iDonate Platform Privacy Policy
(Personal Data Processing Policy)
- Version: 2.0
- Effective date: for new users and Donors — 05.10.2026; for Streamers who registered before this version was published — from the day they give the consent requested in clause 21.5
- Permanent address: https://idonate.uz/privacy-policy
- Previous version: the 2024 version. It ceases to have effect from the date this version enters into force.
Summary
The following summary is provided for convenience. The full and legally binding text is set out in the sections that follow it.
- Your personal data is processed by the owner and operator of the iDonate platform — "CODO IT" LLC (Section 2).
- Only the data necessary for the operation of the Platform, payments, security and compliance with legal requirements is collected (Sections 5–6).
- Your data is not sold. No advertising or web analytics tracking tools (trackers) are used on the Platform (Section 13).
- The Platform's main servers are located in Uzbekistan (in the city of Tashkent). For certain services, part of the data is transferred abroad. These services are: Telegram, text-to-speech conversion, bot protection, Google and the AI assistant in the dashboard (Section 10).
- When you make a Donation, your name (nickname), message and voice message may be shown publicly on the Streamer's live stream. Do not include personal data in your message (Section 8).
- Payment card details are entered not on the Platform but on the Payment Organization's page (clause 5.9).
- Your rights, the procedure for submitting requests and the procedure for deleting an account are set out in Sections 15–17. Email address for requests: info@idonate.uz (clause 2.1).
1. General Provisions
1.1. This Privacy Policy (hereinafter — the Policy) sets out how "CODO IT" LLC processes personal data on the iDonate platform. It specifies:
- what data is processed, for what purposes and on what legal grounds;
- to whom data is disclosed, and where and for how long it is stored;
- how data is protected;
- the rights of personal data subjects and the procedure for exercising them.
1.2. The Policy has been developed in accordance with the following documents:
- Law of the Republic of Uzbekistan No. ZRU-547 "On Personal Data" dated 2 July 2019 (hereinafter — the Law);
- the Model Procedure for Processing Personal Data, registered with the Ministry of Justice on 15 November 2023 under No. 3478 (hereinafter — the Model Procedure);
- Resolution of the Cabinet of Ministers of the Republic of Uzbekistan No. 415 dated 29 July 2026;
- other legislative acts.
1.3. The Policy applies to the following (hereinafter collectively — the Platform):
- the website https://idonate.uz and its subdomains;
- Streamers' donation pages;
- the Streamer's Personal Dashboard;
- widgets (overlays) for OBS and other streaming software;
- the Operator's official Telegram bots (@idonateuzbot, @idonateuz_bot and @idonatetts_bot);
- the Platform's application programming interfaces (API).
1.4. The Policy does not apply to third-party websites and services (for example, the payment pages of the Payment Organization and banks, YouTube, Twitch, Telegram and Google). If you follow a link or use their services, they process your data in accordance with their own rules.
1.5. The Policy is an integral part of the iDonate platform Public Offer (https://idonate.uz/public-offer). In the event of a conflict between the Policy and the Offer on matters of personal data processing, the provisions of the Policy shall apply.
1.6. How consent is given.
- A Streamer, when registering (on the website or in the Operator's Telegram bot), accepts the Public Offer and this Policy by ticking the corresponding box (pressing the consent button). This constitutes consent to the processing of personal data for the purposes specified in the Policy, including the cross-border transfer specified in Section 10 (Article 21 of the Law, clause 9 of the Model Procedure).
- A Donor clicks the payment button on the donation page, next to which links to the Policy and the Public Offer are displayed. By doing so, the Donor consents to the processing necessary to make the Donation, to the public display specified in Section 8 and to the transfer specified in Section 10.
- For a Visitor, only technical data is processed. Such processing is necessary for the operation and security of the Platform (Section 6).
- Form and proof of consent. Consent is given in electronic form. The Operator records the date and time at which the Streamer's consent was given, the method used (website, Telegram bot or the acceptance window in the dashboard), the IP address and the version of the Policy (Article 31 of the Law).
- Term of consent. The Streamer's consent remains valid for as long as the account exists, and the Donor's consent remains valid for the retention periods specified in Section 12. Consent may be withdrawn at any time in accordance with the procedure set out in Section 17 (clauses 10 and 11 of the Model Procedure).
- Previously registered Streamers. From Streamers who registered before this version of the Policy entered into force, the Operator requests separate consent to this version, including to the cross-border transfer specified in Section 10 (clause 21.5).
1.7. The official text of the Policy is in the Uzbek language. Translations into other languages are provided for information purposes. In the event of any discrepancy between the texts, the Uzbek text shall prevail.
2. Information about the Operator
2.1. The owner and operator of the personal data database (hereinafter — the Operator):
- Name: "CODO IT" Limited Liability Company
- TIN: 311366908
- Location (legal address): Navoiy viloyati, Navbahor tumani, Yangiqoʻrgʻon QFY, Sarbozor MFY, Davriqoʻrgʻon koʻchasi, 182-uy
- Postal address: the same as the legal address
- Email (including for requests concerning personal data): info@idonate.uz
- Phone (support): +998 (95) 069-99-11
- Telegram (support): https://t.me/idonate_admin
- Website: https://idonate.uz
2.2. The Operator has designated a person responsible for the processing and protection of personal data (Article 31 of the Law). This person may be contacted via the email address specified in clause 2.1. Write "Personal Data" in the subject line of the email.
3. Key Terms
The following terms are used in the Policy:
-
Personal data — any information relating to a specific natural person or allowing that person to be identified (Article 4 of the Law).
-
Data subject — the natural person to whom the personal data relates.
-
Processing — any action or set of actions performed with personal data: collection, systematization, storage, modification, supplementation, use, provision, dissemination, transfer, depersonalization and destruction.
-
Dissemination — disclosure of data to an indefinite range of persons. For example, displaying a donation message on a public live stream.
-
Cross-border transfer — transfer of personal data outside the territory of the Republic of Uzbekistan.
-
Depersonalization — actions that make it impossible to determine that data belongs to a specific data subject.
-
Third party (service provider) — a person who is neither the data subject nor the Operator but is involved in the processing. For example, the Payment Organization, the SMS service or the hosting provider.
-
Streamer — a person who has registered on the Platform and opened a Personal Dashboard in order to receive Donations.
-
Account holder — the natural person in whose name the account on the Platform is registered, who has passed identification and to whose settlement account payments are credited. As a rule, the account holder is the Streamer themself.
-
Channel Host — a person, other than the account holder, who actually conducts the live streams on the channel linked to the account with the account holder's consent, for example, a family member (clause 5.4).
-
Donor — a person who sends a Donation to a Streamer. The Donor does not register on the Platform.
