• +7 778 231 7826
  • sales@kossanpetroleum.kz
  • Mon-Fri: 9:00-18:00

Privacy Policy

Privacy Policy

Last Updated: December 15, 2024

Important Update: This Privacy Policy was last updated on December 15, 2024, to reflect changes in data protection regulations and our privacy practices.

1. Introduction

Kossan Petroleum ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us in any capacity.

We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) for European Union residents, the Personal Data Protection Act for Kazakhstan, and other relevant international data protection regulations.

Scope: This Privacy Policy applies to all personal information collected through our website, mobile applications, services, and during business interactions with Kossan Petroleum, its subsidiaries, and affiliates.

2. Information We Collect

We collect several types of information for various purposes to provide and improve our services to you.

2.1 Personal Information

Personal information that you voluntarily provide to us, including:

  • Contact Information: Name, email address, phone number, postal address
  • Professional Information: Job title, company name, business contact details
  • Account Information: Username, password, account preferences
  • Communication Data: Correspondence, inquiries, feedback, survey responses
  • Financial Information: Payment details, billing address, transaction history
  • Identification Data: Government-issued ID (for compliance purposes)

2.2 Automatically Collected Information

When you visit our website or use our services, we automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent, navigation patterns, clickstream data
  • Location Data: Approximate geographic location based on IP address
  • Technical Data: Log files, error reports, system performance data

2.3 Information from Third Parties

We may receive information about you from:

  • Business partners and affiliates
  • Publicly available sources
  • Credit reference agencies
  • Government and regulatory bodies
  • Social media platforms (when you interact with us)

3. How We Use Your Information

We use your personal information for the following purposes:

Purpose Type of Data Legal Basis
To provide and maintain our services Contact, Professional, Financial Contractual necessity
To process transactions and payments Financial, Contact Contractual necessity
To communicate with you Contact, Communication Legitimate interest
To improve our website and services Usage, Technical Legitimate interest
To comply with legal obligations Identification, Professional Legal obligation
For marketing and promotions Contact, Usage Consent or legitimate interest
To ensure security and prevent fraud Technical, Usage Legitimate interest

5. Data Sharing and Disclosure

We may share your personal information in the following circumstances:

5.1 With Service Providers

We engage trusted third-party service providers to perform functions and provide services to us, including:

  • Hosting and IT services
  • Payment processing
  • Marketing and analytics
  • Customer support
  • Legal and compliance services

5.2 For Legal Reasons

We may disclose your information where required by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government requests and investigations
  • To protect our rights, property, or safety
  • To prevent fraud or security issues

5.3 Business Transfers

In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

5.4 With Your Consent

We may share your information with third parties when we have your explicit consent to do so.

Data Processing Agreements: All third-party service providers who process personal data on our behalf are bound by strict data processing agreements that comply with data protection laws.

6. Data Security Measures

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

6.1 Security Measures Include:

  • Encryption: Data encryption in transit and at rest using industry-standard protocols
  • Access Controls: Strict access controls and authentication mechanisms
  • Network Security: Firewalls, intrusion detection systems, and regular security audits
  • Physical Security: Secure facilities with controlled access
  • Regular Testing: Vulnerability assessments and penetration testing
  • Employee Training: Regular data protection training for all staff
  • Incident Response: Established procedures for data breach response

6.2 Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with legal requirements.

7. Data Retention Periods

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements.

Data Category Retention Period Rationale
Customer contact information 7 years after last contact Business relationship maintenance
Financial records 10 years Legal and tax requirements
Website analytics data 26 months Performance analysis
Marketing consents Until withdrawal Consent management
Contract documentation 10 years after contract end Legal protection
Compliance records 7 years Regulatory requirements

After the retention period expires, we securely delete or anonymize your personal data.

8. Your Data Protection Rights

Depending on your location and applicable data protection laws, you may have the following rights:

8.1 Right to Access

You have the right to request copies of your personal information that we hold.

8.2 Right to Rectification

You have the right to request correction of any information you believe is inaccurate or incomplete.

8.3 Right to Erasure

You have the right to request that we erase your personal data, under certain conditions.

8.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

8.5 Right to Object to Processing

You have the right to object to our processing of your personal data, under certain conditions.

8.6 Right to Data Portability

You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

8.7 Right to Withdraw Consent

Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates applicable law.

Exercising Your Rights: To exercise any of these rights, please contact us using the details provided in the "Contact Us" section. We will respond to your request within one month of receipt.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our website and hold certain information.

9.1 Types of Cookies We Use:

  • Essential Cookies: Necessary for the website to function properly
  • Preference Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how visitors interact with our website
  • Marketing Cookies: Used to track visitors across websites for marketing purposes

9.2 Managing Cookies

You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse cookies or delete them. However, disabling essential cookies may affect the functionality of our website.

For more detailed information about the cookies we use, please see our separate Cookie Policy.

10. International Data Transfers

Your information, including personal data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.

We ensure appropriate safeguards are in place for international data transfers, including:

  • Standard Contractual Clauses approved by the European Commission
  • Binding Corporate Rules for intra-group transfers
  • Transfer to countries with adequate data protection levels
  • Your explicit consent for specific transfers

11. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18.

If you are a parent or guardian and you believe your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verification of parental consent, we take steps to remove that information from our servers.

13. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

We will also provide additional notification methods for significant changes, such as email notifications or prominent website notices.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Data Protection Officer

Kossan Petroleum

Astana, Yesil district, Syganak street, building 60/2

Kazakhstan

Email: privacy@kossanpetroleum.kz

Phone: +7 778 231 7826 (Privacy Matters)

For general inquiries, please contact us at sales@kossanpetroleum.kz or visit our Contact Page.

Have Privacy Questions?

Contact our Data Protection Officer for any questions about your personal data or our privacy practices.