S SATALYAAI Dialer
  • Platform
  • Access
  • Terms
  • Privacy
  • Request Access

Legal instrument

Privacy Policy

Effective: 8 September 2026 Last updated: 8 September 2026 Applies to all Satalya services
Contents 1. Controller and Scope 2. Principles Applied 3. Categories of Data 4. Purposes and Lawful Bases 5. Customer Content and Roles 6. Sharing and Processors 7. International Transfers 8. Retention 9. Security 10. Rights Requests 11. Cookies and Website Data 12. Children 13. Law Enforcement 14. Changes and Contact

1. Controller and Scope

This Privacy Policy explains how Satalya processes personal data in connection with the website, access requests, Accounts, billing (including cryptocurrency references), support, and the Service. It applies to visitors, prospective clients, Customers, and their authorised users.

For personal data contained in Customer Content (such as numbers and names on a calling list), the Customer is the controller and Satalya acts as a processor, except where Satalya must process that data for its own legal obligations, security, billing disputes, or abuse prevention, in which case Satalya is an independent controller for that limited purpose.

Contact for privacy correspondence: privacy@satalya.com. Legal correspondence: legal@satalya.com.

2. Principles Applied

Satalya designs its processing with regard to principles commonly associated with the GDPR and similar regimes: lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

No compliance certification is made. This Policy describes Satalya’s intended approach. It is not a representation, warranty, or audit opinion that Satalya is certified, supervised, or formally compliant with the GDPR, the UK GDPR, or any other privacy statute, unless Satalya has issued a separate written confirmation to that effect. You must not rely on this Policy as a substitute for your own data-protection programme.

3. Categories of Data

Satalya may process: identity and contact data (name, role, business email, telephone, organisation, country); access-request narratives; Account credentials and authentication logs; billing and payment references, including transaction hashes or wallet identifiers if you pay in cryptocurrency; usage metadata (timestamps, volumes, feature flags, IP addresses, device data); support correspondence; and, as processor, Customer Content you choose to upload.

Satalya does not require special-category data or children’s data to operate the Service and asks that you do not send them.

4. Purposes and Lawful Bases

Where Satalya is a controller and a European-style lawful basis is relevant, Satalya relies as appropriate on: performance of a contract or steps requested prior to contract (reviewing an access request, providing an invited Account); legitimate interests (securing the Service, preventing abuse, defending legal claims, improving reliability), balanced against your interests; legal obligation (tax, sanctions screening, responding to compulsory process); and consent where consent is the appropriate basis (for example, optional marketing email, which is not required for access).

Satalya’s legitimate interests include refusing high-risk applicants, detecting Prohibited Activity, and protecting the platform from being used as an instrument of fraud. Those interests are fundamental to the invitation-only model.

5. Customer Content and Roles

You decide what lists and recordings enter the Service. You must have a lawful basis for every record and must not instruct Satalya to process data for Prohibited Activity. Satalya may refuse or delete Customer Content that appears unlawful or that creates an unacceptable risk.

Satalya does not sell Customer Content. Satalya does not use Customer Content to build a public marketing list. Limited use for security, abuse detection, billing, and service improvement may occur as described in the Terms.

6. Sharing and Processors

Satalya may share personal data with hosting, email, communications, analytics, payment, and professional advisers who process data on Satalya’s instructions or as independent professionals. Satalya may also share data with carriers or upstream providers strictly as needed to transmit a communication you initiate.

Satalya does not sell personal data. Satalya may disclose data if you instruct it, if a successor acquires the relevant business assets, or if disclosure is required as described in Section 13.

7. International Transfers

The Service may be hosted or supported in more than one country. Where a transfer restricted by European-style rules occurs, Satalya will seek to use an available transfer tool such as standard contractual clauses or an adequacy finding, as applicable. Mention of those tools is not a representation that every transfer has been independently audited.

8. Retention

Access-request records may be retained as long as needed to evaluate the request, prevent repeat abuse, and defend claims. Account and billing records are retained for the life of the relationship and thereafter for statutory limitation and tax periods. Security logs are retained for a period appropriate to incident response. Customer Content is retained for the term of the Account and a short wind-down period, unless a longer legal hold applies.

Cryptocurrency transaction identifiers may remain on public ledgers beyond Satalya’s control. Satalya cannot erase a public blockchain.

9. Security

Satalya applies administrative and technical measures appropriate to a private software service, including access control and transmission protection where implemented. No method of transmission or storage is completely secure. You must protect your own credentials and endpoints. Satalya’s security measures are not a warranty that unauthorised access will never occur.

