Acceptable Use Policy

Nexwift

About Nexwift Saudi AI company Aram contact Nexwift Careers at Nexwift blog
Acceptable Use Policy

Acceptable Use Policy

Field Value
Document ID NXW-PUB-ACCEPTABLE-USE-POLICY
Version 1.0
Issue Date 2026-01-01
Next Review 2027-01-01
Owner Chief Information Security Officer
Classification Public

1. Purpose and Scope

This Acceptable Use Policy ("AUP") sets out the conduct that Nexwift requires from every customer, authorised user, and beneficiary who interacts with the Aram platform ("Platform") across text, voice, and video channels. It applies to all deployments, environments, and integrations offered by Nexwift, and supplements the Master Services Agreement, the Data Processing Agreement, and any Order Form or Statement of Work executed between Nexwift and the customer.

Use of the Platform constitutes acceptance of this AUP. Where the customer permits third parties (employees, contractors, or beneficiaries) to interact with the Platform, the customer remains responsible for those parties' compliance with this AUP.

2. Governing Law

This AUP is governed by the laws of the Kingdom of Saudi Arabia, including without limitation the Personal Data Protection Law, the Anti-Cyber Crime Law, the Anti-Commercial Fraud Law, and any regulations, decisions, or guidance issued by the competent Saudi authorities. Any dispute arising out of or in connection with this AUP shall be submitted to the competent Saudi courts and authorities.

3. General Prohibited Uses

The following uses are strictly prohibited across all channels (text, voice, and video):

# Prohibited Use Description
3.1 Unlawful conduct Any use that violates the laws of the Kingdom of Saudi Arabia, the Personal Data Protection Law (PDPL), or the applicable laws of any jurisdiction from which the customer operates or into which content is directed.
3.2 Intellectual property infringement Uploading, transmitting, or generating content that infringes copyrights, trademarks, patents, trade secrets, or other proprietary rights of any third party.
3.3 Defamation Publishing or distributing content that is defamatory, libellous, or that unlawfully damages the reputation of any natural or legal person.
3.4 Harassment and hate speech Content that harasses, threatens, intimidates, or promotes hatred or discrimination against any individual or group on any protected basis.
3.5 Sexually explicit or gratuitously violent content Generation, storage, or transmission of pornographic, sexually explicit, or gratuitously violent content.
3.6 Exploitation of minors Any content or conduct that sexualises, exploits, endangers, or otherwise harms minors. This category is subject to zero tolerance and mandatory reporting where legally required.
3.7 Deception of beneficiaries Deceiving beneficiaries as to the nature of the interaction, the identity of the operator, or material facts affecting the beneficiary's decision. Beneficiaries must be able to understand, in context, that they may be interacting with an AI-assisted system, in accordance with the customer's disclosure obligations.
3.8 Impersonation of officials Impersonation of government officials, public authorities, judicial bodies, security forces, or of Nexwift personnel, in each case without lawful authorisation.
3.9 Spam and unsolicited messaging Sending mass unsolicited messages, chain messages, unsolicited commercial communications, or otherwise using the Platform contrary to applicable anti-spam and telemarketing rules.
3.10 Phishing and fraud Using the Platform to conduct phishing, social engineering, financial fraud, identity theft, or any other deceptive practice designed to obtain data, credentials, or funds without authorisation.
3.11 Malware distribution Uploading, transmitting, or linking to malware, ransomware, spyware, or any code designed to disrupt, damage, or gain unauthorised access to any system.
3.12 Circumvention of controls Circumventing or attempting to circumvent security controls, authentication, rate limits, quotas, guardrails, moderation systems, or any other technical or contractual restriction imposed by Nexwift.
3.13 Competitive AI development Using the Platform, the outputs of Aram agents, or any Nexwift-provided model artefacts to train, fine-tune, benchmark, or otherwise develop a competing artificial intelligence or conversational service.
3.14 Unauthorised security testing Conducting penetration testing, vulnerability scanning, load or stress testing, denial-of-service testing, or any other security research against the Platform without Nexwift's prior written authorisation and a mutually agreed rules-of-engagement document.
3.15 Automated scraping and harvesting Systematic scraping, harvesting, or bulk extraction of Platform content, beneficiary data, agent outputs, or knowledge-base material by any automated means outside the interfaces expressly provided for that purpose.
3.16 Reverse engineering Reverse engineering, decompiling, disassembling, or attempting to derive the source code, model weights, prompts, or underlying architecture of the Platform, except to the minimum extent expressly permitted by applicable mandatory law.
3.17 Sanctions and export controls Using the Platform in violation of applicable trade-sanctions, export-control, or embargo regimes, or making the Platform available to any person or entity subject to such measures.
3.18 Minors as end users Deploying the Platform in a manner that directs Aram agents at children below the age of majority in the relevant jurisdiction without an appropriate lawful basis, parental-consent mechanism, and age-appropriate safeguards documented by the customer.

4. Voice-Channel Specific Rules

The voice channel enables outbound and inbound calling and is subject to the additional rules below.

  • Authorisation for auto-dialling. Automated dialling, predictive dialling, or campaign-style outbound calling is permitted only within the scope authorised in writing by the customer's compliance function and only where the underlying telephony authorisation and beneficiary consent bases are documented.
  • Prohibition on scam robocalling. Robocalling for scam, fraud, or unlawful commercial purposes is strictly prohibited. Customers must maintain do-not-call suppression lists appropriate to their jurisdiction.
  • Recording and notice. Voice-call recording is an optional, customer-configurable capability. Where the customer enables recording, the customer is solely responsible for providing beneficiaries with the notices and, where required, obtaining the consents mandated by applicable law prior to the recording taking place. Nexwift processes recordings on the customer's documented instructions only.
  • Emergency services. The Aram voice agent is not, and must not be represented as, an emergency service. Customers must not deploy the voice agent as a substitute for emergency response.

5. Video-Channel Specific Rules

The video channel supports interactive audio-video sessions between beneficiaries and Aram video agents.

  • No unlawful surveillance. The video channel must not be used to conduct covert surveillance, unlawful monitoring, biometric identification without lawful basis, or any activity prohibited by KSA law or applicable local law.
  • Capture requires notice. Video capture (still images, video recordings, or transcripts) is optional and customer-configurable. Where enabled, the customer is solely responsible for informing beneficiaries in advance and obtaining any consent required by applicable law.
  • Ownership of recordings. Consistent with the Master Services Agreement, the customer owns customer data and configurations, the customer knowledge base, and any transcripts, recordings, and summaries derived from the customer's use of the service. Nexwift retains ownership of the Platform, the underlying models, and aggregated telemetry.

6. AI-Use Safety Rules

The Platform relies on managed AI inference providers. AI-generated outputs are inherently probabilistic and may be inaccurate, incomplete, out-of-date, or biased; no reliance should be placed on such outputs for any decision that has legal, financial, medical, safety, or other material consequences for a beneficiary without independent human review by suitably qualified personnel.

Customers must not deploy Aram agents to deliver medical advice, legal advice, financial or investment advice, or any other regulated professional advice to beneficiaries, and must not represent AI-generated outputs as the advice of a licensed professional. AI-generated outputs are advisory only. Customers are solely responsible for configuring the guardrails, sensitive-topic handling, disclosure notices, and human-in-the-loop review appropriate to their use case, and for validating outputs prior to any action being taken on the basis of them.

The Platform must not be used to make fully-automated decisions that produce legal or similarly significant effects on beneficiaries without a lawful basis under applicable data-protection law and without providing beneficiaries with the safeguards required by that law (including, where applicable, the right to obtain human intervention, to express a point of view, and to contest the decision).

7. Enforcement

Nexwift monitors the Platform on a commercially reasonable basis for compliance with this AUP. Where a suspected breach is identified, Nexwift may, at its sole discretion and having regard to the severity, recurrence, and risk posed to third parties, take any of the following actions:

Measure Description
Warning Written notice to the customer's administrative contact identifying the suspected breach and the remedial action required.
Throttling Temporary reduction of rate limits, concurrent sessions, or feature availability while the matter is investigated.
Suspension Suspension of all or part of the affected service without prior notice where continued operation presents a security, legal, or reputational risk.
Termination Termination of the affected service or the entire agreement in accordance with the Master Services Agreement.

