Legal document
Privacy Policy
What data the portal collects, why, how long it stores it and to whom it transfers it.
Document sections
- 01
What data is collected
This privacy policy, as revised on 10.02.2026, describes what information the MEDGID portal, available at https://medgid.kz, receives from the user, how it processes it, to whom it transfers it and how long it stores it. The policy applies to all sections of the portal: the catalogue of doctors and clinics, the appointment booking form, the patient's personal account, the review form and the enquiry form.
The portal receives data only when the user provides it themselves by filling in one of the forms. The portal does not carry out hidden collection of information about the user. The composition of the data is determined by the action the user performs: — when booking an appointment — name, phone number, email address, the selected doctor, clinic, service, date and time of the appointment, as well as a comment that the user writes in their own words; — when logging into the personal account — email address and a one-time confirmation code, as well as name, message language, a note of consent to data processing and the list of cards added to favourites; — when publishing a review — the text of the review, ratings on five parameters, notes on what was liked and what was not liked, the date of the appointment, the author's signature and an irreversible fingerprint of the confirmed contact; — when contacting the portal's editorial team — name, contact details and the text of the enquiry; — when using search — the search query string, which is stored separately and is not linked to either the user or their contacts.
The portal does not request or store medical information. Diagnoses, examination results, prescriptions and medical documentation are not posted on the portal and are not transmitted through its forms. The user fills in the comment to the request at their own discretion, and the portal asks not to include information about health status in it.
The combination of the phone number and the doctor with whom the appointment is made is regarded by the portal as highly sensitive information and is stored only in encrypted form.
- 02
Purposes of processing
The portal processes personal data only to the extent required for the operation of the stated services, and does not use it for purposes of which the user was not informed when filling out the form.
The purposes of processing are as follows: — arranging an appointment and transmitting the request to the selected clinic, including a callback from an operator to confirm the time: the portal promises to contact the patient within fifteen minutes after the request is submitted; — sending the user service messages about their own appointment — appointment confirmation, a reminder two hours before the appointment and an invitation to leave a review twenty-four hours after the appointment has taken place; — the operation of the personal account: logging in with a one-time code, viewing one's appointments, cancelling and rescheduling them, maintaining favourites and choosing the language of messages; — confirming that a review was left by a person who actually sought the service, and the subsequent verification of the review before publication; — reviewing reports of inaccuracies in the profiles of doctors and clinics and responding to them within the period established by the portal; — maintaining anonymised visit statistics and improving the operation of the catalogue search.
User data is not used for advertising mailings by third parties, is not transferred to advertising networks and is not sold. Service messages concern only the appointment that the user has arranged themselves and are sent to the email address they have provided.
The search query string is stored without being linked to the user and is used solely to improve catalogue results and search suggestions.
- 03
Legal grounds for processing
Processing of personal data on the portal is carried out in accordance with the Law of the Republic of Kazakhstan "On Personal Data and its Protection" No. 94-V, the Civil Code of the Republic of Kazakhstan, the Law of the Republic of Kazakhstan "On Informatisation", the Law of the Republic of Kazakhstan "On Advertising" and the Code of the Republic of Kazakhstan "On Public Health and the Healthcare System".
The main legal basis is the consent of the personal data subject to the collection and processing of their data. Consent is given by a separate conscious action: a tick in the booking form, a tick upon first logging into the personal account, a click of a button in the cookie selection bar. The portal does not use pre-set ticks or consent by default: the absence of action by the user is not considered consent.
The second basis is the performance of a contract and the performance of actions upon the user's request. Making an appointment is the user's request to the clinic, and the transfer to the clinic of the data necessary for the appointment takes place in fulfilment of this request. The portal's relations with clinics and doctors are governed by the public offer published on the portal.
The third basis is the performance of duties imposed on the operator by legislation: storage of information about actions performed, provision of data to state bodies upon a lawful request, response to enquiries from the personal data subject.
