Privacy Policy
TOO IBSurgeon Software · Baizakova, 280, Almaty, Kazakhstan [email protected] · www.ib-aid.com
Effective Date: 01 August 2026 Last Modified: 01 August 2026 (This version supersedes the policy dated 31 October 2024.)
1. Introduction
TOO IBSurgeon Software (“IBSurgeon,” “we,” “our,” or “us”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:
- visit our websites (www.ib-aid.com, deploy.ib-aid.com, cc.ib-aid.com, tools.ib-aid.com);
- use our products and services, including the HQbird software and its license activation mechanisms;
- purchase licenses, subscriptions, or support services; or
- communicate with us electronically.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Law of the Republic of Kazakhstan “On Personal Data and Its Protection,” and other applicable data protection laws.
This policy describes our practices; where the law requires a specific legal basis or your consent for a processing activity, we rely on the bases set out in Section 5 and obtain consent where required. If you do not agree with this policy, please do not use our websites or services.
1.1 Policy Updates
We may update this policy periodically. We will notify you of material changes through a notice on our websites, by email (for registered users and customers), and by updating the effective date at the top of this policy.
2. Data Controller and Contacts
TOO IBSurgeon Software, Baizakova, 280, Almaty, Kazakhstan, is the data controller for personal data collected through our websites, products and services.
- Privacy inquiries and rights requests: [email protected]
- Data Protection Officer: [email protected]
EU/UK representative. We have not designated a representative in the EU or the UK, in reliance on the exemption in Article 27(2) GDPR (and its UK GDPR equivalent): our processing of personal data of EU/UK residents is occasional and limited to business contact, transaction and technical license data, does not include large-scale processing of special categories of data, and is unlikely to result in a risk to the rights and freedoms of natural persons. EU and UK users and supervisory authorities may contact us directly at [email protected]; we respond to all inquiries within the timeframes required by applicable law. We keep this assessment under review and will designate a representative if the nature or scale of our processing changes.
3. Age Restrictions
Our services are directed at businesses and are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn we have collected personal data from a person under 18, we will promptly delete it.
4. Personal Data We Collect
4.1 Identity and Contact Data
Name, email address, company name, job title, and business contact details — collected when you register, purchase, request an evaluation, subscribe to communications, or contact us.
4.2 Transaction Data
Order details, purchase history, invoicing and payment details (payment card data is processed by our payment providers and is not stored by us), license keys issued to you, and support tickets.
4.3 Website Technical Data
IP address, browser type and version, operating system, device information, log data, usage patterns and cookie data relating to your use of our websites (see Section 12).
4.4 Software License Management Data
When HQbird is activated or its license is verified, the software’s license management mechanisms transmit to us only the technical data required for activation and license compliance, as described in Section 2.5 of the HQbird End User License Agreement (https://ib-aid.com/en/hqbird-eula/):
- server hardware identifiers;
- IP address and host name of the server on which the software is installed;
- software version and edition; and
- license key data.
The license management mechanisms do not collect, access or transmit the contents of your databases or other business data.
4.5 Support Data
When you request technical support, we process the information you choose to provide, which may include log files and configuration files. Please do not include personal data or confidential database contents in support materials unless necessary; where diagnostic materials contain such data, we use them solely to resolve your request and treat them as confidential.
4.6 Collection Methods
We collect personal data through direct interactions with you, automated technologies (websites and software license management mechanisms), and third-party sources such as our authorized resellers and partners.
5. How We Use Personal Data and Legal Bases
| Purpose | Data categories | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing products and services; issuing and verifying licenses; activation | Identity, Transaction, License Management Data | Contract performance; legitimate interest in license compliance |
| Processing orders and payments; accounting | Identity, Transaction | Contract performance; legal obligation |
| Customer and technical support | Identity, Transaction, Support Data | Contract performance; legitimate interest |
| Service notifications (renewals, security notices, changes to terms) | Identity | Contract performance; legitimate interest |
| Protecting against fraud, abuse and unlicensed use | Technical, License Management Data | Legitimate interest |
| Website operation and security | Website Technical Data | Legitimate interest |
| Marketing communications, market research, personalization | Identity, Website Technical Data | Consent (you may withdraw at any time) |
| Product improvement based on aggregated usage | Technical (aggregated/anonymized) | Legitimate interest |
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
6. Data Sharing and Disclosure
6.1 Service Providers
We share data with trusted service providers who process it on our behalf and under contract, to: process payments, host our websites and services, provide customer support tooling, analyze website usage, and send communications.
6.2 Resellers and Partners
Where you purchase through an authorized reseller, we and the reseller each process the data needed to fulfil your order and license.
6.3 Legal Requirements
We may disclose personal data if required by law or legal process, to protect rights and safety, or to investigate fraud or unlicensed use of our software.
6.4 Business Transfers
If we are involved in a merger, acquisition or asset sale, personal data may be transferred as part of that transaction, subject to this policy.
6.5 No Sale of Personal Data
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising within the meaning of the CCPA/CPRA.
7. International Data Transfers
We are established in the Republic of Kazakhstan and may process data there and in other countries where we or our service providers operate. Where personal data of EU/EEA or UK residents is transferred outside the EU/EEA or UK, we ensure appropriate safeguards through Standard Contractual Clauses (SCCs), adequacy decisions, or other legal mechanisms, together with supplementary measures where appropriate.
8. Your Privacy Rights
8.1 GDPR Rights (EU/EEA and UK Users)
You have the right to access your data, rectify inaccurate data, erase your data, restrict processing, data portability, object to processing based on legitimate interests, and withdraw consent at any time (without affecting prior processing).
8.2 CCPA/CPRA Rights (California Users)
You have the right to know what personal data is collected, access it, correct it, delete it, opt out of sale or sharing (we do not sell or share personal data), limit use of sensitive personal data (we do not use sensitive personal data beyond permitted purposes), and not be discriminated against for exercising your rights.
8.3 Kazakhstan Users
You have the rights provided by the Law of the Republic of Kazakhstan “On Personal Data and Its Protection,” including access to and correction or destruction of your personal data.
8.4 Exercising Your Rights
Email [email protected]. We will respond within 30 days (GDPR) or within the timeframe required by other applicable law. We may need to verify your identity before acting on a request.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, regular security assessments, and employee training. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
10. Data Retention
- Customer account and license data: for the duration of the relationship and as long as needed to administer licenses, including verifying entitlements to installed instances after a subscription ends;
- Activation records: for as long as the related license or installed instance may remain in use, and thereafter as needed for license compliance;
- Transaction and accounting data: as required by applicable tax and accounting law;
- Support tickets: [RETENTION PERIOD, e.g. 3 years] after closure;
- Marketing data: until you withdraw consent or unsubscribe;
- Backups: according to our backup retention schedules, after which data is deleted or anonymized.
11. Cookies and Tracking
We use cookies and similar technologies on our websites to maintain sessions, remember preferences, analyze usage, and improve security. Where required by law, non-essential cookies are set only with your consent. You can control cookies through your browser settings and, where available, our cookie consent tool.
12. Contact Information
- Privacy / rights requests: [email protected]
- Data Protection Officer: [email protected]
- Technical support: [email protected] · www.ib-aid.com
- Postal address: TOO IBSurgeon Software, Baizakova, 280, Almaty, Kazakhstan
13. Supervisory Authority
EU/EEA users have the right to lodge a complaint with their local data protection authority; UK users with the Information Commissioner’s Office (ICO); Kazakhstan users with the authorized body for personal data protection of the Republic of Kazakhstan.
This Privacy Policy was last updated on 01 August 2026.