All documents

Asterium App Privacy Policy

Revised on June 2, 2026

This Privacy Policy (hereinafter referred to as the “Policy”) of the Asterium mobile application (hereinafter referred to as the “Application”) applies to the information that JSC “Asterium” (hereinafter referred to as “Asterium”) may obtain from the user’s device during the use of the Application. 

Use of the Application constitutes the user’s unconditional consent to the processing of personal data in accordance with the legislation of the Republic of Uzbekistan, including the Law of the Republic of Uzbekistan “On combating the legalization of proceeds derived from criminal activity, financing of terrorism and financing of the proliferation of weapons of mass destruction”, the “Internal control rules on Combating the legalization of proceeds derived from criminal activity, financing of terrorism and financing of the proliferation of weapons of mass destruction for persons engaged in activities involving circulation of crypto assets ”, the Law of the Republic of Uzbekistan “On Personal Data”, and other regulatory legal enactments governing the processing and protection of personal data, as well as consent to this Policy and the terms of processing of information and personal data specified herein, including data obtained from the user’s device. By providing personal data, the user confirms their full and unconditional consent to all types of processing, use, and transfer thereof as provided by personal data legislation, including cross-border data transfer. If the user disagrees with the Policy, the user should refrain from using the Application. 

This Policy applies only to the Asterium Application. Asterium does not control and is not responsible for information (or the consequences of its transfer) transmitted by the user to third parties if such transfer was carried out on third-party resources to which the user may access through links contained in the Application.

Asterium reserves the right to amend this Policy by publishing a new version of the Policy on the Application website. The user is solely responsible for independently reviewing the current version of the Policy.

1. The composition of information that may be obtained from the user and from the user’s device during use of the Application and the purposes for which it is collected (hereinafter referred to as “User Information”):

1.1. Depending on the category of the personal data subject, the Application may collect and process the following personal data:

1.1.1. For individuals:

§  Last name, first name, and patronymic;

§  Date and place of birth;

§  Taxpayer Identification Number or Personal Identification Number of an individual;

§  Citizenship information;

§  Permanent and/or temporary residence address;

§  Identification document details (document number and series, date of issue, and issuing authority);

§  Mobile phone number;

§  Email address and other contact information;

§  Financial data necessary for carrying out transactions;

§  Information on the source of funds;

§  Information regarding politically exposed person (PEP)/public official status (if applicable);

§  Crypto wallet address;

§  Information regarding transactions involving crypto-assets.

1.1.2. For individual entrepreneurs/sole proprietors:

§  All personal data specified in clause 1.1.1;

§  Information on state registration as an individual entrepreneur/sole proprietor;

§  Information on the types of activities carried out;

§  Information on licenses held for activities subject to licensing.

1.1.3. For legal entities:

§  Full and abbreviated company name;

§  State registration information: date, registration number, and name of the registering authority;

§  Taxpayer Identification Number;

§  Registered address (postal address);

§  Information on existing licenses: type of activity, license number and issue date, issuing authority, and validity period;

§  Identification data of the individual acting on behalf of the legal entity;

§  Information on founders (shareholders, participants) and their ownership interests/equity participation in the authorized capital;

§  Information on the amount of the registered and paid-up authorized capital;

§  Information on governing bodies (structure and composition);

§  Telephone numbers;

§  Personal data of beneficial owners in accordance with clause 1.1.1.

1.2. Other information and documents required by the legislation of the Republic of Uzbekistan, including those related to combating the legalization of proceeds derived from criminal activity, financing of terrorism, and financing of the proliferation of weapons of mass destruction.

1.3. Additional documents and information required for identification and verification procedures in accordance with applicable requirements. As part of the verification procedure, biometric identification of the user is carried out, including facial image capture and/or real-time image acquisition to confirm the user’s identity against the submitted documents. Biometric identification is performed using third-party service providers.

1.4. Information about the user device’s location (based on mobile operator network data and GPS signals). Purpose: informing the user, while using the Application, about additional services available depending on the user’s location.

