What personal data we collect, why, who it is disclosed to, where it is hosted, and the rights a data subject can exercise.
This summary is provided for convenience only. It does not form part of this Policy and creates no rights or obligations. In the event of any inconsistency between this summary and the clauses below, the clauses prevail.
1.1. This Policy governs the processing of personal data by the legal entity registered in the Republic of Uzbekistan which operates the website and provides the services described on it (the "Operator").
1.2. This Policy applies to visitors to the website, to persons who submit enquiries, to clients, and to the shareholders, directors, representatives and beneficial owners of clients (each a "Data Subject").
1.3. "Personal Data", "processing", "owner" and "operator" have the meanings given in the Law of the Republic of Uzbekistan "On Personal Data" No. ЗРУ-547 of 2 July 2019, as amended (the "Personal Data Law").
1.4. The Operator is the owner and operator of the personal data database within the meaning of the Personal Data Law and determines the purposes and means of processing.
1.5. The Operator has appointed an individual responsible for the processing and protection of personal data. Requests to that individual shall be addressed to oi@jurishq.io.
2.1. Website visitors. IP address, device and browser characteristics, pages accessed, referring source, and any data submitted through a form on the website, including name, electronic mail address, country and the content of the enquiry.
2.2. Clients and prospective clients.
2.2.1. identity data: passport data, and where applicable the personal identification number (PINFL);
2.2.2. contact data: electronic mail address, telephone number and postal address;
2.2.3. corporate data: proposed company name, intended activity, charter capital, ownership structure, and the identity of shareholders, directors and beneficial owners;
2.2.4. foreign documents: certificates of incorporation, registry extracts, powers of attorney, and translations and legalisations thereof;
2.2.5. compliance data: information required to satisfy obligations on countering money laundering, including source of funds where applicable;
2.2.6. financial data: accounting records and transaction data, where bookkeeping services are provided; and
2.2.7. correspondence between the Data Subject and the Operator.
2.3. The Operator does not process biometric data, genetic data, data concerning health, or data revealing political or religious views. Where a stage of a statutory procedure requires biometric enrolment, that enrolment is performed by the competent state authority and the biometric data is not transferred to the Operator.
2.4. The Operator does not process payment card data.
3.1. The Operator processes Personal Data on the following bases:
| Purpose | Basis |
|---|---|
| Responding to an enquiry and preparing a quotation | Measures preceding conclusion of a contract, at the request of the Data Subject |
| Registration of the company and filing of documents | Performance of the contract |
| Obtaining taxpayer identification numbers, personal identification numbers and electronic digital signatures | Performance of the contract |
| Bookkeeping and filing of tax and statutory returns | Performance of the contract; compliance with a legal obligation |
| Identity, beneficial ownership and source-of-funds verification | Compliance with a legal obligation |
| Retention of records after termination | Compliance with a legal obligation |
| Service communications relating to the engagement | Performance of the contract |
| Marketing communications | Consent |
| Measurement of website use | Consent, where required |
| Establishment, exercise or defence of legal claims | Legitimate interests of the Operator |
3.2. Where processing is based on consent, the Data Subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect processing carried out on any other basis.
3.3. The Operator shall not process Personal Data for a purpose other than that previously notified without establishing a lawful basis for that purpose.
3.4. The volume and character of the Personal Data processed shall correspond to the purposes and means of processing.
4.1. The Operator does not sell Personal Data and does not disclose Personal Data for the marketing purposes of any third party.
4.2. The Operator discloses Personal Data to the following categories of recipient:
4.2.1. state authorities of the Republic of Uzbekistan, including the state business registry and the tax authorities, where required for registration, filing or compliance;
4.2.2. banks and other financial institutions, where the Data Subject has requested assistance with the opening or operation of an account;
4.2.3. notaries, translators and legalisation authorities, where required for the validity of a document;
4.2.4. suppliers who process Personal Data on behalf of the Operator for the purposes of hosting, database services, file storage, electronic mail delivery, error monitoring and website analytics;
4.2.5. professional advisers, auditors and insurers; and
4.2.6. courts, law enforcement authorities and other competent bodies, where required by law.
4.3. Suppliers under clause 4.2.4 process Personal Data solely on the documented instructions of the Operator, under written contracts which prohibit processing for the supplier's own purposes, impose security obligations, regulate the engagement of sub-processors, and require deletion or return of the data upon termination. Each supplier receives only the data necessary for its function.
4.4. The Operator shall identify a specific supplier to a Data Subject on request made in connection with the exercise of a right under clause 8 or the assessment of a prospective engagement.
4.5. Where the Operator receives a request from a competent authority for the disclosure of Personal Data, it shall notify the Data Subject unless prohibited from doing so by law.
5.1. The Operator's systems are hosted with suppliers whose primary hosting region is located within the European Union. Certain suppliers and sub-suppliers operate outside the Republic of Uzbekistan and outside the European Union.
5.2. Article 27-1 of the Personal Data Law, as amended by Law No. ЗРУ-1125 of 26 March 2026, requires storage within the Republic of Uzbekistan of biometric data, genetic data, and data of subscribers of telecommunications operators. The Operator does not process data falling within those categories.
5.3. Personal Data not falling within the categories referred to in clause 5.2 may be stored and processed outside the Republic of Uzbekistan where one of the conditions in Article 27-1 is satisfied. The Operator relies upon the application and observance of contractual data protection terms with each supplier which processes Personal Data on its behalf, meeting the requirements of the authorised state body.
