Voice & Video Recording Notice

Nexwift

About Nexwift Saudi AI company Aram contact Nexwift Careers at Nexwift blog
Voice & Video Recording Notice

Voice & Video Recording Notice

Field Value
Document ID NXW-PUB-VOICE-VIDEO-RECORDING-NOTICE
Version 1.0
Issue Date 2026-01-01
Next Review 2027-01-01
Owner Data Protection Officer
Classification Public

1. Purpose and Scope

This notice explains how the Aram platform ("Aram") operated by Nexwift ("Nexwift", "we") handles voice calls, video sessions, associated recordings, and machine-generated transcripts. It applies to all voice and video features offered through Aram, including telephony calls carried over SIP, browser-based real-time voice and video sessions, and any AI-generated transcript, summary, or diarised text derived from those media streams.

This notice is directed at three audiences:

  • Customers (Data Controllers) who operate an Aram workspace and configure whether recording is enabled.
  • Beneficiaries (end users) who interact with a customer through a voice or video channel powered by Aram.
  • Regulators and researchers conducting due diligence on Nexwift's public compliance posture.

Nexwift acts as a Data Processor on the customer's documented instructions for voice, video, recording, and transcript data. The customer remains the Data Controller and retains primary responsibility under the Kingdom of Saudi Arabia's Personal Data Protection Law ("PDPL") and any other applicable law.

2. Recording Is Optional and Customer-Configured

Whether Aram captures and retains audio, video, or a transcript for any given interaction is determined by the customer's configuration.

Configuration point Controlled by Effect
Recording enabled per channel Customer administrator in the Aram dashboard Determines whether the channel produces recordings at all
Media captured (audio only / audio + video) Customer administrator Determines the format retained
Transcript generation Customer administrator Determines whether an AI-generated transcript is produced from the media
Retention window for recordings and transcripts Customer administrator, subject to the Data Processing Agreement Determines how long the customer's copy is retained before scheduled deletion
Beneficiary consent notice text Customer administrator The wording the customer chooses to present to the beneficiary

If the customer disables recording at the workspace or channel level, no audio, video, or transcript is retained for interactions on that channel. Real-time media may still be transported end-to-end for the duration of the live session so the interaction can take place, but nothing is written to persistent storage on the customer's behalf.

3. Consent Is the Customer's Responsibility

Under PDPL Article 8 (transparency) and applicable local law, the party interacting with the beneficiary is responsible for informing that beneficiary — before the interaction begins — that the call or session may be recorded, that AI may be used to transcribe or summarise it, and how their personal data will be handled.

Because the customer is the Data Controller and the party in the relationship with the beneficiary, the customer is responsible for:

  • Displaying or playing a consent notice at the start of each interaction where recording is enabled.
  • Obtaining any consent, opt-in, or opt-out that applicable law requires, including where the customer or the beneficiary is located in a jurisdiction that requires the consent of all parties to a recording ("two-party" or "all-party" consent) rather than one-party consent.
  • Ensuring their own privacy notice reflects the use of AI, transcription, and recording where enabled.
  • Determining the lawful basis for processing and documenting it.
  • Honouring any beneficiary request to decline recording, and providing a non-recorded alternative interaction path where required by applicable law.

Nexwift provides the technical means (configurable prompts, disclosure templates on request, per-channel controls) but does not itself communicate with beneficiaries and does not authenticate any consent captured through those means.

4. Recordings and Transcripts Are Customer Data

Recordings, video captures, AI-generated transcripts, diarised speaker labels, and derived summaries produced from a customer's voice or video interactions are Customer Data. Ownership follows the general framing in our Data Ownership Notice:

  • The customer owns customer data, customer configurations, knowledge-base content, transcripts, recordings, and summaries.
  • Nexwift owns the platform, the models it builds, and aggregated, de-identified operational telemetry.

Nexwift processes Customer Data only on the customer's documented instructions, within the technical scope of the Aram service, and does not use Customer Data to train foundation models or shared AI systems.