10. Rights Requests

Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability, and to withdraw consent where processing is based on consent. Send requests to privacy@satalya.com with enough information to identify you. Satalya may refuse requests that are manifestly unfounded, excessive, or that would impair the rights of others, security, or legal claims, to the extent permitted by law.

If you are a person whose number appears only in a Customer’s list, you should contact that Customer first. Satalya may redirect the request to the Customer as controller.

You may have a right to complain to a supervisory authority. Satalya does not, by mentioning that possibility, designate a lead authority or claim that it is established in a particular EEA state.

11. Cookies and Website Data

The website is a static commercial presentation plus a contact form. It may use strictly necessary cookies or local storage for interface behaviour. If additional analytics cookies are introduced, Satalya will describe them and, where required, seek consent. Do not send special-category data through the public form.

12. Children

The Service is not directed to children. Satalya does not knowingly create Accounts for persons under 18. If you believe a child has submitted data, contact privacy@satalya.com.

13. Law Enforcement

Satalya discloses personal data to public authorities only when legally obliged to do so or when valid legal process so requires, consistent with the Terms of Service. Satalya does not operate a voluntary bulk-disclosure programme for private complainants.

14. Changes and Contact

Satalya may update this Policy by posting a new version. Material changes will be indicated by the “Last updated” date and, where appropriate, by email to Account holders. Questions: privacy@satalya.com.

This Policy must be read with the Terms, AUP, Disclaimer, Refund Policy, and Compliance Policy. In a conflict on data-protection mechanics, this Policy controls; in a conflict on acceptable use, termination, or liability, the Terms and AUP control.

Annex A — Processor Terms (Summary)

Where Satalya processes Customer Content as a processor, it will process only on documented instructions from the Customer, which include the Legal Documents and the Customer’s configuration of the Service; ensure persons authorised to process the data are under a duty of confidence; implement appropriate security measures; not appoint a sub-processor without a general authorisation, which the Customer grants for infrastructure, communications, and support vendors reasonably required to operate an invitation-only dialer, provided Satalya remains responsible for those sub-processors’ performance as between the parties; assist the Customer, taking into account the nature of processing, with data-subject requests and with the Customer’s own security and impact-assessment duties, at the Customer’s cost if the assistance is more than nominal; delete or return Customer Content at the end of the service, subject to legal holds and backup cycles; and make available information reasonably necessary to demonstrate these commitments.

This Annex is a commercial summary of processor-style commitments. It is not a signed Article 28 agreement with a named EEA legal entity, and it is not a claim that Satalya is established in the European Union. Customers that require a separately executed data-processing agreement must request one at legal@satalya.com. Satalya may decline to execute additional paper if the Customer’s use is not accepted or if the requested form is incompatible with the invitation-only model.

Annex B — What We Ask You Not to Send

Do not send copies of passports, payment-card PAN/CVV, health records, children’s data, or criminal-record files through the public website form. If onboarding later requires identity evidence, Satalya will specify a channel. Unsolicited sensitive files may be deleted without completing a review of your request.

15. Detailed Processing Descriptions

When you submit an access request, Satalya processes the identifiers and narrative you choose to provide in order to decide whether to open a commercial relationship. That processing is a step at your request prior to a contract, and it is also in Satalya’s legitimate interest in refusing high-risk or unlawful applicants. Satalya may keep a record of refused requests in order not to re-open a channel that was closed for cause.

When an Account exists, Satalya processes authentication events, configuration, and usage metadata to deliver the Service, to bill, to detect abuse, and to restore service after an incident. When you contact support, Satalya processes the contents of the ticket. When you pay, Satalya processes invoice data and, if you use cryptocurrency, public ledger references that you or the network make available.

When you upload a list, Satalya’s systems host and transmit that list in order to execute the functions you invoke. Satalya does not independently decide to call a person on that list. The decision to call is yours. For that reason, complaints from called parties are typically directed first to you as controller.

16. Legitimate-Interest Balancing (Descriptive)

Satalya considers that a private, invitation-only vendor has a legitimate interest in protecting its infrastructure from becoming an instrument of fraud, in defending legal claims, in metering usage, and in improving reliability. Those interests are not overridden, in Satalya’s assessment, by a prospective client’s interest in remaining anonymous while requesting a powerful outbound-calling tool. If you object to that balancing, do not submit a request.

This paragraph describes an internal assessment. It is not a claim that a supervisory authority has reviewed or approved the assessment, and it is not a claim of formal GDPR compliance.