Nexwift will use commercially reasonable efforts to notify the customer of any enforcement action without undue delay, except where prior notice would frustrate the purpose of the action, breach a legal obligation, or expose Nexwift, the customer, or a third party to further risk.

A material breach of this AUP, including any breach falling within sections 3.6, 3.10, 3.11, 3.12, 3.13, 3.14, 3.16, or 3.17, or any repeated breach following a warning, shall constitute a material breach of the Master Services Agreement and entitle Nexwift to terminate the affected service with immediate effect and without any refund of prepaid fees.

8. Reporting to Authorities

Where legally required or where Nexwift reasonably believes that reporting is necessary to prevent imminent harm, Nexwift reserves the right to report suspected breaches of this AUP to the competent authorities in the Kingdom of Saudi Arabia or in any other jurisdiction whose law applies, and to disclose to those authorities the minimum information required to comply with the applicable legal obligation.

9. Customer Indemnity

The customer shall indemnify, defend, and hold harmless Nexwift, its affiliates, and their respective personnel from and against any third-party claims, actions, proceedings, losses, damages, fines, costs, and expenses (including reasonable legal fees) arising out of, or in connection with, any breach of this AUP by the customer, its authorised users, its contractors, or any beneficiary acting under the customer's direction or on the customer's channels. This clause survives termination of the Master Services Agreement.

10. Reporting Channel

Suspected breaches of this AUP, abuse of the Platform, or other concerns may be reported to Nexwift at info@nexwift.com. Reports concerning personal data, privacy, or PDPL matters should be addressed to the Data Protection Officer at the same address (attention: Data Protection Officer). Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.

11. Amendments

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.

12. Contact

Purpose Address
General enquiries and AUP reports info@nexwift.com
Data protection matters info@nexwift.com (attention: Data Protection Officer)
Security incidents info@nexwift.com (attention: Chief Information Security Officer)







 

Terms of Service

FieldValue
Document IDNXW-PUB-TERMS-OF-SERVICE
Version1.0
Issue Date2026-01-01
Next Review2027-01-01
OwnerChief Executive Officer
ClassificationPublic

These Terms of Service (“Terms“) govern access to and use of the Aram AI Agent Platform (“Aram“, the “Service“) provided by Nexwift (“Nexwift“, “we“, “us“). By ordering, activating, or using the Service, the customer (“Customer“, “you“) agrees to these Terms. Where a signed Master Services Agreement, Order Form, Data Processing Agreement, or Service Level Agreement is in place between Nexwift and the Customer (together, the “Master Agreement“), those documents prevail over any conflicting provision below.

The Service covers text, voice, and video AI-agent interactions across the channels a Customer chooses to enable.

1. Definitions

TermMeaning
Aram / ServiceNexwift’s multi-channel AI agent platform including agent configuration, knowledge-base tooling, conversation orchestration, voice and video agents, and the supervision dashboard.
Customer DataAll content and configurations submitted to or generated within the Service on the Customer’s behalf, including knowledge-base sources, prompts and playbooks, conversation transcripts, call recordings and derived summaries, and end-user (beneficiary) records.
BeneficiaryA natural person interacting with an Aram agent through a Customer-owned channel (chat, messaging, telephony, or WebRTC video).
Master AgreementThe signed Master Services Agreement, Order Form, Data Processing Agreement, Service Level Agreement, and any accepted policies referenced therein.
AUPThe Acceptable Use Policy published on the Nexwift Trust Center.
DocumentationThe user, administrator, and API documentation published or made available by Nexwift for the Service.

2. Account

The Customer is responsible for the accuracy of registration information, for maintaining the confidentiality of administrator credentials, for enforcing multi-factor authentication on privileged users, and for all activity conducted under its accounts. The Customer must notify Nexwift without undue delay of any suspected credential compromise or unauthorized use.

3. Subscription, Renewal, and Evaluation Period

3.1. Subscriptions run for the term stated on the Order Form and renew automatically for successive terms of equal length unless either party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term.

