SAMI

Legal Centre

Сиёсати махфият

1. Who we are

SAMI-SM MCHJ (“SAMI”, “we”, “us”, or “our”) is an education consultancy based at Niyozbek Passage 3, 6a, Tashkent 100000, Uzbekistan. For the personal information described in this policy, SAMI normally acts as the data controller or equivalent responsible organisation.

Privacy and data-protection questions may be sent to our Data Protection Contact at info@sami.uz. If SAMI formally appoints a data protection officer or representative for a particular jurisdiction, the relevant contact details will be published here.

2. Scope

This policy applies to personal information processed through www.sami.uz, student.sami.uz and other SAMI portals, enquiry and application forms, consultations, events, messages, calls, social-media interactions, advertising campaigns, and education-application services.

It explains our practices under the Uzbekistan Law on Personal Data and, where their territorial scope applies, the EU General Data Protection Regulation (EU GDPR), UK GDPR and Data Protection Act 2018, applicable consumer-protection and electronic-commerce rules, and other relevant privacy laws.

3. Personal information we collect

Depending on how you interact with us, we may collect:

  • identity information, including name, date and place of birth, nationality, gender where relevant to an application, photographs, signatures, passport or identity-document details;
  • contact information, including address, email, telephone number, preferred language, social-media or messaging identifiers, and emergency or parent/guardian contacts;
  • education information, including schools, universities, qualifications, grades, transcripts, certificates, test results, academic history, references, study gaps, and intended field of study;
  • application preferences, including countries, institutions, courses, intakes, budgets, scholarships, accommodation, and career objectives;
  • application and immigration documents you choose or are required to provide, which may include passports, identity cards, civil-status records, financial evidence, sponsorship evidence, medical or disability information, criminal-record documents, visa histories, and correspondence with institutions or authorities;
  • portal information, including username, account status, password hash, verification status, uploaded files, tasks, messages, consent records, electronic signatures, and audit history;
  • service and payment information, including selected package, invoices, payment status, transaction reference, payer name, and refund records. SAMI does not intentionally store full payment-card details when payment is handled by a payment provider;
  • communications, including enquiries, emails, calls, appointment notes, chat messages, complaints, feedback, survey responses, and interactions with SAMI staff;
  • event and marketing information, including registration, attendance, campaign source, communication preferences, and responses to advertising;
  • technical information, including IP address where required for security or legal records, browser and device type, operating system, language, referral URL, pages visited, event timestamps, cookie identifiers, approximate location derived from network information, and security logs; and
  • inferences or service recommendations created from the information above, such as possible programme matches, application-readiness indicators, or support priorities.

We ask you not to provide information that is unnecessary for the service. Where application requirements involve sensitive or special-category information, we process it only where a lawful basis and any additional legal condition apply.

4. Information about other people

If you provide information about a parent, guardian, sponsor, referee, emergency contact, or another person, you must be authorised to do so and should direct them to this policy. We may contact them to verify information or perform the requested service where lawful.

5. How we collect information

We collect information directly from you, your parent or authorised representative, SAMI staff during consultations, website and portal use, institutions and service providers involved in an application, public or official sources, event partners, referral partners, and advertising or analytics platforms where permitted.

If information comes from another source, we use it only where the source may lawfully disclose it and our use is lawful, fair, and relevant.

6. Why we use personal information

We may use personal information to:

  • respond to enquiries and arrange consultations;
  • create, secure, and administer portal accounts;
  • assess stated study preferences and suggest potential institutions or programmes;
  • check document completeness and support application preparation;
  • communicate with universities, schools, pathway providers, scholarship bodies, accommodation providers, insurers, testing organisations, and other recipients at your request or as required for the service;
  • manage agreements, electronic signatures, payments, refunds, complaints, and customer support;
  • send operational notices, application updates, deadline reminders, and security alerts;
  • provide event registration and attendance services;
  • improve website content, service quality, staff training, analytics, and reporting;
  • detect misuse, fraud, security incidents, duplicate records, or unlawful activity;
  • comply with legal, regulatory, accounting, tax, audit, safeguarding, and dispute-resolution obligations; and
  • send marketing or measure advertising where consent or another lawful basis permits.

