Acceptable Use Policy
| Field | Value |
|---|---|
| Document ID | NXW-PUB-ACCEPTABLE-USE-POLICY |
| Version | 1.0 |
| Issue Date | 2026-01-01 |
| Next Review | 2027-01-01 |
| Owner | Chief Information Security Officer |
| Classification | Public |
1. Purpose and Scope
This Acceptable Use Policy ("AUP") sets out the conduct that Nexwift requires from every customer, authorised user, and beneficiary who interacts with the Aram platform ("Platform") across text, voice, and video channels. It applies to all deployments, environments, and integrations offered by Nexwift, and supplements the Master Services Agreement, the Data Processing Agreement, and any Order Form or Statement of Work executed between Nexwift and the customer.
Use of the Platform constitutes acceptance of this AUP. Where the customer permits third parties (employees, contractors, or beneficiaries) to interact with the Platform, the customer remains responsible for those parties' compliance with this AUP.
2. Governing Law
This AUP is governed by the laws of the Kingdom of Saudi Arabia, including without limitation the Personal Data Protection Law, the Anti-Cyber Crime Law, the Anti-Commercial Fraud Law, and any regulations, decisions, or guidance issued by the competent Saudi authorities. Any dispute arising out of or in connection with this AUP shall be submitted to the competent Saudi courts and authorities.
3. General Prohibited Uses
The following uses are strictly prohibited across all channels (text, voice, and video):
| # | Prohibited Use | Description |
|---|---|---|
| 3.1 | Unlawful conduct | Any use that violates the laws of the Kingdom of Saudi Arabia, the Personal Data Protection Law (PDPL), or the applicable laws of any jurisdiction from which the customer operates or into which content is directed. |
| 3.2 | Intellectual property infringement | Uploading, transmitting, or generating content that infringes copyrights, trademarks, patents, trade secrets, or other proprietary rights of any third party. |
| 3.3 | Defamation | Publishing or distributing content that is defamatory, libellous, or that unlawfully damages the reputation of any natural or legal person. |
| 3.4 | Harassment and hate speech | Content that harasses, threatens, intimidates, or promotes hatred or discrimination against any individual or group on any protected basis. |
| 3.5 | Sexually explicit or gratuitously violent content | Generation, storage, or transmission of pornographic, sexually explicit, or gratuitously violent content. |
| 3.6 | Exploitation of minors | Any content or conduct that sexualises, exploits, endangers, or otherwise harms minors. This category is subject to zero tolerance and mandatory reporting where legally required. |
| 3.7 | Deception of beneficiaries | Deceiving beneficiaries as to the nature of the interaction, the identity of the operator, or material facts affecting the beneficiary's decision. Beneficiaries must be able to understand, in context, that they may be interacting with an AI-assisted system, in accordance with the customer's disclosure obligations. |
| 3.8 | Impersonation of officials | Impersonation of government officials, public authorities, judicial bodies, security forces, or of Nexwift personnel, in each case without lawful authorisation. |
| 3.9 | Spam and unsolicited messaging | Sending mass unsolicited messages, chain messages, unsolicited commercial communications, or otherwise using the Platform contrary to applicable anti-spam and telemarketing rules. |
| 3.10 | Phishing and fraud | Using the Platform to conduct phishing, social engineering, financial fraud, identity theft, or any other deceptive practice designed to obtain data, credentials, or funds without authorisation. |
| 3.11 | Malware distribution | Uploading, transmitting, or linking to malware, ransomware, spyware, or any code designed to disrupt, damage, or gain unauthorised access to any system. |
| 3.12 | Circumvention of controls | Circumventing or attempting to circumvent security controls, authentication, rate limits, quotas, guardrails, moderation systems, or any other technical or contractual restriction imposed by Nexwift. |
| 3.13 | Competitive AI development | Using the Platform, the outputs of Aram agents, or any Nexwift-provided model artefacts to train, fine-tune, benchmark, or otherwise develop a competing artificial intelligence or conversational service. |
| 3.14 | Unauthorised security testing | Conducting penetration testing, vulnerability scanning, load or stress testing, denial-of-service testing, or any other security research against the Platform without Nexwift's prior written authorisation and a mutually agreed rules-of-engagement document. |
| 3.15 | Automated scraping and harvesting | Systematic scraping, harvesting, or bulk extraction of Platform content, beneficiary data, agent outputs, or knowledge-base material by any automated means outside the interfaces expressly provided for that purpose. |
| 3.16 | Reverse engineering | Reverse engineering, decompiling, disassembling, or attempting to derive the source code, model weights, prompts, or underlying architecture of the Platform, except to the minimum extent expressly permitted by applicable mandatory law. |
| 3.17 | Sanctions and export controls | Using the Platform in violation of applicable trade-sanctions, export-control, or embargo regimes, or making the Platform available to any person or entity subject to such measures. |
| 3.18 | Minors as end users | Deploying the Platform in a manner that directs Aram agents at children below the age of majority in the relevant jurisdiction without an appropriate lawful basis, parental-consent mechanism, and age-appropriate safeguards documented by the customer. |
4. Voice-Channel Specific Rules
The voice channel enables outbound and inbound calling and is subject to the additional rules below.
