Aironik

Aironik Privacy Policy

Last revised: September 26, 2026

This Privacy Policy (hereinafter the "Policy") describes the processing of personal data of users of Aironik, the application of the AI² platform for managing AI employees (hereinafter the "Service"), available as the "Aironik" mobile application for Android and iOS and as its web version at pwa.aironik.ai (hereinafter the "Application"), as well as of visitors of the aironik.ai website (hereinafter the "Website"). The Application has no data of its own: through it, users work with the data of the TwinCard and AI² Fans services and of the AI² account.

This Policy has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR), Directive 2002/58/EC (ePrivacy Directive) and Regulation (EU) 2024/1689 (EU AI Act) as regards the transparency requirements for artificial intelligence systems.

By using the Service, You confirm that You have read this Policy. If You do not agree with any provisions of the Policy, You should stop using the Service.


1. What this Policy governs

1.1. The Policy governs the processing of personal data by Private Company "New Reality" (hereinafter the "Operator", "We") in accordance with Articles 13 and 14 GDPR in respect of:

  • users - persons who have signed in to the Application with an AI² account and manage AI employees on behalf of a business (a company, individual entrepreneur or self-employed person) or on their own behalf, including human employees of businesses to whom access to AI employees has been granted;
  • visitors - persons who open the Website;
  • customers of businesses - persons who communicate with the AI employees of a business, to the extent that the Operator processes their data as a processor on behalf of the business (Section 2.3).

1.2. Aironik is the control center for AI employees of the AI² platform: AI models of AI² Fans and AI employees of companies from TwinCard. In the Application, the user sees the agents available to him or her and their conversations with customers in real time, gives agents rules and assignments, takes over a conversation and replies to the customer, receives orders and events from external systems in channels, works in groups with people and agents, calls an agent by voice, sends attachments, trains an agent on documents and receives push notifications.

1.3. The Policy applies to the aironik.ai Website and to the Application used in the international jurisdiction. The Application used in Russia and Kazakhstan is governed by the documents published on aironik.ru and aironik.kz respectively.

1.4. Aironik shows the data of Your services and saves in them what You do in the Application. The Application has no storage of its own: everything You do in Aironik (a reply to a customer, a rule for an agent, an upload to the knowledge base, a setting) is recorded in the data of the TwinCard or AI² Fans service. AI employees are created and configured in AI² Fans and TwinCard; the data of company pages and storefronts are also governed by the documents of those services. The Policy does not apply to third-party resources linked from the Service and to channels and systems connected by businesses themselves (for example, Telegram, websites and online stores of businesses).


2. Who processes the information

2.1. Data Controller

Private Company "New Reality" (New Reality Ltd)

New Reality Ltd is the operator of the TwinCard and AI² Fans services and of the AI² account in the international jurisdiction. The Application has no data and no controller of its own: through it, the data of these services and of the AI² account are processed, and everything You do in the Application is recorded in them.

2.2. Data protection contact

For all matters relating to the processing and protection of personal data, You may contact us:

  • Email: [email protected] - marked "Data Protection";
  • Postal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29 - marked "Data Protection Officer".

2.3. When the business is the controller

Businesses use the TwinCard and AI² Fans services, including through the Application, to work with their customers. In respect of the data that customers transmit to a business - in correspondence with AI employees and employees of the business, in attachments, in orders and events sent to channels by the business's own systems - as well as the data that the business uploads itself (knowledge base materials, voice samples), the business is the controller and the Operator is the processor acting on behalf of the business (Article 28 GDPR) under the terms of the Data Processing Agreement included in the user agreement of the service in which the AI employee was created.

If You are a customer of a business, information about the purposes and legal bases of the processing of Your data by the business is contained in that business's privacy policy; please address requests concerning Your data to the business. If You send such a request to the Operator, We will forward it to the business and help the business fulfil it.

2.4. Applicable law

Personal data are processed in accordance with:

  • Regulation (EU) 2016/679 (GDPR);
  • Directive 2002/58/EC (ePrivacy Directive) - as regards local storage and electronic communications;
  • Regulation (EU) 2024/1689 (EU AI Act) - as regards the transparency of artificial intelligence systems;
  • the applicable national legislation of the EU/EEA Member States.

3. Purpose of the Policy

3.1. The purpose of the Policy is to protect personal data against unauthorised access and disclosure and to fulfil the Operator's information obligations (Articles 13 and 14 GDPR).

3.2. The Policy sets out the list of data processed, the purposes and legal bases of processing, security measures, data recipients and international transfers, retention periods, the rights of data subjects, the permissions of the Application, and the use of artificial intelligence technologies.

3.3. The Operator does not permit processing incompatible with the purposes of collection or the processing of excessive data (data minimisation principle, Article 5(1)(c) GDPR).


4. What data are processed through the Application

The categories of data below are data of the AI² account and of the TwinCard and AI² Fans services that are available and can be changed through the Application. The roles of the Operator and of the business (controller or processor), the retention periods and deletion are the same as in the corresponding service.

4.1. Account data

To use the Application, You sign in with an AI² account. The account contains:

  • email address (used for sign-in and communication);
  • password (stored in hashed form, bcrypt algorithm);
  • name, username and country, as well as the telephone number, position and company name, if You have provided them;
  • security settings - information on whether two-factor authentication is enabled.

The AI² account is single for all applications of the AI² Platform: account data (name, email address, password, identifiers) are shared among the applications of the Platform, and the account has a single AI² balance.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

4.2. Agents, access and settings

  • Agents - the AI employees and AI models available to You, their names and @names, folders, pinned and muted conversations, read marks;
  • Access - Your role in respect of each agent (viewing, taking responsibility, changing rules, full control), granted by the owner of the agent;
  • Rules and assignments - the texts of instructions that You give to an agent for all conversations or for one conversation, assignment reports;
  • Agent settings - pause, work schedule and operating mode, the selected voice and the pronunciation dictionary;
  • API keys for connecting agents (stored only in hashed form).

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

4.3. Conversations of agents with customers (processing on behalf of the business)

The Operator processes, as a processor on behalf of the business:

  • customer messages and replies of agents in conversations on websites (widget), storefronts and other channels of the AI² platform, the customer's name as it is shown in the conversation, date and time;
  • takeover of a conversation - who took over the conversation and when, and the replies of the employee, which are marked as a human reply;
  • hints to the agent within a conversation, which the customer does not see;
  • conversation exports that You create; the export file is generated on request and transferred to Your device.

Clearing or deleting a conversation in the Application hides it in Your list; the conversation remains available to the customer and is deleted together with the data of the business (Section 8.3).

4.4. Channels and webhooks

Channels receive information from external systems that the business has connected itself (for example, orders from an online store). For each event, the following are stored: the title, the text, the full content of the event as sent by the external system, the sender and the links or telephone numbers attached to the event. The delivery log stores the status, the first 1,000 characters of the event and a hash of the sender's IP address; IP addresses and request headers are not stored in plain form. The content of events is determined by the business and its external system; the business is the controller of the personal data contained in them.

4.5. Groups

In groups, people and agents communicate together. The following are stored: the members and their roles in the group, messages and attachments, and the "Saved" section.

4.6. Voice calls to an agent

During a call, the audio of Your speech is transmitted to the Operator's servers, recognised by the Operator's own speech recognition service and deleted after recognition; call audio and call transcripts are not stored on the servers. The last lines of the call (no more than 12) are kept by the Application on Your device and sent with each request so that the agent keeps the context. The agent's reply is voiced by speech synthesis on the Operator's servers.

If You call Your personal AI assistant, the recognised text and the replies are saved in Your conversation with the assistant.

4.7. Attachments

  • Images - in conversations with customers and in groups;
  • voice messages - the file is stored, and its text is recognised by the Operator's own service; the agent receives only the text;
  • documents - the file is stored, and for the agent up to 6 pages are converted into images; text files are passed on as text;
  • video - only the audio track is used, for speech recognition.

Attachments are stored in the file storage of the Platform (Section 7.4).

4.8. Training an agent (knowledge base)

You can upload texts and files (TXT, MD, CSV, HTML, DOCX, ODT, PDF) to the knowledge base of an agent or company so that agents answer on their basis. Only the text extracted from the file is stored in the knowledge base on the Operator's servers; the original file is not kept. You can delete a material at any time. If the materials contain personal data of other persons, the business is responsible for uploading them.

4.9. Own voices

If a business creates an own voice, the person's voice sample and the recording of the consent phrase pronounced before the sample is recorded are processed. The sample is used exclusively for speech synthesis for the business's AI employees; no voice biometric templates for identifying a person are created. The business is the controller; the Operator processes the sample on behalf of the business. The person whose voice was used may withdraw consent by contacting the business or the Operator at [email protected]; in that case the voice is deleted.

4.10. Push notifications

  • push notification token of the device (where permitted);
  • notification settings - for an agent as a whole, for an individual conversation and for a channel; notifications about new customer messages are disabled by default.

A notification about a customer message contains the name of the agent, the name of the customer and the beginning of the message (up to 180 characters); a notification about an order, an appointment or a request for a human contains a brief summary of the event.

4.11. Payment data and the AI² Token

  • Wallet - AI² balance, transaction history (top-ups, debits, refunds);
  • App store purchase data - purchase identifier, product, store and status, if top-ups of the balance are available in the Application.

Important: the Operator does not store bank card data. Card details are entered on the side of the app store or the payment institution.

4.12. Technical data

  • IP address;
  • device data - device model, operating system, Application version;
  • interface language and time zone;
  • access logs - date and time of requests, requested addresses, response codes.

4.13. Data the Service does not collect

  • geolocation of the device;
  • the address book of the device;
  • biometric data for identification (face, voice biometric templates);
  • bank card details;
  • data of analytics and advertising trackers (such trackers are not used).

5. Legal bases and purposes of processing

5.1. Legal bases (Article 6 GDPR)

(a) Performance of a contract (Article 6(1)(b)): account and sign-in; the list of agents and access; rules, assignments and agent settings; conversations, takeover, channels, groups, calls, attachments and the knowledge base; the AI² balance; service notifications.

(b) Legal obligation (Article 6(1)(c)): accounting and tax records, retention of payment documents, responses to lawful requests from authorities, reporting of child sexual abuse material.

(c) Legitimate interest (Article 6(1)(f)): security of the Service, protection against spam, fraud and abuse, request rate limiting, handling of complaints, improvement of the Service on the basis of anonymised data. The Operator has carried out a Legitimate Interest Assessment; its results may be requested at [email protected].

(d) Consent (Article 6(1)(a)): push notifications in the Application; the use of the microphone and camera of the device (Section 11); own voices (the consent of the person whose voice is used).

Data of customers of a business processed on behalf of the business (Sections 4.3-4.5, 4.7-4.9) are processed on the legal basis determined by the business as controller.

5.2. Purposes of processing

  • Registration and sign-in - single sign-on to AI² applications, two-factor authentication;
  • Managing agents - the list of agents, access rights, rules and assignments, settings;
  • Working with customers - conversations, takeover, attachments, exports (on behalf of the business);
  • Channels and groups - receiving events from the business's systems, communication of people and agents;
  • AI employees - generation of replies according to the business's instructions and knowledge base, speech recognition and synthesis;
  • Notifications - push notifications about customer messages, orders, appointments and requests for a human;
  • Payments - topping up the balance, refunds;
  • Security - prevention of fraud, spam and abuse, child protection;
  • Improvement of the Service - analysis of anonymised statistics.

5.3. Data minimisation

The Operator collects only the data necessary for the stated purposes. The content of events in channels and of materials in the knowledge base is determined by the business; the Service allows the business not to transmit unnecessary information.

5.4. Summary table

Data categoryPurposeLegal basis (GDPR)
Account (name, email, password, country)Sign-in, communicationArt. 6(1)(b) - contract
Agents, access, rules, assignments, settingsManaging agentsArt. 6(1)(b) - contract
Conversations, takeover, channel events, group messages, attachments, knowledge base, voice samplesFeatures for the businessProcessing on behalf of the business (Art. 28) - legal basis determined by the business
Call audio (not stored)Speech recognition during a callArt. 6(1)(b) - contract
Push token and notification settingsNotifications in the ApplicationArt. 6(1)(a) - consent
Wallet, purchasesPayments, accountingArt. 6(1)(b) - contract; Art. 6(1)(c) - accounting
ComplaintsSecurityArt. 6(1)(f) - legitimate interest
Technical data, logsSecurity, protection against abuseArt. 6(1)(f) - legitimate interest

6. How we protect information

6.1. Organisational measures

  • restricting the circle of persons with access to personal data on the principles of least privilege and need to know;
  • confidentiality obligations for persons authorised to process data;
  • internal documents on data processing and protection, a record of processing activities (Article 30 GDPR);
  • data protection impact assessments (Article 35 GDPR) where required;
  • regular internal monitoring of compliance with GDPR requirements.

6.2. Technical measures

  • HTTPS/TLS 1.2+ for all connections;
  • bcrypt for password hashing; two-factor authentication at the user's option;
  • HMAC-SHA256 for signing inter-service requests (Mars LLM Service, payment gateways) and incoming webhooks;
  • access tokens with a limited validity period, verification of access rights to an agent on every request;
  • limiting the number of sign-in attempts and the rate of requests, protection against automated attacks;
  • storing API keys only in hashed form;
  • firewalling, access logs, timely software updates, backups;
  • data protection by design and by default (Article 25 GDPR).

6.3. Protection of payment data

The Operator does not store payment card data. Payments are processed through app stores and certified payment gateways (PCI DSS).

6.4. Incident response (Articles 33-34 GDPR)

In the event of a personal data breach, the Operator:

  • immediately takes measures to remedy its consequences;
  • notifies the supervisory authority within 72 hours where the breach is likely to result in a risk to the rights and freedoms of data subjects;
  • notifies data subjects without undue delay where there is a high risk;
  • notifies the business without undue delay where data for which the business is the controller are affected;
  • documents the incident and the measures taken.

7. To whom information is disclosed

7.1. General principles

The Operator does not sell or rent out personal data. Data are disclosed only in the cases described in this Section and to the minimum extent necessary. The Operator's processors are bound by data processing agreements (Article 28 GDPR).

7.2. The Operator's own language models (Mars LLM Service)

The replies of AI employees, including replies during calls, are generated exclusively by the Operator's own language models running on the Operator's servers, through the Operator's internal Mars LLM Service. A request to the model contains the text of the conversation, the rules and assignments of the agent, fragments of the knowledge base and the text of attachments; direct identifiers of the customer (email address, telephone) are not included in the request unless the customer has written them in a message himself or herself.

Conversation data, instructions, knowledge bases, attachments and voice data are not transferred to third-party providers of artificial intelligence services. The knowledge base is stored and indexed on the Operator's servers.

7.3. Speech recognition and synthesis

Speech recognition (calls, voice messages, the audio track of video) and voice synthesis (including with the own voices of businesses) are performed by the Operator's own services on the Operator's servers. These data are not disclosed to third parties.

7.4. Server location and hosting

Data are stored on the Operator's servers located in the data centres of hosting providers under contracts with the Operator. Attachments are stored in the Cloudflare R2 file storage. Hosting providers have no right to use the data for their own purposes.

7.5. Cloudflare

The aironik.ai website and the Platform's file storage operate through Cloudflare. Cloudflare processes, as a processor, the IP address and technical request data, as well as stored files, to the extent necessary to deliver pages and files and to protect against attacks.

7.6. Push notifications

To deliver notifications of the Application, Expo Push Service (650 Industries, Inc.), Google Firebase Cloud Messaging and the Apple Push Notification Service are used, and on Android devices without Google services, RuStore (VK LLC). They receive the device token and the text of the notification (Section 4.10).

7.7. App stores

When the balance is topped up in the Application, the payment is processed by Google Play or the App Store as an independent controller; the Operator receives only the purchase identifier and its status. Purchases are recorded through the RevenueCat service (RevenueCat, Inc.), which receives the account identifier, the product, the store and the status of the purchase.

7.8. NOVA

NOVA, the digital employee of the Operator, is added to the contacts of every user. Correspondence with NOVA is processed on the Operator's servers in the Republic of Kazakhstan.

7.9. Integrations connected by a business

On the instructions of the business, data are transmitted to recipients selected by the business: Telegram (if the business has enabled the relay of conversations to its Telegram), the addresses of the business's webhooks and external systems (including the reply to an event that requires confirmation), systems connected by the business's API keys, and the business's websites on which the widget is installed. These recipients process the data in accordance with their own rules and under their contracts with the business.

7.10. Businesses and their employees

Conversations, channels and groups of an agent are visible to the owner of the agent and to the employees to whom the owner has granted access, within the limits of that access. The customer sees the replies of the agent and of the employee who has taken over the conversation.

7.11. Disclosure required by law

The Operator may disclose personal data upon a lawful request from competent authorities where there is an appropriate legal basis, and will inform the data subject of such a request unless prohibited by law. Information on confirmed child sexual abuse material is reported to the competent authorities as required by applicable law.


8. Retention period

8.1. General rules (Article 5(1)(e) GDPR)

Personal data are kept no longer than required by the purposes of processing, after which they are deleted or anonymised.

The data listed below are data of the TwinCard and AI² Fans services: they are kept and deleted according to the rules of the corresponding service and, in any case, are erased when the AI² account is deleted in its entirety.

8.2. Retention periods by category

Data categoryRetention period
AccountAccording to the rules of the AI² account; after the deletion of the entire AI² account - Section 8.3
Agents, access, rules, assignments, settingsAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Conversations of agents with customersAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Channel events and the delivery logAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Group messagesAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Call audio and call transcriptsNot stored: audio is deleted after recognition
AttachmentsAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Knowledge baseAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Voice samples and own voicesAccording to the rules of the TwinCard or AI² Fans service; erased at the latest when the entire AI² account is deleted
Push tokenUntil sign-out of Aironik on the device, withdrawal of the permission or deletion of the entire AI² account; a token not used for 60 days is deleted
Wallet, purchases, payment documentsPeriod established by tax and accounting legislation
ComplaintsPeriod of review and of the establishment, exercise or defence of legal claims
Access logs6 months

8.3. Account deletion

You can delete Your account:

  • in the Application: "Settings" → "Account deletion" → "Delete account";
  • by writing to [email protected] from the address with which the account is registered (reply within 30 days).

There is one AI² account for all applications of the Platform. Aironik has no storage of its own; therefore, in the deletion item You choose what to delete:

  • "Sign out of Aironik on this device" - only the Application's push notifications on this device and the session are deleted; nothing is erased, and the services and the AI² account remain;
  • "Delete TwinCard" or "Delete AI² Fans" - the service is deleted according to its rules: it is closed immediately, signing in to the service within 30 days cancels the deletion and returns everything it hid, and after that the data of the service are erased, except payment records kept as required by law;
  • "Delete the entire AI² account" - according to the procedure below.

A request by email to [email protected] is handled in the same way (a service or the entire AI² account). Deleting the Aironik app from the phone does not erase anything.

Procedure for deleting the AI² account in its entirety:

  1. Immediately after the request, the AI² account is hidden, Your agents stop replying to customers, Your company pages are unpublished, and push notifications stop.
  2. 30 days - cancellation period: signing in to the account during this time and confirming the restoration cancels the deletion and restores the account together with everything that the deletion hid: company pages are published again, agents are switched back on and companies are active again.
  3. After 30 days the data are erased completely, without a separate request, except the data that the law requires to be retained (see "Retained" below); the erased data cannot be recovered.
  4. Deletion in the services. A company, a company page, an AI employee or a model can also be deleted in TwinCard or AI² Fans themselves, without deleting the AI² account; such deletion is governed by the documents of those services.

Erased: the profile and account data; agents, their rules, assignments and settings; knowledge bases; own voices and voice samples; conversations of agents with guests of websites; channel events, webhooks and the delivery log; groups that You own, and folders; attachments; company pages and business data; integrations and API keys. The text of the messages You have sent to other users is replaced with a note on erasure; the replies of agents in conversations with signed-in users are anonymised.

Retained: wallet transactions, orders, invoices and payment information - for as long as the law requires (contact details in orders are deleted); anonymised statistics, which do not constitute personal data.

You can delete an individual material from the knowledge base, a webhook or an own voice without deleting the account.


9. International data transfers

9.1. General principles (Chapter V GDPR, Articles 44-49)

Data are transferred outside the EEA only where appropriate safeguards are in place.

9.2. Transfers outside the EEA

(a) The Operator and the Platform infrastructure:
• Data: all categories specified in Section 4, including processing by the Operator's own language models and speech services;
• Country of destination: the Republic of Kazakhstan (where the Operator is established) and the countries in which the Platform's servers are located;
• Safeguards: the Standard Contractual Clauses (SCC) adopted by Commission Implementing Decision (EU) 2021/914, and the measures set out in Section 6.

(b) Single sign-on to AI² applications:
• Data: account data (name, email address, password hash, identifiers, country);
• Country of destination: the countries in which the Platform's servers are located in other jurisdictions;
• Basis: the transfer is necessary for the performance of the contract - single sign-on to the applications of the Platform (Article 49(1)(b) GDPR), together with the safeguards under Article 46 GDPR.

(c) Cloudflare, push notification services, app stores and RevenueCat:
• Data: technical request data and stored files; the device token and the text of a notification; the account identifier and purchase data;
• Safeguards: SCC, the EU-U.S. Data Privacy Framework (for participating U.S. providers).

9.3. Copies of safeguards

A copy of the safeguards applied may be requested at [email protected].


10. Storage on the device and cookies (ePrivacy)

10.1. The aironik.ai Website does not use cookies or trackers.

10.2. The Application stores on Your device the sign-in token (so that You remain signed in), the interface language and theme, the notification settings and the last lines of a call during the call. These data are strictly necessary for the operation of the Application and are stored on the basis of the exemption in Article 5(3) of the ePrivacy Directive. Analytics and advertising trackers are not used.

10.3. When You sign out or delete the Application, these data are deleted from the device.


11. Permissions of the Application

The Application requests access to the functions of the device only when You use the corresponding feature, and works without it in other respects:

PermissionWhat it is used for
MicrophoneCalls to an agent, voice messages, recording an own voice
Camera and photosSending images and documents
NotificationsPush notifications (Section 4.10)

You can withdraw a permission at any time in the settings of the device. The Application does not request access to geolocation or to the address book.


12. Special categories of personal data (Article 9 GDPR)

12.1. The Service does not request special categories of personal data from users and does not use them for advertising or ranking.

12.2. The Service does not carry out biometric verification and does not create biometric templates for identification. Voice samples are used only for speech synthesis (Section 4.9); call audio is used only for speech recognition and is not stored (Section 4.6).

12.3. A business may not upload special categories of data to the knowledge base or transmit them to channels without a lawful basis. If a customer discloses such information on his or her own initiative in correspondence with a business, the business processes it as controller; the Operator processes it only on behalf of the business for the purposes of operating the correspondence.


13. Your rights (Articles 15-22 GDPR)

To exercise Your rights, please contact [email protected] (marked "Data Protection") or the postal address set out in Section 2.2. A reply is sent within one month (Article 12(3) GDPR), which may be extended by a further two months where necessary. Requests concerning data for which the business is the controller are forwarded by Us to the business (Section 2.3).

13.1. Right of access (Article 15)

You have the right to obtain confirmation of processing and a copy of Your data, as well as information on the purposes, categories, recipients, retention periods, sources, international transfers and automated processing.

13.2. Right to rectification (Article 16)

You can rectify most data Yourself in the Application and in Your AI² account.

13.3. Right to erasure (Article 17)

You have the right to request the erasure of Your data where the grounds of Article 17 GDPR apply. The procedure for deleting the account and erasing data is set out in Section 8.3. The Operator may refuse to erase data whose retention is required by law or which are necessary for the establishment, exercise or defence of legal claims (Article 17(3)).

13.4. Right to restriction of processing (Article 18)

You have the right to request restriction of processing for the period during which the accuracy of the data is verified, where processing is unlawful, where the data are needed for legal claims, or pending the examination of an objection.

13.5. Right to data portability (Article 20)

You have the right to receive the data You have provided in a structured, commonly used and machine-readable format and to transmit them to another controller. Conversations can be exported in the Application (TXT, CSV, JSON); other data are provided upon request to [email protected] within the time limit established by Article 12(3) GDPR.

13.6. Right to object (Article 21)

You have the right to object to processing based on legitimate interest. You may object to direct marketing at any time; such processing then ceases.

13.7. Right to withdraw consent (Article 7(3))

Consent to push notifications and to the use of the microphone and camera may be withdrawn at any time in the settings of the Application or the device; withdrawal does not affect the lawfulness of processing before withdrawal.

13.8. Automated processing (Article 22)

The Service automatically generates replies of AI employees, recognises and synthesises speech and applies automated measures to protect against abuse. These processes do not take decisions producing legal effects concerning You; decisions to block are taken with human involvement. You have the right to obtain information about the logic involved, to contest the outcome and to obtain human intervention.

13.9. Complaint to a supervisory authority (Article 77)

You have the right to lodge a complaint with the data protection supervisory authority of the EU/EEA Member State of Your habitual residence, place of work or place of the alleged infringement. List of supervisory authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en


14. AI transparency (EU AI Act)

14.1. General provisions

AI employees are labelled in the Service as artificial intelligence. An AI employee is not a human being; its replies, including voiced replies, are generated automatically by software. When an employee takes over a conversation, his or her replies are marked as a human reply. The business must inform its customers that they are communicating with AI (Article 50 EU AI Act), including in the channels that it connects itself.

14.2. AI systems in the Service

(a) AI employees (Mars LLM Service):
• Purpose: replies to customers on behalf of the business, replies to the user in a conversation and during a call;
• Technology: the Operator's own large language models on the Operator's servers; search of the knowledge base on the Operator's servers; no data are transferred to third-party AI providers;
• Input data: the text of the conversation, the rules and assignments, fragments of the knowledge base, the text of attachments;
• Limitations: replies may be inaccurate; the business is responsible for the instructions and for the information communicated by AI employees.

(b) Speech recognition and synthesis:
• Purpose: recognition of speech during calls and in voice messages, voicing of replies, including with the own voices of businesses;
• Transparency: voiced replies are a synthesised voice; an own voice is created only with the explicit consent of the person concerned; no biometric identification is performed.

(c) Recognition of documents:
• Purpose: converting pages of documents into images and extracting text so that the agent can take the attachment into account.

Not used: biometric identification, emotion recognition, personality assessment of customers.


15. Changes to the Policy and contact information

15.1. Changes

The Operator may amend the Policy in the event of changes in legislation, the features of the Service, the scope of data, the recipients or the security measures. The Operator gives notice of material changes on the Website, in the Application, by email or by push notification. Where processing is based on consent, renewed consent is requested in the event of material changes.

15.2. Entry into force

Changes take effect upon publication, unless another date is specified in them. If You do not agree, You may stop using the Service and delete Your account (Section 8.3).

15.3. Version archive and language

Previous versions of the Policy are available upon request. The current version is published at https://aironik.ai/privacy. The Policy has been drawn up in English; translations into other languages are provided for convenience, and in the event of discrepancies the English text prevails.

15.4. Contacts

Controller: Private Company "New Reality" (New Reality Ltd)
• Legal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
• Email: [email protected]
• Phone: +7 (747) 029-43-05

When contacting Us, please state Your name, the email address of Your account (if You have one), the substance of Your request and Your preferred means of contact.


Additional provisions

Age restriction. The Service is intended for persons who have reached the age of 18. The Operator does not knowingly collect data of minors; if the registration of a minor is detected, his or her account is deleted.

Consumer rights. If the user is a consumer within the meaning of applicable law, he or she retains the rights granted by the mandatory provisions of consumer protection law.

Anonymisation. The Operator may anonymise data for statistical purposes. Anonymised data do not allow the data subject to be identified and do not fall within the scope of the GDPR (Recital 26).

Non-discrimination. The Service does not permit discrimination on the basis of protected characteristics.


Private Company "New Reality" (New Reality Ltd)
BIN: 220440900016
Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
[email protected] | +7 (747) 029-43-05

Date of publication: September 26, 2026

How to delete your Aironik account