Legal document

Privacy Policy

What data the portal collects, why, how long it stores it and to whom it transfers it.

Sections

10

Effective from

10 February 2026

Text last changed

22 September 2026

Questions about the document

mail@medgid.kz

Document sections

  1. 01

    What data is collected

    This privacy policy, as revised on 10.02.2026, describes what information the MEDGID portal, available at https://medgid.kz, receives from the user, how it processes it, to whom it transfers it and how long it stores it. The policy applies to all sections of the portal: the catalogue of doctors and clinics, the appointment booking form, the patient's personal account, the review form and the enquiry form.

    The portal receives data only when the user provides it themselves by filling in one of the forms. The portal does not carry out hidden collection of information about the user. The composition of the data is determined by the action the user performs: — when booking an appointment — name, phone number, email address, the selected doctor, clinic, service, date and time of the appointment, as well as a comment that the user writes in their own words; — when logging into the personal account — email address and a one-time confirmation code, as well as name, message language, a note of consent to data processing and the list of cards added to favourites; — when publishing a review — the text of the review, ratings on five parameters, notes on what was liked and what was not liked, the date of the appointment, the author's signature and an irreversible fingerprint of the confirmed contact; — when contacting the portal's editorial team — name, contact details and the text of the enquiry; — when using search — the search query string, which is stored separately and is not linked to either the user or their contacts.

    The portal does not request or store medical information. Diagnoses, examination results, prescriptions and medical documentation are not posted on the portal and are not transmitted through its forms. The user fills in the comment to the request at their own discretion, and the portal asks not to include information about health status in it.

    The combination of the phone number and the doctor with whom the appointment is made is regarded by the portal as highly sensitive information and is stored only in encrypted form.

  2. 02

    Purposes of processing

    The portal processes personal data only to the extent required for the operation of the stated services, and does not use it for purposes of which the user was not informed when filling out the form.

    The purposes of processing are as follows: — arranging an appointment and transmitting the request to the selected clinic, including a callback from an operator to confirm the time: the portal promises to contact the patient within fifteen minutes after the request is submitted; — sending the user service messages about their own appointment — appointment confirmation, a reminder two hours before the appointment and an invitation to leave a review twenty-four hours after the appointment has taken place; — the operation of the personal account: logging in with a one-time code, viewing one's appointments, cancelling and rescheduling them, maintaining favourites and choosing the language of messages; — confirming that a review was left by a person who actually sought the service, and the subsequent verification of the review before publication; — reviewing reports of inaccuracies in the profiles of doctors and clinics and responding to them within the period established by the portal; — maintaining anonymised visit statistics and improving the operation of the catalogue search.

    User data is not used for advertising mailings by third parties, is not transferred to advertising networks and is not sold. Service messages concern only the appointment that the user has arranged themselves and are sent to the email address they have provided.

    The search query string is stored without being linked to the user and is used solely to improve catalogue results and search suggestions.

  3. 03

    Legal grounds for processing

    Processing of personal data on the portal is carried out in accordance with the Law of the Republic of Kazakhstan "On Personal Data and its Protection" No. 94-V, the Civil Code of the Republic of Kazakhstan, the Law of the Republic of Kazakhstan "On Informatisation", the Law of the Republic of Kazakhstan "On Advertising" and the Code of the Republic of Kazakhstan "On Public Health and the Healthcare System".

    The main legal basis is the consent of the personal data subject to the collection and processing of their data. Consent is given by a separate conscious action: a tick in the booking form, a tick upon first logging into the personal account, a click of a button in the cookie selection bar. The portal does not use pre-set ticks or consent by default: the absence of action by the user is not considered consent.

    The second basis is the performance of a contract and the performance of actions upon the user's request. Making an appointment is the user's request to the clinic, and the transfer to the clinic of the data necessary for the appointment takes place in fulfilment of this request. The portal's relations with clinics and doctors are governed by the public offer published on the portal.

    The third basis is the performance of duties imposed on the operator by legislation: storage of information about actions performed, provision of data to state bodies upon a lawful request, response to enquiries from the personal data subject.

