Privacy Policy
What data aqlex processes for each feature, on what basis, with whom it is shared (including outside the Kyrgyz Republic), how long it is kept, and how to exercise your rights as a data subject.
Version of 23 September 2026
- TODO(legal): confirm the legal bases under Article 79 of the Digital Code (Section 4): processing for performance of the contract and legitimate interest without asking for consent; separate consent only for Telegram notifications and other cases with no other basis (Article 79(3): consent requested where another basis exists is void).
- TODO(legal): basis for cross-border transfers (Section 5) - until the regulator publishes the list of countries with adequate protection (Article 89), transfers to providers outside the Kyrgyz Republic are made for performance of the contract with the User and under contracts with protective terms; confirm sufficiency and that data processing agreements with all processors listed in Section 5 are in place.
- TODO(legal): confirm the retention period for documents uploaded for analysis and their reports (clause 6.5): they are currently kept until the User deletes them, with no automatic limit; decide whether to introduce a maximum retention period.
- TODO(legal): confirm retention of payment and agreement records (6 years - Articles 51 and 68 of the Tax Code; user agreement records - term plus 3 years under Article 114(4) of the Digital Code).
- TODO(legal): confirm the response deadline for data subject requests - 7 working days (Articles 73, 75 and 84 of the Digital Code); assess whether an impact assessment under Article 82 of the Digital Code is required.
1. General
1.1. This Policy describes how Limited Liability Company “AkylLex” (“AkLex” LLC, INN 00206202610137) (the “Operator”, “we”) processes the personal data of users of the aqlex legal information system (aqlex.ai; the “Service”). The Operator is the owner of personal records within the meaning of the Digital Code of the Kyrgyz Republic (the “Digital Code”), Chapter 11 of which governs personal data processing.
1.2. The Policy applies to all features of the Service and all ways of accessing it. It forms part of the user agreement together with the Public Offer (/offer), the Terms of Use (/terms) and the Refunds and Cancellation Policy (/refund) and is provided to the User before data is collected (Article 73 of the Digital Code).
1.3. We follow the principles of Article 78 of the Digital Code: we collect only the data needed for a specific purpose, do not use it for incompatible purposes, keep it accurate, keep it no longer than necessary and protect it from unauthorised access. We do not sell personal data, do not use it for advertising and do not train artificial intelligence models on it.
2. Definitions
2.1. “Personal data” - digital data containing information about a natural person who is identified or identifiable (Article 1(21) and (42) of the Digital Code). “Data subject” - the natural person the data relates to. “Processor” - a person processing data on the Operator’s instructions under a contract with it (Article 86 of the Digital Code). “Cross-border transfer” - transfer of data to a recipient under the jurisdiction of another state (Article 89).
2.2. Other terms (“Service”, “User”, “Plan”, “AI credits”, “Account area”) have the meaning given in the Public Offer.
3. What data we process and why
3.1. Account and sign-in. E-mail (for e-mail registration) and the password hash (passwords are stored only as an irreversible PBKDF2-SHA256 hash); phone number in international format and its verification mark; for Google sign-in - the Google account identifier, e-mail, name and profile picture link received from Google; for Telegram sign-in - the Telegram identifier, username and name; for passkeys - the public key, identifier and device name (the private key never leaves the User’s device); backup codes as hashes; creation and last-use dates of each sign-in method. One-time codes are stored only as a hash for their validity period (5 minutes). Purpose: account creation, sign-in, account recovery, confirmation of sensitive actions, abuse prevention.
3.2. Sessions. For each sign-in: session identifier, device and browser (User-Agent), IP address, sign-in method, sign-in time and expiry. Purpose: keeping the User signed in (access token - 30 minutes, refresh token - 30 days, extended on activity), showing and ending sessions in the Account area, detecting suspicious activity.
3.3. Profile (optional): display name, type (individual or legal entity), occupation, short bio, avatar (re-encoded to a 256×256 image without the original file’s metadata; the original is not kept). The avatar and display name are visible to other signed-in users of the Service. Purpose: account personalisation.
3.4. Search and reading. The search query text, filters and results are processed to execute the query; a separate search query log is switched off as of this version (queries are not stored linked to the User). For semantic search the query text is sent to the embeddings provider (Section 5). The history of recent queries and opened documents is stored only in the User’s browser. A counter per calendar month is kept to enforce the Plan’s search quota. Purpose: providing the service, enforcing quotas.
