01Who we are and what this policy covers
This Privacy Policy (the “Policy”) explains how Darsly, the operator of the website darsly.uz, the Darsly learning platform, the Darsly mobile applications for iOS and Android and the related services (together, the “Services”), collects and processes personal data. In this Policy “Darsly”, “we”, “us” and “our” refer to the operator of the Services, and “you” refers to any visitor, registered learner, mentor or partner who uses them.
The Policy applies to all personal data processed in connection with the Services, regardless of the device or channel through which you use them. It forms part of the Terms of Use. Where you access Darsly through an educational organisation or employer that enrolled you, that organisation may have additional privacy notices that apply alongside this Policy.
Darsly processes personal data in accordance with the Law of the Republic of Uzbekistan “On Personal Data” No. ZRU-547 of 2 July 2019 and other applicable legislation. Where users from other jurisdictions use the Services, we apply this Policy as a minimum standard.
02What data we collect
Depending on how you use the Services, we may process the following categories of personal data:
- Identity and contact data: name and surname, phone number, e-mail address, profile photo, preferred interface language.
- Authentication data: one-time codes sent to confirm your phone or e-mail, a hashed password, an encrypted PIN code for quick sign-in in the mobile apps, and the technical identifiers issued by Google or Apple if you sign in with those accounts. We never store your Google or Apple password.
- Order and payment data: the course and plan you purchased, the amount, currency, discount or coupon applied, order status, the transaction identifier and confirmation returned by the payment provider. Bank card numbers are entered only on the pages of Click or Payme and are not received or stored by Darsly.
- Learning data: enrolments, lesson and module progress, assignment submissions and drafts, quiz, test and exam attempts and results, game and simulator sessions, achievements, leaderboard positions, calendar entries, learning preferences and certificates issued to you.
- Communications: messages and attachments in course chats, lesson discussion threads and direct messages with mentors, feedback you leave, reports you file about other users, support and partnership requests sent through our forms, and your notification preferences.
- Technical and security data: IP address, browser and operating system, device model and app version, session and refresh-token records, push-notification tokens, time of your last activity and audit-log entries recording security-relevant actions in your account.
- Marketing and lead data: if you leave a request on the website, the details you provide (name, phone, company, type of partnership, message), the page you came from and campaign parameters (UTM tags), and the status of our follow-up with you.
- Data from cookies and browser storage, as described in the Cookie Policy.
Data we ask you not to send
The Services are not designed for special categories of data (health, religious or political views, biometric data). Please do not include such information in messages, assignments or profile fields. If you do, we will treat it as provided voluntarily and will delete it on request.
03Where the data comes from
- Directly from you, when you register, fill in forms, buy a course, complete lessons or communicate on the platform.
- Automatically from your device and browser while you use the Services.
- From payment providers (Click, Payme), which confirm whether a payment succeeded.
- From Google or Apple, if you choose to sign in with those services (name, e-mail and a technical identifier only).
- From an educational organisation or employer that enrolled you in a corporate programme, limited to the details needed to create your access.
04Why we use your data and on what legal basis
Providing the Services
- Examples
- Creating your account, verifying your phone or e-mail, giving access to purchased courses, tracking progress, issuing certificates
- Legal basis
- Performance of the agreement with you (Terms of Use)
Payments and accounting
- Examples
- Creating orders, confirming payments with Click or Payme, issuing receipts, handling refunds, keeping accounting records
- Legal basis
- Performance of the agreement; legal obligations
Communication and support
- Examples
- Answering your requests, sending service messages about your courses, mentors’ replies, reminders about lessons
- Legal basis
- Performance of the agreement; legitimate interest in supporting users
Learning quality and personalisation
- Examples
- Recommending lessons, adapting exercises, showing achievements and leaderboards, letting mentors review your work
- Legal basis
- Performance of the agreement; legitimate interest in improving learning outcomes
Security and fraud prevention
- Examples
- Detecting suspicious sign-ins, protecting content from unauthorised copying, keeping audit logs, blocking abusive accounts
- Legal basis
- Legitimate interest in the security of the Services; legal obligations
Marketing
- Examples
- Contacting you about a request you left, informing you about new courses and offers, push notifications
- Legal basis
- Your consent, which you can withdraw at any time
Analytics and product development
- Examples
- Aggregated statistics on how courses are used, testing new features
- Legal basis
- Legitimate interest; wherever possible we use anonymised or aggregated data
Compliance
- Examples
- Responding to lawful requests from state authorities, establishing or defending legal claims
- Legal basis
- Legal obligations; legitimate interest
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the Services | Creating your account, verifying your phone or e-mail, giving access to purchased courses, tracking progress, issuing certificates | Performance of the agreement with you (Terms of Use) |
| Payments and accounting | Creating orders, confirming payments with Click or Payme, issuing receipts, handling refunds, keeping accounting records | Performance of the agreement; legal obligations |
| Communication and support | Answering your requests, sending service messages about your courses, mentors’ replies, reminders about lessons | Performance of the agreement; legitimate interest in supporting users |
| Learning quality and personalisation | Recommending lessons, adapting exercises, showing achievements and leaderboards, letting mentors review your work | Performance of the agreement; legitimate interest in improving learning outcomes |
| Security and fraud prevention | Detecting suspicious sign-ins, protecting content from unauthorised copying, keeping audit logs, blocking abusive accounts | Legitimate interest in the security of the Services; legal obligations |
| Marketing | Contacting you about a request you left, informing you about new courses and offers, push notifications | Your consent, which you can withdraw at any time |
| Analytics and product development | Aggregated statistics on how courses are used, testing new features | Legitimate interest; wherever possible we use anonymised or aggregated data |
| Compliance | Responding to lawful requests from state authorities, establishing or defending legal claims | Legal obligations; legitimate interest |
Where processing is based on consent, you may withdraw it at any time; this does not affect the lawfulness of processing carried out before withdrawal. Where processing is necessary to provide the Services, refusing to provide the data means we will not be able to provide the relevant part of the Services.
