Ness Privacy Policy
Effective: 8 July 2026
1. Welcome to Ness' Privacy Policy
As a Service Provider, our handling of your personal data is governed by applicable data protection laws, including the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the applicable data protection and personal data protection laws of the Republic of Kazakhstan, and, where applicable, the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and any related implementing regulations.
We take your privacy and data protection seriously and are committed to processing your personal data in a lawful, fair, and transparent manner and ensuring it is kept secure. This Privacy Policy applies to individuals whose personal data we process in connection with the use of the NESS mobile application and related services (the "Service"), including users of the app and visitors to any associated digital platforms.
This Privacy Policy explains how NESS Chat (operated by DataGo LLP) ("we", "us", "our") collects, uses, stores, discloses, and protects personal data in connection with your use of the Service. For any privacy-related enquiries, you may contact us at: Email: Info@datago.kz.
2. Data Controller
For the purposes of applicable data protection law, DataGo LLP acts as the "data controller", meaning we determine the purposes and means of processing your personal data.
Data Controller
DataGo LLP (trading as NESS Chat)
Registered in: Republic of Kazakhstan
App Site: www.ness.chat
Contact Email: Info@datago.kz
Registered Address: Almaty, 17/1 Al-Farabi Ave., 5B, 050059
Company Registration Number: 221240017693
NESS operates and provides the Service through its mobile application and associated platforms (the "Service").
3. Applicable Legal Framework
Our data processing activities are governed by the following legal and regulatory frameworks, where applicable:
a. EU General Data Protection Regulation (EU) 2016/679 (GDPR);
b. UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (where applicable); and
c. Applicable Kazakhstan data protection laws.
We are committed to maintaining privacy and security standards consistent with internationally recognised best practices. Our internal policies, access controls, and security systems implement industry-standard safeguards, including encryption, access restriction, and ongoing monitoring. While no system is completely risk-free, we regularly review and improve our security measures to reduce risks of unauthorised access, alteration, disclosure, or destruction of personal data.
4. Who We Are
NESS ("we", "our", "us") is a technology company operating a wellness and self-reflection mobile application designed to support users with personal development tools, journaling features, AI-assisted reflection, and wellbeing tracking.
We are not a medical provider, healthcare organisation, therapy service, or clinical institution. We are committed to protecting your privacy and handling personal data lawfully, fairly, and transparently.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, you may contact us at: Email: Info@datago.kz
5. Your Consent
Where required under applicable data protection law, including Article 6(1)(a) GDPR, and Article 9 GDPR for special category data, you may provide explicit consent for the processing of your personal data when using the Service. By using the NESS mobile application and voluntarily submitting personal data, including Sensitive Wellness Data, you acknowledge and consent that:
a. your personal data will be processed for the purposes described in this Privacy Policy;
b. such processing may include automated analysis using AI systems;
c. Sensitive Wellness Data (including wellbeing-related information) may be processed on the basis of your explicit consent where required by law; and
d. You may withdraw your consent at any time, subject to legal or operational limitations, by contacting us at Info@datago.kz or deleting your account.
Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
6. What Personal Data We Collect
Users of the NESS Application ("Users")
When you register for or use the NESS mobile application, we may collect and process the following categories of personal data:
| Category | Examples |
|---|---|
| Account Information | Email address, username, account preferences, age verification, and authentication credentials |
| Sensitive Wellness Data | Journal entries, chat messages, prompts, reflections, mood tracking, emotional wellbeing information, responses to wellness questionnaires and self-assessment tools that you voluntarily provide through the Service. |
| Technical Information | Device type, operating system, application version, IP address, device identifiers, crash reports, diagnostics, and log information. |
| Usage Information | Feature usage, session activity, interaction history, analytics, and application performance data. |
| Safety Information | Automated safety flags, moderation events, and security logs generated to help maintain the integrity and safety of the Service. |
| Support Communications | Information you provide when contacting customer support or communicating with us regarding the Service. |
Sensitive Wellness Data is processed only for the purposes described in this Privacy Policy and in accordance with applicable data protection laws.
