Privacy Policy for Personal Information of Spharma LLC
Version effective as of February 25, 2026, Tashkent
Introduction
This Privacy Policy (hereinafter — the “Policy”) has been developed by Spharma LLC (state registration Reg. #2435800, TIN: 311 243 300), hereinafter — the “Company”, “we”, “us”.
The Policy defines the procedures for the collection, processing, storage, use, and protection of personal data of users of the Spharma mobile application (hereinafter — the “Application”, the “Service”) in accordance with the Law of the Republic of Uzbekistan “On Personal Data” (ZRU-547 dated 02.07.2019).
Use of the Application constitutes the User’s unconditional consent to this Policy and the terms of personal information processing. If you do not agree with the terms, please refrain from using the Application.
1. User Information Processed by Spharma
1.1. Data Provided Voluntarily by the User
Provided during registration and use of the Service:
- Phone number — for registration and login via SMS code (OTP).
- Email address — when registering via e-mail (optional).
- First and last name — for profile personalization (optional).
- Date of birth — for personalized offers (optional).
- Gender — for personalized offers (optional).
1.2. Data Collected Automatically
Collected automatically during use of the Application:
- IP address — to ensure session security.
- Device type and name — for managing active sessions.
- Date and time of access — for session logging.
1.3. Loyalty Program Data
- Loyalty card number and unique identifier.
- Bonus points balance.
- Transaction history (bonus accruals and redemptions).
1.4. Security Data
IP addresses and device identifiers may be used to detect activities that violate legal requirements, as well as to prevent fraud and unauthorized access.
1.5. Information from Counterparties
We may receive transaction information from pharmacy network outlets in the course of fulfilling agreements under the loyalty program.
1.6. Data We Do NOT Collect
- Geolocation (GPS coordinates).
- Payment data (bank card numbers, account details).
- Medical information and prescriptions.
- Contacts, photos, and files from the device.
2. Purposes of Personal Information Processing
2.1. Principle of Minimality
The Company collects only necessary information and retains it no longer than required for the purposes of processing, unless otherwise stipulated by the legislation of the Republic of Uzbekistan.
2.2. Primary Purposes of Processing
| # | Purpose |
|---|---|
| 2.2.1 | Compliance with the legislation of the Republic of Uzbekistan |
| 2.2.2 | Registration, authentication, and identification of Users |
| 2.2.3 | Sending SMS verification codes |
| 2.2.4 | Managing User profile and settings |
| 2.2.5 | Operation of the loyalty program (bonus accrual and redemption) |
| 2.2.6 | Displaying personalized offers and recommendations |
| 2.2.7 | Ensuring security and preventing fraud |
| 2.2.8 | Improving the quality of the Application and user experience |
| 2.2.9 | Communication with Users, processing requests and inquiries |
| 2.2.10 | Protecting the legitimate interests of the Company |
3. Terms of Processing and Sharing Data with Third Parties
3.1. General Principles
Personal data processing is carried out in accordance with this Policy and the Company’s internal regulations. We do not sell Users’ personal data. Confidentiality of information is guaranteed.
3.2. Data Sharing Is Permitted in the Following Cases
- With the explicit consent of the User — under the terms provided by this Policy.
- SMS provider (Playmobile) — phone number and verification code for sending SMS messages. Data shared: phone number, message text.
- Pharmacy network outlets — loyalty card data and transaction information for bonus accrual and redemption upon purchase. Data shared: loyalty card identifier, transaction amount and type.
- In accordance with legal requirements — upon request from authorized government bodies in the manner prescribed by the legislation of the Republic of Uzbekistan.
- To protect the rights and interests of the Company — in case of the User’s violation of the Application’s terms of use.
All third parties are required to ensure the confidentiality and security of the data shared in accordance with the Law of the Republic of Uzbekistan “On Personal Data” (ZRU-547).
4. Protection of Personal Information
4.1. Organizational and Technical Measures
The Company takes necessary organizational and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, and distribution.
4.2. Applied Security Mechanisms
- Passwords are stored in encrypted form (bcrypt) and are never stored in plain text.
- Authentication is performed using JWT tokens with a limited validity period.
- Sessions automatically expire after 7 days of inactivity.
- All connections are secured with the HTTPS/TLS protocol.
- Data access is restricted and granted only to authorized personnel.
- Confidentiality mode and compliance monitoring are ensured by internal regulations.
4.3. Regulatory Framework
Personal data protection is carried out in accordance with the Law of the Republic of Uzbekistan “On Personal Data” (ZRU-547 dated 02.07.2019) and other regulatory legal acts.
5. User Rights
5.1. Modification and Deletion of Information
The User has the right to:
- Access their personal data through the profile section in the Application.
- Modify their personal data in the profile settings.
- Delete their account and associated data through the Application or by contacting spharma.uz@gmail.com.
- Withdraw consent to data processing by discontinuing use of the Application and deleting the account.
5.2. Right of Access to Information
In accordance with Art. 22 of the Law of the Republic of Uzbekistan “On Personal Data”, the User has the right to obtain the following information:
- Confirmation of the fact that personal data is being processed.
- Grounds and purposes of processing.
- Methods of data processing.
- Information about the data controller and persons who have access to the data.
- Composition of the data being processed and sources from which it was obtained.
- Processing and data retention periods.
- Information on cross-border data transfers.
Requests should be submitted in writing to spharma.uz@gmail.com. The request review period is 30 (thirty) days from the date of receipt, with the possibility of extension up to 60 (sixty) days if necessary.
5.3. Right to Object
The User has the right to withdraw their consent or raise objections to the processing of personal data on legitimate grounds by submitting a written request to spharma.uz@gmail.com. The User also has the right to file a complaint with the supervisory authority in accordance with the legislation of the Republic of Uzbekistan.
6. Minors’ Data
The Application is not intended for persons under 16 years of age. The Company does not knowingly collect personal data of minors. If we become aware that data has been provided by a person under 16 years of age, we will take measures to delete it immediately.
7. Cookies and Analytics
The mobile application does not use cookies. We do not use third-party analytics systems or advertising trackers.
8. Policy Changes
The Company reserves the right to modify and/or supplement this Policy by publishing the revised version. In the event of significant changes, we will notify Users through the Application. Continued use of the Application after the changes are published constitutes the User’s consent to the updated Policy.
Applicable law — the legislation of the Republic of Uzbekistan.
9. Contact Information
For questions related to this Policy, please contact:
- Company: Spharma LLC
- State registration: Reg. #2435800
- TIN: 311 243 300
- Email: spharma.uz@gmail.com
Appendix: Definition of Terms
- Personal data — any information relating to an identified or identifiable natural person (personal data subject).
- Personal data processing — any action (operation) or set of actions performed with personal data: collection, recording, systematization, accumulation, storage, clarification, use, transfer, anonymization, blocking, deletion, and destruction.
- User — a natural person who uses the Spharma Application.
- Service / Application — the Spharma mobile application providing access to the pharmaceutical catalog and the loyalty program.
- Loyalty program — a bonus program that allows Users to accumulate and use bonus points when making purchases at Spharma pharmacy network outlets.