3.5. AI answers and chats. The User’s questions, previous chat messages and retrieved document fragments are sent to the AI model provider to generate an answer (Section 5). Chat history (questions, answers, source references) is stored in the User’s browser and synchronised to their account on the server so that it is available from other devices; a chat deleted by the User in the interface is deleted on the server too. Answers to identical questions may be cached for 10 minutes without a link to the User. Purpose: providing the service, access to one’s own history, metering AI credits.
3.6. Document analysis. The uploaded file (PDF or DOCX), the text extracted from it, the references to acts found, text fragments around the references, verification results and the final report, plus metadata (file name, size, page count, document date and title, price and credit charge). Text fragments (about 600 characters around each reference) and short excerpts (up to 500 characters) are sent to the AI model and embeddings providers (Section 5); the full text of the document is not sent to them. The Operator’s staff access uploaded documents only to handle the User’s requests and fix faults. Purpose: providing the service.
3.7. Library and feedback. Bookmarks, folders, bookmark notes, the list of watched documents and notifications about their changes; ratings and comments on search results and AI answers together with the text of the corresponding query and technical details of the result. Purpose: providing the service, improving search and answer quality.
3.8. Subscription, credits and payments. Plan, Subscription status and dates, history of credit grants and charges, Orders (contents, amount, status), payment information received from the payment provider (payment identifier, status, amount, time), promo codes used. The Operator does not receive or store card or bank account details. Payer details for an invoice (name, INN) that the User enters to generate an invoice are stored only in their browser and are not sent to the server. Purpose: performance of the contract, settlements, tax and accounting records.
3.9. Telegram notifications (optional). Telegram chat identifier, username or name, linking date, notification type settings, the log of sent notifications and their delivery status. Purpose: delivering notifications about the Subscription, payments and credits to the channel chosen by the User.
3.10. Technical data and security. Web server logs (IP address, request address, time, User-Agent, response code), rate-limit counters, application error reports (request method and address, a technical stack trace; User identifiers are deliberately excluded, but fragments of data being processed at the moment of the error may appear in the trace). Purpose: keeping the Service operational and secure, investigating incidents, preventing abuse.
3.11. Support requests: the content of the request and the contact details provided by the User. Purpose: handling requests, claims and data subject requests.
3.12. The Operator does not deliberately collect special categories of personal data (Article 80 of the Digital Code). If such data appears in the User’s questions or uploaded documents, it is processed solely as part of the User’s content to provide the requested service and is not used for other purposes.
4. Legal bases for processing
4.1. Most processing is necessary to conclude and perform the contract with the User (Article 79(1)(1) of the Digital Code): account and sign-in, sessions, profile, search, AI answers, document analysis, library, Subscription and payments.
4.2. Processing of Order and payment records after the contract has been performed, responses to lawful requests from state bodies and incident notifications to the regulator are carried out to comply with legal obligations imposed on the Operator (Article 79(1)(2)).
4.3. Processing of technical data, logs and error reports, rate limiting, abuse detection and processing of feedback on result quality are carried out in the Operator’s legitimate interest in the security and operation of the Service (Article 79(1)(5)), which does not prejudice the User’s rights.
4.4. Consent is requested only where no other basis exists: for receiving Telegram notifications (Article 44 of the Digital Code) - it is expressed by linking the channel and may be withdrawn at any time by removing the link in the Account area, as easily as it was given (Article 79(5)). Consent for any other purposes that may arise will be requested separately rather than included in the user agreement (Article 79(3)). [TODO(legal): confirm the bases.]
5. Recipients and cross-border transfers
5.1. The Service’s infrastructure (database, search indexes, file storage for uploaded documents and avatars, cache) is hosted on servers in the Kyrgyz Republic at the provider Bekem Soft LLC (ОсОО «Бекем Софт», icloud.kg). The Service’s interface (the static files of the web application) is hosted by a hosting provider; when the interface loads, that provider can see the IP address and technical browser details; account data of the User is not sent to it.
5.2. To provide the services we engage processors acting on our instructions under contracts compliant with Article 86 of the Digital Code. Some of them are located outside the Kyrgyz Republic; such transfers are cross-border (Article 89 of the Digital Code) and are made because they are necessary to perform the contract with the User, and under contracts with the recipients that ensure data protection. A User who does not want their data transferred to such recipients may refrain from using the corresponding features. [TODO(legal): confirm the transfer basis.]
