1. Who processes the data
The BELF provider and the website data operator is DIGITAL REVOLUTION MAKERS. Privacy contact: aonas.main@gmail.com.
The corporate client usually determines the purposes of employee monitoring and acts as the owner and/or operator of the relevant data. DIGITAL REVOLUTION MAKERS processes such data under the client’s documented instructions, the contract, and the DPA.
2. Data and purposes
- Contact and contractual data of client representatives — for negotiations and contract performance.
- Account data, roles, and licence information — for access, activation, and support.
- IP address, device information, versions, errors, and technical logs — for security and diagnostics.
- Employee monitoring data — only within modules selected by the client and for purposes defined by the client.
- Website visit data and Google Analytics — for statistics only after the visitor’s consent.
3. Legal bases for processing
Depending on the circumstances, processing is necessary to enter into and perform a contract, comply with legal obligations, ensure information security and pursue other legitimate interests, or is based on consent. For employee data, the employer determines the appropriate legal basis with regard to applicable labour law.
Consent is used only where it is an appropriate and freely given legal basis and may be withdrawn for the future.
4. Retention periods
- Contractual and payment documents — for the term of the contract and any mandatory accounting, tax, or claims period.
- Accounts and licences — while access remains active and thereafter for the period required to close outstanding obligations.
- Security logs — for an approved period proportionate to the purpose and risk.
- Monitoring data — for the period set by the client in the contract and settings, after which it is deleted or anonymised.
- Cookies and analytics identifiers — in accordance with the Cookie Policy and service settings.
5. Recipients and subprocessors
Access is granted to authorised personnel of the provider and the client. Cloud infrastructure may use UzCloud in Uzbekistan and Amazon Web Services in other agreed regions; Google Analytics is used for website analytics after consent. Banks, advisers, and public authorities receive data only where there is a legal basis.
Current subprocessors, region, and special restrictions are specified in the contract or DPA.
6. Cross-border transfers
Data of citizens of Uzbekistan that is subject to localisation requirements is collected, systematised, and stored on technical facilities located in Uzbekistan. For other jurisdictions, the region is agreed after reviewing localisation and transfer requirements.
Cross-border transfers are carried out only where an appropriate legal basis and safeguards are in place. If the requirements cannot be met, a compliant region or Self hosted deployment is selected.
7. Data subject rights
To the extent provided by applicable law, a data subject may request information about processing, access and a copy, rectification, deletion or restriction, withdraw consent, object, and lodge a complaint with the competent authority.
Requests should be sent to aonas.main@gmail.com and include the person’s name, organisation, contact method, and the substance of the request. Identity verification may be required to protect the data. Employees will usually contact their employer first; DIGITAL REVOLUTION MAKERS assists the client with fulfilling the request within the scope of the DPA.