Home

Terms of Service

TwinCard — User Agreement. International Jurisdiction (GDPR)

Last revised: September 26, 2026

This User Agreement (hereinafter the "Agreement") governs the relationship between Private Company "New Reality" (New Reality Ltd; hereinafter the "Operator", the "Administration", "We") and the person using the TwinCard service, the AI² business platform (hereinafter the "Service"), hosted on the Internet at: twincard.ai (hereinafter the "Website"), as well as in the form of the "AI2 TwinCard" mobile application (hereinafter the "Application").

Operator:
Private Company "New Reality" (New Reality Ltd)
BIN: 220440900016
Legal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
Email: [email protected]
Phone: +7 (747) 029-43-05
Website: https://twincard.ai

This Agreement constitutes a legally binding contract. Registration on the Website or in the Application, submission of an express request, as well as use of the Service, constitutes full and unconditional acceptance of this Agreement.

Applicable law: Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), Regulation (EU) 2022/2065 (Digital Services Act, DSA), Regulation (EU) 2024/1689 (Artificial Intelligence Act, EU AI Act), applicable EU directives, as well as the national legislation of the User's country of residence to the extent of its mandatory provisions.


1. DEFINITIONS AND TERMS

1.1. Service (TwinCard) — the international AI² business platform that enables companies, individual entrepreneurs and self-employed persons to create a company page in the TwinCard catalogue, build the structure of their business, connect AI employees and human employees, communicate with customers on the storefront, receive requests, documents and enquiries from customers, maintain customer lists, connect integrations, and order promotion and advertising.

1.2. Platform (AI² Platform) — the totality of the Operator's software, databases, algorithms, artificial intelligence models and infrastructure that ensure the operation of the Service and other AI² applications, including the twincard.ai website, the "AI2 TwinCard" mobile application and server software.

1.3. User (You) — a legally capable person who has reached the age of 18 (eighteen), has registered an account in the Service, has accepted this Agreement, and acts on behalf of a business or as its representative or employee.

1.4. Business — a company (legal entity), individual entrepreneur or self-employed person on whose behalf a company page, a structure and AI employees have been created in the Service. A single account may manage several businesses.

1.5. Business Owner — the User who created a business in the Service or who has obtained owner authority in the manner provided for by the Service. The Business Owner manages the company page, the structure, access rights, integrations and payment.

1.6. Account — the totality of the User's data stored on the Platform, accessed by means of an email address and password. The AI² account is single for all applications of the AI² Platform: with one sign-in, the User uses all AI² applications in which he or she is registered.

1.7. Company page (storefront) — the public page of a business in the TwinCard catalogue containing information about the business posted by the User: name, description, mission, values, services and price list, address, contacts, logo and photographs, links, banners, business details (including the name of the legal entity and the tax identification number), as well as the AI employees available to Visitors.

1.8. TwinCard catalogue — the public list of the Service's company pages and AI employees with a search function.

1.9. Countries of presence — the countries selected by a business for publication of its company page. An approved copy of the company page is published on the TwinCard website of the selected country (Russia — twincard.ru, Kazakhstan — twincard.kz, other countries — twincard.ai; the "online" option — on all three websites).

1.10. Business structure — the departments, roles and positions of a business in which human employees and AI employees are placed, as well as the rights of access to sections of the Dashboard determined by the structure.

1.11. AI employee — a software assistant of a business based on a large language model, operating according to instructions and rules set by the business and using the business's knowledge base. The AI employee communicates with Visitors and customers of the business on behalf of the business. An AI employee is not a human being.

1.12. Human employee (manager) — a User invited by a business into its structure and granted rights of access to sections of the business's Dashboard.

1.13. Knowledge base — information, documents and texts that a business uploads for its AI employees; they are stored and indexed on the Operator's servers so that they can be searched when generating replies.

1.14. Visitor — a person who has opened a company page, a widget or another channel of a business and communicates with an AI employee or an employee of the business, including without registration (as a guest).

1.15. Customer of a business — a Visitor or another person whose data the business processes in the Service: in correspondence, forms and requests, documents, customer lists, deals and reports.

1.16. Forms and requests — forms created by a business in the Service to collect enquiries, orders, reviews and contact details of customers.

1.17. Integrations — connections configured by a business: a widget for placement on the business's own websites, API keys, webhooks, connection of the business's Telegram bot, the business's keys for the CDEK delivery service, and the business's payment acceptance settings.

1.18. Own voice — a synthesised voice created by a business on the model of the voice of a specific person with that person's explicit consent and used to voice the replies of AI employees.

1.19. Mars LLM Service — the Operator's internal server-side service that processes requests to the Operator's own large language models (LLMs) deployed on the Operator's servers and ensures the operation of the Service's AI employees.

1.20. "From the Internet" block — the part of the Service's search results in which the results of an external web search, obtained from third-party search providers, are shown.

1.21. Express request — a request for placement, promotion or other services of the Service that may be submitted without creating an account; further processing is carried out by the Operator's manager.

1.22. AI² Token — the internal unit of account of the Platform used to pay for services of the Service. The AI² Token is not electronic money, a cryptocurrency, a security or any other financial instrument, is not exchangeable for money and cannot be withdrawn from the Platform.

1.23. Wallet (AI² balance) — the section of the account displaying the balance of AI² Tokens and the history of transactions (top-ups, debits, refunds). The AI² balance is single for the account across all applications of the AI² Platform.

1.24. Digital activation code (card, flyer) — a unique alphanumeric code granting the right to top up the balance of AI² Tokens.

1.25. Order — a purchase of a paid service (item) placed by the User in the Service and paid from the AI² balance or by invoice.

1.26. Personal data — any information relating to an identified or identifiable natural person (data subject), within the meaning of Article 4 GDPR.

1.27. Data Controller — the person who determines the purposes and means of the processing of personal data.

1.28. Data Processor — the person who processes personal data on behalf of, and on the documented instructions of, the controller.

1.29. Content — any information posted or transmitted by the User in the Service, including company page information, images, instructions and rules of AI employees, the knowledge base, forms, messages, documents, customer lists, voice samples and advertising materials.

1.30. Mobile application ("AI2 TwinCard") — the Service's application for mobile devices, distributed through Google Play and the App Store.


2. GENERAL PROVISIONS

2.1. This Agreement is a legally binding contract between the User (and the business on whose behalf he or she acts) and the Operator, concluded in electronic form by acceptance of the terms of the Agreement.

2.2. Acceptance of this Agreement consists in the performance of any of the following actions:
• registration in the Service (creation of an account) or signing in to the Service with an AI² account;
• submission of an express request;
• acceptance of an invitation to join the structure of a business;
• continued use of the Service after publication of amendments to the Agreement.

