Build, connect, and automate intelligent AI Agents across your business — from conversations to real-world actions.

AISYA is a platform for building AI Agents that understand context, leverage knowledge, access data, execute functions, and take real business actions.
Knowledge, RAG, and conversation context — your agent comprehends what matters.
APIs, functions, data sources, and integrations — connect every business system.
Execute functions, workflows, and business actions — beyond just answering questions.
Automated workflows, sequences, and follow-ups — keep operations running.
A visual agent configuration environment — system prompts, model selection, functions, knowledge, and channel settings in one workspace.
Connect business knowledge and documentation directly into your AI Agent.
Agents retrieve relevant information before responding — grounded, accurate answers.
Maintain relevant conversation context across interactions.
Support for multiple AI model providers within a single platform.
AISYA AI Agents use functions to interact with business systems and execute real actions.
Define functions the agent can invoke to interact with your systems.
Structured function calling with parameter validation.
Connect to any HTTP API, internal or external.
Webhooks and Model Context Protocol as advanced integration capabilities.
Visual Flow Builder with conditional branching, multi-step logic, delays, AI processing, API calls, calculations, and chained actions.
Deploy the same AI Agent configuration across all customer-facing channels.
Unified inbox where AI and human agents operate together in a single environment.
CRM capabilities built around AI-powered customer interactions.
Structure customer data the way your business works.
Capture, track, and move customers through your workflow.
Complete profiles tied to every conversation.
Full history across every channel, searchable.
Trigger workflows from new contacts, form submissions, or conversation events.
Multi-step sequences with scheduled follow-ups.
Pipeline changes, custom field updates, and recurring loops.
Actions tied to customer data and behavior.
Structured access and permissions across your organization.
One inbox, many agents — AI and human together.
Manual or round-robin assignment across your team.
Granular control over who sees what.
Where enterprise teams deploy AISYA today.
AI handles customer questions and support, with human escalation when needed.
Lead qualification and follow-up across every channel.
Campaigns and conversational engagement at scale.
Workflow automation and API-driven actions.
AI-assisted booking and scheduling integrated with your systems.
Internal and external knowledge access — for employees and customers.
Connect AI to existing business systems and infrastructure.
AI-powered engagement across social channels.
AISYA is not a chatbot. It is the intelligence layer between your business, your systems, and your customers.
We take data handling seriously. Read our full commitments.
Start the conversation with our team — or begin building in the platform.
How AISYA collects, uses, and protects personal data.
AISYA ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, in compliance with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.
AISYA acts as the data controller for personal data collected through our services. For questions about data protection, contact our Data Protection Officer:
We process your personal data based on the following legal grounds:
We collect information when you:
The information we collect may include:
We use your information to:
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
AISYA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data we read from Google APIs (Calendar, Sheets, Docs, Drive, Gmail) is used solely to provide the user-facing feature you enabled, is never used to train generalized AI/ML models, is never sold, and is never transferred to third parties for unrelated purposes.
AI provider segregation: We enforce technical isolation so that data obtained from Google APIs is never sent to AI providers whose terms permit training on submitted content (currently DeepSeek). Widgets that read from a Google API must use an OpenAI, Anthropic Claude, or Google Gemini key — providers whose enterprise terms forbid training on API-submitted content. See our Limited Use Disclosure for full details.
We engage the service providers below to process personal data on our behalf. Some are used for every account; others are engaged only when you enable the related feature — for example a specific AI model, a messaging channel, or voice calling.
The provider(s) that receive conversation content depend on the AI model you select for your agent:
Training-data note: The primary AI providers above (including OpenAI, Anthropic and Google) do not train their models on data submitted through their business/API terms. DeepSeek, which is based in China, may operate under terms that permit training on submitted content; as described in our Google API section, data we read from Google APIs is technically prevented from being sent to DeepSeek. If you require that participant data is never used for model training, select an OpenAI, Anthropic or Google model for your agent.
Certain optional content- and code-generation features (for example, landing-page generation) can use additional AI providers, but only when your account supplies its own API key for that provider. That use is governed by your own agreement with the provider, is not part of your AI agent conversations, and does not receive data read from Google APIs.