-
Visitor — a person who opens any page of the Platform.
-
Payment Organization — a licensed organization that accepts and transfers payments. The current Payment Organization is "MULTICARD PAYMENT" Joint-Stock Company (License No. 26 of the Central Bank of the Republic of Uzbekistan dated 12.05.2021).
-
Widget — an element of the Platform that the Streamer displays on their live stream. For example, a donation notification, a goal bar, a top Donors list, a wheel or a chat.
-
Dashboard — the Streamer's Personal Dashboard on the Platform.
-
"Rahmat" service — a third-party service used by the Operator to verify, on the basis of the Streamer's PINFL and phone number, the Streamer's official surname, first name and patronymic (hereinafter — full name), self-employed status and payment details.
-
Streamer Settlement Account, Commission, Personal Dashboard, username — have the meanings given in the Public Offer. In the Policy, "service fee" means the Commission under the Offer, and "dashboard" means the Personal Dashboard.
Other terms in the Policy are used in the meanings given in the Law.
4. Processing Principles
4.1. The Operator processes personal data on the basis of the following principles:
- lawfulness — processing is carried out only on a lawful basis;
- purpose limitation — data is used only for the purposes announced in advance;
- data minimization — only data in the amount necessary and sufficient for the purpose is collected;
- accuracy — data is kept accurate and is updated where necessary;
- storage limitation — data is stored until the purpose is achieved or for the period established by law;
- confidentiality and security — data is protected against unauthorized access and disclosure.
4.2. The Operator does not sell personal data, does not lease it and does not provide it to third parties for advertising purposes.
4.3. If the purpose of processing changes, the Operator obtains separate consent from the data subject for the new purpose (Article 19 of the Law).
5. What Data Is Processed
5.1. All Visitors
a) Technical data. It is recorded in web server and application logs:
- IP address;
- browser and device type (User-Agent);
- date and time of the request;
- address of the page opened;
- technical information about errors.
The logs also record notifications from the Payment Organization (which contain the payer's phone number) and login events (with the Streamer's phone number).
b) Cookies and data in browser storage (Section 13).
c) Country detection. The Operator does not determine your country by your IP address and does not send the IP address to third parties for this purpose.
d) Bot protection. The Cloudflare Turnstile script is loaded on the Personal Dashboard and payment status pages. The check is used for password recovery and meme uploads and, where enabled, on the login and registration forms. In this case, the IP address and technical characteristics of the browser are transferred to Cloudflare.
5.2. Donors
a) Data you enter yourself in the donation form:
- name or nickname. This field is optional: if it is not filled in, "Anonymous" is shown;
- message text;
- voice message (optional);
- Donation amount;
- your choice as to whether you pay the service fee yourself;
- payment method;
- if enabled by the Streamer, the selected meme, wheel, goal or other interactive feature.
b) Data received from the Payment Organization:
- payment status, date and time;
- transaction identifier;
- payment system or method;
- fiscal receipt link;
- the payer's phone number. It is provided by the Payment Organization. For payments via SBP (Faster Payments System), the phone number is not received.
c) Technical data (clause 5.1) and a random code generated by your browser to track the payment status. This code is used for 2 hours to display the payment status.
d) The payer's phone number is not shown to the Streamer. It is used only for the purposes specified in Section 6.
5.3. Streamers
a) Registration and login:
- phone number;
- password. It is stored only as a one-way hash; the Operator does not know the original password;
- one-time confirmation codes (6 digits, valid for 5 minutes);
- information about login sessions: IP address, browser type, time and the hash of the session identifier;
- "Is this you?" confirmations.
b) Registration or login via Telegram. The following is obtained from the Telegram profile:
- Telegram identifier;
- first name, last name and username;
- language setting.
If you share your contact with the bot, your phone number is also obtained.
c) Login via Google (Section 20):
- Google identifier;
- email address;
- name;
- profile picture link.
d) Data for identification and receiving payments:
- PINFL (personal identification number of a natural person);
- official surname, first name and patronymic;
- status as a self-employed person;
- number of the settlement account to which payments are credited;
- account identifier with the Payment Organization.
This data is obtained from, or verified through, the "Rahmat" service on the basis of the PINFL and phone number (Section 7).
e) Channel and application data:
- channel link, name, identifier and platform (YouTube, Twitch, Telegram and others);
- channel verification code;
- screenshots you upload;
- public channel statistics;
- results of the review of the application, including reasons for rejection.
f) Profile, settings and content:
- username (nickname) and profile picture;
- email address (if provided);
- widget and voice settings;
- list of banned words;
- memes and other media files you upload;
- wheel, lot, goal and subscription settings;
- widget links and secret keys (tokens).
g) Financial and operational data:
- history of Donations received: amount, date, service fee, payment method, receipt link;
- subscription and balance top-up transactions;
- data related to the service fee and limits.
h) Level and moderation data:
- the Streamer's level, the history of its changes and the reasons for them;
- identifier of the employee who made the relevant decision;
- history of previous usernames. It is retained to prevent fake accounts from being opened in another Streamer's name;
- account status (active, blocked, etc.).
i) YouTube integration (optional, Section 20):
- encrypted access tokens;
- channel and live stream data.
j) Requests: messages you send to the support service and the responses given to them.
5.4. Channel Host (a Person Other than the Account Holder)
5.4.1. If the account holder indicates that another person (for example, a family member) uses the account to conduct live streams, the following data is processed:
- the Channel Host's surname, first name and patronymic;
- their kinship or other relationship with the account holder;
- requests to change this data.
5.4.2. The account holder warrants that they obtained the Channel Host's consent before entering this data. If the Channel Host is a minor, the account holder must be their parent (legal representative) and must give consent on their behalf in written or electronic form (Article 21 of the Law).
5.4.3. The Channel Host may contact the Operator directly and exercise the rights specified in Section 15.
5.5. Users of Telegram Bots
5.5.1. When you use the Operator's Telegram bots, the following is obtained:
- Telegram identifier;
- first name, last name and username;
- language setting;
- messages you send to the bot.
If you share your contact, your phone number is also obtained.
5.5.2. If the Streamer has enabled the points module, the following data of participating viewers is processed:
- Telegram identifier;
- name;
- points balance;
- materials confirming that a task has been completed.
The points module allows viewers to earn points by completing tasks set by the Streamer and to exchange them for gifts set by the Streamer. The module is not currently offered to new Streamers.
5.6. YouTube Live Chat Participants
If the Streamer has connected a YouTube channel and enabled the chat widget, live chat messages are obtained via the YouTube API:
- author name;
- message text;
- message time.
These messages are processed temporarily, solely for display in the widget, and are not stored in the Operator's database.
