bank's page where you enter your card details directly. Tezio does not receive, see or store your card number or CVV — that data is collected by БЦК Bank under their own privacy policy. We only receive a payment result notification (success / error) and the transaction ID.
10. Cookies
We use only technically necessary cookies. Advertising, marketing and tracking cookies are not used. Third-party trackers (Google Analytics, Facebook Pixel, etc.) are not connected.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie (authorization) | Maintaining your login session | Until logout |
| Language cookie | Saving the selected interface language | 1 year |
11. Cross-border data transfer
Part of your data is transferred outside the Republic of Kazakhstan — to the USA:
- Google LLC — when using AI features
- Resend, Inc. — your email on registration and password reset
- DigitalOcean, LLC — application and database storage
The transfer is based on your explicit consent given at registration, in accordance with Article 22 of the Law of the Republic of Kazakhstan "On Personal Data and Their Protection" dated 21 May 2013 No. 94-V.
12. Data retention and deletion
| Data | Retention period |
|---|---|
| Account, profile, clients, proposals | Until account deletion |
| Backups | Up to 30 days after account deletion |
| Technical logs | Up to 30 days |
| AI usage metadata | Until account deletion |
| Payment transaction IDs | As required by RK law (up to 5 years) |
To delete your account: Account settings → "Data" section → "Delete account" button. All your data is immediately removed from the active database. Backups are automatically deleted within 30 days. If you cannot delete your account yourself, write to studio@zhandarcompany.com with the subject "Account deletion".
13. Your rights
As a personal data subject under Article 27 of the RK Law, you have the right to:
- Access: Get information about what data we hold about you ("Export data" in Settings).
- Correction: Update incorrect data in Account settings or Company profile.
- Deletion: "Delete account" button in Settings, or request to studio@zhandarcompany.com.
- Portability: Receive your data in machine-readable JSON format ("Export data" in Settings).
- Withdrawal of consent: You may withdraw consent at any time. Since processing is necessary for the service, withdrawal means account deletion.
- Complaint to the regulator: You may file a complaint with the Committee for Information Security of MDDIAI RK.
All requests are processed within 15 business days of receipt. Send requests to studio@zhandarcompany.com with the subject "Data request" or "Data deletion".
14. Security and incidents
Security measures we apply:
- Passwords stored as a hash (bcrypt) — cannot be read in plain text
- Sessions protected with signed tokens
- Access limited by accounts and workspaces
- Connections encrypted via HTTPS
No protection method provides a 100% guarantee. In the event of a security incident resulting in unauthorised access to your personal data, we will notify affected users by email within 72 hours of discovery, and will notify the Committee for Information Security of MDDIAI RK within the timeframe required by law. The notification will state: the nature of the incident, what data was affected, measures taken, and a contact for questions.
15. Policy changes
We may update this policy. The current version is always available at tezio.app/privacy with the update date. For material changes (new data categories, new recipients, changes to retention periods) we will notify you by email at least 14 days before they take effect. Minor technical edits take effect immediately upon publication.
16. Contacts
For privacy questions:
Company: ЧАСТНАЯ КОМПАНИЯ ZHANDAR COMPANY LTD
BIN: 240640900334
Legal address: Republic of Kazakhstan, Astana, Yesil district, Mangilik El Avenue, building 55/18
Email: studio@zhandarcompany.com
Regulatory authority: Committee for Information Security of MDDIAI RK · gov.kz