05Automated processing and AI features
Some features of the Services are assisted by automated systems and artificial-intelligence models: automatic checking of exercises and assignments, hints and explanations from an AI tutor, generated practice tasks, text-to-speech for lesson audio and course recommendations. To provide these features, the content you submit for checking (for example, an assignment text or a question you ask) may be processed by our own infrastructure and by trusted AI service providers acting on our behalf.
AI outputs are suggestions that help you learn; they may contain inaccuracies and are always reviewed or reviewable by Darsly mentors. Darsly does not make decisions producing legal effects on you solely by automated means. Final grades, certificates and access decisions are made or confirmed by people.
07Cross-border transfers and storage
Our servers and those of our providers may be located both in the Republic of Uzbekistan and abroad. Where personal data of citizens of Uzbekistan is processed, Darsly complies with the requirements of the Law “On Personal Data” regarding the collection and storage of such data on technical means located in Uzbekistan and transfers data abroad only where the law permits it and under contractual safeguards with the recipient.
08How long we keep data
We keep personal data only for as long as it is needed for the purposes described above, and then delete or anonymise it. Typical retention periods are:
Account and profile data
- Retention period
- For the life of the account and up to 3 years after deletion, to resolve disputes and protect against fraud
Learning data and certificates
- Retention period
- For the life of the account; certificate records are kept so that issued certificates can be verified
Orders, payments and accounting documents
- Retention period
- At least 5 years after the transaction, as required by accounting and tax legislation
Messages and support requests
- Retention period
- For the life of the account or until deleted, and up to 12 months afterwards for moderation and safety purposes
Technical logs, audit and security records
- Retention period
- Up to 12 months, unless needed longer for an investigation or legal claim
Marketing requests (leads)
- Retention period
- Up to 24 months from the last contact, or until you object
Cookies and browser storage
- Retention period
- See the Cookie Policy
| Data | Retention period |
|---|---|
| Account and profile data | For the life of the account and up to 3 years after deletion, to resolve disputes and protect against fraud |
| Learning data and certificates | For the life of the account; certificate records are kept so that issued certificates can be verified |
| Orders, payments and accounting documents | At least 5 years after the transaction, as required by accounting and tax legislation |
| Messages and support requests | For the life of the account or until deleted, and up to 12 months afterwards for moderation and safety purposes |
| Technical logs, audit and security records | Up to 12 months, unless needed longer for an investigation or legal claim |
| Marketing requests (leads) | Up to 24 months from the last contact, or until you object |
| Cookies and browser storage | See the Cookie Policy |
09How we protect data
Darsly applies organisational and technical measures appropriate to the risk: encrypted connections (TLS) for all traffic, hashed passwords and encrypted PIN codes, short-lived access tokens with revocable sessions, role-based access for staff and mentors, signed time-limited links for video and files, audit logging of sensitive actions, regular backups and separation of production data from development environments.
No system is completely secure. You are responsible for keeping your credentials confidential and for signing out on shared devices. If we become aware of a breach affecting your data, we will notify you and the competent authority in the manner and within the time required by law.
10Your rights
Subject to applicable law, you have the right to:
- obtain confirmation of whether we process your data and receive a copy of it;
- correct inaccurate or incomplete data (most profile details can be changed in your account settings);
- request deletion of your data or of your account, unless we must retain certain records by law or to resolve a dispute;
- restrict or object to processing based on legitimate interest;
- withdraw consent to marketing communications or push notifications at any time, using the settings in the app or the unsubscribe option in a message;
- lodge a complaint with the authorised state body for personal-data protection of the Republic of Uzbekistan.
To exercise these rights, write to info@darsly.uz from the e-mail address linked to your account or contact us through the app. We may ask you to confirm your identity. We respond within the period established by law and in any case within 30 days.
11Children and minors
The Services are intended for users aged 18 and over. Learners under 18 may use the Services only with the consent and under the supervision of a parent or legal guardian, who accepts the Terms of Use on their behalf and is responsible for their use of the Services. We do not knowingly collect data from children under 14 without such consent. If you believe a child has provided data to us without consent, please contact us and we will delete it.
13Changes to this policy
We may update this Policy when the Services, the law or our practices change. The current version is always published on this page with the date of the last revision. For material changes we will notify you on the platform or by e-mail before they take effect. Continued use of the Services after the effective date means that you have read the updated Policy.
14Contact
Questions, requests and complaints about personal data can be sent to info@darsly.uz or by post to: Darsly, 4A Muminov Street, Mirzo-Ulugbek District, Tashkent, Republic of Uzbekistan. Telephone: +998 77 009 91 14.