Legal

Privacy Policy

Effective date: June 1, 2026  ·  Last updated: June 1, 2026

the Company (“the Company,” “we,” “us,” or “our”) is committed to protecting the privacy of individuals who interact with our platform. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it. It applies to all visitors to our website, prospective customers, and users of the the Company platform.

1. Who We Are

the Company is a Delaware corporation that operates a multi-tenant AI agent SaaS platform. Depending on the context, the Company acts as:

  • Data controller — for personal data we collect directly from visitors to our marketing website, trial sign-ups, and direct contacts (e.g., support requests, newsletter subscribers).
  • Data processor — for personal data that our customers (tenants) submit to the platform on behalf of their own end-users. In this role, we act on the customer's documented instructions as set out in our Data Processing Agreement (DPA).

For questions about this policy or to exercise your rights, see Section 11 (Contact & DPO).

2. What Data We Collect

We collect the following categories of personal data:

Account Data

When you register for an the Company account or trial, we collect your name, work email address, organization name, phone number (optional), country, and the password you set (stored as a one-way hash — never in plain text or exposed via API). We also record the timestamp and IP address of account creation for security auditing.

Usage Data

We automatically collect technical and behavioral data when you interact with the platform, including: IP address, browser type and version, operating system, pages visited and time spent, features used, API request metadata (endpoint, latency, response code), and error logs. This data is pseudonymized where feasible and is used to operate, secure, and improve the Services.

Conversation Data

When your deployed AI agents handle conversations with end-users, we store the message content, channel metadata (e.g., WhatsApp sender hash, Telegram chat ID), timestamps, agent configuration at the time of the conversation, and inference metadata. This data is tenant- isolated and is processed on your behalf as data processor. You are responsible for obtaining appropriate consent from your end-users.

Payment Data

We do not store full payment card numbers or sensitive payment credentials. Payment processing for the Global track is handled entirely by Stripe, Inc., which stores payment method details on our behalf under their own security certifications (PCI-DSS Level 1). For the Iran track, payment processing is handled by ZarinPal. We receive and store only tokenized references, transaction IDs, billing addresses, and subscription status from these processors.

Communications Data

If you contact us for support, respond to surveys, or communicate with our team by email or in-app chat, we retain the content of those communications to resolve your request and improve our services.

3. How We Use Data

We use personal data for the following purposes:

  • Providing the Services — provisioning your tenant, running AI agents, processing conversations, and delivering API responses.
  • Account management — authenticating users, managing roles and permissions, and sending transactional emails (e.g., password resets, billing receipts).
  • Billing and payments — processing subscriptions, invoicing, and handling disputes.
  • Security and fraud prevention — detecting abuse, unauthorized access, and policy violations.
  • Product improvement — analyzing aggregated, anonymized usage patterns to improve features and performance. We do not use your tenant's conversation data to train shared AI models without your explicit written consent.
  • Legal compliance — complying with applicable laws, regulations, and lawful requests from competent authorities.
  • Marketing communications — sending product updates and newsletters to users who have opted in. You may unsubscribe at any time via the link in any marketing email.

5. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, or as required by applicable law. Our standard retention schedules are:

Data TypeHot StorageCold / Archive
Conversation messages12 months (queryable)5 years (compressed archive)
Audit logs (access, changes, API)90 days (searchable)7 years (compliance archive)
Account and billing recordsDuration of account + 30 days7 years (tax/financial obligation)
Support communications3 years from ticket closeNot archived
Marketing consent recordsUntil consent withdrawn + 3 yearsNot archived
Security event logs90 days1 year

After the applicable retention period, data is deleted or irreversibly anonymized. Tenant customers may request earlier deletion of their Tenant Data subject to applicable legal retention obligations and as described in the DPA.