    Consent may be withdrawn at any time in the manner described in the section on the rights of the personal data subject. Withdrawal of consent terminates further processing of data, except in cases where processing continues on another basis expressly provided for by law.

  4. 04

    Transfer of data to third parties

    The portal does not sell personal data, does not transfer it to advertising networks, data brokers or other persons not connected with the provision of the service for which the data was collected. The circle of recipients is limited and fully described below.

    Personal data is transferred to: — the medical organisation and the doctor with whom the user has made an appointment — to the extent described in a separate section of this policy; — the provider of electronic message delivery services — to the extent of the recipient's address and the text of the service message about their own appointment; no other information is disclosed to this provider; — the traffic statistics system — to the extent of the address of the opened page and the designation of the clicked card, without the name, contacts and any other information about the user, and only after the user has consented to analytics; — state bodies and the court — upon a duly executed request, within the limits established by the legislation of the Republic of Kazakhstan.

    The portal does not carry out cross-border transfer of personal data. The portal's database is located on a server located in the territory of the Republic of Kazakhstan, as required by the legislation on personal data.

    Data is not transferred to third parties for their own purposes in any volume. Portal employees gain access to data by roles: the appointment operator sees requests and the patient's contact details, the moderator sees reviews and enquiries, access beyond one's role is closed by technical means, not by instruction.

    Employees' actions with cards and requests are recorded in a log with the possibility of cancellation, so that every change of data has an author and a time.

  5. 05

    Transfer of data to the clinic when booking

    An appointment booking is a user's request addressed to a specific medical organisation. The portal does not provide medical services and acts as an intermediary that forwards the request to its destination.

    The following is transmitted to the clinic: the patient's name, their phone number, the selected doctor and branch, the selected service, the date and time of the appointment, the type of appointment and a comment, if the user left one. The clinic receives no other information about the user from the portal. The request number is communicated to the patient so that they can quote it when contacting the reception desk.

    The combination of the phone number and the doctor is stored in the portal's database in encrypted form using the AES-256-GCM algorithm. The encryption key is stored only in the server settings and is not contained in any portal file; a request is not created at all without a valid key. Only the booking operator, when processing a specific request, and the clinic's staff, who receive the request in their account, can decrypt the pairing.

    From the moment the request is received, the medical organisation processes the patient's data independently and as an independent controller: the further conduct of the appointment, medical documentation and the retention periods for medical information are determined by healthcare legislation and the clinic's internal rules. The portal has no access to the patient's medical record and does not receive information about the results of the appointment from the clinic.

    The patient can cancel or reschedule the appointment in their personal account, and the cancellation is transmitted to the clinic in the same manner as the request itself. If the appointment did not take place and the request was cancelled, the information transmitted to the clinic remains with it to the extent necessary to confirm the contact.

  6. 06

    Storage periods

    The portal stores data no longer than the purpose of its collection requires. The time limits are enforced automatically, not at an employee's discretion.

    The following time limits are established: — an appointment request is stored in full for one year from the moment it is created; after a year the request is depersonalised: the patient's name, phone number and comment are removed, while the record of the appointment that took place is retained as a fact of contact, without information about the person; — a login session in the personal account is valid for seven days, after which login is closed and the contact must be confirmed again; — a one-time confirmation code is valid for fifteen minutes, works once and is protected by a limit on the number of entry attempts; the database stores not the code itself but its irreversible fingerprint; — a review and ratings are stored indefinitely while the review is published on the portal, and are removed at the author's request to delete the data; — reports of inaccuracies are stored in the queue of reports together with a note of the reply, so that the fact and the time frame of consideration can be confirmed; — search queries are stored without any link to the user's identity and are not personal data in themselves.

    When a request to delete data is fulfilled, the time limits are not awaited: the patient's requests are depersonalised immediately, reviews are deleted together with ratings and the clinic's replies, the average ratings of the cards are recalculated, and confirmation codes, service messages, the name and all the user's sessions are deleted.

