Privacy Policy
Last updated: 22 September 2026
Aisar is the service record that lives with the car. This policy explains what personal data we process, why, on what legal basis, and what rights you have. It covers the Aisar web app, the Aisar mobile app, the public car pages and our marketing site. It is written in plain language because trust is our product.
1. Who we are and in what role
The operator of the Aisar platform is META MINE OOD, company number 208222364, VAT number BG208222364, registered at Zornitsa 42, Apt. 3, Burgas 8018, Bulgaria. For privacy questions: .
Aisar acts in two distinct roles, which it is important to distinguish:
- Processor (on behalf of the workshop): a workshop's customer contact data (name, phone) is entered by the workshop. For that data the workshop is the controller and Aisar processes it on the workshop's instructions under a data-processing agreement.
- Controller (or joint controller): for the cross-workshop public car record and workshop user accounts, Aisar determines the purposes and means and acts as a controller.
2. Data we collect
We collect only the data needed to keep the service record:
- Workshop user account: email, password hash (strong, industry-standard one-way password hashing — the password itself is never stored), display name, preferred language.
- Session and preferences: strictly necessary cookies that keep you signed in, remember the language you chose, and remember which of your locations you are working at.
- Workshop customer data (collected indirectly): name and phone. These people do not sign up themselves — the data is entered by the workshop. See “Source of data” (GDPR Art. 14).
- Car data: VIN, plate, make, model, year.
- Service entries: work summary, AI-generated customer explanation, mileage, cost, photos, raw voice transcript.
- Voice audio: transient, sent for speech recognition and not stored by us.
- Photos taken to scan a VIN, plate or odometer: sent to be read and not stored — only the values you confirm are saved.
- Audit log and entry-visibility metadata.
- IP address: in-memory only, for rate-limiting (anti-abuse). Not stored long-term.
- Error reports: when something breaks, we record the technical details — the error, the page or request, the browser type and, where relevant, internal account or workshop IDs — so that we can fix it. They never contain your IP address, and the server's reports are set up to filter out names, phone numbers, email addresses, VINs and voice transcripts.
- Billing data: company name, billing address, VAT number, and an email address for invoices. Card numbers do NOT pass through us and are never stored by us — they are entered directly with the payment provider.
- Signed-in phones (mobile app): device name, platform, app version and when it was last used — see section 2a.
- A local offline queue on your device so the app works without a connection — in the browser and in the mobile app (section 2a).
2a. The mobile app
The Aisar app for iOS and Android does what the web app does, and everything in this policy applies to it too. What is specific to the app:
- Permissions, asked for only when you use the feature that needs them: the microphone, while you are recording a spoken log; the camera, when you photograph a repair or scan a VIN; and your photo library, to attach photos of a repair — the phone hands the app only the photos you pick. The app never records in the background.
- Voice recordings: sent to our speech-recognition provider to be turned into text, and not stored by us. The phone keeps a recording only until it has been transcribed, so that one made without signal can be sent once the connection is back.
- Photos: a photo taken to scan a VIN, plate or odometer is sent to our AI provider to be read and is not stored. A photo you attach to an entry is stored with that entry and shown on the public car page (section 7).
- On the phone: your sign-in credentials, in the phone's secure keychain (iOS) or keystore (Android); your chosen language; entries and job steps you have confirmed that have not reached us yet, in a file in the app's storage that your phone's own backup may include; the last list of your workshop's cars, so you can pick one offline; and a report you downloaded to share. Signing out removes the credentials, the car lists and the downloaded report, and your unsent work stays on the phone until you sign back in; deleting your account removes your unsent work, the car lists and the report.
- On our servers: for each phone signed in to your account, the device name the phone reports, whether it is iOS or Android, the app version and when it was last used. We use this to recognise the phone and to be able to sign it out — a lost phone, for example, or every phone when your password is reset. See section 9 for how long it is kept.
- No advertising, no analytics, no tracking: the app contains no advertising, analytics or tracking code, and it connects only to our own servers.
3. Source of customer and staff data (GDPR Art. 14)
If you are a workshop's customer, your name and phone were most likely entered by the workshop, not by you. We receive them from the workshop, which is the controller of that data. To access, correct, or delete this data, contact the relevant workshop; we will assist as a processor. You may also contact us and we will route the request.
- Workshop staff (collected indirectly): your account was created by the workshop that employs you, which enters your name and, where you have a login, your email address and your first password. You did not sign up, and your employer decides whether you have an account at all. Write to us at to see, correct, or object to that data. If your profile has a login, you can also delete your account yourself (section 9a).
4. Why we process data and on what basis
For each category we rely on a specific GDPR legal basis:
- Performance of a contract (Art. 6(1)(b)): creating and maintaining workshop accounts and providing the service.
- Legitimate interest (Art. 6(1)(f)): maintaining the cross-workshop record, anti-abuse rate-limiting by IP, notifying customers (a car ready, an appointment), and keeping error reports so that we can find and fix faults.