2.3. The Service is intended for businesses. The User uses the Service as a company, individual entrepreneur or self-employed person, or as their representative or employee, for the purposes of his or her business or professional activity. By accepting the Agreement on behalf of a business, the User confirms that he or she is authorised to act on its behalf. If, under applicable law, the User is deemed to be a consumer, he or she retains all rights granted by the mandatory provisions of consumer protection legislation; the provisions of this Agreement do not limit those rights.

2.4. The Service is intended exclusively for persons who have reached the age of 18 (eighteen). By registering, the User confirms that he or she has reached that age. The Administration may request confirmation of age and authority at any time and block the account if a violation is detected.

2.5. The Service is provided internationally in accordance with applicable law, including, but not limited to:
• Regulation (EU) 2016/679 (GDPR);
• Directive 2002/58/EC on privacy and electronic communications (ePrivacy);
• Directive 2011/83/EU on consumer rights (to the extent applicable to consumers);
• Directive 2000/31/EC on electronic commerce;
• Regulation (EU) 2022/2065 (Digital Services Act, DSA);
• Regulation (EU) 2019/1150 on promoting fairness and transparency for business users of online intermediation services (P2B);
• Regulation (EU) 2024/1689 (Artificial Intelligence Act, EU AI Act);
• the national legislation of the User's country of residence to the extent of its mandatory provisions.

2.6. The Service is an information intermediary and hosting service provider in respect of the content of businesses. The Operator is not a party to contracts concluded by a business with its customers, does not sell the goods or provide the services of a business, and is not responsible for their quality, price, delivery or payment.

2.7. The Service applies Domain-Based Jurisdiction technology: the set of features, the payment methods and the applicable edition of the documents are determined by the website through which the User accesses the Service and by the country selected at registration. This international edition of the Agreement applies to the twincard.ai website and to the Application used in the international jurisdiction.

2.8. The Administration may change the functionality of the Service and add, modify or remove individual features, provided that Users are notified of material changes (Section 16). Changes affecting paid services shall not worsen their terms during the paid period.

2.9. The Service and the documents are available in several languages. For the international domains, the English-language version of the Agreement is legally binding. In the event of discrepancies between language versions, the English-language version shall prevail.

2.10. The Platform does not permit discrimination on the basis of sex, gender identity, sexual orientation, race, nationality, religion, disability or other protected characteristics — either by the Operator or by businesses in respect of their customers.


3. REGISTRATION, ACCOUNT AND DELETION

3.1. Registration

3.1.1. To use the Dashboard of the Service, the User completes registration, which includes:
• selecting a country (the country determines the TwinCard website and the edition of the documents under which registration continues) and providing a telephone number;
• selecting a status: company or natural person (individual entrepreneur, self-employed person);
• providing an email address, creating a password and confirming the address with a code sent to it;
• providing a name and information about the business: the company name, the name and number of the tax identifier used in the business's country, and the User's position;
• selecting cooperation options (company page in the catalogue, employees, advertising, etc.);
• confirming acceptance of this Agreement and of the Privacy Policy.

3.1.2. If the User already has an AI² account, he or she signs in to the Service with that account; the account data are shared among the applications of the AI² Platform (clause 1.6).

3.1.3. The User must provide accurate and up-to-date information about himself or herself and about the business. The provision of knowingly false information, including as to the name, the tax number or authority, constitutes grounds for refusing publication and for blocking the account.

3.1.4. The User is solely responsible for keeping his or her credentials secure. The Service makes it possible to enable two-factor authentication. The User must notify the Administration without delay of any unauthorised access to the account at [email protected].

3.1.5. No biometric face verification is carried out in the Service.

3.2. Express request

3.2.1. A request for placement, promotion or other services of the Service may be submitted without creating an account, through the express request form, by providing contact details and information about the business. By submitting a request, the applicant accepts this Agreement and the Privacy Policy.

3.2.2. Following an express request, the Operator's manager contacts the applicant, agrees the scope of services and the price (including for items priced "from", Appendix 1) and helps complete the ordering process. Services are provided after the order has been placed and paid for.

3.3. Business, representatives and human employees

3.3.1. The User may create one or more businesses in the Service. By creating a business, the User confirms that he or she is entitled to represent that business and to post information about it.

3.3.2. The Business Owner may invite human employees into the structure of the business and assign them roles and access rights. Access rights are determined by the structure of the business. Each human employee uses the Service under his or her own account and accepts this Agreement.

3.3.3. The business is responsible for the actions of its human employees in the Service as for its own, for the timely modification and revocation of their access rights, and for ensuring that its employees comply with this Agreement.

3.3.4. A human employee may leave the structure of a business at any time; the business may remove him or her from the structure at any time. Removal from the structure terminates the employee's access to the business's data and does not delete his or her account.

3.4. Account management

3.4.1. The User may at any time edit profile data and information about the business, change the password and security settings, and manage the structure, employees, AI employees, integrations and subscriptions.

3.4.2. The User may delete an individual business or dismiss (delete) an individual AI employee without deleting the account. When a business is deleted, its company page is unpublished, its AI employees are hidden from the catalogue, and the business's data are deleted in the manner and within the time limits specified in clause 3.5.

3.4.3. The Administration may block or restrict access to an account or a business in the event of a breach of this Agreement, receipt of substantiated complaints, detection of suspicious activity, or at the request of competent authorities. In the event of blocking, the User is notified of the reasons, with reference to the specific facts, and may appeal the decision (clause 11.5).

3.5. Account deletion

3.5.1. The User may delete the account at any time:
• in the Dashboard of the Service on the Website: "Profile" → "Delete account" (with password confirmation);
• in the Application: "Settings" → "Account deletion" → "Delete account";
• by sending a request to [email protected] from the address with which the account is registered. A reply to the request is sent within 30 (thirty) days.

3.5.2. The AI² account is single for all applications of the AI² Platform. Deleting the account in the Service closes only the Service: AI² Fans, AIRONIK, AI² Space and the other applications of the AI² Platform used by the User continue to work, and the AI² account is kept for as long as the User uses them. If the User has no other applications of the AI² Platform left (the AIRONIK messenger is not counted for this purpose), the AI² account is deleted in its entirety. The User may delete the AI² account in its entirety, in all applications at once, using a separate option in the application settings or by writing to [email protected]. When the account is deleted only in the Service, the following are retained: everything related to AI² Fans (Fans models, their placements and advertising, Fans subscriptions); AI models that are at the same time a Fans model and an AI employee of a business; the Wallet (clause 1.23) and the data recorded on the AI² account itself (personal knowledge base, voices, rules, personal API keys). They are deleted only together with the AI² account in its entirety.

