All documents

Privacy policy

Privacy Policy outlines our strict commitment to you, detailing exactly how your personal data is transparently collected, securely stored, and fiercely protected.

upd. 01.09.2026DIGITAL NETWORK SYSTEMS, TOO · DUNS: 373896210

SECTION 1

Who we are

DIGITAL NETWORK SYSTEMS, TOO («DigitalNS», «we», «us») is the operator and controller of the personal data described in this policy. We are registered as a limited liability partnership and identified by DUNS number 373896210.

We supply network monitoring, maintenance planning, alerting and analytics services to business and consumer customers across Asian and European markets. This policy explains what personal data we process when you use our website, contact us, or use our platform, and what rights you have over that data.

For any question about this policy, or to exercise your rights, write to [email protected]. We respond to data subject requests within 30 days.

SECTION 2

Data we collect

We collect only the data we need to operate and secure the service. We never sell personal data.

  • Identity and contact data — name, company name, job title, business email address and telephone number, provided when you contact us or open an account.
  • Account and billing data — login identifiers, hashed credentials, subscription plan, invoices and payment references. We do not store full card numbers; payments are handled by our payment processors.
  • Service telemetry — IP addresses, hostnames, device identifiers, interface names, configuration snapshots, event logs and alert history belonging to the infrastructure you connect to the platform.
  • Support data — the content of tickets, emails and attachments you send us, and our replies.
  • Technical and usage data — browser type and version, operating system, referring page, pages viewed, timestamps and approximate location derived from IP address.

We do not knowingly collect special categories of personal data (health, biometric, political or religious data) and ask that you do not submit them to us.

SECTION 3

Why we process your data and on what basis

Where the GDPR applies, we rely on the following legal bases. Where the law of the Republic of Kazakhstan or another local data protection law applies, we rely on the equivalent lawful ground.

  • Performance of a contract — to create and administer your account, deliver monitoring and maintenance features, generate alerts and reports, and provide support.
  • Legitimate interests — to keep the service secure and available, prevent abuse and fraud, debug faults, measure aggregate product usage, and improve our features. We balance these interests against your rights and stop where your rights prevail.
  • Consent — for optional analytics cookies and marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal obligation — to retain accounting records, respond to lawful requests from authorities, and meet tax and corporate reporting duties.

SECTION 4

Cookies and similar technologies

Our website uses a small number of cookies and equivalent local storage entries:

  • Strictly necessary — session, authentication, load-balancing and CSRF-protection cookies. These cannot be switched off without breaking the site.
  • Preference — remembering your language and interface choices.
  • Analytics — aggregate, IP-truncated statistics on how pages are used. Set only with your consent.

You can clear or block cookies through your browser settings, and you can withdraw analytics consent at any time. Blocking strictly necessary cookies may prevent you from signing in.

SECTION 5

Sharing and disclosure

We disclose personal data only to the following categories of recipients, and only under a written agreement that restricts their use of the data to our instructions:

  • Infrastructure providers — hosting, storage, content delivery and backup providers operating our production environment.
  • Operational tools — error tracking, product analytics, email delivery, ticketing and billing providers.
  • Professional advisers — auditors, accountants and lawyers, where necessary and under duties of confidentiality.
  • Authorities — where disclosure is required by a binding legal order. We review every request and challenge those that are overbroad.
  • Successors — an acquirer in the context of a merger, reorganisation or sale of assets, subject to this policy continuing to apply.

SECTION 6

International transfers

Because we serve customers in Asia and Europe, personal data may be processed in countries other than your own, including outside the European Economic Area and outside the Republic of Kazakhstan.

Where we transfer personal data out of the EEA to a country without an adequacy decision, we use the European Commission’s Standard Contractual Clauses together with a transfer risk assessment and, when appropriate, supplementary technical measures such as encryption in transit and at rest. Cross-border transfers from Kazakhstan are made only to jurisdictions that provide an adequate level of protection or on the basis of your consent, as required by the Law on Personal Data and its Protection.

You may request a copy of the relevant transfer safeguards by contacting [email protected].

SECTION 7

Retention

We keep personal data only as long as it serves the purpose it was collected for:

  • Account data — for the life of the account and 12 months after closure, to allow reactivation and dispute resolution.
  • Service telemetry and event logs — up to 13 months, unless a longer retention window is configured by you in the platform.
  • Security and audit logs — up to 24 months.
  • Invoices and accounting records — for the statutory period applicable to us, currently 5 years.
  • Support correspondence — 24 months after the ticket is closed.

At the end of the retention period data is deleted or irreversibly anonymised. Backups are rotated on a rolling schedule and expire within 90 days.

SECTION 8

Security

We apply technical and organisational measures proportionate to the risk, including TLS 1.2+ for data in transit, encryption at rest for databases and backups, role-based access control with least privilege, mandatory multi-factor authentication for administrative access, centralised audit logging, network segmentation, dependency and vulnerability scanning, and periodic restore testing.

Staff access to customer data is limited to personnel who need it to deliver support or operate the platform, is logged, and is subject to confidentiality obligations. If a personal data breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform affected data subjects without undue delay.

No system is perfectly secure. Please report suspected vulnerabilities to [email protected]; we do not pursue good-faith security research.

SECTION 9

Your rights

Subject to the law that applies to you, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate or incomplete data corrected;
  • have your data erased where it is no longer necessary, where you withdraw consent, or where you successfully object;
  • restrict processing while a dispute or accuracy check is open;
  • receive your data in a structured, machine-readable format and have it transmitted to another controller;
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • withdraw consent at any time, and not be subject to solely automated decisions producing legal effects;
  • lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

To exercise any right, email [email protected] from the address associated with your account. We may ask for additional information to verify your identity. Requests are answered within 30 days; complex requests may be extended once, and we will tell you if that happens.

SECTION 10

Data of customers' end users

When you connect infrastructure to the platform, you act as the controller of any personal data contained in the telemetry you send us, and we act as your processor. In that role we process the data only on your documented instructions, assist you with data subject requests and security obligations, use approved sub-processors under equivalent terms, and delete or return the data at the end of the engagement.

A data processing agreement is available on request and forms part of our contract with business customers.

SECTION 11

Children

The service is intended for business use and for adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

SECTION 12

Changes to this policy

We may update this policy to reflect changes in our services or in the law. The revision date is shown at the top of this page. When a change materially affects your rights we notify you by email or by an in-product notice at least 30 days before it takes effect. Continuing to use the service after that date means you accept the updated policy.

SECTION 13

Contact and complaints

Operator: DIGITAL NETWORK SYSTEMS, TOO, DUNS 373896210.

We are available 24/7 for security incidents. Non-urgent requests are handled during business hours and answered within 30 days.

Questions about documents

Inquiries regarding the processing of personal data, withdrawal of consent, and requests from data subjects. A response will be provided within 30 days.

[email protected]

We are available 24/7

Contact support

AGREEMENT

Terms of service

Terms of Service establish the rules of engagement, ensuring you understand your rights, acceptable use, and responsibilities while navigating our platform.

Read