Introduction
Welcome to AILINCOM. We value your privacy and are committed to protecting personal data. This Privacy Policy describes what data we collect, how we use and share it when you use the AILINCOM website, mobile applications, API, and related services ("Services"), including interaction with digital avatars and AI features.
By using the Services, you confirm your agreement to this Policy. If you do not agree, please refrain from using the Services.
Personal Data We Collect About You
When you register, use the Services, create digital avatars, post content, or participate in AILINCOM communities, we collect data to provide and improve our services. "Personal Data" means information that identifies you directly or indirectly. Anonymized/aggregated data is not considered personal data unless linked to identifiers.
Categories of Data
1. User Data and Identifiers
- Name, pseudonym, email, phone number, avatar, bio, social media links, country/region, language.
- Account identifiers, roles (user, creator, organization), settings.
2. Payment Information
- For purchases/subscriptions: name, billing address, postal code, order details, taxes. Sensitive card details are processed by the payment provider; AILINCOM does not store full card data.
3. Payouts to Creators/Experts
- Banking/payment details processed through providers: account/bank name, account number/IBAN, etc.
- Tax information (country of residence, Tax ID, required forms).
4. Stored Card Data (Non-Sensitive)
- The last 4 digits and expiration date of a card may be stored if provided by the payment provider for payment convenience.
5. Technical Data and Logs
- IP address, user-agent, OS/browser type/version, security events, request logs, usage metrics, errors.
Data Modes for Experts/Users/Companies
- Open Data Data uploaded by an expert, company, or user into a digital avatar for interaction purposes: to determine user or bot needs; to verify required skills and experience; to determine the cost of service types and quality. This data may be used by the bot for initial qualification, offer selection, and preliminary calculations. Availability is limited to bot interactions and only to the extent necessary for the specified purposes; it is indexed within the platform according to the bot owner's settings.
- Commercial Data Data of an expert, user, or company necessary for commercialization and constituting a trade secret: prompts, private datasets, vector indexes, routing, integrations, pricing models, margin/royalties, output rules, monetization analytics. This data may be made available to users of a specific digital avatar on a paid basis or other terms determined by the bot owner. By default, it is inaccessible to third parties and protected by access policies.
- Personal Data Data used by an expert, company, or user for their own purposes using AILINCOM's built-in services (identifiers, contacts, documents, personal notes/files, etc.). Under no circumstances may this data be accessible to other ecosystem users or AILINCOM without the owner's express will, except in cases directly required by law and in the manner prescribed by it.
Architecture and AI
- AILINCOM uses an isolated architecture with role-based and policy-based access control; open, commercial, and personal data are stored and processed separately.
- RAG (Retrieval-Augmented Generation) is used: models receive only the minimum necessary context from permitted sources.
- AILINCOM does not train its own models on data uploaded by experts/users. The transmission of context to external LLMs is limited by the digital avatar owner's settings and the principle of data minimization.
How We Use the Personal Data We Collect About You
How AILINCOM Uses Your Data
- Account Management: creating and maintaining your profile, secure authentication, and support.
- Personalization: content recommendations, digital avatar, and community suggestions based on preferences and activity.
- Access to Content and Digital Avatar: providing lessons, materials, bot interactions, issuing certificates/badges.
- Communication and Engagement: chats, forums, posts, notifications, community collaborations.
- Payments and Subscriptions: processing purchases, subscriptions, and payouts.
- Recommendation Systems: suggesting courses, digital avatars, and plans based on activity history and settings.
- Creator Analytics: audience metrics, views/engagement, earnings, and referrals for experts and organizations.
- Service Improvement: analyzing usage, testing, optimizing interfaces, RAG indices, and performance.
- GenAI and RAG: generating responses using minimal necessary context from permitted sources; no training of proprietary models on expert data.
- Marketing and Messaging: informing about features, promotions, surveys; controllable via notification settings and consent.
- Security and Anti-Fraud: risk monitoring, account protection, detecting abuse.
- Legal Obligations: complying with laws, enforcing Terms, investigating incidents and lawful requests from authorities.
- Audience Analysis: aggregated statistics and segmentation for ecosystem development.
- Third-Party Integrations: fulfilling agreements with partners/providers (payments, LLMs, hosting) while minimizing data and respecting your consents.
- Other Purposes Based on Your Consent: processing data for specific tasks with your explicit permission.
We use an isolated architecture and differentiated access controls for public, commercial, and personal data. Personal data is not disclosed without your consent except as required by law. Privacy settings allow you to manage personalization, marketing, and data sharing.
Disclosure of Your Personal Data
We share data only when necessary and in compliance with the principle of minimization.
- To Creators/Experts: We may share non-personal and limited user data (e.g., country/region, interface language, device/browser, aggregated activity, feedback) to improve the quality of content/digital avatar. Data is not shared without your consent.
- Profile Visibility: Depending on your privacy settings, your profile, posts, reviews, community participation, and basic metadata may be public.
- Service Providers: Payment providers, anti-fraud services, hosting, LLM/AI providers, analytics, support, and mailing services. They use data solely to perform their functions and under contract.
- Commerce and Marketing: Affiliates and partners may receive limited data for promotion and distribution of services, personalization, and analytics, if permitted by your settings/consents.
- Social Networks: When using widgets and sharing features, the respective platforms may collect IP addresses and events; their privacy policies apply.
- Security and Law: Disclosure as required by law/court orders, to protect the rights of AILINCOM, users, and public safety, and to prevent fraud and incidents.
