Skip to document
sayws
Back to home

Legal information

Privacy Policy

This Policy explains how personal data is processed when you visit the website, request access, use the dashboard or connect customer-support channels. It forms part of the Terms of Use.

Effective date: 28 September 2026

1. Operator and scope

The administrator of sayws, identified at the end of this document, is the operator of data relating to website visitors, applicants and account users.

When a business customer connects WhatsApp, Instagram, Telegram or another channel, that customer determines the purposes for processing its own customers' data. sayws processes that data on the customer's instructions solely to provide the service, unless the law requires otherwise.

2. Data we process

The data involved depends on the features you use.

  • application and account data, including business name, name, work email, phone number, selected plan, roles and settings;
  • security data, including password hash, sign-in records, IP address, device data, audit events and anti-bot results;
  • support data, including messages, participant identifiers and names, contact details, attachments, conversation status and staff replies;
  • booking data, including customer name, phone number, service, date, time, notes and status;
  • technical data, including cookies, language, time zone, requested page and diagnostic events;
  • billing and contract details if paid features are activated. We do not store full payment-card details.

3. Why we use data

We process only the data reasonably needed for the stated purposes.

  • review applications and create and administer accounts;
  • route enquiries, generate AI-assisted replies and hand conversations to people;
  • perform bookings, notifications and other customer-enabled actions;
  • provide support, secure the service, prevent abuse and diagnose faults;
  • measure plan usage, issue documents and perform the contract;
  • comply with law and protect the legitimate rights of the parties.

4. Legal grounds and consent

Processing may be based on consent, steps to enter or perform a contract, a legal requirement or another ground permitted by law. Consent is obtained through an action that can be evidenced, such as selecting a checkbox and submitting a form.

A user who uploads or transmits another person's data confirms that the required notices, consents or other lawful grounds are in place. Do not submit excessive information, sensitive categories or state secrets unless expressly agreed and legally permitted.

5. AI and service providers

The message and knowledge-base excerpts needed to generate a reply may be sent to the selected AI model provider. We may also use hosting, bot protection, monitoring, email and connected messaging-platform providers.

Providers receive only the data required for their function and process it under contract or the platform's own terms. A current list of material processors is available on request.

The sign-in and application forms are protected by the Cloudflare Turnstile anti-bot check. During the check Cloudflare receives the IP address and technical details about the browser and device, processes them outside Kazakhstan under its own privacy policy and tells us only the result. These details are not used for advertising.

6. Storage and international transfers

We select storage locations and transfer mechanisms in accordance with applicable law. Where Kazakhstan law requires a personal-data database to be stored in Kazakhstan, the primary database is hosted in Kazakhstan.

A transfer to another country takes place only where the required protection and legal ground are present, including consent where required. A foreign platform connected by the customer may transfer data under that platform's terms.

7. Retention and security

Data is retained until the processing purpose is met, the contract and mandatory retention period end, and is then deleted or anonymised. Backups may remain for a limited additional recovery cycle.

We use access controls, encryption in transit, password hashing, security logs, backups and other reasonable organisational and technical safeguards. No system removes all risk; incidents are handled as required by law and contract.

8. Your rights

To the extent provided by law, a data subject may:

  • ask whether and why their data is processed;
  • request correction, blocking or deletion of inaccurate or unlawfully processed data;
  • withdraw consent where processing relies on consent;
  • object to certain processing and complain to the competent authority or a court.

9. Cookies and local preferences

The service uses necessary cookies for sign-in, security, language, theme and time-zone preferences. They are needed for the site to work and are not used to sell personal data.

If optional analytics or advertising technology is added, we will update this Policy and request separate consent before enabling it where required.

10. Changes and requests

The current version appears on this page with a new effective date. Material changes affecting active customers will be announced in the service or by email.

Send privacy requests to the contact shown below. To protect data, we may ask you to verify your identity and connection to the relevant account or conversation.

Service administrator

Name
sayws
Contact email
support@sayws.com

Legal basis

Related document: Terms of Use and Public Offer