NeuralSys International Privacy Notice
Version: 2026-08-19
This Privacy Notice explains how NeuralSys (the Controller), processes personal data in connection with NeuralSys.
Privacy contact: neuralsys@mail.ru.
1. Scope and applicable law
1.1. This Notice applies to the NeuralSys website, Telegram bot @NeuralSys_AI_bot, support, billing, and related service functions.
1.2. The Controller is established in the Russian Federation. Russian data-protection requirements apply where they govern the Controller's processing.
1.3. In addition, where their territorial-scope requirements are met, other mandatory privacy regimes may apply. In particular, Regulation (EU) 2016/679 (EU GDPR) may apply to processing related to offering goods or services to people in the European Union, and the UK GDPR may apply where NeuralSys specifically offers goods or services to people in the United Kingdom or otherwise falls within its territorial scope.
1.4. This Notice is designed to provide a common international explanation of NeuralSys processing. It does not state that every listed law applies to every User or every processing activity.
2. Categories of personal data
Depending on how NeuralSys is used, the Controller may process:
- internal NeuralSys user and conversation identifiers;
- Telegram user ID, chat ID, username, first and last name, Telegram language code, and other profile information made available to the bot;
- messages, dialogue history, prompts, and other content submitted by the User;
- conversation summaries, context, and memory elements generated by NeuralSys when those functions are enabled;
- interface, model, memory, language, and other service settings;
- service usage, request identifiers, selected processing modes, token/usage accounting, points credited, reserved, or deducted, and related billing records;
- payment and refund records supplied by the payment provider or generated by NeuralSys; NeuralSys should not receive or store full payment-card credentials where payment is handled by an external payment provider;
- support requests and feedback;
- technical and security information, including IP address and User-Agent in web interfaces where received, timestamps, logs, request status, error and anti-abuse information;
- records of acceptance of Terms, privacy acknowledgements, consents where requested, withdrawals, and versions of legal documents.
3. Purposes and legal bases
3.1. NeuralSys processes personal data for the following purposes:
- creating and maintaining the User's NeuralSys account and Telegram identity;
- providing dialogue, context, memory, settings, and other requested service functions;
- transmitting the minimum context reasonably required to an AI technology provider for a requested AI operation;
- calculating usage, maintaining balances, processing payments and refunds, and preventing billing abuse;
- providing support and handling feedback;
- maintaining security, diagnosing failures, preventing fraud and misuse, and protecting infrastructure;
- complying with legal obligations, resolving disputes, establishing or defending legal claims, and maintaining legally significant records;
- improving and analysing the service where permitted by applicable law and consistent with the User's settings and reasonable expectations.
3.2. Where the EU GDPR or UK GDPR applies, the Controller does not rely on one blanket consent for all processing. Depending on the activity, the intended lawful basis may be:
- performance of a contract or steps requested before entering into a contract for processing objectively necessary to provide requested NeuralSys functions, account access, billing, and support;
- compliance with a legal obligation for records or processing required by applicable law;
- legitimate interests for proportionate security, fraud prevention, service integrity, defence of legal claims, and limited operational improvement, subject to the required balancing of interests and rights;
- consent only where consent is an appropriate and legally required basis for a specific activity. Consent may be withdrawn for the future without affecting processing lawfully carried out before withdrawal.
3.3. If special-category or similarly sensitive data is voluntarily included in a message, additional legal conditions may apply. Users should avoid sending sensitive data unless it is genuinely necessary for the requested conversation. NeuralSys does not ask Users to disclose such data merely to create an account.
4. How processing occurs
4.1. Processing is primarily automated. Limited human access may occur where necessary for support, security, moderation of feedback submitted for possible publication, incident response, compliance, or protection of legal rights.
4.2. Access should be limited to persons and systems that need the data for the relevant function.
4.3. NeuralSys may collect, record, organize, store, retrieve, use, transmit, restrict, anonymize, delete, or otherwise process personal data to the extent necessary for the purposes and legal bases described in this Notice.
5. Recipients and technology providers
5.1. NeuralSys may disclose or make personal data available, as necessary, to categories of recipients such as:
- Telegram and related messaging infrastructure used to communicate with the User;
- AI technology providers used to generate requested responses;
- hosting, infrastructure, database, networking, monitoring, and security providers;
- payment providers when the User makes a payment or requests a refund;
- professional advisers or competent public authorities where disclosure is legally required or reasonably necessary to establish, exercise, or defend legal claims.