We do not sell student documents or personal information.

7. Lawful bases

The lawful basis depends on the purpose and the law that applies:

  • Contract and pre-contract steps: to answer a service request, create an account, prepare an application, administer an agreement, or provide a purchased service.
  • Consent: for optional marketing cookies, certain advertising, optional sensitive information, or another activity where the law requires consent. Consent can be withdrawn at any time without affecting earlier lawful processing.
  • Legal obligation: to meet applicable accounting, tax, consumer, court, regulatory, fraud-prevention, or data-protection duties.
  • Legitimate interests: to operate and secure our services, keep proportionate business records, improve support, prevent misuse, understand service performance, and communicate with existing users where those interests are not overridden by individual rights.
  • Vital interests or substantial public interest: only in limited circumstances where an applicable law permits or requires it.

Where EU GDPR or UK GDPR applies to special-category data, we also identify an Article 9 condition, such as explicit consent, legal claims, vital interests, or another condition available under applicable law.

8. Student documents

Student documents may contain extensive personal information and are handled for application and support purposes. Access is limited according to staff role and operational need. We may use document-scanning, optical character recognition, quality checks, and structured extraction to help identify fields or missing information.

Automated extraction can be inaccurate. Students and staff should review important data against the original document before submission. Original documents and extracted data may be shared with a selected institution or authorised service provider when needed for the application.

9. Artificial intelligence and automated tools

SAMI may use artificial-intelligence or automated tools to assist with document classification and extraction, translation, duplicate detection, programme matching, drafting, analytics, support routing, and service-quality checks.

These tools support staff and do not replace the independent decisions of universities, schools, scholarship providers, embassies, or visa authorities. SAMI does not intend to make a decision based solely on automated processing that produces legal or similarly significant effects on a student. Where applicable law gives you rights relating to such a decision, you may request human review, express your view, and challenge the result.

We apply access controls and data-minimisation measures and evaluate providers before personal information is submitted to an AI service. We do not permit providers to use confidential student documents to train general-purpose models unless a lawful, transparent arrangement and any required consent are in place.

For profile-photo moderation, SAMI may use automated face detection to check whether an uploaded image contains exactly one sufficiently visible human face. This check is used to enforce the profile-photo rules; it is not intended to identify the person or compare the face against an identity database. Staff may review, remove, replace, revert, or lock a profile photo as described in the Terms & Conditions.

10. Cookies, analytics, and advertising

The website uses essential technologies needed for security, sessions, preferences, and forms. With the required consent, it may also use analytics or advertising technologies such as Google Analytics, Google Ads, Meta/Facebook Pixel, Microsoft Clarity, and remarketing tools.

These services may collect device, browser, interaction, referral, cookie, and approximate-location information. Optional tools should not be activated before any consent required by applicable law. You can manage choices through the cookie controls and browser settings described in our Cookie Policy.

11. Who receives personal information

We disclose only information reasonably needed for the purpose. Recipients may include:

  • universities, colleges, schools, pathway providers, scholarship bodies, and their authorised admissions partners;
  • visa-support, translation, certification, testing, courier, accommodation, insurance, travel, or other providers selected by or supporting the student;
  • payment, banking, accounting, invoicing, and fraud-prevention providers;
  • cloud hosting, database, communications, email, SMS, customer-support, security, document-processing, analytics, advertising, and IT providers acting under appropriate terms;
  • professional advisers, auditors, insurers, mediators, arbitrators, and courts;
  • regulators, law-enforcement bodies, public authorities, or other persons where disclosure is required or permitted by law; and
  • a buyer, investor, or successor organisation during a genuine corporate transaction, subject to confidentiality and legal safeguards.

An institution receiving an application normally acts under its own privacy notice and may be an independent controller. Read the Third-Party Services Notice and the recipient’s own terms.

12. International transfers

International education applications necessarily involve information moving between Uzbekistan and countries where institutions, authorities, students, or service providers are located. Technology suppliers may also process information in other countries.

Where Uzbekistan law requires particular categories of personal information to be stored in Uzbekistan or a relevant database to be registered, we follow those requirements. Other storage or processing outside Uzbekistan is used only where a permitted condition applies, which may include an officially recognised adequate level of protection, compliant standard contractual terms or binding corporate rules, recognised international data-management standards, the individual’s consent, or another statutory ground.