5.7. Data the Operator Does Not Collect
5.7.1. The Operator does not request and does not purposefully process the following data:
- special categories of personal data (Article 25 of the Law): data on racial or social origin, political, religious or philosophical beliefs, membership of political parties and trade unions, physical or mental health, private life and criminal record;
- biometric and genetic data used to identify a person;
- copies of passports or other documents.
5.7.2. We ask that you do not include such data in a donation message or voice message.
5.8. Voice Messages
A voice message is accepted solely for broadcasting on the Streamer's live stream. The Operator does not use voice messages to identify a person (biometric identification) or to create voice samples. Voice messages are stored only on servers located in the territory of Uzbekistan and are not transferred abroad.
5.9. Payment Card Data
5.9.1. Card details for a Donation or other payment are entered not on the Platform but on the page of the Payment Organization or payment system. Such details are: card number, expiry date and SMS confirmation code. They are processed by the Payment Organization in accordance with its own rules. The Operator does not store the card's CVV/CVC code.
5.9.2. The Operator does not store the full payment card number or its expiry date. The Payment Organization provides the Operator only with the payment result and the data specified in clause 5.2. Card numbers entered under the Platform's old card payment and withdrawal methods (until August 2026) are stored only in masked form (the first 6 and last 4 digits), and the card expiry dates have been deleted. CVV/CVC codes have never been stored.
5.10. AI Assistant (Support Chat)
5.10.1. In the support chat in the dashboard, the Streamer's questions are answered first by an artificial intelligence-based assistant (the AI assistant). Its use is optional: at any time, you can contact a member of the Operator's staff via the "Contact an operator" button.
5.10.2. To enable the AI assistant to prepare a response, the following is sent to the service of Anthropic, PBC (USA):
- the text of the message written by the Streamer in the chat and the previous messages in the current conversation;
- brief service data on the status of the Streamer's account: level; the amount, time and status of the five most recent Donations (without the Donor's name or message); whether widgets are connected; and the status of certain settings.
The phone number, PINFL, official full name, settlement account number and payment card data are not transferred to the AI assistant. Do not include your personal data in the chat.
5.10.3. The AI assistant only provides information and does not make any decisions regarding the Streamer's account (Section 19). If the Streamer writes to the Operator, the text of the request is sent to a closed Telegram working group of the Operator's staff.
5.10.4. Under Anthropic's commercial terms, data sent via the API is not used to train its models and is deleted by Anthropic within 30 days (except where flagged as violating its usage policies). Conversations are stored on the Operator's server for the period specified in Section 12.
6. Purposes and Legal Grounds of Processing
6.1. The Operator processes personal data on the following grounds provided for in Article 18 of the Law:
- Contract — performance of a contract to which the data subject is a party (the Public Offer, including the Contract concluded with the Donor for each Donation), or taking steps at the data subject's request before entering into a contract.
- Consent — the data subject's consent (Article 21 of the Law).
- Legal obligation — performance of the Operator's obligations established by law. For example, obligations in the areas of tax, accounting, payments and information, or lawful requests from government authorities.
- Legitimate interest — exercise of the rights and legitimate interests of the Operator or a third party, provided that the rights and legitimate interests of the data subject are not violated. For example, protection against fraud and attacks.
6.2. Purposes:
| No. | Purpose | Data | Data subjects concerned | Legal ground |
|---|---|---|---|---|
| 1 | Creating an account, logging in, recovering and protecting the account | Phone, password hash, confirmation codes, Telegram/Google identifiers, login sessions | Streamer | Contract |
| 2 | Identifying the Streamer, connecting the Streamer to payment acceptance, routing payments directly to the Streamer's account (split payment) | PINFL, official full name, self-employed status, settlement account number, identifier with the Payment Organization | Streamer | Contract; legal obligation |
| 3 | Verifying the channel and reviewing the application, preventing fake accounts | Channel data, verification code, screenshots, username history | Streamer | Contract; legitimate interest |
| 4 | Accepting the Donation, processing the payment and delivering it to the Streamer | Name/nickname, message, voice message, amount, payment method, data received from the Payment Organization | Donor | Contract (the Contract concluded with the Donor) |
| 5 | Displaying the Donation on the live stream and in widgets, converting the message to speech (TTS) | Name/nickname, message, voice message, amount, selected meme | Donor | Consent |
| 6 | Fiscal receipts, accounting and tax records | Donation and payment records, the Streamer's identification data (to the extent required by law) | Donor, Streamer | Legal obligation |
| 7 | Calculating the Streamer's level and limits | Donation statistics, number of unique payers (based on the payer's phone number) | Streamer, Donor | Contract; legitimate interest |
| 8 | Preventing fraud, bot attacks, abuse and unauthorized access; investigating security incidents | IP address, browser data, logs, Turnstile result, payment data, payer's phone number | All data subjects | Legitimate interest; legal obligation |
| 9 | Content moderation (filtering banned words, detecting and removing unlawful content) | Donation message, voice message, memes, payment monitoring data | Donor, Streamer | Legal obligation; legitimate interest |
| 10 | Sending service messages (confirmation codes, account status, subscription period, etc.) | Phone, Telegram identifier | Streamer | Contract |
| 11 | Handling requests and providing support, including the AI assistant (clause 5.10) | Contact details, content of the request, relevant account or payment data; conversations with the AI assistant | All data subjects | Contract; legal obligation; for the AI assistant — the Streamer's consent |
| 12 | Subscriptions and balance top-ups | Amount, transaction identifier, account identifier | Streamer | Contract; legal obligation |
| 13 | Displaying YouTube widgets and channel statistics | Data specified in clause 20.4 | Streamer, chat participants | The Streamer's consent; legitimate interest (chat participants' public messages on YouTube) |
| 14 | Complying with lawful requests of government authorities and courts | Data specified in the request | All data subjects | Legal obligation |
| 15 | Analyzing and improving service quality | Only depersonalized or aggregated statistics | — | Article 18 of the Law (subject to depersonalization) |
6.3. The Operator sends advertising messages only with the data subject's separate consent. This consent may be withdrawn at any time. Service messages (row 10 of the table in clause 6.2) are not considered advertising.
6.4. The Donor may reduce the data they provide for purpose 5 (public display): leave the name field blank ("Anonymous") and not write a message text. The Platform may ask the Donor to choose one of the following: a message text, a voice message or a meme; whether they are displayed on the live stream depends on the Streamer's settings. The Donation is delivered to the Streamer in any case.
7. Sources of Data
The Operator obtains personal data from the following sources:
- From the data subject themself — through forms, the dashboard, bots and requests.
- From the "Rahmat" service (service operator — "MULTICARD PAYMENT" Joint-Stock Company). On the basis of the PINFL and phone number provided by the Streamer, the following is obtained: official full name, self-employed status, settlement account number and identifier with the Payment Organization.
