Cookie & Tracking Notice

Nexwift

About Nexwift Saudi AI company Aram contact Nexwift Careers at Nexwift blog
Cookie & Tracking Notice

Cookie & Tracking Notice

Field Value
Document ID NXW-PUB-COOKIE-TRACKING-NOTICE
Version 1.0
Issue Date 2026-01-01
Next Review 2027-01-01
Owner Data Protection Officer (DPO)
Classification Public

1. Purpose and Scope

This Cookie & Tracking Notice ("Notice") explains how Nexwift uses cookies, similar identifiers, and limited client-side storage on:

  • the public Nexwift website at nexwift.com and its sub-domains ("Website"); and
  • the Aram web chat widget ("Widget") when it is embedded on a customer's own website.

This Notice complements the Nexwift Privacy Notice and the Aram Service Terms. It does not describe cookies set by third-party websites that link to, or embed the Widget alongside, other content — those cookies are the responsibility of the operator of that website.

Nexwift is committed to compliance with the Kingdom of Saudi Arabia's Personal Data Protection Law, its implementing regulations, and subsequent guidance issued by the Saudi competent authority.

2. Definitions

Term Meaning
Cookie A small text file stored by your browser at the request of a website, and read back on subsequent requests.
Similar identifier Client-side storage mechanisms such as localStorage, sessionStorage, or IndexedDB used for equivalent purposes.
Strictly necessary Required to deliver a service you have explicitly requested or to maintain the security of that service.
Functional Improves usability by remembering preferences (for example, language).
Analytics Measures aggregated, non-identifying usage to help us improve the service.
Beneficiary An end user who interacts with the Widget on a customer's website (for example, a customer's client, employee, or visitor).

3. Our Cookie Categories

Nexwift does not use advertising cookies, cross-site tracking cookies, profiling cookies, or cookies that build behavioural advertising profiles on the Website or in the Widget.

The categories in use are limited to those below.

3.1 Strictly Necessary

Sub-purpose What it does Retention
Session Maintains your session state across page requests (for example, navigation state on nexwift.com, or continuity of a live chat conversation in the Widget). Session, or until the conversation is closed.
Security Protects against cross-site request forgery (CSRF), token binding, session fixation, and abuse (for example, rate-limiting). Session, or up to 24 hours.
Load balancing Routes your requests consistently to the same backend during a session, so features work correctly. Session.

Strictly necessary cookies do not require prior consent under applicable law. You cannot disable them and continue to use the affected feature; if you block them, the Website or Widget will not function correctly.

3.2 Functional

Sub-purpose What it does Retention
Language / locale Remembers the interface language you selected. Up to 12 months.
Theme / display Remembers display preferences (for example, contrast or font-size settings where offered). Up to 12 months.
Consent state Records the choices you made in the consent banner, so we do not ask again on every page. Up to 12 months.

3.3 Analytics (Aggregated, Opt-Out)

We may use a limited number of first-party analytics identifiers to produce aggregated, non-identifying statistics about how the Website is used (for example, page-view counts, referral sources, broad geography at country level, browser family). Analytics are:

  • minimised to what is needed to improve the service;
  • aggregated before use — no individual profile is built;
  • opt-out — you can decline analytics through the consent banner or your browser controls, and the Website will continue to function; and
  • not used for cross-site tracking, advertising, or profiling.

Third-party analytics processing is minimised. Where any third-party category is engaged, the provider processes only aggregated, non-identifying metrics on our documented instructions and under a written data processing agreement. Sub-processor category updates are communicated as described in Section 8.

4. The Aram Web Chat Widget

The Widget is embedded by our customers on their own websites and other digital surfaces to enable text-based (and, where the customer has enabled it, voice or video) conversations with an AI assistant, with a human agent, or with both.