Where EU GDPR or UK GDPR restricted-transfer rules apply, we use a permitted mechanism where required, such as an adequacy decision or regulation, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, binding corporate rules, or a specific lawful exception. We also consider supplementary technical and organisational measures and transfer risk where required.

No transfer mechanism removes our other duties of fairness, security, transparency, and data minimisation.

13. Data security

We use proportionate administrative, technical, and physical controls designed to protect personal information. These may include role-based access, authentication controls, encryption in transit, backups, monitoring, staff confidentiality, provider review, and incident-response procedures.

No online service is completely secure. You must protect portal credentials, use a secure device, and notify us promptly if you suspect unauthorised access. If a personal-data breach creates a legal notification duty, we will notify the relevant authority and affected individuals as required.

14. Retention

We keep information only as long as reasonably needed for the purpose, legal obligations, security, or disputes. Our retention schedule may vary by record and jurisdiction. As a general guide:

  • basic enquiries and consultation records may be kept for up to three years after the last meaningful interaction;
  • portal accounts may be retained while active and for up to two years after closure, unless linked to an application or required record;
  • application, agreement, consent, complaint, and service records may be kept for up to six years after the relationship ends where needed for legal claims, audit, or continuity;
  • accounting, invoice, and payment records are retained for the period required by applicable tax and accounting law;
  • routine security and access logs are normally retained for a shorter period, commonly up to twelve months, unless an incident requires longer retention;
  • marketing records are retained until consent is withdrawn, an objection is received, or the record is no longer needed, with a minimal suppression record retained to respect opt-outs; and
  • cookies and similar identifiers follow the periods stated in the Cookie Policy.

We may anonymise information so it no longer identifies a person and retain that anonymous information for statistics and service improvement.

15. Your rights

Depending on applicable law and the processing, you may have rights to:

  • be informed and receive transparent information;
  • request access to personal information and a copy;
  • correct inaccurate or incomplete information;
  • request deletion where no lawful reason for retention remains;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format;
  • withdraw consent at any time;
  • request human intervention regarding qualifying automated decisions; and
  • complain to a competent data-protection authority or seek a judicial remedy.

Rights can be subject to legal conditions and exceptions. We may ask for information needed to verify identity and protect records from unauthorised disclosure. We aim to respond within the period required by the law that applies.

16. Deletion and account closure

You may request account closure or deletion by contacting us. Closing an account does not automatically require deletion of every record. We may retain information needed for an active application, a legal obligation, fraud prevention, accounting, consent evidence, dispute handling, or legal claims. Where deletion is not available, we will explain the relevant reason where the law requires.

17. Marketing choices

You can unsubscribe through a message link or contact us. An opt-out applies to marketing, not essential service messages about an account, application, payment, security, or agreement.

Where marketing depends on consent, withdrawing consent is as easy as giving it and does not affect earlier lawful processing. Advertising platforms may provide their own preference and opt-out controls.

18. Children and minors

Our services may involve students who are under the age of legal majority. Where consent or a contract requires parent or guardian authority, we ask for that involvement and take reasonable steps to verify it. We use clear information appropriate to the student’s age and apply additional care to children’s information.

Parents and guardians should not create false adult accounts for children. They should provide accurate relationship and authority information.

19. Complaints and regulators

Please first contact our Data Protection Contact at info@sami.uz so we can investigate. You may also use our Complaints Procedure.

Where EU GDPR or UK GDPR applies, you may complain to the supervisory authority in the country of habitual residence, place of work, or alleged infringement. In Uzbekistan, you may contact the competent authority responsible for personal-data regulation. Nothing in this policy limits a right to seek a judicial remedy.

20. Changes to this policy

We may update this policy when services, providers, technology, or laws change. The current version is published here. If a change materially affects how existing information is used, we will provide any additional notice or choice required by law.

21. Contact

Data Protection Contact

SAMI-SM MCHJ

Niyozbek Passage 3, 6a, Tashkent 100000, Uzbekistan

Email: info@sami.uz