Visitors / Unregistered Users
When you access or interact with the NESS platform without creating an account, we may collect:
| Category | Examples |
|---|---|
| Technical data | IP address, device type, browser information, operating system |
| Usage data | Pages/screens viewed, interaction events, session duration |
| Cookie data | Tracking identifiers, analytics data, and session cookies (see Cookie Policy) |
7. How We Collect Personal Data
We collect personal data through the following methods:
a. Direct interactions – when you register an account, use the NESS application, submit journal entries, complete wellness assessments, or communicate with the Service (including Sensitive Wellness Data);
b. In-app usage – through your interaction with features such as chat, journaling tools, AI responses, wellbeing tracking, and settings within the application;
c. Communication with us – when you contact us via email, in-app support, feedback forms, or other support channels;
d. Third-party service providers – including infrastructure providers, analytics providers, cloud hosting services, notification services, and safety monitoring tools;
e. Automated collection technologies – including cookies (where applicable), SDKs, analytics tools, crash reporting systems, and device-level identifiers used to maintain security, performance, and functionality of the Service (further described in our Cookie Policy, where applicable).
8. Why We Use Your Personal Data and Our Lawful Basis
We process your personal data under applicable data protection laws, including the EU GDPR, Kazakhstan data protection laws, and the UAE PDPL (where applicable).
We rely on one or more of the following lawful bases: contractual necessity, legitimate interests, legal obligation, and explicit consent (particularly for Sensitive Wellness Data).
Users of the NESS Application
| Purpose | Lawful Basis | Details |
|---|---|---|
| Provide and operate the NESS Service | Contract | To enable core app functionality including AI chat, journaling, and wellbeing tools |
| Process Sensitive Wellness Data (journals, reflections, assessments, mood data) | Explicit Consent | Required due to the sensitive nature of wellness-related and emotional data |
| Generate AI-driven responses and personalised insights | Contract / Consent | To deliver wellness reflections, summaries, and AI-assisted interactions |
| Account creation and authentication | Contract | To create and manage your user account securely |
| Provide customer and technical support | Legitimate Interests / Contract | To respond to user queries and resolve technical or service issues |
| Safety monitoring and risk detection | Legitimate Interests / Legal Obligation | To detect potential distress signals, misuse, or security risks using automated systems |
| Service improvement and analytics | Legitimate Interests / Consent (where required) | To improve functionality, user experience, and system performance |
| Security and fraud prevention | Legitimate Interests | To protect users, systems, and prevent misuse or unauthorised access |
| Legal and regulatory compliance | Legal Obligation | To comply with applicable laws, lawful requests, and regulatory requirements |
| System notifications and service updates | Contract / Legitimate Interests | To communicate essential updates regarding the Service |
Non-Registered Users / App Visitors
| Purpose | Lawful Basis | Details |
|---|---|---|
| Operate and maintain the Service | Legitimate interests | To ensure app stability, performance, and availability |
| Usage analytics and performance monitoring | Legitimate interests / Consent | To understand how users interact with the Service and improve functionality |
| Security and abuse prevention | Legitimate Interests | To detect fraudulent activity, bots, or malicious use |
| Technical performance monitoring | Legitimate Interests | To identify crashes, bugs, and system errors for improvement |
| Cookie-based functionality (where applicable) | Consent | Where required by applicable cookie and tracking laws |
9. How Long We Keep Your Data (Data Retention)
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, and to protect our legitimate interests.
