Key principles. "FLOTT" LLC processes personal data in accordance with the legislation of the Republic of Uzbekistan. Personal data is processed lawfully, fairly and only for the purposes set out in this policy. We collect only the data necessary for these purposes, keep it accurate, do not store it longer than necessary, and protect it. We will not use data for a new purpose without first updating this policy and, where required by law, obtaining your consent.
1. Who we are
- "FLOTT" LLC (ООО «FLOTT»), TIN (STIR/INN): 312387381
- Address: Tashkent city, Sergeli district, Ezgulik Mahalla Citizens' Assembly (MFY), Sergeli-8A residential area, building 12, apartments 73, 74
- Email: info@flott.uz · Phone: +998 (71) 200-20-21
2. Our role
Flott is a software platform (SaaS) on which suppliers, buyers and banks/factoring companies exchange and approve invoices, documents and applications.
- For your account and technical data (login, contact, device and usage data), Flott determines why and how this data is processed.
- For business data uploaded to or exchanged on the platform (invoices, contracts, counterparty details, statements, documents), the purpose is determined by the organization that uploaded it (supplier, buyer or bank). That organization is itself responsible for having a legal basis, including the consent of the persons whose data is being uploaded. Flott processes this data on the organization's behalf and only to provide the Service.
- A bank / factoring company that receives your data through the platform processes it independently, in accordance with its own privacy terms and banking secrecy rules.
3. What data we process
3.1 Account and identification data
- Full name, email, phone number, job title, language
- Your and/or your organization's PINFL (JSHSHIR) and TIN (STIR/INN); the organization's name and your role in it
- Login credentials (passwords are stored only in hashed form)
- When you log in with an E-IMZO qualified electronic signature: certificate data (full name, PINFL, TIN, serial number, validity period)
3.2 Business and transaction data
- Invoices, contracts, acts and related documents, and the personal data in them (for example, the full names and PINFLs of signatories)
- The organization's bank details, factoring applications, limits, offers, payment history, statuses
- Files you upload (PDFs, images, scans), including the text of feedback submitted through the app and the images attached to it
- Electronic signatures and signature verification results
3.3 Data obtained from external sources
— through integrations, on a legal basis or with your consent, and only for the purpose of the requested operation:
- Tax data, credit reports (KATM, GRKI, CRIF), the factoring register of the Central Bank of Uzbekistan (CB), electronic document management operators, publicly available data
3.4 Technical data
- IP address, device type, operating system, app and browser version, language, time zone
- Logs and audit trail: date and time, account, role, action, object, result. We keep them for security and as proof of actions taken on the platform.
- Location at login and at transactions: if you grant permission, the approximate or precise location of your device at the moment you logged in or confirmed a transaction; if you do not grant permission, we record only an approximate location based on your IP address. We use it only for security, fraud prevention and as proof of the action.
- Error and performance reports
- Your device's push notification token (mobile app), used only to deliver notifications
- Usage analytics: we send only a pseudonymous user ID and role; we never send your name, email, PINFL or TIN.
- Data stored in the browser/app: session tokens (needed to keep you logged in), language and theme settings
3.5 Mobile app permissions
(The app may request the following permissions. Each permission is requested only when you first use the relevant feature; you may refuse it or turn it off later in your device settings, and the rest of the Service will continue to work.)
- Files, camera and gallery: to attach a file, image or scan to a document or to feedback. Only files you select or photograph are sent.
- Biometrics: to unlock the app with your fingerprint or face
- Notifications: alerts about applications, offers and status changes
- Network: communication with our servers
- Location (only while the app is open): we do not track your location in the background. If you do not grant permission, we use only an approximate location based on your IP address.
We do not collect your contacts or advertising identifiers, do not track your location in the background, and do not show ads. We use each permission only for the purpose stated above.
4. Why and on what basis we process data
- Creating and managing accounts, logging in, verifying E-IMZO signatures
- Providing platform features: document exchange, applications, notifications, integrations
- Sending applications and data to the bank or factor you choose
- Security, fraud prevention (including checking where logins and transactions are made from), incident investigation, logs and audit trail
- Compliance with laws (accounting, tax, AML/CFT, requests from authorities and courts)
- Support and communication about the Service
- Improving the Service based on anonymized and aggregated statistics
We do not sell personal data and do not use it for advertising. We may use anonymized, aggregated data that does not allow anyone to be identified for analytics and to improve the platform.
5. Consent
By registering, logging in or ticking the consent box, you consent to the processing described in this policy for the purposes above. Your consent remains valid while your account is active and until you withdraw it. You can withdraw it at any time by writing to info@flott.uz; after that, we will stop processing, except for data the law requires us to retain, and some features may stop working. You can withdraw consent to analytics in the mobile app with a single button in Settings.
If you upload data about other persons (employees, managers, counterparties), you confirm that you have the right to do so.
6. Who receives data
- Banks / factoring companies on the platform that you or your counterparty work with
- Your counterparties (supplier / buyer): only the data necessary for the transaction
- Government authorities and credit bureaus: CB, SOLIQ, KATM, GRKI, CRIF operators — as required by law or with your consent
- Service providers acting on our instructions under confidentiality obligations: hosting and infrastructure, file storage, error monitoring, product analytics, push notification delivery (Apple and Google services), electronic signature verification (E-IMZO), message delivery
- Courts and competent authorities upon lawful request
- Legal successors if Flott is reorganized, under the same protection
Service providers process data only on our instructions and only to provide the Service, and do not use it for their own purposes (advertising, profiling, sale).
7. Security
Encryption in transit (HTTPS/TLS), hashed passwords, role-based access control, separation of each organization's data, logging of access and actions, backups and an internal incident response procedure. If a breach affects your data, we will notify you and the competent authority as required by law. If your device is hacked or your passwords are stolen through your device, operations carried out in your name are your responsibility. Flott does not accept liability for operations carried out in your name. Protect your password, tokens and E-IMZO key.
8. Storage location and cross-border transfer
- In accordance with legal requirements, personal data of citizens of Uzbekistan is stored on servers located in the territory of the Republic of Uzbekistan.
9. Retention period
- While the account or contract is active.
- After that, for the period required by law for accounting, tax, banking and AML/CFT records (usually at least 5 years after the relationship ends).
- Logs and audit trail: 5 years, to prove actions and investigate incidents.
- After that, we delete or anonymize the data.
10. Your rights
Under the Law of the Republic of Uzbekistan "On Personal Data", you may:
- know that your data is being processed and obtain a copy;
- demand that your data be corrected, blocked or deleted (unless the law requires it to be retained);
- withdraw your consent;
- object to processing and file a complaint with the competent state authority for personal data protection or with a court.
Send requests from your registered email to info@flott.uz. We will respond within 30 days. If your data was uploaded by a bank or another organization, we may refer you to that organization.
11. Deleting your account
Write to info@flott.uz from your registered email. We will delete or anonymize your account after the retention periods above.
12. Children
The Service is intended for businesses and adults (18+). We do not knowingly collect data from children.
13. Changes
We may update this policy. The date at the top shows the latest version. We will announce significant changes in the app, on the website or by email. If you continue to use the Service after an update, you are deemed to have accepted it.
14. Contact
"FLOTT" LLC · info@flott.uz · +998 (71) 200-20-21 · Tashkent, Uzbekistan