Privacy Policy
Last updated: April 29, 2026
This Privacy Policy describes how Parketiko ("we", "us", or "our") collects, uses, and protects your personal information when you use our website parketiko.com and related services. We comply with the requirements of the Law of the Republic of Kazakhstan "On Personal Data and its Protection" of May 21, 2013, No. 94-V, as well as the European Union's General Data Protection Regulation (GDPR) where applicable (e.g., when working with European design studios).
1. Definitions
For the purposes of this Policy, the following terms are used:
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person (name, phone, email, IP address, etc.) |
| Processing | Any operation with personal data — collection, storage, use, transfer, deletion |
| Operator / Data Controller | Entity determining the purposes and means of processing personal data (Parketiko) |
| Data Processor | Entity processing data on behalf of the controller (e.g., Resend, Bitrix24) |
| Data Subject | Natural person whose data is processed (you) |
| Cookies | Small text files stored on your device |
| Service | Website parketiko.com and related parquet supply services |
2. Who We Are
Parketiko
| Business | European parquet distribution in Kazakhstan |
| Exclusive | Official ESTA Parket representative in Kazakhstan from January 1, 2026 |
| Warehouse | Astana, Kazakhstan |
| denys.fursov@parketiko.com | |
| Phone / WhatsApp | +7 705 557 0189 |
| Telegram | @denysparketiko |
| Role | Personal Data Operator / Controller |
We are the personal data operator under Kazakh Law No. 94-V and the data controller under GDPR for the personal data you provide to us. This means we determine the purposes and means of processing your data.
3. Data We Collect
Data you provide directly:
- Contact information (name, phone, email)
- Project information (project area, address / building, installation pattern)
- Content of your messages and inquiries
- Messenger conversation history (Telegram, WhatsApp)
- Payment information (when paying for an order — invoice details, business ID/BIN for legal entities)
Data collected automatically:
- IP address and approximate location
- Device type, browser, and operating system
- Website visit data (pages, time, referral source)
- Cookies and similar technologies (see Cookie Policy)
Data from external sources:
- Information from Bitrix24 (if you filled out the online form via the widget)
- Data from analytics platforms (aggregated)
- Public company information (designer's business, architectural firm) — for B2B inquiries
4. Purposes of Processing
| Purpose | Description | Legal Basis |
|---|---|---|
| Parquet supply | Order fulfillment: selection, calculation, delivery | Contract performance |
| Communication | Responding to price requests and consultations | Legitimate interest / consent |
| Installation coordination | Contact with client's installer | Contract performance |
| Marketing | Informing about new ESTA collections | Consent |
| Analytics | Improving the website and material selection | Legitimate interest |
| Security | Fraud protection, spam filtering | Legitimate interest |
| Legal obligations | Bookkeeping, Kazakhstan taxes | Legal obligation |
5. Legal Basis for Processing
Under Kazakhstan Law No. 94-V we process your data based on:
- Your consent (filling out the price form, subscribing to a newsletter)
- Performance of a supply contract or pre-contractual steps at your initiative
- Compliance with legal requirements (bookkeeping)
- Protection of our legitimate interests
If you are in the EU, under GDPR Art. 6 the same bases apply:
Consent — Art. 6(1)(a)
- Marketing communications
- Cookies (analytics and marketing)
Contract Performance — Art. 6(1)(b)
- Parquet supply and related services
- Payment processing
- Warranty service
Legitimate Interest — Art. 6(1)(f)
- Service improvement
- Website security
- Basic analytics
- Direct marketing to existing customers
Legal Obligations — Art. 6(1)(c)
- Kazakhstan tax reporting
- Responding to lawful authority requests
6. Data Sharing
Service Providers (data processors):
| Category | Purpose |
|---|---|
| Email provider (Resend) | Sending notifications about inquiries |
| CRM (Bitrix24) | Tracking inquiries and customer history |
| Web analytics (Google Analytics, Yandex Metrika) | Analyzing website visits and behavior |
| Hosting and infrastructure (Hetzner, Cloudflare) | Hosting and DDoS protection |
| Logistics and delivery | Delivering parquet to project address |
| ESTA Parket (Estonia) | Forwarding the order to the manufacturing plant |
Team:
Your data may be processed by Parketiko employees and contractors located in Kazakhstan and other countries to provide services. All of them are bound by confidentiality obligations.
Other Recipients:
- Kazakhstan government authorities (upon lawful request — tax, courts)
- Professional advisors (lawyers, auditors)
- Authorized ESTA dealers (with your consent — for regional projects)
We carefully select service providers and enter into Data Processing Agreements with them. Specific tools may change, but processing categories remain the same.
7. Cross-Border Data Transfers
Your data may be transferred outside Kazakhstan:
| Country / Region | Transfer Purpose | Basis |
|---|---|---|
| Estonia (EU) | Forwarding ESTA Parket order for production | Contract + consent |
| USA | Cloud services (Google Analytics, Cloudflare, Resend) | Standard Contractual Clauses (SCCs) |
| Germany (EU) | Hosting (Hetzner) | Contract + GDPR adequacy |
| Russia | Yandex Metrika (optional) | Standard Contractual Clauses |
Under Kazakhstan Law No. 94-V cross-border transfer is allowed if the recipient country provides adequate protection of personal data, or with your consent.