Retention periods are determined by considering:
| Data Type | Retention Period |
|---|---|
| Active user account data | Retained while the account is active and for up to 24 months after last meaningful activity, unless deletion is requested earlier |
| Sensitive Wellness Data (journals, chat, assessments, reflections) | Retained while account is active and for up to 24 months after last activity, unless earlier deletion is requested, subject to safety/legal retention exceptions |
| AI interaction data (chat history, prompts, responses) | Same as Sensitive Wellness Data retention policy |
| Transaction or billing data (if applicable in future monetisation) | Up to 6 years for legal, tax, and accounting compliance |
| Technical and diagnostic data | Typically up to 12–24 months, depending on security and performance requirements |
| Safety and risk-related logs | May be retained for longer periods (up to 5 years) where reasonably necessary for safety auditing, abuse prevention, or legal compliance |
| Analytics data | Typically 12–24 months, depending on provider configuration |
| Communication with support | Up to 3 years from last interaction unless required longer for legal or dispute resolution purposes |
Deletion and Anonymisation
After the applicable retention period:
a. personal data is securely deleted; or
b. irreversibly anonymised; or
c. Aggregated for statistical and analytical purposes where individual identification is no longer possible.
Where anonymisation is used, data is no longer considered personal data under applicable law.
10. Who We Share Your Data With
At NESS, we respect your privacy and are committed to handling your personal data responsibly and securely.
We do not sell, rent, or trade your personal data to third parties.
We share personal data only where necessary to operate, secure, and improve the Service, comply with legal obligations, or provide the functionality you request.
Our principal service providers include:
| Service Provider | Purpose | Data Processed |
|---|---|---|
| Microsoft Azure OpenAI Service | Provides AI-powered conversational responses, wellness reflections, summaries, and other AI-assisted features within NESS. | Chat messages, prompts, journal entries, wellbeing reflections, responses to wellness questionnaires, and limited technical information necessary to process your request. |
| Microsoft Azure | Cloud hosting, infrastructure, storage, and application security. | Account information, application data, technical data, and encrypted user content. |
| Amplitude | Product analytics and application performance monitoring. | Device information, usage analytics, session information, and application events. |
| OneSignal and/or Expo | Push notifications and service communications. | Device tokens, notification preferences, and technical identifiers. |
| Brevo | Transactional email communications and account notifications. | Email address and communication records. |
| Crisp | Customer support and user communications. | Support enquiries, account information, and communication history. |
| Apple App Store and Google Play | Application distribution and platform services. | Information processed in accordance with the applicable platform's privacy practices. |
Each service provider is engaged under contractual obligations requiring it to protect personal data, process it only for authorised purposes, maintain appropriate security measures, and comply with applicable data protection laws incorporated below.
All third-party processors:
a. Shall process personal data only on our documented instructions to comply with the United Arab Emirates (PDPL);
b. Are bound by written data processing agreements (DPAs);
c. Must act only on our documented instructions;
d. Are prohibited from using your data for their own purposes; and
e. Must maintain appropriate security and confidentiality standards.
NESS Chat mobile application uses carefully selected third-party service providers ("Sub-Processors") to support the operation, security, maintenance, and improvement of the Services. These providers may process personal data on our behalf and only in accordance with our documented instructions and applicable data protection laws. We maintain a current list of our Sub-Processors, including a description of the services they provide, which is available through our app site or upon request by contacting us at Info@datago.kz.
11. Artificial Intelligence Services
NESS uses artificial intelligence services provided through Microsoft Azure OpenAI Service to generate conversational responses, personalised wellness reflections, summaries, and other AI-assisted features.
When you use AI-powered functionality within the Service, the information you voluntarily submit, including chat messages, prompts, journal entries, wellbeing reflections, and responses to wellness questionnaires, may be transmitted to Microsoft Azure OpenAI Service for processing on our behalf. Limited technical information, such as session identifiers and device metadata, may also be processed where necessary to deliver the requested functionality.
Microsoft Azure OpenAI Service acts solely as our authorised service provider and processes personal data only on our documented instructions. We require Microsoft to implement appropriate technical and organisational safeguards and to provide a level of protection for personal data that is substantially equivalent to the level of protection required under applicable data protection laws and described in this Privacy Policy.
We do not permit Microsoft Azure OpenAI Service to use your personal data for its own marketing purposes or for any purpose unrelated to providing AI functionality to NESS.
You acknowledge that AI-generated responses are produced using automated technologies and may not always be accurate, complete, or appropriate. AI-generated content is provided for informational and wellness purposes only and should not be relied upon as medical, psychological, therapeutic, or professional advice.
