naya

Privacy Policy

Version v11 of 28 September 2026

This English version is a translation provided for convenience. The official texts are in Kazakh and Russian; if this translation differs from them, the Kazakh and Russian texts prevail.

Naya is an online booking service. The operator of personal data is NayaIT Solutions LLP, BIN 260940005233, 2/23 Saken Zhunisov Street, Apt. 129, Shugyla Microdistrict, Nauryzbay District, Almaty 050035, Kazakhstan. Data is processed under the Law of the Republic of Kazakhstan No. 94-V of 21 May 2013 "On Personal Data and Their Protection".

What data we collect

  • Phone number. Without it we can neither book you nor let you into your account: you sign in to the service with your number and a code from a message.
  • Password. You create it at your first sign-in and use it to sign in from then on. We do not store the password itself — only the result of an irreversible transformation from which the original password cannot be recovered; the service's staff cannot see it. A forgotten password is changed with a code sent to your number, and you can change it at any time.
  • Name — the one you gave when booking. The venue sees it so it knows whom to expect.
  • Your bookings: the venue, service, specialist, time and your comment, if you left one; cancellations and reschedules.
  • Reviews — if you write them. They are public and shown with your name. You can also leave a review via a link sent by a venue or a specialist — such a review is labeled "By invitation".
  • Messages with a venue — messages, photos and files that you send to a venue and it sends to you. Only the participants of the conversation see them; the service's staff open a message only if it has been reported.
  • Photos — your avatar and pictures attached to reviews, if you upload them. A review photo is public together with the review. Venues you book with see your avatar — you can turn this off in your profile ("Photo for venues").
  • Location — only if you tap "Near me" and allow access to it. The coordinates go into the search request to sort places by distance, are not saved in your account and remain only in the server's technical logs for a limited time.
  • The camera works on your device: it reads a venue's QR code at the entrance or takes a picture you decided to send. The camera image is not sent to us — only a picture you have sent yourself.
  • A venue's notes about you — if the venue keeps them: for example, about an allergy to an ingredient or what was done at your last visit, sometimes with a photo of the result. The venue keeps them itself; we store them on its instructions and do not show them to you in the service. To find out what has been recorded, or to correct or delete it, contact the venue; deleting your account deletes them at all venues at once.
  • Technical data: IP address, device and browser type, session cookies. They are needed for sign-in to work and to tell people from bots.
  • Usage statistics: which pages and screens were opened (together with the page address, including the text of a search query), where you came from, device and browser type, whether it was the website or the app, and approximate location based on the IP address. They are collected by Google Analytics through its own identifier — both on the websites and in the apps.
  • Device token — if you installed the app and allowed notifications. It contains neither your number nor your name.

We do not ourselves collect health data, documents or payment details, and we do not track you in other apps or on other websites. You pay for a service at the venue, not through us.

If you own a venue or are a specialist

The dashboard has a different role, and it is more honest to describe it separately than to mix it into the general list. About you, we collect your phone number (sign-in is the same — by code), name, the name and address of the venue, the price list, schedule and photos you uploaded, and your subscription payment history.

  • Your clients' data belongs to you. We store it and pass it on at your instruction — we remind clients of visits and show you their contacts — but you control it, and you are responsible for it to the client. We do not use your client base for anything other than running your own dashboard: we do not send our own messages to it, do not pass it to other venues and do not sell it.
  • Public and non-public. The name, address, opening hours, price list, photos, and the names and ratings of specialists are visible to everyone — that is the storefront. Your number, client base, till and subscription are visible only to you and those you have given access to.
  • Staff do not see everything. Permissions are nested: the owner sees more than an administrator, an administrator more than a specialist. A specialist sees their own schedule and does not see clients' contacts — this restriction is enforced in the database, not in interface settings.
  • Notes about clients — the client card and visit log kept by you and your staff, together with photos. The client does not see them in the service; if the client asks to see or delete what has been recorded about them, you must respond, and the notes export exists for this. A specialist sees notes only about people who booked with them and cannot export them. When a client deletes their account, their notes are erased together with the photos.
  • Number for tips. If you have turned on showing a number for tips, clients who had a visit with you see it for 30 days after the visit. Only you can turn it on and off — a venue owner cannot do it for you; turning it off takes effect immediately. The transfer goes directly to you and we take no part in it: we take no fee, do not see it and store nothing except the number and the recipient's name that you entered.
  • Automatic translation of catalog texts. If you save a name or description in fewer than all of the service's languages, the dashboard offers a translation of the missing ones. For this, the field text goes to a machine translation provider — Anthropic, PBC (USA); see "Who we share data with". The translation is only suggested: it is published after you review and confirm it. Only the texts you write about the venue for the storefront are sent: names and descriptions of services, price list sections, options and passes, and the "About us" text. Clients' data, phone numbers, bookings, notes and a specialist's "About me" text are not sent; so do not put information about people in the descriptions.

A subscription paid on the website goes through a payment gateway. The card number never reaches us and is not stored by us — we receive from the gateway only a confirmation of successful payment and the last digits. If the subscription was purchased in the app, the payment is taken by the App Store or Google Play: we have no card data at all, and the store tells us only about the purchase itself — its identifier, term and amount.

