Skip to content
S Satalya
Product Contact Terms Privacy Request access

Legal

Privacy Policy

Effective: 7 September 2026 Last updated: 7 September 2026 Operator: Satalya · satalya.com
1. Scope and Who We Are2. Principles We Aim to Observe3. Categories of Personal Data4. Sources5. Purposes and Legal Bases6. Call Recording, Transcripts, and AI7. Cookies and Similar Technologies8. Sharing and Sub-processors9. International Transfers10. Retention11. Your Rights12. Security13. Children14. Automated Processing15. Changes and Contact16. Controller and Processor Matrix17. Do-Not-Sell and Regional Disclosures18. European Representative and Transfers — Status19. Lawful Bases in More Detail20. Recipients and Location Categories21. Data-Subject Request Procedure22. Children and Vulnerable Persons — Client Duties23. No Sale; No Unexpected Secondary Use24. Additional Processing Narratives

These Legal Documents are binding, internally consistent, and apply to the invite-only Satalya AI Dialer and Classic Dialer. There is no public registration. Misuse is the User’s sole responsibility.

Lawful businesses only. Fraud, phishing, impersonation, financial crime, money laundering, unauthorized access, and abuse of third-party data are strictly prohibited. Satalya and its project creator are not liable for a client’s unlawful use, to the maximum extent permitted by law. We may refuse, suspend, or permanently terminate any account on reasonable suspicion.

Terms of ServiceAcceptable UsePrivacyRefundsDisclaimerCompliance

1. Scope and Who We Are

This Privacy Policy explains how Satalya (“we”, “us”) processes personal data in connection with satalya.com, access requests, Accounts, and the Services. It is designed with regard to widely recognized principles associated with the EU General Data Protection Regulation and similar regimes. This Policy does not claim that Satalya has obtained a formal GDPR certification, has adhered to an approved code of conduct, or has been approved by a supervisory authority. Those statements would be made only if they were true and documented.

Depending on the context, Satalya may act as an independent controller (for example, for website logs, access-request correspondence, billing, and abuse prevention) or as a processor on behalf of a Client (for example, for calling lists the Client uploads). Where we are a processor, the Client is responsible for its own transparency and lawful basis toward individuals.

Contact for privacy inquiries: privacy@satalya.com. Legal: legal@satalya.com.

If we appoint a representative or data-protection officer as required by law, we will publish those details here or in an addendum. Until such an appointment is published, inquiries should use the addresses above.

2. Principles We Aim to Observe

We aim to process personal data in a manner consistent with the following principles. This is a statement of approach, not a warranty of residual-risk-free processing and not a certification.

  • Lawfulness, fairness, and transparency — we seek a lawful basis and to explain our processing in this Policy.
  • Purpose limitation — we collect for specified, explicit purposes described here or in a later notice.
  • Data minimization — we seek to limit data to what is reasonably needed for those purposes.
  • Accuracy — we expect you to keep Account data accurate and we correct controller-held data when we become aware of inaccuracy.
  • Storage limitation — we retain for as long as needed for the purposes, legal claims, and legal duties, then delete or anonymize where practicable.
  • Integrity and confidentiality — we apply technical and organizational measures we consider appropriate to the risk.
  • Accountability — we seek to document material processing and vendor decisions.

Where a principle cannot be fully realized because of the nature of telecommunications logs, security, or legal holds, we will prefer the most restrictive option that still allows us to operate securely and lawfully.

3. Categories of Personal Data

We may process the following categories, depending on how you interact with us:

  • Identity and contact data: name, role, company, email, telephone, country, and signatures on correspondence.
  • Access-request data: intended use, representations about lawful business, and any documents you send.
  • Account data: usernames, role assignments, authentication events, and support tickets.
  • Billing and payment data: invoices, fiat payment references, and, if you pay in Cryptocurrency, wallet addresses, transaction identifiers, network, amounts, and related compliance notes. We do not need your private keys and you must never send them.
  • Client Content and Call Data, when you use the Services: numbers, names on lists, call metadata, recordings, transcripts, notes, and agent identifiers. We process these primarily as a processor.
  • Technical data: IP address, device and browser type, approximate location derived from IP, referring URLs, and diagnostic logs.
  • Communication data: emails, meeting notes, and recordings of calls with us if we notify you.
  • Compliance data: sanctions-screening results, adverse-media notes we generate, and records of AUP enforcement.

We do not require special-category data to operate a dialer. You must not upload health, biometric, political, religious, or similar special-category data unless we have agreed in a written data-processing arrangement and you have a lawful basis.

4. Sources

We receive data from you, from your users, from your integrations (such as a CRM you connect), from payment networks or blockchain explorers when you pay in Cryptocurrency, from communications providers involved in delivering the Services, from publicly available registers when we review an access request, and from devices that access the website.

