Privacy Policy

Consent for Personal Data Processing

Last Updated: November 5, 2025

Your Data is Protected

GeneLab.kz guarantees the confidentiality and security of your medical data in accordance with the legislation of the Republic of Kazakhstan on the protection of personal data and medical confidentiality.

1. Basic Definitions

Site Administration — LLP "QazGene", authorized employees managing the genelab.kz website, who organize and carry out the processing of personal data.

Personal Data — any information relating to a directly or indirectly identified or identifiable natural person (personal data subject).

Medical Data — a special category of personal data, including results of genetic testing, analyses, consultations, and diagnoses.

Personal Data Processing — any action (operation) or set of actions (operations) performed with or without automation tools with personal data.

Personal Data Confidentiality — a requirement mandatory for the Site Administration not to allow their dissemination without the consent of the personal data subject or other legal basis.

Site User (User) — a person who has access to the Site via the Internet and uses the Site.

Cookies — a small piece of data sent by a web server and stored on the user's computer.

IP Address — a unique network address of a node in a computer network built on the IP protocol.

2. General Provisions

2.1. The User's use of the genelab.kz website means agreement with this Privacy Policy and the terms of processing the User's personal data.

2.2. In case of disagreement with the terms of the Privacy Policy, the User must stop using the site.

2.3. This Privacy Policy applies only to the genelab.kz website. The Site Administration does not control and is not responsible for third-party sites to which the User may navigate via links available on the genelab.kz site.

2.4. The Site Administration does not verify the accuracy of personal data provided by the Site User.

3. Legal Basis

Personal data processing is carried out in accordance with:

  • Law of the Republic of Kazakhstan "On Personal Data and their Protection" dated May 21, 2013 No. 94-V;
  • Law of the Republic of Kazakhstan "On Health Protection of Citizens" dated July 7, 2020 No. 360-VI;
  • Code of the Republic of Kazakhstan "On People's Health and Healthcare System" dated July 7, 2020 No. 360-VI;
  • Constitution of the Republic of Kazakhstan;
  • Other regulatory legal acts of the Republic of Kazakhstan.

4. Subject of the Privacy Policy

4.1. This Privacy Policy establishes the obligations of the Site Administration for non-disclosure and ensuring the protection of personal data confidentiality.

4.2. Personal data allowed for processing within this Privacy Policy is provided by the User by filling out the registration form on the Site in the "Registration" section and includes the following information:

  • Last name, first name, patronymic (if available);
  • Contact phone number;
  • Email address;
  • Date of birth;
  • City of residence;
  • IIN (Individual Identification Number) — optionally for identification;
  • Gender;
  • Medical data: genetic test results, doctor's conclusions, consultation history.

4.3. The Site protects data that is automatically transmitted when using the Site:

  • IP address;
  • Information from cookies;
  • Information about the browser (or other program used to access the Site);
  • Access time;
  • Address of the requested page;
  • Geolocation data.

4.4. Disabling cookies may result in the inability to access parts of the site requiring authorization.

4.5. The Site collects statistics about IP addresses of its visitors. This information is used to identify and solve technical problems, to control the legality of financial payments.

4.6. Any other personal information not specified above (purchase history, browsers used and operating systems, etc.) is subject to reliable storage and non-distribution, except in cases provided for in clauses 5.2 and 5.3 of this Privacy Policy.

5. Purposes of Collecting User Personal Information

5.1. The Site Administration may use the User's personal data for the purposes of:

  • Identifying the User registered on the Site for access to the personal account;
  • Providing the User with access to personalized Site resources;
  • Establishing feedback with the User, including sending notifications and requests;
  • Determining the User's location to ensure security and prevent fraud;
  • Confirming the accuracy and completeness of personal data provided by the User;
  • Providing medical consultations;
  • Processing and receiving payments;
  • Providing the User with effective customer and technical support;
  • Providing the User, with their consent, with product updates, special offers, price information, newsletters;
  • Carrying out advertising activities with the User's consent;
  • Providing the User access to partner websites or services to receive products, updates, and services.

