Privacy Policy

Last updated: 25.09.2026

This policy explains how IMEX AI processes the personal data of users of the ai-imex.com website and the IMEX AI mobile apps for Android and iOS (together, the "Service").

The personal data operator is [LEGAL ENTITY NAME — TO BE FILLED IN] ("we"). For questions about data processing, write to [CONTACT EMAIL — TO BE FILLED IN].

We collect only what the marketplace needs to work:

  • Account data: phone number, name, login and password hash (we never store the password itself), interface language, last sign-in time.
  • Company registration data: name, tax ID (INN), address, bank details, and the details of the director and staff you enter.
  • Company verification documents: registration certificate, bank letter, licences, certificates and other files you upload.
  • Trading data: offers, purchase requests, inquiries, deals, contracts, specifications, electronic invoices (ESF) and payment marks.
  • Chat messages and attachments exchanged with other companies, laboratories, logistics providers and technologists.
  • Photos and images you upload: product photos, company logos and covers, a technologist's profile photo.
  • E-IMZO certificate data when you confirm a company or sign a contract: full name, PINFL, tax ID, position, certificate details and the signature itself (PKCS#7). Name and PINFL are stored encrypted.
  • Didox electronic document exchange data: documents, their statuses and signatures, company details from the tax registry.
  • Technical logs: IP address, request times, browser or device type, errors. We need them for security and troubleshooting.
  • to provide the Service: signing in, publishing offers, requests, deals, chats;
  • to verify companies and protect participants from fraud;
  • to prepare and sign contracts and electronic documents;
  • to notify you about your deals, requests and messages;
  • to keep the Service secure, limit abuse and fix errors;
  • to comply with tax, civil and other legal obligations.

We process data on the basis of your consent, to enter into and perform the contract with you and your company, and to meet obligations imposed by law — in accordance with the Law of the Republic of Uzbekistan "On Personal Data" and other applicable rules.

We do not sell personal data. We share it only with those who help us run the Service, and only as much as they need:

  • Hosting and file storage — [HOSTING PROVIDER, COUNTRY — TO BE FILLED IN]. Files are kept in our own S3-compatible storage on those servers.
  • Didox (electronic document exchange operator, Uzbekistan) — to check a company against the tax registry and to send contracts and ESF, if you choose that signing method.
  • E-IMZO (UNICON.UZ) — electronic digital signature. The signature is created by the E-IMZO module on your device and verified by an E-IMZO verification server that runs in our infrastructure.
  • Telegram — delivering news and notifications through our bot and channel. If you use our Telegram Mini App, Telegram passes us your Telegram ID and name.
  • Anthropic and OpenAI (USA) — AI model providers we use to classify news and analyse the text of requests and offers. They receive the text of the request or offer, never your phone number, login or password. This is a cross-border data transfer.

We also disclose data to public authorities where the law requires it, and to the other party of a deal to the extent the deal itself needs.

  • Account data — for as long as the account exists. When you delete the account, the personal data in it is erased.
  • Company records — company details, contracts, deals, ESF, signed documents and signature evidence — are kept for as long as tax and civil law require, including after your account is deleted. They belong to the company, not to an individual user.
  • Messages exchanged with other companies remain with the other party as part of the deal history.
  • The log of calls to external services — 90 days; server technical logs — no longer than needed for security and troubleshooting.

You have the right to:

  • find out which of your data we process and get a copy;
  • correct inaccurate data — most of it you can edit yourself in the cabinet;
  • delete your account — in the app or on the website, without contacting support;
  • withdraw consent where processing is based on consent;
  • complain to the authorised state body for personal data protection.

How to delete your account and what is kept is explained on the "Account deletion" page.

The IMEX AI mobile apps do not track you across other apps or websites, do not use advertising identifiers (IDFA, Google Advertising ID), show no ads, and share no data with ad networks or data brokers.

Connections to the Service are encrypted (HTTPS). Passwords are stored only as hashes, bank details and certificate data are encrypted, and staff access is restricted and logged.

The Service is intended for company representatives and is not intended for anyone under 18.

We may update this policy. The date of the current version is shown at the top of the page; we will announce material changes in the Service.

Send questions about personal data and requests to exercise your rights to [CONTACT EMAIL — TO BE FILLED IN].