Terms and Privacy
Effective from 26 August 2026
Terms of Use
1.General provisions
These Terms of Use (the “Terms”) govern the relationship between AI App (the “Provider”, “we”) and any person using the website ai.sogeking.kz or ordering software development services (the “Client”, “you”).
In respect of website use and how you reach out to us, these Terms constitute a public offer under applicable civil law. Using the website means you accept these Terms.
Development services are provided under a separate written agreement. These Terms apply to that relationship only where the agreement is silent; if the two conflict, the agreement prevails.
If you disagree with any provision of these Terms, do not use the website and do not send us enquiries.
2.Definitions
- Website — the Provider's web resource, including all of its pages and the contact details published on them.
- Services — work on the planning, design, development, testing, publishing and maintenance of mobile and related software products.
- AI agents — autonomous software components based on artificial intelligence models that perform individual roles in the Provider's production process.
- Specification — a document agreed by the parties that describes the scope, functionality and boundaries of the work.
- Deliverables — the source code, designs, documentation and other materials created while providing the Services.
- Milestone — a part of the work identified in the Specification that is delivered and paid for separately.
3.Scope and how we work
The Provider delivers bespoke software development services. The scope, timeline and price are set out in the Specification and quote agreed by the parties before work begins.
A project normally runs as follows:
- Brief. You describe the task; the Provider asks follow-up questions. This stage is free and commits you to nothing.
- Specification and quote. The Provider prepares a written spec, a screen map, a timeline and a fixed price. Work starts once you approve them in writing.
- Design. Approval of the prototype and screen designs. Revisions at this stage are included to the extent set out in the Specification.
- Development. Work runs in iterations; after each one you receive a test build and access to the task board.
- Testing. Automated tests and on-device checks before each milestone is delivered.
- Delivery and handover. Publishing to the app stores and handover of the source code, design files and accounts.
Timeframes shown on the website are indicative. Exact dates are fixed in the Specification and account for the time you need to supply materials and feedback.
4.Use of AI agents
You are informed of and agree that the work is carried out using AI agents. Analysis, design, coding, review, testing and release preparation are performed by automated components based on artificial intelligence models.
The Provider designs the production process, sets the rules the agents follow, checks intermediate results and performs the final review before Deliverables reach you. The Provider is responsible for the quality of the Deliverables regardless of the tools used to create them.
Quality is assured through layered controls: automated review of every code change, automated tests, on-device checks and a final review by the Provider.
The Provider chooses which tools, models and technologies to use, unless the Specification says otherwise.
You may ask which tools were used on a particular milestone.
5.Your responsibilities
- supply the materials needed for the work on time: copy, logos, data, accounts and access to third-party services;
- provide feedback and approvals within the period set out in the Specification, and in any case within 5 (five) business days of a request;
- warrant that the materials you supply do not infringe third-party rights and that you hold the rights to use them;
- pay for milestones by the agreed dates;
- appoint a contact person authorised to make decisions about the project.
Any delay by you in supplying materials or approvals extends the delivery deadline by the same number of days.
6.Price and payment
The price of the Services is agreed individually and fixed in the quote before work begins. Any indicative estimate we share on request does not constitute a binding offer.
Payment is made by milestone. The number and size of milestones are set out in the agreement; as a rule the first payment falls due once the Specification is approved, and the rest on acceptance of each milestone.
Change of scope. Requirements outside the agreed Specification are handled through an addendum with its own timeline and price. The Provider does not start such work without written approval.
Costs of third-party services required for the product to operate (store developer accounts, hosting, payment gateways, licences) are paid by you separately and are not included in the price unless the quote says otherwise.
If you stop the project, you pay for the work actually completed as at that date. Deliverables for paid milestones are handed over to you.
7.Acceptance
When a milestone is finished, the Provider delivers the result together with a notice that it is ready for acceptance.
You must review the result and send any reasoned objections within 5 (five) business days. Objections are considered insofar as they relate to compliance with the agreed Specification.
If no objections are received within that period, the milestone is deemed accepted without reservation.
Valid objections are addressed by the Provider free of charge within a reasonable time. Requests beyond the Specification are handled as a change of scope.
8.Ownership of the deliverables
Exclusive rights to the Deliverables pass to you in full once the relevant milestone is paid for. You receive the source code, the repository, the design source files and the technical documentation.
Until payment is made in full, the Deliverables remain the property of the Provider and you hold a temporary right to use them solely for testing and acceptance.
The Deliverables may include third-party libraries and components distributed under open-source licences. Those remain the property of their respective owners; a list of such components and their licences is handed over with the code.
The Provider retains a non-exclusive right to reuse general technical approaches, solutions and internal tooling developed during the project on other projects, provided your confidential information is not disclosed.
The Provider may state that the two of you worked together and publish a general description of the project and its visuals in a portfolio, unless you object in writing.
