EventAI Privacy Policy
App: EventAI Document version: 1.0 Effective date: 28.06.2026 Operator: J-19 group LLP, Tax ID (BIN/IIN) 190540021304, address: РК, г. Алматы, Алатауский район, мкр. Акбулак, ул. Шарипова, д. 157, индекс 160600 Contacts: J19europe01@gmail.com · data protection: J19europe01@gmail.com
This Privacy Policy (hereinafter, the "Policy") describes what personal data is processed in the EventAI mobile application and service (hereinafter, the "App", the "Service"), for what purposes, on what legal grounds, to whom it is disclosed, and what rights the user has. By using the App, you confirm that you have reviewed this Policy.
The Service is a marketplace of venues and services for events (weddings, corporate functions, etc.) with an audience in Kazakhstan. Personal data is processed in accordance with the Law of the Republic of Kazakhstan "On Personal Data and Its Protection".
1. What Data We Collect
1.1. Registration and Account
- Phone number, password (as a hash), country code.
- Account type: personal or business.
1.2. Profile
ID, email, phone, name/full name, nickname, date of birth (opt.), avatar (opt.), region/city/district, Google ID (when signing in via Google), profession (opt.), "show my services in profile" flag, interface language, creation/update dates, last login date.
1.3. Location Data
- Manual selection of region/city/district.
- GPS in the foreground only (approximate and precise) — to display venues and services nearby. There is no background location.
1.4. User-Generated Content (UGC)
- Reviews and ratings: rating 1–5, text, photos; for venues — the owner's reply.
- Chat messages: text, attachments (photos/files), read statuses, online/typing statuses, mute/pin/archive flags.
- Listings (for providers): venues, services, organizations — names, descriptions, photos/videos, prices, contacts (phone, email, website, Telegram, Instagram), address, capacity.
- Invitations (generator): template, title/description, images, audio, video, link slug, guest list. By entering guest data (names/contacts — third-party data), you confirm that you have the right and/or the consent of these individuals to process it (see the User Agreement).
- Scenarios / event planning: event type, date, guest count, budget, service preferences, free-text request.
- Smart Selection: budget, guest count, event type, location, date, preferences.
- Orders/bookings: service/venue IDs, event date, guest count, notes, status.
- Favorites: services, venues, organizations.
1.5. Business Account Data
Additional fields for business verification: legal name, Tax ID (BIN/IIN), legal address, logo, cover image, photos, video, verification documents, verification status.
1.6. Technical Identifiers
- FCM push token (bound to the user) — registered on login, removed on logout.
- With crash reporting enabled: device information (see §9).
We do not process payment data: wallet/payment features are disabled at launch.
2. Purposes and Legal Grounds for Processing
| Purpose | Data categories | Ground (RK Law "On Personal Data") |
|---|---|---|
| Registration, login, identification | Phone, password, Google ID, tokens | Performance of the contract (the Agreement) |
| Marketplace operation (listings, search, orders) | Profile, UGC, location | Performance of the contract |
| Chat and notifications | Messages, FCM token | Performance of the contract |
| Showing nearby venues/services | Location (in the foreground) | Consent |
| Scenario generation and selection (AI) | Event parameters | Performance of the contract / consent |
| Business verification | Documents, BIN/IIN | Performance of the contract, statutory requirements |
| Security, fraud prevention | Technical identifiers, logs | Legitimate interest / performance of the contract |
| Crash reporting and stability | Device data, stack traces | Consent (off by default) |
3. Disclosure of Data to Third Parties (Sub-processors)
We do not sell personal data. Data is disclosed to processors only to the extent necessary to operate the Service:
| Service | What it processes | Purpose |
|---|---|---|
| Firebase Authentication (Google) | Phone numbers (for SMS-OTP), ID tokens | Phone verification, authorization |
| Firebase Cloud Messaging (Google) | Device FCM token, notification content | Push notifications |
| Firebase Crashlytics (Google) | Stack traces, errors, device info | Crash reports — with consent only |
| Google Sign-In (Google) | Google ID token (email, profile) | Sign-in via Google |
| Yandex Cloud Object Storage | Uploaded media: avatars, service/review photos, invitation media, video, documents | Storage of user files |
| DeepSeek | Event parameters (type, date, guest count, budget, preferences, free text), venue data (name, address, capacity) | AI event scenario generation |
| Groq | Event parameters and compact candidate data (name, description, price, rating) | AI service selection (Smart Selection) |
Important regarding AI: your personal identifiers (name, phone, email) are not disclosed to DeepSeek or Groq — only event parameters and de-identified offer data. For details, see the AI Usage Policy.
