TwinCard — Privacy Policy. International Jurisdiction (GDPR)
Last revised: September 26, 2026
This Privacy Policy (hereinafter the "Policy") describes the procedure for the collection, processing, storage, transfer and protection of personal data of users and visitors of the TwinCard service, the AI² business platform (hereinafter the "Service"), hosted on the Internet at: twincard.ai (hereinafter the "Website"), as well as in the form of the "AI2 TwinCard" mobile application (hereinafter the "Application").
This Policy has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR), Directive 2002/58/EC (ePrivacy Directive) and Regulation (EU) 2024/1689 (EU AI Act) as regards the transparency requirements for artificial intelligence systems.
By using the Service, You confirm that You have read this Policy. If You do not agree with any provisions of the Policy, You should stop using the Service.
1. What this Policy governs
1.1. The Policy governs the processing of personal data by Private Company "New Reality" (hereinafter the "Operator", "We") in accordance with Articles 13 and 14 GDPR in respect of:
- users — persons who have registered an account in the Service and act on behalf of a business (a company, individual entrepreneur or self-employed person), including human employees of businesses;
- contact persons of businesses — persons whose data are stated in the information about a business, in express requests and in settlements;
- visitors — persons who open the Website, the catalogue, company pages and widgets, including without registration;
- customers of businesses — to the extent that the Operator processes their data as a processor on behalf of a business (Section 2.3).
1.2. TwinCard is a service for businesses: a company page in the TwinCard catalogue, the business structure, AI employees and human employees, communication with customers on the storefront, forms, documents, customer lists, integrations, promotion and advertising.
1.3. The Policy applies to the twincard.ai website and the "AI2 TwinCard" mobile application. Copies of company pages published on the TwinCard websites of other countries (twincard.ru, twincard.kz) are governed by the documents of the relevant websites.
1.4. The Policy does not apply to third-party resources linked from the Service, including the websites of businesses, the results of the "From the Internet" block and channels connected by businesses (for example, Telegram).
2. Who processes the information
2.1. Data Controller
Private Company "New Reality" (New Reality Ltd)
- BIN: 220440900016
- Legal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
- Email: [email protected]
- Phone: +7 (747) 029-43-05
- Website: https://twincard.ai
2.2. Data protection contact
For all matters relating to the processing and protection of personal data, You may contact us:
- Email: [email protected] — marked "Data Protection";
- Postal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29 — marked "Data Protection Officer".
2.3. When the business is the controller
Businesses use the Service to work with their customers. In respect of the data that customers and Visitors transmit to a business — in correspondence with AI employees and employees of the business, in forms and requests, and in documents — as well as the data that the business uploads itself (customer lists, deals, reports, voice samples), the business is the controller and the Operator is the processor acting on behalf of the business (Article 28 GDPR) under the terms of the Data Processing Agreement (Appendix 2 to the User Agreement).
If You are a customer or Visitor of a business, information about the purposes and legal bases of the processing of Your data by the business is contained in that business's privacy policy; please address requests concerning Your data to the business. If You send such a request to the Operator, We will forward it to the business and help the business fulfil it.
Company page information is published at the business's choice; the business is the controller in respect of the personal data contained therein.
2.4. Applicable law
Personal data are processed in accordance with:
- Regulation (EU) 2016/679 (GDPR);
- Directive 2002/58/EC (ePrivacy Directive) — as regards cookies, local storage and electronic communications;
- Regulation (EU) 2022/2065 (DSA) — as regards moderation and advertising;
- Regulation (EU) 2024/1689 (EU AI Act) — as regards the transparency of artificial intelligence systems;
- the applicable national legislation of the EU/EEA Member States.
3. Purpose of the Policy
3.1. The purpose of the Policy is to protect personal data against unauthorised access and disclosure and to fulfil the Operator's information obligations (Articles 13 and 14 GDPR).
3.2. The Policy sets out the list of data processed, the purposes and legal bases of processing, security measures, data recipients and international transfers, retention periods, the rights of data subjects, the use of cookies and local storage, and the use of artificial intelligence technologies.
3.3. The Operator does not permit processing incompatible with the purposes of collection or the processing of excessive data (data minimisation principle, Article 5(1)(c) GDPR).