- From the Payment Organization, "MULTICARD PAYMENT" — payment result, transaction data, the payer's phone number, fiscal receipt link.
- From Telegram — the data specified in clause 5.3(b) and clause 5.5 when logging in via Telegram or interacting with a bot.
- From Google — when logging in via Google and when YouTube is connected (Section 20).
- From the public APIs of YouTube, Twitch and Telegram — the channel's public data (name, identifier, description, statistics) for channel verification.
- From the account holder — data about the Channel Host (clause 5.4).
- From the payment service for Paid Features (once charging begins, clause 8.2 of the Offer) — the status of subscription and balance top-up transactions.
- From Cloudflare — the bot check result.
8. Publicly Visible Data (Dissemination)
8.1. Donation data. Depending on the Streamer's settings, the following may be displayed or played on the Streamer's live stream and in widgets:
- the Donor's name or nickname;
- message text;
- Donation amount;
- voice message;
- the message read out in a synthesized voice (TTS);
- selected meme.
The live stream is broadcast to an indefinite range of viewers on YouTube, Twitch and other platforms. It may be recorded and stored by the Streamer or by those platforms.
8.2. Top Donors list and goal widgets. These may display Donors' names or nicknames and amounts.
8.3. The Streamer's public profile. The following is visible to everyone on the donation page:
- username;
- channel name and link;
- profile picture;
- goals and other information the Streamer has made public.
The Streamer's PINFL, phone number, official full name and settlement account number are not shown publicly. Where fiscal receipts are enabled, the Streamer's PINFL appears on the receipt as the principal's (komitent's) identifier in accordance with tax legislation. The receipt link is provided to the Donor and is visible in the Streamer's donation history.
8.4. Circumstances beyond the Operator's control. Once information has been displayed on a live stream, the Operator cannot control its recording and dissemination by viewers, the Streamer or other platforms. Therefore:
- do not write personal data about yourself or other persons (phone number, address, document number, etc.) in a donation message;
- do not record and send another person's voice without their consent.
8.5. Streamer's responsibility. The Streamer is independently responsible for displaying Donors' data on their live stream and for storing stream recordings. The Streamer must use this data only within the scope of the Platform's services.
9. Disclosure of Data to Third Parties
9.1. General rule. The Operator discloses personal data only on the following conditions:
- for the purposes specified in this Policy;
- only to the extent necessary for that purpose;
- only to persons who are obliged to ensure the confidentiality of the data.
9.2. Recipients in Uzbekistan:
| Recipient | Purpose | Data disclosed |
|---|---|---|
| "MULTICARD PAYMENT" — Payment Organization (License No. 26 of the Central Bank) | Accepting the Donation payment, transferring the Streamer's share directly to the Streamer's account (split payment), issuing the fiscal receipt | Amount, the Streamer's username, identifier with the Payment Organization and settlement account number, the Donor's name and message in the payment description; where fiscal receipts are enabled, the Streamer's PINFL (for the fiscal receipt) |
| Banks, payment systems and e-wallets (Uzcard, Humo, Visa, Mastercard, Payme, Click, Uzum, Paynet and others) | Processing the payment | The Operator does not transfer data to them. The Donor enters their data directly on their pages; they interact with the Payment Organization |
| "Rahmat" service ("MULTICARD PAYMENT" JSC) | Identifying the Streamer, verifying self-employed status | PINFL, phone number |
| Eskiz ("Best Internet Solution" private enterprise) — SMS service | Sending confirmation codes and service SMS messages | Phone number, SMS text |
| Data center ("Uzbektelekom" JSC network) | Server hosting (Tashkent) | All data on the Platform is stored. The provider does not process it for its own purposes |
| Tax authorities and the fiscal data operator (via the Payment Organization) | Registration of fiscal receipts | Receipt details established by law |
9.3. Recipients abroad are specified in Section 10.
9.4. Streamer. In their dashboard and widgets, the Streamer sees:
- the Donor's name or nickname;
- the Donor's message and voice message;
- the Donation amount and date.
If the Streamer's Telegram account is linked to the Platform, this information about each Donation (together with the selected meme) is also sent to the Streamer via the Operator's Telegram bot (clause 10.3).
The payer's phone number and payment instrument details are not provided to the Streamer.
9.5. Government authorities. The Operator discloses personal data to courts, law enforcement agencies and other competent government authorities only on the grounds and in the manner established by law. When a government authority requests data, the Operator notifies the data subject thereof (clause 18 of the Model Procedure). This does not apply where notification is prohibited or restricted by law.
9.6. Reorganization. If the Operator is reorganized or the Platform is transferred to another person, personal data passes to the legal successor in accordance with the law. The Operator notifies data subjects of this in advance. Google user data is transferred only in the manner specified in clause 20.6.
9.7. Notification. When data is disclosed to a third party, the Operator notifies the data subject within three days in writing, including in electronic form (Article 23 of the Law). With respect to the data disclosed to the recipients specified in this Policy in connection with each Donation, registration or identification, the data subject is notified in electronic form before the data is disclosed — when they are made familiar with the Policy. If data is disclosed to a third party not specified in the Policy, the Operator sends the data subject a separate notice. This does not apply where notification is not required by law (for example, when government authorities exercise their powers).
10. Cross-Border Transfer
10.1. The Platform's main database and files are stored on servers located in the territory of Uzbekistan (Section 11). Certain features work only through foreign services. For this reason, the data specified in clause 10.3 is transferred outside Uzbekistan.
10.2. Grounds for transfer (Articles 15 and 27¹ of the Law):
- Listed states. Resolution of the Cabinet of Ministers No. 415 dated 29 July 2026 approved the list of states that ensure equivalent protection of personal data. The list includes the member states of the European Union, the United Kingdom and Switzerland. The USA is included in the list only in respect of companies operating under the EU-US Data Privacy Framework (DPF).
- States not on the list. Transfers to such states are made only to the minimum extent necessary for a feature chosen by the data subject, and with the data subject's consent (Article 15 of the Law; clause 21 of the Model Procedure). Where the competent government authority establishes legal, organizational and technical conditions in accordance with clause 4 of Resolution No. 415, the Operator complies with them. If you do not consent to such transfer, you may use the alternatives specified in clause 10.5.
- Data that must be stored in Uzbekistan under Article 27¹ of the Law (clause 11.2) is not transferred abroad.
