Kazimir — Privacy Policy

Last updated: 2026-01-01
Version: 1.0

1. Who is responsible for your data

The controller of your personal data is Rao Tech Ltd, a company registered in England and Wales under company number 13457335.

- Contact for privacy matters: info@rao-tech-ltd.com
- Representative in the European Union (Article 27 GDPR): Flat 3 Halcyon 65-71 Ashbourne Road, Derby, England, DE22 3FS.

The Kazimir platform is operated together with Individual Entrepreneur Angelina Smirnova, which hosts the platform servers. Where both entities jointly determine the purposes and means of processing, they act as joint controllers within the meaning of Article 26 GDPR, and the essence of their arrangement is available on request at info@rao-tech-ltd.com. Whichever entity you contact, you may exercise your rights in full against either of them.

This policy explains what personal data the Kazimir mobile application (the "App") collects, why, on what legal basis, who receives it, how long we keep it and what rights you have.

2. Definitions

Personal data — any information relating to an identified or identifiable natural person. Processing — any operation performed on personal data. Data subject — you, the user of the App. Controller and processor have the meanings given in the GDPR. Space Owner and Renter are defined in the https://kazimir-carplace.ru/terms_en.

3. Categories of personal data we process

Account data - Mobile phone number; the interface language you choose. You, at registration |
Profile data - Your Balance, the residential complex you selected, the list of your parking spaces. You and your use of the App.
Parking space data - Address, building/section, location on the map and description of a space you list. You, as a Space Owner.
Booking and transaction data - Bookings, rental periods, amounts, platform fee, refunds, penalties. Generated by your use of the App.
Payout data - The bank you select for payouts and the phone number used for instant transfers. You, when requesting a payout.
Communications - Messages you exchange in the in-app chat with other Users and with support, including photos you attach.
Technical data - Device identifier sent by the App, IP address, app version, operating system, push notification token. Automatically, when you use the App

What we do NOT collect:

- We do not collect your device location. The App does not request location permission and contains no location-tracking component. Map screens show the position of residential complexes and parking spaces, not your position.
- We do not see your card details. Payments are made on the pages of our Payment Provider, opened in a secure in-app browser window; card numbers never reach the App or our servers.
- We do not process special categories of data (health, biometrics, political opinions and similar), and we do not carry out profiling or advertising tracking.

4. Why we process your data and on what legal basis

| Purpose | Data used | Legal basis |
| --- | --- | --- |
| Creating and maintaining your account; signing you in with an SMS code | Account data, technical data | Article 6(1)(b) — performance of a contract |
| Publishing listings, matching Space Owners and Renters, managing Bookings | Profile, parking space, booking data | Article 6(1)(b) — performance of a contract |
| Processing payments, crediting balances, making payouts, issuing refunds | Booking, transaction and payout data | Article 6(1)(b) — performance of a contract |
| Enabling communication between Users and with support | Communications | Article 6(1)(b) — performance of a contract |
| Sending push notifications about your bookings and messages | Push token, technical data | Article 6(1)(a) — your consent, given in the operating system permission prompt; you may withdraw it at any time in the device settings |
| Keeping accounting, tax and anti-money-laundering records | Transaction and payout data | Article 6(1)(c) — legal obligation |
| Preventing fraud and abuse, investigating incidents, ensuring the security of the App | Technical data, booking data, communications | Article 6(1)(f) — our legitimate interest in a safe and trustworthy marketplace |
| Handling complaints, defending and bringing legal claims | Any of the above, as relevant | Article 6(1)(f) — our legitimate interest in establishing and defending claims |

Where we rely on legitimate interests, we have assessed that our interest is
not overridden by your rights and freedoms. You may object at any time
(section 10).

5. Providing your data is a contractual requirement

Providing your phone number is necessary to create an account and to use the
App: without it we cannot identify you or conclude a contract. Providing
payout details is necessary only if you wish to receive payouts. Push
notifications are optional and the App works without them.

6. Who receives your data

We do not sell your personal data and we do not share it for advertising.