- Corporate Transactions: In the event of a merger or sale of assets, data may be transferred to a successor in compliance with confidentiality obligations.
- Aggregated/De-identified Data: We may use and share such data for research, analytics, and reporting without identifying individuals.
- With Your Consent: Any disclosure beyond this Policy will only occur with your explicit consent.
Special Provisions for Expert Data / Digital Avatars:
- Open Data: Used by digital avatars to qualify requests, match skills/experience, and preliminarily calculate the cost/quality of services; accessible to the extent necessary for these purposes according to the owner's settings.
- Commercial Data: Trade secrets (prompts, private datasets, indices, pricing, etc.) may be provided to users of a specific digital avatar on a paid or other basis determined by the bot owner; otherwise not disclosed.
- Personal Data: Used by the owner for their own purposes within embedded services and is not disclosed to users or AILINCOM without the owner's personal will, except as expressly provided by law.
AI Technologies and Isolation:
- We use an isolated architecture and RAG; expert data is not used to train our own models. Only the minimum necessary context is transmitted to external LLMs according to settings and consents.
Security and Protection of Your Information
We apply technical and organizational measures to protect data from unauthorized access, alteration, disclosure, or destruction, taking into account the type and sensitivity of the data. The AILINCOM architecture isolates open, commercial, and personal data; access is role-based, encryption is used in transit and at rest, security event logging is performed, and integrations (including external LLMs) are monitored. Expert data is not used to train our own models; in RAG, only the minimum necessary context is transmitted.
Limitations
- No online service provides 100% security. We strive for high levels of protection but cannot guarantee absolute security.
Your Responsibilities
- Keep your password, keys/seed phrases, and access tokens confidential; do not share them.
- If you suspect a compromise, immediately change your password/rotate keys and notify support.
- Use strong passwords and 2FA, update them regularly; use a secure browser/device.
- Monitor for suspicious activity and report it through the "Contact Us" section.
Note
- Security is a shared responsibility: we ensure protection at the platform level, and you ensure it at the level of your devices, credentials, and integrations.
Your Rights
- Access: Request a copy of your personal data and information about how it is used.
- Rectification: Update inaccurate or incomplete data in your account settings or via a request.
- Erasure: Request deletion of data if its retention is not required by law or for the performance of contracts.
- Restriction and Objection: Restrict processing or object to it (including for marketing and profiling).
- Withdrawal of Consent: Withdraw previously given consent; this does not affect the lawfulness of processing prior to withdrawal.
- Portability: Receive your data in a machine-readable format, where applicable.
- Transparency of Sharing: Obtain information about third parties with whom your data has been shared, the purposes, and categories of data.
- Complaints: Lodge a complaint with the competent data protection authority of your country or in the Republic of Kazakhstan.
Special provisions for experts/creators:
- Manage data modes (open, commercial, personal) through bot/account settings.
- Personal data is not disclosed to other users or to AILINCOM without your will, except as required by law.
Contact: privacy@ailincom.com. For security purposes, we may request identity verification before fulfilling your request.
Data Management and Account Deletion
- You can change your personal data independently in your account profile.
- Account deletion is available in your personal account without contacting support.
- After deletion, the account and data become inaccessible to other users and system functions; data is retained for 30 days to allow for possible restoration at the user's initiative.
- After 30 days, all data is permanently deleted, except for information that must be retained by law or for the performance of existing obligations.
Children's Privacy
- AILINCOM's services are not intended for children under 13 years of age, nor for individuals who have not reached the minimum age for processing personal data under local law or who require parental consent.
- We do not knowingly collect data from such children. If you are under 13, please do not use AILINCOM or provide any personal data.
- If we discover that we have unintentionally collected data from a child under 13 (or under 16 for EU residents without parental consent), we will promptly delete such data.
Parental Requests
- Parents/guardians may write to privacy@ailincom.com if they suspect that a child has provided data. After verification, we will delete the data and the associated account.
- We comply with additional age restrictions imposed by local laws.
Jurisdiction-Specific Rules
U.S. Privacy Laws
For residents of U.S. states with active privacy laws, the rights and procedures for exercising them are described in our U.S. State Privacy Laws Notice.
International Data Transfers
- AILINCOM is based in the Republic of Kazakhstan; infrastructure may be located and data processed in several jurisdictions (including the EU/UK/US/Asia) through trusted providers.
- Your data may be transferred outside your country of residence and may be subject to different protection regimes. We apply contractual and technical measures (standard contractual clauses, risk assessments, encryption, data minimization) to ensure an equivalent level of protection.
- For the EEA/UK/Switzerland: we use EU Standard Contractual Clauses and appropriate supplementary measures; when transferring to the US and other third countries, we implement necessary safeguards.
- For the US: we comply with applicable federal and state requirements, as well as contractual mechanisms for cross-border transfers.
- For the CIS and Asia: we comply with mandatory local law rules regarding cross-border transfers and store data in accordance with localization requirements where applicable.
For more details on the mechanisms we use and the current list of processors and transfer countries, please refer to the AILINCOM International Data Transfer Policy.
Changes to Our Privacy Policy
This Privacy Policy supersedes all previous notices relating to the AILINCOM Services. We may update this Policy at any time; changes become effective upon posting of the updated version in the Services. We will notify you of material changes via the Services and/or by email. The "Last Updated" date is indicated at the top of the page. By continuing to use the Services after the posting of changes, you accept the updated terms.