Consent may be withdrawn at any time in the manner described in the section on the rights of the personal data subject. Withdrawal of consent terminates further processing of data, except in cases where processing continues on another basis expressly provided for by law.
- 04
Transfer of data to third parties
The portal does not sell personal data, does not transfer it to advertising networks, data brokers or other persons not connected with the provision of the service for which the data was collected. The circle of recipients is limited and fully described below.
Personal data is transferred to: — the medical organisation and the doctor with whom the user has made an appointment — to the extent described in a separate section of this policy; — the provider of electronic message delivery services — to the extent of the recipient's address and the text of the service message about their own appointment; no other information is disclosed to this provider; — the traffic statistics system — to the extent of the address of the opened page and the designation of the clicked card, without the name, contacts and any other information about the user, and only after the user has consented to analytics; — state bodies and the court — upon a duly executed request, within the limits established by the legislation of the Republic of Kazakhstan.
The portal does not carry out cross-border transfer of personal data. The portal's database is located on a server located in the territory of the Republic of Kazakhstan, as required by the legislation on personal data.
Data is not transferred to third parties for their own purposes in any volume. Portal employees gain access to data by roles: the appointment operator sees requests and the patient's contact details, the moderator sees reviews and enquiries, access beyond one's role is closed by technical means, not by instruction.
Employees' actions with cards and requests are recorded in a log with the possibility of cancellation, so that every change of data has an author and a time.
- 05
Transfer of data to the clinic when booking
An appointment booking is a user's request addressed to a specific medical organisation. The portal does not provide medical services and acts as an intermediary that forwards the request to its destination.
The following is transmitted to the clinic: the patient's name, their phone number, the selected doctor and branch, the selected service, the date and time of the appointment, the type of appointment and a comment, if the user left one. The clinic receives no other information about the user from the portal. The request number is communicated to the patient so that they can quote it when contacting the reception desk.
The combination of the phone number and the doctor is stored in the portal's database in encrypted form using the AES-256-GCM algorithm. The encryption key is stored only in the server settings and is not contained in any portal file; a request is not created at all without a valid key. Only the booking operator, when processing a specific request, and the clinic's staff, who receive the request in their account, can decrypt the pairing.
From the moment the request is received, the medical organisation processes the patient's data independently and as an independent controller: the further conduct of the appointment, medical documentation and the retention periods for medical information are determined by healthcare legislation and the clinic's internal rules. The portal has no access to the patient's medical record and does not receive information about the results of the appointment from the clinic.
The patient can cancel or reschedule the appointment in their personal account, and the cancellation is transmitted to the clinic in the same manner as the request itself. If the appointment did not take place and the request was cancelled, the information transmitted to the clinic remains with it to the extent necessary to confirm the contact.
- 06
Storage periods
The portal stores data no longer than the purpose of its collection requires. The time limits are enforced automatically, not at an employee's discretion.
The following time limits are established: — an appointment request is stored in full for one year from the moment it is created; after a year the request is depersonalised: the patient's name, phone number and comment are removed, while the record of the appointment that took place is retained as a fact of contact, without information about the person; — a login session in the personal account is valid for seven days, after which login is closed and the contact must be confirmed again; — a one-time confirmation code is valid for fifteen minutes, works once and is protected by a limit on the number of entry attempts; the database stores not the code itself but its irreversible fingerprint; — a review and ratings are stored indefinitely while the review is published on the portal, and are removed at the author's request to delete the data; — reports of inaccuracies are stored in the queue of reports together with a note of the reply, so that the fact and the time frame of consideration can be confirmed; — search queries are stored without any link to the user's identity and are not personal data in themselves.
When a request to delete data is fulfilled, the time limits are not awaited: the patient's requests are depersonalised immediately, reviews are deleted together with ratings and the clinic's replies, the average ratings of the cards are recalculated, and confirmation codes, service messages, the name and all the user's sessions are deleted.