We do not buy consumer calling lists to operate the website. If a Client uploads a list, that Client is the source as to those individuals.

5. Purposes and Legal Bases

Where the GDPR or a similar statute applies to us as controller, we rely on one or more of the following bases as appropriate to the activity: performance of a contract or steps at your request before a contract; legitimate interests (such as securing the platform, preventing abuse, asserting legal claims, and responding to access requests); compliance with a legal obligation; and consent where we choose to rely on it and are not required to do so for all processing.

Purposes include: evaluating and responding to access requests; provisioning and securing Accounts; providing the AI Dialer and Classic Dialer; billing and collecting fees, including Cryptocurrency receipts; preventing Prohibited Use; establishing, exercising, or defending legal claims; complying with compulsory legal process as described in the Law Enforcement Requests Policy; improving reliability and documentation; and communicating about the Services.

Our legitimate interests do not override your interests or fundamental rights where a balancing test is required and comes out against us. You may object to legitimate-interest processing as described in Section 10.

When we act as a processor, the Client determines the purposes of Call Data. We process on documented instructions in the Terms, this Policy, and any order, unless Applicable Law requires otherwise.

6. Call Recording, Transcripts, and AI

If a Client enables recording, transcription, or AI analysis, personal data in the audio and text will be processed to provide those features. The Client must configure notices and obtain consents required by Applicable Law. Satalya does not independently notify every called party.

AI features may send limited context to model infrastructure that we operate or that a sub-processor operates. We will not use Client call audio to train a public model in a way that makes the audio available to other customers, unless we provide a clear opt-in and the Client accepts. We may use aggregated or de-identified telemetry to maintain quality.

You should treat AI suggestions as unverified. Do not paste unnecessary special-category data into prompts.

7. Cookies and Similar Technologies

The public website is designed to be simple. We may use strictly necessary cookies or local storage for security, load balancing, or to remember a UI preference. We do not currently use advertising cookies on the public pages. If that changes, we will update this Policy and, where required, present a consent mechanism.

If we use analytics, we will prefer privacy-respecting configurations. Browser signals will be honored where required by law and technically feasible.

Account interfaces may use additional cookies that are necessary to keep you signed in and to protect against cross-site request forgery.

8. Sharing and Sub-processors

We may share personal data with:

  • infrastructure, hosting, email, and communications providers that enable the Services;
  • professional advisers (legal, accounting) under confidentiality;
  • payment processors and, for Cryptocurrency, any compliance vendor we use to review a transaction;
  • authorities, when legally compelled or as permitted under the Law Enforcement Requests Policy and Compliance Policy;
  • a buyer or successor in a reorganization, under appropriate safeguards;
  • other parties at your direction (for example, a CRM you connect).

We do not sell personal data for advertising. We do not permit sub-processors to use Client Content for their own unrelated marketing.

A current list of material sub-processor categories will be provided to an Account holder upon reasonable request to privacy@satalya.com. We may update vendors. Where a processor addendum requires notice and a right to object, we will follow that addendum.

9. International Transfers

We may process data in countries other than the country where you or the called party reside. Where a transfer restriction applies, we aim to use an appropriate mechanism, which may include standard contractual clauses, an adequacy decision, or another recognized tool. This Policy does not assert that every transfer has been approved by a regulator.

Clients who export data from the Services are responsible for their own transfer impact assessments.

10. Retention

Access-request records are retained for as long as needed to evaluate the request and thereafter for a period appropriate to security, sanctions, and legal-claim purposes, typically not less than the limitation period for contract claims in the relevant forum.

Account and billing records are retained for the life of the Account and for a subsequent period required for tax, accounting, and dispute purposes.

Call Data retention is primarily controlled by the Client’s settings and by our backup cycles. After Account closure we will delete or de-identify Client Content from active systems within a commercially reasonable period, subject to legal holds, compulsory preservation, AUP investigations, and backup expiry.

Security logs are retained for a period aligned with incident-response practice.

Cryptocurrency transaction identifiers may remain visible on public ledgers indefinitely; that is a feature of those networks and not a retention choice we can reverse.

11. Your Rights

Where the GDPR or a similar law applies to our controller processing, you may have the right to request access, rectification, erasure, restriction, portability, and to object to certain processing, and the right not to be subject to a solely automated decision with legal or similarly significant effects that we make as controller. We do not make solely automated eligibility decisions of that kind without human review of access requests.

To exercise rights, email privacy@satalya.com from an address we can reasonably associate with you and describe the request. We may need to verify identity. We will respond within the time Applicable Law requires, subject to extensions and exceptions (including privilege, other persons’ data, and manifestly unfounded or excessive requests).