    Depersonalised information — the fact of an appointment that took place without a name and contacts, aggregated statistics, search query strings — is stored further, since it is impossible to restore a person's identity from it and it is no longer personal data.

  7. 07

    Cookies and analytics

    The portal uses two types of cookies: those essential for the operation of the service and analytical ones. The difference between them is fundamental, and the portal does not combine them in a single consent.

    Essential cookies ensure login to the personal account and protection of forms from request forgery. Without them the account does not work, therefore they are installed at login and cannot be disabled. A separate record stores the user's own choice regarding cookies, so that the consent bar is not shown again.

    Analytical cookies and the visit counter are not loaded until the user has clicked the consent button. The choice bar distinguishes three states: the user has not yet made a choice — analytics does not work; the user has selected "Only essential" — analytics does not work; the user has selected "Accept" — analytics is permitted. Closing the bar without making a choice is not considered consent, and in this case not a single byte of the counter is loaded.

    Only the address of the opened page and the designation of the clicked card are included in the statistics event. The name, contacts, content of the request, text of the review and the search query are not transmitted to the statistics system.

    The choice made can be changed at any time in the profile of the personal account or by clearing the website data in the browser. Refusal of analytical cookies does not restrict access to the catalogue, nor to booking an appointment, nor to reviews: all main sections of the portal work the same way with any choice.

  8. 08

    Rights of the data subject

    The Law of the Republic of Kazakhstan "On Personal Data and Its Protection" grants the data subject rights that the portal fulfils in full and without charging a fee.

    The user has the right to: — obtain information about whether the portal holds their personal data, its composition, the source of obtaining it and the purposes of processing; — demand that the data be amended and supplemented if it is incomplete, outdated or inaccurate; — demand that their data be blocked and destroyed if it is processed in violation of the law or the purpose of processing has been achieved; — withdraw previously given consent to the collection and processing of data; — appeal the actions of the operator to the authorised body for the protection of personal data of the Republic of Kazakhstan or in court.

    A request to delete data is submitted on the portal at /kabinet/udalenie-dannyh/. Logging into the personal account is not required for this: it is enough to confirm your contact with a one-time code. The request is fulfilled by a portal employee in a single action, and as a result the patient's requests are depersonalised, reviews are withdrawn, card ratings are recalculated, and service records about the user are deleted. Requests concerning the remaining rights are sent to the portal's email address.

    The period for considering a request is three working days from the moment it is received. The reply is sent to the contact details that the user specified in the request.

    One limitation is stated directly: a depersonalised record of an appointment that took place remains with the medical organisation, since it relates to its medical documentation and is stored in accordance with the rules of healthcare legislation. Reviews for which there is no confirmed contact fingerprint are withdrawn not automatically, but upon a separate request in which the applicant confirms their authorship.

  9. 09

    Information security measures

    The portal takes legal, organisational and technical measures to protect personal data from unlawful access, alteration, dissemination and destruction.

    Technical measures include: — encryption of the combination of phone number and doctor using the AES-256-GCM algorithm with integrity verification, in which the key is stored only in the server settings and is absent from the portal's files; — storage of irreversible fingerprints instead of the values themselves where the value does not need to be read: confirmation codes and the contact of the review author are not stored in the database in plain form; — masking of contact data in the interface: the caption under a review and the confirmations of code sending do not show the value in full; — transmission of all portal pages exclusively over a secure connection with redirection of insecure requests and prohibition of insecure access; — separation of patient and employee access at the storage level: a patient session does not pass any administrator rights checks, since it is stored in a different table; — mandatory two-factor authentication when portal administrators log in and limitation of the validity periods of their sessions.

    Organisational measures include differentiation of employee access by roles, keeping a log of actions with the author, time and the possibility of cancellation, regular backup of the database and limitation of the circle of persons authorised to process patient data.

    If a fact of unlawful access to personal data is detected, the portal stops processing in the affected part, eliminates the cause and notifies the affected subjects and the authorised body in the manner and within the time limits established by the legislation of the Republic of Kazakhstan.

