Version 1.0Effective from 26.08.2026

Supplement to the Privacy Policy: the QoyHunter Bazar marketplace and the auction

Contents (12)

Marketplace: https://bazar.qoyhunter.com · Website: https://qoyhunter.com · Contact for personal data matters: help@qoyhunter.com
Edition 1.0

This Supplement forms an integral part of the QoyHunter Privacy Policy and describes the processing of personal data in the use of the QoyHunter Bazar marketplace, of messaging between a buyer and a seller, of Buyer requests, of the auction and of the Telegram channels associated with them. In matters not governed here, the Privacy Policy applies. Terms are used in the meaning given to them by the Policy, by the Marketplace Terms of Use and by the Auction Rules.

1. What this Supplement governs

1.1. The Operator (“we”) is the person that operates the QoyHunter service and determines the purposes and the content of the processing of personal data on the marketplace and in the auction; enquiries to the Operator are sent to help@qoyhunter.com (clause 12.4). This Supplement describes the additional categories of data, purposes, legal bases, recipients and retention periods that arise on the marketplace and in the auction. The general provisions — the purpose of the Policy, the rights of the data subject, security, cross-border transfer, the procedure for lodging complaints — remain in the Policy and are not repeated here. This Supplement has been prepared under the Law of the Republic of Uzbekistan “On Personal Data” (No. ZRU-547) as amended by the Law of the Republic of Uzbekistan No. ZRU-1125 of 26 March 2026, and takes account of the principles applied in the Policy in force.
1.2. In the event of a discrepancy between the Policy and this Supplement in respect of the marketplace and the auction, this Supplement applies as the more specific instrument.
1.3. This Supplement also applies to persons who have not created an account: to those who have applied for the “Order of rams” service, to complainants (a complaint is accepted anonymously) and to auction participants known to the Operator only by their Telegram identifier (section 10).
1.4. Some of the functions described are being launched in stages. If a function has not been launched, the corresponding processing is not carried out; the availability of a function is determined by the interface.

2. What additional data we process

2.1. A Listing and an auction Lot. The title, the catalogue section, the breed, the sex, the live weight, the age, the ear length, the vaccination mark, the price and the currency stated by the Seller, the price-display flag, the description, the photographs, the country and the region, the date of publication, the moderation status and its outcome; for a Lot, in addition — the video, the starting price, the Bid step and the desired auction time. On the service side: the identifiers of the authoring User, of the farm and of the source animal, and, for Lots submitted through the Telegram bot without an account, the Telegram identifier of the submitter and a contact telephone number. The price is stored in the currency of the Seller; conversion into another currency is performed solely in order to display it to a visitor, at the official exchange rate, and is not saved in the database. The text and the photographs of a Listing are composed by the User, and therefore any information about themselves that the User has entered there is processed as part of the Listing (clause 11.3).
2.2. The veterinary certificate of a Listing. If the Seller has attached a document, the following are processed: the file itself, the time and the outcome of its verification by an administrator, and the identifier of the person who carried out the verification. The file is not published and is not passed to the Buyer: only the fact of verification is displayed publicly.
2.3. Messaging between the Buyer and the Seller. The following are processed: the participants (both accounts), the link to the Listing and a snapshot of its title, the texts of the messages, the time of sending and of reading, the unread counters, and also the fact that one participant has blocked the other and the time thereof. Messaging is available only to signed-in Users: there is no anonymous messaging on the Platform. Separate enquiries from a product card containing the contact details of the Buyer are not accepted and not processed by the Operator — the product has no such function.
2.4. An Order and a delivery request. Where a person applies through the “made to order” form or through the Telegram bot, the following are processed: the contact details for communication (telephone, Telegram or another method, in free form), the breed, the quantity, the place of delivery, the text of the message, the date, the processing status and the IP address of the sender. The enquiry is accepted without registration and is addressed to the Company (section 14 of the Terms), not to the Seller.
2.5. A Buyer request and Sellers' responses. A Buyer request is submitted by a User holding an account; the following are processed: the catalogue section, the title, the description, the breed, the weight range, the quantity, the budget and the currency, the desired date, the country and the region, the status and the closing date, and the number of responses. The name of the author of a Buyer request is not displayed publicly. A Seller's response contains the price offered, a comment and, at the Seller's option, a link to the Seller's own Listing; the response itself is visible to everyone on the request page (clause 4.2) — only the contact details of the responding Seller are withheld. Together with the response, the author of the Buyer request (and only the author) is shown: the display name, the account telephone number (the one stated in the profile or the one used as the telephone sign-in login) and the Telegram username, where the Seller has set them (clause 5.3).
2.6. A complaint. The following are processed: the type and the identifier of the target (a Listing, a User, a Buyer request, a chat thread), the reason code, the free-form comment of the complainant, the IP address of the complainant, the identifier of the complainant if the complainant was signed in (a complaint is also accepted anonymously), the contact details of the complainant if any were left, and also the outcome of the review: the status, the text of the decision, and by whom and when it was taken. A complaint about a chat thread gives the administrator access to the content of that particular thread — without this it is impossible to tell a threat from a slander. A complaint is retained even after the object complained of has been deleted — otherwise the Operator would be unable to confirm that it responded.
2.7. Reviews of a Seller. The following are processed: the author, the seller, the rating, the text, a snapshot of the display name of the author and of the name of the transaction as at the time of publication, the reply of the Seller and its time, and the flag indicating that a moderator has hidden it. The right to leave a review arises only from a transaction recorded by the Operator following an auction.
2.8. Favourites, subscriptions and Listing statistics. The “in favourites” mark links the User, the Listing and the time of addition; the Seller is shown only the number of persons who have added it, and on the storefront it is displayed only from a threshold value upwards. The “notify me when available” subscription contains: the User and Telegram identifiers, the catalogue section, the breed, the region, the price ceiling, the active flag and the time of the last dispatch. Listing views are counted by person rather than by impression, and therefore a record is stored for each first view of a card: the Listing, the browser identifier (an depersonalised token, or, where there is none, a hash of the IP address and of the browser details, clauses 7.1–7.2), the User identifier if the User was signed in at that moment, and the time of the view. Only the aggregate number of viewers is disclosed externally, and then only from a threshold value upwards; who exactly viewed it is seen neither by the Seller nor by other visitors.
2.9. Location. For a Listing and a Buyer request, the country and the region are processed. Geographic coordinates are not collected by the Service: there are no forms for entering them, the browser is not asked for a location, and public responses, exports and product feeds contain no coordinates (section 6).
2.10. Product usage events (funnels). For each of the products (the recordkeeping application, the marketplace, delivery, the blog) the following events are processed: a visit, registration, sign-in, creation of a farm, taking out a subscription, adding to favourites, creating a Listing, submitting an enquiry, placing a Bid at the auction, reacting to a blog publication. With each event the following are processed: the depersonalised browser identifier, the User identifier (if the User was signed in at the time of the event), and the time and the calendar day of the event. We give express warning: from the moment of sign-in, events are linked to the account (section 7).
2.11. The auction. The following are processed:

  • the Bid — the amount, the currency, the time, the method of submission (bot, website or a comment in the discussion group of the auction channel), the Telegram identifier of the person placing it, that person's account (if the Bid was placed from the website or Telegram is linked), the display name (nickname) as at the time of the Bid and an irreversible derived value of the network address (see clause 11.2). For a Bid placed as a comment, the coordinates of the Participant's own message in the group (the chat and the message number) are additionally stored — they link the Bid to its evidence; the content of that message is the amount stated, and it remains published in the group by the Participant themselves (clause 4.5);
  • the telephone number of an auction Participant — it is stated in the Telegram bot as a condition of participation in the auction: without it a Bid is accepted neither in the bot, nor on the website, nor by a comment in the discussion group (clause 3.3.1 of the Auction Rules). The Operator receives the number from Telegram through the “Share contact” button, or directly from the user where the user has entered the number in a message; the Operator sends no verification codes or SMS of its own at this step, and therefore the user is obliged to state their own number (clause 11.4). The number is stored with the account — with the Telegram account or with the website account — and not in the record of each individual Bid (clause 2.13, section 3 of the Policy);
  • the auction notification subscription — the Telegram identifier, the set of events, the active flag; an opt-out is stored as a flag and the record is not deleted, so that the opt-out is not lost;
  • the service log of notification delivery — the identifier of the recipient and the event key;
  • the candidate queue step — to whom and at what price the Lot was offered, the Telegram identifier and the nickname of the Participant, the times of the offer, of the delivery of the notification and of the closing of the step, the outcome of the step and the “counted as a Default” flag;
  • the mark of the administrator on the outcome and the objection of a Participant — including the free text of the explanations, the time of the objection, and the time of its review and the internal note thereon;
  • information on Defaults — the number of undisputed instances of non-performance over the last 12 months (clause 4.6).
    2.12. Consents and confirmations. The following are processed: the slug and the version of the document accepted, the time of acceptance or of withdrawal, the interface language, the IP address and the browser details as at the time of acceptance. The consent of an auction Participant to the Rules is recorded against the Telegram identifier — including for a person without an account (section 10) — together with the version of the Rules and the time of acceptance; it is recorded in the same way whether it is given by a button in the Telegram bot or by ticking the box on the Lot page, and it operates on both surfaces. The consent log is append-only: records are neither amended nor deleted, as otherwise there would be nothing with which to prove that consent was given.
    2.13. Telegram. The following are processed: the Telegram user identifier, the username, the first and last name from the profile, the language code, the times of the first and of the last contact, the identifier and the type of the chat, and also the telephone number if the user has passed it to the bot — through the “Share contact” button or in a message (clause 2.11). The Operator does not store the content of correspondence with the bot. The exception is an unfinished step-by-step scenario: while a User is filling in a request in the bot, the values entered (the breed, the weight, the price, the Bid step, the contact telephone number, the attached photographs) are stored as a draft until the scenario is completed or cancelled.
    2.14. Platform service data. The IP address of the sender is stored upon receipt of an Order, of a delivery request and of a complaint — for protection against spam, detection of duplicates and investigation of abuse. For a Buyer request, a response, messaging and a review the IP address is not stored: they are submitted from an account. Actions on records are recorded in the internal audit log: who, when, with which entity and which fields were changed; passwords and tokens do not reach the log. The same log receives the creation of the record of a first Listing view and of product usage events (clauses 2.8, 2.10) — together with the depersonalised browser identifier and the User identifier where the User was signed in; the IP address is not stored in the log. The log is available to the Operator only, is not published and is not shown to any User.