4.1 Session Identifier (Required for Continuity)

The Widget stores a session identifier on the beneficiary's device. This identifier is strictly necessary because it:

  • links successive messages in the same conversation to the correct thread;
  • allows the beneficiary to reload the page, briefly disconnect, or return within a permitted window and continue the same conversation;
  • separates one beneficiary's session from another's on shared devices; and
  • protects the conversation against session hijacking.

The session identifier does not, by itself, identify the beneficiary. It carries no name, email, phone number, or contact detail unless the beneficiary voluntarily provides one in the conversation.

Retention of the session identifier is configured per customer deployment and defined in that customer's own privacy notice on the site where the Widget is embedded.

4.2 Voice and Video Sessions

Where the customer has enabled voice or video, additional short-lived tokens are exchanged with WebRTC/media infrastructure provider(s) solely to establish and maintain the real-time media session. These tokens are not tracking identifiers, are scoped to a single session, and expire when the session ends.

Recording of voice or video is optional and configured by the customer. Where recording is enabled, the customer (as Data Controller) is responsible for notifying the beneficiary and obtaining any consent required by applicable law. Transcripts, summaries, and recordings are the customer's data; Nexwift processes them on the customer's documented instructions.

4.3 Third-Party Analytics in the Widget

The Widget does not embed third-party advertising trackers. Aggregated operational telemetry (for example, error rates and latency) is transmitted to error monitoring provider(s) with personal identifiers scrubbed at the client SDK before transmission.

4.4 Responsibility on Customer Websites

When the Widget is embedded on a customer's website:

  • the customer is the operator of that website and the Data Controller for interactions initiated on it;
  • the customer is responsible for the consent mechanism on that website — including the cookie banner, granular controls, and record-keeping — where consent is required by applicable law; and
  • the customer's own cookie / privacy notice governs the beneficiary's interaction with that website. This Notice governs only the Widget's own cookies and identifiers as listed above.

Nexwift makes available to customers a categorical description of the Widget's cookies and identifiers so that they can integrate them into their own cookie notice.

5. Consent Mechanism

Where consent is required by applicable law on the Nexwift Website (nexwift.com), we present a cookie banner that:

  • loads before non-strictly-necessary cookies are set;
  • allows you to accept, reject, or make granular choices between functional and analytics categories;
  • records and honours your choice, and offers a persistent means to change it later; and
  • does not use dark patterns or pre-tick optional categories.

For beneficiaries interacting with the Widget on a customer's site, the applicable banner and consent controls are those provided by the customer operator of that site.

6. How to Disable or Delete Cookies

You can control cookies and similar identifiers in the following ways.

  • Consent banner (Website) — change your preferences at any time using the persistent control provided in the footer of nexwift.com.
  • Browser settings — most modern browsers allow you to view, delete, and block cookies on a per-site basis. Consult your browser's documentation. Blocking strictly necessary cookies will prevent the Website or Widget from functioning.
  • Private / incognito browsing — most browsers offer a mode in which cookies and storage are discarded when the window is closed.
  • Widget on a customer's site — use the controls provided by that customer's website. Ending or reloading the conversation and clearing your browser storage will remove the Widget's session identifier.

You do not need to enter any personal information, account, or payment detail to control cookies. Nexwift will never ask you for such information for cookie-management purposes.

7. Legal Basis and PDPL Alignment

Cookies and similar identifiers may involve the processing of personal data. Where they do, our processing is limited as follows.

Category Lawful basis
Strictly necessary Necessary for the performance of the service you have requested and for the security of that service.
Functional Your consent, expressed through the consent banner or by the persistence of a functional preference you set.
Analytics (aggregated) Your consent, on an opt-out basis, for aggregated non-identifying measurement.

Data minimisation, purpose limitation, transparency, and security requirements under Articles 4, 5, 7, 8, and 26 of the PDPL apply. Where any cross-border processing is involved, we rely on comparable-standard safeguards as described in the Nexwift Privacy Notice; European Union hosting is used for platform infrastructure. AI outputs generated during a conversation are advisory and are not medical, legal, or financial advice; voice AI is not an emergency service.