10.3. Foreign recipients:
| Recipient | Country | Purpose | Data transferred | Ground |
|---|---|---|---|---|
| Telegram Messenger Inc. (Telegram group) | The Netherlands (Telegram stores the data of users registered from Uzbekistan in data centers in the Netherlands); group companies — the British Virgin Islands and the UAE | 1) Login and registration via Telegram; 2) confirmation codes and service notifications to the Streamer via the Telegram bots they have connected; replies to text sent to the Telegram bot for TTS; 3) internal notifications in closed working groups of the Operator's staff (monitoring of applications and payments); 4) if the Streamer's Telegram account is linked to the Platform — a notification to the Streamer about each Donation | 1–2) Data you have shared on Telegram (Telegram identifier, name, username, language setting and, if you share it, phone number) and the text of the notification. 3) Internal identifiers (account, application or Donation number) and the Streamer's public username; where necessary for reviewing applications and requests — channel data, the text of the Streamer's request, the Channel Host's name and their relationship to the Streamer (clause 5.4); in the payment monitoring channel — the Donation amount, the Donor's name (nickname), message and the Streamer's channel. Phone numbers, PINFLs and settlement account numbers are sent only in masked form (the last digits); email addresses and card data are not sent. 4) The Donor's name (nickname), message, amount and selected meme | The Netherlands is on the list; the UAE and the British Virgin Islands, where group companies are located, are not, therefore — the data subject's consent, only for the feature they have chosen (clause 10.2); for item 4 — the Donor's consent (clause 1.6). For item 3, only the minimum data necessary for review and monitoring is provided to Telegram |
| Microsoft Corporation (Azure Speech service) | USA (Azure East US region) | Converting the donation message into a synthesized voice (TTS) | Text of the donation message (after banned words have been filtered out); text sent to the Operator's Telegram bot for conversion to speech. The Donor's name, phone number and other identifiers are not transferred | DPF (the USA is a listed state for DPF companies) |
| Eleven Labs Inc. (ElevenLabs) | USA | Converting the donation message into a synthesized voice (TTS) for certain Streamers | Text of the donation message | DPF |
| Cloudflare, Inc. | USA (global network); the backup — R2 storage in the Eastern Europe region | Protecting the Platform's forms from bots (Turnstile, clause 5.1(d)); delivering certain libraries (cdnjs); storing an encrypted backup copy of the database (R2, clause 11.1) | IP address, technical characteristics of the browser and device; the backup is encrypted (AES-256, the key is held only by the Operator) | DPF |
| Google LLC | USA | Login via Google, YouTube integration and channel verification (Section 20); fonts in certain widgets (Google Fonts) | Data specified in Section 20; the channel's public identifier; IP address and browser data when fonts are loaded | DPF |
| Twitch Interactive, Inc. | USA | Twitch channel verification | The channel's public name or identifier | The Streamer's consent (clause 1.6); the company does not participate in the DPF |
| Content delivery networks (CDN): jsDelivr, code.jquery.com, fonts.bunny.net (BunnyWay d.o.o., Slovenia), cdn.tailwindcss.com | Various countries (European Union, USA) | Loading the software libraries and fonts needed to display pages | IP address and browser data when your browser accesses them directly | Listed state / DPF |
| Anthropic, PBC | USA | AI assistant in the dashboard: preparing answers to the Streamer's questions (clause 5.10) | The text of the message written by the Streamer, previous messages in the current conversation and the service data specified in clause 5.10.2. Phone number, PINFL, official full name, settlement account and card data are not transferred | The Streamer's consent (clause 1.6); use of the AI assistant is optional |
10.4. Safeguards.
- Only the minimum data necessary for the feature is transferred abroad. For example, only the message text is sent for TTS; the Donor's name or phone number is not transferred.
- Voice messages, password hashes, PINFLs, settlement account numbers and payment card data are not transferred abroad. Phone numbers, PINFLs and settlement account numbers are sent to the Telegram working groups of the Operator's staff only in masked form (the last digits).
- Data is transferred via encrypted communication channels (HTTPS/TLS).
- Foreign service providers process data in accordance with their own terms of use and privacy policies.
10.5. Opting out of transfer.
- If the Donor does not want the message text to be transferred to the TTS service (abroad), the Donor may choose not to write a text, or may choose a voice message or a meme instead. In these cases, and also if the Streamer has disabled TTS, the text is not transferred to the TTS service.
- A Streamer may log in with a phone number and SMS code instead of logging in via Telegram or Google, and may choose not to connect the YouTube integration.
- Bot protection (Turnstile) is mandatory for the security of the Platform.
10.6. Notification of leaks. If it is discovered that data has been leaked in the course of a cross-border transfer, the Operator:
- notifies the competent government authority thereof within 24 hours of the moment of discovery;
- provides detailed information on the causes and the measures taken to eliminate them within 72 hours.
(Resolution of the Cabinet of Ministers No. 415 dated 29 July 2026, clause 4.)
11. Place of Storage
11.1. The Platform's database, uploaded files (voice messages, memes, screenshots, profile pictures) and logs are stored on servers located in the territory of the Republic of Uzbekistan, in the city of Tashkent. Synthesized voice files (TTS) are also stored on this server. A daily backup copy of the database is stored on the same server; an AES-256-encrypted copy of it is also uploaded to Cloudflare R2 cloud storage (Eastern Europe region) for recovery purposes (clause 10.3). The encryption key is held only by the Operator.
11.2. The Operator does not process data that must be stored in Uzbekistan under Article 27¹ of the Law. Such data is biometric and genetic data and data on subscribers of telecommunications operators. Voice messages are not used for biometric identification. Nevertheless, they are stored only in Uzbekistan (clause 5.8).
12. Retention Periods
12.1. General rule. Personal data is stored until the purpose of processing is achieved or until the period established by law expires (Article 10 of the Law). Once the purpose has been achieved, the data is destroyed or depersonalized within three days (clause 23 of the Model Procedure).