5.2. The Site Administration has the right to send the User notifications about new products and services, special offers, and various events. The User can always refuse to receive informational messages by sending an email to r.nazarbekova@qazgene.kz with the note "Unsubscribe from notifications".

5.3. Anonymized User data collected through Internet statistics services serve to collect information about User actions on the site, improve the quality of the site and its content.

6. Methods and Terms of Personal Information Processing

6.1. Processing of the User's personal data is carried out without time limit, by any legal method, including in personal data information systems using automation tools or without such tools.

6.2. The User's personal data may be transferred to authorized state authorities of the Republic of Kazakhstan only on the grounds and in the manner established by the legislation of the Republic of Kazakhstan.

6.3. In case of loss or disclosure of personal data, the Site Administration informs the User about the loss or disclosure of personal data.

6.4. The Site Administration takes necessary organizational and technical measures to protect the User's personal information from unlawful or accidental access, destruction, modification, blocking, copying, distribution, as well as from other unlawful actions of third parties.

6.5. The Site Administration, together with the User, takes all necessary measures to prevent losses or other negative consequences caused by the loss or disclosure of the User's personal data.

7. User Rights and Obligations

7.1. The User has the right to:

  • Make a free decision about providing their personal data necessary for using the Site and consent to their processing;
  • Update, supplement the provided personal data information in case of changes;
  • Receive information from the Site Administration regarding the processing of their personal data;
  • Require the Site Administration to clarify their personal data, block or destroy it if the personal data is incomplete, outdated, inaccurate, illegally obtained, or not necessary for the stated processing purpose;
  • Withdraw consent for personal data processing;
  • Appeal to the authorized body for the protection of personal data subjects' rights or in court against unlawful actions or inactions when processing their personal data.

7.2. The User is obliged to:

  • Provide accurate information about themselves;
  • Update the provided personal data information in case of changes.

8. Transfer of Personal Data to Third Parties

8.1. The Site Administration does not transfer the User's personal data to third parties, except in the following cases:

  • The User has explicitly expressed their consent to such actions;
  • Transfer is necessary for the User to use a specific service or to provide a service to the User;
  • Transfer is provided by the legislation of the Republic of Kazakhstan within the procedure established by law;
  • Transfer to geneticists for providing medical consultations.

8.2. Medical data is transferred only to licensed physicians to provide professional consultations. All physicians sign a confidentiality agreement.

9. Features of Medical Data Processing

9.1. Medical data (genetic test results, analyses, consultations) belong to a special category of personal data and are subject to enhanced protection.

9.2. The Site Administration ensures:

  • Encryption of medical data during storage and transmission;
  • Limited access to medical data only to authorized persons;
  • Compliance with medical confidentiality in accordance with the legislation of the Republic of Kazakhstan;
  • Use of secure communication channels when transmitting medical information.

9.3. Genetic testing and consultation results are provided only to the User themselves and to physicians to whom the User has granted access.

10. Security Measures

10.1. The Site Administration applies the following security measures:

  • Use of SSL encryption to protect transmitted data;
  • Storage of passwords in hashed form;
  • Regular data backup;
  • Restriction of access to personal data based on a role model;
  • Monitoring of unauthorized access;
  • Regular updates of software and security systems.

11. Changes to the Privacy Policy

11.1. The Site Administration has the right to make changes to this Privacy Policy without the User's consent.

11.2. The new Privacy Policy comes into force from the moment of its posting on the Site, unless otherwise provided by the new edition of the Privacy Policy.

11.3. All suggestions or questions about this Privacy Policy should be sent to: r.nazarbekova@qazgene.kz

11.4. The current Privacy Policy is posted on the page at: https://genelab.kz/en/privacy-policy

12. Contact Information

Site Administration

Name: LLP "QazGene"

BIN: 210240031288

Legal Address: Republic of Kazakhstan, 010006, Astana city, Saryarka district, Sultanbuqa Aqan street, building 85/2

Phone: +7 771 088 2624

Email: r.nazarbekova@qazgene.kz

Website: https://genelab.kz