Privacy Policy
How BonTarget collects, uses, stores, and protects data.
Effective date: 29 July 2026
This Policy sets out how personal data is processed when using the https://bontarget.com website, the BonTarget software service, related pages, Telegram bots, Telegram Mini App, administrative interfaces, forms and support channels.
The data operator is Individual Entrepreneur Ilgiz Khamzin, registered in Tbilisi, Georgia, individual entrepreneur identification number 302356402, operating under the commercial name BonTarget, hereinafter the Operator.
BonTarget is the commercial name of the Service and is not a separate legal entity.
1. DEFINITIONS AND SCOPE
1.1. The Service is the BonTarget software service for automating appointments and managing services, specialists, schedules, clients, bookings and related workflows.
1.2. A User is an individual, an independent professional, a self-employed person, an individual entrepreneur, a legal entity, an organisation or a representative thereof using the Service.
1.3. A User's Client is a person whose data is entered by the User or who uses booking tools provided by the User.
1.4. Personal Data means information relating to an identified or directly or indirectly identifiable individual.
1.5. Processing means any operation involving data, including collection, receipt, recording, organisation, storage, use, alteration, disclosure, restriction, deletion and destruction.
1.6. This Policy applies to website visitors, Users, their representatives and specialists, and User's Clients whose data is processed through the Service.
2. APPLICABLE LAW
2.1. This Policy is governed by the laws of Georgia, including applicable requirements of the Law of Georgia on Personal Data Protection.
2.2. Where mandatory rules of another jurisdiction apply to a particular person or operation, they apply to the extent that they are binding on the Operator and cannot be excluded by agreement.
2.3. This Policy supplements the License Agreement and the Limitation of Liability appendix.
3. ROLES OF THE OPERATOR AND USER
3.1. For User account, payment, support, security and contract performance data, the Operator independently determines the purposes and necessary means of processing within the law.
3.2. For User's Client data submitted or collected for appointment management, the User independently determines its purpose, selects the data and is responsible for a lawful processing basis. The Operator processes that data to provide the Service in accordance with User actions and settings and, to a limited extent, for security, compliance and protection of rights.
3.3. The User must give its clients the required notices, obtain consent where required and enable them to exercise their rights.
3.4. The Operator is not required to verify the lawful basis for every individual booking unless the law expressly requires such verification.
4. DATA THAT MAY BE PROCESSED
4.1. Account and identification data:
- first and last name;
- phone number and email address, if provided;
- Telegram ID, Telegram username and language;
- role, association with a business account and access information;
- data required for sign-in, action confirmation and session security.
4.2. User and business data:
- business name and description;
- country, city, time zone, address and location, if provided;
- contact details and public links;
- business category and service format;
- services, prices, duration and currency;
- specialists, their names, services, schedules, working hours, days off and absence periods;
- Telegram bot, notification and booking rule settings;
- other data entered by the User in Service fields made available to it.
4.3. User's Client and booking data:
- first and last name, Telegram ID, Telegram username and language;
- phone number and email, if provided by the User or client;
- selected service, specialist, booking date, time and duration;
- history of bookings, cancellations, rescheduling, completed visits and no-shows;
- service price and currency at the time of booking;
- address, coordinates and mobile-service details where needed for the selected scenario;
- comments, notes and preference information where entered;
- technical details concerning booking progress and notification delivery.
4.4. Subscription and payment data:
- pricing region and currency;
- selected number of specialists and quoted price;
- payment amount, date, purpose and status;
- payment identifier, link or confirmation;
- invoice, refund, dispute or duplicate-payment information;
- history of access provision and restriction.
4.5. The Operator does not state that it stores full bank card details. Such details may be processed by a bank or payment intermediary under its own rules. The Operator may receive only the information needed to confirm and account for payment.
4.6. Support and communication data:
- content of messages and support requests;
- attachments and details voluntarily supplied by the sender;
- communication channel, date, time and outcome;
- messages and notifications necessary to operate the Service and perform the contract.
4.7. Technical data:
- IP address and request date and time;
- device, browser, operating system and interface language information where transmitted;
- error, security and activity logs;
- account, session, request and device technical identifiers;
- referral source and attribution tags where actually transmitted;
- cookies, local storage and similar technologies necessary for sign-in, language selection, context retention, security and proper interface operation.
4.8. The exact amount of data depends on the features used. The Operator does not need to process every listed category for every person.
4.9. BonTarget does not continuously collect precise geolocation. An address or coordinates are processed only when the User or the User's Client submits them or uses an available feature for which those data are necessary.
5. DATA SOURCES
5.1. The Operator receives data:
- directly from the User or the User's Client;
- from the User's representative, specialist or employee;
- from Telegram when a person interacts with a bot or Mini App;
- from files imported by the User;
- automatically when the website and Service are used;
- from a bank or payment intermediary to the extent necessary to confirm payment;
- from infrastructure and security suppliers when diagnosing an event;
- from lawful public sources where needed to verify a request or protect rights.