3.5.3. Procedure and time limits for deletion:
• immediately after the request, access to the Service is closed and the data are hidden: the User's company pages are unpublished, his or her AI employees stop replying, subscriptions are hidden, and push notifications of the Service stop;
• a recovery period applies for 30 (thirty) days: signing in to the Service during this period cancels the deletion and restores the account itself (if the AI² account was deleted in its entirety, by signing in to it and confirming the recovery); signing in also brings back everything that was hidden by the deletion: businesses, their company pages and AI employees;
• upon expiry of 30 (thirty) days the account is deleted: the personal data of the User and the data of his or her businesses are deleted or anonymised in accordance with Article 17 GDPR; they cannot be recovered thereafter;
• records whose retention is required by applicable law are retained for the period prescribed by law and then permanently deleted.

3.5.4. When the account is deleted, the following are deleted or anonymised (subject to clause 3.5.2):
• profile and account data;
• the company pages of businesses of which the User is the owner, their structure and information about employees;
• AI employees of businesses, their instructions, rules and knowledge bases;
• customer lists, deals, reports and customer summaries;
• correspondence of Visitors with AI employees and employees of the business;
• forms, requests and responses to them, customer documents;
• voice samples and own voices of businesses created from them;
• integrations of businesses, their API keys, webhooks, Telegram bot connections, CDEK keys and payment acceptance settings.

Business data shared with the AI² Space application (company information, structure, AI employees, customers, activity log, knowledge base) are retained for as long as the User uses Space; in this case, upon expiry of 30 (thirty) days, the company page of the Service (with versions, files, publication in countries of presence and address), widgets, the account in the Service, the User's subscriptions to other businesses and his or her place on the staff of other companies are deleted. If the User does not have Space or it has been deleted, the business data are also deleted: structure, employees, AI employees, customers, activity log, forms, API keys and the business knowledge base.

3.5.5. The following are retained for the periods prescribed by law: orders, invoices, AI² wallet transactions, payment information and other accounting records; contact details in orders are, however, deleted. Messages sent by the User to other users may remain in their history in anonymised form.

3.5.6. If a business has other human employees, deletion of the Business Owner's account in the Service terminates their access to that business in the Service. If the business data are retained because the owner uses AI² Space (clause 3.5.4), access to them in AI² Space is governed by the rules of AI² Space. Before deletion, the owner may transfer owner authority to another employee of the business by sending a request to [email protected].

3.5.7. Upon deletion of the account, active subscriptions and recurring services of the Service are terminated. The unused AI² balance is not refundable in money, except in cases provided for by the mandatory provisions of applicable law (clause 10.8).

3.5.8. Before deleting the account, the User may exercise the right to data portability (Article 20 GDPR) by sending a request to [email protected]; a reply is sent within the time limit established by Article 12(3) GDPR.


4. LICENCE TO USE THE SERVICE

4.1. Grant of licence

4.1.1. The Operator grants the User a non-exclusive, non-transferable, revocable licence to use the Service (including the Website, the Application, the widget and the API) in accordance with this Agreement for the entire term of this Agreement.

4.1.2. The licence is granted for use of the Service in the activities of the User's business within the scope of the features available free of charge or as part of paid services.

4.2. Licence restrictions

4.2.1. The User may not:
• copy, modify, decompile, disassemble or reverse engineer the software of the Service;
• resell access to the Service, sublicense it, or provide access to third parties outside the structure of his or her business, unless otherwise agreed with the Operator in writing;
• use the Service to create a competing product, including to train third-party artificial intelligence models on the replies of AI employees;
• extract or re-utilise substantial parts of the Service's databases, including the catalogue (Directive 96/9/EC);
• use automated means (bots, scripts, crawlers) to access the Service outside the API provided;
• exceed the established API limits or circumvent the technical protection measures of the Service;
• exploit vulnerabilities of the Service.

4.3. Updates

4.3.1. The Operator may update the Service, including correcting errors, adding features, and changing the interface, the language models used and the voices used for voicing. Such updates do not require the User's separate consent, provided they do not change the purposes and legal bases of the processing of personal data.


5. COMPANY PAGE, CATALOGUE AND COUNTRIES OF PRESENCE

5.1. Company page

5.1.1. The User populates the company page himself or herself: name, description, mission, values, services and price list, address, contacts, logo, photographs, links, banners and business details (including the name of the legal entity and the tax number).

5.1.2. The information on the company page is information about the business and is published at the business's choice. By posting personal data on the page (for example, the name of an individual entrepreneur, contact details of employees, photographs of people), the business confirms that it has a lawful basis for publishing them.

5.1.3. The business is responsible for the accuracy and currency of the information on the company page, including prices, business details and information about goods and services, and for its compliance with the law, including requirements concerning information for consumers.

5.1.4. Publication of a company page in the catalogue is a paid service (Appendix 1). The payment procedure and the consequences of non-payment are set out in Section 10.

5.2. Moderation of company pages

5.2.1. A company page and subsequent changes to its content undergo moderation before publication. Moderation may be manual or automated; a decision to refuse is taken with human involvement.

5.2.2. The Operator may refuse publication, require corrections, or unpublish a company page, part of it, an AI employee or an advertising material if they infringe the law, this Agreement or the rights of third parties. The business is notified of the decision and the reasons for it (Article 4 of Regulation (EU) 2019/1150, Article 17 DSA) and may appeal the decision (clause 11.5).

5.2.3. Until changes are approved, the last approved version continues to be displayed on the published page.

5.3. Countries of presence

5.3.1. The business selects its countries of presence. An approved copy of the company page is published on the TwinCard website of each selected country: Russia — twincard.ru, Kazakhstan — twincard.kz, other countries — twincard.ai; the "online" option publishes the page on all three websites.

5.3.2. The TwinCard website of another country may be operated by an operator of the AI² Platform acting in that jurisdiction and may operate under the documents of that website. By selecting a country of presence, the business instructs that the information on the company page be published on the relevant website and understands that it becomes publicly available in that country and is subject to its law (including law on advertising, language and the content of information).

5.3.3. The business may change the list of countries of presence at any time; when a country is removed, the copy of the page is unpublished from the website of that country.

5.4. Catalogue and search

5.4.1. The TwinCard catalogue is available to Visitors without registration. The order in which results are displayed in the catalogue is determined by relevance to the query, the Visitor's country and language, the information on the company page and paid promotion services. The main ranking parameters are disclosed in accordance with Article 5 of Regulation (EU) 2019/1150 and Article 27 DSA: relevance to the query, completeness of the page, country and language, as well as paid search priority and advertising, which are always labelled as promotion or advertising.

5.4.2. The texts of search queries are stored without being linked to a user and are used for the operation of search, statistics and improvement of the Service.

5.5. "From the Internet" block

5.5.1. In search results, the Service may display the "From the Internet" block — the results of an external web search. For this purpose, the text of the search query (as well as the country, the language and the city specified) is transmitted to a third-party search provider: on the twincard.ai website — Google via the SerpApi service, with Brave Search as a fallback. No other data of the Visitor are transmitted to the provider.