9.Warranty
The Deliverables carry a warranty of between 1 (one) and 3 (three) months depending on the package chosen. The warranty period runs from the date the final milestone is accepted.
During the warranty period the Provider fixes defects free of charge — that is, discrepancies between the Deliverables and the agreed Specification, including errors that break the functionality promised in it.
The warranty does not cover:
- new functionality or changes not set out in the Specification;
- failures caused by changes made to the delivered code by you or by third parties;
- breakage caused by changes in third-party services and APIs, or by new operating system releases;
- issues with infrastructure, hosting and accounts under your control.
Work not covered by the warranty is carried out under a separate agreement or as part of a maintenance plan.
10.Confidentiality
Each party undertakes not to disclose information received during the engagement and marked as confidential, for the term of the agreement and for 3 (three) years after it ends.
At your request we sign a separate non-disclosure agreement (NDA) before any project materials change hands.
Your confidential information may be shared with the infrastructure and AI model providers engaged by the Provider, strictly to the extent needed to perform the work and on confidentiality terms no weaker than those in this section.
The confidentiality obligation does not extend to information that is publicly available or must be disclosed at the lawful request of a competent authority.
11.Publishing to the app stores
Publishing takes place under your developer account. If you do not have one, the Provider helps you register it; the cost of the accounts is yours.
The Provider prepares builds, metadata, screenshots and privacy details in line with Apple App Store and Google Play requirements.
The app stores decide independently whether to approve an app. The Provider does not control the timing or outcome of review, but will address review findings that relate to the quality of the work free of charge.
Store requirements change over time. Work required because the rules changed after handover is carried out under a maintenance plan.
12.Liability
The Provider is responsible for the Deliverables matching the agreed Specification and for meeting the deadlines fixed in the agreement.
The Provider's aggregate liability under any claim is limited to the amount you actually paid under the relevant agreement.
The Provider is not liable for lost profit, indirect losses, or the commercial outcome of using the product: user numbers, revenue or other business metrics.
The Provider is not responsible for the availability of third-party services and APIs integrated at your request, nor for what you or third parties do with the delivered code.
The limitations in this section apply to the fullest extent permitted by applicable law and do not cover wilful misconduct.
Neither party is liable where performance is prevented by force majeure, provided the other party is notified within 10 calendar days.
13.Using the website
The content of the website — copy, design, graphics and code — belongs to the Provider and is protected by intellectual property law.
When using the website you must not: scrape data, generate excessive load, attempt unauthorised access, or copy the website's materials to build a similar resource.
The contact details published on the website are for genuine enquiries. Sending advertising or bulk messages to them is not permitted.
The website may link to third-party resources; the Provider is not responsible for their content.
14.Personal data
Personal data is processed in accordance with our Privacy Policy, which forms an integral part of these Terms.
By contacting us on WhatsApp, Instagram, Threads or by email you confirm that you have read the Privacy Policy and consent to the processing of the data you provide so that we can respond to your enquiry.
15.Changes, governing law and disputes
The Provider may amend these Terms. The current version is always published on this page with its effective date. Amendments do not apply to agreements concluded before they take effect.
These Terms are governed by the substantive law of the Provider's country of registration, excluding its conflict-of-law rules. The specific jurisdiction is named in the client agreement.
The parties will first try to settle any disagreement through a written complaint, which is considered within 30 calendar days of receipt.
If no agreement is reached, the dispute is heard by the court at the Provider's registered seat under the applicable procedural law.
If any provision of these Terms is held invalid, the remaining provisions stay in force.
16.Company details and contacts
- Name: AI App
- Legal enquiries: legal@ai.sogeking.kz
- General enquiries: hello@ai.sogeking.kz
Privacy Policy
1.General provisions
This Privacy Policy (the “Policy”) sets out how the personal data of visitors to ai.sogeking.kz and of AI App clients is processed and protected.
The data controller is AI App (the “Company”, “we”).
This Policy is drawn up in accordance with applicable data protection law.
By using the website and contacting us through messengers or by email, you confirm that you have read this Policy and consent to the processing of personal data on the terms set out in it.
2.What data we process
Data from your enquiries. Your name, phone number, messenger handle or email address, a description of the task and anything else you choose to tell us when you write to us on WhatsApp, Instagram, Threads or by email.
Correspondence and calls. The content of messages, and recordings or notes from calls where you were told in advance that the call is recorded.
Client data under a contract. Company details, information about signatories and contact persons, and payment documents.
Project materials. Files, credentials and data you hand over so the work can be done. These may contain third-party personal data — in that case you are the controller and we process it on your instructions.
Technical website data. IP address, browser and operating system type and version, referrer, date and time of the visit, and pages viewed.
We do not request special category personal data and ask you not to send it unless it is genuinely necessary.
