GDPR Compliance — SecondBook

Effective Date: July 6, 2026
Last Updated: June 4, 2026
Version: 1.0
🇪🇺 For Users in the European Union: This document describes how SecondBook complies with the requirements of the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679.

1. Introduction

SecondBook is committed to protecting the personal data of all users, including residents of the European Union and the European Economic Area (EEA). This document supplements our Privacy Policy and describes specific measures for GDPR compliance.

1.1. Who We Are

Data Controller: Ilnur Stybayev, an independent individual developer (not a legal entity).

2ndBook is a non-commercial tool that lets users find and contact each other directly. The operator is not a party to any transaction between users, does not hold, transfer or retain funds, and charges no commission.

Email for GDPR Requests: support@secondbook.kz

General Email: support@secondbook.kz

1.2. Scope of Application

The provisions of this document apply to:

2. Legal Bases for Data Processing

In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:

Legal Basis GDPR Article Processing Purposes
Consent 6(1)(a) • Marketing communications
• Personalized advertising
• Non-essential cookies
• Participation in research
Contract Performance 6(1)(b) • Account creation
• Order and transaction processing
• Communication with sellers/buyers
• Technical support
Legal Obligations 6(1)(c) • Tax reporting
• Responding to authority requests
• Data retention as required by law
Legitimate Interests 6(1)(f) • Fraud prevention
• Platform security
• Service improvement
• Usage analytics

3. Your Rights Under GDPR

As a data subject, you have the following rights:

3.1. Right to Information (Articles 13-14)

You have the right to know what data we collect, why, and how we use it. This information is provided in this document and the Privacy Policy.

3.2. Right of Access (Article 15)

You may request:

Response Time: 30 days (with possible extension of 60 days for complex requests).

3.3. Right to Rectification (Article 16)

You may request correction of inaccurate data or completion of incomplete data. You can also update your data yourself in profile settings.

3.4. Right to Erasure ("Right to Be Forgotten") (Article 17)

You may request deletion of your data if:

Exceptions: We may refuse deletion if data is necessary for fulfilling legal obligations or defending legal claims.

3.5. Right to Restriction of Processing (Article 18)

You may request restricted processing if:

3.6. Right to Data Portability (Article 20)

You may receive your data in a structured, machine-readable format (JSON, CSV) and transfer it to another controller. This right applies to data that:

3.7. Right to Object (Article 21)

You have the right to object to:

3.8. Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which have legal or similarly significant effects.

Note: SecondBook does not use fully automated decision-making with legal consequences without human involvement.

3.9. Right to Withdraw Consent (Article 7(3))

If processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

3.10. Right to Lodge a Complaint (Article 77)

You have the right to file a complaint with a data protection supervisory authority. For EU residents, this is the authority in your country of residence, work, or alleged violation.

4. How to Exercise Your Rights

4.1. Methods of Submitting Requests

4.2. Identity Verification

To protect your data, we may request identity confirmation before fulfilling a request. This may include:

4.3. Response Times

Request Type Response Time
Standard request 30 days
Complex request Up to 90 days (with notification)
Objection to marketing Immediately (no more than 48 hours)

4.4. Cost

Exercising your rights is free. We may charge a reasonable fee or refuse to act only for manifestly unfounded or excessive requests (e.g., repeated requests).

5. International Data Transfers

5.1. Cross-Border Transfer

Your data may be transferred outside the EEA for storage and processing. We ensure data protection through the following mechanisms:

Destination Country Protection Mechanism
Kazakhstan Standard Contractual Clauses (SCC)
USA (cloud providers) SCC + additional security measures
Other countries Adequacy decision or SCC

5.2. Standard Contractual Clauses

We use Standard Contractual Clauses approved by the European Commission for data transfers to countries without an adequacy decision.

6. Data Protection by Design and by Default

In accordance with Article 25 of the GDPR, we implement the following principles:

6.1. Privacy by Design

6.2. Privacy by Default

7. Breach Notification

7.1. Notification to Supervisory Authority (Article 33)

In the event of a personal data breach that may pose a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours.

7.2. Notification to Data Subject (Article 34)

If the breach may result in a high risk to your rights and freedoms, we will notify you without undue delay, indicating:

8. Data Protection Impact Assessment (DPIA)

In accordance with Article 35 of the GDPR, we conduct data protection impact assessments before implementing processing operations that may pose a high risk to the rights of data subjects, including:

9. EU Representative

In accordance with Article 27 of the GDPR, if you wish to contact our EU representative or have questions about GDPR, please write:

Email: support@secondbook.kz

We will consider appointing an official EU representative as our presence in the European market expands.

10. Cookies and Tracking

For EU users, we provide:

Cookie Categories:

Category Consent Required Can Be Disabled
Strictly Necessary No No
Functional Yes Yes
Analytics Yes Yes
Marketing Yes Yes

11. Document Changes

We may update this document. We will notify you of significant changes by email at least 30 days before the changes take effect.

12. Contact Information

Data Controller: SecondBook

Address: Republic of Kazakhstan, Almaty

Email for GDPR Requests: support@secondbook.kz

General Email: support@secondbook.kz

Support Service: support@secondbook.kz

Website: secondbook.kz

© 2026 SecondBook. All rights reserved.
Document updated: June 4, 2026 | Version: 1.0 | GDPR Compliance