Why

  • to make a booking and pass it to the venue;
  • to remind you of a visit and tell you if an earlier time has become available;
  • to let you into your account and show your bookings;
  • to protect the service from abuse — limit request rates and block those who disrupt other people's bookings;
  • to understand from aggregate statistics which website pages and app screens are used and where people get stuck.

Who we share data with

We do not sell data and do not give it to advertisers. Data is shared in exactly five cases: three are needed for the service to work, the fourth is to understand how it is used, and the fifth concerns only the texts a venue writes about itself for the storefront:

  • The venue you booked with receives your name, number, the booking itself and your profile photo, if you uploaded one and did not turn off showing it to venues. From then on the venue handles this data on its own and is responsible for it. Other venues do not see your data. The venue also receives your name and number if you left a review via its invitation link: you become its client.
  • Meta Platforms Ireland Ltd. (WhatsApp) — the confirmation code is sent to you on WhatsApp, so your number is passed to Meta to deliver the message. Meta's servers are outside Kazakhstan, which makes this a cross-border transfer, and by booking you consent to it.
  • Google (Firebase Cloud Messaging) delivers notifications to the app. Only the device token is passed, without your number or name.
  • Google (Google Analytics) counts visits to the naya.kz and biz.naya.kz websites and the Naya apps: it receives an identifier from its own cookie, the addresses of pages opened, device and browser type, whether it is the website or the app, and the IP address. Your phone number and name are not sent, and the booking page opened via a link from a message has no counter at all. Google's advertising features (Signals and ad personalization) are turned off: the statistics are not used for advertising and are not linked to your data in other apps or on other websites. Google's servers are outside Kazakhstan — this is a cross-border transfer.
  • Anthropic, PBC (machine translation) receives catalog texts that a venue writes about itself when the owner or an administrator saves them in fewer than all languages: names and descriptions of services, price list sections, options and passes, and the "About us" text. Only the venue's field of activity is sent with the text, to make the translation more accurate. The result is a suggested translation that is published after the venue reviews and confirms it. Clients' data (names, numbers, bookings, notes) and a specialist's "About me" text are not sent. Anthropic's servers are in the USA, which makes this a cross-border transfer.

Where data is stored and how it is protected

Data is stored on servers in Kazakhstan. Venues' clients' phone numbers are stored encrypted; only the venue itself has access to its data — the separation is enforced at the database level, not by interface settings. A venue employee with limited permissions does not see clients' contacts.

How long we keep data

Bookings and related data — as long as your account exists: the visit history is needed by both you and the venue. Technical logs — for a limited time needed to investigate failures and abuse. At your request we delete earlier.

If you have deleted your account, a fingerprint of your number remains — a hash with a secret key from which the number itself cannot be read. It serves one purpose: if a venue uploads its old client base with your number, no bulk messages through Naya will be sent to it.

Your rights

You can find out what data we hold, correct it, withdraw your consent and demand deletion. Withdrawing consent means we will no longer be able to book you or remind you of visits. Records that a venue is required to keep under its own rules stay with the venue — our deletion does not extend to them.

The deletion procedure — step by step, with what is deleted and what remains — is on a separate page: data deletion.

Write or call — we will reply:

Children

The service is used by adults. If you book for a child, you do so as a parent or legal representative and are responsible for the child's data.

Changes

If the processing rules change, we will raise the version number on this page. The current one is v11 of 28 September 2026.

On 3 September 2026, the operator of personal data changed from the individual entrepreneur Ryzhkov to NayaIT Solutions LLP, BIN 260940005233. The data collected, the purposes of processing and the retention periods did not change.

On 13 September 2026, Google Analytics visit statistics appeared on the websites — they are described in "What data we collect" and "Who we share data with". Nothing changed in the apps.

On 17 September 2026, Google Analytics statistics appeared in the apps as well — with the same data as on the websites and with Google's advertising features turned off.

At the same time, venues' notes about clients appeared — they are described in "What data we collect" and in the section for venue owners.

On 23 September 2026, automatic translation of catalog texts appeared in the dashboard — it is described in the section for venue owners and in "Who we share data with". It does not concern clients' data.

At the same time, in version v9, the policy described in more detail what was already in the service: messages with venues and attachments, photos, location for "near me" search, the camera, and subscription payment through the App Store and Google Play. Visit reminders come only as app notifications, so WhatsApp remains only for the confirmation code.

On 25 September 2026, in version v10, reviews by invitation appeared: a venue or a specialist sends a link, and by leaving a review through it you become their client — your name and number are passed to them just as when booking. This is described in "What data we collect" and "Who we share data with".

On 28 September 2026, in version v11, venues you book with began to see your profile photo — in bookings and in messages, to recognize you at the front desk. You can turn this off in your profile with the "Photo for venues" switch; a photo you did not upload will not appear anywhere.

Service
Naya — naya.kz
Provided by
NayaIT Solutions Limited Liability Partnership
BIN
260940005233
Address
2/23 Saken Zhunisov Street, Apt. 129, Shugyla Microdistrict, Nauryzbay District, Almaty 050035, Kazakhstan
Phone
+7 706 716 81 76
WhatsApp
+7 777 116 81 76
Email
support@naya.kz