5.5.2. The results of the "From the Internet" block are generated by the third-party provider; the Operator does not verify, and is not responsible for, the content of external websites. The provider's family filter is enabled in strict mode.


6. AI EMPLOYEES

6.1. Nature of the service

6.1.1. A business may create AI employees, give them a name, a role, instructions and rules, populate the knowledge base, and place them in the structure of the business, on the company page, in the widget and in connected channels.

6.1.2. AI employees generate replies to Visitors and customers of the business on the basis of the business's instructions and rules, the business's knowledge base, the information on the company page and the course of the conversation.

6.2. The Operator's own models

6.2.1. AI employees operate exclusively on the Operator's own large language models deployed on the Operator's servers, through the Operator's internal Mars LLM Service. Speech recognition and speech synthesis are also performed by the Operator's own services on the Operator's servers. The knowledge base is stored and indexed on the Operator's servers.

6.2.2. Conversation data, instructions and the knowledge base are not transferred to third-party providers of artificial intelligence services and are not used to train models for the benefit of third parties.

6.3. Responsibility of the business for AI employees

6.3.1. The replies of AI employees are generated automatically and may be inaccurate, incomplete or erroneous. The business itself checks the performance of its AI employees and is responsible for its instructions and rules, the content of the knowledge base, and the information that its AI employees communicate to the customers of the business, as for information communicated by the business itself.

6.3.2. The business may not instruct AI employees to provide medical, legal, financial or other professional advice requiring special qualifications or a licence, unless the business itself possesses such qualifications and bears responsibility for such advice; to take legally significant decisions on behalf of the business in respect of customers without human review; or to mislead customers.

6.3.3. The Operator bears no liability for decisions taken by the business or its customers on the basis of the replies of AI employees, except where the damage has been caused by a failure of the Service attributable to the Operator.

6.4. AI transparency

6.4.1. The business must inform its customers that they are communicating with artificial intelligence and not with a human being (Article 50 of Regulation (EU) 2024/1689, EU AI Act). The Service labels AI employees as artificial intelligence on the company page and in the widget; the business may not conceal or remove such labelling or present an AI employee as a human being, and must ensure the same notice in the channels that it connects itself (for example, in a Telegram bot).

6.4.2. The voice used to voice the replies of an AI employee is synthesised; if it is the own voice of a real person, the business may not use it in such a way that customers perceive the replies as the speech of that person.

6.5. Own voices

6.5.1. A business may create an own voice on the model of the voice of a specific person only with that person's explicit consent. Before the sample is recorded, the person pronounces the consent phrase provided by the Service; the sample and the consent phrase are retained.

6.5.2. The voice sample is stored on the Operator's servers and is used exclusively for speech synthesis for the business's AI employees on behalf of the business. No voice biometric templates for identifying a person are created.

6.5.3. The business warrants that the person whose voice is used gave consent voluntarily, is informed of the purposes of use and may withdraw consent at any time; upon withdrawal, the business must delete the voice in the Service. It is prohibited to create voices of public figures or other people without their consent, or to use a synthesised voice for deception or impersonation.

6.5.4. The voice sample and the voice created from it are deleted at the decision of the business, at the request of the person whose voice was used (upon contacting [email protected]), and upon deletion of the account (clause 3.5).


7. WORKING WITH CUSTOMERS OF THE BUSINESS

7.1. Communication on the storefront

7.1.1. Visitors may communicate with AI employees and employees of the business on the company page and in the widget without registration (as a guest) or under their AI² account, and may leave contact details, reviews and enquiries. Employees of the business with the relevant rights see the correspondence and may join the conversation.

7.1.2. The correspondence of Visitors with AI employees is stored on the Operator's servers and is available to the business within the access rights established by the structure of the business.

7.2. Forms and requests

7.2.1. A business may create forms and requests, define their fields and receive customers' responses. The business determines the scope of the data requested and is responsible for compliance with the principle of data minimisation and for informing customers of the purposes of collection.

7.3. Customer documents

7.3.1. Customers of a business may send documents to the business through the Service. Documents are stored in private storage, are accessible only to authorised employees of the business, and are deleted upon expiry of 90 (ninety) days from upload, unless the business deletes them earlier.

7.4. Customer lists, deals and reports

7.4.1. A business may import into the Service its own customer lists (name, email address, telephone, Telegram username, external identifier), deals and reports. The business warrants that it has a lawful basis for such processing, including for subsequently contacting customers.

7.4.2. On the basis of the business's data, the Service may generate customer summaries using AI. Summaries are of an auxiliary nature and do not constitute a basis for decisions producing legal effects for the customer without human review.

7.5. Invoices and payment requests

7.5.1. A business may issue invoices and payment requests to its customers through the Service. Payment by the customer is made through the payment acceptance method configured by the business; the Operator is not the recipient of such funds and is not responsible for the performance by the business of its obligations to the customer.

7.6. Relationship between the business and its customers

7.6.1. Contracts, claims and settlements between a business and its customers constitute a relationship between the business and its customers. The business itself complies with the legislation on consumer protection, advertising and trade, and with other requirements applicable to its activities.


8. INTEGRATIONS

8.1. A business may connect integrations:
• widget — for placing AI employees on the business's own websites on the domains specified by the business;
• API keys — for data exchange between the Service and the business's systems;
• webhooks — for transmitting events of the Service to the addresses specified by the business;
• the business's Telegram bot — for communication of AI employees with customers in Telegram;
• the business's CDEK keys — for arranging delivery under the business's contract with the delivery service;
• payment acceptance settings — for accepting payments from the business's customers through the business's payment provider.

8.2. Data transmitted through integrations (for example, to Telegram, CDEK, the business's payment provider or webhook addresses) are transmitted on the instructions of the business; the recipients process them in accordance with their own rules and under their contracts with the business. The Operator is not responsible for the actions of such recipients.

8.3. The business must keep API keys, CDEK keys and other secrets confidential, revoke compromised keys without delay, and place the widget only on websites that it lawfully controls. The business must inform the visitors of its website about the operation of the widget in its privacy policy.

8.4. The Operator may limit the rate of API requests and suspend an integration that poses a security threat or places a load on the Service.


9. ADVERTISING AND PROMOTION

9.1. A business may order promotion and advertising: search priority, advertising in AI chats, mentions in AI replies, and contextual advertising (Appendix 1).

9.2. Advertising materials and campaigns undergo moderation. Advertising in the Service, including in AI replies, is always labelled as advertising; information about the advertiser is available to the Visitor (Article 26 DSA).

