Data Processing Agreement

Nexwift

About Nexwift Saudi AI company Aram contact Nexwift Careers at Nexwift blog
Data Processing Agreement (Template)

Data Processing Agreement (Template)

Field Value
Document ID NXW-PUB-DATA-PROCESSING-AGREEMENT
Version 1.0
Issue Date 2026-01-01
Next Review 2027-01-01
Owner Data Protection Officer
Classification Public

This template Data Processing Agreement ("DPA") is published by Nexwift as a public reference for enterprise customers of the Aram platform ("Aram"). It is intended to be countersigned as a schedule to a Master Services Agreement or equivalent principal agreement ("Master Agreement"). Where any term of this DPA conflicts with the executed Master Agreement, the Master Agreement prevails. This template does not itself create binding obligations until executed.

1. Definitions

Term Meaning
Applicable Data Protection Law The Saudi Personal Data Protection Law, its implementing regulations, and guidance issued by the competent Saudi authority; where personal data of individuals in other jurisdictions is processed, the equivalent laws of those jurisdictions to the extent applicable.
Controller The Customer identified in the Master Agreement, which determines the purposes and means of processing.
Processor Nexwift, acting on documented instructions from the Controller in respect of Customer Personal Data.
Customer Personal Data Personal data processed by Nexwift on behalf of the Controller in the provision of the Aram service, including text messages, voice recordings and transcripts, video recordings and transcripts, and related metadata.
Beneficiary The end-user (data subject) with whom the Controller interacts through Aram (for example, a customer, applicant, citizen, or member of the public).
Sub-processor A third party engaged by Nexwift to process Customer Personal Data on its behalf.
Personal Data Breach A confirmed security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

2. Roles and Scope

For processing carried out through Aram, the Controller is the Customer and Nexwift acts as Processor. Nexwift acts as an independent Controller only for its own internal data (employees, prospects, billing, operational telemetry).

The obligations in this DPA apply solely to Customer Personal Data processed under the Master Agreement and within its documented technical scope, and do not extend to any other processing by Nexwift outside that scope.

3. Subject Matter, Duration, Nature and Purpose

Subject matter. Processing of Customer Personal Data to deliver Aram's conversational, voice, and video engagement capabilities across text (messaging channels), voice (telephony and web voice), and video (web video) modalities, including AI-assisted reply generation, retrieval over Controller-supplied knowledge, supervision, analytics, and archival.

Duration. For the term of the Master Agreement, plus any post-termination period required to return or delete Customer Personal Data under Section 12.

Nature. Collection, structuring, storage, retrieval, transmission, transcription (for voice and video where enabled), generation of AI-drafted responses, human supervision, and, at the Controller's configuration, recording of voice or video sessions.

Purpose. Enabling the Controller to engage its Beneficiaries through the channels the Controller has enabled, in accordance with the Controller's own lawful purposes.

4. Categories of Data Subjects and Personal Data

Category of Data Subject Typical Categories of Personal Data
Beneficiaries interacting with the Controller through Aram Channel identifier (phone number, messaging handle, room participant identifier); message content (text, voice audio and transcript, video audio/video and transcript where recording is enabled); interaction metadata (timestamps, session identifiers, device/network attributes as provided by the channel); any personal data volunteered by the Beneficiary in the course of the conversation.
Controller personnel (supervisors, agents, administrators) Name, work email, authentication attributes, role assignments, activity logs within Aram.

Special categories not solicited. Aram is not designed to solicit special categories of personal data (health, religion, biometric, or similar). The Controller is responsible for configuring interaction flows so as not to elicit such data unnecessarily; where a Beneficiary volunteers such data, Nexwift processes it under the same technical and organisational measures as other Customer Personal Data.

5. Processor Obligations

Nexwift shall, using commercially reasonable efforts and to the extent reasonably possible in the operation of a multi-tenant service:

(a) process Customer Personal Data only on documented instructions from the Controller, including those given through the platform configuration, unless required otherwise by applicable law;

(b) ensure that persons authorised to process Customer Personal Data are bound by confidentiality;

(c) implement and maintain appropriate technical and organisational measures ("TOMs") as summarised in Section 8;

(d) assist the Controller, insofar as reasonably possible, in fulfilling its obligations to respond to data subject requests (Section 9), and to security, breach-notification, impact-assessment, and prior-consultation obligations, taking into account the nature of the processing and the information available to Nexwift; where such assistance is materially burdensome, repetitive, or manifestly unfounded, Nexwift may charge its reasonable costs on a time-and-materials basis, notified in advance;

(e) make available the information reasonably necessary to demonstrate compliance with this DPA, subject to Section 10; and

(f) engage Sub-processors only in accordance with Section 7.

