Privacy Policy

1. Who we are

Altair Foundation (Частный фонд имени Хаби Жакыпова “Алтаир”, BIN 080540019316) is a registered charitable foundation in the Republic of Kazakhstan. Our registered address is 358A Zharokova Street, Bostandyk district, Almaty.

For privacy questions, contact us at info@altair.foundation.

2. What information we collect

We collect minimal personal information necessary to operate the Foundation and deliver our charitable programs:

  • Contact form submissions — name, email, phone (optional), message you submit through /contact-us. Used solely to respond to your inquiry.
  • Donation information — when you donate via Stripe or Kaspi Pay, the payment provider collects payment details. We receive only confirmation of the transaction (amount, donor name and email if you provided them, transaction ID). We do not store your card data.
  • Volunteer applications — name, email, phone, optionally CV, when you apply to volunteer.
  • Anonymous analytics — page views, browser type, referrer (via Google Analytics 4 with anonymized IP). Only collected if you accept analytics cookies in our cookie banner.
  • Server logs — IP address, request URL, user agent, timestamp, retained for 30 days for security and debugging.
  • Consent — analytics cookies, marketing emails (you can withdraw consent anytime).
  • Legitimate interest — server security logs, anti-fraud measures.
  • Contract / pre-contract — donation processing, volunteer onboarding.
  • Legal obligation — anti-money-laundering checks for donations above threshold, financial reporting required by Kazakhstan law.

4. How we use it

  • Respond to contact and volunteer inquiries
  • Process and acknowledge donations
  • Send tax receipts and donation confirmations
  • Send periodic newsletters (only with your explicit opt-in)
  • Improve the website (anonymous analytics)
  • Comply with legal and regulatory requirements

We do not sell, rent, or share your personal information with third parties for marketing.

5. Who we share with

Limited third-party processors that help us operate:

  • Stripe (USA) — international card payments. Stripe Privacy Policy
  • Kaspi Bank JSC (Kazakhstan) — domestic payments
  • Google LLC (USA) — analytics (only with consent), email (Workspace)
  • Resend (USA) — transactional email
  • Hosting provider — Hetzner Online GmbH (Germany)
  • Cloudflare — DNS and security (USA / EU)

All processors operate under data processing agreements consistent with applicable law.

6. International transfers

Some of our processors are located outside Kazakhstan (USA, EU). We rely on standard contractual clauses and the processors’ adherence to recognized frameworks (EU-US Data Privacy Framework where applicable).

7. How long we keep it

  • Contact form messages: 2 years from last contact
  • Donation records: 7 years (financial reporting requirement)
  • Volunteer applications: 1 year (or longer with consent)
  • Analytics: aggregated, retention configured at 14 months in GA4
  • Server logs: 30 days

8. Your rights

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your information (subject to retention obligations)
  • Restrict or object to processing
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent for any processing based on consent
  • Lodge a complaint with the data protection authority of Kazakhstan or, if applicable, your local EU authority

To exercise any right, email info@altair.foundation with subject “Privacy request”. We respond within 30 days.

9. Cookies

See our Cookie Policy for details. By default, only essential cookies are set. Analytics cookies require your explicit consent through the banner shown on first visit.

10. Children

The Foundation’s services are not directed at children under 16. We do not knowingly collect personal data from children. If a parent or guardian believes their child has provided us with personal information, please contact us at info@altair.foundation and we will delete it.

11. Security

We use TLS 1.3 encryption for all site traffic. Donation processing is handled by PCI-DSS-compliant providers (Stripe, Kaspi). Internal access to personal data is restricted to authorized personnel.

12. Changes to this policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with the “Last updated” date. Material changes will be communicated by email to subscribed users.


Last updated: May 3, 2026 Version: 1.0