5.2. The User confirms that it is entitled to transfer third-party data to the Operator and is responsible for its accuracy within the User's control.
6. PROCESSING PURPOSES
6.1. Data may be processed to:
- create and maintain an account;
- configure and operate a Telegram bot and Mini App;
- provide online booking and booking management;
- manage services, specialists, schedules and client information;
- send service notifications and reminders;
- provide an administrative interface;
- calculate prices, confirm payments and maintain accounting records;
- provide trial and paid access;
- respond to requests and provide technical support;
- detect errors, maintain security and prevent abuse;
- perform the contract and comply with law;
- establish, exercise and defend legal claims;
- improve the reliability, usability and quality of current Service features.
6.2. The Operator does not use data for incompatible purposes without another lawful basis.
7. LAWFUL BASES
7.1. Depending on the circumstances, processing may be based on:
- the need to enter into and perform a contract;
- steps taken at a person's request before entering into a contract;
- consent where required by law;
- compliance with the Operator's legal obligation;
- a legitimate interest in security, fraud prevention, Service support and protection of rights, where that interest is not overridden by the person's mandatory rights;
- other grounds available under applicable law.
7.2. Where processing is based on consent, withdrawal operates prospectively and does not make earlier processing unlawful.
7.3. A refusal to provide data required for a selected feature may make that feature or conclusion of the contract impossible.
8. THIRD-PARTY DATA AND USER DUTIES
8.1. The User is solely responsible for the lawful collection, use and transfer of data relating to its clients, specialists, employees and contractors.
8.2. The User must:
- collect only necessary data;
- inform persons that their data is transferred to BonTarget;
- ensure an appropriate lawful basis;
- keep data accurate and current;
- restrict staff access to what is necessary;
- handle its own clients' requests and cooperate with the Operator where needed.
8.3. The User must not upload unnecessary sensitive data without a genuine need and a lawful basis, including health information, biometric data, political opinions, religion, ethnic origin and other special categories.
8.4. If sensitive or excessive data is supplied without an Operator request, the Operator may restrict its processing, delete it or require the User to delete or correct the relevant record.
9. COOKIES AND LOCAL STORAGE
9.1. The website and Service interfaces may use technically necessary cookies, local or session storage and similar technologies.
9.2. They may be used for:
- authentication and session retention;
- protection against request forgery and abuse;
- retention of language and selected work context;
- proper interface operation;
- temporary retention of submitted information and recovery of an incomplete action;
- error diagnosis and Service protection.
9.3. This Policy does not state that any particular advertising or analytics platform is used. If an optional technology of that kind is introduced, information and a consent mechanism will be provided where required by law.
9.4. The User may restrict cookies through its browser, but essential sign-in, security and interface functions may stop working.
10. DATA DISCLOSURE AND SUPPLIERS
10.1. The Operator may disclose data only to the extent needed for the stated purposes to the following categories of recipients:
- Telegram, for bot and Mini App operation and message delivery;
- hosting, database, network and other technical infrastructure providers;
- email, notification, support and communications providers;
- banks and payment intermediaries selected for a particular payment;
- mapping or geocoding suppliers where the User uses an address or location feature;
- Operator employees and contractors who need access for support and operation;
- accountants, lawyers, auditors and other professional advisers;
- government authorities, courts and other persons where disclosure is required by law or needed to protect rights;
- a successor in connection with a transfer of the Service, rights or obligations in compliance with applicable law.
10.2. Recipients process data under a contract, the Operator's instructions or their own legal obligations, depending on their role.
10.3. The Operator does not sell personal data as an independent commodity.
10.4. When following an external link, a person must independently review that resource owner's terms.
11. INTERNATIONAL TRANSFERS
11.1. Because Telegram, infrastructure providers and other necessary contractors may operate in different countries, data may be processed outside the User's country and outside Georgia.
11.2. The Operator takes reasonable measures to ensure that an international transfer has a lawful basis and takes account of applicable data protection requirements.
11.3. This Policy does not guarantee that all servers are located or all data categories are processed in one particular country.
12. RETENTION
12.1. Data is retained for as long as necessary to provide BonTarget, perform the contract, comply with law, maintain accounting records, ensure security and resolve potential disputes.
12.2. In setting a period, the Operator considers the data type, account activity, potential claim periods, mandatory accounting and legal periods, fraud risk and technical need.
12.3. Once a purpose is fulfilled, data may be deleted, anonymised or isolated unless further retention is required by law or to protect rights.
12.4. Terminating access or deleting part of a profile does not mean immediate deletion of all payment, accounting, security and dispute records.
12.5. Data may remain temporarily in technical copies until scheduled overwrite. The Operator does not promise a particular backup schedule or retention period unless confirmed in a separate written term.
