Alterego

Privacy Policy

AlterEgo Travel Concierge
Effective date: 11 December 2025
Last updated: 2 September 2026

1. WHO WE ARE

The controller of personal data is:

ALTER EGO CONCIERGE SERVICE LLC

Email for data protection matters: [email protected]

In this Policy, 'we', 'us', and 'our' mean the above-mentioned Company, and 'User' means a natural person who installs or uses the AlterEgo Travel Concierge mobile application (hereinafter – the 'App').

We act in accordance with the laws of Ukraine and, where applicable, with Regulation (EU) 2016/679 (GDPR) with respect to Users located in the EU/EEA.

2. SCOPE OF THIS POLICY

This Policy applies to:

3. KEY TERMS

Personal data – any information relating to an identified or identifiable natural person.

Processing – any operation or set of operations performed on personal data (collection, recording, organisation, storage, adaptation, alteration, transfer, access, deletion, etc.).

Controller – the Company that determines the purposes and means of processing personal data.

Processor – a natural or legal person who processes personal data on behalf of the Controller on the basis of a contract (for example, cloud services, email/SMS providers).

Soft Delete – deactivation of an account without physical deletion of all User personal data from our systems.

Hard Delete – final, irreversible deletion of personal data from our operational systems (with the exception of data that must be retained under the law).

4. PRINCIPLES OF PERSONAL DATA PROCESSING

We process personal data in accordance with the following principles:

5. WHAT DATA WE COLLECT

5.1. Data you provide yourself

When registering and using the App, you may provide:

For arranging trips (where necessary):

In correspondence with managers (chats):

5.2. Data collected automatically

When using the App, we may automatically receive:

As a rule, these data are used in an aggregated and/or anonymised form for statistics and service improvement.

5.3. Geolocation data

The App may request access to geolocation via standard operating system mechanisms (for example, 'Allow once', 'Allow while using the app', 'Always'), depending on the version of the App and the device settings.

At the time of updating this Policy:

Providing access to geolocation is voluntary. You can change your choice at any time in your device operating system settings.

5.4. Address book contacts

If you create a group chat and grant the App access to your contacts, the phone numbers from your address book are sent to Alterego servers solely in order to determine which of your contacts already have an Alterego account. The numbers are used only for this matching, are not stored on our servers and are not transferred to third parties. Granting access is voluntary: if you do not grant it, the App will not read your address book and will not send any numbers, and creating a group chat will be unavailable – the rest of the App's features will work as usual. You can withdraw access at any time in your device settings.

5.5. Automated recognition of document data

To spare you manual data entry, the App offers to scan the page of your international passport. If you choose this option, the photo of the document page is transferred to Alterego servers and further – to the automated recognition service Microsoft Azure Document Intelligence (Microsoft Corporation), which reads the document data from it (surname, given name, number, date of birth, sex, date of issue and expiry date, citizenship) and returns them to us to fill in the fields. The recognised data are shown to you for checking before saving. Neither the photo nor the data obtained from it are used to train artificial intelligence models. Scanning is voluntary: you can always fill in the same fields manually, in which case the document photo is not transferred to the recognition service.

6. SOURCES OF DATA

We obtain personal data:

7. PURPOSES AND LEGAL BASES OF PROCESSING

7.1. Performance of a contract / provision of services (GDPR Art. 6(1)(b))

We process your data because it is necessary to:

7.2. Legitimate interests of the Company (GDPR Art. 6(1)(f))

We may process your data for:

We always assess that our legitimate interests do not override your fundamental rights and freedoms.

7.3. Compliance with legal obligations (GDPR Art. 6(1)(c))

We may process data where necessary for:

7.4. Consent (GDPR Art. 6(1)(a))

Where the legal basis for processing is your consent (for example, certain types of marketing communications, use of geolocation for personalised recommendations), we:

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

8. CHATS WITH MANAGERS

8.1. All messages in chats (text, photos, documents, voice messages, geolocation) are stored in our system for the period necessary to provide services, resolve possible disputes and fulfil legal obligations.

8.2. We may use the content of chats to:

8.3. Only authorised employees of the Company who need such access to perform their duties (managers, support service, legal and finance specialists in case of disputes) have access to chats.

8.4. In case of Soft Delete of your account, the chat history remains in the CRM, but:

8.5. In case of Hard Delete (final deletion), the chat history that is not subject to mandatory retention by law is deleted or anonymised.

9. PUSH NOTIFICATIONS

The App may send you push notifications regarding:

Push notifications are sent only if you have enabled them in your device operating system settings. You can change notification settings at any time in your device settings.

10. TRANSFER OF DATA TO THIRD PARTIES

We may transfer your personal data to the following categories of recipients:

In doing so, we act as a technical intermediary: you provide the data, and we transfer them to the provider. You are responsible for the accuracy and completeness of the data provided.

11. PROCESSORS (TECHNICAL PROVIDERS)

To operate the App, we engage the following providers:

Each of these providers acts under a contract with the Company that obliges them to process personal data only in accordance with our instructions, to ensure the confidentiality of the information and to apply protection measures equivalent to those observed by the Company.

12. INTERNATIONAL DATA TRANSFERS

Your data may be stored and processed on servers located both in Ukraine and in other countries. In case of data transfer to countries where the level of data protection may differ from European standards, we take measures provided for by law (for example, standard contractual clauses).

13. DATA RETENTION PERIODS AND DELETION

We store personal data for as long as necessary for the purposes for which they were collected or to comply with legal obligations.

Approximately:

13.1. Soft Delete (deletion of account in the App)

When you press 'Delete account' in the App:

13.2. Hard Delete (final deletion)

To fully delete personal data, the User may send a request to: [email protected]

After receiving the request, an authorised employee of the Company:

After Hard Delete, personal data that are not subject to mandatory retention are deleted or anonymised.

14. DATA SECURITY

We apply technical and organisational measures to protect personal data, including:

No online service can guarantee absolute security; however, we take all reasonable steps to protect your data.

15. YOUR RIGHTS

You have the right (within the limits established by law):

To exercise your rights, you can contact us at: [email protected]

16. CHILDREN

The App is intended only for adults (18+). We do not knowingly collect data of persons under 18 years of age. If we become aware that we have received such data, we will take steps to delete them.

17. CHANGES TO THIS POLICY

We may update this Policy from time to time. The new version takes effect from the moment it is published in the App, unless otherwise expressly stated.

18. CORPORATE CHANGES (MERGERS AND ACQUISITIONS)

In the event of reorganisation, merger, acquisition or sale of the Company's business, personal data may be transferred to the successor, provided that it ensures a level of data protection that is equivalent to or higher than that provided by this Policy.

19. COOKIES AND SIMILAR TECHNOLOGIES

We may use cookies and similar technologies (for example, mobile SDKs) for:

Cookies are not used to directly identify you outside the App. You can manage permissions for collection of certain data via your device settings.

20. FRAUD PREVENTION AND SECURITY

We may process certain data in order to:

Where necessary and in accordance with the law, we may transfer data to competent public authorities.

21. CONTACTS

For all questions related to the protection of personal data, you can contact us at:

Email: [email protected]