Privacy Policy
Last updated: 27 March 2026 Β· Effective: 27 March 2026
This Privacy Policy explains how Prometeo Chain Systemkz Ltd, operating the Ikarus Way logistics platform ("we", "us", "our"), collects, uses, stores, and shares your personal data when you use our website at www.ikarusway.com and the Ikarus Way platform (collectively, the "Service").
We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR), the Republic of Kazakhstan Law on Personal Data and Its Protection, and applicable data protection laws of the jurisdictions in which we operate.
1. Data Controller
Prometeo Chain Systemkz Ltd (trading as Ikarus Way) is the Data Controller responsible for your personal data.
Address: Astana Hub, 1 Expo Boulevard, Astana 010000, Republic of Kazakhstan
Privacy contact: [email protected]
General inquiries: [email protected]
2. Data We Collect
2.1 Account & Identity Data
- Full name (first and last name)
- Email address
- Phone number
- Profile photograph
- Driver's licence or passport number (required for drivers)
- Department and role within your organisation
- Cryptographic public key (linked to your blockchain identity)
2.2 Company & Business Data
- Company name and legal trading name
- Business registration number (BIN / INN or equivalent)
- Company address (country, city, street)
- Company type (Shipper, Carrier, Expeditor)
- Contact emails and websites
- Company description, rating, and review data
- Subscription plan and publication limits
2.3 Order & Shipment Data
- Cargo description, type, weight, dimensions, and volume
- Departure and arrival dates and times
- Pick-up, delivery, and intermediate checkpoint locations
- Loading and unloading types
- Incoterms and payment conditions
- Reference numbers, order notes, and attachments
- Special requirements (refrigerated, heavy, oversized)
2.4 Real-Time Location Data (GPS)
When a transport order is in progress, we collect GPS coordinates, speed, and heading from IoT tracking devices assigned to vehicles. This data is:
- Transmitted in real-time via secure WebSocket connections
- Visible to the relevant shipper, carrier, and expeditor parties of that order
- Stored for the duration of the order and the applicable retention period
2.5 IoT & Sensor Data
- Temperature and humidity readings (for cold-chain shipments)
- Device IMEI, model, MAC address
- Device configuration and frequency settings
- Light sensitivity flags
2.6 Vehicle & Fleet Data
- Plate number, VIN, truck brand and model
- Vehicle dimensions, load capacity, and body type
- Fuel type, maintenance dates, and mileage records
- Trailer specifications and certifications
- Vehicle photographs
2.7 Payment & Financial Data
- Payment method preferences
- Transaction amounts and currency
- Payment status and confirmation references
- Invoice data
Card and banking details are processed by our payment processor (Stripe). Ikarus Way does not store raw card numbers.
2.8 Documents & Files
- Company certification and licence documents
- Order attachments (bills of lading, manifests, proof-of-delivery)
- QR codes for order verification
2.9 Blockchain Records
Certain platform actions β including company activation, order publication, offer acceptance, and payment confirmations β are recorded as immutable transactions on the Prometeo Chain blockchain. Once written, these records cannot be altered or deleted. See Section 8 for further detail.
2.10 Technical & Usage Data
- IP address, browser type, and device information
- Pages visited, time on page, and scroll depth
- Referring website and UTM parameters
- Cookie and consent preferences
- API request logs with unique process identifiers
3. Legal Basis for Processing
| Processing Purpose | Legal Basis (GDPR Art.) |
|---|---|
| Providing platform services (account management, orders, tracking) | Art. 6(1)(b) β Performance of a contract |
| Company registration verification (BIN/INN) | Art. 6(1)(b) β Performance of a contract |
| Payment processing and invoicing | Art. 6(1)(b) β Performance of a contract |
| Compliance with legal obligations (tax, trade, audit) | Art. 6(1)(c) β Legal obligation |
| Blockchain recording for audit trail and regulatory compliance | Art. 6(1)(c) β Legal obligation / Art. 6(1)(f) β Legitimate interest |
| Analytics cookies, marketing pixels, session recording | Art. 6(1)(a) β Consent |
| Fraud prevention and platform security | Art. 6(1)(f) β Legitimate interest |
| Email and push notifications (transactional) | Art. 6(1)(b) β Performance of a contract |
| Marketing communications | Art. 6(1)(a) β Consent |
4. How We Use Your Data
- To create and manage your account and company profile
- To process and match transportation orders between shippers, carriers, and expeditors
- To provide real-time shipment tracking, temperature monitoring, and alerts
- To verify company registration numbers with official government APIs
- To process payments and generate invoices
- To send transactional notifications via email, push notifications, and Telegram
- To record key transactions on the Prometeo Chain blockchain for legal and audit purposes
- To improve the platform through analytics, A/B testing, and UX research
- To detect, prevent, and investigate fraud or security incidents
- To comply with applicable laws and regulatory requirements
5. Third-Party Services & Data Sharing
We share data with the following categories of third parties only where necessary for the purposes described in this Policy:
5.1 Analytics & Marketing (with your consent)
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google Tag Manager / Google Analytics 4 | Website analytics and user behaviour | policies.google.com |
| Google Ads (Conversion Tracking) | Ad conversion measurement | policies.google.com |
| Meta Pixel (Facebook / Instagram) | Ad targeting and retargeting | facebook.com/privacy |
| LinkedIn Insight Tag | B2B ad targeting and analytics | linkedin.com/legal |
| Microsoft Clarity | Heatmaps and session recording | privacy.microsoft.com |
All analytics and marketing tools are loaded only after you grant explicit cookie consent. You may withdraw consent at any time via the Cookie Settings link in the footer.