Security Safeguards:
- Data Processing Agreements (DPAs) with each processor
- Standard Contractual Clauses (SCCs) for transfers to the USA and third countries
- Technical protection measures (HTTPS/TLS, encryption at the service level)
- Confidentiality obligations for all employees and contractors
8. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Customer contact data (active contracts) | Contract term + 5 years | Kazakhstan tax law |
| Data on inactive inquiries | 12 months from last contact | Legitimate interest |
| Marketing subscriptions | Until consent is withdrawn | Consent |
| Analytics data (GA, Yandex) | Up to 26 months | Legitimate interest |
| Cookies | Session to 1 year (see [Cookie Policy](/cookies)) | Consent / interest |
| Messenger correspondence | 3 years after last contact | Legitimate interest |
| Accounting data | 5 years | Tax Code of Kazakhstan |
After expiration, data is deleted or anonymized.
9. Your Rights
Under Kazakhstan Law No. 94-V you have the right to:
- Receive information about what data of yours we hold
- Request correction of inaccurate data
- Withdraw consent for processing
- Demand deletion (except where retention is required by law)
- File a complaint with the Authorized Body of the Republic of Kazakhstan for personal data protection
If you are in the EU, under GDPR additionally:
| Right | Description |
|---|---|
| Right of Access | Obtain a copy of your data |
| Right to Rectification | Correct inaccurate data |
| Right to Erasure | Delete data ("right to be forgotten") |
| Right to Restriction | Restrict data processing |
| Right to Portability | Receive data in machine-readable format |
| Right to Object | Object to processing |
| Right to Withdraw Consent | Withdraw consent at any time |
How to Exercise Rights:
- Email: denys.fursov@parketiko.com
- Response time: 30 business days (may be extended up to 2 months for complex requests)
- Free of charge (except for manifestly unfounded or repetitive requests)
11. Do Not Track and Global Privacy Control Signals
Do Not Track (DNT)
Some browsers send a "Do Not Track" signal. Currently, we do not respond to DNT signals as there is no uniform standard for processing them. Instead, we honor your choice via the cookie consent banner.
Global Privacy Control (GPC)
We honor Global Privacy Control signals. If your browser sends GPC, marketing cookies will not be activated automatically — this is equivalent to declining marketing cookies in the consent banner.
12. Messengers and Online Forms
Most communication with clients goes through messengers:
| Channel | What we process | Provider |
|---|---|---|
| Telegram (@denysparketiko) | Text messages, project photos | Telegram FZ-LLC |
| WhatsApp (+7 705 557 0189) | Text messages, voice, photos | Meta Platforms, Inc. |
| Bitrix24 widget | Name, phone, email, inquiry text | "Bitrix24" (Russia / Germany) |
| "Request price" form on site | Name, phone, email, area, comment | Stored with us + Resend for email |
Data processing in messengers is also governed by the platforms' policies. By using these channels, you agree to their terms.
To opt out of messages: write "STOP" in the messenger or email denys.fursov@parketiko.com.
13. Protection of Minors' Data
Our website and services are intended for designers, architects, and property owners — i.e., adults. We do not knowingly collect personal data from persons under 18.
If you learn that a minor has provided us with personal data, please contact us, and we will promptly delete this information.
14. AI Assistants and Automated Decisions
We may use AI tools and chatbots for:
- Initial inquiry qualification (project type, area, budget)
- Preparing commercial proposals
- Generating marketing content (blog articles, descriptions)
Important:
- Data you share with AI assistants is processed in accordance with this Policy
- AI-based decisions are not made fully automatically without human involvement in significant matters (prices, discounts, supply terms)
- You can request human review of any automated decision
- AI systems may make errors — the final calculation is always confirmed by a manager
15. Data Security
We implement technical and organizational measures to protect your data:
Technical Measures:
- Encryption in transit (HTTPS/TLS on parketiko.com)
- Encryption at rest (at the cloud provider level)
- Regular backups
- Security monitoring and DDoS protection (Cloudflare)
- Two-factor authentication in admin panels
Organizational Measures:
- Access restrictions (need-to-know basis)
- Staff training on data protection basics
- Internal security policy
- Regular access audits
Despite our efforts, no method of transmission over the internet is completely secure. In case of a data breach posing a high risk to your rights, we will notify you and the Authorized Body of Kazakhstan (or the relevant EU supervisory authority) within the required time.
16. Policy Changes
We may update this Policy. When making changes:
- We update the "Last updated" date at the top of the page
- For material changes, we notify subscribed clients via email
- We publish changes on this page
We recommend checking this page periodically. Continued use of the website after changes means acceptance of the updated Policy.
17. Contacts
For data protection inquiries, contact us:
Parketiko
| denys.fursov@parketiko.com | |
| Phone / WhatsApp | +7 705 557 0189 |
| Telegram | @denysparketiko |
| Address | Astana, Kazakhstan |
Response Time: up to 30 business days.
Supervisory Authorities:
- Kazakhstan: Ministry of Digital Development, Innovation and Aerospace Industry of the RK — gov.kz
- EU: list of GDPR supervisory authorities — edpb.europa.eu