4. What information we collect
4.1. Account data
At registration, You provide:
- country (determines the TwinCard website and the edition of the documents) and telephone number;
- status — company or natural person (individual entrepreneur, self-employed person);
- email address (confirmed with a code; used for sign-in and communication);
- password (stored in hashed form, bcrypt algorithm);
- name and position;
- company name, name and number of the tax identifier;
- selected cooperation options (company page, employees, advertising, etc.);
- security settings — information on whether two-factor authentication is enabled.
The AI² account is single for all applications of the AI² Platform: account data (name, email address, password, identifiers) are shared among the applications of the Platform, and the account has a single AI² balance.
Legal basis: performance of a contract (Article 6(1)(b) GDPR).
4.2. Express requests and contact persons of a business
- Express request — name, email address, telephone, business name, selected services and comment; used by the Operator's manager for communication and arranging services;
- contact persons — persons designated by the business for communication concerning the contract, settlements and moderation.
Legal basis: performance of a contract and pre-contractual steps taken at the data subject's request (Article 6(1)(b) GDPR); in respect of contact persons who are not party to the contract — the Operator's legitimate interest in performing the contract with the business (Article 6(1)(f) GDPR).
4.3. Information about the business and the company page
Name, description, mission, values, services and price list, address, contacts, logo and photographs, links, banners, business details (including the name of the legal entity and the tax number), countries of presence, change history and moderation decisions.
This information is information about the business and is published at the business's choice in the TwinCard catalogue and on the TwinCard websites of the selected countries of presence (Section 7.10). If it contains personal data (for example, the name of an individual entrepreneur, photographs of people), the business is responsible for publishing it.
4.4. Structure, employees and AI employees
- Business structure — departments, roles, positions and access rights;
- Human employees — account, role in the structure, access rights, actions in the business's Dashboard (activity log);
- AI employees — name, role, instructions and rules, knowledge base (texts and documents uploaded by the business), selected voice.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); activity log — legitimate interest in security and dispute resolution (Article 6(1)(f) GDPR).
4.5. Data of Visitors and customers of a business (processing on behalf of the business)
The Operator processes, as a processor on behalf of the business:
- correspondence on the storefront and in the widget — the Visitor's messages, replies of AI employees and employees of the business, date and time;
- contact details, reviews and enquiries left by the Visitor for the business;
- responses to forms and requests, the fields of which are determined by the business;
- documents sent by customers to the business (stored in private storage for 90 days);
- customer lists imported by the business (name, email address, telephone, Telegram username, external identifier), deals, reports and customer summaries generated by AI;
- invoices and payment requests issued by the business to a customer, and information on delivery arranged through the business's integration.
For guest correspondence without registration, a guest chat token is stored on the Visitor's device (Section 10) so that the conversation can continue when the page is reopened.
If the Visitor has signed in to the Service with an AI² account, the name from his or her account is used in correspondence with the business; the Visitor's subscriptions to company updates are stored in his or her account.
4.6. Own voices
If a business creates an own voice, the person's voice sample and the recording of the consent phrase pronounced before the sample is recorded are processed. The sample is used exclusively for speech synthesis for the business's AI employees; no voice biometric templates for identifying a person are created. The business is the controller; the Operator processes the sample on behalf of the business. The person whose voice was used may withdraw consent by contacting the business or the Operator at [email protected]; in that case the voice is deleted.
4.7. Integrations
Settings of the business's integrations: domains for the widget, API keys (stored in protected form), webhook addresses, connection of the business's Telegram bot, the business's CDEK keys, the business's payment acceptance settings, and integration call logs.
4.8. Search and advertising
- Search queries — the text of the query, country and language; stored without being linked to a user;
- Advertising statistics — impressions and clicks, indicating the viewer's country and language and the text of the query for which the advertisement was displayed; provided to the advertiser in aggregated form;
- Advertising campaigns — materials, budgets, display settings, moderation decisions.
4.9. Payment data and the AI² Token
- Wallet — AI² balance, transaction history (top-ups, debits, refunds);
- Orders and invoices — services, amounts, periods, payment statuses, renewals;
- Payment transactions — identifiers, amounts, currency, statuses;
- Details for bank transfer payment — the payer's name, tax number and bank details stated in the invoice or payment order;
- Digital activation codes and app store purchase data (purchase identifier and status).
Important: the Operator does not store bank card data. Card details are entered on the side of the payment institution or the app store.
4.10. Technical data
- IP address;
- User-Agent — browser, device, operating system, Application version;
- interface language and time zone;
- cookie and local storage data (Section 10);
- push notification token in the Application (where permitted);
- access logs — date and time of requests, requested addresses, response codes.
