GDPR Compliance — SecondBook

Effective Date: July 6, 2026
Last Updated: August 21, 2026
Version: 1.2
🇪🇺 For Users in the European Union: This document describes how SecondBook complies with the requirements of the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679.

1. Introduction

SecondBook is committed to protecting the personal data of all users, including residents of the European Union and the European Economic Area (EEA). This document supplements our Privacy Policy and describes specific measures for GDPR compliance.

1.1. Who We Are

Data Controller: Ilnur Stybayev, an independent individual developer (not a legal entity).

2ndBook is a non-commercial tool that lets users find and contact each other directly. The operator is not a party to any transaction between users, does not hold, transfer or retain funds, and charges no commission.

Email for GDPR Requests: support@secondbook.kz

General Email: support@secondbook.kz

1.2. Scope of Application

The provisions of this document apply to:

This document does not extend GDPR to users outside the EU/EEA — the general Privacy Policy applies to them.

2. Legal Bases for Data Processing

In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:

Legal Basis GDPR Article Processing Purposes
Consent 6(1)(a) • Marketing communications
• Personalized advertising
• Non-essential cookies
• Participation in research
Contract Performance 6(1)(b) • Account creation
• Order and transaction processing
• Communication with sellers/buyers
• Technical support
Legal Obligations 6(1)(c) • Tax reporting
• Responding to authority requests
• Data retention as required by law
Legitimate Interests 6(1)(f) • Fraud prevention
• Platform security
• Service improvement
• Usage analytics

3. Your Rights Under GDPR

As a data subject, you have the following rights:

3.1. Right to Information (Articles 13-14)

You have the right to know what data we collect, why, and how we use it. This information is provided in this document and the Privacy Policy.

3.2. Right of Access (Article 15)

You may request:

Response Time: 30 days (with possible extension of 60 days for complex requests).

3.3. Right to Rectification (Article 16)

You may request correction of inaccurate data or completion of incomplete data. You can also update your data yourself in profile settings.

3.4. Right to Erasure ("Right to Be Forgotten") (Article 17)

You may request deletion of your data if:

Exceptions: We may refuse deletion if data is necessary for fulfilling legal obligations or defending legal claims.

3.5. Right to Restriction of Processing (Article 18)

You may request restricted processing if:

3.6. Right to Data Portability (Article 20)

You may request a copy of your data in a readable format to transfer to another controller. Self-service automated export (a button in the app) is not yet implemented — we prepare the data manually on request. This right applies to data that:

3.7. Right to Object (Article 21)

You have the right to object to:

3.8. Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which have legal or similarly significant effects.

How this works for us: automated moderation systems analyze listings, images, and messages for prohibited content and fraud, and may hide a listing or show a warning in chat. Final decisions on disputed cases and reports are made by a human (our support team); you can always contest an automated decision by contacting support.

3.9. Right to Withdraw Consent (Article 7(3))

If processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

3.10. Right to Lodge a Complaint (Article 77)

You have the right to file a complaint with a data protection supervisory authority. For EU residents, this is the authority in your country of residence, work, or alleged violation.

4. How to Exercise Your Rights

4.1. Methods of Submitting Requests

4.2. Identity Verification

To protect your data, we may request identity confirmation before fulfilling a request. This may include:

4.3. Response Times

Request Type Response Time
Standard request 30 days
Complex request Up to 90 days (with notification)
Objection to marketing Immediately (no more than 48 hours)

4.4. Cost

Exercising your rights is free. We may charge a reasonable fee or refuse to act only for manifestly unfounded or excessive requests (e.g., repeated requests).

5. International Data Transfers

5.1. Cross-Border Transfer

The data controller is based in the Republic of Kazakhstan — data from EU/EEA users is transferred to and stored outside the EEA. We apply reasonable technical and organizational measures to protect data in such transfers (encryption in transit and at rest, restricted access). We have not entered into formal Standard Contractual Clauses (SCCs) approved by the European Commission with our current infrastructure providers — if this becomes legally required as the service grows, we will do so and update this section.

6. Data Protection by Design and by Default

In accordance with Article 25 of the GDPR, we implement the following principles:

6.1. Privacy by Design

6.2. Privacy by Default

7. Breach Notification

7.1. Notification to Supervisory Authority (Article 33)

In the event of a personal data breach that may pose a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours.

7.2. Notification to Data Subject (Article 34)

If the breach may result in a high risk to your rights and freedoms, we will notify you without undue delay, indicating:

8. Data Protection Impact Assessment (DPIA)

Article 35 of the GDPR requires a formal data protection impact assessment for high-risk processing operations. We do not yet have a formalized DPIA program — we informally assess privacy risk before rolling out significant changes that affect personal data (e.g. new moderation or age-restriction features). If the scale and complexity of our processing grows to the point a formal DPIA becomes legally required, we will conduct one.

9. EU Representative

In accordance with Article 27 of the GDPR, if you wish to contact our EU representative or have questions about GDPR, please write:

Email: support@secondbook.kz

We will consider appointing an official EU representative as our presence in the European market expands.

10. Cookies and Tracking

SecondBook does not use cookies for tracking, analytics, or advertising — for EU users or anyone else. See Section 7 of our Privacy Policy for details. Because no non-essential cookies are used, no separate EU consent banner is required.

11. Document Changes

We may update this document. We will notify you of significant changes by email at least 30 days before the changes take effect.

12. Contact Information

Data Controller: SecondBook

Address: Republic of Kazakhstan, Almaty

Email for GDPR Requests: support@secondbook.kz

General Email: support@secondbook.kz

Support Service: support@secondbook.kz

Website: secondbook.kz

© 2026 SecondBook. All rights reserved.
Document updated: August 21, 2026 | Version: 1.2 | GDPR Compliance