9.3. The advertiser is responsible for the accuracy and lawfulness of the advertising, for holding the rights to the materials used, and for compliance with the advertising legislation of the countries in which the advertising is displayed.

9.4. The advertiser is provided with impression and click statistics: the viewer's country and language, the text of the query for which the advertisement was displayed, and the number of impressions and clicks. Statistics are provided in aggregated form and contain no information enabling the viewer to be identified.

9.5. Advertising is not selected on the basis of the content of Visitors' correspondence with AI employees and does not use profiling based on special categories of personal data (Article 26(3) DSA).


10. PAID SERVICES AND PAYMENTS

10.1. General provisions

10.1.1. The price of paid services is stated in AI² Tokens. The list and prices of services are set out in Appendix 1; current prices are displayed on the Website and in the Dashboard and take precedence over Appendix 1. For items priced "from", the final price is agreed with the Operator's manager after the request has been reviewed.

10.1.2. The AI² Token is a notional unit for recording the volume of paid services; it is not electronic money, a cryptocurrency, a security or any other financial instrument, is not exchangeable for money and cannot be withdrawn from the Platform.

10.1.3. The conversion rate of AI² Tokens into EUR, USD and other currencies is set by the Operator and published on the Website. The equivalent price in local currency is shown on the Website and in the Dashboard. The Operator may change the conversion rate with 14 (fourteen) days' prior notice to Users.

10.1.4. The AI² balance is single for the account across all applications of the AI² Platform (clause 1.23).

10.2. Topping up the balance

10.2.1. The AI² balance may be topped up by the following methods (availability depends on the country):
• bank cards via certified payment gateways;
• cryptocurrency via the payment providers specified on the Website;
• digital activation codes (cards and flyers);
• app stores (Google Play, App Store) — when topping up in the Application;
• other methods specified on the Website.

10.2.2. A top-up of the balance is irrevocable; money is refunded only in the cases specified in clause 10.8.

10.3. Order and payment

10.3.1. An order placed in the Dashboard is paid immediately from the AI² balance. If the balance is insufficient, the invoice for the order awaits a top-up and is paid automatically once the balance is topped up, provided the top-up occurs within 14 (fourteen) days from the selection of the payment method. Upon expiry of that period, the invoice reverts to the "issued" status and is no longer paid automatically upon a top-up: the business may pay it manually in the Dashboard or cancel the order.

10.3.2. Provision of the service begins after payment of the order and, for services requiring moderation or agreement (advertising, items priced "from"), after their approval.

10.4. Payment by invoice (bank transfer)

10.4.1. Companies may pay for services by bank transfer against the Operator's invoice. The service is provided after the funds have been credited to the Operator's account. Closing documents are provided upon request to [email protected].

10.5. Recurring services and automatic renewal

10.5.1. Monthly services (company page in the catalogue, search priority, recurring advertising) are renewed automatically for the next period: 3 (three) days before the end of the paid period, an invoice is issued and paid from the AI² balance.

10.5.2. The business may cancel renewal in the Dashboard at any time. After cancellation, the service remains in effect until the end of the paid period.

10.6. Non-payment for the company page

10.6.1. If the company page has not been paid for, a grace period of 7 (seven) days applies after the end of the paid period (or after a payment reminder). Upon its expiry, the company page is unpublished and the business's AI employees are hidden from the catalogue.

10.6.2. After payment, the company page and the AI employees are restored automatically, without repeated moderation of previously approved content.

10.7. Payment through an app store

10.7.1. When the balance is topped up in the Application through Google Play or the App Store, payment is made using the means of the relevant store at the price stated in the store. Refunds of such payments are requested from the store in accordance with its rules.

10.8. Refunds

10.8.1. The price of a paid service period is not refunded, except where the service was not provided through the fault of the Operator; in that case, the price of the part not provided is returned to the AI² balance or, at the User's request, by the same method by which payment was made.

10.8.2. When an advertising campaign is stopped, the unspent remainder is returned to the AI² balance.

10.8.3. The AI² balance is not refunded in money, except in cases provided for by the mandatory provisions of applicable law, as well as in cases of technical failures and double charging attributable to the Operator.

10.8.4. Payments made by bank transfer are refunded (where there are grounds) by the same method — to the bank account from which the payment was received.

10.8.5. Money is refunded (where there are grounds) within 14 (fourteen) days from approval of the request. The request is sent to [email protected], stating the reason and the details of the transaction.

10.9. Consumer rights

10.9.1. If the User is a consumer within the meaning of applicable law, he or she retains the right to withdraw from the contract within 14 (fourteen) days in accordance with Directive 2011/83/EU, provided that performance of the digital service has not yet begun. By ordering a service with immediate commencement of performance, the consumer gives consent to its immediate commencement and acknowledges that he or she is aware of losing the right of withdrawal once the service has been fully performed.

10.9.2. Consumers from EU countries may also contact an alternative dispute resolution (ADR) body or the consumer protection authority of their country of residence.


11. RULES OF USE

11.1. General rules

11.1.1. The User undertakes:
• to use the Service in good faith and in accordance with its intended purpose;
• to provide accurate information about himself or herself and about the business;
• to comply with the law applicable to the business and to the countries of presence;
• to respect the rights of customers of the business, other users and third parties;
• not to use the Service for purposes contrary to this Agreement.

11.2. Prohibited content

11.2.1. It is prohibited to post, transmit or distribute on company pages, in advertising, in the instructions and knowledge bases of AI employees, in forms and in correspondence:
• child sexual abuse material (CSAM) and any sexualisation of minors;
• pornographic material;
• material promoting violence, terrorism or extremism;
• material inciting hatred or enmity on the basis of protected characteristics;
• knowingly false information, defamation, unfair or misleading advertising;
• offers of goods and services the circulation of which is prohibited or requires a licence that the business does not hold;
• malware and phishing material;
• personal data of third parties without a lawful basis;
• content infringing copyright, trade mark rights or other intellectual property rights;
• other illegal content within the meaning of Regulation (EU) 2022/2065 (DSA) and the legislation of the countries of presence.

11.3. Prohibited actions

11.3.1. It is prohibited:
• to impersonate another person or another business, or to create pages of businesses that the User is not entitled to represent;
• to use AI employees and the Service for fraud, spam, intrusive mailings or collection of data without a lawful basis;
• to contact customers from imported lists without a lawful basis, including sending advertising without their consent where such consent is required;
• to use the Service to promote escort services and prostitution;
• to attempt to gain unauthorised access to the accounts and data of other users and businesses;
• to transfer the account to third parties (human employees are used for collaboration, clause 3.3);
• to circumvent the technical restrictions, moderation and payment of the Service.