4.11. Data the Service does not collect
- biometric data for identification (face, voice biometric templates);
- bank card details;
- data of analytics and advertising cookies (such cookies are not used).
5. Legal bases and purposes of processing
5.1. Legal bases (Article 6 GDPR)
(a) Performance of a contract (Article 6(1)(b)): registration and account; company page, catalogue and publication in the countries of presence; structure, employees and AI employees; customer features and integrations; orders, AI² balance, renewal of services; service notifications.
(b) Legal obligation (Article 6(1)(c)): accounting and tax records, retention of invoices and payment documents, responses to lawful requests from authorities, reporting of child sexual abuse material.
(c) Legitimate interest (Article 6(1)(f)): security of the Service, protection against spam, fraud and abuse, request rate limiting, moderation and handling of complaints, the activity log in the Dashboard, aggregated search and advertising statistics, improvement of the Service on the basis of anonymised data, communication with contact persons of a business. The Operator has carried out a Legitimate Interest Assessment; its results may be requested at [email protected].
(d) Consent (Article 6(1)(a)): push notifications in the Application; the Operator's advertising mailings.
Data of customers and Visitors of a business processed on behalf of the business (Sections 4.5–4.6) are processed on the legal basis determined by the business as controller.
5.2. Purposes of processing
- Registration and sign-in — creation of an account, single sign-on to AI² applications, two-factor authentication;
- Company page and catalogue — publication of information about the business, moderation, search, publication in the countries of presence;
- AI employees — generation of replies according to the business's instructions and knowledge base, voicing of replies;
- Working with customers — correspondence, forms, documents, customer lists, summaries, invoices, integrations (on behalf of the business);
- Advertising and promotion — display of advertising, statistics for the advertiser;
- Payments — topping up the balance, payment for orders, invoices, renewal, refunds;
- Security — prevention of fraud, spam and abuse, moderation, child protection;
- Improvement of the Service — analysis of anonymised statistics.
5.3. Data minimisation
The Operator collects only the data necessary for the stated purposes. The scope of customer data collected through forms and integrations is determined by the business; the Service allows the business not to request unnecessary information.
5.4. Summary table
| Data category | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account (name, email, telephone, country, password) | Registration, sign-in, communication | Art. 6(1)(b) — contract |
| Company information, position, tax number | Identification of the business, invoices | Art. 6(1)(b) — contract; Art. 6(1)(c) — accounting |
| Express request | Communication and arranging services | Art. 6(1)(b) — pre-contractual steps |
| Contact persons of a business | Performance of the contract with the business | Art. 6(1)(f) — legitimate interest |
| Company page | Publication in the catalogue and countries of presence | Art. 6(1)(b) — contract |
| Structure, employees, AI employees, knowledge base | Operation of the Dashboard and AI employees | Art. 6(1)(b) — contract |
| Correspondence, forms, documents, customer lists, summaries, voice samples | Features for the business | Processing on behalf of the business (Art. 28) — legal basis determined by the business |
| Search queries (not linked to a user) | Search, statistics | Art. 6(1)(f) — legitimate interest |
| Advertising statistics | Reports to the advertiser | Art. 6(1)(f) — legitimate interest |
| Orders, transactions, invoices | Payments, accounting | Art. 6(1)(b) — contract; Art. 6(1)(c) — accounting |
| Complaints, moderation, activity log | Security, DSA | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) |
| Technical data, logs | Security, protection against abuse | Art. 6(1)(f) — legitimate interest |
| Strictly necessary cookies and local storage | Operation of the Service | Art. 5(3) ePrivacy — exemption; Art. 6(1)(f) |
| Push token | Notifications in the Application | Art. 6(1)(a) — consent |
| Email for the Operator's advertising | Advertising mailings | Art. 6(1)(a) — consent |
6. How we protect information
6.1. Organisational measures
- restricting the circle of persons with access to personal data on the principles of least privilege and need to know;
- confidentiality obligations for persons authorised to process data;
- internal documents on data processing and protection, a record of processing activities (Article 30 GDPR);
- data protection impact assessments (Article 35 GDPR) where required;
- regular internal monitoring of compliance with GDPR requirements.