Engaged only for the channels you connect:
All our sub-processors are engaged under data-processing terms that require them to protect your data and comply with applicable data protection laws. We do not sell your personal data. This list may change as we add or remove providers; the current version is always published on this page.
Your data is primarily processed in the United States. Depending on the AI models and channels you enable, some data may also be processed by providers located outside the US and the European Economic Area (EEA) — including, for certain optional AI models, providers in China (see the sub-processor list above). For transfers from the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, together with the provider-selection controls described above, to ensure an adequate level of protection.
We use cookies and similar technologies to enhance your experience.
If you are located in the EEA or UK, you have the following rights:
To exercise any of these rights, please contact us at aisya@aisya.id or use the data export feature in your account settings.
California residents have additional rights including:
We do not sell your personal information to third parties.
We implement appropriate technical and organizational security measures to protect your information, including:
However, no method of transmission over the Internet or electronic storage is 100% secure. In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours as required by GDPR.
Our AI-powered services may involve automated processing, but we do not make decisions that significantly affect you based solely on automated processing. You have the right to request human intervention for any AI-related decisions.
Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we discover that we have collected data from a child under 16, we will delete it promptly.
We may update our Privacy Policy from time to time. We will notify you of material changes by email and by posting the new Privacy Policy on this page with an updated "Last updated" date. We encourage you to review this page periodically.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
For complaints, you may also contact your local data protection supervisory authority.
Terms governing the use of the AISYA Platform.
By accessing or using AISYA, you agree to be bound by these Terms of Service and our Privacy Policy. If you disagree with any part of the terms, you may not access the service.
AISYA offers a subscription-based service with a 7-day free trial. After the trial period, your payment method will be charged the subscription fee unless you cancel before the trial ends.
You are responsible for all charges incurred under your account. We use Stripe for payment processing and do not store your full credit card information on our servers.
Subscription fees are non-refundable. You may cancel your subscription at any time, and you will continue to have access to the service through the end of your billing period.
All pricing is subject to change at any time at the sole discretion of AISYA. Continued use of the service following any pricing change constitutes acceptance of the updated pricing. AI agent accounts that exceed 1,000 messages per calendar month may be subject to additional usage-based charges.
You must register for an account to use AISYA. You agree to provide accurate and complete information and to keep your account information updated. You are responsible for maintaining the security of your account and password.
You agree not to use AISYA for any illegal purposes or to conduct any unlawful activity, including but not limited to:
If you use our service to collect or process personal data of your customers or end users, you acknowledge that:
AISYA and its content, features, and functionality are owned by PT Cendrawasih Empower Teknologi. and are protected by international copyright, trademark, patent, trade secret, and other intellectual property laws.
You retain ownership of any content you create, upload, or share through AISYA. By providing content, you grant us a worldwide, non-exclusive, royalty-free license to use, reproduce, modify, adapt, publish, translate, and distribute your content in connection with the service.
We may terminate or suspend your account and access to the service without prior notice or liability for any reason, including breach of these Terms. Upon termination, your right to use the service will immediately cease.
You may terminate your account at any time by contacting us or using the account deletion feature in your settings. Upon account deletion, we will delete or anonymize your personal data in accordance with our Privacy Policy.
In no event shall PT Cendrawasih Empower Teknologi, its officers, directors, employees, or agents, be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or relating to your use of or inability to use the service.
You agree to indemnify and hold harmless PT Cendrawasih Empower Teknologi from any claims, damages, or expenses arising from your violation of these Terms or your use of the service.
We reserve the right to modify these terms at any time. We will provide notice of significant changes by email and by posting the new Terms on our website with an updated "Last updated" date. Your continued use of the service after changes constitutes acceptance of the new terms.
These Terms shall be governed by the laws of the United States and the State of South Carolina, without regard to conflict of law provisions.
When you connect a Google account (Calendar, Sheets, Docs, Drive, or Gmail), AISYA handles the data received from Google APIs in compliance with the Google API Services User Data Policy and its Limited Use requirements. We do not use Google User Data to train generalized AI models, do not sell it, and do not transfer it to advertisers. Widgets that read from a Google API are technically restricted from being served by our DeepSeek platform fallback. See our Limited Use Disclosure for the full statement and our Privacy Policy for data handling details.
