Cookie & Tracking Notice
| Field | Value |
|---|---|
| Document ID | NXW-PUB-COOKIE-TRACKING-NOTICE |
| Version | 1.0 |
| Issue Date | 2026-01-01 |
| Next Review | 2027-01-01 |
| Owner | Data Protection Officer (DPO) |
| Classification | Public |
1. Purpose and Scope
This Cookie & Tracking Notice ("Notice") explains how Nexwift uses cookies, similar identifiers, and limited client-side storage on:
- the public Nexwift website at
nexwift.comand its sub-domains ("Website"); and - the Aram web chat widget ("Widget") when it is embedded on a customer's own website.
This Notice complements the Nexwift Privacy Notice and the Aram Service Terms. It does not describe cookies set by third-party websites that link to, or embed the Widget alongside, other content — those cookies are the responsibility of the operator of that website.
Nexwift is committed to compliance with the Kingdom of Saudi Arabia's Personal Data Protection Law, its implementing regulations, and subsequent guidance issued by the Saudi competent authority.
2. Definitions
| Term | Meaning |
|---|---|
| Cookie | A small text file stored by your browser at the request of a website, and read back on subsequent requests. |
| Similar identifier | Client-side storage mechanisms such as localStorage, sessionStorage, or IndexedDB used for equivalent purposes. |
| Strictly necessary | Required to deliver a service you have explicitly requested or to maintain the security of that service. |
| Functional | Improves usability by remembering preferences (for example, language). |
| Analytics | Measures aggregated, non-identifying usage to help us improve the service. |
| Beneficiary | An end user who interacts with the Widget on a customer's website (for example, a customer's client, employee, or visitor). |
3. Our Cookie Categories
Nexwift does not use advertising cookies, cross-site tracking cookies, profiling cookies, or cookies that build behavioural advertising profiles on the Website or in the Widget.
The categories in use are limited to those below.
3.1 Strictly Necessary
| Sub-purpose | What it does | Retention |
|---|---|---|
| Session | Maintains your session state across page requests (for example, navigation state on nexwift.com, or continuity of a live chat conversation in the Widget). |
Session, or until the conversation is closed. |
| Security | Protects against cross-site request forgery (CSRF), token binding, session fixation, and abuse (for example, rate-limiting). | Session, or up to 24 hours. |
| Load balancing | Routes your requests consistently to the same backend during a session, so features work correctly. | Session. |
Strictly necessary cookies do not require prior consent under applicable law. You cannot disable them and continue to use the affected feature; if you block them, the Website or Widget will not function correctly.
3.2 Functional
| Sub-purpose | What it does | Retention |
|---|---|---|
| Language / locale | Remembers the interface language you selected. | Up to 12 months. |
| Theme / display | Remembers display preferences (for example, contrast or font-size settings where offered). | Up to 12 months. |
| Consent state | Records the choices you made in the consent banner, so we do not ask again on every page. | Up to 12 months. |
3.3 Analytics (Aggregated, Opt-Out)
We may use a limited number of first-party analytics identifiers to produce aggregated, non-identifying statistics about how the Website is used (for example, page-view counts, referral sources, broad geography at country level, browser family). Analytics are:
- minimised to what is needed to improve the service;
- aggregated before use — no individual profile is built;
- opt-out — you can decline analytics through the consent banner or your browser controls, and the Website will continue to function; and
- not used for cross-site tracking, advertising, or profiling.
Third-party analytics processing is minimised. Where any third-party category is engaged, the provider processes only aggregated, non-identifying metrics on our documented instructions and under a written data processing agreement. Sub-processor category updates are communicated as described in Section 8.
4. The Aram Web Chat Widget
The Widget is embedded by our customers on their own websites and other digital surfaces to enable text-based (and, where the customer has enabled it, voice or video) conversations with an AI assistant, with a human agent, or with both.
4.1 Session Identifier (Required for Continuity)
The Widget stores a session identifier on the beneficiary's device. This identifier is strictly necessary because it:
- links successive messages in the same conversation to the correct thread;
- allows the beneficiary to reload the page, briefly disconnect, or return within a permitted window and continue the same conversation;
- separates one beneficiary's session from another's on shared devices; and
- protects the conversation against session hijacking.
The session identifier does not, by itself, identify the beneficiary. It carries no name, email, phone number, or contact detail unless the beneficiary voluntarily provides one in the conversation.