6.2. Technical measures
- HTTPS/TLS 1.2+ for all connections;
- bcrypt for password hashing; two-factor authentication at the user's option;
- HMAC-SHA256 for signing inter-service requests (Mars LLM Service, payment gateways);
- access tokens with a limited validity period, verification of access rights on every request, segregation of rights within a business according to its structure;
- limiting the number of sign-in attempts and the rate of requests, protection against automated attacks;
- private storage of customer documents, accessible only to authorised employees of the business;
- firewalling, access logs, timely software updates, backups;
- data protection by design and by default (Article 25 GDPR).
6.3. Protection of payment data
The Operator does not store payment card data. Payments are processed through certified payment gateways (PCI DSS) and app stores; data exchange is protected by an HMAC key and encryption.
6.4. Incident response (Articles 33–34 GDPR)
In the event of a personal data breach, the Operator:
- immediately takes measures to remedy its consequences;
- notifies the supervisory authority within 72 hours where the breach is likely to result in a risk to the rights and freedoms of data subjects;
- notifies data subjects without undue delay where there is a high risk;
- notifies the business without undue delay where data for which the business is the controller are affected;
- documents the incident and the measures taken.
7. To whom information is disclosed
7.1. General principles
The Operator does not sell or rent out personal data. Data are disclosed only in the cases described in this Section and to the minimum extent necessary. The Operator's processors are bound by data processing agreements (Article 28 GDPR).
7.2. The Operator's own language models (Mars LLM Service)
The replies of AI employees are generated exclusively by the Operator's own language models running on the Operator's servers, through the Operator's internal Mars LLM Service. A request to the model contains the text of the conversation, the instructions and rules of the AI employee, fragments of the business's knowledge base and information from the company page; direct identifiers of the Visitor (email address, telephone) are not included in the request unless the Visitor has written them in a message himself or herself.
Conversation data, instructions and knowledge bases are not transferred to third-party providers of artificial intelligence services. The knowledge base is stored and indexed on the Operator's servers.
7.3. Speech recognition and synthesis
Speech recognition and voice synthesis (including with the own voices of businesses) are performed by the Operator's own services on the Operator's servers. These data are not disclosed to third parties.
7.4. Server location and hosting
Data are stored on the Operator's servers located in the data centres of hosting providers under contracts with the Operator. Hosting providers have no right to use the data for their own purposes.
7.5. Cloudflare
The twincard.ai website operates through the Cloudflare content delivery and DDoS protection network. Cloudflare processes, as a processor, the IP address and technical request data to the extent necessary to deliver pages and protect against attacks.
7.6. Web search providers ("From the Internet" block)
For the "From the Internet" block, the text of the search query, the country, the language and the city specified are transmitted to a third-party search provider: Google via the SerpApi service, with Brave Search as a fallback. No other data about You are transmitted to the provider. The providers process queries in accordance with their own privacy policies.
7.7. Payment gateways and app stores
When the balance is topped up, the payment gateway receives the transaction identifier and amount, the currency, the payment description and the email address (for the receipt). When topping up in the Application, the payment is processed by Google Play or the App Store as an independent controller; the Operator receives only the purchase identifier and its status. For bank transfer payments, the data are processed by the parties' banks.
7.8. Push notifications
Google Firebase Cloud Messaging and the Apple Push Notification Service are used for notifications of the Application. A notification may contain a brief summary of the event.
7.9. Integrations connected by a business
On the instructions of the business, data are transmitted to recipients selected by the business: Telegram (correspondence of AI employees with customers via the business's Telegram bot), CDEK (recipient data for delivery under the business's contract), the business's payment provider (payment by a customer of the business's invoice), recipients of the business's webhooks and API, and the business's websites on which the widget is installed. These recipients process the data in accordance with their own rules and under their contracts with the business.
7.10. Public information and countries of presence
Company page information is publicly available in the TwinCard catalogue. An approved copy of the company page is published on the TwinCard website of each country of presence selected by the business (Russia — twincard.ru, Kazakhstan — twincard.kz, other countries — twincard.ai; "online" — on all three). The websites of other countries may be operated by operators of the AI² Platform in the relevant jurisdictions.
Visitors to a company page can see the information that the business has posted on it and the names of AI employees. Account data, correspondence, customer lists and payment data are not shown to Visitors.
7.11. Businesses
If You communicate with a business, fill in its form or send it a document, these data are received by the business and its authorised employees. Advertisers receive only aggregated impression and click statistics.
