Privacy Policy for GK Aseto Management Ltd (Aseto)

Effective Date: January 1, 2026

GK Aseto Management Ltd (“Aseto,” “we,” “our,” or “us“) provides AI-powered voice and chat agents — including customer support, scheduling, smart answering, outbound calling, call evaluation, and conversational IVR products (together, the “Services“) — used by business and organizational clients (“Client Organizations“) to interact with their own customers, patients, or contacts (“End Users“).

This Privacy Policy explains, in general terms, how we collect, use, and protect personal data in connection with the Services and our website. It complies with the GDPR and UK GDPR.

A note on scope. This is a general policy intended to give visitors, prospective clients, and End Users a clear overview of our practices. For every Client Organization we work with, we execute a separate Data Processing Agreement (DPA) and/or Service Level Agreement (SLA) setting out the specific data categories, retention periods, security controls, and sector-specific requirements (e.g., healthcare, finance, insurance) relevant to that deployment. Where this policy conflicts with a signed DPA/SLA between Aseto and a Client Organization, the DPA/SLA governs.


1. Who This Policy Applies To

  • End Users — people who receive a call, place a call, or chat with an Aseto-powered voice or chat agent deployed by a Client Organization (e.g., a caller to a business’s phone line, or a visitor to a client’s chat widget).
  • Platform Users — staff or authorized users of a Client Organization who configure the Services or direct the AI to carry out a task (e.g., an outbound call, a scheduling request).
  • Website visitors — people browsing aseto.ai.

If you are an End User contacted by, or contacting, an Aseto-powered agent, the Client Organization operating that deployment is typically responsible for your query — see Section 2.


2. Controller vs. Processor

  • When an End User interacts with an Aseto-powered agent deployed by a Client Organization, that Client Organization is typically the data controller — they determine the purpose of the deployment and the applicable legal basis (including, where relevant, the Article 9 GDPR condition for any health or other special category data discussed).
  • Aseto acts as a data processor, processing personal data only on the documented instructions of the Client Organization, as set out in our DPA with them.
  • Where Aseto processes data for its own purposes — operating this website, managing our direct client relationships, or providing tools that a Platform User directly instructs (e.g., an outbound call feature used at their own discretion) — Aseto acts as a controller for that specific processing.

3. Information We May Process

The exact data processed depends on the specific product and deployment, as agreed with each Client Organization. This may include:

  • Contact identifiers (phone number, email)
  • Name, where provided
  • Content of the spoken or typed conversation
  • Requested department, service, or reason for contact
  • Message content, where a message is left for callback
  • Call/chat metadata (timestamp, duration, routing outcome)
  • For Platform Users: account information (name, email) and app usage/interaction data (e.g., via analytics tools such as Firebase)

We apply data minimization by design. Our Services are configured to capture only what is operationally necessary for the task requested — for example, a callback message is generally structured as “requested department + callback details” rather than capturing unnecessary sensitive detail, unless a Client Organization’s specific use case and DPA require otherwise.

We do not use voice data to uniquely identify individuals (i.e., no voice biometric identification). This means voice data is not, by itself, treated as biometric special-category data under Article 9 GDPR. Where a conversation includes special category data volunteered by an End User (e.g., health information), that data is processed strictly to deliver the administrative function requested, under the Client Organization’s lawful basis.


4. Legal Basis for Processing

Where Aseto acts as controller (Section 2), we rely on:

  • Consent — e.g., where a Platform User registers to use our tools.
  • Performance of a contract — to provide the Services under our agreement with a Client Organization or Platform User.
  • Legitimate interests — to maintain, secure, and improve the Services.

Where Aseto acts as processor, the applicable legal basis is determined by the Client Organization and documented in the DPA.

Use of AI. Our Services use generative AI and natural language processing to interpret input (voice or text) and generate responses. The AI does not make autonomous decisions about eligibility, entitlement, or treatment, and does not perform profiling beyond what is needed to respond to the immediate interaction. We do not train, fine-tune, or improve any AI model using Client or End User conversation data — data is processed solely to deliver the contracted service.


5. Where Data Is Processed & Subprocessors

  • Our core pipeline (speech-to-text, call/chat orchestration, conversation logic) runs on infrastructure we own and operate, in the EU.
  • Our hosting environment is a private, single-tenant cloud environment in the EU — not shared multi-tenant infrastructure.
  • We use a limited number of subprocessors for specific functions:
SubprocessorFunctionRegion
Cloud AI provider (e.g., Microsoft Azure)Language model processing, text-to-speechEU
Cloud hosting provider (e.g., AWS)Private-tenant infrastructure hostingEU
Telephony/SIP carrierCall routing (voice product only)EU
Firebase (Google)Analytics/crash reporting for Platform Users’ app usageEU

Our own speech-to-text, audio processing, and orchestration are not third-party subprocessing — they run on infrastructure we build and operate ourselves. We do not transfer personal data outside the EU/UK in standard Service delivery. Where an international transfer does occur, we ensure appropriate safeguards (such as Standard Contractual Clauses) are in place. A current, detailed subprocessor list is available to Client Organizations under their DPA and on request.