- Language model (AI) provider - receives the question text, previous chat messages and document fragments (AI answers), and fragments of uploaded documents and cited provisions (document analysis). User identifiers are not sent. The provider does not train models on the data received; the data is retained by the provider for a limited time under its retention policy.
- Embeddings and reranking provider for semantic search - receives the text of the search query, of the question to the AI and short excerpts from the uploaded document (up to 500 characters). User identifiers are not sent.
- Object storage provider - the corpus of normative acts, search index snapshots, and encrypted (AES-256) backups of the Service database containing account, chat, library, Subscription and analysis report data. The backup encryption key is held only by the Operator. Backups are kept for 14 days.
- Application error reporting service - request method and address, technical stack trace; User identifiers are deliberately excluded (clause 3.10).
- Google LLC (USA) - for Google sign-in: the User discloses to Google the fact of signing in to the Service, and the Operator receives from Google the data listed in clause 3.1; processing on Google’s side is governed by Google’s privacy policy.
- Telegram (Telegram Messenger Inc. and affiliates; servers in various jurisdictions) - for Telegram sign-in, delivery of one-time codes via Telegram Gateway and bot notifications: receives the phone number (for codes), the chat identifier and the notification text; processing on Telegram’s side is governed by Telegram’s privacy policy.
- Sistema Quickpay LLC (Finik, Kyrgyz Republic) - payment provider: receives the amount, Order number, payment purpose and return address; it processes the User’s payment data independently as a participant of the payment system.
- SMS provider - receives the phone number and the message text with the one-time code.
5.3. Personal data may be disclosed to state bodies of the Kyrgyz Republic on their lawful and substantiated request in cases expressly provided by law. The Operator verifies the lawfulness of every request.
5.4. Other users of the Service can see only the User’s display name and avatar. Data is not shared with or sold to any other third parties.
6. Retention periods
6.1. Account, profile, sign-in method, library and settings data is kept for the life of the account and deleted when the account is deleted (Section 7). An inactive account may be deleted after the calendar year following the year of last activity, with prior notice (Article 118 of the Digital Code).
6.2. One-time codes - 5 minutes; Telegram linking codes - 15 minutes; sessions - until ended by the User or 30 days after the last refresh; profile cache - 90 seconds; rate-limit counters - until the end of the relevant window (hour, day or calendar month).
6.3. Chat history - until deleted by the User in the interface or the account is deleted. The cache of answers to identical questions - 10 minutes.
6.4. Feedback on results (ratings, comments with the query text) - for the life of the account; deleted on the User’s request.
6.5. Documents uploaded for analysis, extracted text, detected fragments and reports - until deleted by the User in the Service or on their request; no automatic maximum retention period is set as of this version, and if one is introduced it will be stated at upload. [TODO(legal): confirm.]
6.6. Records of Orders, payments, credit grants and charges, and records of the conclusion and performance of the user agreement are kept after account deletion to the extent required for tax and accounting purposes and defence against claims: 6 years (Articles 51 and 68 of the Tax Code of the Kyrgyz Republic); agreement records - the term plus 3 years (Article 114(4) of the Digital Code). [TODO(legal): confirm the periods.]
6.7. Notifications and their delivery log - for the life of the account; notifications not delivered within 24 hours are not sent. Notifications about changes to watched documents - for the life of the account.
6.8. Web server logs - 90 days; application error reports - under the error reporting service’s retention policy. Database backups - 14 days; data deleted from the Service disappears from backups after that period.
6.9. Data for which the Policy sets no other period is kept until the purpose of processing is achieved and then deleted or anonymised.
7. Data subject rights
7.1. The User has the right (Articles 73–76 and 83–85 of the Digital Code) to: obtain information about the processing of their data and a copy of the data; have inaccurate data corrected; have data deleted where it is no longer needed for the purpose or is processed unlawfully; withdraw consent (for Telegram notifications); object to processing based on legitimate interest; have processing restricted; receive their data in a machine-readable form.
7.2. In the Account area the User can independently: edit the profile and avatar; view and end sessions; add or unlink sign-in methods; change the phone number; delete chats; delete uploaded documents and reports; delete bookmarks and stop watching documents; unlink Telegram and change notification settings; cancel the Subscription and delete unpaid Orders.