8. Changes to This Notice

Nexwift may update this Notice from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated Notice.

Categorical changes to sub-processor categories are notified in accordance with the applicable Data Processing Agreement.

9. Contact

For questions about this Notice, requests relating to cookies or personal data, or to exercise your rights under the PDPL:

Purpose Contact
Data protection questions and PDPL rights requests info@nexwift.com (attn: Data Protection Officer)
General enquiries info@nexwift.com

Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.

10. Governing Law and Jurisdiction

This Notice is governed by, and interpreted in accordance with, the laws of the Kingdom of Saudi Arabia. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the competent Saudi courts and authorities, without prejudice to the mandatory jurisdiction of the competent Saudi data-protection authority.

Nothing in this Notice limits any right you may have under applicable law that cannot be waived by agreement.







 

Terms of Service

FieldValue
Document IDNXW-PUB-TERMS-OF-SERVICE
Version1.0
Issue Date2026-01-01
Next Review2027-01-01
OwnerChief Executive Officer
ClassificationPublic

These Terms of Service (“Terms“) govern access to and use of the Aram AI Agent Platform (“Aram“, the “Service“) provided by Nexwift (“Nexwift“, “we“, “us“). By ordering, activating, or using the Service, the customer (“Customer“, “you“) agrees to these Terms. Where a signed Master Services Agreement, Order Form, Data Processing Agreement, or Service Level Agreement is in place between Nexwift and the Customer (together, the “Master Agreement“), those documents prevail over any conflicting provision below.

The Service covers text, voice, and video AI-agent interactions across the channels a Customer chooses to enable.

1. Definitions

TermMeaning
Aram / ServiceNexwift’s multi-channel AI agent platform including agent configuration, knowledge-base tooling, conversation orchestration, voice and video agents, and the supervision dashboard.
Customer DataAll content and configurations submitted to or generated within the Service on the Customer’s behalf, including knowledge-base sources, prompts and playbooks, conversation transcripts, call recordings and derived summaries, and end-user (beneficiary) records.
BeneficiaryA natural person interacting with an Aram agent through a Customer-owned channel (chat, messaging, telephony, or WebRTC video).
Master AgreementThe signed Master Services Agreement, Order Form, Data Processing Agreement, Service Level Agreement, and any accepted policies referenced therein.
AUPThe Acceptable Use Policy published on the Nexwift Trust Center.
DocumentationThe user, administrator, and API documentation published or made available by Nexwift for the Service.

2. Account

The Customer is responsible for the accuracy of registration information, for maintaining the confidentiality of administrator credentials, for enforcing multi-factor authentication on privileged users, and for all activity conducted under its accounts. The Customer must notify Nexwift without undue delay of any suspected credential compromise or unauthorized use.

3. Subscription, Renewal, and Evaluation Period

3.1. Subscriptions run for the term stated on the Order Form and renew automatically for successive terms of equal length unless either party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term.

3.2. Where an Order Form provides an evaluation period, that period commences on the date the Service is first activated in the Customer’s live environment (not on contract signature or provisioning start), unless expressly stated otherwise on the Order Form.

3.3. Continued use of the Service after the evaluation period constitutes acceptance of the standing subscription and applicable fees.

4. Fees, Usage Measurement, and Payment

4.1. Fees, billing cycles, and included quantities (agents, conversations, minutes, storage, and channel volumes as applicable) are set out in the Order Form. Usage is metered by Nexwift from platform telemetry and rounded per the metrics table published in the Documentation.

4.2. Invoices are payable in accordance with the Master Agreement. Amounts not disputed in good faith and unpaid past their due date may accrue interest at the maximum rate permitted by applicable law and may trigger suspension under Section 15.