Our platform provides SMS messaging capabilities using a shared phone number. Each account receives a limited number of free platform SMS messages per month. Once free messages are exhausted, additional SMS credit packs may be purchased. SMS credits are non-refundable and paid credits do not expire. Free monthly credits reset at the beginning of each calendar month and unused free credits do not roll over.
Users who connect their own Twilio credentials and phone numbers are not subject to platform SMS metering or charges. Platform SMS is provided on a best-effort basis and we do not guarantee message delivery. Standard carrier messaging rates may apply to recipients.
Any disputes arising from these Terms or your use of the service will first be attempted to be resolved through good-faith negotiation. If a resolution cannot be reached, disputes will be resolved through binding arbitration in accordance with the rules of the American Arbitration Association.
If you have questions about these Terms, please contact us:
Our approach to responsible data processing, Google API usage, and contractual data protection.
Last updated: May 28, 2026
AISYA use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account to AISYA (Google Calendar, Google Sheets, Google Docs, Google Drive, or Gmail), the data we read from those Google APIs is used only to provide the user-facing feature you enabled — for example, showing your real-time calendar availability to a booking visitor, populating a webshop catalog from a linked spreadsheet, or using a Google Doc as the system prompt for your AI agent.
We do not:
AISYA supports multiple AI providers (OpenAI, Anthropic Claude, Google Gemini, xAI Grok, DeepSeek, Groq). Because some third-party AI providers reserve the right to use submitted content to train their general models, we enforce strict data segregation:
https://www.googleapis.com/auth/calendar — to list calendars, check free/busy availability, and create booking events on your behalf for the Calendar Booking feature.https://www.googleapis.com/auth/calendar.events — to read and write calendar events for the bookings you create.https://www.googleapis.com/auth/spreadsheets — to read product catalogs, data sources, and write conversation/contact data to spreadsheets you select.https://www.googleapis.com/auth/drive.file — to access only the specific Google Docs / Sheets files you pick using the Google Picker.https://www.googleapis.com/auth/userinfo.email and userinfo.profile — to show which Google account is connected.OAuth tokens are stored encrypted at rest. You can revoke AISYA's access at any time from your account settings (disconnect button) or directly via your Google Account permissions page. Revocation immediately invalidates our tokens and stops all further reads. Cached data fetched from Google APIs (e.g., short-TTL spreadsheet caches) is purged within 10 minutes of revocation.
For questions about how we handle Google User Data, contact us at aisya@aisya.id, or see our Privacy Policy and Terms of Service.
Last updated: July 23, 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement") between AISYA ("Processor", "we", "our", or "us") and the customer that uses our services (the "Customer", "Controller", or "you"). It governs how we process personal data on your behalf in connection with the services, and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and comparable data protection laws.
Where you use our platform to communicate with your own customers, contacts, and end users, you act as the Controller of their personal data and we act as your Processor. This DPA should be read together with our Privacy Policy (which contains our current sub-processor list) and our Terms of Service. If there is a conflict between this DPA and the Agreement in respect of data protection, this DPA prevails.
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given to them in applicable data protection law. "Applicable Data Protection Law" means all laws and regulations relating to the processing of personal data that apply to a party, including the GDPR, the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), as amended.
For personal data you submit to or collect through the services (for example, your contacts and the content of conversations with them), you are the Controller and we are the Processor acting on your documented instructions. For personal data relating to your own account (such as your billing and login information), we act as an independent Controller as described in our Privacy Policy.
We process personal data only to provide, maintain, secure, and support the services, and as further described in Annex A. The details of the processing are:
In accordance with Article 28(3) GDPR, we will:
You are responsible for establishing a lawful basis for the processing, for providing any required notices to and obtaining any required consents from data subjects, and for ensuring your instructions to us comply with Applicable Data Protection Law. You must not use the services to process special categories of data or children's data except as permitted by law and with appropriate safeguards.
We implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as further described in Annex B. These include, at minimum:
You provide general authorization for us to engage sub-processors to process personal data in connection with the services. Our current sub-processors, the purpose for which each is engaged, and their processing location are listed in the "Third-Party Service Providers (Sub-Processors)" section of our Privacy Policy, which forms Annex C to this DPA.