3.2. Where an Order Form provides an evaluation period, that period commences on the date the Service is first activated in the Customer’s live environment (not on contract signature or provisioning start), unless expressly stated otherwise on the Order Form.

3.3. Continued use of the Service after the evaluation period constitutes acceptance of the standing subscription and applicable fees.

4. Fees, Usage Measurement, and Payment

4.1. Fees, billing cycles, and included quantities (agents, conversations, minutes, storage, and channel volumes as applicable) are set out in the Order Form. Usage is metered by Nexwift from platform telemetry and rounded per the metrics table published in the Documentation.

4.2. Invoices are payable in accordance with the Master Agreement. Amounts not disputed in good faith and unpaid past their due date may accrue interest at the maximum rate permitted by applicable law and may trigger suspension under Section 15.

4.3. Fees are exclusive of value-added tax and other applicable duties, which the Customer bears.

5. Customer Responsibilities

The Customer is responsible for:

  • Configuring agents, playbooks, and channel connections in line with its legal, sectoral, and regulatory obligations;
  • Obtaining and maintaining all beneficiary consents required by applicable law for AI interaction, message exchange, call handling, and, where enabled, recording of voice and video sessions and generation of transcripts and summaries;
  • Providing the required disclosures to beneficiaries that they are interacting with an AI agent;
  • Ensuring the lawful basis for all personal data submitted to or processed via the Service;
  • Managing user accounts, role assignments, and offboarding of its personnel;
  • Reviewing outputs of AI-generated public replies where the deployment model requires human approval;
  • Monitoring its own use for compliance with the AUP.

6. Nexwift Responsibilities

Nexwift will use commercially reasonable efforts to:

  • Provide the Service in accordance with the Documentation and the Master Agreement;
  • Maintain the technical and organizational security measures described in the Nexwift Information Security Policy summary published on the Trust Center;
  • Notify the Customer of security incidents affecting Customer Data without undue delay in line with the Data Processing Agreement;
  • Provide advance notice of material sub-processor changes on a categorical basis as described in the Sub-processor Policy.

Availability commitments and service credits (if any) are set exclusively in the Service Level Agreement. Service credits, where offered, are the Customer’s sole financial remedy for availability shortfalls, without prejudice to termination rights for sustained material breach.

7. AI Output Disclaimer

7.1. Aram uses generative and retrieval-augmented AI models. Outputs are probabilistic and may contain errors, omissions, or content that does not reflect Customer intent. Aram outputs are advisory and informational only. They do not constitute, and must not be presented to beneficiaries as, medical, legal, or financial advice.

7.2. Voice and video AI agents are not emergency services. They must not be used, and must not be represented to beneficiaries as available, for life-safety, medical emergency, law-enforcement, or similar time-critical events. The Customer must configure appropriate escalation and fall-back paths to human operators or public emergency services.

7.3. Where recording, transcription, or summarization is enabled, the Customer remains responsible for informing beneficiaries and obtaining any legally required consent before the interaction proceeds.

7.4. High-risk and safety-critical uses excluded. The Service is not designed, tested, or certified for use in environments where failure could lead to death, personal injury, or severe environmental or property damage, including nuclear facilities, aircraft or air-traffic control, medical devices or life-support systems, autonomous vehicle control, industrial safety systems, or critical infrastructure operation. The Customer will not deploy the Service in such contexts.

7.5. No warranty of intellectual-property protection over AI outputs. The copyright, patent, and other intellectual-property status of AI-generated content varies by jurisdiction and may be uncertain or unavailable. Nexwift makes no representation that AI outputs are protectable by intellectual-property rights in any jurisdiction and does not warrant that outputs are non-infringing. As between the parties, ownership is allocated under Section 10.

8. Acceptable Use; Third-Party Terms

8.1. Acceptable Use. The Customer, its users, and its beneficiaries must comply with the Acceptable Use Policy published on the Nexwift Trust Center. Violation is grounds for suspension or termination under Sections 15 and 16.

8.2. Third-party channels and platforms. The Service integrates with third-party messaging, telephony, media-transport, and other platforms selected or connected by the Customer. The Customer is solely responsible for reading, accepting, and complying with the terms of service, developer policies, community standards, template and content policies, quality ratings, and rate limits of every such platform, and for any account, application, or channel identifier that the Customer registers or connects. Suspensions, deprecations, quality-rating downgrades, throttles, or policy actions imposed by any such platform are outside Nexwift’s control and are excluded from availability commitments.