1.5. Photographic images obtained using the device camera. Purpose: obtaining and using photographic images within the services implemented in the Application, including capturing images of payment documents, QR codes, and barcodes for recognition and use in money transfer operations within the Application.

1.6. Information about the operating system version and device model. Purpose: analysis of possible Application errors and improvement of Application performance. For analytical purposes, information about the operating system and device model may be transferred to third parties in anonymized form.

1.7. Information about the IP address and the user’s connection point address. Purpose: enhancing user security while using the Application and conducting financial transactions.

1.8. Information about SMS messages on the User’s device. Purpose: storage and use of SMS messages within the Application.

2. Terms of Processing of User Information

2.1. The processing of personal data includes: collection, systematization, storage, modification, supplementation, use, provision, dissemination, transfer, cross-border transfer, anonymization/depersonalization, and destruction of personal data.

2.2. Carrying out audio and/or video recording of communications with the user, including recording of correspondence, and storing such information for at least 5 years.

2.3. The user agrees that Asterium is entitled to process personal data both with the use of automated means and without the use of such means.

2.4. The user agrees that Asterium may transfer the user’s personal data to the following persons/entities:

2.4.1. The authorized body — the National Agency for Perspective Projects of the Republic of Uzbekistan;

2.4.2. The specially authorized state authority in the field of combating the legalization of proceeds derived from criminal activity, financing of terrorism, and financing of the proliferation of weapons of mass destruction;

2.4.3. Law enforcement authorities and other state authorities in cases provided for by legislation of the Republic of Uzbekistan;

2.4.4. Financial, banking, payment, and other organizations for the purpose of conducting money transfer transactions within the Application.

2.4.5. Third parties in cases provided for by the legislation of the Republic of Uzbekistan and the public offer.

2.5. The user — whether a resident and/or non-resident of the Republic of Uzbekistan, individual and/or legal entity — gives consent to the transfer of their personal data to the Authorized body, specially authorized state authority, law enforcement authorities, and other state authorities of the Republic of Uzbekistan in cases provided for by the legislation of the Republic of Uzbekistan, including in the event of a request for such information by the aforementioned bodies/authorities.

2.6. The period for processing the user’s personal data shall be determined by the term of the agreement with the user, as well as by the information retention periods established by the legislation of the Republic of Uzbekistan, but in any case not less than 5 years from the date of the user’s last transaction in the Application.

2.7. The user has the right to withdraw consent to the processing of personal data by sending written notice. In the event of withdrawal of consent to the processing of personal data, the Application shall cease providing services to the user. Asterium shall cease processing personal data, except where retention of personal data is required by the legislation of the Republic of Uzbekistan, including requirements regarding storage of information on user transactions for at least 5 years from the date of the user’s last transaction.

3. Confidentiality and Information Protection

3.1. Asterium undertakes to ensure the confidentiality of user information and not to disclose such information to third parties, except in cases provided for by the legislation of the Republic of Uzbekistan or this Policy.

3.2. Asterium, in cases provided for by the legislation of the Republic of Uzbekistan, is entitled to disclose user information to the Authorized body; the specially authorized state authority; law enforcement authorities; and other state authorities upon their request.

3.3. Asterium ensures the protection of the user’s personal data in accordance with the requirements of the legislation of the Republic of Uzbekistan on personal data.

3.4. All audio and video recordings of communications, as well as correspondence history, are stored strictly in accordance with the requirements of applicable legislation and internal security standards. Such information is used exclusively for the purposes of ensuring transaction security, resolving disputes, and complying with regulatory requirements. Asterium guarantees that such recordings are not used for any other purposes and are not transferred to third parties without the user’s explicit consent, except in cases expressly provided for by law and the public offer.

3.5. The user undertakes to maintain the confidentiality of their account credentials and not to transfer such data to third parties.

This document is the intellectual property of JSC “ASTERIUM”. Any copying, distribution, or use of this document, in whole or in part, without the written permission of JSC “ASTERIUM” shall be prohibited and punishable by law.

© JSC “ASTERIUM”, 2026

This document is published in its current version and updated by the legal team as changes occur.