Links to relevant third-party privacy policies: Google Play Services · Google Analytics for Firebase · Firebase Crashlytics · App Store · OpenAI· AWS · Microsoft Azure 


6. Data Retention

Retention periods (raw audio, transcripts, messages, system logs) are configured per Client Organization and defined in the applicable DPA/SLA. Our default posture is to minimize retention — e.g., not retaining raw audio beyond what is operationally necessary — unless a client’s use case requires a defined longer period. For Platform User accounts, data is generally retained for the duration of active use and up to three years after deactivation, or longer where required by law or for legitimate business purposes (e.g., dispute resolution, fraud prevention). Once retention is no longer required, data is securely deleted or anonymized.


7. Security

We maintain administrative, technical, and organizational measures designed to protect personal data, including:

  • Encryption of data in transit and at rest
  • Access controls and role-based access, with multi-factor authentication for administrative access
  • Tenant separation through private, single-tenant infrastructure
  • Audit logging
  • Backup and disaster recovery procedures
  • Vulnerability management and patching
  • Restricted employee access to production data
  • A documented incident response process
  • A documented data deletion process
  • Secrets and key management controls

We do not claim certifications we do not hold. No transmission over the internet can be guaranteed completely secure, and by using the Services you acknowledge the inherent risks associated with AI and internet-based technologies. A detailed, current mapping of our security controls is available to Client Organizations on request and can be aligned to sector-specific requirements.


8. Data Sharing and Disclosure

We do not sell personal data. We may share information with:

  • Subprocessors listed in Section 5, under contractual data protection obligations.
  • Law enforcement or regulators, where required by law or in response to a valid legal request.
  • A successor entity, in connection with a merger, acquisition, or sale of business assets, provided the recipient agrees to handle data consistently with this policy.

9. Data Breach Notification

If we become aware of a personal data breach affecting a Client Organization’s data, we contain and investigate the incident and notify the affected Client Organization per the timelines in our DPA, providing the information needed for their own regulatory notification obligations. Where Aseto is the controller, we will notify affected individuals and/or supervisory authorities as required by law.


10. AI Transparency

In line with applicable AI transparency requirements (including Article 50 of the EU AI Act), our voice and chat Services are designed to clearly disclose at the start of an interaction that the End User is speaking with an AI system. This is a standard, non-optional part of our Service design.


11. Your Rights

Under GDPR/UK GDPR, you have the right to: access your data, rectify inaccurate data, request erasure, restrict processing, request data portability, object to processing, and withdraw consent at any time. We aim to respond to requests within one month.

  • If you are an End User of a Client Organization’s deployment, your primary point of contact is generally that Client Organization, as they are the data controller. Aseto supports our clients in fulfilling such requests for data we process on their behalf.
  • For all other requests, or questions about Aseto’s own processing, contact us using the details in Section 15.

12. International Data Transfers

Where personal data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.


13. Responsibility for Instructed Tasks (Platform Users)

Where a Platform User directs the Services to carry out a task on their behalf — such as placing an outbound call, making a reservation, or scheduling an appointment — the following applies:

  • User accountability. You are solely responsible for the accuracy of instructions given, the appropriateness of the task, and any legal or practical consequences of its execution. The Services function as a tool that follows your direct instructions; you are responsible for ensuring those instructions comply with applicable law and any third-party terms.
  • Limitation of liability. Aseto has no involvement in the content or nature of a task beyond executing the instructions given, and is not responsible for: the accuracy of information you provide, the outcome of any call, reservation, or appointment, or any dispute, cancellation, or consequence arising from the task, whether with third parties or otherwise.
  • Third-party interactions. Aseto is not responsible for the actions or responses of third parties contacted on your instruction, and does not guarantee the outcome of any such interaction.
  • Indemnification. You agree to indemnify and hold harmless Aseto, its affiliates, directors, officers, employees, and agents from claims, liabilities, damages, or expenses (including legal fees) arising from a task you instructed the Services to perform, including any breach of law or third-party rights.

14. Misuse of the Services

  • The Services are intended solely for lawful, proper purposes such as scheduling, customer support, and administrative call/chat handling within applicable law.
  • You agree not to use the Services to harass, defraud, or deceive individuals or businesses, to conduct unlawful activity, or to circumvent applicable laws or third-party terms.
  • Aseto is not liable for misuse of the Services by a Platform User or Client Organization; responsibility for lawful use rests with the user.
  • Aseto reserves the right to suspend or terminate access in cases of misuse or illegal activity, and may take legal action or report incidents to authorities where warranted.
  • Reports of misuse are reviewed promptly, with an initial response typically provided within 7 business days, and further investigation within 30 days where needed. If you receive a call or message from an Aseto-powered agent that you believe was offensive, inappropriate, or used for an unlawful purpose, contact us immediately at info@aseto.ai.

15. Contact Us

GK Aseto Management Ltd Eleftherias 30, Flat 201, 7102 Aradippou, Larnaca, CY Email: info@aseto.ai

Data Protection Officer: for privacy-related concerns, contact us at info@aseto.ai.


16. Children’s Privacy

The Services are not intended for use by children under 16. We do not knowingly collect data from children under this age. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.


17. Cookies

Our website and app may use cookies and similar technologies to improve experience and analyze usage. See our separate Cookie Policy for details.


18. Complaints

If you believe your data rights have been violated, you can file a complaint with your local data protection authority (in the EEA/UK) or contact us directly at info@aseto.ai to raise a concern first.


19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page and, where appropriate, notified via email. Specific contractual data processing terms with Client Organizations are governed by the applicable DPA/SLA and are not affected by changes to this general policy.

By using the Services, you acknowledge that you have read and understood this Privacy Policy.