Privacy Policy
§ 1 Controller and scope
The controller is TOO Steyer Engineering, Microdistrict Asa 41, 080004 Taraz, Republic of Kazakhstan, administration in Almaty. Managing director: Arnold Steyer. Email: [email protected]. Phone: +7 707 9979 525.
This notice covers personal data from this website (steyer.studio, a brand of TOO Steyer Engineering), from enquiries, and from web and software work we do for clients. It does not cover systems that a client operates alone after handover.
We apply the Law of the Republic of Kazakhstan on Personal Data and Their Protection of 21 May 2013 (No. 94-V). Where the EU General Data Protection Regulation applies, because the person is in the EU or the processing is caught by it, we also follow that regulation. The principles are lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
Status: 5 October 2026.
§ 2 Data we process
From the enquiry form we receive the name and email address, optionally the company, the current website, and a message, plus your answers about the project: type of project, current platform, features wanted, languages, and timeframe, and the price the form estimates from them. A hidden field is used only to filter automated submissions. We do not use it for anything else. The enquiry goes through our server by email to [email protected].
If a contract follows, we also keep the organisation, role, correspondence, offer, order, invoices, and the project record needed to do the work.
When we build or maintain a website or software, the client decides which personal data goes into that system. That can include customer, member, booking, or order data in a website, customer area, portal, or shop. For that data the client remains the controller, unless the contract says otherwise.
The server that hosts the website can log connection data for technical reasons: IP address, time, requested address, and browser type. We do not use these logs to identify a visitor for marketing.
We do not ask for special categories of data, such as health data. Do not send them unless the job cannot be done without them and you have a legal basis to share them.
This website is aimed at companies. We do not knowingly collect data from children.
§ 3 Purposes
We use the data to answer the enquiry, prepare an offer, and perform the contract. The work can be web design, the development of a website or web application with a back end, visibility in search engines and AI search, hosting, or service.
We also use the data to issue invoices, keep the project record required by our ISO 9001:2015 system, protect the website and our accounts, and meet legal duties. We do not analyse how the website is used.
We do not sell personal data. We do not use it for advertising profiles.
§ 4 Legal bases
Depending on the step, the basis is one of the following. Your consent, where we ask you for it explicitly. Steps before a contract and performance of the contract, for the enquiry, the offer, and the work. A legal obligation, for tax and accounting records. Our legitimate interests, for a secure website, for answering a business enquiry, for remembering the language you chose, and for keeping a project record, where those interests are not overridden by yours.
Where the processing is based on consent, you can withdraw it at any time with effect for the future. Withdrawal does not affect processing that was lawful before the withdrawal. Under the law of Kazakhstan, consent to the processing of personal data can also be withdrawn by a notice to us.
§ 5 Cookies and measurement
If you choose a language with the flags, we store one cookie named lang. It holds only the chosen language, so the website opens in that language on your next visit. Without this cookie the language follows your browser setting.
We set no other cookies. We do not use analytics or advertising services such as Google Analytics or Google Tag Manager. Fonts and images come from the server of this website, not from third parties.
The website is delivered through the Cloudflare network, which protects it against attacks. For that purpose Cloudflare can set a technical cookie, such as __cf_bm, that recognises automated traffic and expires after a short time.
§ 6 Recipients and transfers abroad
Inside the company, people see personal data only if their work needs it. Managing director and the staff on the job are the usual recipients.
Outside the company, recipients are the email path that carries the enquiry (Microsoft), the host of this website (Hostinger), and Cloudflare, whose network delivers the website. A subcontractor sees project data only if the order needs that person and the person is bound to confidentiality.
The company sits in Kazakhstan and works for clients in Europe and Central Asia. A transfer can therefore leave the country of the person concerned. Where the GDPR requires it, we use an adequacy decision or standard contractual clauses. Where the law of Kazakhstan requires a cross-border notice or consent, we follow that rule for the transfer in question.
§ 7 Storage and protection
An enquiry that does not become a contract is kept while we answer it and for a short period afterwards, in case you write again about the same job. It is then deleted, unless a legal hold applies.
Contract, invoice, and tax records are kept for the retention period required by the law of the Republic of Kazakhstan. Project records under ISO 9001:2015 are kept for the life of the contract and for the period the quality system requires after it ends.
The lang cookie stays in the browser for one year, unless you delete it sooner. Server logs are kept for the period the host needs for security, then deleted.
We limit access, use encrypted transport (HTTPS) for the website, keep backups of project data, and bind staff to confidentiality. No measure removes every risk of a breach.
§ 8 Your rights
You can ask whether we process data about you, and you can ask for a copy. You can ask for correction of inaccurate data. You can ask for deletion or for a restriction, where the law gives that right. Where the GDPR applies, you can ask for portability of data you provided, and you can object to processing that rests on legitimate interests.
You can withdraw consent as stated in § 4. You can complain to the competent authority of the Republic of Kazakhstan. Where the GDPR applies, you can complain to a supervisory authority in the EU, in particular in the member state where you live.
If we process personal data only on the instructions of a client, because the data sit in a system the client controls, send the request to that client as well. We will help the client answer it where our contract requires that.
§ 9 Contact and changes
Questions about this notice, and requests to exercise a right, go to [email protected] or to the postal address in § 1. There is no separate data protection officer. The managing director is the contact.
If we change this notice, the new text replaces the old one on this page. The date at the end of § 1 is the date of the current text. A change does not reduce rights you already have for data we already hold.