Privacy Policy
Revised on · version 2.0
This Policy explains what data ТОО «QDEMY» (the “Operator”) receives when you use enot.gg, why it is needed, how long it is stored and who it is shared with. It covers the website enot.gg and the Telegram bot @enotggbot.
1. Who processes your data
- Operator: ТОО «QDEMY», БИН 180940009586, 010000, Республика Казахстан, г. Астана, район Есиль, пр. Қабанбай батыр, д. 53.
- Data protection contacts: @heIIo_stars or hello@enot.gg.
- Using the Service means you agree to this Policy. If you disagree with it, please do not use the Service.
2. What we collect
- Telegram account data when you sign in with Telegram Login or use the bot: numeric id, username, name, profile photo, interface language.
- Recipient details you enter: @username or Telegram account link, Steam login, transfer comment or memo, gift caption text.
- Order data: line of business, quantity, amount, currency, payment method, status, timestamps, change history.
- Payment data to the extent needed for settlement: transaction id and status from the payment provider and, for payouts, the payout details you provide.
- Technical data: IP address, browser type and version, device and screen parameters, referral source, on-page actions.
- Support conversations and bot messages, including attachments you send.
We do not request identity documents to place an order or to process a refund. If you send such data to support on your own initiative, it is used solely to handle your request.
3. Why we process it
- Placing, fulfilling and supporting orders, including re-delivery and recipient changes.
- Processing payments and payouts, reconciliation, accounting and tax records.
- Communication: order statuses, support replies, incident notifications.
- Fraud prevention: transaction checks, limits, anti-fraud rules, protection against automated attacks.
- Running the referral programme: tracking invitations and rewards.
- Service quality analytics and interface improvements.
- Compliance with applicable law and responses to lawful requests from authorities.
4. Cookies and analytics
We use two categories of cookies and similar technologies.
- Necessary — the authentication session, chosen language and theme, cart and order state, bot protection. The Service does not work without them, so they are always set.
- Analytics — set only after you consent in the banner; they help us understand how the site is used.
Analytics and service providers we connect:
- Yandex Metrica — traffic and behaviour statistics, including interface session recording.
- Microsoft Clarity — heatmaps and session recordings: pointer movement, clicks, scrolling. Loaded only if you consent to analytics cookies.
- New Relic — performance and error monitoring in the browser and on the server.
- GlitchTip (Sentry-compatible) — technical error reports.
- Yandex SmartCaptcha — form protection against automated requests; it receives the IP address and technical request parameters.
You can withdraw consent to analytics cookies by clearing site data in your browser — the consent banner will appear again. Withdrawal does not affect processing carried out before it.
5. Who we share data with
We share data only with parties without whom the service cannot be delivered, and only to the extent required:
- payment providers and payment systems — to accept payments and send payouts;
- Telegram infrastructure — to credit digital goods to the recipient;
- suppliers through which digital goods are delivered;
- hosting, monitoring and analytics providers listed in section 4;
- authorities — on the grounds and in the manner prescribed by law.
We do not sell data and do not share it for advertising. Processing, including storage, may take place outside your country of residence — on the servers of the Operator and its providers.
6. Retention
- Order, payment and payout records — for the period required by accounting and tax rules, typically up to 5 years from the transaction date.
- Authentication sessions — up to 30 days of inactivity.
- Technical logs — up to 90 days.
- Support correspondence — until the request is resolved and for as long as needed to handle possible claims.
After that data is deleted or anonymised. Individual records may be kept longer where required for fraud prevention or by law.
7. Security
- Access is limited to staff who need it for their work; order actions are written to a change log.
- Traffic between your device and the Service is protected with TLS encryption.
- We apply organisational and technical measures against unauthorised access, alteration and loss of data.
- No system guarantees absolute security: transmitting data over the internet always carries a risk that we work to minimise.
8. Your rights
- Find out what data about you is processed and for what purpose.
- Request correction, restriction or deletion of data that is incomplete, outdated or processed in breach of the rules.
- Withdraw consent where processing is based on it.
- Complain to the competent data protection authority.
Send requests to hello@enot.gg or to support @heIIo_stars. We reply within 30 days. To help us locate your data, include your Telegram account id or an order number. Data required to record completed transactions can only be deleted after the retention periods in section 6.
9. Users in Russia
If you are located in Russia, your personal data is processed with regard to Federal Law No. 152-FZ “On Personal Data”.
- Processing is based on your consent, expressed by using the Service and placing an order, and on the necessity of performing the contract to which you are a party.
- The data, purposes and retention periods are set out in sections 2, 3 and 6; the operations are collection, recording, structuring, storage, updating, use, transfer and deletion.
- The Operator is registered outside Russia, so processing involves cross-border transfer to the Operator’s country of registration and to the countries of its providers.
- Consent is withdrawn by writing to hello@enot.gg; after withdrawal we stop processing except where the law allows it to continue without consent.
10. Minors
The Service is intended for people over 18. We do not knowingly collect data from children. If you believe a minor has provided us with data, write to hello@enot.gg and we will delete it.
11. Changes to this Policy
We update this Policy when our processes or providers change. The current version is always published at enot.gg/privacy with its date and version number. Material changes are additionally announced in the interface.