9. Data Protection and Privacy

Nexwift processes personal data on the Customer’s behalf under the Data Processing Agreement, which reflects the Kingdom of Saudi Arabia’s Personal Data Protection Law. The Nexwift Privacy Policy published on the Trust Center describes personal data processed by Nexwift as a controller for its own operational purposes.

10. Data Ownership

10.1. The Customer owns all Customer Data, including its knowledge-base content, agent configurations, prompts, conversation transcripts, call and video recordings (where enabled), and derived summaries produced for the Customer.

10.2. Nexwift owns the Service and all associated intellectual property, including the platform software, agent orchestration logic, evaluation and analytics logic, embedded prompt scaffolding, and aggregated, de-identified operational telemetry used to operate, secure, and improve the Service.

11. Intellectual Property; Licenses

11.1. Nexwift grants the Customer, for the term of the subscription, a non-exclusive, non-transferable, non-sublicensable, revocable, limited license to access and use the Service and Documentation for its internal business purposes, subject to these Terms and the Master Agreement.

11.2. The Customer grants Nexwift a limited, worldwide, royalty-free right to host, process, transmit, display, and create derivative representations of Customer Data solely as required to provide, secure, and support the Service. Nexwift may use aggregated, de-identified telemetry to operate, secure, benchmark, and improve the Service.

11.3. No rights are granted by implication, estoppel, or otherwise. The Customer will not reverse-engineer, decompile, benchmark for competitive purposes, resell, or create derivative works of the Service except as expressly permitted by law.

11.4. Feedback. If the Customer or any of its personnel provides suggestions, ideas, feature requests, or other feedback about the Service (“Feedback“), Nexwift may use that Feedback for any purpose, without obligation, attribution, or restriction. Feedback is not treated as the Customer’s confidential information unless expressly marked as confidential in writing at the time of disclosure.

11.5. No competing use of outputs. The Customer will not, and will not permit any third party to, use outputs, telemetry, prompts, or Documentation of the Service to train, fine-tune, evaluate, or develop any AI model, product, or service that competes with the Service, nor to circumvent metering, safety, rate-limit, or abuse controls.

12. Confidentiality

Each party will protect the other’s non-public information disclosed under or in connection with these Terms with at least the degree of care it uses for its own confidential information, and never less than a reasonable standard. If a party is legally compelled to disclose the other’s confidential information, it will, unless legally prohibited, give prompt notice and disclose only the minimum required.

13. Warranties and Disclaimers

13.1. Each party warrants that it has the authority to enter into these Terms.

13.2. Except as expressly stated in the Master Agreement, the Service is provided “as is” and “as available”. To the maximum extent permitted by law, Nexwift disclaims all other warranties, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy of AI-generated outputs, and uninterrupted or error-free operation.

13.3. Beta, preview, and experimental features. Nexwift may designate certain features as “beta”, “preview”, “early access”, “alpha”, or “experimental” (“Preview Features“). Preview Features are provided free of any availability, support, or performance commitment, are excluded from any Service Level Agreement and service-credit remedy, may be modified, deprecated, or withdrawn at any time without notice, and may be more likely than the general Service to contain defects. The Customer’s use of Preview Features is at its sole discretion and risk.

14. Liability, Indemnity, Force Majeure

14.1. Each party’s aggregate liability arising out of or related to these Terms is capped as set out in the Master Agreement. In the absence of a specific figure, liability is limited to the fees paid by the Customer for the Service in the twelve (12) months preceding the event giving rise to liability.

14.2. Neither party is liable for indirect, incidental, consequential, special, punitive, or exemplary damages, or for loss of profits, revenue, goodwill, or data, even if advised of the possibility.

14.3. Any indemnity obligations are those expressly stated in the Master Agreement and are subject to the liability cap in Section 14.1, save for exclusions required by mandatory law.