- Legal obligation (Art. 6(1)(c)): where we are required by law to retain or disclose data.
- Consent (Art. 6(1)(a)): analytics on our marketing site. It does not start before you press “Allow”. You can withdraw your consent at any time (see section 14); withdrawal applies going forward and does not affect processing carried out before it.
5. Artificial intelligence (EU AI Act Art. 50)
We disclose this transparently: the voice transcript and the customer explanation are AI-generated and are always confirmed by a human (the mechanic) before becoming part of the record. Nothing is committed automatically without confirmation.
For these features, voice audio and scanned photos (to read VIN, plate, and odometer) are sent to a US AI model provider. See the sub-processors and transfers section.
6. Sharing and categories of recipients
To provide the service we use providers in the following categories. All of them act as our processors under data-processing agreements and only on our instructions:
- Providers that host our application, database, and file storage.
- A speech-to-text and AI text/vision provider (to transcribe voice notes, generate the plain-language customer explanation, and read VIN, plate, and odometer from photos).
- An email delivery provider (to send account emails: the welcome message, email-address confirmation, and password reset).
- A vehicle-data lookup service (to decode a VIN into make/model/year).
- Messaging and SMS providers (to send customer notifications, when enabled).
- Stripe — the payment provider for paid plans (Stripe Payments Europe, Ltd., Ireland). Stripe receives the company name, billing address, VAT number, invoice email address, and the card details. Card details are entered with Stripe and never reach our servers. Stripe also acts as an independent controller for its fraud-prevention checks and its own legal obligations. See section 8.
- Google — Google Analytics 4, on our marketing site only and only after you agree. We do not run ads, and we do not sell personal data or pass it to data brokers.
7. The public car page
A service record can be opened by anyone who has its link (/c/[publicId]). There is no password, no per-car opt-in, and no setting that makes one car private; sharing the link publishes the record. The page shows a masked registration plate (the first two and last two characters), the make, model and year, the latest odometer reading and a chart of the mileage over time, the number of records, and the year the history starts. For each entry it shows the workshop that did the work, the date, the work summary, the plain-language explanation, the parts used with quantities and prices, the mileage, the total cost, and the photos. If a workshop keeps entries of its own off the page, the page still shows how many. The VIN is never shown, and neither are the voice recording, the transcript made from it, or any customer name or phone number. Entries stay credited to the workshop that wrote them — never to a person by name — including after their author, or the workshop itself, has deleted its account (section 9a).
8. International transfers
Aisar is EU-facing, with Bulgaria as the lead jurisdiction. Some data (voice audio, photos, VIN) may be processed outside the European Economic Area (EEA). Where data is processed outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR, such as an adequacy decision or standard contractual clauses. UK-GDPR also applies where relevant.
Payments are the second such case, but this one does not depend on a choice: if a workshop is on a paid plan, its billing data is processed by Stripe. The contract is with Stripe Payments Europe, Ltd. in Ireland (inside the EEA); Stripe may pass some of that data to Stripe, Inc. in the USA, for which we rely on standard contractual clauses and the EU–US Data Privacy Framework. Signing up on the free plan sends nothing to Stripe: a customer record is created there when an account first goes to checkout for a paid plan, even if the purchase is not completed.
9. Retention
We keep each category only as long as needed:
- Workshop account data (email, name, login, language): for as long as the account exists. You can delete your account yourself at any time, and these are erased at once (section 9a).
- Session: the session cookie expires after 30 days.
- Phone sign-ins (mobile app): a sign-in expires after 60 days without use, and its record is deleted once it has expired — or at once when you delete your account.
- Customer contact data (name, phone): retained while the workshop maintains the relationship; the workshop (as controller) decides retention and we delete on its instruction. They are also deleted at once if the workshop's account is closed.
- Jobs, bookings and opening hours: kept while the workshop's account is open; deleted at once when it closes.
- Service-record entries — work description, plain-language explanation, mileage, cost, photos, and the raw voice transcript kept as provenance: retained as part of the permanent, cross-workshop vehicle record. By design these are not deleted in the ordinary flow; they are corrected by superseding, voided, or hidden from the public page by the workshop that wrote them (with the hidden count disclosed). They stay when their author, or the workshop, deletes its account.
- Audit log: retained for the life of the record as the trust/integrity trail.
- Anti-abuse IP data: held only transiently in memory for rate-limiting and not stored.
- Error reports: deleted after 30 days.
- Backups: our database backups are deleted after 30 days. Until then, a backup can still hold data that has since been deleted (section 9a).
- Invoices and accounting records (paid plans): retained for 10 years after the end of the year in which the invoice was issued, as required by Bulgarian accounting and tax law. This period is a legal obligation and cannot be shortened on request.
