To schedule a custom demo tailored to your specific use case.
By submitting, you agree to our data handling practices.
GK Aseto Management Ltd (“Aseto,” “we,” “our,” or “us“) provides AI-powered voice and chat agents — including customer support, scheduling, smart answering, outbound calling, call evaluation, and conversational IVR products (together, the “Services“) — used by business and organizational clients (“Client Organizations“) to interact with their own customers, patients, or contacts (“End Users“).
This Privacy Policy explains, in general terms, how we collect, use, and protect personal data in connection with the Services and our website. It complies with the GDPR and UK GDPR.
A note on scope. This is a general policy intended to give visitors, prospective clients, and End Users a clear overview of our practices. For every Client Organization we work with, we execute a separate Data Processing Agreement (DPA) and/or Service Level Agreement (SLA) setting out the specific data categories, retention periods, security controls, and sector-specific requirements (e.g., healthcare, finance, insurance) relevant to that deployment. Where this policy conflicts with a signed DPA/SLA between Aseto and a Client Organization, the DPA/SLA governs.
If you are an End User contacted by, or contacting, an Aseto-powered agent, the Client Organization operating that deployment is typically responsible for your query — see Section 2.
The exact data processed depends on the specific product and deployment, as agreed with each Client Organization. This may include:
We apply data minimization by design. Our Services are configured to capture only what is operationally necessary for the task requested — for example, a callback message is generally structured as “requested department + callback details” rather than capturing unnecessary sensitive detail, unless a Client Organization’s specific use case and DPA require otherwise.
We do not use voice data to uniquely identify individuals (i.e., no voice biometric identification). This means voice data is not, by itself, treated as biometric special-category data under Article 9 GDPR. Where a conversation includes special category data volunteered by an End User (e.g., health information), that data is processed strictly to deliver the administrative function requested, under the Client Organization’s lawful basis.
Where Aseto acts as controller (Section 2), we rely on:
Where Aseto acts as processor, the applicable legal basis is determined by the Client Organization and documented in the DPA.
Use of AI. Our Services use generative AI and natural language processing to interpret input (voice or text) and generate responses. The AI does not make autonomous decisions about eligibility, entitlement, or treatment, and does not perform profiling beyond what is needed to respond to the immediate interaction. We do not train, fine-tune, or improve any AI model using Client or End User conversation data — data is processed solely to deliver the contracted service.
| Subprocessor | Function | Region |
|---|---|---|
| Cloud AI provider (e.g., Microsoft Azure) | Language model processing, text-to-speech | EU |
| Cloud hosting provider (e.g., AWS) | Private-tenant infrastructure hosting | EU |
| Telephony/SIP carrier | Call routing (voice product only) | EU |
| Firebase (Google) | Analytics/crash reporting for Platform Users’ app usage | EU |
Our own speech-to-text, audio processing, and orchestration are not third-party subprocessing — they run on infrastructure we build and operate ourselves. We do not transfer personal data outside the EU/UK in standard Service delivery. Where an international transfer does occur, we ensure appropriate safeguards (such as Standard Contractual Clauses) are in place. A current, detailed subprocessor list is available to Client Organizations under their DPA and on request.
Links to relevant third-party privacy policies: Google Play Services · Google Analytics for Firebase · Firebase Crashlytics · App Store · OpenAI· AWS · Microsoft Azure
Retention periods (raw audio, transcripts, messages, system logs) are configured per Client Organization and defined in the applicable DPA/SLA. Our default posture is to minimize retention — e.g., not retaining raw audio beyond what is operationally necessary — unless a client’s use case requires a defined longer period. For Platform User accounts, data is generally retained for the duration of active use and up to three years after deactivation, or longer where required by law or for legitimate business purposes (e.g., dispute resolution, fraud prevention). Once retention is no longer required, data is securely deleted or anonymized.
We maintain administrative, technical, and organizational measures designed to protect personal data, including:
We do not claim certifications we do not hold. No transmission over the internet can be guaranteed completely secure, and by using the Services you acknowledge the inherent risks associated with AI and internet-based technologies. A detailed, current mapping of our security controls is available to Client Organizations on request and can be aligned to sector-specific requirements.
We do not sell personal data. We may share information with:
If we become aware of a personal data breach affecting a Client Organization’s data, we contain and investigate the incident and notify the affected Client Organization per the timelines in our DPA, providing the information needed for their own regulatory notification obligations. Where Aseto is the controller, we will notify affected individuals and/or supervisory authorities as required by law.
In line with applicable AI transparency requirements (including Article 50 of the EU AI Act), our voice and chat Services are designed to clearly disclose at the start of an interaction that the End User is speaking with an AI system. This is a standard, non-optional part of our Service design.
Under GDPR/UK GDPR, you have the right to: access your data, rectify inaccurate data, request erasure, restrict processing, request data portability, object to processing, and withdraw consent at any time. We aim to respond to requests within one month.
Where personal data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Where a Platform User directs the Services to carry out a task on their behalf — such as placing an outbound call, making a reservation, or scheduling an appointment — the following applies:
GK Aseto Management Ltd Eleftherias 30, Flat 201, 7102 Aradippou, Larnaca, CY Email: info@aseto.ai
Data Protection Officer: for privacy-related concerns, contact us at info@aseto.ai.
The Services are not intended for use by children under 16. We do not knowingly collect data from children under this age. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
Our website and app may use cookies and similar technologies to improve experience and analyze usage. See our separate Cookie Policy for details.
If you believe your data rights have been violated, you can file a complaint with your local data protection authority (in the EEA/UK) or contact us directly at info@aseto.ai to raise a concern first.
We may update this Privacy Policy from time to time. Material changes will be posted on this page and, where appropriate, notified via email. Specific contractual data processing terms with Client Organizations are governed by the applicable DPA/SLA and are not affected by changes to this general policy.
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
We use cookies and similar technologies to improve your experience. Consent allows us to process browsing data; declining may affect site features.