  10. 10

    Contacts for data processing matters

    The operator of personal data is the administration of the MEDGID portal, which ensures the operation of the website https://medgid.kz. The details of the party are provided when concluding a contract and in the issued invoice; for enquiries regarding the processing of personal data, the contacts listed below are sufficient.

    For any matters related to the processing of personal data — regarding the composition of the stored information, its amendment, blocking, deletion, withdrawal of consent and violation of the rights of the data subject — please contact: — by email mail@medgid.kz; — by phone +7 (747) 708 28 18; — via the enquiry form available in the profiles of doctors and clinics and in the feedback section of the portal.

    The period for reviewing an enquiry is three working days. A request for deletion of data is submitted via a separate form at /kabinet/udalenie-dannyh/ and is executed without waiting for the specified period after confirming the contact with a one-time code.

    If the portal's response did not satisfy the applicant, they have the right to apply to the authorised body for the protection of personal data of the Republic of Kazakhstan or to a court in the manner established by law.

    The portal administration has the right to make changes to this policy. The current version is always posted on this page with an indication of the date of entry into force. Continued use of the portal after publication of the new version means consent to it; if the user does not agree with the changes, they have the right to withdraw consent and demand deletion of their data.

What data the portal receives and how long it keeps it

The list is derived from the portal itself: it changes together with it and therefore describes what the portal does now.

  • The name you gave

    when you submit an appointment request

    a year — then the name is removed from the request, the appointment record itself remains

  • Phone number

    when you submit an appointment request

    a year — then the number is removed from the request · stored sealed

  • Your email address, if you left one

    when you submit an appointment request

    a year — then the address is removed from the request · stored sealed

  • What you added to the request in your own words

    when you submit an appointment request

    a year — then removed together with the name and number

  • The number your booking SMS is sent to

    when the portal sends you a confirmation or a reminder

    remains in the message queue as a record of sending · stored sealed

  • The address the portal’s letter is sent to

    when the portal sends you a sign-in code or a letter about an appointment

    letters about a request leave the queue when the request is anonymized · stored sealed

  • The phone number or email you signed in to your account with

    when you sign in to your account with a code

    7 days — then the session closes by itself and you need to sign in again · stored sealed

  • The name we address you by in your account

    when you enter it yourself in your account

    removed at your request to delete your data

  • The language your booking SMS messages come in

    when you choose it in your account profile

    removed at your request to delete your data

  • When you gave consent to personal data processing

    when you sign in to your account and tick the consent box

    removed at your request to delete your data

  • Doctors and clinics you added to favourites

    when you press “Add to favourites” on a profile

    removed with a button in your account or at your request to delete your data

  • A fingerprint of the contact that confirms the review

    when you leave a review and confirm your number with a code

    15 min — then the code expires and the record becomes unusable · stored sealed

  • The text of your review

    when you submit a review

    taken down at your request to delete your data

  • What you liked — a separate line of the review

    when you submit a review

    taken down together with the review

  • What you did not like — a separate line of the review

    when you submit a review

    taken down together with the review

  • The date of the appointment the review is about

    when you submit a review

    taken down together with the review

  • The signature under the review: a number with some digits hidden

    when you submit a review

    taken down together with the review

  • A fingerprint of the author’s number: it is how the review is found as yours

    when you submit a review

    taken down together with the review · stored sealed

  • How to contact you about your enquiry

    when you report an inaccuracy or ask a question

    remains in the enquiry queue

  • Your name, if you gave it in the enquiry

    when you report an inaccuracy or ask a question

    remains in the enquiry queue

  • The text of the enquiry

    when you report an inaccuracy or ask a question

    remains in the enquiry queue

  • The number the portal uses to find your data for deletion

    when you request deletion of your data

    left empty once fulfilled · stored sealed

  • The text you searched for

    when you submit a search query

    remains in the list of queries; it is not linked to you in any way

What leaves the portal

  • To the SMS delivery provider

    the recipient’s number and the text of the message about their appointment

  • To the email delivery provider

    the recipient’s address and the text of the letter about their appointment or sign-in code

  • To the visitor counter

    which page is open and which profile was clicked — and only after your consent

Other documents

Full index