Depersonalised information — the fact of an appointment that took place without a name and contacts, aggregated statistics, search query strings — is stored further, since it is impossible to restore a person's identity from it and it is no longer personal data.
- 07
Cookies and analytics
The portal uses two types of cookies: those essential for the operation of the service and analytical ones. The difference between them is fundamental, and the portal does not combine them in a single consent.
Essential cookies ensure login to the personal account and protection of forms from request forgery. Without them the account does not work, therefore they are installed at login and cannot be disabled. A separate record stores the user's own choice regarding cookies, so that the consent bar is not shown again.
Analytical cookies and the visit counter are not loaded until the user has clicked the consent button. The choice bar distinguishes three states: the user has not yet made a choice — analytics does not work; the user has selected "Only essential" — analytics does not work; the user has selected "Accept" — analytics is permitted. Closing the bar without making a choice is not considered consent, and in this case not a single byte of the counter is loaded.
Only the address of the opened page and the designation of the clicked card are included in the statistics event. The name, contacts, content of the request, text of the review and the search query are not transmitted to the statistics system.
The choice made can be changed at any time in the profile of the personal account or by clearing the website data in the browser. Refusal of analytical cookies does not restrict access to the catalogue, nor to booking an appointment, nor to reviews: all main sections of the portal work the same way with any choice.
- 08
Rights of the data subject
The Law of the Republic of Kazakhstan "On Personal Data and Its Protection" grants the data subject rights that the portal fulfils in full and without charging a fee.
The user has the right to: — obtain information about whether the portal holds their personal data, its composition, the source of obtaining it and the purposes of processing; — demand that the data be amended and supplemented if it is incomplete, outdated or inaccurate; — demand that their data be blocked and destroyed if it is processed in violation of the law or the purpose of processing has been achieved; — withdraw previously given consent to the collection and processing of data; — appeal the actions of the operator to the authorised body for the protection of personal data of the Republic of Kazakhstan or in court.
A request to delete data is submitted on the portal at /kabinet/udalenie-dannyh/. Logging into the personal account is not required for this: it is enough to confirm your contact with a one-time code. The request is fulfilled by a portal employee in a single action, and as a result the patient's requests are depersonalised, reviews are withdrawn, card ratings are recalculated, and service records about the user are deleted. Requests concerning the remaining rights are sent to the portal's email address.
The period for considering a request is three working days from the moment it is received. The reply is sent to the contact details that the user specified in the request.
One limitation is stated directly: a depersonalised record of an appointment that took place remains with the medical organisation, since it relates to its medical documentation and is stored in accordance with the rules of healthcare legislation. Reviews for which there is no confirmed contact fingerprint are withdrawn not automatically, but upon a separate request in which the applicant confirms their authorship.
- 09
Information security measures
The portal takes legal, organisational and technical measures to protect personal data from unlawful access, alteration, dissemination and destruction.
Technical measures include: — encryption of the combination of phone number and doctor using the AES-256-GCM algorithm with integrity verification, in which the key is stored only in the server settings and is absent from the portal's files; — storage of irreversible fingerprints instead of the values themselves where the value does not need to be read: confirmation codes and the contact of the review author are not stored in the database in plain form; — masking of contact data in the interface: the caption under a review and the confirmations of code sending do not show the value in full; — transmission of all portal pages exclusively over a secure connection with redirection of insecure requests and prohibition of insecure access; — separation of patient and employee access at the storage level: a patient session does not pass any administrator rights checks, since it is stored in a different table; — mandatory two-factor authentication when portal administrators log in and limitation of the validity periods of their sessions.
Organisational measures include differentiation of employee access by roles, keeping a log of actions with the author, time and the possibility of cancellation, regular backup of the database and limitation of the circle of persons authorised to process patient data.
If a fact of unlawful access to personal data is detected, the portal stops processing in the affected part, eliminates the cause and notifies the affected subjects and the authorised body in the manner and within the time limits established by the legislation of the Republic of Kazakhstan.