3. Purposes and legal bases (in addition to section 4 of the Policy)

3.1. Placement and display of Listings and Lots, the operation of search, of filters and of price conversion for display — performance of a contract (the Marketplace Terms of Use).
3.2. Messaging between the Buyer and the Seller, Buyer requests and responses, and notifications thereof — performance of a contract; legitimate interest (ensuring that the Platform is operable). Blocking a correspondent — the legitimate interest of the data subject and of the Operator (protection against harassment and spam).
3.3. Pre-moderation, review of complaints, removal of unlawful content, and combating spam and fraud — the legitimate interest of the Operator and of third parties; requirements of law. Access by an administrator to the content of messaging — only when reviewing a complaint about that messaging.
3.4. Conducting the auction, determining the winner, maintaining the candidate queue, communication between the administrator and the parties and recording the outcome — performance of a contract (the Auction Rules). The processing of the telephone number of a Participant — performance of a contract (the number is a condition of participation in the auction, clause 3.3.1 of the Auction Rules) and the legitimate interest of the Operator and of bona fide participants: so that an auction Participant may be identified and the measures under section 11 of the Auction Rules are not circumvented by means of a new account. The transfer of the number to the Seller of the Lot the right to purchase which has passed to the Participant — performance of a contract: without direct contact between the parties, no transaction is concluded following the auction (clause 5.4).
3.5. Recording of the non-performance of obligations by participants and restriction of participation in the auction — the legitimate interest of the Operator and of bona fide Users. The restriction is calculated automatically from the number of undisputed instances over the last 12 months (the thresholds are set out in the Auction Rules) and ceases just as automatically: where an objection is upheld, where an instance is excluded from the count, or where an instance falls outside the 12-month window. The restriction concerns participation in the auction only and is not a blocking of the account. The circumstances that served as the ground for the measure are not disclosed in the interface, nor is the number of instances counted: they are visible only to the administrators of the Operator (clause 11.9 of the Auction Rules). The decision may be appealed to help@qoyhunter.com — upon such an application it is reviewed by a person and not by the system, and it is by way of that procedure that the data subject obtains information about themselves.
3.6. Countering manipulation of the auction (analysis of the totality of Bids, clause 11.2) — the legitimate interest of the Operator and of bona fide participants. The result of the analysis is a ground for a check by a person, and not an automated decision.
3.7. Reviews of Sellers — performance of a contract and legitimate interest (informing buyers). The right to leave a review is confirmed by the Operator's own record of a transaction that has taken place.
3.8. Receipt and processing of Orders and of delivery requests — performance of a contract and the provision of a service by the Company upon the application of the data subject.
3.9. Notifications through Telegram of new messages, responses, matching Listings and the course of the auction — performance of a contract; legitimate interest. Marketing mailings — only on the basis of separate consent and separately from service notifications.
3.10. Product analytics and funnels (section 7), and also web analytics of public pages — the legitimate interest of the Operator; the right to object — section 11 or blocking cookies through your browser settings.
3.11. Product feeds to search and product services (clause 5.5) — legitimate interest (promotion of the Listings placed); the scope is set out in clause 4.1.
3.12. Recording of consents and maintenance of the audit log — requirements of law; legitimate interest (provability).
3.13. Consent given for any of the purposes listed may be withdrawn (section 11 of the Policy and clause 9.4 of this Supplement); withdrawal does not affect the lawfulness of the processing carried out previously and does not cancel processing carried out on other grounds.

4. What becomes publicly available

This is a key section: part of the data on the marketplace is published by the very nature of the service, and the Operator cannot reverse the consequences of publication.

