Data Ownership & Portability

Nexwift

About Nexwift Saudi AI company Aram contact Nexwift Careers at Nexwift blog
Data Ownership & Portability

Data Ownership & Portability

Field Value
Document ID NXW-PUB-DATA-OWNERSHIP-PORTABILITY
Version 1.0
Issue Date 2026-01-01
Next Review 2027-01-01
Owner Data Protection Officer (DPO)
Classification Public
Applies to Aram platform (text, voice, and video use cases)

1. Purpose

This statement sets out, in plain terms, who owns what in the customer's use of the Aram platform, and how customer data is exported and deleted on termination or at any time during the subscription. It is a public commitment intended to remove any concern of vendor lock-in.

It applies uniformly to all supported interaction modalities on the platform: text (messaging channels, web chat, comments and direct messages), voice (telephony and WebRTC voice), and video (WebRTC video), including the recordings and transcripts produced by those modalities where the customer has enabled them.


2. Ownership at a glance

Item Owner
Customer Content and Configurations (see §3) Customer
Aram platform, software, and underlying models (see §4) Nexwift

Nothing in the customer's use of the platform transfers ownership of Nexwift's intellectual property to the customer, and nothing in Nexwift's operation of the platform transfers ownership of Customer Content to Nexwift.


3. What the customer owns ("Customer Content")

The customer retains full ownership of, and all intellectual property rights in, the following, whether they existed before onboarding, were uploaded by the customer, or were generated in the course of using the platform on the customer's behalf:

  • Customer data — accounts, user records, contact records, tags, and any business data supplied by the customer or collected from the customer's beneficiaries through the customer's channels.
  • Configurations — tenant settings, channel connections, routing rules, business hours, escalation rules, brand and voice settings, agent personas, and any operator-defined workflow parameters.
  • Knowledge base content — documents, articles, FAQs, product catalogues, and other retrieval sources uploaded, connected, or curated by the customer.
  • Dialogue scripts and scenarios — flows, decision trees, and scripted interaction sequences authored by the customer.
  • Prompts — system prompts, personas, and prompt fragments authored by or on behalf of the customer.
  • Text transcripts — conversation transcripts across text channels.
  • Voice recordings and transcripts — where voice recording is enabled by the customer.
  • Video recordings and transcripts — where video recording is enabled by the customer.
  • AI summaries and derived artefacts produced from any of the above.

Recording of voice and video is optional and customer-configurable. Where the customer enables recording or transcription, the customer is responsible for obtaining any legally required notice or consent from the individuals whose voice or image is captured, and for compliance with all applicable law of the relevant jurisdictions.

Nexwift processes Customer Content only on the customer's documented instructions and for the purpose of delivering the service and meeting Nexwift's legal obligations, as further described in the Master Agreement and the Data Processing Agreement.


4. What Nexwift owns

Nexwift retains ownership of:

  • The Aram platform and all associated software, source code, user interfaces, APIs, documentation, workflows, and know-how.
  • The models, model configurations, and provider integrations that make up the platform's AI stack, other than customer-authored prompts, personas, and knowledge-base content described in §3.
  • Service improvements, learnings, and know-how developed by Nexwift, provided they do not identify the customer, its beneficiaries, or its Customer Content.
  • Aggregated and de-identified operational telemetry (for example: request volumes, latencies, error rates, feature-usage counters) used to monitor, secure, and improve the service. This telemetry is produced in a form that cannot reasonably be used to identify a customer or a natural person, and may be retained beyond the customer's subscription for continued operational and service-improvement purposes.

5. Export rights — when and how

5.1 When a customer can request export

  • At any time during the subscription — the customer may request an export of Customer Content as an operational matter, subject to reasonable rate limits.
  • On termination — the customer may request an export at any point within 30 days from the effective date of the termination notice. Where the customer has not requested an export by the end of that window, Nexwift proceeds to deletion under §7 subject to any earlier written instruction.

5.2 Formats

Exports are provided in industry-standard formats designed to be re-imported into other systems without proprietary conversion:

Data category Export format
Configurations, tenant settings, personas, prompts, knowledge-base metadata JSON
Structured records (contacts, users, conversation headers, ticket history) JSON
Tabular reports and audit exports CSV
Knowledge-base source documents Original uploaded format where available
Voice recordings WAV or OPUS
Video recordings MP4
Text, voice, and video transcripts TXT and/or JSON (with timestamps and speaker labels where applicable)
AI summaries and derived artefacts JSON, plus TXT for human-readable copies

5.3 Delivery

Exports are delivered via a secure, time-limited download link protected by access controls. Very large exports may be delivered in staged parts. Nexwift retains an audit record of the export request, the operator who authorised it, and confirmation of successful delivery.