9a. Deleting your account, and what the permanent record keeps
Anyone with a login can delete their account at any time: on the web in Settings › Account, or in the mobile app's settings. You confirm with your password. Deletion is immediate and cannot be undone. Before you confirm, you are shown what it will do.
- Erased at once: your name, email address, password hash and language; every sign-in, in browsers and on phones; any unused password-reset or email-confirmation links; and your membership of every workshop. What is left of the account is an empty placeholder — an internal ID, your role, and the dates the account was created, accepted our terms and was deleted. The database itself refuses to keep a name, email address or password on it. It stays because entries on cars' records point to it.
- Your entries stay on the cars' records, credited to the workshop, without your name. The voice transcript kept with an entry stays with it and is never shown on the public page.
- If you are the last person managing a workshop's account, deleting your account closes the workshop. Everyone on its team loses access to it, and anyone left with no other workshop has their account erased in the same way as yours. The workshop's customer list (names and phone numbers), its jobs and bookings and its opening hours are deleted at once, its API keys stop working, and its subscription is cancelled straight away without a final invoice (if the payment provider cannot be reached at that moment, we keep trying until the cancellation goes through).
- What a closure keeps: the workshop's entries stay on the cars' records under the workshop's name, which remains public — if the workshop traded under a person's name, that name stays with its entries. After closure nobody can void, hide or correct those entries any more. Words spoken into a voice log — a customer's name, for example — stay in that entry's transcript.
- If you are the only owner of a location in an account that someone else still manages, deletion is refused until the location has another owner — write to us to transfer ownership.
- Payment records: if the account had a customer record with our payment provider, Stripe keeps it and the invoices, which we are required to keep for 10 years (section 9).
- Backups: deleted data can remain in our database backups until they are deleted, at most 30 days later. If we ever restore a backup, we re-apply every deletion made since it was taken; for this we keep the internal IDs of deleted accounts, with no name or email address.
- On the phone: when you delete your account in the app, it removes your unsent work, the car lists and any downloaded report, and signs out.
- Without a login: workshop staff whose profile has no login cannot delete it themselves — ask the workshop, or write to us at . For workshop customers' data, see section 11.
- Other erasure requests: where you ask us to erase data and we can lawfully do so, we will; where the permanent-record design or a legal obligation requires retention, we explain that and use voiding/superseding/hiding instead of deletion.
10. Record immutability and your rights
Service entries are tamper-proof (append-only): a written row cannot be deleted or silently altered in the ordinary flow. This protects trust in the record. As a result, GDPR rights are exercised in a specific way:
- Access (Art. 15): you can request a copy of your personal data.
- Rectification (Art. 16): errors in an entry are fixed by supersede/void — the old row is marked, not deleted.
- Erasure (Art. 17): you can delete your account yourself at any time, on the web or in the mobile app (section 9a). The ordinary flow does not delete entries — they stay on the car's record without your name; for other valid requests we apply a controlled erasure path.
- Restriction (Art. 18) and objection (Art. 21): you can request restriction of processing or object to processing based on legitimate interest.
- Portability (Art. 20): on request we provide the data you gave us in a structured, machine-readable format.
- A workshop can hide its own service entry from the public page: this does not change the entry itself — the entry stays in the immutable record and the public page discloses a hidden-entry count (workshops can hide, not silently erase).
- Complaint to the supervisory authority: you have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP / КЗЛД), www.cpdp.bg.
11. Requests from non-registered customers
If your data was entered by a workshop (you did not sign up), the workshop is the controller of that data. We route the request to the relevant workshop and assist as a processor.
12. Children
Aisar is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have received such data, contact us and we will remove it.
13. Security
We protect personal data with technical and organizational measures appropriate to the risk. We do not publish the list, because an inventory of our defenses is of more use to an attacker than to you.
Photos attached to a service record are visible to anyone who has the link. We strip location metadata on upload and refuse the phone-camera formats we cannot strip.
The Aisar web app has no analytics, no advertising, and no third-party scripts, and nothing in it tracks you across other sites. This is enforced, not just promised: the app sends a Content-Security-Policy that permits your browser to open connections only to our own servers. The mobile app has no analytics, advertising or tracking either (section 2a).
14. Cookies and analytics consent
In the web app itself we use only strictly necessary cookies — for your session, your language, and the location you are working at. The app sets no analytics or advertising cookies. The mobile app uses no cookies; what it keeps on the phone is described in section 2a.
Our marketing site can use Google Analytics 4, and only with your consent: nothing is stored until you press Allow in the consent bar, advertising signals are never granted in any state, and if you were never shown such a bar then no analytics is running. Your choice is kept in your own browser, not with us. To change it, clear the site's data in your browser settings, or write to us at .
15. Changes to this policy
We may update this policy. Material changes will be reflected by the “last updated” date at the top. We recommend reviewing it periodically.
16. Contact and complaints
For questions or to exercise rights: . You have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP / КЗЛД): 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, Bulgaria, www.cpdp.bg.