4.1. A Listing is available to an unlimited range of persons: the title, the catalogue section, the characteristics of the animal, the price (if the Seller has permitted it to be displayed) and its approximate conversion for display, the description, the photographs, the region, the mark of verification of the veterinary certificate, the counters of views and of additions to favourites (from the threshold upwards), information about the Seller (the number of the Seller's Listings and the date of the first publication) and reviews of the Seller. A Listing is indexed by search engines and is available by direct link; those Listings for which the Seller has permitted the price to be displayed are exported to product services (clause 5.5). The contact details of the Seller are not published — contact begins with messaging. The exception is information that the Seller has themselves entered in the title or the description, or placed on a photograph (clause 11.3).

4.2. A Buyer request is available to an unlimited range of persons to the extent set out in clause 2.5, without the name and the contact details of its author. Sellers' responses are likewise publicly available: any visitor sees the price offered, the comment and the Listing attached by the responding Seller. A Seller should proceed on the basis that the price named in their response becomes public; only their contact details are withheld — those are visible exclusively to the author of the request (clause 5.3). Closing a request removes it from the public list, but the page, together with the responses, remains available by direct link.

4.3. Reviews of a Seller are public: the rating, the text, a snapshot of the display name of the author, the name of the transaction and the reply of the Seller. The author of a review must proceed on the basis that their display name and their text will be seen by any visitor.

4.4. The auction on the pages of the website. The following are published: the Lot, the course of the auction, the current and the final price, the number of Bids and the abbreviated display name of the leading Participant (for example, “Az***”). The full name is not published on the indexed pages of the website.

4.5. The auction in the Telegram channel and in the discussion group — read carefully. A post about the Lot is published in the public auction channel, and the discussion takes place in the linked group. In the channel post the display name (nickname) of the leading Participant is published in full, and in the discussion group a separate comment is published for each accepted Bid, containing the full nickname of the person who placed it, the amount and the time — that is, publicly available becomes the name not only of the winner, but of everyone who raised the price. A Bid may also be placed by the comment itself (clause 3.2 of the Auction Rules): in that case the Participant's own message stating the amount becomes publicly available, and the bot replies to it in the same thread. The channel and the group are conducted in Uzbek (Uzbek Cyrillic script), regardless of the language chosen by the Participant in the bot or on the website. The channel and the group are publicly available; their content is readable without a QoyHunter account, is indexed by search engines and may be forwarded or copied by third parties. In respect of this data Telegram acts as an independent operator; the Operator cannot delete a message from other persons' forwards, screenshots and search caches and is not liable for the processing of this information by Telegram and by other independent operators, nor for the actions of persons who have copied, forwarded or saved what has been published. A Participant who places a Bid agrees that their display name will become public when they are in the lead. If this is unacceptable, the display name in Telegram should be changed before taking part, or the person should not take part in the auction.

4.6. Information on the non-performance of obligations (Defaults). At present the Default counter is not displayed publicly: it is used only for restricting participation in the auction (clause 3.5) and is visible to the administrators of the Operator. If public display is introduced, only the number of undisputed instances over the last 12 months will be shown, without any description of the circumstances, amounts, names of Lots or value judgements. An instance that has been disputed, and an instance in respect of which an objection has not yet been reviewed, are not displayed publicly and are not taken into account. An instance is not counted at all if the notification was not delivered to the Participant.

4.7. Never published: the content of messaging between the Buyer and the Seller; contact details from Orders and delivery requests; geographic coordinates; the veterinary certificate file itself; the composition of the favourites and subscriptions of a particular User; the content of complaints and information about the complainant; the explanations of the parties in respect of an objection; the internal notes of a moderator; farm data from the recordkeeping application.

4.8. The consequences of publication. Withdrawal of a Listing or of a Lot removes it from the pages of the Operator but does not reverse what has already occurred: saved copies in search engines and product services are updated with a delay and in accordance with their own rules, while posts and comments in Telegram live by the rules of Telegram. The Operator assists with deletion within the limits of its technical capabilities and upon application to help@qoyhunter.com.