7.3. Other requests, including account deletion, a copy of data and objection to processing, are sent to the contacts in Section 13 stating the account (e-mail or phone). The Operator may ask for confirmation that the request comes from the account holder (for example, a code sent to the phone). A response is given within 7 working days (Articles 73, 75 and 84 of the Digital Code). [TODO(legal): confirm the deadline.]
7.4. On account deletion the Operator deletes all data except the records it must retain by law (clause 6.6); such records are not used for other purposes and are deleted when the statutory period ends.
7.5. The User may complain about the Operator’s actions to the State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic (dpa.gov.kg) and to court.
8. Automated processing and artificial intelligence
8.1. The Operator does not make decisions about the User that produce legal effects for them solely on the basis of automated processing (Article 57 of the Digital Code). Rate limiting, Plan quotas and automatic credit refunds on failure are technical rules of contract performance and are not such decisions; their application can be contested through support.
8.2. AI answers and document analysis reports are generated by an artificial intelligence system and are the informational output of the service, not a decision of the Operator about the User. The Operator and its processors do not use Users’ questions, chats and uploaded documents to train models.
9. Cookies and browser storage
9.1. The Service uses only strictly necessary cookies set at sign-in: the access-token cookie and the refresh-token cookie (inaccessible to scripts, sent over HTTPS only; the refresh token only to the authentication endpoints) and the CSRF protection cookie. They last for the browser session; the tokens’ own lifetimes are in clause 3.2. No analytics, advertising or cross-site tracking cookies are used; the interface language is determined by the page address, not a cookie.
9.2. Browser local storage (localStorage) holds: the chosen theme; chat history and the active chat (synchronised to the account, clause 3.5); recent search queries and opened documents; the last sign-in method used and a masked phone number as a sign-in hint; payer details for an invoice (name, INN - cleared on sign-out); interface settings (AI features on/off, citation expansion). Session storage (sessionStorage), cleared when the tab closes, holds the search result cache and scroll positions, marks of submitted ratings and the state of the payment dialog. Except for chat history, this data is not sent to the server.
9.3. External scripts are loaded only when the corresponding sign-in method is used: the Google sign-in library (accounts.google.com) and the Telegram login widget (telegram.org). No web analytics tools or visitor counters are installed in the Service.
9.4. The User can delete cookies and storage data with browser tools; signing in again will then be required, and chat history will be restored from the account.
10. Security
10.1. The Operator applies technical and organisational protection measures (Article 88 of the Digital Code): data transfer over HTTPS only; storage of passwords and codes as irreversible hashes; confirmation of sensitive actions by a code sent to the phone; rate limiting; infrastructure isolated in a private network with no public access to the database and storage; encryption of backups; role-based staff access and logging of administrative actions; regular software updates.
10.2. In the event of an incident affecting personal data, the Operator notifies the competent authority within 72 hours of discovery (Article 63 of the Digital Code) and informs the affected Users where the incident creates a risk to their rights.
10.3. The User, for their part, must keep the password and codes secret, use passkeys or backup codes, end sessions on shared devices and report suspicious activity to the Operator.
11. Children
11.1. The Service is not intended for persons under 14, and the Operator does not knowingly collect their data. Persons aged 14 to 18 may consent to the processing of their data themselves within their legal capacity (Article 81 of the Digital Code) and use the Service with the consent of a legal representative (Terms of Use, clause 4.2). On learning that data of a child under 14 is being processed, the Operator deletes it. [TODO(legal): confirm the age thresholds.]
12. Changes to the Policy
12.1. The Operator may update the Policy by publishing a new version at aqlex.ai/privacy with its date. Users are notified of material changes (new purposes, new categories of recipients, changed retention periods) at least one month in advance in the Service interface and, where a channel is linked, via Telegram. Where a change requires the User’s consent, it is requested separately.
13. Contacts
13.1. Owner of personal records: Limited Liability Company “AkylLex” (“AkLex” LLC), INN 00206202610137; address: 125 Shevchenko St., apt. 15, Leninsky District, Bishkek, Kyrgyz Republic. Full details are given in Section 16 of the Public Offer.
13.2. Data subject requests and questions about this Policy: e-mail help@aqlex.ai. Contact of the person responsible for personal data protection: help@aqlex.ai.
13.3. Supervisory authority: the State Agency for Personal Data Protection under the Cabinet of Ministers of the Kyrgyz Republic (dpa.gov.kg).
Still have questions
Contact us: help@aqlex.ai - support, questions and claims.
See also: Public Offer · Terms of Use · Refunds and Cancellation · Plans and pricing