Legal Information & Company Credentials
Company credentials, privacy practices, consent and retention for FZM.kz.
Corporate Credentials & Registration
ТОО «Forza-M» operates under the laws of the Republic of Kazakhstan. Commercial obligations arise only through agreed contracts; automated tools and preliminary estimates do not create a binding offer.
Privacy and Personal Data
Operator and contact
The operator is ТОО «Forza-M», BIN 171140027774, Republic of Kazakhstan. Privacy and data-subject requests may be sent to info@fzm.kz. Commercial inquiries use sales@fzm.kz.
Purposes
We process only data needed to create, evaluate, save, recover or share a Project; generate and deliver a Smart Brief; respond to an explicit contact request; send requested transactional communications; secure and operate the service; run limited first-party analytics; operate the AI Advisor without sending personal data; and meet applicable legal, accounting or security duties. Generating a Smart Brief alone does not create a contact request.
Data categories
Depending on the action, this may include a name, optional company, email or phone, preferred contact channel, Project selections and answers, Smart Brief metadata, consent evidence, delivery state, and limited security or audit data. Ordinary contact intake does not request an identity document or IIN. Anonymous Configurator work is not retained server-side unless needed for limited security processing or the user explicitly saves it.
Retention
Default detailed application and abuse-protection logs: 30 days; security audit events: 90 days; first-party analytics detail: 12 months; detailed AI usage without personal data: 30 days and aggregate cost metrics: 12 months; Projects and contact requests containing personal data: 24 months after the last meaningful activity or interaction; Smart Brief artifacts: 12 months after the last Project activity; transactional delivery detail: 12 months; rolling backups: 30 days. A shorter lawful period prevails, while narrowly required compliance evidence may be retained separately for a legal obligation or dispute. No category is silently retained forever.
Recipients, storage and cross-border processing
Primary personal-data storage is in Kazakhstan. The current service does not send personal data to a foreign processor merely for convenience and does not publish user personal data. Service providers receive data only within a limited, lawful operational need. Public AI receives no name, email, phone, CRM data, contracts, secrets or source material. Any future cross-border transfer of personal data requires a separate legal and consent assessment.
Analytics and AI
First-party analytics use limited events, coarse route/product/locale state and aggregates without personal data, raw Project answers, persistent full IP addresses or browser identifiers, recorded browsing sessions, page-content recording, keystroke capture, cross-site identifiers or advertising pixels. AI is advisory: it may propose, the backend validates, the user confirms where required, and deterministic engines execute. AI cannot set prices or make security, publication or legal decisions.
Private access links, security and recovery
Private recovery and sharing links are treated as secrets: access values are kept in URL fragments rather than server-visible query parameters, excluded from analytics and logs, and may expire or be revoked. Access controls, audit evidence and limited security telemetry protect processing. After backup recovery, deletion records are reapplied so removed data is not permanently restored.
Your rights and withdrawal
Subject to applicable law, you may request access, correction, blocking or deletion of personal data and withdraw consent by writing to info@fzm.kz. After a valid withdrawal, processing is stopped within 15 working days when further storage or processing is not required by Kazakhstan law; otherwise a reasoned refusal is provided. We record the request and delete or anonymize affected data when legally permitted.
Contact and marketing consent
Consent to respond to a requested contact is required for the contact flow. Marketing consent is a separate optional choice, off by default, and may be withdrawn without affecting requested transactional service. Contact consent is not silently reused for marketing, and transactional mail does not use tracking pixels.