- 10
Contacts for data processing matters
The operator of personal data is the administration of the MEDGID portal, which ensures the operation of the website https://medgid.kz. The details of the party are provided when concluding a contract and in the issued invoice; for enquiries regarding the processing of personal data, the contacts listed below are sufficient.
For any matters related to the processing of personal data — regarding the composition of the stored information, its amendment, blocking, deletion, withdrawal of consent and violation of the rights of the data subject — please contact: — by email mail@medgid.kz; — by phone +7 (747) 708 28 18; — via the enquiry form available in the profiles of doctors and clinics and in the feedback section of the portal.
The period for reviewing an enquiry is three working days. A request for deletion of data is submitted via a separate form at /kabinet/udalenie-dannyh/ and is executed without waiting for the specified period after confirming the contact with a one-time code.
If the portal's response did not satisfy the applicant, they have the right to apply to the authorised body for the protection of personal data of the Republic of Kazakhstan or to a court in the manner established by law.
The portal administration has the right to make changes to this policy. The current version is always posted on this page with an indication of the date of entry into force. Continued use of the portal after publication of the new version means consent to it; if the user does not agree with the changes, they have the right to withdraw consent and demand deletion of their data.
What data the portal receives and how long it keeps it
The list is derived from the portal itself: it changes together with it and therefore describes what the portal does now.
The name you gave
when you submit an appointment request
a year — then the name is removed from the request, the appointment record itself remains
Phone number
when you submit an appointment request
a year — then the number is removed from the request · stored sealed
Your email address, if you left one
when you submit an appointment request
a year — then the address is removed from the request · stored sealed
What you added to the request in your own words
when you submit an appointment request
a year — then removed together with the name and number
The number your booking SMS is sent to
when the portal sends you a confirmation or a reminder
remains in the message queue as a record of sending · stored sealed
The address the portal’s letter is sent to
when the portal sends you a sign-in code or a letter about an appointment
letters about a request leave the queue when the request is anonymized · stored sealed
The phone number or email you signed in to your account with
when you sign in to your account with a code
7 days — then the session closes by itself and you need to sign in again · stored sealed
The name we address you by in your account
when you enter it yourself in your account
removed at your request to delete your data
The language your booking SMS messages come in
when you choose it in your account profile
removed at your request to delete your data
When you gave consent to personal data processing
when you sign in to your account and tick the consent box
removed at your request to delete your data
Doctors and clinics you added to favourites
when you press “Add to favourites” on a profile
removed with a button in your account or at your request to delete your data
A fingerprint of the contact that confirms the review
when you leave a review and confirm your number with a code
15 min — then the code expires and the record becomes unusable · stored sealed
The text of your review
when you submit a review
taken down at your request to delete your data
What you liked — a separate line of the review
when you submit a review
taken down together with the review
What you did not like — a separate line of the review
when you submit a review
taken down together with the review
The date of the appointment the review is about
when you submit a review
taken down together with the review
The signature under the review: a number with some digits hidden
when you submit a review
taken down together with the review
A fingerprint of the author’s number: it is how the review is found as yours
when you submit a review
taken down together with the review · stored sealed
How to contact you about your enquiry
when you report an inaccuracy or ask a question
remains in the enquiry queue
Your name, if you gave it in the enquiry
when you report an inaccuracy or ask a question
remains in the enquiry queue
The text of the enquiry
when you report an inaccuracy or ask a question
remains in the enquiry queue
The number the portal uses to find your data for deletion
when you request deletion of your data
left empty once fulfilled · stored sealed
The text you searched for
when you submit a search query
remains in the list of queries; it is not linked to you in any way
What leaves the portal
To the SMS delivery provider
the recipient’s number and the text of the message about their appointment
To the email delivery provider
the recipient’s address and the text of the letter about their appointment or sign-in code
To the visitor counter
which page is open and which profile was clicked — and only after your consent