9 October 2026
Privacy policy
This policy describes how Fitora CRM (https://www.fitora.kz) processes personal data, including data received from Meta when a school connects WhatsApp or Instagram. It follows the Law of the Republic of Kazakhstan of 21 May 2013 No. 94-V on personal data and its protection.
1. Operator
The operator of the Fitora CRM platform is CODEMASTERSPRO LLP, BIN 240140022429. Contact: https://www.fitora.kz or WhatsApp +7 771 685 2561.
This policy covers the website, the school workspace, and the official mobile apps. It does not replace a school’s own policy toward its pupils and parents.
2. Roles
Demo requests on the marketing site (name, phone, later WhatsApp messages): Fitora is the controller.
Staff login accounts and platform security logs: Fitora processes them to perform the contract with the school.
Pupils, parents, contracts, payments, attendance, and school conversations that the school enters or receives in the CRM: the school is the controller. Fitora processes that data only on the school’s instructions.
3. Data we process
Demo requests: the name and phone number the person submits, and the content of the follow-up WhatsApp conversation.
Staff accounts: name, email, role, organisation, and session identifiers.
School content: the contacts, documents, payments, schedule, and messages the school itself stores.
Meta Platform Data, only after a school admin connects WhatsApp or Instagram with Facebook Login: the Facebook user id of that admin, access tokens, the list of Facebook Pages they manage, the Page they confirm, the linked professional Instagram id and username, and Instagram Direct or WhatsApp messages delivered to that Page or number so staff can reply in Fitora.
4. Why
To provide the CRM the school paid for: one inbox for WhatsApp and Instagram, lead records from inbound messages, and staff replies on the same thread.
Fitora does not sell personal data and does not use a school’s message history for Fitora’s own advertising.
5. Meta data deletion
A person who connected Fitora with Facebook can remove the app in Facebook Settings → Apps and Websites, or ask Meta to delete the data Fitora received about them. Meta then calls https://www.fitora.kz/api/v1/meta/data-deletion with a signed request.
Fitora deletes the access token and the Facebook user id stored for that login and disconnects the WhatsApp or Instagram channel that login connected. The JSON response contains a confirmation code and a status URL: https://www.fitora.kz/en/meta/data-deletion?code=CONFIRMATION_CODE.
Conversations and records the school keeps in the CRM belong to the school. They are not erased by a Facebook user’s deletion request. The school owner asks Fitora to delete the organisation’s workspace.
6. Cookies
The workspace uses a necessary session cookie, fitora_session (HttpOnly, up to 14 days). The public site language is the URL (/ru, /kk, /en). The public site does not load Google Analytics, Yandex Metrica, or a Meta advertising pixel.
The Meta JavaScript SDK loads only when a school connects WhatsApp or Instagram in settings.
7. Retention and requests
Organisation data is kept while the school’s access is active, plus a short backup period. The owner can ask for deletion, usually within 30 days, except records the law requires us to keep longer.
Parents and pupils ask their school first. Staff and demo leads contact the operator at https://www.fitora.kz or WhatsApp +7 771 685 2561.