Processing countries and training on data (AI providers):
- Groq (USA). Under the Groq Services Agreement, Groq does not use the transmitted data (Inputs/Outputs) to train or fine-tune models and does not retain it by default; the Zero Data Retention (ZDR) mode is enabled for the service.
- DeepSeek (China, PRC). Under DeepSeek's terms, the provider is entitled to use the transmitted data to support and improve its services and technologies, including training models; the data may be processed outside the RK, including within the territory of the PRC. To limit this, we do not disclose identifying personal data to DeepSeek and minimize the content of requests. The legal ground for disclosure is your consent.
Real-time chat and updates run on our own infrastructure (Socket.IO, JWT authorization) and are not disclosed to third-party services.
Links to processors' policies:
- Google/Firebase (USA): https://policies.google.com/privacy
- Yandex Cloud: https://yandex.ru/legal/cloud_terms_kz/ (and related documents)
- DeepSeek (PRC): https://www.deepseek.com/privacy
- Groq (USA): https://groq.com/privacy-policy/
4. Device Permissions
The App requests permissions only as needed:
| Permission | Why |
|---|---|
| Camera | Photos for profile, listings, reviews, invitations |
| Photo library / media | Selecting images and audio (for invitations) |
| Location (in the foreground) | Showing nearby venues and services |
| Microphone | Recording video for listings |
| Contacts | Helping share services with friends |
| Notifications (push) | Messages and order updates |
| Face ID / biometrics | Quick and secure sign-in (handled by the device OS) |
Background location is not requested. You can revoke permissions in device settings.
5. Data Storage and Security
- Transport: HTTPS only. Cleartext is prohibited (Android
network_security_config, iOS ATS). The only exception is the Yandex Cloud Storage domains for media; the API is always over HTTPS. - On-device: the JWT token and the PIN hash are kept in secure storage (Keychain/Keystore); the PIN is hashed with SHA-256. Non-sensitive settings (language, theme, onboarding flags, crash reporting consent) are stored in SharedPreferences.
- Backup exclusion: secure storage, local databases and files are excluded from cloud backup and device-to-device transfer.
- Server: passwords are stored only as bcrypt hashes; sessions are in Redis; data access is restricted and logged.
- Sessions: on expiry/revocation (401) a re-login is required.
Retention: data is processed while the account is active. After account deletion, personal data is anonymized immediately; copies in system backups are removed within the technically determined period of their rotation. Some data may be kept longer where required by law (e.g., to resolve disputes).
6. Your Rights
Under the RK Law "On Personal Data and Its Protection", you may:
- obtain information about the processing of your data;
- request correction of inaccurate data (profile editing in the App);
- withdraw consent (e.g., for location or crash reporting — in settings);
- request deletion of data and delete your account directly from the App (Settings → Account → Delete account). See Account Deletion;
- block other users (chat and visibility) — Profile → Block;
- report content or a user (the "Report" button in the app) — see the Complaints Policy.
Send rights requests to J19europe01@gmail.com. The response time is in accordance with RK law.
7. Children and Age
The Service is intended only for persons who have reached 18 years of age and is not intended for children. By registering, the user confirms their age (see the User Agreement, §4). We do not knowingly collect the data of minors. If you believe that an account was created by a person under 18 years of age, write to J19europe01@gmail.com — we will block the account and delete the associated data.
8. Analytics and Crash Reporting
- Crashlytics: OFF by default; enabled only with the user's consent (stored in SharedPreferences, applied on the next start). Always off in debug builds. When enabled it collects: stack traces, error messages, device info (OS, model), build tag.
- Other analytics (Google Analytics, Amplitude, Mixpanel, etc.) — none.
9. International Transfers
Some processors process data outside the Republic of Kazakhstan: Google/Firebase and Groq — in the USA; DeepSeek — in China (PRC). We transfer the minimum necessary amount of data. The legal ground for cross-border transfer is your consent (given when using the relevant features). For DeepSeek, an additional restriction applies: identifying personal data is not transferred, and the content of requests is minimized (see §3). For the storage region of Firebase and the server infrastructure, see the operator's configuration.
10. Changes to the Policy
We may update this Policy. The current version is published at https://eventai.kz/privacy. For material changes we will notify users in the App or by other available means. The effective date is shown at the beginning of the document.
11. Contacts
- Operator: J-19 group LLP
- Support: J19europe01@gmail.com
- Personal data inquiries: J19europe01@gmail.com
- Address: РК, г. Алматы, Алатауский район, мкр. Акбулак, ул. Шарипова, д. 157, индекс 160600