11.4. Rules for the use of AI

11.4.1. The User undertakes:
• not to give AI employees instructions aimed at deceiving customers, discrimination or breaking the law;
• not to attempt to extract system instructions, model parameters or other confidential information about the Operator's AI services (prompt injection);
• not to use AI replies to mislead third parties, including by presenting them as statements made by a human being;
• not to upload to the knowledge base information relating to special categories of personal data without a lawful basis (clause 3.3 of Appendix 2).

11.4.2. The Administration may restrict access to AI features for a User who breaches these rules, with notification of the reasons.

11.5. Moderation and appeals

11.5.1. The Administration moderates content in accordance with the DSA manually and by automated means. The Administration may remove or hide content, restrict features, and suspend or block a company page, an AI employee or an account, stating the reasons.

11.5.2. A moderation decision may be appealed by contacting [email protected]. The period for review is 15 (fifteen) business days. Complaints are reviewed with human involvement.

11.5.3. The User may refer the matter to a certified out-of-court dispute settlement body (Article 21 DSA) or to a mediator (Article 12 of Regulation (EU) 2019/1150) if he or she is not satisfied with the outcome of the internal procedure.

11.6. Notices of illegal content

11.6.1. Any person may report illegal content on a company page, in advertising or in the replies of an AI employee by using the "Report" action or by sending a message to [email protected], stating the address of the page and the reasons. The Administration reviews notices, as a rule, within 5 (five) business days and informs the notifier of the decision taken.

11.7. Child protection

11.7.1. The Platform maintains zero tolerance towards child sexual abuse and exploitation (CSAE) and CSAM. Confirmed material is removed, the responsible account is permanently blocked, and the information is reported to the competent authorities as required by applicable law.


12. INTELLECTUAL PROPERTY

12.1. All exclusive rights to the Service, including the program code, design, logos, interface texts, models and algorithms of the AI services (Mars LLM Service), the synthesised voices of the Service, databases and the catalogue (its structure and content to the extent created by the Operator), and the AI² and TwinCard trade marks, belong to the Operator or are used by it on lawful grounds.

12.2. The rights to the content of a business (company page information, logos, photographs, texts, instructions of AI employees, the knowledge base, advertising materials) remain with the business or its right holders.

12.3. By posting content in the Service, the User grants the Operator a non-exclusive, royalty-free, worldwide licence to use such content for the purposes of providing the Service: storage, processing, display in the catalogue, on the company page and in the widget, publication on the TwinCard websites of the selected countries of presence, display in search results and in the replies of AI employees, as well as in advertising ordered by the business.

12.4. The licence terminates upon deletion of the content or the account, except for anonymised statistical data and copies that are retained for the backup retention periods.

12.5. The User warrants that his or her content does not infringe the rights of third parties and undertakes to settle claims of third parties at his or her own expense and to compensate the Operator for losses incurred in connection with them.

12.6. The replies of AI employees are provided for use in the activities of the business. The Operator does not guarantee the uniqueness of the replies or the absence of similarities between them and third-party materials.


13. PERSONAL DATA

13.1. Roles of the parties

13.1.1. The Operator is the controller of personal data in respect of: account data of Users and human employees; contact persons of a business; settlement and payment data; moderation, complaint and security data (including protection against spam and abuse); technical data of visitors to the Website; search queries and aggregated statistics.

13.1.2. The business is the controller and the Operator is the processor, acting on behalf of and on the documented instructions of the business, in respect of the personal data of customers and Visitors of the business processed through AI employees, correspondence, forms and requests, documents, customer lists, deals, reports and summaries, and the business's integrations, as well as voice samples uploaded by the business. The terms of such processing are set out in the Data Processing Agreement (Appendix 2), which forms an integral part of this Agreement and is accepted by the business together with it.

13.1.3. Company page information is published at the business's choice; the business is the controller in respect of the personal data contained therein.

13.2. Processing by the Operator as controller

13.2.1. The processing of personal data by the Operator as controller is carried out in accordance with the GDPR and the Privacy Policy published on the Website. Legal bases: performance of a contract (Article 6(1)(b) GDPR), legal obligation (Article 6(1)(c)), legitimate interest (Article 6(1)(f)) and consent (Article 6(1)(a)) — in the cases specified in the Privacy Policy.

13.2.2. Contact for data protection matters: [email protected] (marked "Data Protection").

13.3. Rights of data subjects

13.3.1. Data subjects have the rights provided for in Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection, rights in relation to automated decision-making, withdrawal of consent) and the right to lodge a complaint with a supervisory authority. The procedure for exercising them is set out in the Privacy Policy.

13.3.2. Requests from customers of a business concerning data for which the business is the controller are handled by the business; the Operator assists the business in accordance with Appendix 2 and, upon receiving such a request directly, forwards it to the business.

13.4. International transfers and servers in different jurisdictions

13.4.1. Account data are replicated between the Platform's servers in different jurisdictions to the extent necessary for single sign-on to the applications of the AI² Platform. Company page information is published on the TwinCard websites of the selected countries of presence (clause 5.3).

13.4.2. Data are transferred outside the EEA in compliance with Chapter V GDPR (Articles 44–49), including on the basis of adequacy decisions and the Standard Contractual Clauses adopted by the European Commission.


14. LIABILITY OF THE PARTIES

14.1. Liability of the User and the business

14.1.1. The User and the business are responsible for:
• the accuracy of the information about themselves and about the business;
• the content of the company page, advertising, and the instructions and knowledge base of AI employees;
• the information that the business's AI employees communicate to customers (clause 6.3);
• the lawfulness of the processing of personal data of customers for which the business is the controller;
• the actions of the business's human employees and actions performed using the account;
• the performance of the business's obligations to its customers.

14.1.2. In the event of a breach of the Agreement, the Administration may issue a warning, restrict features, unpublish content, block the account temporarily (for up to 30 days) or permanently, and contact law enforcement authorities.

14.1.3. The business shall indemnify the Operator for losses, fines and expenses incurred in connection with claims of third parties (including customers of the business and supervisory authorities) arising from the business's breach of this Agreement or of the law.

14.2. Liability of the Operator

14.2.1. The Operator undertakes:
• to ensure the functioning of the Service with a reasonable level of availability;
• to take appropriate technical and organisational measures to protect data (Article 32 GDPR);
• to handle requests within the established time limits;
• to notify personal data breaches in accordance with Articles 33–34 GDPR and Appendix 2.

14.2.2. The Operator is not liable for:
• the content and accuracy of the information of businesses and of advertising;
• the relationships between businesses and their customers, or the quality of the goods and services of businesses;
• the accuracy of the replies of AI employees configured by a business, or of the results of the "From the Internet" block;
• the actions of third-party services connected by a business (Telegram, CDEK, the business's payment providers, webhook recipients), or of app stores and payment systems;
• temporary unavailability of the Service for reasons beyond the Operator's control;
• loss of profit and indirect losses of the business.