4.3. Fees are exclusive of value-added tax and other applicable duties, which the Customer bears.

5. Customer Responsibilities

The Customer is responsible for:

  • Configuring agents, playbooks, and channel connections in line with its legal, sectoral, and regulatory obligations;
  • Obtaining and maintaining all beneficiary consents required by applicable law for AI interaction, message exchange, call handling, and, where enabled, recording of voice and video sessions and generation of transcripts and summaries;
  • Providing the required disclosures to beneficiaries that they are interacting with an AI agent;
  • Ensuring the lawful basis for all personal data submitted to or processed via the Service;
  • Managing user accounts, role assignments, and offboarding of its personnel;
  • Reviewing outputs of AI-generated public replies where the deployment model requires human approval;
  • Monitoring its own use for compliance with the AUP.

6. Nexwift Responsibilities

Nexwift will use commercially reasonable efforts to:

  • Provide the Service in accordance with the Documentation and the Master Agreement;
  • Maintain the technical and organizational security measures described in the Nexwift Information Security Policy summary published on the Trust Center;
  • Notify the Customer of security incidents affecting Customer Data without undue delay in line with the Data Processing Agreement;
  • Provide advance notice of material sub-processor changes on a categorical basis as described in the Sub-processor Policy.

Availability commitments and service credits (if any) are set exclusively in the Service Level Agreement. Service credits, where offered, are the Customer’s sole financial remedy for availability shortfalls, without prejudice to termination rights for sustained material breach.

7. AI Output Disclaimer

7.1. Aram uses generative and retrieval-augmented AI models. Outputs are probabilistic and may contain errors, omissions, or content that does not reflect Customer intent. Aram outputs are advisory and informational only. They do not constitute, and must not be presented to beneficiaries as, medical, legal, or financial advice.

7.2. Voice and video AI agents are not emergency services. They must not be used, and must not be represented to beneficiaries as available, for life-safety, medical emergency, law-enforcement, or similar time-critical events. The Customer must configure appropriate escalation and fall-back paths to human operators or public emergency services.

7.3. Where recording, transcription, or summarization is enabled, the Customer remains responsible for informing beneficiaries and obtaining any legally required consent before the interaction proceeds.

7.4. High-risk and safety-critical uses excluded. The Service is not designed, tested, or certified for use in environments where failure could lead to death, personal injury, or severe environmental or property damage, including nuclear facilities, aircraft or air-traffic control, medical devices or life-support systems, autonomous vehicle control, industrial safety systems, or critical infrastructure operation. The Customer will not deploy the Service in such contexts.

7.5. No warranty of intellectual-property protection over AI outputs. The copyright, patent, and other intellectual-property status of AI-generated content varies by jurisdiction and may be uncertain or unavailable. Nexwift makes no representation that AI outputs are protectable by intellectual-property rights in any jurisdiction and does not warrant that outputs are non-infringing. As between the parties, ownership is allocated under Section 10.

8. Acceptable Use; Third-Party Terms

8.1. Acceptable Use. The Customer, its users, and its beneficiaries must comply with the Acceptable Use Policy published on the Nexwift Trust Center. Violation is grounds for suspension or termination under Sections 15 and 16.

8.2. Third-party channels and platforms. The Service integrates with third-party messaging, telephony, media-transport, and other platforms selected or connected by the Customer. The Customer is solely responsible for reading, accepting, and complying with the terms of service, developer policies, community standards, template and content policies, quality ratings, and rate limits of every such platform, and for any account, application, or channel identifier that the Customer registers or connects. Suspensions, deprecations, quality-rating downgrades, throttles, or policy actions imposed by any such platform are outside Nexwift’s control and are excluded from availability commitments.

9. Data Protection and Privacy

Nexwift processes personal data on the Customer’s behalf under the Data Processing Agreement, which reflects the Kingdom of Saudi Arabia’s Personal Data Protection Law. The Nexwift Privacy Policy published on the Trust Center describes personal data processed by Nexwift as a controller for its own operational purposes.