12.2. Periods:
| Data | Retention period |
|---|---|
| Account and profile data (phone, password hash, username, Telegram/Google identifiers, settings, memes) | For as long as the account exists. After the account is deleted, destroyed within the period specified in Section 17 |
| PINFL, official full name, settlement account number, identifier with the Payment Organization | For as long as the account exists. Thereafter, only to the extent related to financial records, for the period established by tax and accounting legislation |
| Donation and payment records (amount, date, Streamer, service fee, transaction identifier, receipt link) | For the period established by tax and accounting legislation (at least 5 years after the reporting year — Article 29 of the Law "On Accounting"). After the period expires, depersonalized or destroyed |
| Donor's name and message | In the Streamer's donation history, for as long as the Streamer's account exists. At the request of the Donor or the Streamer, the name and message are depersonalized (for example, replaced with "Anonymous") |
| Voice messages | 30 days from the date the Donation is received. After the period expires, deleted automatically |
| Synthesized voice files (TTS) | 30 days from the date of creation. May be reused for the same text within that period |
| Payer's phone number and payment status tracking code | 12 months. After the period expires, deleted or irreversibly hashed |
| Channel verification screenshots | 30 days after the application has been reviewed |
| History of previous usernames | For as long as the account exists and for 1 year after the account is deleted (the same as the period in clause 17.5 of the Offer). This is necessary to prevent another person from opening an account in the Streamer's name |
| PINFL and phone number of a person whose Contract was terminated under subclause "a" or "b" of clause 17.4 of the Offer | One year from the date the Contract was terminated (clause 17.5 of the Offer). Used only to prevent such a person from re-registering without the Operator's consent |
| Confirmation codes and phone verification records | Deleted automatically within 1 day after their validity expires. Deleted immediately once the account has been created |
| Login sessions (IP address, browser type) | Deleted automatically once the session expires |
| Server and application logs | 90 days. Web server access logs — 10 days |
| YouTube data | Not stored in the database; held in temporary memory for no more than 5 minutes for performance (clause 20.8) |
| Google account data | For as long as the account exists or until the Google link is removed (clause 20.8) |
| Points module data | Until the Streamer disables the module or until the participant so requests |
| Requests and responses to them | 3 years after the last message |
| Conversations with the AI assistant (clause 5.10) | The same period as for requests |
| Data confirming that consent was given (date, time, method, IP address, Policy version) | For as long as the consent is valid and thereafter for the limitation period for disputes established by law (Article 31 of the Law) |
| Backup copies | On the server — 7 days; encrypted external copy (Cloudflare R2) — 30 days. Deleted data disappears from backup copies when that period expires |
12.3. Statutory retention. Data that the law requires to be retained is retained for the period established by law even if consent is withdrawn or the account is deleted. Examples of such data are tax and accounting documents. During that period, the data is not used for any other purposes (Article 18 of the Law).
13. Cookies and Browser Storage
13.1. The Platform uses only cookies and browser storage that are necessary for its operation. Advertising, web analytics or third-party tracking cookies are not used.
13.2. Cookies:
| Name | Purpose | Duration |
|---|---|---|
Session cookie (..._session) |
Maintaining the logged-in state | Expires after 120 minutes of inactivity. HttpOnly, for the Platform only |
XSRF-TOKEN |
Protection against cross-site request forgery (CSRF) | For the duration of the session |
remember_web_... |
"Remember me" function; login via Telegram or Google | 30 days |
yangi_royxat |
Managing the registration process | 90 days |
yt_oauth_uid |
YouTube connection process | 20 minutes |
merchant_panel |
Access to the service panel (for authorized users only) | 14 days |
13.3. Browser storage (localStorage, sessionStorage). For convenience, the following is stored on your device:
- the last name, amount, payment method and service fee choice entered in the donation form (the message text is not stored);
- the status of an incomplete payment;
- dashboard interface settings (for example, the open tab, the state of the side panel).
This data is not sent to the Operator's server and remains only in your browser. Card data is not stored in browser storage; if pages of a previous version have saved it, it is deleted when the donation page is opened.
13.4. Third-party technical tools. Cloudflare Turnstile and the external resources specified in clause 10.3 may use their own technical tools in accordance with their own rules.
13.5. Deleting cookies. You can delete cookies and browser storage in your browser settings. If necessary cookies are deleted, login and certain features will not work.
14. Security Measures
14.1. The Operator takes legal, organizational and technical measures to protect personal data against unauthorized access, modification, destruction, copying and dissemination (Article 27 of the Law). In particular:
- Communication with the Platform is carried out via the encrypted HTTPS (TLS) protocol.
- Passwords are stored only in the form of a one-way cryptographic hash.
- YouTube access tokens are stored in encrypted form in the database.
- Confirmation codes are 6 digits long, randomly generated and valid for 5 minutes. The number of attempts to send and enter a code is limited.
- The number of requests is limited, and tools for protection against automated attacks are used.
- Login via Telegram is bound to the browser from which the request was sent, and additional confirmation ("Is this you?") is required.
- Payment notifications (callbacks) are verified by means of a checksum hash calculated on the basis of a secret key, or by means of a list of allowed IP addresses.
- The PINFL and official full name are protected from modification after identification. The PINFL is shown in masked form in the dashboard.
- Access to administrative tools is granted only to authorized employees, each through a personal account and within the scope of their duties. For certain important administrative actions (for example, changing a level), it is recorded who performed them. A separate service panel provided to partners for searching payments is protected by a login and password, a limit on the number of attempts and bot protection.
- Voice message files are stored under names with a random suffix and are deleted after 30 days (Section 12).
- The Operator's employees use personal data only within the scope of their job duties and undertake not to disclose it (Article 12 of the Law).
- Secret keys and access credentials are renewed when necessary.
14.2. No method of transmission over the Internet or of electronic storage is absolutely secure. The Operator continuously improves its protective measures.
14.3. Incident response. If the Operator discovers a breach of personal data security, it:
- takes measures to eliminate the breach and mitigate its consequences;
- notifies the competent government authorities in the cases provided for by law (clause 10.6);
- where there is a serious risk to the rights and interests of data subjects, notifies them as soon as possible and gives recommendations on how to protect themselves.
14.4. Your part:
- do not give your password or confirmation codes to anyone. The Operator's employees will never ask for a code by phone or by message;
- keep widget links and keys secret. If they are disclosed, renew them in the dashboard;
- log out when you finish working on shared devices;
- if you suspect unauthorized access to your account, immediately notify us at the address specified in clause 2.1.
15. Rights of the Data Subject
15.1. In accordance with Articles 11, 17, 21, 22, 24 and 30 of the Law, every data subject has the following rights:
- To know whether data exists. To know whether the Operator holds personal data about them and what that data consists of.
- To receive information about processing (Article 22 of the Law):
- the fact, grounds and purposes of processing;
- the methods of processing;
- the composition and source of the data;
- to whom the data has been disclosed;
- retention periods;
- cross-border transfer.
- Rectification and supplementation. To demand that incomplete, outdated or inaccurate data be changed and supplemented.
- Temporary suspension. To demand that processing be temporarily suspended if the data is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the purpose.
- Destruction. To demand the destruction of data in the cases provided for by law.
- Withdrawal of consent (Section 17).
- Objection to an automated decision (Section 19).
- Complaint. If they consider that their rights have been violated, to apply to the competent government authority in the field of personal data (Article 8 of the Law) or to a court.
15.2. The rights of a data subject who lacks legal capacity or is a minor are exercised by their legal representative.
15.3. Where it would violate the rights and legitimate interests of other persons, the provision of information to a data subject may be restricted in accordance with the law (Article 22 of the Law).