7.12. Disclosure required by law
The Operator may disclose personal data upon a lawful request from competent authorities where there is an appropriate legal basis, and will inform the data subject of such a request unless prohibited by law. Information on confirmed child sexual abuse material is reported to the competent authorities as required by applicable law.
8. Retention period
8.1. General rules (Article 5(1)(e) GDPR)
Personal data are kept no longer than required by the purposes of processing, after which they are deleted or anonymised.
8.2. Retention periods by category
| Data category | Retention period |
|---|---|
| Account | Period of use of the Service + 30 days after deletion in TwinCard or deletion of the AI² account |
| Information about the business and company page | Until deletion of the business or the account (+ 30 days for recovery) |
| Structure, AI employees, instructions, knowledge base | Until deleted by the business or until deletion of the account |
| Correspondence of Visitors with the business, forms and requests | Until deleted by the business or until deletion of the business's account |
| Customer documents | 90 days from upload, or earlier at the business's decision |
| Customer lists, deals, reports, summaries | Until deleted by the business or until deletion of the account |
| Voice samples and own voices | Until deleted by the business, withdrawal of consent by the person concerned, or deletion of the account |
| Integrations and API keys | Until disconnected by the business or until deletion of the account |
| Express requests that did not result in a contract | Until processing of the request is completed, but no longer than 12 months from submission |
| Search queries (not linked to a user) | Kept in aggregated form for statistics |
| Advertising statistics | Duration of the campaign and the period necessary for settlements |
| Orders, invoices, payment transactions | Period established by tax and accounting legislation |
| Complaints and moderation data | Period of review and of the establishment, exercise or defence of legal claims |
| Push token | Until the permission is withdrawn or the account is deleted |
| Access logs | 6 months |
Business data shared with the AI² Space application are retained after deletion of the TwinCard account for as long as You use Space (clause 8.3).
8.3. Account deletion
You can delete Your account:
- in the Dashboard on the Website: "Profile" → "Delete account" (with password confirmation);
- in the Application: "Settings" → "Account deletion" → "Delete account";
- by writing to [email protected] from the address with which the account is registered (reply within 30 days).
There is one AI² account for all applications of the Platform AI². Deleting the TwinCard account closes only TwinCard: AI² Fans, AIRONIK, AI² Space and the other applications of the Platform that You use continue to work as before, and the AI² account is kept for as long as You use them. If You have no other applications of the Platform left (the AIRONIK messenger is not counted for this purpose), the AI² account is deleted in its entirety. You can delete the AI² account in its entirety, in all applications at once, using a separate option in the application settings or by writing to [email protected].
When only TwinCard is deleted, the following are retained: everything related to AI² Fans (Fans models, their placements and advertising, Fans subscriptions); AI models that are at the same time a Fans model and an AI employee of a company; the Wallet and the data recorded on the AI² account itself (personal knowledge base, voices, rules, personal API keys). They are deleted only together with the AI² account in its entirety; Wallet transactions are retained for as long as the law requires.
Deletion procedure:
- Immediately after the request, access to TwinCard is closed and the data are hidden: company pages are unpublished, AI employees stop replying, subscriptions are hidden, and TwinCard push notifications stop.
- 30 days — recovery period: signing in to TwinCard during this time cancels the deletion and restores the TwinCard account itself (if the AI² account was deleted in its entirety, it is necessary to sign in to it and confirm the recovery). Signing in also brings back everything that was hidden by the deletion: businesses, their company pages and AI employees.
- After 30 days the TwinCard account is deleted: personal data and the data of Your businesses are deleted or anonymised. They cannot be recovered thereafter.
- Records that the law requires to be retained (orders, invoices, wallet transactions, payments, accounting records; contact details in orders are deleted) are kept for the period prescribed by law and then permanently deleted.
Deleted: profile and account; company pages, structure and information about employees; AI employees of businesses, their instructions and knowledge bases; customer lists, deals, reports and summaries; correspondence of Visitors with the business's AI employees; forms and requests; documents; voice samples and own voices of businesses; integrations and API keys of businesses. Personal voices, rules, the knowledge base and API keys recorded on the AI² account itself are not deleted when TwinCard is deleted (see above).
If You use AI² Space: business data shared with the AI² Space application (company information, structure, AI employees, customers, activity log, knowledge base) are retained for as long as You use Space. After 30 days, the TwinCard company page (with versions, files, publication in countries of presence and address), widgets, the TwinCard account, Your subscriptions to other businesses and Your place on the staff of other companies are deleted. If You do not have Space or it has been deleted, the business data are deleted as well: structure, employees, AI employees, customers, activity log, forms, API keys and the business knowledge base.