- Authorisation for auto-dialling. Automated dialling, predictive dialling, or campaign-style outbound calling is permitted only within the scope authorised in writing by the customer's compliance function and only where the underlying telephony authorisation and beneficiary consent bases are documented.
- Prohibition on scam robocalling. Robocalling for scam, fraud, or unlawful commercial purposes is strictly prohibited. Customers must maintain do-not-call suppression lists appropriate to their jurisdiction.
- Recording and notice. Voice-call recording is an optional, customer-configurable capability. Where the customer enables recording, the customer is solely responsible for providing beneficiaries with the notices and, where required, obtaining the consents mandated by applicable law prior to the recording taking place. Nexwift processes recordings on the customer's documented instructions only.
- Emergency services. The Aram voice agent is not, and must not be represented as, an emergency service. Customers must not deploy the voice agent as a substitute for emergency response.
5. Video-Channel Specific Rules
The video channel supports interactive audio-video sessions between beneficiaries and Aram video agents.
- No unlawful surveillance. The video channel must not be used to conduct covert surveillance, unlawful monitoring, biometric identification without lawful basis, or any activity prohibited by KSA law or applicable local law.
- Capture requires notice. Video capture (still images, video recordings, or transcripts) is optional and customer-configurable. Where enabled, the customer is solely responsible for informing beneficiaries in advance and obtaining any consent required by applicable law.
- Ownership of recordings. Consistent with the Master Services Agreement, the customer owns customer data and configurations, the customer knowledge base, and any transcripts, recordings, and summaries derived from the customer's use of the service. Nexwift retains ownership of the Platform, the underlying models, and aggregated telemetry.
6. AI-Use Safety Rules
The Platform relies on managed AI inference providers. AI-generated outputs are inherently probabilistic and may be inaccurate, incomplete, out-of-date, or biased; no reliance should be placed on such outputs for any decision that has legal, financial, medical, safety, or other material consequences for a beneficiary without independent human review by suitably qualified personnel.
Customers must not deploy Aram agents to deliver medical advice, legal advice, financial or investment advice, or any other regulated professional advice to beneficiaries, and must not represent AI-generated outputs as the advice of a licensed professional. AI-generated outputs are advisory only. Customers are solely responsible for configuring the guardrails, sensitive-topic handling, disclosure notices, and human-in-the-loop review appropriate to their use case, and for validating outputs prior to any action being taken on the basis of them.
The Platform must not be used to make fully-automated decisions that produce legal or similarly significant effects on beneficiaries without a lawful basis under applicable data-protection law and without providing beneficiaries with the safeguards required by that law (including, where applicable, the right to obtain human intervention, to express a point of view, and to contest the decision).
7. Enforcement
Nexwift monitors the Platform on a commercially reasonable basis for compliance with this AUP. Where a suspected breach is identified, Nexwift may, at its sole discretion and having regard to the severity, recurrence, and risk posed to third parties, take any of the following actions:
| Measure | Description |
|---|---|
| Warning | Written notice to the customer's administrative contact identifying the suspected breach and the remedial action required. |
| Throttling | Temporary reduction of rate limits, concurrent sessions, or feature availability while the matter is investigated. |
| Suspension | Suspension of all or part of the affected service without prior notice where continued operation presents a security, legal, or reputational risk. |
| Termination | Termination of the affected service or the entire agreement in accordance with the Master Services Agreement. |
Nexwift will use commercially reasonable efforts to notify the customer of any enforcement action without undue delay, except where prior notice would frustrate the purpose of the action, breach a legal obligation, or expose Nexwift, the customer, or a third party to further risk.
A material breach of this AUP, including any breach falling within sections 3.6, 3.10, 3.11, 3.12, 3.13, 3.14, 3.16, or 3.17, or any repeated breach following a warning, shall constitute a material breach of the Master Services Agreement and entitle Nexwift to terminate the affected service with immediate effect and without any refund of prepaid fees.
8. Reporting to Authorities
Where legally required or where Nexwift reasonably believes that reporting is necessary to prevent imminent harm, Nexwift reserves the right to report suspected breaches of this AUP to the competent authorities in the Kingdom of Saudi Arabia or in any other jurisdiction whose law applies, and to disclose to those authorities the minimum information required to comply with the applicable legal obligation.
9. Customer Indemnity
The customer shall indemnify, defend, and hold harmless Nexwift, its affiliates, and their respective personnel from and against any third-party claims, actions, proceedings, losses, damages, fines, costs, and expenses (including reasonable legal fees) arising out of, or in connection with, any breach of this AUP by the customer, its authorised users, its contractors, or any beneficiary acting under the customer's direction or on the customer's channels. This clause survives termination of the Master Services Agreement.
10. Reporting Channel
Suspected breaches of this AUP, abuse of the Platform, or other concerns may be reported to Nexwift at info@nexwift.com. Reports concerning personal data, privacy, or PDPL matters should be addressed to the Data Protection Officer at the same address (attention: Data Protection Officer). Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.
11. Amendments
Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.
12. Contact
| Purpose | Address |
|---|---|
| General enquiries and AUP reports | info@nexwift.com |
| Data protection matters | info@nexwift.com (attention: Data Protection Officer) |
| Security incidents | info@nexwift.com (attention: Chief Information Security Officer) |