We impose data protection obligations on each sub-processor that are substantially the same as those set out in this DPA. We remain responsible for the performance of our sub-processors. We will provide notice of any intended addition or replacement of a sub-processor by updating the list in our Privacy Policy, and you may object on reasonable data protection grounds by contacting us using the details in Section 13.
Personal data is primarily processed in the United States. Depending on the AI models and channels you enable, some data may be processed by sub-processors located outside the United States and the European Economic Area (EEA). Where personal data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, such transfers are made subject to the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with the provider-selection controls described in our Privacy Policy.
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights (including access, rectification, erasure, restriction, portability, and objection). Where a data subject contacts us directly regarding data we process on your behalf, we will promptly forward the request to you and will not respond directly except to confirm that the request has been forwarded, unless legally required to do so.
We will make available to you the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. Upon reasonable prior written request, and subject to confidentiality obligations, we will contribute to audits or inspections conducted by you or an independent auditor mandated by you, no more than once per year (except where required by a supervisory authority or following a personal data breach). Access to customer accounts by our support and administrative personnel is logged and available to you on request for the applicable log-retention period.
Upon termination or expiry of the services, or upon your written request, we will delete or return personal data processed on your behalf. Account data is deleted within 30 days of a deletion request or termination, except where retention is required by law — for example, payment and transaction records retained for tax and accounting purposes (currently up to 7 years) and anonymized analytics. These retention periods are described in more detail in our Privacy Policy.
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and in any event within seventy-two (72) hours where feasible. Our notification will describe, to the extent known, the nature of the breach, the likely consequences, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to address it. We will reasonably cooperate with you and take reasonable steps to mitigate the effects of the breach.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law.
This DPA takes effect on the date you accept the Agreement or first use the services and remains in force for as long as we process personal data on your behalf. It is governed by the same governing law and jurisdiction as the Agreement, except where Applicable Data Protection Law requires otherwise. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect. We may update this DPA to reflect changes in law or our processing; the current version will always be published on this page with an updated "Last updated" date.
For any questions about this DPA, to exercise controller rights, or to request a signed copy, please contact:
As described in Section 3, to operate the multi-channel messaging, AI, payment, scheduling, and analytics features you enable.
We maintain measures that include, without limitation:
The list of current sub-processors, the service each provides, and its processing location is maintained in the "Third-Party Service Providers (Sub-Processors)" section of our Privacy Policy and is incorporated into this DPA by reference.
PT Cendrawasih Empower Teknologi is committed to responsible handling of personal data processed through the AISYA Platform. We approach data protection as a core operational responsibility, not a marketing claim.
Our approach to personal data processing takes into account the applicable legal framework in Indonesia, including:
Compliance with UU PDP is treated as an evolving obligation that we take seriously and address through operational and contractual measures.
Our approach to processing is guided by core principles, including:
The roles of the parties involved in data processing depend on the contractual relationship and the actual processing activity. In a typical enterprise deployment:
The precise allocation of roles and responsibilities is defined in the applicable customer agreement and in our Data Processing Agreement.
Customers are responsible for ensuring that data entered into the Platform has an appropriate legal basis for processing and that any necessary notices, consents, or other obligations have been fulfilled in relation to the relevant data subjects.
Data subjects have rights under applicable law, including rights recognized under UU PDP. Mechanisms for exercising these rights are typically coordinated with the relevant data controller (often the customer). We support customers in handling valid data subject requests processed through the Platform.
We implement technical and organizational controls appropriate to the nature of the Platform and the data processed. Specific controls deployed are described in our Privacy Policy (Annex B of our DPA) and customer agreements.
Data is retained for the period necessary to fulfill the purposes for which it was processed, in accordance with customer agreements and applicable legal obligations. Specific retention periods are defined in our Privacy Policy and the applicable customer agreement.
The AISYA Platform may use third-party AI, model, and integration providers in accordance with the customer's configuration and the applicable agreement. How such providers process data is governed by their respective terms and the contractual arrangements in place.
Where processing involves transfer of personal data outside Indonesia, mechanisms used are those actually implemented and documented in the applicable customer agreement, including Standard Contractual Clauses where required.
We maintain internal procedures for handling data security incidents, aligned with our obligations under applicable law and our contractual commitments to customers. Notification timelines and procedures are described in our DPA.
For data privacy and protection inquiries: