AISAR
Privacy Policy
This policy explains what personal data the AISAR service collects, the purposes it is processed for, the territory where it is stored, who it may be disclosed to, how it is protected, and what rights data subjects have.
Revision of August 11, 2026
1. General provisions
This Privacy and Personal Data Processing Policy (the “Policy”) sets out how personal data of users of the AISAR cloud service, available at https://aisar.app and its related subdomains, is processed and protected.
The data operator is SINAPSYS LLP (ТОО «SINAPSYS»), BIN 191040022892, registered address: 55/4 Turan Ave., office 91, Astana, Republic of Kazakhstan, business address: 50/3 NP4 Turan Ave., Astana, Republic of Kazakhstan (the “Operator”).
The Policy is drawn up in accordance with the Law of the Republic of Kazakhstan “On Personal Data and Its Protection” and other regulations of the Republic of Kazakhstan.
Using the AISAR service constitutes the user’s agreement with this Policy. If the user does not agree with its terms, they should stop using the service.
The current revision of the Policy is permanently available at https://aisar.app/privacy.
2. What data is processed
Account data: last and first name, email address, phone number, company name, job title, interface language, and the password stored as an irreversible hash.
Subscription and billing data: the selected plan, payment history, amounts and dates of charges, invoices, electronic receipts and service acceptance acts, and the details of the legal entity or sole proprietor in the case of bank transfers.
Technical data: IP address, browser and operating system type and version, date and time of access, pages visited, cookies and web analytics data.
Communications data: messages, attachments and conversation metadata received by the service from the channels connected by the user (messengers, email, telephony), as well as call recordings and metadata where that functionality is enabled.
Bank card details are neither collected nor stored by the Operator — they are entered solely on the side of the payment organisation (section 6 of this Policy).
The Operator does not request or process special categories of personal data, or data of minors, unless expressly provided for by a separate agreement with the user.
3. Purposes of processing
Registering and authenticating the user and granting access to the functionality covered by the selected plan.
Performing the agreement concluded under the public offer: taking out and renewing the subscription, settling payments, and issuing invoices, receipts and service acceptance acts.
Sending service notifications: about upcoming and completed charges, changes to the terms, maintenance work and security incidents.
Providing technical support and handling user requests.
Keeping the service secure, preventing fraud and unauthorised access, and investigating incidents.
Improving the quality of the service and analysing anonymised usage statistics.
Sending informational and marketing messages — only where the user has given separate consent, which may be withdrawn at any time.
4. Roles of the parties for the user’s own customer data
In respect of the user’s account data and billing data, the Operator acts as an independent personal data operator.
In respect of personal data of third parties (the user’s own customers) received by the service through connected channels, the Operator acts on the user’s instructions and in the user’s interest, that is, as a processor of such data. The user determines the purposes and scope of processing, ensures that lawful grounds and consents are in place, and is responsible for the lawfulness of obtaining such data.
The Operator does not use the user’s customer data for its own purposes, does not disclose it to third parties other than as set out in section 6, and processes it only to the extent necessary for the service to function.
5. Storage territory and retention periods
Personal data is stored and processed on servers located in the territory of the Republic of Kazakhstan. The Operator does not store personal data outside the Republic of Kazakhstan.
Account data and communications data are kept for as long as the user’s account exists. Once the account is deleted, the data is erased or anonymised within no more than 90 calendar days, except for data that must be retained further by law.
Documents and records relating to settlements (invoices, receipts, service acceptance acts, payment records) are kept for the periods required by the tax and accounting legislation of the Republic of Kazakhstan.
Backups are held on servers in the territory of the Republic of Kazakhstan and are deleted once the established rotation period expires.
6. Disclosure to third parties
Card payments are accepted and processed by the payment organisation PayLink.kz LLP (ТОО «PayLink.kz»). Card details are entered on its secure payment page and are not passed to the Operator; the Operator receives only the authorisation result, the masked card number and the payment token used for recurring charges.
When the user uses connected channels (WhatsApp, Telegram, Instagram, Facebook Messenger and others), messages are exchanged through the infrastructure of the respective providers, which act as independent operators in respect of the data transmitted through them and follow their own privacy policies. By connecting a channel, the user accepts that provider’s data processing terms.
Personal data may be provided to state authorities of the Republic of Kazakhstan upon a reasoned request, in the manner and to the extent prescribed by law.
Otherwise the Operator does not transfer personal data to third parties, does not sell it and does not grant access to it for advertising purposes.
7. Security measures
Data is transmitted between the user’s device and the service over HTTPS using current TLS versions.
Passwords are stored solely as irreversible hashes; account access is protected by session tokens with a limited lifetime.
Employee access to personal data is granted on a least-privilege basis, separated by a role model and logged.
The Operator applies organisational and technical measures to protect data against unauthorised access, alteration, disclosure and destruction, including backups, network segmentation and security event monitoring.
Users are advised to use a unique password, not to share credentials with third parties, and to notify the Operator immediately of any signs of unauthorised access to their account.
8. Rights of the data subject
To obtain information about the fact of processing of their personal data, its composition, and the purposes and methods of processing.
To request that their personal data be amended, supplemented or corrected where it is incomplete, outdated or inaccurate.
To request that their personal data be blocked or deleted where it is processed in breach of the law.
To withdraw consent to the processing of personal data previously given, and to opt out of informational and marketing messages.
To exercise these rights, send a request to info@aisar.app from the email address provided at registration. Requests are handled within no more than 15 calendar days unless a different period is prescribed by law.
Withdrawing consent or deleting data required to provide the services may make further use of the service impossible.
10. Changes to the Policy
The Operator may amend this Policy. A new revision takes effect once published at https://aisar.app/privacy, unless the revision itself states otherwise.
Where the terms of personal data processing change materially, the Operator additionally notifies users by email or through their account.
11. Operator’s contact details
For any questions about personal data processing, exercising data subject rights or the content of this Policy, please use the details below.
SINAPSYS LLP (ТОО «SINAPSYS»)
BIN 191040022892
Registered address: 55/4 Turan Ave., office 91, Astana, Republic of Kazakhstan
Business address: 50/3 NP4 Turan Ave., Astana, Republic of Kazakhstan
Email: info@aisar.app
Phone: +7 700 855 00 55