5.4. The Operator shall make available the substance of the contractual protections referred to in clause 5.3 on request.
6.1. Personal Data is retained for the following periods:
| Category | Retention period |
|---|---|
| Enquiries which did not result in an engagement | 12 months from the date of the enquiry |
| Client files and identity documents | Duration of the engagement, plus the minimum period required by legislation on countering money laundering |
| Accounting and tax records | The minimum period required by accounting and tax legislation |
| Correspondence relating to an engagement | 5 years from termination of the engagement |
| Marketing contact data | Until withdrawal of consent |
| Website technical logs | 12 months |
6.2. Upon expiry of the applicable retention period, Personal Data is destroyed or irreversibly anonymised.
6.3. Personal Data is destroyed upon achievement of the purpose of processing, withdrawal of consent, expiry of the period of processing, or entry into force of a court decision requiring destruction, subject to clause 6.4.
6.4. Where legislation prescribes a minimum retention period, the Operator shall not destroy the Personal Data before expiry of that period notwithstanding a request by the Data Subject. The Operator shall notify the Data Subject of the applicable provision and the date of expiry.
7.1. The Operator applies organisational and technical measures to protect Personal Data, determined by reference to the assessed level of protection required, in accordance with the Personal Data Law and Resolution of the Cabinet of Ministers No. 570 of 5 October 2022.
7.2. Those measures include:
7.2.1. role-based access, restricted to the performance of professional, official or employment duties;
7.2.2. storage of client documents in non-public storage, access to which is granted only by links expiring within 60 seconds;
7.2.3. isolation of client data at database record level;
7.2.4. encryption of Personal Data in transit and at rest;
7.2.5. multi-factor authentication for administrative access;
7.2.6. logging of access and of data exports;
7.2.7. encryption of backup copies;
7.2.8. contractual security obligations imposed on suppliers; and
7.2.9. an incident response procedure.
7.3. Where a breach of security affecting Personal Data occurs, the Operator shall notify the affected Data Subjects and the competent authority, describe the nature of the breach and the measures taken, and specify the steps recommended to the Data Subject.
8.1. In accordance with Article 30 of the Personal Data Law, a Data Subject has the right to:
8.1.1. know whether the Operator processes Personal Data relating to them, and what data is processed;
8.1.2. obtain information as to the purposes, methods and duration of processing and the categories of recipient;
8.1.3. require the correction or completion of Personal Data which is inaccurate, incomplete or out of date;
8.1.4. require the temporary suspension of processing where the Personal Data is incomplete, out of date, inaccurate, unlawfully obtained, or no longer necessary for the purposes of processing;
8.1.5. withdraw consent, where processing is based on consent;
8.1.6. require the destruction of Personal Data, subject to clause 6.4; and
8.1.7. apply to the authorised state body or to the courts.
8.2. Requests shall be submitted to oi@jurishq.io. The Operator shall verify the identity of the applicant before responding.
8.3. The Operator shall effect correction or completion under clause 8.1.3 within 3 days of receipt of the request, as required by the Personal Data Law. Other requests shall be answered within 10 working days.
8.4. No fee is charged for the exercise of a right under this clause.
8.5. Where the Operator refuses a request, it shall state the grounds for refusal and the means of challenging it.
9.1. Upon inclusion of Personal Data in a database, the Operator shall notify the Data Subject in writing of the purposes of processing and of the rights set out in clause 8, in accordance with the Personal Data Law.
10.1. The website uses cookies which are strictly necessary for its operation, including for authentication, session continuity and protection against abuse. Such cookies are not subject to consent.
10.2. The website uses analytics cookies for the purpose of measuring use of the website. Such cookies are set only with the consent of the visitor, which may be withdrawn at any time.
10.3. The Operator does not use advertising trackers and does not disclose audience data to third parties.
11.1. The services are intended for persons of full legal capacity. The Operator does not knowingly process Personal Data relating to persons under 18 years of age.
11.2. Where a document submitted to the Operator contains Personal Data relating to a minor, the Data Subject shall notify the Operator, and the Operator shall redact such data unless its retention is required for a statutory filing.
12.1. The Operator does not take decisions producing legal effects in respect of a Data Subject by automated means alone. Calculation of prices and generation of document checklists are performed automatically; the decision whether to accept an engagement and on what terms is taken by an individual.
13.1. The Operator may amend this Policy. The current version, with its effective date, is published on the website.
13.2. Where an amendment materially affects the processing of Personal Data already held, the Operator shall notify affected Data Subjects by electronic mail not less than 30 calendar days before the amendment takes effect.
13.3. The Operator shall retain previous versions and shall provide the version applicable at a given date on request.
14.1. Requests and complaints shall be addressed to oi@jurishq.io or, where a physical copy is required, to Tashkent, Oltintepa street 260, Republic of Uzbekistan.
14.2. A Data Subject may at any time apply to the authorised state body for the protection of personal data of the Republic of Uzbekistan, or bring proceedings before the courts. Submission of a complaint to the Operator does not affect those rights.
14.3. This Policy is governed by the law of the Republic of Uzbekistan and is published in the English language. Any translation is provided for information only.
The public offer for the provision of services — what we undertake to do, what we do not control, how fees are earned, and how the agreement ends.
When a fee is refundable and when it stops being refundable, how recurring services are cancelled, and how a refund is paid.
Questions about any of this go to oi@jurishq.io — a written claim is answered within 15 calendar days.