12. International Data Transfers
International transfers of personal data may be carried out using appropriate safeguards permitted under applicable data protection laws, including:
a. Contractual data protection and data processing agreements with recipients of personal data;
b. Transfers to service providers that implement appropriate technical, organisational, and security measures to protect personal data;
c. Transfers made pursuant to adequacy determinations, regulatory approvals, or other legally recognised transfer mechanisms where available under applicable law; or
d. Other safeguards or transfer mechanisms permitted under the laws of the Republic of Kazakhstan, the United Arab Emirates, or any other applicable data protection framework.
Where required, we will take reasonable steps to ensure that personal data transferred internationally receives a level of protection substantially equivalent to that described in this Privacy Policy.
For further details on our transfer mechanisms, please see our Data Processing Addendum (DPA). The Ness (DataGo LLP) mobile application remains the Data Controller for personal data processed on its behalf and retains overall responsibility for ensuring that its sub processors comply with applicable data protection standards.
13. Your Rights under the GDPR/PDPL
Under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the data protection laws of the Republic of Kazakhstan, and, where applicable, the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), you are recognised as a data subject and are granted certain rights in relation to your personal data. These rights apply regardless of your nationality or place of residence, to the extent your personal data is processed under applicable law.
You may exercise your rights by contacting us at: Info@datago.kz
| Right | What It Means in Practice |
|---|---|
| Right of access | You may request confirmation of whether we process your personal data and obtain a copy of the personal data we hold about you (commonly known as a Subject Access Request). We will respond within one (1) calendar month, subject to applicable legal extensions. |
| Right to rectification | You may request correction of inaccurate or incomplete personal data. |
| Right to erasure | You may request deletion of your personal data where there is no legal, regulatory, or operational justification for its continued processing (also known as the "right to be forgotten"). |
| Right to restriction | You may request that we temporarily suspend processing of your personal data in certain circumstances, such as where accuracy is contested or processing is unlawful. |
| Right to data portability | Where applicable, you may request your personal data in a structured, commonly used, and machine-readable format for transfer to another service provider. |
| Right to object | You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, or freedoms, or where processing is required for legal claims. |
| Right to withdraw consent | Where processing is based on consent (including Sensitive Wellness Data), you may withdraw consent at any time. This does not affect the lawfulness of processing carried out before withdrawal. |
| Right to complain | You have the right to lodge a complaint with your local data protection authority, where applicable, a supervisory authority in the Kazakhstan region, or the UAE. |
To exercise any of your rights, please contact us at Info@datago.kz; we will respond within one calendar month of receiving your request. In complex cases we may extend this period by a further two months, in which case we will notify you. We will not charge a fee for responding to rights requests unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to respond.
14. Data Security
We take the security of personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, destruction, or damage.
In the event of a personal data breach, we will promptly investigate the incident, take appropriate measures to mitigate any risks, and comply with applicable legal notification requirements. Where required by the laws of the Republic of Kazakhstan, the United Arab Emirates, or any other applicable jurisdiction, we will notify the relevant regulatory authorities and affected individuals. Such notifications may include details of the breach, the data affected, potential consequences, and measures taken to address the incident, and recommended protective actions.
We will provide breach notifications only to the extent required by applicable law.
15. Children's Data
Our Services are strictly intended for individuals aged 18 years and above. We do not knowingly collect, request, or process personal data from anyone under 18 years of age in any jurisdiction. If we become aware that we have inadvertently collected personal data from a person under 18, we will take prompt steps to delete or anonymise such data, unless we are legally required to retain it.
If a parent or legal guardian believes that a person under 18 has provided personal data to us, they may contact us at Info@datago.kz. We will review the request, verify where necessary, and take appropriate action to remove the data in accordance with applicable law.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons. The latest version will always be available on this page and marked with its last updated date.
17. Contact Us
If you have any questions, concerns, or requests in relation to this Privacy Policy or your personal data, please contact us: Info@datago.kz