10. Data Ownership

10.1. The Customer owns all Customer Data, including its knowledge-base content, agent configurations, prompts, conversation transcripts, call and video recordings (where enabled), and derived summaries produced for the Customer.

10.2. Nexwift owns the Service and all associated intellectual property, including the platform software, agent orchestration logic, evaluation and analytics logic, embedded prompt scaffolding, and aggregated, de-identified operational telemetry used to operate, secure, and improve the Service.

11. Intellectual Property; Licenses

11.1. Nexwift grants the Customer, for the term of the subscription, a non-exclusive, non-transferable, non-sublicensable, revocable, limited license to access and use the Service and Documentation for its internal business purposes, subject to these Terms and the Master Agreement.

11.2. The Customer grants Nexwift a limited, worldwide, royalty-free right to host, process, transmit, display, and create derivative representations of Customer Data solely as required to provide, secure, and support the Service. Nexwift may use aggregated, de-identified telemetry to operate, secure, benchmark, and improve the Service.

11.3. No rights are granted by implication, estoppel, or otherwise. The Customer will not reverse-engineer, decompile, benchmark for competitive purposes, resell, or create derivative works of the Service except as expressly permitted by law.

11.4. Feedback. If the Customer or any of its personnel provides suggestions, ideas, feature requests, or other feedback about the Service (“Feedback“), Nexwift may use that Feedback for any purpose, without obligation, attribution, or restriction. Feedback is not treated as the Customer’s confidential information unless expressly marked as confidential in writing at the time of disclosure.

11.5. No competing use of outputs. The Customer will not, and will not permit any third party to, use outputs, telemetry, prompts, or Documentation of the Service to train, fine-tune, evaluate, or develop any AI model, product, or service that competes with the Service, nor to circumvent metering, safety, rate-limit, or abuse controls.

12. Confidentiality

Each party will protect the other’s non-public information disclosed under or in connection with these Terms with at least the degree of care it uses for its own confidential information, and never less than a reasonable standard. If a party is legally compelled to disclose the other’s confidential information, it will, unless legally prohibited, give prompt notice and disclose only the minimum required.

13. Warranties and Disclaimers

13.1. Each party warrants that it has the authority to enter into these Terms.

13.2. Except as expressly stated in the Master Agreement, the Service is provided “as is” and “as available”. To the maximum extent permitted by law, Nexwift disclaims all other warranties, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy of AI-generated outputs, and uninterrupted or error-free operation.

13.3. Beta, preview, and experimental features. Nexwift may designate certain features as “beta”, “preview”, “early access”, “alpha”, or “experimental” (“Preview Features“). Preview Features are provided free of any availability, support, or performance commitment, are excluded from any Service Level Agreement and service-credit remedy, may be modified, deprecated, or withdrawn at any time without notice, and may be more likely than the general Service to contain defects. The Customer’s use of Preview Features is at its sole discretion and risk.

14. Liability, Indemnity, Force Majeure

14.1. Each party’s aggregate liability arising out of or related to these Terms is capped as set out in the Master Agreement. In the absence of a specific figure, liability is limited to the fees paid by the Customer for the Service in the twelve (12) months preceding the event giving rise to liability.

14.2. Neither party is liable for indirect, incidental, consequential, special, punitive, or exemplary damages, or for loss of profits, revenue, goodwill, or data, even if advised of the possibility.

14.3. Any indemnity obligations are those expressly stated in the Master Agreement and are subject to the liability cap in Section 14.1, save for exclusions required by mandatory law.

14.4. Neither party is liable for delay or failure to perform caused by events beyond its reasonable control, including natural events, war, terrorism, civil disturbance, labor action, government action, cyber-attacks not attributable to its negligence, and outages of third-party networks, platforms, or providers (“force majeure“). Outages of third-party messaging channels, telephony carriers, WebRTC transport, AI inference providers, mapping providers, and other upstream services are outside Nexwift’s control and are excluded from availability commitments.

