1Scope and who controls the data
This Privacy Policy applies to thekompetenz.com, our contact and enquiry channels, events, marketing, client onboarding and professional services. It covers personal data relating to website visitors, prospects, clients, insured persons, claimants, beneficiaries, counterparties, suppliers, applicants and business contacts.
For the Website and engagements where no other controller is expressly identified, the controller is LLP “Insurance Broker “Kompetenz”, BIN 220940002589, Licence No. 2.3.3 dated 08 April 2024, contactable at info@kompetenz.kz and Seifullin Street, Building 498, Almaty 050000, Kazakhstan. Where another Kompetenz entity determines why and how personal data is processed, that entity will be the controller for the relevant activity.
When we process data solely on documented instructions from a client, that client may be the controller and Kompetenz may act as processor or service provider. The applicable engagement documents govern that relationship.
2Categories of personal data
| Category | Examples | Typical context |
|---|---|---|
| Identity and contact | Name, employer, role, postal address, email, telephone, signature and preferred language. | Enquiries, contracts, policy administration and communications. |
| Business and insurance | Company ownership, assets, operations, exposures, policy details, risk surveys and loss history. | Advisory, placement, renewal and claims support. |
| Financial and transaction | Invoices, payment status, bank details, premium records, tax data and source-of-funds information. | Payments, compliance and accounting. |
| Compliance and verification | Identification documents, beneficial ownership, sanctions screening, regulatory status and fraud indicators. | Know-your-client, sanctions and financial-crime controls. |
| Claims and sensitive data | Incident information, health or injury data, employment details, litigation and other special-category data where necessary. | Employee benefits, liability, accident or claims services. |
| Technical and usage | IP address, device and browser data, timestamps, pages viewed, approximate location, cookie identifiers and security logs. | Website operation, security, analytics and fraud prevention. |
| Communications | Emails, call notes, meeting records, instructions, preferences, complaints and feedback. | Relationship management and evidence of instructions. |
| Recruitment | CV, qualifications, work history, interview notes and references. | Vacancies and talent management. |
We seek to avoid collecting sensitive data unless it is necessary, lawful and proportionate for a requested service or legal obligation. Please do not send unnecessary identity, health, payment or claims information through an open website form.
3Where data comes from
We collect data directly from individuals and organisations, and may also receive it from employers, policyholders, insureds, representatives, brokers, insurers, reinsurers, claims handlers, experts, public authorities, sanctions and company registries, professional databases, publicly available sources and technology providers.
If you provide data about another person, you confirm that you are authorised to do so and have delivered any notice or obtained any consent required by law. We may give this Policy to that person or ask you to do so.
4Purposes and legal bases
| Purpose | Data used | Legal basis where required |
|---|---|---|
| Respond to enquiries and prepare proposals | Identity, contact, business and communications data. | Steps requested before a contract; legitimate interests; consent where required. |
| Deliver brokerage, advisory and claims support | Business, insurance, financial, claims and communications data. | Contract; legitimate interests; legal obligation; substantial public interest or explicit consent for sensitive data where applicable. |
| Compliance, screening and fraud prevention | Identity, ownership, financial, technical and verification data. | Legal obligation; public interest; legitimate interests. |
| Payments, accounting and records | Transaction, contact and contract data. | Contract; legal obligation; legitimate interests. |
| Operate, secure and improve the website | Technical, usage and communications data. | Legitimate interests; consent for non-essential cookies where required. |
| Relationship and service communications | Contact, preferences and engagement data. | Contract; legitimate interests. |
| Marketing and events | Contact, role, interests and engagement data. | Consent where required; otherwise legitimate interests, with opt-out. |
| Legal claims, audits and corporate transactions | Relevant categories necessary for the matter. | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims. |
Where we rely on legitimate interests, we consider necessity, proportionality and the reasonable expectations and rights of individuals. Where consent is the legal basis, it may be withdrawn prospectively without affecting prior lawful processing.
5Cookies, analytics and online technologies
Our website may use strictly necessary cookies for security, language, forms and session management, and optional analytics or functionality technologies where configured. Embedded maps, videos, fonts or similar third-party features may receive technical data when loaded.
Where required, optional cookies are activated only after consent. You may use the available cookie controls and browser settings to withdraw or change choices. Blocking necessary cookies may affect functionality. We do not respond to every browser “Do Not Track” signal because no single standard applies globally, but we will honour legally recognised opt-out preference signals where required and technically supported.
Kompetenz does not intend to sell personal data for monetary consideration. If a disclosure involving advertising technology is treated as a “sale”, “sharing” or targeted advertising under applicable law, eligible individuals may request an opt-out by contacting us. We do not knowingly sell or share data of children.
6Who may receive data
We disclose data only where reasonably necessary and lawful, including to:
- Kompetenz affiliates, offices and authorised personnel;
- insurers, reinsurers, underwriting agencies, brokers, co-brokers and insurance-market participants;
- claims administrators, loss adjusters, surveyors, medical or technical experts and legal advisers;
- cloud, hosting, security, communications, CRM, analytics, document and payment providers;
- auditors, accountants, banks and professional advisers;
- regulators, law enforcement, courts, sanctions authorities and public bodies;
- potential counterparties in a merger, financing, reorganisation or sale, subject to safeguards; and
- other parties authorised by the individual or organisation concerned.