6. Controller Obligations

The Controller warrants that it has a valid lawful basis for the processing it directs Nexwift to perform, and shall in particular:

(a) provide Beneficiaries with the transparency information required by Applicable Data Protection Law, including notice that AI is used to generate or assist responses;

(b) obtain any consents required for its processing purposes, including — where recording is enabled — consent to the recording of voice or video sessions;

(c) configure Aram (including channel selection, retention windows, recording, and access controls) in a manner compliant with Applicable Data Protection Law;

(d) not upload to Aram, or elicit through it, personal data that the Controller is not lawfully entitled to process; and

(e) ensure that its personnel using Aram do so under appropriate authorisation and confidentiality obligations.

7. Sub-processors

The Controller grants Nexwift a general written authorisation to engage Sub-processors within the following categories, as required to provide the service:

  • EU-based cloud infrastructure provider(s) (compute, storage, network, backup);
  • AI inference provider(s) (large-language-model and embeddings APIs);
  • Messaging channel platform(s) (where the Controller has enabled a given channel — the Controller is separately responsible for its own relationship with such platforms);
  • Telephony provider(s) (where voice via telephone is enabled);
  • WebRTC / media infrastructure provider(s) (for browser-based voice and video);
  • Error monitoring provider(s) (EU-region hosted).

Nexwift shall notify the Controller of intended additions or replacements of Sub-processors within a category in advance of material changes; emergency changes required to maintain security or service continuity shall be notified as soon as reasonably practicable. The Controller may object on reasonable data-protection grounds within the notification window; where a reasonable objection cannot be remediated by Nexwift, the parties will discuss next steps in good faith.

Nexwift shall impose on each Sub-processor data protection obligations substantially equivalent to those in this DPA. For widely-used cloud, AI, and infrastructure providers, Nexwift may contract on the provider's published standard data-processing terms, provided those terms are recognised as aligned with GDPR / PDPL standards. Nexwift remains responsible to the Controller for the performance of its Sub-processors' data protection obligations.

8. Technical and Organisational Measures

Nexwift maintains a documented set of TOMs, summarised as follows and detailed in its Information Security and Data Protection policies (a current summary is available on request):

  • encryption in transit (TLS 1.2 or above) and at rest (AES-256-GCM);
  • multi-factor authentication for administrative access;
  • role-based access control on the principle of least privilege;
  • audit logging and monitoring of privileged operations;
  • backup and recovery with encrypted, rotating backup windows;
  • documented incident-response process;
  • vulnerability management with regular scanning and remediation;
  • personnel security screening and periodic security-awareness training;
  • vendor / sub-processor due diligence.

Nexwift may update its TOMs over time, provided the level of protection is not materially reduced.

9. Data Subject Rights Assistance

Nexwift shall, insofar as reasonably possible and taking into account the nature of the processing, assist the Controller in responding to requests by data subjects to exercise their rights under Applicable Data Protection Law. Where a Beneficiary contacts Nexwift directly, Nexwift will, without responding substantively, refer the request to the Controller. Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law. Where assistance requests are materially burdensome, manifestly unfounded, or excessive (including by their repetitive character), Section 5(d) applies.

10. Audit

The Controller (or an independent auditor appointed by the Controller and subject to reasonable confidentiality undertakings) may audit Nexwift's compliance with this DPA, subject to the following:

  • Frequency. No more than once per calendar year, save for audits following a confirmed Personal Data Breach affecting the Controller or where required by the competent Saudi authority.
  • Scope of evidence. Nexwift will make available (and only) the following categories of evidence: (i) this DPA and its schedules; (ii) Nexwift's Information Security, Data Protection, and Incident Management policy summaries; (iii) current TOMs summary; (iv) sub-processor register; (v) most recent penetration-test executive summary; (vi) third-party certifications and attestations held by Nexwift or its Sub-processors. Nexwift is not obligated to produce new documents or to disclose information outside this list, except as required by applicable law or a final court order.
  • Third-party attestations. Independent third-party audit reports and certifications satisfy the audit right where they cover the relevant control area, including for Sub-processors.
  • Conduct. Audits are conducted during business hours, without unreasonable disruption to the service, and with respect for the confidentiality of other Nexwift customers.
  • Cost. Audit costs are borne by the Controller, unless the audit identifies a material breach by Nexwift attributable to it, in which case reasonable audit costs are borne by Nexwift.

