Does this apply to you
GDPR is the European Union's data protection regulation. It follows the person, not the company: if you are in the EU or EEA, your rights hold even when the contractor sits in Kyrgyzstan.
PROlab LLC is registered in the Kyrgyz Republic. When we work with clients and users in Europe we hold to GDPR requirements — and below is how, without vague wording.
The role we act in
It depends on whose data it is, and the two roles must not be blurred.
Controller — for data you leave on our website: your request, our conversation, visit statistics. We decide the purposes and we answer for them. What exactly gets collected is in the privacy policy.
Processor — for your users' data inside the projects we build for you. There you set the purposes, we act on your instructions, and the boundaries are fixed by a data processing agreement (DPA).
What our processing rests on
- Lawfulness and transparency. Every collection has a basis and an explanation. No just-in-case fields in forms.
- Minimisation. The calculator asks for a name and a phone number — enough to call you back. We don't ask for your address, job title or company size.
- Limited storage. Data lives exactly as long as it is needed and is deleted when it stops being needed.
- Security. HTTPS, access granted per task, access revoked when the task ends.
Your rights and how to use them
- Access to your data — Art. 15.
- Rectification — Art. 16.
- Erasure, the right to be forgotten — Art. 17.
- Restriction of processing — Art. 18.
- Data portability — Art. 20.
- Objection to processing — Art. 21.
- Withdrawal of consent at any time — Art. 7.
An email to [email protected] from the address you gave us is enough. No form, no template request. We answer within 30 days, free of charge. If a request can't be fulfilled, we explain why and point to the provision instead of brushing you off.
Transfers outside the EEA
There is no European Commission adequacy decision for Kyrgyzstan, and we won't pretend otherwise. So transfers of EU data to us rest on Standard Contractual Clauses (SCC), included in the client contract. The same applies to our subcontractors.
The services this site uses are listed in the privacy policy: Google, Yandex, Anthropic and our own WorkSpace. Each has its own policy and its own transfer terms.
Subcontractors
Part of the team works remotely, and access to project data goes to named people, not to an abstract "team". Every employee and contractor has signed a non-disclosure agreement, and wherever European users' data is processed, a DPA on the same terms we give you.
Data Protection Officer
A dedicated Data Protection Officer under Art. 37 is not mandatory for every company, and we don't have one — we don't meet the criteria. Data protection duties sit with company management. In practice that means an email to [email protected] reaches someone who can decide, rather than a support queue.
If a breach happens
For an incident that threatens people's rights we notify the supervisory authority within 72 hours, as Art. 33 requires. Where the risk is high we tell the affected people too, without waiting until the full scale is clear.
Complaints
If you believe we have infringed your rights, you may lodge a complaint with the data protection authority in the country where you live or work. But start with an email to us: almost everything is settled faster directly.
Contact us
Email: [email protected]
Phone: +996 553 04 02 07
PROlab LLC, TIN 01305202210073, 80 Yunusaliev Ave, Bishkek, Kyrgyz Republic.