Privacy Policy
Last updated: 22 September 2026
This Privacy Policy explains what information (including personal data) VAIZEN, OsOO (a limited liability company organised under the laws of the Kyrgyz Republic, registration number 225289-3301-OOO, TIN 01412202310122) collects when you visit the vaizen.dev website, submit a project brief, or engage us for software development, design, consulting, or support services (the "Services"); for what purposes we collect it; how we use, store, and protect it; with whom it may be shared; and how you can exercise your rights.
This Policy applies to all visitors and clients worldwide. It is designed to comply with the EU General Data Protection Regulation ("GDPR") and the UK General Data Protection Regulation ("UK GDPR"). Additional provisions applicable to users in the European Economic Area and the United Kingdom are set out in Section 14.
Who we are (controller)
VAIZEN, OsOO, Tynystanova St., Office 38, Pervomaisky District, Bishkek, Kyrgyz Republic, is the controller of your personal data in respect of the processing described in this Policy.
Privacy contact: support@vaizen.dev
Legal contact: legal@vaizen.dev
Personal data we collect and legal bases
2.1 Brief form data
When you submit a project brief through vaizen.dev/brief, we collect your name, company name, email address, Telegram handle, phone number, a description of your project, your indicative budget range, and your desired timeline. Fields marked optional are not required to submit a brief.
Legal basis: taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR); our legitimate interest in responding to enquiries where no contract follows (Art. 6(1)(f)).
2.2 Technical data
When you visit our website, we process your IP address and User-Agent string for security, abuse prevention, and rate-limiting of the brief form.
Legal basis: legitimate interests in the security and integrity of our website and infrastructure (Art. 6(1)(f)).
2.3 Communications
When you contact us by email or otherwise, we process the content of your message and related metadata (such as your email address and timestamps) in order to respond to you.
Legal basis: performance of a contract, or steps taken at your request prior to entering into one (Art. 6(1)(b)); legitimate interests in providing support (Art. 6(1)(f)).
2.4 Client project data
Where we are engaged to build, design, or maintain software, we may process personal data contained in project materials, credentials, or end-user data that a client provides to us in order to deliver the Services. In this context we act as a processor on behalf of our client, who remains the controller of that data. The terms of that processing are set out in the applicable Statement of Work or in a separate data processing agreement, available on request from legal@vaizen.dev.
Legal basis: performance of a contract with our client; the client's own legal basis governs the underlying processing of its end-user data.
Purposes of processing
We process personal data to: respond to and evaluate project briefs; prepare proposals and enter into and perform contracts; deliver, support, and maintain software we build; secure our website and infrastructure; comply with legal, tax, and accounting obligations; and, where you have consented, measure use of our website.
AI-assisted development
We use AI-assisted development tools as part of our engineering process. We do not submit client confidential source code or project data to train third-party AI models, and we will not do so without a client's prior written consent. Where such tools process code or data on our behalf, we select providers on the basis of appropriate confidentiality and data protection commitments. See also Section 9 of our Terms of Service.
Cookies and analytics
Our website uses a minimal set of cookies and browser storage, described in our Cookie Policy. Analytics tools, such as Google Analytics, are used only where enabled and where you have given your consent through our cookie banner, which you may withdraw at any time.
Sharing and recipients
We do not sell personal data. We share personal data only as necessary with:
Hosting and infrastructure: Hetzner Online GmbH (Germany), which hosts our website, backend, and database.
Email service providers, to send and receive business correspondence.
Telegram, to deliver internal notifications to our team when a new brief is submitted. Telegram receives only the fact and summary of the submission for this purpose.
Analytics providers (Google Analytics), only where enabled and where you have consented.
Professional advisers and legal or compliance recipients, where necessary to comply with law or to establish, exercise, or defend legal claims.
Business successors, in the event of a reorganisation, merger, or sale of assets.
Each service provider processes personal data under a written agreement and only on our instructions.
International transfers
We are established in the Kyrgyz Republic. Our hosting provider and other service providers may process data in other countries, including within the European Economic Area. Kyrgyzstan is not the subject of an adequacy decision of the European Commission or of the United Kingdom. Where personal data is transferred from the EEA or the UK to us, or onward to our processors in third countries, we rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures such as encryption in transit and at rest.
Retention
Brief form submissions that do not lead to a contract: retained for up to 24 months from submission, then deleted.
Data processed under a contract, including invoicing and accounting records: retained for the statutory accounting period applicable in the Kyrgyz Republic, currently five years, and thereafter deleted.
Support correspondence: retained for up to 24 months from the date of the last communication.
Website and infrastructure security logs: retained for up to 30 days, unless a longer period is necessary to investigate a specific security incident.
Client project data processed as a processor: retained and deleted in accordance with the applicable Statement of Work or data processing agreement.
Security
We implement administrative, technical, and organisational measures appropriate to the risk: access controls, encryption in transit and at rest, network segmentation, least-privilege principles, vulnerability management, and confidentiality obligations for staff and contractors.
Your rights
Subject to applicable law, you have the right to: access your personal data; have inaccurate data rectified; have your data erased; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, contact support@vaizen.dev. We will respond within one month, or within such shorter period as applicable law requires. We may ask you to verify your identity before acting on a request. Exercising your rights is free of charge, save for manifestly unfounded or excessive requests.
Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you.
Children
Our Services are directed at businesses and individuals aged 18 or older. We do not knowingly collect personal data from individuals under 18. If you believe a child has provided us with personal data, contact support@vaizen.dev and we will delete it without undue delay.
Personal data breaches
We assess and respond to security incidents promptly. Where required under applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, and we will inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
European Economic Area and United Kingdom
Where you are located in the European Economic Area or the United Kingdom, the GDPR or the UK GDPR applies to the processing described in this Policy. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, or — in the United Kingdom — with the Information Commissioner's Office. Where we rely on legitimate interests, you have the right to object to that processing at any time on grounds relating to your particular situation.
Changes to this policy
We may update this Policy from time to time. The "Last updated" date indicates the latest version. Material changes will be highlighted on our website.
Contact us
📧 Support: support@vaizen.dev
📧 Legal: legal@vaizen.dev
📍 VAIZEN, OsOO, registration number 225289-3301-OOO, Tynystanova St., Office 38, Pervomaisky District, Bishkek, Kyrgyz Republic