17. Recipients in More Detail

Categories of recipients may include: cloud infrastructure providers; transactional email providers; communications and number-routing providers strictly as needed to complete a communication you initiate; professional advisers (legal, accounting) under professional duties; payment or conversion counterparties if you elect a payment method that requires them; and competent authorities when legally obliged or when valid process so requires.

Satalya does not sell personal data and does not permit recipients to use controller-side website data for their own unrelated advertising, except to the extent a standard infrastructure cookie is technically unavoidable and disclosed if additional cookies are introduced.

18. Retention Schedule (Indicative)

The following periods are indicative and may be shortened or extended for legal holds, disputes, or statutory requirements: website server logs, up to thirteen months; access-request records, up to six years after last contact where needed for abuse prevention and limitation periods; billing records, up to ten years or the local statutory minimum if longer; security incident files, up to six years; Customer Content after Account end, a short wind-down not exceeding ninety days plus backup expiry, unless a hold applies.

Indicative periods are not a warranty that deletion will occur on a particular calendar day, because backups and legal holds may delay physical erasure.

19. Data-Subject Request Procedure

Send requests to privacy@satalya.com from an address that allows Satalya to relate you to a record, or provide other reasonable identification. Satalya may request additional information to prevent disclosure to the wrong person. Satalya will respond within the time required by a law that actually applies to the request, and otherwise within a commercially reasonable time.

Satalya may refuse or charge for manifestly unfounded or excessive requests to the extent permitted. Satalya may decline to delete data that it must keep for legal claims, security, or invoicing. If you are identified only inside a Customer’s list, Satalya may refer you to that Customer and may inform the Customer of the request.

20. Automated Decision-Making

Access decisions may be assisted by internal rules and risk signals. A human at Satalya remains responsible for issuing or withholding an invitation. Satalya does not make legally significant decisions about called parties by fully automated means on its own account; calling decisions are the Customer’s.

This description is not a claim that Article 22 of the GDPR, or any analogue, has been assessed by an authority as inapplicable or applicable.

21. Security Incidents

If Satalya becomes aware of a personal-data breach affecting data it controls, it will notify affected persons and, where a law that applies to Satalya so requires, the relevant authority, in the manner and time that law requires. If the breach concerns Customer Content for which the Customer is controller, Satalya will notify the Customer without undue delay after becoming aware, with such information as is reasonably available at that time.

You must notify Satalya without undue delay if you become aware that your Account has been used to exfiltrate data or to conduct Prohibited Activity that may constitute a breach in your programme.

22. Marketing

Satalya does not operate a public newsletter as a condition of access. If Satalya later sends optional commercial email to persons who requested information, it will provide an unsubscribe mechanism. Transactional messages about invitations, invoices, security, and legal updates are not marketing and may continue while the relationship or a legal necessity exists.

23. California and Similar Disclosures (If Applicable)

If a statute such as the CCPA/CPRA applies to a particular request, Satalya does not “sell” or “share” personal information in the ordinary advertising sense. The categories of information described in this Policy are the categories collected. Rights of access, deletion, and correction will be honoured to the extent that statute actually applies and no exception is available. Satalya will not discriminate against a person for exercising a privacy right, except that Satalya may refuse to open an Account for any lawful commercial reason unrelated to the exercise of that right, including invitation-only risk decisions.

Mention of California law is precautionary. It is not a representation that Satalya is a “business” above any particular threshold or that Satalya is subject to that statute.

24. Contact and Complaints

Privacy: privacy@satalya.com. Legal: legal@satalya.com. You may have a right to lodge a complaint with a supervisory authority. Satalya’s description of principles associated with the GDPR is not a designation of a lead supervisory authority and not a claim of establishment in the EEA or the United Kingdom.

This instrument is a commercial legal document of Satalya. It does not constitute legal advice to any third party. Nothing in this document is a representation that Satalya is certified, audited, or officially attested as compliant with any particular statute, including the GDPR, unless a separate written confirmation is issued by Satalya. Satalya provides software tools only. Users remain solely responsible for their campaigns, lists, scripts, and any unlawful misuse.

Satalya

A private AI dialer and conventional dialer for lawful premium businesses. Access is granted only after review.

Legal

  • Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Refund Policy

Governance

  • Disclaimer
  • Compliance Policy
  • legal@satalya.com

Access

  • Request invitation
  • contact@satalya.com
© 2026 Satalya. All rights reserved. Software tools only. Users remain solely responsible for unlawful misuse.