5. To whom data is transferred within the Platform and outside it

5.1. To the administrator of the Platform. An Order, a delivery request, an auction application and a complaint reach the administrators of the Operator, including by notification in Telegram, and are handled in the internal system by processing status. The notification contains a brief summary of the enquiry and the contact details of the person who made it. The recipients are a limited list of staff determined by a setting of the Operator. The administrator is entitled to contact the person who made the enquiry in order to clarify details. Following the auction, the administrator contacts the winner and the seller (clause 5.4). The administrators of the Operator see the telephone numbers of the Participants of the auction for a particular Lot — in the list of Bids and in the candidate queue steps: the Platform itself contacts the winner and the holder of the right to purchase and reviews objections (sections 10 and 11 of the Auction Rules). Access is limited by operational necessity.
5.2. To the Seller. The Seller sees the display name of the Buyer who has written to them and the texts of that Buyer's messages. The Operator does not transfer to the Seller the telephone number, the e-mail address or any other contact details of the Buyer — the parties exchange contact details themselves, in the messaging, when they see fit. This clause relates to Listings and to Messaging; the transfer to the Seller of the telephone number of an auction Participant following the auction is governed by clause 5.4. In addition, to those Sellers who have an active Listing in the same catalogue section (and, where it is stated in the request, in the same region) the Operator sends through the Telegram bot notice of a new Buyer request — the title of the request and a link to it, without information about its author; the number of recipients of a single mailing is limited.
5.3. To the Buyer who is the author of a Buyer request. The contact details of the responding Seller (the display name, the telephone number, the Telegram username) are disclosed only to the author of the Buyer request and only upon a response being made. The telephone number is taken from the profile of the Seller or, where it is not set there, from the telephone login with which the Seller signs in to the Service. The Buyer is bound by the same restriction on use.
5.4. To the parties to the auction. Following the auction, the Operator notifies the Participant and the Seller through the Telegram bot. Together with the notification, the telephone number of the Participant to whom the right to purchase has passed (the winner or the next candidate) is transferred to the Seller — together with that Participant's Telegram display name and the amount of the Bid, so that the Seller may contact them directly (clauses 3.3.1 and 8.5 of the Auction Rules). The Operator transfers no other information about the Participant to the Seller. To the Participant the Operator transfers such information about the Seller as it holds (the display name and the Telegram identifier, and the contact details stated when the Lot was submitted). The telephone number is not stored in the record of the Bid itself — it is stored with the account of the Participant (clause 2.11).
5.5. To external recipients. In addition to the recipients listed in section 8 of the Policy (hosting, payment providers, e-mail, Telegram, web analytics, state authorities), marketplace data is transferred: to product and search services — Google Merchant Center, Yandex and Microsoft (Bing) — to the extent of the published Listing (clause 4.1), including the photographs, the price, the characteristics and the region; to Telegram — to the extent of the posts of the auction channel, the comments of the group and the notifications of the bot (clause 4.5). Coordinates, contact details, the content of messaging and farm data are not included in these exports.
5.6. The Operator does not sell personal data, does not transfer the contact details of Users to advertisers and does not use them for the mailings of third parties.

6. Location

6.1. What we process. For a Listing and a Buyer request — the country and the region. The region is the level of precision that a buyer needs in order to decide whether the journey is worth making, and at the same time the level that does not reveal where the animal is kept.
6.2. What we do not do. The Service does not request the location from the browser, does not display a map, a radius or the distance to a Listing and does not collect the geographic coordinates of a farm: there are no forms for entering them. Accordingly, coordinates are never published — neither on the pages, nor in the product feeds, nor in the responses of the application programming interface.
6.3. Technically, the database provides for coordinate fields and a mechanism for concealing them (publication of a shifted point instead of the real one). These fields are not populated, and until the collection of coordinates is introduced no processing is carried out in respect of them. If the collection of coordinates is introduced, this Supplement will be amended in advance, and the exact point will not become public in any form.
6.4. Photographs. Uploaded images are re-encoded on the server, and the original technical information of the shot (including the coordinates at which it was taken, the device model and the date) is not stored and not published.

7. Depersonalised identifiers and linking to an account

7.1. The browser identifier. In order to count unique visits and to build funnels, a random depersonalised identifier stored in the browser is used. It contains no name, telephone number or other information about the identity of a person.
7.2. Where there is no identifier (a request made without the execution of browser scripts), a hash of the IP address and of the browser details is used instead. The IP address and the browser details themselves are not stored as part of the event — only the result of hashing, and they cannot be recovered from the stored value by a reverse transformation. The Operator does not assert that such a value entirely excludes matching to a person, and treats it as personal data.
7.3. Linking. From the moment of signing in to an account, events are marked with the User identifier. This means that actions previously depersonalised become part of the history of a particular person — otherwise it is impossible to measure a person's movement between products. The Operator uses this data in statistical form and does not take decisions on the basis of it that give rise to legal consequences for the User.
7.4. Objection. Analytical processing may be objected to by means of the interface (withdrawal of consent to web analytics), through your browser settings, or by a request to help@qoyhunter.com. Identifiers strictly necessary for the operation of the service (session, authorisation) are retained in that case.