15.4. Data subject's obligation. The data subject must provide the Operator with accurate information about themselves and update it in a timely manner when it changes.
16. Procedure for Requests and Response Times
16.1. Ways to submit a request:
- via the email address specified in clause 2.1. Subject: "Personal Data";
- by a written application sent to the postal address specified in clause 2.1;
- via the support chat in the dashboard (the "Contact an operator" button).
The Operator accepts requests to stop processing and to destroy data in electronic form (Article 31 of the Law).
16.2. Content of the request. The request should include:
- your name;
- your contact details for receiving a response;
- the substance of your request;
- the details necessary to find the data about you. For a Streamer — username or phone number. For a Donor — the date of the Donation, the Streamer, the amount and the phone number used for the payment.
16.3. Identity verification. To prevent the disclosure of another person's data, the Operator may ask the applicant to verify their identity. For example, a code may be sent to the registered phone number or to Telegram. Only the minimum data necessary for this purpose is requested.
16.4. Requests are handled free of charge.
16.5. Response times:
| Request | Period | Basis |
|---|---|---|
| Receiving information about processing | Within 10 days. If the provision of information is refused, a reasoned written notice is also sent within 10 days | Article 22 of the Law (for the notice of refusal); the rest — the Operator's own commitment |
| Changing or supplementing data | Within 3 days from the moment the request is received. If the data is found to be untrue — immediately | Article 11 of the Law; clause 15 of the Model Procedure |
| Withdrawal of consent | Processing is stopped. The data is destroyed no later than the business day following the day the application is received (except in the cases referred to in clause 12.3) | Clause 10 of the Model Procedure |
| Destruction of unlawfully processed data | Within 1 business day | Clause 24 of the Model Procedure |
| Destruction upon achievement of the purpose of processing | Within 3 days | Article 17 of the Law; clause 23 of the Model Procedure |
| Temporary suspension | Immediately after a justified request is confirmed, and in any event within 3 days | Article 30 of the Law (the period is the Operator's own commitment) |
| Review of an objection to an automated decision | Within 10 days; the result is communicated in writing | Article 24 of the Law |
16.6. Notification of the outcome. When data is changed or destroyed, or its use is restricted, the Operator notifies the data subject in writing, including in electronic form. Where necessary, the Operator also notifies the other participants in the processing (Article 31 of the Law).
17. Withdrawal of Consent and Account Deletion
17.1. Withdrawal of consent. A data subject may withdraw consent at any time. To do so, they submit a written (electronic) request in the same form in which the consent was given or in the manner specified in clause 16.1 (Article 21 of the Law).
Withdrawal of consent does not affect processing lawfully carried out before the withdrawal.
17.2. Consequences. If consent to the processing of data necessary to use the Platform is withdrawn, the Operator cannot provide the relevant services. For example:
- the Streamer's ability to receive Donations is terminated and the account is closed;
- the YouTube integration is disconnected.
17.3. Account deletion. A Streamer may request deletion of their account. To do so, the Streamer submits a request in the manner specified in clause 16.1. After identity has been verified:
- access to the account is blocked immediately;
- the following data is destroyed or irreversibly depersonalized no later than the next business day:
- phone number (except in the case specified in clause 17.4) and password hash;
- Telegram and Google links. The permission granted on Google is revoked (clause 20.9);
- profile picture, email address, settings, memes and widgets;
- channel verification materials;
- identification data, except for the part specified in clause 17.4;
- Donors' names, messages and voice messages in the donation history are deleted or depersonalized.
17.4. Data retained after deletion. Even after the account is deleted, the following is retained:
- Donation and payment records that the law requires to be retained for tax and accounting purposes. They are retained only for the period established by law and only for that purpose;
- data related to a case under consideration at the request of a court or government authority, or to an unresolved dispute. Such data is retained until the case or dispute is concluded;
- the history of previous usernames, for the period specified in clause 12.2;
- the PINFL and phone number of a person whose Contract was terminated under subclause "a" or "b" of clause 17.4 of the Offer — solely to prevent re-registration, for the period specified in clause 17.5 of the Offer.
17.5. Donor's request. A Donor may request the following with respect to their Donation:
- depersonalization of the name and message;
- deletion of the voice message;
- deletion of the phone number.
The financial record (amount, date, transaction) is retained in accordance with clause 17.4. The Operator cannot delete data that has already been shown on a live stream from recordings made by the Streamer or by third parties (clause 8.4).
17.6. Parents of a minor. A parent or legal representative of a minor may request deletion of the minor's data in the same manner.
18. Minors
18.1. Streamers. Registration on the Platform as a Streamer is permitted from the age of 18. If a minor uses an account holder's account as a Channel Host, clause 5.4.2 applies.
18.2. Donors. Persons under the age of 18 may make a Donation only with the consent of their parent or legal representative.
18.3. Data collected without parental consent. The Operator does not separately verify age. If the Operator discovers that a minor's data has been collected without parental consent, the Operator stops processing it. At the request of the parent or legal representative, the data is destroyed within the periods specified in clause 16.5. This does not apply to data that the law requires to be retained.
19. Automated Processing and Decisions
19.1. Rules applied automatically. The following are applied automatically in order to perform the terms of the Public Offer (Article 24 of the Law):
- Donation limits are determined depending on the Streamer's level and the payment method, and the service fee depending on the Streamer's level and the terms of connection with the Payment Organization. The exact values are shown on the Platform, in the dashboard and on the donation page before payment;
- technical security restrictions (request rate limits, bot checks) are temporary and do not give rise to legal consequences;
- the answers of the AI assistant in the dashboard (clause 5.10) are for information purposes only and do not give rise to legal consequences.
19.2. Decisions reviewed by an employee. The following decisions are not made solely by automated means. They are reviewed by an authorized employee of the Operator:
- raising a Streamer's level (after the established conditions have been met);
- rejecting a registration application;
- blocking an account;
- other decisions having legal consequences.
19.3. Objection. A data subject may object to a decision based solely on automated processing. The Operator reviews the objection and notifies the data subject of the outcome in writing within 10 days.
20. Google User Data (Sign in with Google and YouTube)
20.1. Scope. This Section applies to data that the Platform receives through Google API services ("Google user data"). This data is received through two features:
- "Sign in with Google";
- the YouTube integration, which the Streamer connects at their own option.
Both features are optional: you can also log in to the Platform with a phone number or via Telegram.
20.2. "Sign in with Google". A Streamer who has previously linked a Google account to their account on the Platform may log in with that Google account; new accounts are not created via Google. Login and connecting YouTube are carried out through a single Google permission window: the Operator requests the openid, email, profile and youtube.readonly permissions. The following is obtained from the Google account (YouTube data is covered in clause 20.4):
- the unique identifier of the Google account;
- email address and the indicator that it has been verified by Google;
- the name in the Google profile;
- profile picture link.