If we process data as a processor, we will direct you to the Client where appropriate, because that Client decides.

You may lodge a complaint with a supervisory authority. We invite you to contact us first so that we can attempt to resolve the issue.

Where processing is based on consent, you may withdraw consent without affecting prior lawful processing. Withdrawal may prevent us from providing a feature.

12. Security

We implement measures we consider appropriate, which may include access control, encryption in transit, least-privilege administration, logging, and vendor diligence. No method of transmission or storage is perfectly secure. You must protect your credentials and devices.

If we become aware of a personal-data breach that we are required to notify, we will do so in the manner and time Applicable Law requires. Clients acting as controllers remain responsible for their own notifications to individuals and authorities when the breach relates to their Call Data and the duty falls on them.

13. Children

The Services and the website are not directed to children. We do not knowingly collect personal data from children through the public site. If you believe a child has provided data, contact privacy@satalya.com. Clients must not use the Services to target children in violation of Applicable Law.

14. Automated Processing

We may use automated scoring to flag suspicious traffic, sanctions hits, or AUP risk. Such flags are reviewed by a human before a final refusal or termination except where an automated block is required to contain an active attack. This is abuse-prevention, not consumer credit scoring.

15. Changes and Contact

We may update this Policy as described in the Terms. Material changes will be signaled by a new date at the top of this page and, for Account holders, by email or in-product notice where practicable.

This Policy is consistent with the Terms, AUP, Refund Policy, Disclaimer, and Compliance Policy. Those documents govern liability, indemnities, and lawful use. This Policy does not create a warranty beyond what those documents allow.

Privacy: privacy@satalya.com. Operator website: https://satalya.com.

16. Controller and Processor Matrix

Website visitors and access requesters: we are controller of the data you send in the form or email and of technical logs.

Account administrators: we are controller of billing, authentication, and contract data; we are processor of the calling lists and recordings you upload or generate, except when we process those materials to prevent abuse, secure the platform, or comply with law, in which case we may be an independent controller for that limited purpose.

Called parties: we typically do not have a direct relationship. Their primary controller is the Client. We will not respond to a called party with campaign details that would confirm another Client’s confidential program except as law requires.

17. Do-Not-Sell and Regional Disclosures

We do not sell personal information for monetary consideration in the ordinary advertising sense. We also do not share personal information for cross-context behavioral advertising on the public website as of the date of this Policy.

Residents of jurisdictions that grant additional rights (including certain U.S. state laws) may contact privacy@satalya.com to exercise access, deletion, correction, or to appeal a refusal. We will not discriminate against you for exercising a privacy right.

Authorized agents may submit requests with proof of authority. We may still need to verify the individual.

18. European Representative and Transfers — Status

If and when Satalya is required to appoint an EU or UK representative, those details will be added here. Until then, this absence should be read as “not appointed / not stated”, not as a claim that no such duty could ever apply.

If we rely on standard contractual clauses with a vendor, we will provide a copy to a Client who is a controller upon reasonable request, subject to redaction of commercial secrets.

19. Lawful Bases in More Detail

Contract. When you request access, pay an invoice, or use an Account, we process identity, contact, and billing data to take steps at your request and to perform the contract. Without that data we cannot evaluate or provision the Services.

Legitimate interests. We have a legitimate interest in securing an invite-only communications platform, in preventing fraud against us and against the public, in defending claims, in improving reliability, and in keeping records of who asked for access. We consider that users of a business dialer reasonably expect such processing. You may object; we will consider the objection and may continue if our interests override or if we need the data for claims.

Legal obligation. We may process data to comply with tax, accounting, sanctions, export, and compulsory process. We do not rely on this basis to volunteer data in the absence of an obligation, except as the Law Enforcement Requests Policy allows for emergencies and self-protection.

Consent. We use consent only where we choose to, for example for optional marketing emails if we ever send them, or for optional cookies if we introduce them. Consent can be withdrawn. Withdrawal does not affect the lawfulness of prior processing or of processing on another basis.

Processor context. For Call Data, the Client typically supplies the basis. If you cannot identify a basis, you must not upload the data.

20. Recipients and Location Categories

Hosting and compute may be located in one or more of the following categories of country: the country of our principal operations; jurisdictions where our cloud vendor operates regions; and jurisdictions where a support contractor is located. We will identify regions to an Account holder upon reasonable request.

Email and ticketing vendors process the content of your messages to us. Do not send unnecessary special-category data in tickets.

Carriers and interconnects process numbers and signaling data to complete calls you initiate. Those providers may be independently obliged to retain certain communications metadata under local law. We cannot prevent a carrier’s legal duty.

If you pay in Cryptocurrency, the public ledger, your originating exchange, and any analytics vendor we use will see the transaction. That visibility is inherent to the payment method you chose.

21. Data-Subject Request Procedure

Send the request to privacy@satalya.com. State whether you are an access requester, an Account user, or a called party. If you are a called party, identify the Client if you know it, the number that called you, and the time. We may be unable to locate you without that information because we do not operate a global directory of every dialed number across all Clients in a form designed for public search.

We will not disclose one Client’s confidential campaign to another person except as law requires. If we are a processor, we will inform the Client and follow the Client’s lawful instructions unless those instructions would cause us to break the law.

We may refuse or charge a reasonable fee for manifestly unfounded or excessive requests, as Applicable Law allows.

Appeals of our decision as controller may be sent to legal@satalya.com with the word “APPEAL” in the subject line. You may also complain to a supervisory authority.

22. Children and Vulnerable Persons — Client Duties

The Services are for business Users. If your campaign could reasonably reach a child or a person you know to be vulnerable, you must apply additional care required by Applicable Law, including stopping the call and suppressing the number. Satalya is not designed as a youth product and we do not provide age-gating of called parties.

23. No Sale; No Unexpected Secondary Use

We do not sell calling lists. We do not license your Client Content to data brokers. We may use telemetry and abuse signals to protect the platform. We may use de-identified statistics to understand product reliability.

If a future feature would use Client Content to train a model that is shared with other customers, we will describe that feature and require an opt-in or a contract amendment. Until then, you should not assume such training occurs, and we do not promise that no vendor model retains ephemeral inference logs except as that vendor’s terms state.

24. Additional Processing Narratives

This Section 24 provides additional detail for readers who need a closer mapping between our processing and common accountability questions. It remains a description of practice and principle. It is not a certificate issued by a supervisory authority and not an assertion that a formal data-protection audit has been completed.

24.1 Website visitors

When you load satalya.com, your browser sends technical data that our host will log in the ordinary way: IP address, time, path, user-agent, and referrer. We use that data to keep the site available, to diagnose errors, and to detect abusive automated traffic. The lawful basis, where GDPR-style rules apply to us as controller, is legitimate interests in operating a website and defending it. Retention of raw web logs is typically short and then rotated, except where a log is pulled into a security incident file.

24.2 Access requesters

The contact facility on the homepage prepares an email to contact@satalya.com. Depending on your device, a copy of the draft may also exist in your own mail client. We process the content of the email to decide whether to invite you. We may store the email, our reply, and notes of our decision. If we refuse you, we may keep enough information to recognize a repeat application under a new name. That retention is for security and abuse prevention, not for marketing.

24.3 Account users

We process login events to confirm that the person at the keyboard is entitled to the seat. We process support tickets to fix problems. We process invoices to get paid and to keep books. If you add teammates, you must have authority to provide their work contact details. You should not add a personal email for a teammate if a work email exists, unless the teammate agrees.

24.4 Called parties

We do not choose who you call. If you upload a name and number, we will process that pair to place or log a call because you instructed us to. If a called party writes to privacy@satalya.com, we will explain this allocation and, where we are processor, we will refer them to you. We will not pretend that we independently verified your consent file.

24.5 Special situations

Legal claims. We may retain otherwise deletable data when a claim is reasonably foreseeable, including an AUP dispute or a traceback. Compulsory process. We may process and disclose as described in the Law Enforcement Requests Policy. Emergencies. We may process limited data to protect life or to contain an active compromise of the platform.

24.6 Your duties as a Client controller

You should provide a notice to persons you call that identifies you, describes the call recording if any, and explains how they exercise rights against you. You should honor erasure and objection where they apply to you, and you should send us a deletion instruction for Call Data when you are obliged to erase and no exemption applies. You should not instruct us to erase data that we must keep for a legal hold we have told you about.

24.7 International readers

If you are in a country that requires a local storage mandate for certain data, you must not use the Services for that data unless we have agreed a region and a contract that matches the mandate. The public website is globally reachable; reachability is not an offer to host regulated data in every country.

Questions under this Section 24 go to privacy@satalya.com, with a copy to legal@satalya.com if the question concerns compulsory process or a dispute.

S Satalya

A private AI dialer and classic dialer for lawful enterprise. Access by request only. satalya.com

Product

  • AI Dialer
  • Classic Dialer
  • Invite-only access
  • Contact

Legal

  • Terms of Service
  • Acceptable Use Policy
  • Privacy Policy
  • Refund Policy
  • Disclaimer
  • Compliance Policy

Contact

  • contact@satalya.com
  • legal@satalya.com
  • privacy@satalya.com
© 2026 Satalya. All rights reserved. For lawful businesses only. Misuse is prohibited and is the user’s responsibility.