14.4. Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including natural events, war, terrorism, civil disturbance, labor action, government action, cyber-attacks not attributable to its negligence, and outages of third-party networks, platforms, or providers (“force majeure“). Outages of third-party messaging channels, telephony carriers, WebRTC transport, AI inference providers, mapping providers, and other upstream services are outside Nexwift’s control and are excluded from availability commitments.

15. Suspension

Nexwift may suspend the Service or any part of it, in whole or in part, on notice appropriate to the circumstances (including immediate notice for security-critical matters), where:

  • The Customer is in material breach of these Terms, the AUP, or the Master Agreement and has not cured within any applicable cure period;
  • Fees are overdue;
  • Continued operation poses a security, integrity, or legal risk to the Service, to Nexwift, to other customers, or to third parties;
  • A sub-processor or upstream provider requires it for compliance or safety reasons.

16. Termination

16.1. Either party may terminate for material breach not cured within thirty (30) days after written notice.

16.2. Either party may terminate for convenience at the end of the then-current term by giving written notice as required in Section 3.1.

16.3. On termination or expiry: (a) the Customer’s right to use the Service ceases; (b) outstanding fees for the used portion of the term become immediately due; (c) each party returns or, at the disclosing party’s option, deletes the other’s confidential information, subject to routine backup retention protected by these Terms until expiry, and to any legally required retention.

16.4. Export and deletion of Customer Data on termination are handled per the Data Retention Policy and the Data Processing Agreement. Standard on-request deletion is executed within thirty (30) days of a confirmed request, subject to overriding legal retention.

16.5. Survival. The following Sections survive expiry or termination of these Terms to the extent required to give them effect: 1 (Definitions), 4 (as to fees accrued or invoiced before termination), 7 (AI Output Disclaimer), 10 (Data Ownership), 11.3, 11.4 and 11.5 (Restrictions, Feedback, and Competing-Use Prohibition), 12 (Confidentiality), 13 (Warranties and Disclaimers), 14 (Liability, Indemnity, Force Majeure), 16.3 and 16.4 (post-termination obligations and data return/deletion), 19 (Governing Law and Disputes), 20 (Notices), 21 (Severability), 22 (Assignment), 23 (Entire Agreement), and this Section 16.5.

17. Changes to the Terms

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.

18. Sub-processors

Nexwift engages sub-processors in categories including EU-based cloud infrastructure provider(s), AI inference provider(s), messaging channel platform(s), telephony provider(s), WebRTC/media infrastructure provider(s), and error monitoring provider(s). The current categorical Sub-processor Register is published on the Trust Center. Sub-processor governance, including notice arrangements, is set out in the Data Processing Agreement.

19. Governing Law and Disputes

19.1. These Terms are governed by the laws of the Kingdom of Saudi Arabia.

19.2. The parties will attempt in good faith to resolve any dispute amicably. Failing resolution, the competent courts and regulatory authorities of the Kingdom of Saudi Arabia have exclusive jurisdiction, without prejudice to Nexwift’s right to seek injunctive relief in any competent forum to protect its intellectual property or the Service.

20. Notices

Formal legal notices must be sent in writing to info@nexwift.com, with a copy where applicable to any account address on file. Operational notices (product updates, sub-processor changes, security bulletins) may be issued through the Trust Center, in-product notifications, or the Customer’s registered administrator email.

21. Severability

If any provision is held unenforceable, it will be modified to the minimum extent necessary to be enforceable, and the remainder will continue in full force.

22. Assignment

Neither party may assign these Terms without the other’s prior written consent, except that either party may assign to a successor in interest through merger, acquisition, or sale of substantially all assets, on written notice. Any purported assignment in breach of this Section is void.

23. Entire Agreement

These Terms, together with the Master Agreement and the policies referenced above, constitute the entire agreement between the parties regarding the Service and supersede any prior or contemporaneous understandings on the subject.

24. Contact

PurposeContact
Contracts, legal notices, generalinfo@nexwift.com
Data protection (attn: Data Protection Officer)info@nexwift.com
Security mattersinfo@nexwift.com (attn: CISO)

Document Owner: Chief Executive Officer. Classification: Public. Issued 2026-01-01; next scheduled review 2027-01-01.



Launch login modal Launch register modal