11. Personal Data Breach Notification

Nexwift shall notify the Controller of a confirmed Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of confirmation. Notification may be provided in phases where complete information is not yet available, with subsequent information supplied without undue delay as it becomes known, and is limited to information reasonably known and available at the time of notification. Notification is not an acknowledgement of fault or liability.

The Controller, as data controller, is responsible for any notification to the competent supervisory authority and to affected data subjects; Nexwift will provide the information reasonably required to support such notifications.

12. Deletion or Return on Termination

On termination or expiry of the Master Agreement, Nexwift shall, at the Controller's written election notified within 30 days of termination, delete or return Customer Personal Data. Deletion or return shall be completed within 30 days of the Controller's election (or, absent an election, within 60 days of termination).

The following exceptions apply: (a) one archival copy retained where required for legal or regulatory compliance; and (b) copies present in routine encrypted backups, which remain protected by this DPA and are deleted on expiry of the applicable backup retention window. Where the Controller requires immediate deletion from backups, the affected backup chain is cryptographically destroyed.

13. International Transfers

The Aram production environment is hosted in the European Union. Where transfers of Customer Personal Data outside the Kingdom of Saudi Arabia occur in the course of providing the service, Nexwift relies on the appropriate safeguards recognised under Applicable Data Protection Law, including the equivalence framework applicable to jurisdictions offering a comparable standard of protection, and imposes contractual protections on recipients.

14. Voice and Video Specific Provisions

Where the Controller enables voice or video modalities:

  • Recording is optional and Controller-configurable. Recording of voice or video sessions is off unless the Controller enables it.
  • Consent. The Controller is responsible for informing Beneficiaries that a session may be recorded and for obtaining any consents required by applicable law.
  • Ownership. Customer Personal Data captured in voice/video sessions — including recordings, transcripts, and derived summaries — is Customer data owned by the Controller.
  • AI safety. AI-generated voice and video responses are advisory. Voice AI is not an emergency service and must not be presented to Beneficiaries as such; the Controller is responsible for configuring appropriate escalation paths.

14A. AI Output — General Disclaimer

AI-generated content produced by Aram across all modalities (text, voice, and video) is advisory in nature, may contain errors or inaccuracies, and is not a substitute for professional legal, medical, financial, or other regulated advice. The Controller is responsible for (i) reviewing and supervising AI-generated content as appropriate to its use case, (ii) informing Beneficiaries that AI is used to generate or assist responses (Section 6(a)), and (iii) configuring escalation and human-review paths suitable to the risk profile of the interactions. Nexwift does not warrant the accuracy, completeness, or fitness for a particular purpose of AI-generated outputs beyond the warranties expressly set out in the Master Agreement.

15. Data Ownership and Platform Rights

The Controller owns its Customer Personal Data, configurations, uploaded knowledge-base content, transcripts, recordings, and summaries. Nexwift owns the Aram platform, its underlying models and software, and aggregated, de-identified telemetry used to operate and improve the service.

16. Liability

The liability of the parties in connection with this DPA is subject to the limitations and exclusions of liability set out in the Master Agreement, which apply on an aggregate basis across the Master Agreement and this DPA.

17. Governing Law and Jurisdiction

This DPA is governed by the laws of the Kingdom of Saudi Arabia. The competent Saudi courts and authorities have exclusive jurisdiction, without prejudice to the competence of the Saudi supervisory authority.

18. Contact

  • Data Protection Officer: info@nexwift.com (attn: Data Protection Officer)
  • General enquiries: info@nexwift.com

Version 1.0 · Issue Date 2026-01-01 · Next Review 2027-01-01 · Classification: Public

Launch login modal Launch register modal