How OJSC Envoys Vision Digital Exchange processes and protects personal data. Approved by decision of the Board of Directors, minutes No. 21/1 of 25 January 2025.
The policy is based on the laws of the Kyrgyz Republic on personal information, on commercial secrets, on the securities market, on commodity exchanges and exchange trading, on electronic commerce, on articles 18 and 49 of the Civil Code, on government resolutions covering consent of data subjects and data protection requirements, and on the laws on countering the financing of terrorism and the laundering of criminal proceeds and on virtual assets.
The data operator is OJSC Envoys Vision Digital Exchange. The policy covers www.envoys.vision, mobile applications and other digital services of the exchange. Consent is given by signing the questionnaire for an individual, a legal entity or a partner, depending on the type of user.
The document is public: it is published on the website, and every employee with access to user data is required to read it.
When handling personal data the exchange follows these principles:
Processing rests on one or more lawful grounds: the subject's consent; performance of a contract to which the subject is a party; a duty imposed on the exchange by law; protection of vital interests; or the exchange's legitimate interest where it does not infringe the subject's rights.
Data is not processed for purposes beyond those listed above. If the purposes change, the exchange notifies the user and, where required, obtains new consent.
Virtual asset transactions are recorded in a public distributed ledger. Wallet addresses, amounts and timestamps are publicly available, immutable and cannot be deleted for technical reasons — the exchange is not responsible for third-party access to that data.
Blockchain analytics software is used to monitor transactions and assess risk (the Know Your Transaction procedure). The results of such checks are confidential information of the exchange and are not disclosed to the user, except where the law expressly requires it.
Because the exchange operates across several sectors, the same information may fall under more than one legal regime at once. In such cases all of them apply, and the strictest requirements govern.
The protection regime does not cover information whose disclosure is mandatory by law: data subject to issuer disclosure, data provided to supervisory authorities, and data transferred to the State Financial Intelligence Service.
The exchange controls access to equipment and storage media, logs operations with an immutable audit trail, encrypts data at rest and in transit, and limits staff access on a need-to-know basis.
Once the retention period expires, data is destroyed and the destruction is recorded in a formal act; backup copies are deleted when their own retention period ends. Longer retention is allowed where the authorised body requests it.
Data is shared with third parties without additional consent where this is strictly necessary to protect the subject's interests, at the request of state bodies acting within their powers, and where the law requires it. The exchange notifies the user of such a transfer, unless doing so would harm its lawful interests or breach the law.
Information is transferred to the State Financial Intelligence Service without the subject's consent and without notifying them.
Data may be received by:
Cross-border transfers are allowed provided the receiving party ensures an adequate level of protection for data subjects. Transfers to countries without such a level are possible only with the subject's consent or where strictly necessary to protect their interests.
Substantiated requests are answered within 14 business days. If the applicant's identity has to be verified, the period may be extended to 30 business days with notice.
Disclosure or erasure may be refused in the cases set out in article 15 of the Law on Personal Information, and for data the exchange is obliged to keep under the laws on the securities market, on AML/CFT, on virtual assets and under the Tax Code. Withdrawing consent ends the provision of services, but such data is retained for the statutory periods.
The user must:
The exchange must:
If an incident occurs that caused or could cause unauthorised access, leakage, alteration or destruction of data, the exchange:
Notice is sent to the contact details given at registration and describes the incident, the categories and approximate volume of data affected, the contact person, possible consequences and the measures taken. Incidents can also be reported through the channels set out in the anti-bribery and anti-corruption policy.
The exchange is liable for unlawful use of personal data under the legislation of the Kyrgyz Republic; employees who breach confidentiality face disciplinary, material, administrative or criminal liability.
The exchange is not liable for loss or disclosure of data that the user disclosed themselves or that became known to third parties through their fault, nor for data made public by being written to a blockchain — an inherent technical property of a distributed ledger, of which the user is informed at registration.
A written claim must be filed before going to court: the recipient must respond within 30 calendar days. If no agreement is reached, the dispute is heard by a court at the exchange's location. Regardless of any court proceedings, the subject may complain to the State Agency for Personal Data Protection under the Cabinet of Ministers.
The website and mobile applications use cookies and similar technologies to run the platform, analyse its use and improve service quality:
Analytical and functional cookies can be disabled in browser settings — some platform features may then become unavailable.
The policy takes effect once approved by the Board of Directors and published on the website. Changes are communicated by publishing the current version on www.envoys.vision no later than 10 business days before they take effect.
The policy is reviewed at least once a year. An unscheduled review takes place if legislation changes, if the data processed or the purposes change materially, if a security incident is detected, or following an internal or external audit.
Contacts for enquiries
OJSC Envoys Vision Digital Exchange
19 Razzakov street, Bishkek, Kyrgyz Republic
Incident reports: via the secure reporting line