Retention of the session identifier is configured per customer deployment and defined in that customer's own privacy notice on the site where the Widget is embedded.
4.2 Voice and Video Sessions
Where the customer has enabled voice or video, additional short-lived tokens are exchanged with WebRTC/media infrastructure provider(s) solely to establish and maintain the real-time media session. These tokens are not tracking identifiers, are scoped to a single session, and expire when the session ends.
Recording of voice or video is optional and configured by the customer. Where recording is enabled, the customer (as Data Controller) is responsible for notifying the beneficiary and obtaining any consent required by applicable law. Transcripts, summaries, and recordings are the customer's data; Nexwift processes them on the customer's documented instructions.
4.3 Third-Party Analytics in the Widget
The Widget does not embed third-party advertising trackers. Aggregated operational telemetry (for example, error rates and latency) is transmitted to error monitoring provider(s) with personal identifiers scrubbed at the client SDK before transmission.
4.4 Responsibility on Customer Websites
When the Widget is embedded on a customer's website:
- the customer is the operator of that website and the Data Controller for interactions initiated on it;
- the customer is responsible for the consent mechanism on that website — including the cookie banner, granular controls, and record-keeping — where consent is required by applicable law; and
- the customer's own cookie / privacy notice governs the beneficiary's interaction with that website. This Notice governs only the Widget's own cookies and identifiers as listed above.
Nexwift makes available to customers a categorical description of the Widget's cookies and identifiers so that they can integrate them into their own cookie notice.
5. Consent Mechanism
Where consent is required by applicable law on the Nexwift Website (nexwift.com), we present a cookie banner that:
- loads before non-strictly-necessary cookies are set;
- allows you to accept, reject, or make granular choices between functional and analytics categories;
- records and honours your choice, and offers a persistent means to change it later; and
- does not use dark patterns or pre-tick optional categories.
For beneficiaries interacting with the Widget on a customer's site, the applicable banner and consent controls are those provided by the customer operator of that site.
6. How to Disable or Delete Cookies
You can control cookies and similar identifiers in the following ways.
- Consent banner (Website) — change your preferences at any time using the persistent control provided in the footer of
nexwift.com. - Browser settings — most modern browsers allow you to view, delete, and block cookies on a per-site basis. Consult your browser's documentation. Blocking strictly necessary cookies will prevent the Website or Widget from functioning.
- Private / incognito browsing — most browsers offer a mode in which cookies and storage are discarded when the window is closed.
- Widget on a customer's site — use the controls provided by that customer's website. Ending or reloading the conversation and clearing your browser storage will remove the Widget's session identifier.
You do not need to enter any personal information, account, or payment detail to control cookies. Nexwift will never ask you for such information for cookie-management purposes.
7. Legal Basis and PDPL Alignment
Cookies and similar identifiers may involve the processing of personal data. Where they do, our processing is limited as follows.
| Category | Lawful basis |
|---|---|
| Strictly necessary | Necessary for the performance of the service you have requested and for the security of that service. |
| Functional | Your consent, expressed through the consent banner or by the persistence of a functional preference you set. |
| Analytics (aggregated) | Your consent, on an opt-out basis, for aggregated non-identifying measurement. |
Data minimisation, purpose limitation, transparency, and security requirements under Articles 4, 5, 7, 8, and 26 of the PDPL apply. Where any cross-border processing is involved, we rely on comparable-standard safeguards as described in the Nexwift Privacy Notice; European Union hosting is used for platform infrastructure. AI outputs generated during a conversation are advisory and are not medical, legal, or financial advice; voice AI is not an emergency service.
8. Changes to This Notice
Nexwift may update this Notice from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated Notice.
Categorical changes to sub-processor categories are notified in accordance with the applicable Data Processing Agreement.
9. Contact
For questions about this Notice, requests relating to cookies or personal data, or to exercise your rights under the PDPL:
| Purpose | Contact |
|---|---|
| Data protection questions and PDPL rights requests | info@nexwift.com (attn: Data Protection Officer) |
| General enquiries | info@nexwift.com |
Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.
10. Governing Law and Jurisdiction
This Notice is governed by, and interpreted in accordance with, the laws of the Kingdom of Saudi Arabia. Any dispute arising out of or in connection with it is subject to the exclusive jurisdiction of the competent Saudi courts and authorities, without prejudice to the mandatory jurisdiction of the competent Saudi data-protection authority.
Nothing in this Notice limits any right you may have under applicable law that cannot be waived by agreement.