Retained: orders, invoices, wallet transactions, payment information and accounting records — for as long as the law requires (contact details in orders are deleted); messages You have sent to other users — in their history in anonymised form; anonymised statistics, which do not constitute personal data.
You can delete an individual business or dismiss an AI employee without deleting the account.
9. International data transfers
9.1. General principles (Chapter V GDPR, Articles 44–49)
Data are transferred outside the EEA only where appropriate safeguards are in place.
9.2. Transfers outside the EEA
(a) The Operator and the Platform infrastructure:
• Data: all categories specified in Section 4, including processing by the Operator's own language models;
• Country of destination: the Republic of Kazakhstan (where the Operator is established) and the countries in which the Platform's servers are located;
• Safeguards: the Standard Contractual Clauses (SCC) adopted by Commission Implementing Decision (EU) 2021/914, and the measures set out in Section 6.
(b) Single sign-on to AI² applications:
• Data: account data (name, email address, password hash, identifiers, country);
• Country of destination: the countries in which the Platform's servers are located in other jurisdictions;
• Basis: the transfer is necessary for the performance of the contract — single sign-on to the applications of the Platform (Article 49(1)(b) GDPR), together with the safeguards under Article 46 GDPR.
(c) Publication in the countries of presence:
• Data: company page information;
• Country of destination: the countries of presence selected by the business;
• Basis: publication at the choice and on the instructions of the business; the transfer is necessary for the performance of the contract with the business (Article 49(1)(b) GDPR).
(d) Cloudflare, web search providers, push notification services:
• Data: technical request data; the text of the search query; a notification that may contain a brief summary of the event;
• Safeguards: SCC, the EU-U.S. Data Privacy Framework (for participating U.S. providers).
9.3. Copies of safeguards
A copy of the safeguards applied may be requested at [email protected].
10. Cookies and local storage (ePrivacy)
10.1. What is used
The Service uses only technologies that are strictly necessary for the operation of the Service and for carrying out Your actions. Analytics and advertising cookies are not used.
10.2. Cookies
| Name | Purpose | Duration |
|---|---|---|
| tc_lang | Selected interface language | 1 year |
10.3. Local storage (Local Storage and Session Storage)
- sign-in token — so that You remain signed in to Your account;
- theme;
- interface language;
- guest chat token — so that a guest conversation with an AI employee continues when the page is reopened;
- Session Storage — technical information for navigation within a tab; deleted when the tab is closed.
These data are stored in Your browser, are not automatically sent with every request (except for the sign-in token when accessing the Service), and are set without consent on the basis of the exemption in Article 5(3) of the ePrivacy Directive as strictly necessary.
10.4. Management
You can delete cookies and local storage data in Your browser settings. After deletion, You will need to sign in again, and a guest conversation will start anew.
11. Special categories of personal data (Article 9 GDPR)
11.1. The Service does not request special categories of personal data from users and does not use them for advertising or ranking.
11.2. The Service does not carry out biometric verification and does not create biometric templates for identification. Voice samples are used only for speech synthesis (Section 4.6).
11.3. A business may not upload special categories of data to the knowledge base, forms or customer lists without a lawful basis. If a Visitor discloses such information on his or her own initiative in correspondence with a business, the business processes it as controller; the Operator processes it only on behalf of the business for the purposes of operating the correspondence.
12. Your rights (Articles 15–22 GDPR)
To exercise Your rights, please contact [email protected] (marked "Data Protection") or the postal address set out in Section 2.2. A reply is sent within one month (Article 12(3) GDPR), which may be extended by a further two months where necessary. Requests concerning data for which the business is the controller are forwarded by Us to the business (Section 2.3).
12.1. Right of access (Article 15)
You have the right to obtain confirmation of processing and a copy of Your data, as well as information on the purposes, categories, recipients, retention periods, sources, international transfers and automated processing.
12.2. Right to rectification (Article 16)
You can rectify most data Yourself in the Dashboard (profile, information about the business).
12.3. Right to erasure (Article 17)
You have the right to request the erasure of Your data where the grounds of Article 17 GDPR apply. The procedure for deleting the account is set out in Section 8.3. The Operator may refuse to erase data whose retention is required by law or which are necessary for the establishment, exercise or defence of legal claims (Article 17(3)).
