SecondBook is committed to protecting the personal data of all users, including residents of the European Union and the European Economic Area (EEA). This document supplements our Privacy Policy and describes specific measures for GDPR compliance.
Data Controller: Ilnur Stybayev, an independent individual developer (not a legal entity).
2ndBook is a non-commercial tool that lets users find and contact each other directly. The operator is not a party to any transaction between users, does not hold, transfer or retain funds, and charges no commission.
Email for GDPR Requests: support@secondbook.kz
General Email: support@secondbook.kz
The provisions of this document apply to:
This document does not extend GDPR to users outside the EU/EEA — the general Privacy Policy applies to them.
In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:
| Legal Basis | GDPR Article | Processing Purposes |
|---|---|---|
| Consent | 6(1)(a) |
• Marketing communications • Personalized advertising • Non-essential cookies • Participation in research |
| Contract Performance | 6(1)(b) |
• Account creation • Order and transaction processing • Communication with sellers/buyers • Technical support |
| Legal Obligations | 6(1)(c) |
• Tax reporting • Responding to authority requests • Data retention as required by law |
| Legitimate Interests | 6(1)(f) |
• Fraud prevention • Platform security • Service improvement • Usage analytics |
You have the right to know what data we collect, why, and how we use it. This information is provided in this document and the Privacy Policy.
You may request:
Response Time: 30 days (with possible extension of 60 days for complex requests).
You may request correction of inaccurate data or completion of incomplete data. You can also update your data yourself in profile settings.
You may request deletion of your data if:
Exceptions: We may refuse deletion if data is necessary for fulfilling legal obligations or defending legal claims.
You may request restricted processing if:
You may request a copy of your data in a readable format to transfer to another controller. Self-service automated export (a button in the app) is not yet implemented — we prepare the data manually on request. This right applies to data that:
You have the right to object to:
You have the right not to be subject to decisions based solely on automated processing, including profiling, which have legal or similarly significant effects.
How this works for us: automated moderation systems analyze listings, images, and messages for prohibited content and fraud, and may hide a listing or show a warning in chat. Final decisions on disputed cases and reports are made by a human (our support team); you can always contest an automated decision by contacting support.
If processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
You have the right to file a complaint with a data protection supervisory authority. For EU residents, this is the authority in your country of residence, work, or alleged violation.
To protect your data, we may request identity confirmation before fulfilling a request. This may include:
| Request Type | Response Time |
|---|---|
| Standard request | 30 days |
| Complex request | Up to 90 days (with notification) |
| Objection to marketing | Immediately (no more than 48 hours) |
Exercising your rights is free. We may charge a reasonable fee or refuse to act only for manifestly unfounded or excessive requests (e.g., repeated requests).
The data controller is based in the Republic of Kazakhstan — data from EU/EEA users is transferred to and stored outside the EEA. We apply reasonable technical and organizational measures to protect data in such transfers (encryption in transit and at rest, restricted access). We have not entered into formal Standard Contractual Clauses (SCCs) approved by the European Commission with our current infrastructure providers — if this becomes legally required as the service grows, we will do so and update this section.
In accordance with Article 25 of the GDPR, we implement the following principles:
In the event of a personal data breach that may pose a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours.
If the breach may result in a high risk to your rights and freedoms, we will notify you without undue delay, indicating:
Article 35 of the GDPR requires a formal data protection impact assessment for high-risk processing operations. We do not yet have a formalized DPIA program — we informally assess privacy risk before rolling out significant changes that affect personal data (e.g. new moderation or age-restriction features). If the scale and complexity of our processing grows to the point a formal DPIA becomes legally required, we will conduct one.
In accordance with Article 27 of the GDPR, if you wish to contact our EU representative or have questions about GDPR, please write:
Email: support@secondbook.kz
We will consider appointing an official EU representative as our presence in the European market expands.
SecondBook does not use cookies for tracking, analytics, or advertising — for EU users or anyone else. See Section 7 of our Privacy Policy for details. Because no non-essential cookies are used, no separate EU consent banner is required.
We may update this document. We will notify you of significant changes by email at least 30 days before the changes take effect.
Data Controller: SecondBook
Address: Republic of Kazakhstan, Almaty
Email for GDPR Requests: support@secondbook.kz
General Email: support@secondbook.kz
Support Service: support@secondbook.kz
Website: secondbook.kz
© 2026 SecondBook. All rights reserved.
Document updated: August 21, 2026 | Version: 1.2 | GDPR Compliance