We disclose data to the following categories of recipients:

| Recipient | Purpose | Role |
| --- | --- | --- |
| Other Users of the App | A Space Owner and a Renter who have a common Booking see each other's chat messages and the information needed to complete the rental (contact details as displayed in the App, access instructions for the space) | Independent controller |
| The Payment Provider | Processing card and instant-transfer payments, issuing refunds | Independent controller |
| The SMS provider | Delivering one-time sign-in codes | Processor |
| Google Ireland Ltd / Google LLC (Firebase Cloud Messaging) | Delivering push notifications | Processor |
| Yandex (MapKit) | Displaying maps and geocoding of complex and parking-space addresses | Independent controller |
| Hosting and infrastructure provider | Operating our servers | Processor |
| Professional advisers, auditors | Legal and accounting support | Processor / independent controller |
| Public authorities and courts | Where required by law | Independent controller |

We conclude data processing agreements meeting the requirements of Article 28
GDPR with all our processors.

7. Retention

| Data | Retention period |
| --- | --- |
| Account and profile data | For as long as your account exists |
| Booking, transaction and payout records | 6 years after the end of the financial year in which the transaction took place (accounting and tax obligations) |
| In-app chat messages and attached photos | For as long as your account exists, and up to 12 months after deletion where needed to resolve an open dispute |
| Push notification token | Until you sign out, disable notifications or delete the account |
| Technical logs | 12 months |
| Records relating to a complaint or legal claim | Until the claim is finally resolved and any limitation period has expired |

When a retention period ends, we delete the data or irreversibly anonymise it.

8. Where your data is processed and international transfers

The App's servers are located in the Russian Federation. The United Kingdom and the European Commission have not issued an adequacy decision in respect of the Russian Federation.

Transfers of personal data from the UK/EEA to our servers therefore take place on the basis of standard contractual clauses approved by the European Commission (and the UK International Data Transfer Addendum), as provided for by Article 46 GDPR, supported by a transfer impact assessment and by technical measures including encryption in transit and encrypted storage on your device.

You may request a copy of the safeguards we rely on by writing to info@rao-tech-ltd.com. Push notification delivery may additionally involve transfers to the United States under Google's own transfer mechanisms.

9. How we protect your data

- All traffic between the App and our servers uses TLS; the App additionally
pins the server certificate.
- Authentication tokens and other sensitive values are stored on your device in
encrypted storage backed by the Android Keystore / iOS Keychain.
- Access to production data inside our organisation is limited to a defined
group of staff who need it for their duties and who are bound by
confidentiality.
- Card data is handled exclusively by our PCI DSS-compliant Payment Provider.

10. Your rights

Under the GDPR you have the right to:

- be informed about how we use your data — this policy;
- access your data and obtain a copy of it;
- rectification of inaccurate or incomplete data;
- erasure ("right to be forgotten"), including by deleting your account in
the App (Profile → Delete account), subject to records we must keep by
law;
- restriction of processing in the cases set out in Article 18 GDPR;
- data portability — to receive the data you provided in a structured,
commonly used, machine-readable format;
- object to processing based on our legitimate interests, on grounds
relating to your particular situation;
- withdraw consent at any time where processing is based on consent (for
example, push notifications) — this does not affect the lawfulness of
processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing — we
do not take such decisions (section 11).

To exercise any of these rights, write to info@rao-tech-ltd.com. We respond within one month; where a request is complex we may extend this by a further two months and will tell you why.

Complaints. If you believe we have handled your data unlawfully you may complain to a pervisory authority: in the United Kingdom, the Information Commissioner's Office (ICO, https://ico.org.uk); in the EEA, the supervisory authority of the country where you live or work, or where the alleged infringement took place.

11. Automated decision-making

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not carry out profiling.

12. Children

The App is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to info@rao-tech-ltd.com and we will delete it.

13. The App on your device

The App asks for the following permissions, each only when the corresponding
feature is used:

| Permission | Why | If you decline |
| --- | --- | --- |
| Photo library | To attach a photo to a message in the in-app chat | You can still use the chat, without photo attachments |
| Notifications | To inform you about bookings, messages and payouts | The App works normally; you check updates by opening it |

The App stores on your device: the authentication token, your interface
language, the residential complex you selected and a cache of reference data
(cities, complexes). This data is stored in encrypted form and is removed when
you sign out or delete the App.

The App does not use advertising identifiers, analytics SDKs or
cross-app tracking.

14. Changes to this policy

We may update this policy. The current version is always available in the App (Profile → Privacy Policy) and at https://kazimir-carplace.ru/privacy_en, with the date of the last update at the top. Where a change materially affects you, we will notify you in the App before it takes effect.

15. Contact

Questions about this policy or about how we handle your data:

- Email: info@rao-tech-ltd.com
- Postal address: Rao Tech Ltd, Flat 3 Halcyon 65-71 Ashbourne Road, Derby, England, DE22 3FS