13. SECURITY
13.1. The Operator takes reasonable organisational and technical measures having regard to the nature of data, available technologies and risks.
13.2. Measures may include access controls, authority verification, session protection, logging of significant actions, software updates, redundancy and incident response.
13.3. No transmission or storage method provides absolute security. The Operator does not guarantee the complete absence of unauthorised access, errors, vulnerabilities or cyberattacks.
13.4. The User is responsible for the security of its Telegram account, devices, email, passwords and employee access. Suspicious activity should be reported to bontarget.team@gmail.com.
14. SERVICE AND MARKETING MESSAGES
14.1. The Operator may send messages required for bookings, account operation, payment, security, support and contract performance. Opting out of optional messages does not stop essential service notices.
14.2. Marketing messages are sent where the legal basis required by law exists. A recipient may opt out using the method stated in the message or by emailing bontarget.team@gmail.com.
14.3. The User is solely responsible for the lawfulness of messages it sends to its clients using the Service, including any required consent and opt-out mechanism.
14.4. Spam and unsolicited bulk messages are prohibited.
15. DATA SUBJECT RIGHTS
15.1. In the cases and manner provided by applicable law, a person may have the right to:
- obtain information about processing;
- request access to and a copy of data;
- correct inaccurate or incomplete data;
- request deletion or cessation of processing;
- restrict or object to processing;
- withdraw consent;
- receive data in a portable format where that right applies;
- lodge a complaint with a competent authority or court.
15.2. Rights are not absolute. A request may be limited where data is needed for legal compliance, accounting, security, protection of Operator rights or the rights of others.
15.3. Where a request concerns data entered by a particular User about its client, the Operator may direct the applicant to that User or involve the User in handling the request.
16. DATA REQUEST PROCEDURE
16.1. A request must be sent to bontarget.team@gmail.com. It should describe the request and provide details sufficient to locate the relevant account or record.
16.2. The Operator may request reasonable proof of identity, representative authority and the applicant's connection to the data. A request may remain pending until verification is completed.
16.3. The Operator reviews a written request within 15 calendar days unless mandatory law provides another period. Where objectively necessary, the applicant may be notified of a lawful extension.
16.4. The Operator may refuse a request in whole or in part where permitted by law and will explain the applicable basis.
17. DELETION, ANONYMISATION AND EXPORT
17.1. On a substantiated request and where the relevant right exists, the Operator may provide available information, rectify, delete or anonymise data within applicable law and technical feasibility.
17.2. Manual review may be required. This Policy does not guarantee a fully automated self-service export or deletion.
17.3. Payment details, accounting records, access history, security logs and dispute information may be retained where needed for compliance, fraud prevention or protection of rights.
17.4. Anonymisation may be irreversible. It may be impossible to restore the link between the data and a particular person afterwards.
18. CHILDREN AND LEGAL CAPACITY
18.1. A person independently entering into a contract to use BonTarget must have the necessary legal capacity.
18.2. If the User provides services to minors or enters their data, the User is solely responsible for involving a legal representative and establishing another lawful basis where required.
18.3. The Operator does not ask Users to enter children's data unless it is necessary for a real booking and has a lawful basis.
19. INCIDENTS
19.1. If an incident is identified, the Operator assesses its nature and takes reasonable measures to contain its effects and restore security.
19.2. The Operator notifies affected persons and competent authorities in the cases, manner and time limits required by applicable law.
19.3. A suspected incident should be reported to bontarget.team@gmail.com.
20. POLICY CHANGES AND SERVICE TRANSFER
20.1. The Operator may publish a new version of this Policy. Each version states its effective date and applies upon publication or from a later date stated in it.
20.2. Continued use after a new version takes effect may mean acknowledgement and acceptance of the updated processing arrangements to the extent permitted by law.
20.3. The Operator may communicate material changes by email or through the Service interface.
20.4. The Operator may transfer its rights and obligations, the Service and related data to a successor upon notice to Users and in compliance with applicable law.
21. DISPUTES AND APPLICABLE LAW
21.1. The parties shall first seek to resolve a dispute through negotiations.
21.2. A written claim must be sent to bontarget.team@gmail.com and is reviewed within 15 calendar days.
21.3. If no agreement is reached, the dispute shall be heard by a court in Georgia. This Policy is governed by the laws of Georgia.
21.4. Messages sent to the parties' email addresses may have legal effect. Mandatory legal provisions that cannot be excluded by agreement remain in force.
22. OPERATOR CONTACT AND DETAILS
Ilgiz Khamzin, Individual Entrepreneur Service commercial name: BonTarget Registration jurisdiction: Tbilisi, Georgia Individual entrepreneur identification number: 302356402 Website: https://bontarget.com Email for all data requests: bontarget.team@gmail.com
This version of the Privacy Policy is effective from 29 July 2026.