14.2.3. To the extent permitted by applicable law, the aggregate liability of the Operator is limited to the amount paid by the User for services of the Service during the last 12 (twelve) months. The limitation does not apply to cases of intent or gross negligence of the Operator, harm to life and health, or liability that cannot be limited by law.

14.3. Force majeure

14.3.1. The parties are released from liability for non-performance of obligations resulting from force majeure circumstances: natural disasters, military operations, epidemics, changes in legislation, acts of public authorities, and large-scale failures of communication networks and power supply.


15. NOTIFICATIONS AND COMMERCIAL COMMUNICATIONS

15.1. Service notifications (concerning orders, invoices, renewal, moderation, customer enquiries and security) are sent in the Dashboard, by email and (where permitted) as push notifications in the Application, and form part of the performance of the contract.

15.2. Advertising and marketing communications of the Operator are sent only with consent (Article 13 of Directive 2002/58/EC) and may be switched off at any time via the link in the email, in the settings, or upon request to [email protected].

15.3. The content of Visitors' correspondence with AI employees is not used for selecting and displaying advertising.


16. AMENDMENT AND TERMINATION OF THE AGREEMENT

16.1. Amendment of the Agreement

16.1.1. The Operator may amend the Agreement. Amendments take effect 30 (thirty) days after notification of Users (which is not shorter than the period established by Article 3 of Regulation (EU) 2019/1150), unless a longer period is specified in the amendment itself. Amendments required by law may take effect within the period established by law.

16.1.2. Notification is made by publication on the Website and in the Application, by email and in the Dashboard.

16.1.3. Amendments affecting the processing of personal data, the price of services, the liability of the parties, the dispute resolution procedure and the rights of data subjects are deemed material.

16.1.4. If the User does not agree with the amendments, he or she may terminate the Agreement and delete the account before the amendments take effect. Continued use of the Service after the amendments take effect constitutes acceptance of the new edition.

16.2. Termination of the Agreement

16.2.1. The User may terminate the Agreement at any time by deleting the account (clause 3.5).

16.2.2. The Operator may terminate the Agreement by blocking the account in the event of a breach of the Agreement, detection of fraudulent or unlawful activity, at the request of competent authorities, or where the account has not been used for more than 24 (twenty-four) consecutive months (after 30 days' notice). The Operator gives at least 30 (thirty) days' notice of termination of the provision of services to a business user, except in the cases provided for by Article 4(4) of Regulation (EU) 2019/1150.

16.2.3. Termination does not release the parties from obligations that arose before termination. The provisions of Appendix 2 on the return and deletion of data remain in effect until they have been performed.


17. DISPUTE RESOLUTION

17.1. Disputes are resolved through negotiation. A claim is sent to [email protected]; the period for review is 30 (thirty) calendar days. The reply is sent to the email address specified at registration.

17.2. Business users may use the internal complaint-handling system (clause 11.5) and mediation in accordance with Articles 11–12 of Regulation (EU) 2019/1150.

17.3. Consumers from EU countries may contact an alternative dispute resolution (ADR) body or the consumer protection authority of their country of residence.

17.4. If a dispute is not settled, it shall be submitted to the competent court in accordance with applicable law. This provision does not restrict the right of a consumer to bring proceedings before the courts of his or her place of residence (Regulation (EU) No 1215/2012, Brussels I bis).

17.5. The applicable law is determined in accordance with Regulation (EC) No 593/2008 (Rome I). For consumers residing in the EU, the mandatory consumer protection provisions of their country of residence apply.

17.6. A data subject may lodge a complaint with a data protection supervisory authority in the Member State of his or her habitual residence, place of work or place of the alleged infringement.


18. FINAL PROVISIONS

18.1. The Agreement enters into force upon acceptance and remains in force indefinitely until terminated.

18.2. The invalidity of any individual provision does not affect the validity of the remaining provisions; an invalid provision is replaced by a valid provision that most closely reflects its purpose.

18.3. The appendices to the Agreement and the Privacy Policy form an integral part of it. In respect of the processing of personal data of customers of a business, Appendix 2 prevails in the event of conflict.

18.4. Failure by the Operator to act upon a breach of the Agreement does not constitute a waiver of the right to assert claims at a later date.

18.5. The business may not assign its rights under the Agreement without the Operator's consent. The Operator may assign its rights and obligations to a person continuing to provide the Service, with notification of Users.

18.6. Nothing in the Agreement limits the rights granted to the User by the mandatory provisions of applicable law.

18.7. Questions, comments and suggestions may be sent to:
• Email: [email protected]
• Website: https://twincard.ai

18.8. This Agreement is drawn up in the English language. In the event of translation into other languages, the English-language text shall prevail.


APPENDIX 1. PAID SERVICES AND PRICES

ServicePricePayment terms
Company page in the TwinCard catalogue5 AI² per monthMonthly, with automatic renewal
Search priority20 AI² per monthMonthly, with automatic renewal
Advertising in AI chatsfrom 100 AI² per monthMonthly; price agreed with the manager
Mentions in AI repliesfrom 300 AI² per monthMonthly; price agreed with the manager
Creation and placement of a custom AI model1,000 AI²One-off
Digital stafffrom 2,000 AI²One-off; price agreed with the manager
Contextual advertising0.004 AI² per impression (4 AI² per 1,000 impressions)Charged per actual impressions

Items priced "from" are arranged after the request has been reviewed; the final price is agreed with the Operator's manager before payment.

The equivalent price in EUR, USD and other currencies is calculated at the conversion rate published on the Website. The current list of services and prices is displayed on the Website and in the Dashboard and takes precedence over this appendix. The prices in effect at the time the order is placed apply. A change in prices does not affect a paid period. The procedure for payment, renewal and refunds is set out in Section 10.


APPENDIX 2. DATA PROCESSING AGREEMENT (DPA)

This appendix constitutes a data processing agreement within the meaning of Article 28(3) GDPR between the business (hereinafter in this appendix, the "Controller") and the Operator (hereinafter in this appendix, the "Processor").

1. Subject matter and duration

1.1. The Processor processes personal data of the Controller's customers and Visitors to the extent necessary to provide the Controller with the features of the Service specified in Sections 6–8 of the Agreement.

1.2. Processing continues for the period during which the Controller uses the Service and until the data are deleted in accordance with clause 9 of this appendix.

2. Nature and purposes of processing

2.1. Nature of processing: collection via the company page, the widget, forms and integrations; recording, storage, indexing, retrieval, structuring, generation of replies of AI employees and customer summaries, speech synthesis, transmission via integrations specified by the Controller, and erasure.

2.2. Purposes of processing: communication of AI employees and employees of the Controller with its customers; receipt of enquiries, requests, reviews and documents; maintenance of customer lists, deals and reports; issuing invoices to customers; delivery and acceptance of payments through the Controller's integrations; voicing replies with an own voice.