The Operator does not receive your Google account password, contacts, emails, files or other Google data.
20.3. Use of Google account data. This data is used only for the following purposes:
- creating and logging in to an account on the Platform;
- linking the Google account to your account on the Platform;
- ensuring account security;
- sending service messages relating to the account.
20.4. YouTube integration. If the Streamer clicks the "Connect with YouTube" button in the dashboard or logs in via Google, Google requests the youtube.readonly permission, i.e. read-only access. If the permission is granted, the Operator receives the following through YouTube API Services:
- channel identifier, name and public statistics (for example, the number of subscribers and views);
- information about live streams and videos;
- live chat messages (author name, message text and time).
This data is used only to display the widgets enabled by the Streamer (for example, chat and statistics widgets) and the channel information in the dashboard. Access and refresh tokens are stored in encrypted form in the database. The Operator does not post, modify or delete anything on YouTube on the Streamer's behalf.
20.5. YouTube and Google terms. By using the Platform's YouTube features, you agree to the YouTube Terms of Service: https://www.youtube.com/t/terms. Google processes data in accordance with its own Privacy Policy: http://www.google.com/policies/privacy.
20.6. Limited Use.
iDonate's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
(In other words: iDonate's use of information received from Google APIs, and its transfer of such information to any other app, will comply with the requirements of the Google API Services User Data Policy, including the Limited Use requirements.)
In particular, Google user data:
- is used only to provide and improve user-facing features that are visible to, and used by, the user;
- is not sold;
- is not used for advertising, including personalized or targeted advertising;
- is not used to determine creditworthiness or for lending purposes;
- is not provided to data brokers or information resellers;
- is not used to develop, improve or train generalized artificial intelligence or machine learning models;
- is transferred to third parties only in the following cases:
- where necessary to provide or improve a feature that you use and that is visible on the Platform, and only with your consent;
- for security purposes;
- to comply with applicable law;
- in the event of a reorganization of the Operator (merger, acquisition), or a sale of its shares or assets — with your explicit prior consent.
The Operator's employees read Google user data only in the following cases:
- with your explicit consent (for example, to review your request);
- for security purposes (for example, to investigate abuse);
- to comply with applicable law;
- where the data is used in depersonalized, aggregated form for internal operations.
20.7. Place of storage. Google user data is stored on the Operator's servers in Uzbekistan. YouTube live chat messages are not stored in the database.
20.8. Retention periods:
- Google account data (clause 20.2) is retained for as long as the account exists or until the Google link is removed.
- YouTube data (statistics, live stream and video data) is not stored in the database: it is retrieved through the YouTube API when a widget is opened and is held in temporary memory (cache) for no more than 5 minutes for performance.
- Access tokens are retained until YouTube is disconnected or the permission is revoked.
- At your request, and also when YouTube is disconnected or the account is deleted, Google user data is deleted no later than the next business day.
- If you revoke the permission in your Google account settings, the Operator deletes the data no later than the business day following the day on which it detects this. In any case, this is done no later than 30 days from the date on which the permission was revoked.
20.9. Revoking permission. You may revoke permission to access Google data at any time in the following ways:
- via the "Disconnect YouTube" button on the "YouTube widgets" page in the dashboard;
- on the https://myaccount.google.com/connections or https://security.google.com/settings/security/permissions page of your Google account;
- by sending a request to the email address specified in clause 2.1.
When your account is deleted, the Operator also revokes the permission on Google.
20.10. Changes. If the Operator intends to change the way it uses Google user data, it will notify you in advance and ask for your consent to the new use.
21. Amendments to the Policy
21.1. The Operator may amend the Policy in the following cases:
- when legislation changes;
- when the Platform's features or service providers change;
- for other justified reasons.
21.2. Publication. A new version of the Policy is published on the Platform together with its effective date and version number. Previous versions are kept in an archive on the Platform and are provided upon request.
21.3. Material changes. Streamers are notified of material changes via the Personal Dashboard and the Telegram bot or SMS at least 30 calendar days before they take effect. Material changes include:
- new purposes or new categories of data;
- new foreign recipients;
- extension of retention periods.
When the purpose of processing changes, the Operator obtains new consent from the data subject (Article 19 of the Law).
21.4. Disagreement with a new version. A data subject who does not agree to a new version may withdraw consent and delete their account in accordance with Section 17.
21.5. Separate consent. For processing for a new purpose or for transfer to a new foreign recipient, the Operator obtains separate consent; continued use of the Platform does not constitute such consent. Streamers who registered before this version entered into force are shown this version when they first log in to the dashboard, and their consent is requested. Until consent is given, the Operator processes their data only to the extent necessary to perform the Public Offer and its legal obligations (Articles 18 and 19 of the Law).
22. Final Provisions and Contact Details
22.1. The Policy is governed by and interpreted in accordance with the legislation of the Republic of Uzbekistan. Disputes relating to personal data are resolved in the manner established by law (Article 32 of the Law). This does not limit the data subject's right to apply directly to the competent government authority or to a court.
22.2. If any provision of the Policy is held to be invalid, this does not affect the validity of its remaining provisions.
22.3. Contact details:
- "CODO IT" LLC, TIN 311366908
- Address: Navoiy viloyati, Navbahor tumani, Yangiqoʻrgʻon QFY, Sarbozor MFY, Davriqoʻrgʻon koʻchasi, 182-uy
- Email: info@idonate.uz
- Phone (support): +998 (95) 069-99-11
- Telegram (support): https://t.me/idonate_admin
Annex. Legal Sources
- Law of the Republic of Uzbekistan "On Personal Data" (No. ZRU-547, 02.07.2019; as amended by No. ZRU-1125, 26.03.2026): https://lex.uz/docs/4396419
- Model Procedure for Processing Personal Data (Ministry of Justice registration No. 3478, 15.11.2023): https://lex.uz/docs/6663967
- Resolution of the Cabinet of Ministers No. 415 dated 29 July 2026 "On Approval of the List of Foreign States Ensuring Equivalent Protection of Personal Data": https://lex.uz/docs/8369688
- Law of the Republic of Uzbekistan "On Informatization": https://lex.uz/docs/82956
- Law of the Republic of Uzbekistan "On Cybersecurity": https://lex.uz/docs/5960604
- Google API Services User Data Policy: https://developers.google.com/terms/api-services-user-data-policy
- YouTube API Services — Developer Policies: https://developers.google.com/youtube/terms/developer-policies
- YouTube Terms of Service: https://www.youtube.com/t/terms
- Google Privacy Policy: http://www.google.com/policies/privacy