8. Retention periods

8.1. Data is stored no longer than is necessary for the purposes set out in section 3, or for the period established by law.
8.2. An honest account of the current position — read this before the table. Automated deletion on a schedule is at present implemented for funnel and visit events (365 days) and for inactive session tokens (14 days). The remaining marketplace and auction data is deleted once the purposes of the processing have been achieved — by a decision of the Operator, upon the User deleting the corresponding record, upon deletion of the account (section 9) or upon the application of the data subject to help@qoyhunter.com — but not automatically on a schedule. The periods in the table below are the maximum periods that the Operator assumes; each of them takes effect together with the launch of the corresponding automated clean-up, of which the Operator gives notice by issuing a new edition of this Supplement. Until that moment the data subject is entitled at any time to demand the deletion or depersonalisation of their data where there is no ground for storing it further (clause 9.3); the Operator complies with such a demand.
8.3. Maximum periods by type of marketplace and auction data (in addition to section 7 of the Policy):

Data Retention period Why so long
A Listing, a Lot, photographs while they are published; after withdrawal — 12 months, then deletion (upon deletion of the account — immediately, clause 9.1) a window for reviewing complaints in respect of a sale already completed
The veterinary certificate file until the Listing is withdrawn, and thereafter together with it the document is needed only in order to verify a particular card
Messaging between the Buyer and the Seller 12 months from the last message (upon deletion of the account of either party — immediately, clause 9.1) a window for reviewing complaints about the messaging
An Order, a delivery request 36 months from the date on which the enquiry was closed; the contact details and the IP are depersonalised earlier — after 12 months a claim in respect of a service may be brought later than the service itself, and therefore the record lives for the whole period during which a demand may be presented; but by that time the identifying fields are no longer needed
A Buyer request and the responses to it 12 months from the date on which the request was closed demand becomes stale; the arrangement reached through a response remains with the parties
Favourites until deleted by the User or until the account is deleted this is a personal selection, not a history
“Notify me when available” subscriptions until switched off by the User or 24 months without dispatches (deletion of the account does not affect them at present — clause 9.2) a subscription lives for as long as the person needs it
Records of Listing views (clause 2.8) 12 months from the view; upon deletion of the Listing — together with it the counter reflects interest in a current Listing, not the history of a visitor
A review of a Seller and the reply to it 36 months from publication a reputational record concerning a particular transaction
A complaint and the outcome of its review 12 months after the review; where a measure has been applied — 36 months confirmation that the Platform responded; where a measure was applied — the ground for it
Bids, queue steps, marks and objections 36 months from the end of the auction the evidentiary basis of a dispute between the parties
The record of instances of non-performance (Defaults) 12 months (the counting window) it coincides with the window applied by the Auction Rules
The consent of an auction Participant to the Rules 36 months from the last Bid proof of the expression of will
The log of consents to documents the whole term of the relationship and 36 months after its termination consent has to be provable for exactly as long as a demand based on the processing of data may be presented
Notifications (the delivery log) 12 months diagnosis of non-delivery
Funnel and visit events 365 days (the clean-up is operating) measuring the product does not require a deeper history
Telegram profile data and chat details, including the telephone number of an auction Participant 24 months from the last contact with the bot (upon deletion of the account the profile is depersonalised and the number is erased — clause 9.2) without contact with the bot the link to the person ceases to serve any purpose
An unfinished bot scenario (a draft request) 30 days without activity an abandoned draft is of no use either to us or to the User
IP addresses in Orders and complaints 12 months, after which the IP is deleted while the record itself is retained anti-spam measures and investigations do not require the address to be stored indefinitely
The derived value of the network address attached to a Bid 36 months (together with the Bid) it exists solely as an indicator of a link between Bids
The internal audit log 36 months access control and investigation of incidents
Backup copies 30 days from the date on which the copy was created, after which the copy is overwritten recovery after a failure does not require a deeper history; deleted data disappears from the copies within that period

8.4. Depersonalisation instead of deletion. Where a record is needed for statistics, for proof or for the protection of the rights of third parties, upon the expiry of the period the Operator deletes the identifying fields (contact details, IP, name, Telegram identifier) and retains an depersonalised record. Depersonalised data is not restricted by the Policy. There is at present no automated depersonalisation on a schedule (clause 8.2): until it is launched, depersonalisation is carried out upon the application of the data subject and by a decision of the Operator.
8.5. Upon the expiry of the periods, data is deleted from the working systems; from backup copies — as they are rotated. Individual items of information may be stored for longer where this is required by law or is necessary for the protection of rights in connection with a dispute that has been raised — to the extent necessary for that purpose.