5.2 Platform Infrastructure
| Service | Purpose |
|---|---|
| Stripe | Payment processing |
| MinIO / IPFS | Secure file and document storage |
| Prometeo Chain blockchain | Immutable transaction ledger (public) |
| Hostinger SMTP | Transactional email delivery |
| Firebase Cloud Messaging (FCM) | Push notifications |
| Telegram Bot API | Order and app notifications |
| Apache Kafka / Redis | Message queuing and caching |
5.3 Government & Verification APIs
- Kazakhstan Statistics Bureau (stat.gov.kz) β BIN verification
- Dadata API (dadata.ru) β Russian INN/OGRN verification
We share only the minimum company registration number required for verification. No personal data is transmitted to these services.
5.4 Other Parties
We may disclose personal data to law enforcement, regulatory authorities, or courts where required by applicable law, or to protect the rights, property, or safety of Ikarus Way, our users, or third parties.
We do not sell personal data to third parties.
6. Cookies & Tracking Technologies
We use cookies and similar technologies on our website. Our cookie consent system is built on Google Consent Mode v2 β all analytics and marketing scripts are blocked by default until you grant consent.
| Category | Examples | Required? |
|---|---|---|
| Essential | Session authentication, CSRF protection, consent record | Yes (no consent needed) |
| Analytics | Google Analytics 4, Microsoft Clarity | No β consent required |
| Marketing | Google Ads, Meta Pixel, LinkedIn Insight Tag | No β consent required |
| Preferences | Language, UI state | No β consent required |
You can manage or withdraw your cookie preferences at any time by clicking "Cookie Settings" in the footer. Consent records are stored in your browser's localStorage and expire after 180 days.
7. International Data Transfers
Ikarus Way operates across Kazakhstan, Russia, and the United States. Your data may be processed in any of these jurisdictions. When data is transferred outside the European Economic Area (EEA), we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Your explicit consent
Blockchain data recorded on Prometeo Chain is stored in a distributed manner across multiple nodes globally and cannot be restricted by geography due to the technical nature of blockchain architecture.
8. Blockchain Records & Data Immutability
Important: Certain transaction records (company activation, order publication, payment confirmations) are written to the Prometeo Chain public blockchain. Once written, these records are immutable and cannot be deleted, even upon your request.
Blockchain records contain transaction hashes and smart contract codes β they do not contain your full name, email, or other directly identifiable personal data. However, if your public key is linked to your identity, transactional activity may be traceable.
By using the Ikarus Way platform and initiating transactions (creating orders, accepting offers, making payments), you acknowledge and accept the immutable nature of blockchain records.
9. Data Retention
| Data Type | Retention Period |
|---|---|
| Account and profile data | Duration of account + 3 years after closure |
| Order and shipment data | 7 years (commercial contract law requirements) |
| GPS and location data | 90 days after order completion |
| IoT sensor data (temperature, humidity) | 2 years after order completion |
| Payment and financial records | 7 years (tax and accounting obligations) |
| Document files (bills of lading, certificates) | 7 years or document expiry + 2 years |
| Analytics and usage data (cookies) | Up to 14 months (per Google Analytics defaults) |
| Consent records | 3 years |
| Blockchain records | Indefinite (technically immutable) |
10. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right of access β request a copy of the data we hold about you
- Right to rectification β correct inaccurate or incomplete data
- Right to erasure β request deletion of your data (subject to legal obligations and blockchain immutability)
- Right to restriction β ask us to pause processing of your data
- Right to data portability β receive your data in a structured, machine-readable format
- Right to object β object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent β for consent-based processing (e.g., analytics cookies)
- Right not to be subject to automated decision-making
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.
11. Data Security
- All data in transit is encrypted using TLS 1.2+
- Authentication uses JWT tokens with HMAC-SHA256 signatures
- Passwords are hashed; private keys are encrypted at rest
- Role-based access control (RBAC) limits data access to authorised personnel
- Every API request is logged with a unique Process ID for audit trail purposes
- File storage (documents, photos) is access-controlled via signed URLs
Despite our measures, no system is 100% secure. In the event of a data breach affecting your rights, we will notify you and the relevant authorities within the timeframes required by law.
12. Children's Privacy
Ikarus Way is a B2B platform intended for business use only. We do not knowingly collect data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact [email protected] and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated Policy.
Contact Us
For any privacy-related questions, data requests, or concerns:
Email: [email protected]
Post: Prometeo Chain Systemkz Ltd, Astana Hub, 1 Expo Boulevard, Astana 010000, Kazakhstan