Privacy Policy
| Field | Value |
|---|---|
| Document ID | NXW-PUB-PRIVACY-POLICY |
| Version | 1.0 |
| Issue Date | 2026-01-01 |
| Next Review | 2027-01-01 |
| Owner | Data Protection Officer |
| Classification | Public |
1. Introduction and Scope
Nexwift ("we", "us", "Nexwift") provides the Aram conversational AI platform to enterprise customers, together with the corporate website and related billing and support services. This Privacy Policy explains how we process personal data in each of those settings, the roles we take under the Kingdom of Saudi Arabia's Personal Data Protection Law (the "PDPL"), and the rights available to data subjects.
This notice applies to:
- Visitors to Nexwift websites and Trust Center resources.
- Authorised users of the Aram customer dashboard (staff of our customer organisations).
- End users who interact with a customer's deployment of the Aram platform over text, voice, or video channels ("beneficiaries").
- Prospects and contacts communicating with Nexwift for commercial or support purposes.
2. Our Role: Controller and Processor
Nexwift is committed to compliance with the PDPL, the implementing regulations issued by SDAIA, and any subsequent guidance issued by the Saudi competent authority.
| Scenario | Nexwift's Role | Controller |
|---|---|---|
| Website visits, marketing, prospect enquiries, billing, contract administration | Data Controller | Nexwift |
| Personal data processed through a customer's Aram deployment (text conversations, voice or video interactions, associated recordings and transcripts, knowledge-base content) | Data Processor | The customer organisation |
| Employees, contractors and operational telemetry | Data Controller | Nexwift |
For services delivered through the Aram platform, Nexwift processes personal data only on the documented instructions of the customer Controller, as set out in the applicable Data Processing Agreement. Nothing in this statement displaces the customer Data Controller's primary responsibility under PDPL for its own beneficiaries.
3. Categories of Personal Data
| Category | Examples |
|---|---|
| Website visitor data | IP address, browser type, pages visited, referrer, session duration |
| Dashboard user data | Name, work email, role, authentication events, actions taken |
| Beneficiary contact data | Channel handle (e.g., phone number, messaging identifier), display name where provided |
| Text conversation content | Inbound and outbound messages, attachments, timestamps |
| Voice interaction data | Call metadata (time, duration, direction); voice recordings and transcripts where the customer has enabled recording |
| Video interaction data | Session metadata; video recordings and transcripts where the customer has enabled recording |
| Knowledge-base content | Customer-supplied documents used to ground AI responses (which may contain personal data supplied by the customer) |
| Billing and commercial data | Company details, invoicing contacts, payment references |
4. Lawful Basis for Processing
We rely on the following bases under PDPL:
- Contractual necessity — to provide the services described in the customer's Master Agreement, or to respond to a prospect's request.
- Legitimate interest — to secure our services, prevent abuse, maintain operational telemetry, and improve platform quality on a de-identified basis.
- Legal obligation — tax, accounting, and regulatory record-keeping.
- Consent — where required (for example, non-essential website cookies, or optional marketing communications). Consent may be withdrawn at any time.
- Documented Controller instructions — where Nexwift acts as Processor, the lawful basis is determined by the customer Controller and reflected in the Data Processing Agreement.
Processing is limited to specified, explicit, and legitimate purposes. Repurposing requires a fresh lawful basis.
5. How the Aram Platform Handles Conversations
The Aram platform does not request personal identifiers from beneficiaries by default. Outbound queries to AI inference providers carry only the minimum data required to generate a response — typically the message text, retrieved knowledge-base context, and the system prompt. Logging and operational telemetry exclude personal data by default.
5.1 Text Conversations
Text conversations across messaging channels are routed through the platform, presented to the customer's staff in the dashboard, and — where the customer has enabled AI-assisted or AI-automated responses — processed for reply generation. Conversation content is stored for the retention period agreed with the customer.
5.2 Voice Interactions
Where a customer enables voice channels, calls are transported over telephony or WebRTC infrastructure and may involve AI-assisted response generation. Recording and transcription of voice interactions are optional and are configured by the customer. Where enabled, recordings and transcripts are stored subject to the customer's configured retention. The Aram voice service is not an emergency service and must not be relied on for time-critical safety-of-life communications.
5.3 Video Interactions
Where a customer enables video channels, sessions are transported over WebRTC infrastructure and may involve AI-assisted interaction. Recording and transcription of video interactions are optional and are configured by the customer. Where enabled, recordings and transcripts are stored subject to the customer's configured retention.
5.4 Customer Responsibility for Beneficiary Notice and Consent
The customer, as Data Controller, is responsible for notifying its beneficiaries of the use of AI, the categories of personal data collected, and — where recording of voice or video is enabled — for obtaining any consent or providing any notice required under applicable law before the interaction proceeds.
6. Data Ownership
The customer owns its customer data, configurations, knowledge-base content, transcripts, recordings, and generated summaries. Nexwift owns the Aram platform, its models, and aggregated operational telemetry that does not identify any individual.
7. Website Analytics
We use analytics on the corporate website to understand aggregate traffic patterns and improve content. Non-essential analytics and marketing cookies are set only where you consent through the cookie banner. You may decline non-essential cookies without losing access to the site.
8. Sub-Processors
Where Nexwift acts as Processor, we engage a limited set of sub-processors under written agreements imposing data-protection obligations substantially equivalent to those in our Data Processing Agreements. Sub-processors are organised in the following categories:
- EU-based cloud infrastructure provider(s) — compute, network, storage, and backup.