5.2. For an AI request, necessary fragments of the current dialogue, relevant retained context, service instructions, and technical parameters may be sent to the AI provider selected by NeuralSys. The exact provider set may change as the service develops.
5.3. NeuralSys currently supports integration with DeepSeek as an AI technology provider. The fact that a provider is technically supported does not mean it is used for every request or every User.
5.4. The Controller should maintain an up-to-date internal record of actual processors/providers, their roles, locations, contractual arrangements, and transfer mechanisms. This public Notice does not substitute for that compliance record.
6. International transfers
6.1. NeuralSys is operated by a Controller established in the Russian Federation and uses technology services that may be established or operate in different countries. Consequently, use of NeuralSys may involve international access to or transfer of personal data.
6.2. Where the EU GDPR applies to a transfer governed by Chapter V of the EU GDPR, the Controller must use a legally available transfer mechanism before making the restricted transfer, such as an applicable adequacy decision, appropriate safeguards (including approved standard contractual clauses where appropriate), or a valid derogation in the limited circumstances in which the GDPR permits one.
6.3. Where the UK GDPR applies to a restricted transfer, the Controller must use a mechanism permitted under the UK regime, such as UK adequacy regulations, appropriate safeguards (which may include an applicable International Data Transfer Agreement or UK Addendum), or a permitted exception.
6.4. This Notice does not itself create a transfer mechanism and does not claim that Standard Contractual Clauses, an adequacy decision, an IDTA, an Addendum, or another safeguard is in place unless the Controller has actually implemented it for the relevant provider and transfer. NeuralSys must not represent an unverified transfer safeguard as existing.
6.5. Where Russian law imposes data-localisation, notification, or cross-border-transfer requirements on the Controller, those requirements must also be observed where applicable.
6.6. Users may contact neuralsys@mail.ru for information about the transfer mechanism applicable to their data, subject to lawful confidentiality and security limitations.
7. Retention
7.1. Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to contractual requirements, mandatory retention periods, dispute/limitation periods, security needs, and legal obligations.
7.2. Dialogue history, summaries, settings, and memory-related information may be retained while the relevant service functions remain active and may be deleted or anonymized when the purpose ends, subject to mandatory retention grounds.
7.3. Billing, payment, legal acceptance, consent, security, support, and dispute records may be retained longer where necessary for accounting, legal compliance, fraud prevention, or establishment and defence of legal claims.
7.4. NeuralSys should maintain operational retention rules for the principal data categories. This Notice does not promise a specific deletion period where the actual system has not yet implemented and verified one.
8. Security
8.1. The Controller takes organizational and technical measures intended to protect personal data against unauthorized access, accidental loss, alteration, disclosure, destruction, and other unlawful processing, taking account of the nature of the processing and reasonably foreseeable risks.
8.2. Measures may include access controls, encryption for appropriate data, separation of privileges, logging, backups, monitoring, and incident-response procedures.
8.3. No Internet service can guarantee absolute security. Users should avoid submitting information that is unnecessary for the requested service function.
The User understands that transmitting information over the Internet inherently involves risks. To the maximum extent permitted by applicable law, the Operator is not responsible for loss, theft, or disclosure of data where this results from the acts of third parties or the User and the Operator has not breached mandatory data-protection obligations.
9. Individual rights
9.1. Depending on the law applicable to the User and processing, rights may include access to personal data, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right to complain to a competent supervisory authority.
9.2. Where the EU GDPR applies, the User may have the rights provided in Articles 15–22 GDPR, subject to their statutory conditions and exceptions. Where the UK GDPR applies, corresponding UK data-protection rights may apply.
9.3. A User may exercise applicable rights by contacting neuralsys@mail.ru. The Controller may request information reasonably necessary to verify identity and protect data from unauthorized disclosure.
9.4. Withdrawal of consent affects processing based on that consent for the future. It does not automatically require the Controller to erase data that must or may lawfully be retained on another basis.
9.5. If the User believes applicable EU or UK data-protection law has been infringed, the User may also have the right to lodge a complaint with the supervisory authority competent under that law.
10. Children
10.1. NeuralSys is offered under the Terms to legally capable Users aged 18 or older. The service is not intentionally offered as a child-directed service through these Terms.
11. Changes to this Notice
11.1. The current version is published at https://neuralsys.ru/en/legal/privacy and may be updated to reflect changes in NeuralSys, providers, processing, or applicable law.
11.2. If a change creates a new processing activity that legally requires consent, NeuralSys must request that consent separately rather than treating continued use as consent where the law does not permit that approach.