9. Deletion of an account, deletion of individual data, and export

9.1. Deletion of the account is available to the User independently. The owner of a farm that holds data must first transfer the farm to another member or delete it. Upon deletion of the account the following are deleted:

  • the profile, the sign-in methods, the sessions, memberships of farms, password recovery codes and unfinished Telegram linking codes, the settings and the notification log, and the User's empty farms;
  • their Listings together with the photograph files — that is, the card disappears from the storefront, from the sitemap and, at the next update, from the product feeds;
  • their Buyer requests together with all responses received to them, and their own responses to the requests of others;
  • favourites;
  • the chat threads in which they took part — together with the messages of both parties. This decision is not self-evident and is therefore stated expressly: private messaging exists only as a conversation between two people, and to leave it with the correspondent would mean preserving the words of a person who has demanded that they be deleted. The correspondent loses the history of the conversation — that is a deliberate price.
    9.2. What remains after deletion, and why. Part of the data cannot be deleted immediately together with the account:
  • complaints — they are retained, but cease to point to the complainant: a signal about unlawful content must not disappear merely because the person who complained has deleted their account;
  • Bids, candidate queue steps, marks and objections — they constitute the evidentiary basis of the relations between the Seller and the Participants of the auction;
  • reviews of Sellers — they contain a snapshot of the name of the author and relate to a transaction of which other buyers are entitled to know;
  • the consent log and the audit log — they are append-only and serve as confirmation that the processing was lawful;
  • information about the Telegram account — it exists independently of the website account and remains the identifier of the person in those places where there is no account at all: the consent of an auction Participant, subscriptions and Bids are keyed precisely to the Telegram identifier (section 10). Upon deletion of the account the Telegram profile is depersonalised: the telephone number, the username, the first name and the last name are erased, and the link to the account is removed — what remains is an anonymous chat identifier. If a person took part in the auction only through the bot, without creating an account on the website, there is nothing to delete: their number and Telegram profile live according to the periods set out in section 8 and are deleted upon application to help@qoyhunter.com;
  • “notify me when available” subscriptions, records of Listing views (clause 2.8) and marks that a correspondent has been blocked — these too are not deleted at present together with the account. None of them is published or visible to anyone other than the Operator, but their deletion may be demanded by an application to help@qoyhunter.com;
  • the auction notification subscription and the service log of the delivery of such notifications (clause 2.11) — they are attached to the Telegram identifier rather than to the account and live independently of it;
  • Orders and delivery requests (clause 2.4) — they are accepted without registration and are not linked to an account at all, and therefore its deletion does not affect them. The contact details and the IP address left in them are deleted according to the periods set out in section 8 or upon application to help@qoyhunter.com;
  • product usage events (clause 2.10) — after deletion of the account they retain its identifier until the expiry of the 365-day period (clause 8.3), after which they are deleted automatically;
  • comments and reactions in the blog, and also the service roles assigned to the User — they relate to other parts of the Service and are not governed by this Supplement; their deletion may likewise be demanded by an application.
    In all of the cases listed, depersonalisation applies upon the expiry of the periods set out in section 8 (clause 8.4 — subject to the reservation in clause 8.2), and until then access to the data is limited by operational necessity.
    9.3. Deletion of individual data without deletion of the account. The User is entitled at any time independently to withdraw their Listing, to close a Buyer request, to clear their favourites, to switch off a subscription and to opt out of auction notifications. The withdrawal of an individual consent, and the deletion or depersonalisation of particular information where there is no ground for storing it further, are carried out upon application to help@qoyhunter.com — there is at present no separate button in the interface for withdrawing consent.
    9.4. Withdrawal of consent. Withdrawal by an auction Participant of their consent to the Rules means that their participation in the auction ceases; withdrawal does not cancel Bids already placed or the consequences of those Bids.
    9.5. Export. The User is entitled independently and free of charge to download a copy of their data in machine-readable form; this facility does not depend on the tariff paid for. The download includes: the profile, the sign-in methods (without secrets), consents, participation in farms, Listings, Buyer requests, responses, favourites, the User's own messages in the messaging and the fact of the threads themselves, the reviews written by the User and their Bids. The data of other persons is deliberately not included in the download: the messages of correspondents and reviews of the User belong to other people, and to hand them over under the guise of giving effect to the right of one person would be to disclose the data of another. Analytical downloads of farm data (animals, finances, feed) are provided by means of the application; on the free tariff a copy of the same data is provided upon application to help@qoyhunter.com. The categories of the User's own data that are not included in that download at present — Orders and delivery requests, complaints submitted by the User, subscriptions, information about the Telegram account, records of views, candidate queue steps and auction marks — are provided upon application to help@qoyhunter.com within the period set out in clause 9.6.
    9.6. The period for responding to applications under this section is the period established by the legislation of the Republic of Uzbekistan, as a rule no later than 30 days. The Operator is entitled to request confirmation of identity where the data subject cannot be reliably established from the application.