Service providers are expected to process data under appropriate confidentiality, security and purpose restrictions. We remain accountable where required by law, but cannot control an independent controller’s lawful processing.
7International data transfers
Insurance and reinsurance are international. Data may be accessed or processed in Kazakhstan and in countries where Kompetenz, Markets or service providers operate. Those countries may have different privacy laws.
Where transfer restrictions apply, we use a lawful mechanism appropriate to the circumstances, such as an adequacy decision, standard contractual clauses, contractual and organisational safeguards, consent where valid, or a necessity permitted by law. Additional safeguards may include access controls, encryption, data minimisation and transfer risk assessment.
8How long data is retained
We retain data only as long as reasonably necessary for the stated purposes, legal and regulatory obligations, dispute defence, fraud prevention and legitimate business records. Actual periods depend on jurisdiction and engagement.
| Record type | Indicative period | Reason |
|---|---|---|
| Enquiries not resulting in engagement | Up to 24 months after last meaningful contact. | Follow-up, service history and dispute evidence. |
| Client, policy, treaty and claims records | Engagement term plus 7–10 years, or longer where claims, limitation periods or regulation require. | Contract, compliance, professional and evidentiary duties. |
| Compliance and screening records | Generally 5–10 years after relationship end, subject to law. | Financial-crime and regulatory requirements. |
| Marketing preferences | Until opt-out, plus a suppression record. | Respect communication choices. |
| Security logs | Typically 6–24 months unless investigation requires longer. | Security, resilience and fraud prevention. |
| Recruitment records | Usually 12–24 months unless hired or a longer period is agreed. | Recruitment administration and defence of claims. |
At the end of retention, data is deleted, anonymised or securely isolated unless continued retention is required by law.
9Security and incident management
We use risk-based legal, organisational and technical safeguards designed to protect confidentiality, integrity and availability. Measures may include role-based access, least privilege, authentication, encryption in transit where supported, backups, logging, supplier review, staff confidentiality, awareness and incident response.
No system is completely secure. Individuals should use appropriate precautions and avoid sending highly sensitive data through insecure channels. If an incident creates a notification obligation, we will notify the competent authority, affected clients or individuals as required by applicable law.
10Your privacy rights
Depending on applicable law, you may have rights to:
Know and access
Confirm processing and obtain information or a copy of personal data.
Correct
Update inaccurate or incomplete information.
Delete or restrict
Request deletion, blocking or limited use where legal conditions are met.
Object or opt out
Object to certain legitimate-interest processing or opt out of marketing, sale, sharing or targeted advertising where applicable.
Portability
Receive certain data in a structured format where the law provides.
Withdraw consent
Withdraw consent prospectively when processing depends on consent.
Submit a request to info@kompetenz.kz and state your relationship with Kompetenz, jurisdiction and requested action. We may verify identity and authority, clarify scope, refuse manifestly unfounded or excessive requests, and retain data required for legal obligations or claims. We will not unlawfully discriminate against a person for exercising privacy rights.
11Regional information
Kazakhstan
Where Kazakhstan law applies, individuals may request information about processing, correction, blocking or destruction of unlawfully processed data, withdraw consent where permitted, and protect their rights before the authorised body or courts. Processing and cross-border transfer will be based on consent or another lawful basis recognised by applicable law.
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, the relevant Kompetenz entity acts as controller or processor as stated above. Individuals may also object to direct marketing, lodge a complaint with their local supervisory authority and exercise rights subject to statutory conditions. A representative or data protection officer will be identified where legally required.
California and other U.S. states
Where an applicable state privacy law covers Kompetenz, eligible residents may request access, correction, deletion or a copy, and may opt out of sale, sharing, targeted advertising or certain profiling. Authorised agents may submit requests subject to verification. Categories collected and disclosed are described in Sections 2 and 6; we do not use sensitive data to infer characteristics except as necessary for requested insurance or legal purposes.
Regional rights apply only when the relevant law covers the person, entity and processing activity. Exceptions and verification rules may apply.
12Automated processing and profiling
We may use rules, analytics or risk indicators to prioritise enquiries, support fraud and sanctions screening, evaluate risk information or assist professional judgment. Unless separately disclosed, we do not make decisions producing legal or similarly significant effects solely by automated means.
Where applicable law grants a right concerning automated decisions, you may request meaningful information, express a view, object where permitted and seek human review.
13Children and vulnerable individuals
The website and business services are not directed to children. We do not knowingly collect children’s data through general marketing or enquiry forms. Insurance and claims services may require data about dependants, beneficiaries or injured minors; in that case we process only data reasonably necessary and rely on an appropriate legal basis, representative or guardian process.
14Third-party sites and services
Links, embedded maps and third-party services are governed by their own privacy practices. Kompetenz is not responsible for independent sites or providers. Review their notices before providing data. A link does not imply endorsement or make us controller of the third party’s processing.
15Changes, questions and complaints
We may update this Policy to reflect legal, technical or business changes. The effective date and version appear at the top. Material changes may be highlighted on the website or communicated through appropriate channels.
Please contact us first so we can investigate a concern. You may also complain to the privacy or data-protection authority with jurisdiction over you. Nothing in this Policy limits mandatory statutory remedies.
Privacy contact
Licence No. 2.3.3 dated 08 April 2024
Seifullin Street, Building 498, Almaty 050000, Kazakhstan
Please do not include unnecessary identity documents or sensitive claim information in an initial email. We will explain any secure verification steps required.