- AI inference provider(s) — hosted large-language-model and embeddings APIs for response generation and retrieval.
- Messaging channel platform(s) — for transport of messages on public channels used by the customer.
- Telephony provider(s) — where voice channels are enabled.
- WebRTC/media infrastructure provider(s) — for real-time voice and video transport.
- Error monitoring provider(s) — EU-region-hosted, with personal data scrubbed at source before transmission.
Nexwift remains liable for the performance of its sub-processors' data-protection obligations. Customers may request the current sub-processor register through their account contact. Sub-processor governance, including notice of changes, is addressed in the applicable Data Processing Agreement.
9. International Transfers
The Aram platform is hosted on infrastructure located outside the Kingdom of Saudi Arabia. Cross-border transfers of personal data are conducted in accordance with PDPL and its implementing regulations, and rely on the transfer mechanisms recognised by SDAIA — including, where required, appropriate contractual safeguards, purpose limitation, and, where applicable, the data subject's explicit consent or another lawful basis. Where a customer requires KSA-resident processing, this is available as a separately scoped engagement subject to a signed statement of work. Any onward transfer by a sub-processor is governed by the contractual safeguards described in Section 8.
10. Retention
Personal data is retained only as long as necessary for the purpose for which it was collected, plus any legally required retention. Customer-specific retention requirements set out in a Data Processing Agreement override the defaults where they require shorter retention. At end of retention, data is securely deleted using methods appropriate to its classification. On-request deletion is executed within 30 days of a confirmed request, subject to any overriding legal retention. Backup copies expire under the documented backup retention window.
For beneficiary conversation content (including voice and video recordings and transcripts where enabled), the applicable period is defined in the customer's Data Processing Agreement.
11. Security
We maintain a documented information-security programme aligned to international standards, including encryption in transit and at rest (TLS 1.2 or higher; AES-256-GCM at rest), multi-factor authentication for administrative access, role-based access control and least privilege, audit logging and monitoring, backup and recovery, incident response, vulnerability scanning and remediation, and personnel training.
No security programme can guarantee absolute protection against all threats. In the event of a personal-data breach affecting Nexwift-controlled data, we will notify affected data subjects and the competent supervisory authority in accordance with the timelines and thresholds specified by PDPL and its implementing regulations. Where Nexwift acts as Processor, we will notify the customer Controller without undue delay after becoming aware of a breach affecting personal data processed on their behalf, and support the Controller in meeting its own notification obligations.
12. Your PDPL Rights
Subject to PDPL and applicable exceptions, data subjects have the right to:
| Right | Description |
|---|---|
| Access | Obtain confirmation of processing and a copy of personal data held. |
| Rectification | Request correction of inaccurate or incomplete personal data. |
| Erasure | Request deletion of personal data where the legal basis no longer applies. |
| Restriction | Request that processing be temporarily limited. |
| Objection | Object to processing based on legitimate interest. |
| Portability | Receive personal data in a structured, commonly used format where technically feasible. |
| Withdraw Consent | Where processing is based on consent, withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal. |
| Automated Decision-Making | Request human review of, and object to, decisions producing legal or similarly significant effects that would be based solely on automated processing. |
13. How to Exercise Your Rights
- Beneficiaries of a customer's deployment: please contact the customer organisation directly, as that organisation is the Data Controller for your data. Nexwift will support the customer in responding without undue delay.
- Website visitors, prospects, dashboard users, and other data subjects for whom Nexwift is the Controller: please contact us at the address below. Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.
We may request reasonable information to verify identity before acting on a request.
14. AI Safety Notice
AI-generated outputs are advisory and are provided for informational and transactional purposes only. They may be incomplete, inaccurate, or otherwise unsuitable for a particular purpose, and they do not constitute medical, legal, or financial advice. AI outputs must not be relied upon for time-critical safety-of-life decisions. The Aram voice service is not an emergency service and must not be used for emergency communications.
The platform is designed to keep a human in the loop for consequential decisions: Nexwift does not use the personal data processed through the Aram platform to take decisions producing legal or similarly significant effects about a beneficiary based solely on automated processing. Where a public-channel reply is generated by AI, the customer may require staff review and approval before publication.
15. Children's Data
The Aram platform is not directed at, and Nexwift does not knowingly collect personal data from, children under the age of 18 without an appropriate lawful basis (including verified parental or guardian consent where required). Where a customer's deployment interacts with minors, the customer, as Data Controller, is responsible for verifying age, obtaining any required parental or guardian consent, and providing age-appropriate notice.
16. Governing Law and Jurisdiction
This Privacy Policy and any dispute arising out of it are governed by the laws of the Kingdom of Saudi Arabia. The competent Saudi courts and authorities have jurisdiction. This Privacy Policy does not create rights or remedies beyond those provided under PDPL and other applicable law; nothing in it operates as a warranty or an amendment to any contract between Nexwift and its customers, which continues to be governed by its own terms.
17. Complaints
If you believe your personal data has been processed in breach of PDPL, you may lodge a complaint with the Saudi Data & AI Authority (SDAIA) as the competent supervisory authority. We encourage you to contact us first so that we have an opportunity to address your concern.
18. Changes to This Policy
Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.
19. Contact
Data Protection Officer, Nexwift
Email: info@nexwift.com (attn: Data Protection Officer)
Postal address: available on the Nexwift corporate website.