Privacy Policy
Effective Date: 22.04.2026 · Version 2.0
This Privacy Policy explains how AiSat ("we", "us", "our", the "Service", or the "Operator") collects, uses, stores, and shares personal data in connection with the website aisat.me and the AiSat platform.
1. Operator Identification
The Service is operated by:
- Legal name: Individual Entrepreneur 2147 (ИП 2147)
- Registration number (BIN / IIN): 930129350349
- Registered address: Astana, Yugo-Vostok (Pravaya Storona) microdistrict, Aynakol str., 56/1-65
- Contact phone: +7 707 368 7207
- Contact email: hi@aisat.me
- Working hours: Mon–Fri, 10:00–19:00 (Asia/Almaty)
We act as the data controller (Operator) for personal data of users and end customers processed through the Service.
2. Categories of Personal Data We Collect
2.1. Account and Registration Data
- Full name
- Email address
- Phone number (optional)
- Password hash and authentication tokens
- Preferred language and interface settings
2.2. Business Profile Data
- Business name, niche, description, FAQs, knowledge base content
- Uploaded documents, price lists, product descriptions
- Contact channels, message templates, AI agent configurations
- Voice model settings and voice samples (see Section 5)
2.3. Customer Communication Data
When you connect external channels (Telegram, WhatsApp, Instagram, web chat), we process data about the end customers of your business:
- Customer name and external identifier (Telegram chat ID, WhatsApp phone number, etc.)
- Text and voice messages exchanged through the Service
- Full webhook payloads from messaging platforms (may contain additional metadata about the customer)
- Conversation history, timestamps, delivery status
- AI-generated draft and sent replies
You, as the business owner, are responsible for obtaining consent from your end customers for processing their data via AiSat. We act as processor on your behalf for this category of data.
2.4. Payment Data
- Transaction identifiers, amounts, currency, status
- Subscription plan, billing period, renewal dates
- Invoice details
We do not store full card numbers, CVV codes, or bank credentials. Card data is processed directly by our payment providers (Paddle, Kaspi, or others listed in Section 4).
2.5. Referral, Promotional, and Partner Data
- Referral codes, partner identifiers, internal balance
- Promo codes used, referral and partner events, bonus payouts
- Public bio-page content (links, galleries, video) that you voluntarily publish
- Demo lead information (industry, revenue, team size) submitted via demo forms
2.6. Technical and Usage Data
- IP address, browser type, device and OS information
- Cookies and similar tracking technologies (see Section 9)
- Server logs, access logs, error reports
- Temporary audio cache for voice transcription (auto-deleted within 24 hours)
3. Purposes and Legal Basis for Processing
We process personal data to:
- Provide access to the Service and its features (contract performance)
- Authenticate users and prevent unauthorized access (legitimate interest, security)
- Generate AI replies, voice responses, and business assistant features (contract performance)
- Process payments and manage subscriptions (contract performance)
- Send transactional and service notifications (contract performance)
- Send marketing communications — only with separate opt-in consent (consent)
- Improve Service quality and develop new features (legitimate interest)
- Comply with legal obligations (tax, accounting, law enforcement requests)
- Detect and prevent fraud and abuse (legitimate interest)
4. Third Parties with Whom We Share Data
To provide the Service we engage the following processors. Each of them processes only the minimum data necessary for the specific function, under contractual data-protection obligations.
| Processor | Purpose | Data shared |
| Google LLC (Gemini API) | AI reply generation, funnel analysis | System prompts, conversation history, user messages |
| OpenAI, L.L.C. | Alternative AI reply generation | System prompts, conversation history, user messages |
| Groq, Inc. | Alternative AI inference and voice transcription (Whisper) | Messages, voice audio files |
| ElevenLabs, Inc. | Voice synthesis and voice model creation | Voice samples, generated audio, voice model IDs |
| Green API LLC | WhatsApp / Telegram messaging integration | Messages, phone numbers, attachments |
| Meta Platforms, Inc. | WhatsApp Business API (Graph API) | Phone numbers, OAuth tokens, messages, templates |
| Supabase, Inc. | Database hosting, authentication | All persistent application data |
| Vercel Inc. | Application hosting, edge functions, logs | IP addresses, request logs, application data in transit |
| Paddle.com Market Ltd | Payment processing (international) | Payment and billing information |
| Kaspi Pay | Payment processing (Kazakhstan) | Payment and billing information |
We may also disclose data to government authorities when required by law and to professional advisors (lawyers, auditors) bound by confidentiality obligations. We do not sell personal data.
5. Voice Data and Biometric Processing
Voice data may constitute biometric personal data under applicable law and is treated with heightened protection. Voice features are processed only with your separate, explicit opt-in consent.
When you use voice-related features:
- Voice samples you upload are used solely to create the voice model you requested and to generate synthesized audio within the Service.
- Voice samples and generated audio are transmitted to ElevenLabs for processing.
- You confirm that you own the voice being cloned, or you have obtained explicit, documented consent from the voice owner.
- You may delete voice models at any time from your dashboard.
- You may withdraw consent for voice processing by deleting your voice models and contacting support; after deletion, new samples will not be submitted to ElevenLabs.
6. Data Retention Periods
- Active account data (profile, knowledge base, conversations): for the entire period of your subscription and 30 days after account closure.
- Financial records (invoices, payments): 5 years, as required by tax and accounting law.
- Server and access logs: up to 90 days.
- Backups: up to 90 days on a rolling basis.
- Temporary audio cache: up to 24 hours.
- Voice models: until you delete them; otherwise for the period of your subscription + 30 days.
- Marketing consent records: until you withdraw consent + 3 years thereafter (to prove the basis of prior communications).
After the retention period, data is deleted or irreversibly anonymized.
7. Your Rights as a Data Subject
Subject to applicable law, you have the following rights:
- Right of access — request a copy of your personal data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to blocking (restriction of processing) — request temporary suspension of processing.
- Right to erasure — request deletion of your data, subject to legal retention obligations.
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object to processing based on legitimate interests or direct marketing.
- Right to lodge a complaint with the competent supervisory authority (in the Republic of Kazakhstan — Ministry of Digital Development, Innovations and Aerospace Industry / МЦРИАП РК, gov.kz/memleket/entities/mdai).
To exercise these rights, email hi@aisat.me. We will respond within 30 calendar days (or within a shorter period if required by local law).
8. International Data Transfers
Some of our processors (Google, OpenAI, Supabase, Vercel, ElevenLabs, Meta) store and process data outside the Republic of Kazakhstan, primarily in the European Union and the United States.
By registering and using the Service, you explicitly consent to the cross-border transfer of your personal data to these jurisdictions for the purposes described in Section 3. Where required by local law, additional protections (standard contractual clauses, data-processing addenda) are applied.
9. Cookies and Tracking
We use cookies and similar technologies to authenticate users, maintain sessions, remember preferences, and analyse service usage. You can manage or disable cookies in your browser settings; disabling essential cookies may prevent the Service from working correctly.
10. Security
We apply reasonable technical and organizational measures to protect personal data, including encryption of sensitive secrets (e.g., bot tokens), access controls, and encrypted connections (HTTPS/TLS). No method of transmission or storage is 100% secure.
11. Children
The Service is not directed to persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us for deletion.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via the Service or email at least 14 days before taking effect.
13. Contact
Data protection inquiries: hi@aisat.me
Website: https://aisat.me