5.4 Fees

  • Standard exports (routine termination export, periodic operational exports of ordinary volume) are included in the subscription at no additional charge.
  • Extraordinary volumes — for example, repeated large-scale re-exports, exports requiring bespoke transformation, or exports of unusually large recording archives outside the standard retention window — may attract a commercial handling fee, agreed in writing before the work is performed. Nexwift will not withhold a routine termination export on cost grounds.

6. No lock-in

Nexwift's commitment to open, industry-standard export formats is intended to give the customer a practical exit path at all times. The customer is free to migrate to another provider, to a self-hosted alternative, or to discontinue the service, without dependency on Nexwift for the ongoing readability of exported Customer Content.


7. Deletion after termination

  • Following confirmed delivery of the termination export (or expiry of the export request window under §5.1 with no export requested), Nexwift deletes Customer Content from live systems within 30 days.
  • Copies present in routine backups persist only until those backups expire under the documented backup retention window, and remain protected by the same confidentiality and security obligations until deletion.
  • The customer may set shorter retention for specific categories of Customer Content in the Data Processing Agreement or by written instruction; the customer's instruction overrides Nexwift's defaults where it requires shorter retention.
  • Nexwift may retain aggregated and de-identified operational metrics (as defined in §4) for continued service improvement.
  • Nexwift may also retain the minimum records required by applicable law (for example, invoicing and tax records) and records subject to a legal hold, protected under the same confidentiality regime and deleted on expiry of the applicable obligation.

Nexwift will provide, on request, a written confirmation of deletion.


8. Voice and video — additional detail

Because voice and video introduce sensitivities that text alone does not, the following clarifications apply.

  • The customer decides whether to record audio, transcripts, video, or any combination, and per which use case, through the platform's documented configuration.
  • Beneficiary notice and consent are the customer's responsibility as the party interacting with the individual. Nexwift provides configurable disclosures (for example, opening announcements on voice calls) but does not adjudicate the legal sufficiency of the customer's notice.
  • Voice AI is not an emergency service. The customer must not deploy voice agents as a substitute for emergency services (police, ambulance, civil defence) and must configure appropriate signposting in the agent's prompt.
  • Ownership and export of recordings and transcripts follow §3 and §5. Deletion on termination follows §7.

9. AI outputs — advisory only

Outputs generated by the platform's AI components are provided on a commercially reasonable, best-effort basis and are advisory. They must not be relied on as medical, legal, financial, or professional advice. The customer is responsible for reviewing and, where appropriate, human-approving AI outputs before they are acted on. Nothing in this document alters the allocation of risk for AI outputs set out in the Master Agreement.


10. Where data is processed

Customer Content is processed on infrastructure operated by EU-based cloud infrastructure provider(s) within the European Union. AI inference is performed via AI inference provider(s) under contracts that exclude customer inputs from provider model training. Voice and video transport is delivered via telephony provider(s) and WebRTC/media infrastructure provider(s). Messaging channel content is exchanged with messaging channel platform(s) that the customer has connected under the customer's own accounts. Operational telemetry is transmitted to error monitoring provider(s) in EU regions with personally identifying information scrubbed at source.

Sub-processor categories, and material changes to them, are notified in accordance with the Data Processing Agreement.


11. Suspension and termination — protective reservations

Nexwift may suspend access on reasonable grounds — including non-payment, breach of the Acceptable Use Policy, or a demonstrated security risk to the platform or its other customers — without prejudice to the customer's export and deletion rights under this statement. Nexwift will use commercially reasonable efforts to preserve the customer's ability to export Customer Content during any suspension imposed for non-security reasons.

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms. Rights and obligations that are load-bearing for the customer's export and deletion pathway — the availability of an export, the formats above, the 30-day export window on termination, and the deletion commitment — will not be materially reduced without the customer's agreement.


12. Liability and remedies

The customer's rights under this statement are provided subject to the limitations and remedies set out in the Master Agreement. Service credits, where applicable to availability shortfalls under the Service Level Agreement, are the customer's sole financial remedy for those shortfalls, without prejudice to termination rights for sustained material breach. Force majeure events, third-party outages beyond Nexwift's reasonable control, and events attributable to the customer are excluded from Nexwift's liability, without in any way narrowing the export and deletion obligations set out above.


13. Governing law and jurisdiction

This statement is governed by the laws of the Kingdom of Saudi Arabia. Any dispute arising in connection with it is subject to the exclusive jurisdiction of the competent Saudi courts and authorities.


14. Contact

Purpose Address
Data protection matters (attn: Data Protection Officer) info@nexwift.com
Export requests, deletion requests, and portability questions info@nexwift.com (attn: DPO)

Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.


End of document.

Launch login modal Launch register modal