10. Participants without an account on the website

10.1. It is possible to take part in the auction, to submit a lot and to place an Order through the Telegram bot or a public form, without creating an account on the website. In that case the Operator knows such a person by their Telegram identifier and display name and — if the person has provided them — by their telephone number or other contact details. For participation in the auction a telephone number is mandatory and is stated in the bot (clause 2.11): without it a Bid is not accepted.
10.2. Messaging with a Seller and responding to a Buyer request are not possible without an account (clause 2.3): there can be no anonymous correspondent where the other party must have the opportunity to reply.
10.3. Before the first Bid, consent to the Auction Rules is requested — in the Telegram bot by a button, and on the Lot page by ticking a box containing a link to the Rules; without consent a Bid is not accepted by either method. Consent is recorded against the Telegram identifier, with the version of the Rules and the time of acceptance. The Auction Rules, the Privacy Policy and this Supplement are permanently published and are available before a Bid is placed; by confirming consent the participant confirms that they have been given the opportunity to review them and that they have been notified of the public nature of the display name (clause 4.5, clause 1.4 of the Auction Rules).
10.4. The rights of the data subject are exercisable without an account as well. An application may be made through the same Telegram bot or to help@qoyhunter.com, stating the Telegram identifier or username; the Operator is entitled to confirm that the identifier belongs to the applicant by asking that the application be sent from the same Telegram account.
10.5. The deletion of the data of such a participant is carried out to an extent that does not affect the data of the other party or the evidentiary basis of the auction (clause 9.2), with depersonalisation upon the expiry of the periods set out in section 8.

11. Features of the Platform that affect privacy

11.1. Pre-moderation and the review of complaints. The Listings of Users are checked before publication, and complaints are reviewed after it. This means that the staff of the Operator see the content of Listings, of attached veterinary documents, of Buyer requests, of complaints and — when reviewing a complaint about messaging — the content of that messaging. Access is limited by operational necessity, and actions are recorded in the audit log.
11.2. Countering manipulation of the auction. In order to detect concerted Bids, the Operator compares the Bids placed on a single lot by reference to an irreversible derived value of the network address: the address itself is not stored in the record of the Bid, and it cannot be recovered from the stored value. Account is also taken of whether the leading participant has placed Bids at other auctions on the Platform. The result of the comparison is a ground for a check by a person, and not an automated decision about the rights of the User.
11.3. Self-disclosure is the responsibility of the User. The Operator does not publish the contact details of a Seller, but it cannot prevent a User from stating a telephone number, an address or other information in a title, a description, a response, a review or on a photograph. Such information becomes publicly available and reaches search engines and product services together with the Listing. We strongly recommend that documents, bank details, exact addresses and information about third parties without their consent should not be placed in open text. The Operator is not liable for the consequences of such self-disclosure; upon application to help@qoyhunter.com it will delete the information concerned from its own pages within the limits of its technical capabilities (clause 4.8).
11.4. The data of third parties. In placing information about another person, the User must have a legal ground for doing so and must inform that person. Liability for breach of this duty rests with the User; in respect of such information the User acts independently.
11.5. Protection against spam and abuse. In receiving public forms, rate limiting, hidden trap fields and a limit on the size of an enquiry are applied; for this purpose the IP address is processed (clause 2.14; the period — section 8). For messaging, a limit on the number of new threads per day and a minimum interval between messages are applied.
11.6. Security incidents — section 10 of the Policy applies. The Operator takes reasonable and proportionate organisational and technical protective measures; however, no system for transmitting and storing data provides absolute protection: the Operator does not guarantee that data will not be lost, altered or obtained by third parties as a result of circumstances beyond its reasonable control — the unlawful acts of third parties, failures of communication networks, of hosting and of Telegram services, or force majeure. This clause does not release the Operator from the duties established by law to ensure the security of personal data and to give notice of incidents.

12. Amendments, language and contacts

12.1. The current edition of the Supplement is published together with the Privacy Policy, with the date stated; the Operator gives notice of material amendments through the Service, the Telegram bot or e-mail.
12.2. For questions concerning the processing of personal data on the marketplace and in the auction, and in order to exercise the rights of a data subject — help@qoyhunter.com. The complaints procedure is set out in section 14 of the Policy.
12.3. This is an English translation of the Supplement executed in Russian and Uzbek. In case of any discrepancy in interpretation, the Uzbek version shall prevail; the English text is provided for convenience only.
12.4. Contacting the Operator. Applications under this Supplement, including demands for the exercise of the rights of a personal data subject, are sent to the e-mail address help@qoyhunter.com; the website of the Operator is https://qoyhunter.com. A person known to the Operator only by a Telegram account is also entitled to apply through the Telegram bot (clause 10.4). The periods established by this Supplement run from the day on which the application is received through these channels. The Operator is entitled to request confirmation of the identity of the applicant where the data subject cannot be reliably established from the application (clause 9.6).