15. Suspension

Nexwift may suspend the Service or any part of it, in whole or in part, on notice appropriate to the circumstances (including immediate notice for security-critical matters), where:

  • The Customer is in material breach of these Terms, the AUP, or the Master Agreement and has not cured within any applicable cure period;
  • Fees are overdue;
  • Continued operation poses a security, integrity, or legal risk to the Service, to Nexwift, to other customers, or to third parties;
  • A sub-processor or upstream provider requires it for compliance or safety reasons.

16. Termination

16.1. Either party may terminate for material breach not cured within thirty (30) days after written notice.

16.2. Either party may terminate for convenience at the end of the then-current term by giving written notice as required in Section 3.1.

16.3. On termination or expiry: (a) the Customer’s right to use the Service ceases; (b) outstanding fees for the used portion of the term become immediately due; (c) each party returns or, at the disclosing party’s option, deletes the other’s confidential information, subject to routine backup retention protected by these Terms until expiry, and to any legally required retention.

16.4. Export and deletion of Customer Data on termination are handled per the Data Retention Policy and the Data Processing Agreement. Standard on-request deletion is executed within thirty (30) days of a confirmed request, subject to overriding legal retention.

16.5. Survival. The following Sections survive expiry or termination of these Terms to the extent required to give them effect: 1 (Definitions), 4 (as to fees accrued or invoiced before termination), 7 (AI Output Disclaimer), 10 (Data Ownership), 11.3, 11.4 and 11.5 (Restrictions, Feedback, and Competing-Use Prohibition), 12 (Confidentiality), 13 (Warranties and Disclaimers), 14 (Liability, Indemnity, Force Majeure), 16.3 and 16.4 (post-termination obligations and data return/deletion), 19 (Governing Law and Disputes), 20 (Notices), 21 (Severability), 22 (Assignment), 23 (Entire Agreement), and this Section 16.5.

17. Changes to the Terms

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.

18. Sub-processors

Nexwift engages sub-processors in categories including EU-based cloud infrastructure provider(s), AI inference provider(s), messaging channel platform(s), telephony provider(s), WebRTC/media infrastructure provider(s), and error monitoring provider(s). The current categorical Sub-processor Register is published on the Trust Center. Sub-processor governance, including notice arrangements, is set out in the Data Processing Agreement.

19. Governing Law and Disputes

19.1. These Terms are governed by the laws of the Kingdom of Saudi Arabia.

19.2. The parties will attempt in good faith to resolve any dispute amicably. Failing resolution, the competent courts and regulatory authorities of the Kingdom of Saudi Arabia have exclusive jurisdiction, without prejudice to Nexwift’s right to seek injunctive relief in any competent forum to protect its intellectual property or the Service.

20. Notices

Formal legal notices must be sent in writing to info@nexwift.com, with a copy where applicable to any account address on file. Operational notices (product updates, sub-processor changes, security bulletins) may be issued through the Trust Center, in-product notifications, or the Customer’s registered administrator email.

21. Severability

If any provision is held unenforceable, it will be modified to the minimum extent necessary to be enforceable, and the remainder will continue in full force.

22. Assignment

Neither party may assign these Terms without the other’s prior written consent, except that either party may assign to a successor in interest through merger, acquisition, or sale of substantially all assets, on written notice. Any purported assignment in breach of this Section is void.

23. Entire Agreement

These Terms, together with the Master Agreement and the policies referenced above, constitute the entire agreement between the parties regarding the Service and supersede any prior or contemporaneous understandings on the subject.

24. Contact

PurposeContact
Contracts, legal notices, generalinfo@nexwift.com
Data protection (attn: Data Protection Officer)info@nexwift.com
Security mattersinfo@nexwift.com (attn: CISO)

Document Owner: Chief Executive Officer. Classification: Public. Issued 2026-01-01; next scheduled review 2027-01-01.



Launch login modal Launch register modal