3.Why we process it
- to respond to your enquiry and prepare an estimate and proposal;
- to enter into and perform a development agreement, including handover of the deliverables and accounts;
- to carry out project work and provide support after launch;
- to issue invoices, take payment and keep accounting and tax records;
- to protect the Company's rights and legitimate interests in the event of a dispute;
- to improve the website: anonymised traffic statistics and error diagnostics;
- to keep you informed about project status and material changes to our documents;
- to comply with applicable law.
We do not use your data for marketing mailings without separate consent, and we do not share it with advertising networks.
4.Legal bases for processing
- Your consent — for the data you provide in an enquiry and for optional cookies;
- Performance of a contract — to carry out the work, handle payment and hand over the deliverables;
- The Company's legitimate interests — to keep the website secure, prevent abuse and defend our rights in disputes;
- Legal obligations — to retain accounting records and respond to lawful requests from competent authorities.
5.Project materials and AI agents
Project work is carried out using AI agents. To make that possible, project materials — code fragments, specification text, designs — may be sent to artificial intelligence model providers and cloud infrastructure providers, only to the extent needed for the task at hand.
We use providers that do not use the data sent to them to train their models, and we sign processing agreements with them on confidentiality terms.
We do not process personal data of your product's end users taken from production databases. Development and testing use synthetic or anonymised datasets. If a task requires otherwise, the arrangement is agreed with you separately and in writing.
At your request we sign a non-disclosure agreement (NDA) before any project materials are handed over.
6.Sharing data with third parties
We do not sell personal data. It is shared only with the following categories of recipient and only to the extent necessary:
- cloud infrastructure and AI model providers — to carry out project work;
- code hosting and development services — to maintain the repository and build the apps;
- email services and messengers — to correspond with you; their own data policies apply to the messages themselves;
- banks and payment providers — to process payments;
- accounting and legal advisers — to the extent needed to support our operations;
- app stores — when the product is published, to the extent their rules require;
- competent authorities — where there is a lawful and properly issued request.
International transfers. Some of the services we use are located outside the Company's country of registration. Data is transferred only where the recipient ensures the protection of personal data and in line with applicable law. By accepting this Policy you consent to such transfers.
7.How long we keep it
- Enquiries that did not lead to a contract — 12 months from the last contact;
- Project correspondence — for the duration of the work and 3 (three) years afterwards;
- Contracts, acceptance documents and payment records — 5 (five) years, or another period required by applicable law;
- Project materials and credentials — until handover; afterwards working copies and accounts are deleted within 30 days unless a maintenance arrangement is agreed;
- Server logs — 12 months.
Once the retention period ends, the data is deleted or anonymised.
8.Security measures
We apply organisational and technical safeguards proportionate to the risks of processing:
- TLS encryption of traffic in transit;
- secrets and credentials stored in a secure password manager rather than in correspondence;
- least-privilege access control and multi-factor authentication;
- private repositories and logging of access to project materials;
- separate development and production environments, with no production data in test environments;
- regular dependency updates and checks for known vulnerabilities.
Complete security of data transmitted over the internet cannot be guaranteed. If we detect a breach that puts your rights at risk, we will notify you and the competent authority within the timeframes required by applicable law.
9.Your rights
In relation to your personal data you have the right to:
- be told what data is processed, where it came from and who it has been shared with;
- have data corrected or completed if it is incomplete, out of date or inaccurate;
- have processing restricted where you have evidence that it is unlawful;
- have data erased where it is processed in breach of the law;
- withdraw consent you have previously given;
- receive a copy of your data in a machine-readable format;
- complain about the Company's actions to the competent data protection authority or in court.
To exercise these rights, write to privacy@ai.sogeking.kz. We will review your request and respond within 10 (ten) business days, and will tell you if extra checks mean we need longer.
Withdrawing consent for data needed to perform a contract makes it impossible to continue providing the services and ends the work.
10.Cookies and analytics
The website uses a minimal set of technologies:
- strictly necessary — needed for pages to work at all; used without consent because the site does not function without them;
- analytics — anonymised traffic statistics: which pages are viewed and where visitors come from.
Optional categories are enabled only after you consent. Declining them does not affect access to the site's content. You can change the settings in your browser at any time, including blocking cookies entirely.
We do not use advertising pixels and do not share visit data with advertising networks.
11.Children's data
The website and the services are not intended for children. We do not knowingly collect personal data from anyone under 16.
If you become aware that a child has given us data, write to privacy@ai.sogeking.kz and we will delete it as soon as possible.
12.Changes to this Policy
We may update this Policy. The current version is always published on this page with its effective date.
We will notify active clients by email at least 15 calendar days before any material change to the data we process or the purposes of processing takes effect.
13.Contacts
For anything to do with the processing of personal data, get in touch:
- Controller: AI App
- Data protection enquiries: privacy@ai.sogeking.kz
- General enquiries: hello@ai.sogeking.kz
You also have the right to lodge a complaint with the competent data protection authority.