Privacy Policy
Effective date: January 1, 2025
Last updated: September 1, 2026
1. Introduction
Trust-Transfer SRL (“Trust-Transfer,” “trust-transfer®,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal data processed through trust-transfer® AIOS (“AIOS”), our websites, applications, artificial intelligence assistants, agents, integrations, APIs, and communication channels, including our integration with the WhatsApp Business Platform.
This Privacy Policy explains what information we may collect or process, how and why we use it, how it may be shared, how long it may be retained, and the rights available to individuals.
By using AIOS, communicating with us through WhatsApp, accessing our website, or interacting with an AIOS assistant or agent, you acknowledge the practices described in this Privacy Policy.
2. Scope
This Privacy Policy applies to personal data processed through:
trust-transfer® AIOS;
Trust-Transfer websites and web applications;
AI-powered assistants and specialized agents;
WhatsApp Business communications;
Microsoft Teams, web chat, email, APIs, and other enabled channels;
integrations with SAP, SAP SuccessFactors, ERP, CRM, HCM, databases, document repositories, collaboration tools, and other corporate systems;
technical support, implementation, and customer service activities.
This Privacy Policy does not replace the privacy notices or internal policies of the companies that use AIOS. When AIOS is provided on behalf of a business customer, that customer may be responsible for determining why and how personal data is processed.
3. Our role and the role of our customers
AIOS is a business-to-business, multitenant platform.
Depending on the context:
Trust-Transfer may act as a data controller when it determines the purposes and means of processing, such as when managing its website, commercial contacts, accounts, billing, security, or direct support services.
Trust-Transfer may act as a data processor or service provider when it processes personal data on behalf of a customer that uses AIOS within its organization.
The customer organization generally acts as the data controller for information relating to its employees, contractors, clients, suppliers, candidates, or other authorized users.
When Trust-Transfer acts as a processor, we process personal data according to the customer’s documented instructions, the applicable agreement, and applicable law. Requests regarding data controlled by a customer may be referred to that customer.
4. Information we may process
Depending on the configuration selected by the customer and the way AIOS is used, we may process the following categories of information.
4.1 Account and identity information
Name and surname;
business email address;
telephone number;
company, position, department, or organizational unit;
username, user identifier, employee identifier, or account identifier;
roles, permissions, and authentication information;
language and communication preferences.
4.2 WhatsApp information
When a user communicates with AIOS through WhatsApp, we may process:
telephone number and WhatsApp identifier;
WhatsApp profile name, when available;
message content;
files, images, audio, documents, or other content voluntarily submitted;
message date, time, status, and delivery information;
technical metadata required to receive and respond to messages;
opt-in, opt-out, and communication preference records.
WhatsApp and Meta may independently process information in accordance with their own terms and privacy policies. Trust-Transfer does not control Meta’s independent processing activities.
4.3 Conversation and user-submitted content
Questions, instructions, prompts, and responses;
conversation history;
documents or files submitted for consultation or processing;
feedback and support requests;
confirmations or approvals provided before an action is executed;
information voluntarily included in communications with an AIOS agent.
Users should not submit personal, confidential, sensitive, or regulated information unless they are authorized to do so and the relevant AIOS environment has been approved for that purpose.
4.4 Customer content and corporate information
Subject to the customer’s configuration and permissions, AIOS may access or process:
internal documents, manuals, policies, and procedures;
human resources information;
vacation balances and requests;
financial, commercial, administrative, or operational information;
customer, supplier, employee, or candidate records;
orders, invoices, tickets, requests, workflows, and transactions;
calendar, meeting, collaboration, or email information;
information retrieved from SAP, SAP SuccessFactors, ERP, CRM, HCM, databases, APIs, legacy applications, and other systems;
information available from authorized external or public sources.
AIOS only accesses the systems, sources, tools, and actions enabled for the relevant customer, agent, user, and use case.
4.5 Technical and usage information
IP address;
browser and device information;
operating system;
application and session identifiers;
authentication, access, and security logs;
dates and times of access;
feature usage and consumption metrics;
API requests and integration events;
system performance, diagnostic, and error information;
records of actions executed through AIOS.
4.6 Commercial and support information
Business contact details;
communications with our sales and support teams;
service configuration and implementation information;
contracts, subscriptions, invoices, and billing records;
incidents, requests, and troubleshooting information.
5. How we obtain information
We may receive information:
directly from users;
from the organization that provides the user with access to AIOS;
through WhatsApp Business Platform and other enabled communication channels;
from corporate systems connected to AIOS;
from identity and authentication providers;
from documents or databases authorized by the customer;
from public sources or Internet searches enabled for a particular agent;
automatically through logs, APIs, cookies, and similar technologies;
from service providers supporting the operation, security, and maintenance of AIOS.
6. How we use information
We may process information to:
provide, operate, maintain, and improve AIOS;
authenticate users and manage accounts, roles, and permissions;
receive and respond to WhatsApp messages;
understand questions, prompts, and instructions;
retrieve relevant information through retrieval-augmented generation and related technologies;
generate contextual responses;
route requests to the appropriate specialized agent;
connect AIOS with authorized corporate systems and data sources;
execute actions and business processes requested or approved by authorized users;
synchronize users and corporate information;
provide technical support and resolve incidents;
monitor performance, availability, quality, and security;
prevent fraud, abuse, unauthorized access, and unlawful activity;
maintain audit trails and transaction records;
enforce contractual rights and service limitations;
comply with legal and regulatory obligations;
communicate administrative, operational, or security-related information;
develop and improve features using aggregated, anonymized, or otherwise non-identifiable information.
Trust-Transfer does not sell personal data.
Trust-Transfer does not use WhatsApp message content or customer confidential information for third-party advertising.
7. Artificial intelligence processing
AIOS may use retrieval-augmented generation, vector databases, specialized AI agents, AI Skills, Model Context Protocol, multiple large language models, and other artificial intelligence technologies.
Depending on the customer’s configuration, information submitted to AIOS may be processed to:
identify the user’s intent;
locate relevant corporate information;
create a response;
select an appropriate agent, tool, or system;
prepare or execute an authorized action;
validate, log, or audit a process.
AI-generated responses may be inaccurate, incomplete, or require human review. Customers determine the permitted level of autonomy for each agent and may require confirmation or human intervention before actions are completed.
Trust-Transfer does not use customer content to train its own general-purpose artificial intelligence models unless this has been expressly authorized in writing by the customer.
Third-party model providers may process limited information as subprocessors when required to provide the selected AI functionality. The providers used may vary according to the customer’s configuration, technical requirements, contractual terms, security requirements, and geographic location.
8. Automated actions and human oversight
AIOS may be configured to perform actions in connected systems, such as:
retrieving or updating information;
creating meetings;
sending communications;
opening tickets;
consulting orders or invoices;
submitting requests;
initiating workflows;
executing other authorized business processes.
The organization using AIOS determines which actions are permitted, which users may request them, and whether prior confirmation, additional authentication, or human approval is required.
AIOS is not intended to make legally binding, employment, credit, healthcare, or similarly significant decisions about an individual without the controls and human oversight required by the customer and applicable law.
9. Legal bases for processing
Depending on the circumstances and applicable law, personal data may be processed on one or more of the following grounds:
performance of a contract or provision of requested services;
consent;
legitimate business interests, provided those interests do not override individual rights;
compliance with legal or regulatory obligations;
protection of the security, integrity, and availability of AIOS;
instructions provided by a customer acting as data controller;
establishment, exercise, or defense of legal claims.
Where consent is required, it may be withdrawn at any time, without affecting processing lawfully performed before withdrawal.
10. WhatsApp communications
Trust-Transfer uses the WhatsApp Business Platform to enable authorized users to interact with AIOS.
We will only use WhatsApp to communicate for authorized business purposes and in accordance with applicable law, user preferences, and WhatsApp requirements.
Users may stop receiving messages by:
replying STOP, UNSUBSCRIBE, BAJA, or an equivalent instruction;
blocking the relevant WhatsApp business number;
contacting Trust-Transfer or the organization that provided access to AIOS.
Operational or transactional responses requested by the user may still be provided where permitted.
WhatsApp is operated by Meta. Meta may process account information, telephone numbers, message metadata, usage data, and other information according to its own privacy terms. Users should review WhatsApp’s privacy documentation for information about Meta’s processing practices.
11. How information may be shared
We may share personal data only when necessary and for the purposes described in this Privacy Policy, including with:
the customer organization that provides access to AIOS;
authorized users and administrators of that organization;
Meta and WhatsApp, when the WhatsApp channel is used;
cloud infrastructure, hosting, database, storage, cybersecurity, monitoring, and technical support providers;
artificial intelligence and language model providers selected for the service;
identity, authentication, communication, and collaboration providers;
integration partners and technology providers required to connect authorized systems;
professional advisers, auditors, insurers, or legal representatives;
government authorities, courts, or regulators when required by law;
a successor entity in connection with a merger, acquisition, restructuring, financing, or transfer of business assets.
Service providers are authorized to process information only as required to perform the relevant services and are subject to contractual, confidentiality, and security obligations, where applicable.
12. International data transfers
AIOS, WhatsApp, cloud infrastructure providers, artificial intelligence providers, and other technology services may process information in Argentina, the United States, Brazil, the European Union, or other countries.
Where personal data is transferred internationally, Trust-Transfer and its customers, as applicable, will use contractual, organizational, or legal safeguards required by applicable data protection laws.
The laws of the country in which information is processed may differ from those of the user’s country of residence.
13. Data retention
We retain personal data only for as long as necessary to:
provide AIOS and the contracted services;
maintain security and audit records;
comply with contractual and legal obligations;
resolve disputes and enforce agreements;
respond to customer instructions;
protect the rights and security of Trust-Transfer, its customers, and users.
Retention periods may vary according to:
the customer’s configuration;
the type of information;
the relevant AIOS agent or integration;
contractual requirements;
legal and regulatory obligations;
security and audit requirements.
Customers may configure or agree specific retention periods for conversations, documents, logs, vectorized content, and integration records.
When information is no longer required, it will be deleted, anonymized, or securely isolated in accordance with applicable obligations and technical limitations. Residual copies may remain temporarily in encrypted backups until they are overwritten under normal backup cycles.
14. Data security
Trust-Transfer applies reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, loss, alteration, disclosure, misuse, or destruction.
Measures may include:
encryption in transit and at rest;
authentication and access controls;
role-based permissions;
tenant isolation;
secure API credentials and secret management;
network protection and controlled connectivity;
logging, traceability, and monitoring;
backups and business continuity measures;
vulnerability management;
restricted administrative access;
confidentiality obligations;
confirmation and authorization controls for sensitive actions.
No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.
Users and customers are responsible for protecting their credentials, devices, accounts, and authentication methods and for immediately reporting suspected unauthorized access.
15. Data isolation and customer control
AIOS is designed as a multitenant platform in which each customer has its own configuration, integrations, permissions, agents, and authorized information sources.
Customers determine:
which users may access AIOS;
which agents are available;
which documents and systems may be consulted;
which tools may be used;
which actions may be executed;
which approvals are required;
which models and providers may be used;
which consumption and usage limits apply.
Customer information is not intentionally disclosed to another customer.
16. Sensitive and confidential information
AIOS may process sensitive or confidential information only when:
the customer has enabled and authorized the relevant use case;
the processing is lawful;
appropriate permissions and safeguards are in place; and
the user is authorized to submit or access the information.
Users must not submit passwords, private cryptographic keys, payment card security codes, authentication secrets, or information they are not authorized to disclose.
17. Children’s privacy
AIOS is designed for business and professional use and is not directed to children.
Trust-Transfer does not knowingly collect personal data directly from children without appropriate authorization. If we become aware that information relating to a child has been processed without a valid legal basis or required authorization, we will take reasonable steps to delete or restrict it.
18. Individual rights
Subject to applicable law and the circumstances of the processing, individuals may have the right to:
request information about the processing of their personal data;
access their personal data;
request correction or updating of inaccurate information;
request deletion or suppression;
request restriction or blocking of processing;
object to certain processing;
withdraw consent;
request portability, where applicable;
challenge certain automated decisions;
submit a complaint to a competent data protection authority.
When Trust-Transfer processes information on behalf of a customer, individuals should generally submit requests directly to that customer. Trust-Transfer will reasonably assist the customer in responding to valid requests where required.
We may request reasonable information to verify identity and protect personal data before processing a request.
In Argentina, individuals may exercise the rights recognized under Personal Data Protection Law No. 25,326 and its applicable regulations. The Agency for Access to Public Information is the competent supervisory authority.
19. How to request access, correction, or deletion
To request access, correction, updating, deletion, or suppression of personal data:
Visit https://trust-transfer.tech.
Use the contact form.
Enter the subject “Privacy Request” or “Data Deletion Request.”
Provide:
your full name;
the telephone number associated with WhatsApp, including country code;
your business email address, if applicable;
the name of the organization through which you use AIOS;
a clear description of your request.
For security reasons, we may need to verify your identity before completing the request.
If the relevant data is controlled by a Trust-Transfer customer, we may forward or redirect the request to that organization.
We will respond within the time required by applicable law.
20. WhatsApp data deletion instructions
A user may request deletion of data associated with their interaction with the trust-transfer® AIOS WhatsApp application at any time.
To submit a deletion request:
Go to https://trust-transfer.tech.
Open the contact form.
Select or enter “WhatsApp Data Deletion Request.”
Include the WhatsApp telephone number used to communicate with AIOS, including country code.
Identify the company or organization through which AIOS was used.
Specify whether the request relates to:
WhatsApp conversation data;
AIOS account information;
submitted documents;
conversation history;
all personal data associated with the interaction.
After identity verification, Trust-Transfer will delete or anonymize the information under its control unless retention is required by law, security obligations, contractual requirements, or the establishment, exercise, or defense of legal claims.
Information controlled by a customer organization may need to be deleted by that organization. Information independently retained by Meta or WhatsApp is governed by Meta’s own policies and must be requested through the mechanisms provided by Meta.
21. Cookies and website technologies
Our website may use cookies or similar technologies that are necessary to:
operate the website;
maintain security;
remember preferences;
understand website performance and usage.
Where required, non-essential cookies will be used only after consent. Users may manage cookies through the consent controls on the website or their browser settings.
Third-party services embedded in the website may apply their own cookies and privacy policies.
22. Third-party services and links
AIOS and our website may connect to or contain links to third-party services, including Meta, WhatsApp, Microsoft, SAP, cloud platforms, identity providers, and artificial intelligence providers.
Those third parties may process information under their own privacy policies. Trust-Transfer is not responsible for independent processing performed by third parties outside the services provided on our behalf.
23. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in AIOS, applicable law, security practices, or third-party services.
The updated version will be published on our website with a revised “Last updated” date. Where required, we will provide additional notice or obtain consent.
24. Contact us
The entity responsible for this Privacy Policy is:
Trust-Transfer SRL
Product: trust-transfer® AIOS
Country: Argentine Republic
Website: https://trust-transfer.tech
Privacy, access, correction, or deletion requests may be submitted through the contact form available at:
Please use the subject “Privacy Request” or “Data Deletion Request.”