6. Data Subject Rights

If you are in the EEA, UK, or Switzerland, or in any jurisdiction with applicable data protection law, you have the following rights with respect to your personal data:

  • Right of access — You may request a copy of the personal data we hold about you and information about how we process it.
  • Right to rectification — You may ask us to correct inaccurate or incomplete personal data.
  • Right to erasure (“right to be forgotten”) — You may request deletion of your personal data where we have no legal basis or overriding legitimate interest to retain it.
  • Right to data portability — You may request a machine-readable export of personal data you have provided to us, to the extent technically feasible.
  • Right to restrict processing — You may ask us to restrict processing of your data while a dispute about its accuracy or legality is being resolved.
  • Right to object — You may object to processing based on legitimate interests or for direct marketing purposes.
  • Rights related to automated decision-making — You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects, unless such processing is necessary for a contract, authorized by law, or based on your explicit consent.

To exercise any of these rights, submit a request to privacy@alsaas.com. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request. There is no fee for exercising these rights unless requests are manifestly unfounded or excessive.

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the supervisory authority in your country of residence or place of work. In the EU, you may find the relevant authority at edpb.europa.eu.

7. Cookies

We use cookies and similar tracking technologies on our marketing website and dashboard. Cookies are small text files stored on your device. We use the following categories:

  • Strictly necessary cookies — Required for the platform to function (authentication sessions, CSRF tokens, load balancer affinity). These cannot be disabled.
  • Analytics cookies — Help us understand how visitors interact with our marketing site (e.g., pages visited, bounce rate). We use privacy-preserving analytics tools that anonymize IP addresses. These are set only with your consent.
  • Preference cookies — Remember your settings such as language, theme, and notification preferences.

You can manage your cookie preferences via our cookie banner (shown on first visit) or by adjusting your browser settings. Blocking strictly necessary cookies may impair the functionality of the platform.

8. Third-Party Processors

We engage the following sub-processors to help deliver the Services. All sub-processors are bound by data processing agreements and are required to implement appropriate technical and organizational security measures:

ProcessorPurposeRegion
OpenAI, Inc.LLM inference (Global track, where enabled)USA
Google CloudLLM inference, speech-to-text (Global track)USA / EU
Stripe, Inc.Payment processing (Global track)USA
ZarinPalPayment processing (Iran track)Iran
Amazon Web ServicesCloud infrastructure, storage, compute (Global track)USA / EU / regional
Arvan CloudCloud infrastructure, storage, compute (Iran track)Iran

We may update this list as we add or change sub-processors. We will provide notice of material changes via email or in-platform notification at least 14 days in advance, giving customers the opportunity to object under the DPA.

9. International Transfers

For customers in the EEA, UK, or Switzerland, your personal data may be transferred to and processed in countries outside your home jurisdiction, including the United States, where data protection laws may differ from those in your country.

Where such transfers occur, we ensure an adequate level of protection through one or more of the following mechanisms:

  • Standard Contractual Clauses (SCCs) — We execute the European Commission's approved SCCs (2021 version) with all sub-processors that receive EEA personal data.
  • Adequacy decisions — Where the European Commission has issued an adequacy decision for the destination country.
  • UK IDTA — For transfers from the UK, we rely on the UK International Data Transfer Agreement where applicable.

For customers on the Iran track, all personal data remains within Iran-based infrastructure. No international transfers of Iran-track data occur, and encryption keys never leave the Iran region.

A copy of our SCCs and transfer impact assessments is available upon written request to privacy@alsaas.com.

10. Data Breach Notification

In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, the Company will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR and equivalent applicable law.

Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals directly without undue delay, unless one of the exemptions under Article 34(3) of the GDPR applies (e.g., the data was encrypted such that it is unintelligible to unauthorized parties).

We will notify affected tenant customers of breaches involving their Tenant Data within 48 hours of our internal confirmation, as required by our DPA, to enable customers to meet their own notification obligations.

To report a suspected security incident, contact us immediately at security@alsaas.com.

11. Contact & DPO

If you have questions about this Privacy Policy, wish to exercise your data subject rights, or have a concern about how we handle personal data, please contact our Data Protection Officer:

Data Protection Officer — the Company

Email: privacy@alsaas.com

Subject line: “Privacy Request — [Your Name]”

For EEA residents who are not satisfied with our response, you have the right to escalate your complaint to your local data protection supervisory authority.