12.4. Right to restriction of processing (Article 18)
You have the right to request restriction of processing for the period during which the accuracy of the data is verified, where processing is unlawful, where the data are needed for legal claims, or pending the examination of an objection.
12.5. Right to data portability (Article 20)
You have the right to receive the data You have provided, and a Business Owner has the right to receive the business's data, in a structured, commonly used and machine-readable format and to transmit them to another controller. There is no export in the Dashboard: the right is exercised upon request to [email protected], and a reply is sent within the time limit established by Article 12(3) GDPR.
12.6. Right to object (Article 21)
You have the right to object to processing based on legitimate interest. You may object to direct marketing at any time; such processing then ceases.
12.7. Right to withdraw consent (Article 7(3))
Consent to push notifications and advertising mailings may be withdrawn at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
12.8. Automated processing (Article 22)
The Service automatically generates replies of AI employees, customer summaries, search results and the display of advertising, and applies automated measures to protect against abuse. These processes do not take decisions producing legal effects concerning You; decisions to refuse publication and to block are taken with human involvement. You have the right to obtain information about the logic involved, to contest the outcome and to obtain human intervention.
12.9. Complaint to a supervisory authority (Article 77)
You have the right to lodge a complaint with the data protection supervisory authority of the EU/EEA Member State of Your habitual residence, place of work or place of the alleged infringement. List of supervisory authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en
13. AI transparency (EU AI Act)
13.1. General provisions
AI employees are labelled in the Service as artificial intelligence. An AI employee is not a human being; its replies, including voiced replies, are generated automatically by software. The business must inform its customers that they are communicating with AI (Article 50 EU AI Act), including in the channels that it connects itself.
13.2. AI systems in the Service
(a) AI employees (Mars LLM Service):
• Purpose: replies to Visitors and customers on behalf of the business;
• Technology: the Operator's own large language models on the Operator's servers; search of the business's knowledge base on the Operator's servers; no data are transferred to third-party AI providers;
• Input data: the text of the conversation, the business's instructions and rules, fragments of the knowledge base, company page information;
• Limitations: replies may be inaccurate; the business is responsible for the instructions and for the information communicated by AI employees.
(b) Customer summaries:
• Purpose: a brief description of the history of a customer's interaction with the business for employees of the business;
• Limitations: an auxiliary feature; it does not take decisions.
(c) Speech recognition and synthesis:
• Purpose: recognition of voice messages and voicing of replies, including with the own voices of businesses;
• Transparency: voiced replies are a synthesised voice; an own voice is created only with the explicit consent of the person concerned; no biometric identification is performed.
(d) Search and advertising:
• Purpose: selection of company pages and AI employees in response to a query, display of labelled advertising; the main ranking parameters are disclosed in the User Agreement (clause 5.4).
Not used: biometric identification, emotion recognition, personality assessment of Visitors.
14. Changes to the Policy and contact information
14.1. Changes
The Operator may amend the Policy in the event of changes in legislation, the features of the Service, the scope of data, the recipients or the security measures. The Operator gives notice of material changes on the Website, in the Dashboard, by email or by push notification. Where processing is based on consent, renewed consent is requested in the event of material changes.
14.2. Entry into force
Changes take effect upon publication, unless another date is specified in them. If You do not agree, You may stop using the Service and delete Your account (Section 8.3).
14.3. Version archive
Previous versions of the Policy are available upon request. The current version is published on the twincard.ai Website (the "Privacy Policy" link at registration and in the Dashboard) and in the Application.
14.4. Contacts
Controller: Private Company "New Reality" (New Reality Ltd)
• Legal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
• Email: [email protected]
• Phone: +7 (747) 029-43-05
When contacting Us, please state Your name, the email address of Your account (if You have one), the substance of Your request and Your preferred means of contact.
Additional provisions
Age restriction. The Service is intended for persons who have reached the age of 18. The Operator does not knowingly collect data of minors; if the registration of a minor is detected, his or her account is deleted.
Anonymisation. The Operator may anonymise data for statistical purposes. Anonymised data do not allow the data subject to be identified and do not fall within the scope of the GDPR (Recital 26).
Non-discrimination. The Service does not permit discrimination on the basis of protected characteristics.
Private Company "New Reality" (New Reality Ltd)
BIN: 220440900016
Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
[email protected] | +7 (747) 029-43-05
Date of publication: September 25, 2026