3. Categories of data and data subjects

3.1. Data subjects: visitors to the Controller's company pages and widgets; customers and prospective customers of the Controller; persons whose data are contained in the Controller's customer lists, deals, reports and documents; persons who have provided voice samples.

3.2. Categories of data: name, contact details (email address, telephone, Telegram username), external identifiers; the content of correspondence, enquiries, forms, requests and reviews; documents sent by customers; information on deals, orders, invoices and delivery; customer summaries; voice samples and consent phrases; technical data of the guest session.

3.3. The Controller does not transfer to the Service special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR), except where the Controller has a lawful basis for doing so and such data are necessary for its activities; the Controller itself assesses such necessity.

4. Obligations of the Processor

4.1. The Processor:
• processes data only on the documented instructions of the Controller, including the settings of the Service made by the Controller and this Agreement, unless otherwise required by law (in which case the Processor informs the Controller, unless the law prohibits this);
• immediately informs the Controller if, in its opinion, an instruction infringes the GDPR;
• ensures that persons authorised to process the data have committed themselves to confidentiality;
• takes the technical and organisational measures under Article 32 GDPR described in the Privacy Policy (encryption in transit, access control, logging, backup, infrastructure protection);
• does not use the Controller's data for its own purposes, including for training models for the benefit of third parties or for advertising;
• does not transfer data to third-party providers of artificial intelligence services: processing is performed by the Processor's own models on its servers.

5. Sub-processors

5.1. The Controller gives general authorisation for the engagement of sub-processors. The Processor engages only providers of its own infrastructure: the data centres and hosting providers in which the Processor's servers are located, and the provider of the content delivery network and DDoS protection (Cloudflare) for the TwinCard websites.

5.2. The Processor imposes on sub-processors data protection obligations no less stringent than this appendix and is liable for their performance. The Processor informs the Controller of any intended engagement or replacement of sub-processors at least 14 (fourteen) days in advance (in the Dashboard or by email); the Controller may object on reasonable grounds and, if no agreement is reached, terminate the Agreement.

5.3. Recipients to which data are transmitted via integrations selected by the Controller (Telegram, CDEK, the Controller's payment provider, webhook and API recipients) are not sub-processors of the Processor: the transmission is made on the Controller's instructions.

6. Assistance to the Controller

6.1. Taking into account the nature of the processing, the Processor assists the Controller:
• in responding to requests from data subjects (Articles 15–22 GDPR) — by providing in the Service features for viewing and deleting data, providing information about the data upon request, and forwarding to the Controller requests received directly;
• in ensuring security, carrying out data protection impact assessments (Article 35 GDPR) and prior consultation with the supervisory authority (Article 36 GDPR) — by providing the necessary information about the processing.

7. Personal data breaches

7.1. The Processor notifies the Controller of a personal data breach without undue delay after becoming aware of it, providing the available information on the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken, so that the Controller can fulfil its obligations under Articles 33–34 GDPR.

8. International transfers

8.1. The Processor may process data outside the EEA (including in the Republic of Kazakhstan, where the Processor is established) in compliance with Chapter V GDPR; the applicable Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are deemed incorporated into this appendix by reference in the relevant module.

9. Deletion and return of data

9.1. Upon the end of the provision of services, the Controller may request a copy of its data at [email protected] within the scope of the right to data portability (Article 20 GDPR). The Controller's data are deleted within the time limits specified in clause 3.5 of the Agreement, unless the law requires their retention; customer documents are deleted 90 (ninety) days after upload (clause 7.3 of the Agreement). Backup copies are overwritten in the course of the normal backup cycle.

10. Audits and information

10.1. The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR upon request to [email protected]. Audits are conducted primarily by providing written information and documents; on-site inspections are permitted where the information is insufficient or where required by a supervisory authority, subject to at least 30 days' prior notice, during business hours, subject to confidentiality and at the Controller's expense.

11. Obligations of the Controller

11.1. The Controller:
• has a lawful basis for processing the data of its customers and Visitors, including importing customer lists and contacting customers;
• informs its customers of the processing of their data (Articles 13–14 GDPR), including the operation of AI employees and the use of the Service, and places the relevant information in its privacy policy;
• informs customers that they are communicating with artificial intelligence (clause 6.4 of the Agreement);
• does not upload special categories of data without a lawful basis (clause 3.3 of this appendix);
• obtains the consent of the person concerned to the creation of an own voice (clause 6.5 of the Agreement);
• is responsible for the lawfulness of its instructions, settings and integrations and for responding to requests from data subjects.

12. Precedence

12.1. In the event of a conflict between this appendix and other provisions of the Agreement concerning the processing of personal data of the Controller's customers, this appendix prevails.


APPENDIX 3. PROCEDURE FOR HANDLING REQUESTS

Types of requests

  1. Technical support — operation of the Service, integrations, payment.
  2. Content complaint — a report of illegal content on a company page, in advertising or in the replies of an AI employee (DSA).
  3. Moderation appeal — disagreement with a refusal to publish, removal of content or blocking.
  4. Personal data request — exercise of the rights of a data subject.
  5. Own voice request — withdrawal of consent by the person whose voice was used.
  6. Claim — pre-trial settlement of a dispute, including concerning refunds.

Response times

Type of requestResponse time
Technical support1–5 business days
Content complaint5 business days
Moderation appeal15 business days
Personal data requestOne month (Article 12(3) GDPR)
Own voice requestWithout delay, no later than 5 business days
Claim30 calendar days

Contact details


APPENDIX 4. LIST OF APPLICABLE LEGISLATION

  1. Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
  2. Directive 2002/58/EC — Directive on privacy and electronic communications (ePrivacy)
  3. Directive 2011/83/EU — Consumer Rights Directive
  4. Directive 2000/31/EC — Directive on electronic commerce
  5. Regulation (EU) 2022/2065 — Digital Services Act (DSA)
  6. Regulation (EU) 2019/1150 — on promoting fairness and transparency for business users of online intermediation services (P2B)
  7. Regulation (EU) 2024/1689 — Artificial Intelligence Act (EU AI Act)
  8. Directive 2001/29/EC — Directive on copyright in the information society
  9. Directive 96/9/EC — Directive on the legal protection of databases
  10. Regulation (EU) No 1215/2012 — Brussels I bis (jurisdiction)
  11. Regulation (EC) No 593/2008 — Rome I (applicable law)

Date of publication: September 25, 2026

Operator:
Private Company "New Reality" (New Reality Ltd)
BIN: 220440900016
Legal address: Republic of Kazakhstan, Astana, Zhenis Avenue, building 1, office 29
Email: [email protected]
Phone: +7 (747) 029-43-05
Website: https://twincard.ai