Voice data and biometrics. Voice and video recordings can, depending on the processing performed on them, constitute sensitive personal data under PDPL Article 6 and comparable provisions of other applicable laws. Nexwift does not perform voice-print enrolment, speaker identification against a biometric template, face recognition, or any other biometric identification or authentication on Customer Data in the ordinary course of providing the Aram service. Speaker diarisation (labelling that distinguishes between speakers within a single interaction) is a session-scoped separation and is not a biometric identifier.

5. Storage, Formats, and Retention

Where recording is enabled, media is stored in industry-standard container and codec formats configurable per customer environment. Transcripts are stored as structured text with timestamps and, where enabled, speaker labels.

Retention is configurable per customer and set out in the Data Processing Agreement. Defaults referenced in our public Data Retention framing:

Data category Default retention
Beneficiary voice/video interaction transcripts As specified in the DPA (typical 90 days to 2 years)
AI reasoning traces (intermediate prompts, retrieval logs) 30 days
Application audit logs 12 months
Backups (encrypted, rolling window) 30 days

At the end of the retention window, data is securely deleted. On the customer's documented request, deletion is executed within 30 days of confirmed request, subject to any overriding legal retention. Backup copies expire under the documented backup retention window; where the customer requires immediate deletion from backups, the affected backup chain is cryptographically destroyed.

6. Access, Encryption, and Security

Access to recordings and transcripts is restricted to:

  • Authorised users of the customer's own Aram dashboard, subject to role-based access control configured by the customer administrator.
  • A designated Nexwift support role, on a strict need-to-know basis, only when required to investigate a support ticket the customer has raised or a confirmed incident, and always subject to audit logging.

Nexwift personnel do not routinely listen to recordings, read transcripts, or perform automated content analysis of Customer Data. All administrative access is protected by multi-factor authentication and least-privilege role assignment.

Control Implementation
Encryption in transit TLS 1.2 or higher for all customer-facing endpoints
Encryption at rest AES-256-GCM for stored media and transcripts
Access control RBAC + least privilege; MFA for administrative access
Audit logging Access to recordings and transcripts is logged and available to the customer on request
Hosting region Processing infrastructure operated by EU-based cloud infrastructure provider(s); European Union residency by default
KSA-resident processing Available as a separately-scoped engagement
Personal-data breach notification Notification to the affected customer without undue delay after Nexwift becomes aware of a confirmed personal-data breach, and in any event within seventy-two (72) hours where feasible, with follow-up information as it becomes available
Cross-border transfer safeguards Where personal data is transferred outside the customer's jurisdiction of collection, appropriate safeguards apply (Standard Contractual Clauses or equivalent) as documented in the Data Processing Agreement

7. AI Transcription Accuracy

Transcripts and summaries are generated by AI inference provider(s) selected by Nexwift and, on documented customer requirement, restrictable to a specified provider set or residency region.

Users should be aware that:

  • AI-generated transcripts may contain errors, including misheard words, incorrect speaker attribution, and omissions — particularly in noisy conditions, with strong accents, on low-bandwidth calls, or in code-switched speech.
  • Transcripts and summaries are not a legal record of the interaction. Where a legal record is required, the underlying audio or video (if recorded) is the primary source, subject to the customer's own evidentiary processes.
  • AI outputs must not be used as the sole basis for high-stakes decisions — such as legal, medical, financial, employment, safety-critical, immigration, or law-enforcement decisions — without meaningful human review by a qualified person.
  • AI outputs are advisory. Nexwift does not provide medical, legal, or financial advice through Aram, and voice and video AI features must not be relied upon as a substitute for professional advice.
  • No automated decision-making with legal effect. The Aram voice and video features are not designed to produce, on their own, decisions that have a legal or similarly significant effect on the beneficiary within the meaning of applicable data-protection law.

8. Not an Emergency Service

The voice and video features of Aram are not a substitute for emergency services. They do not provide, and are not designed to provide, connectivity to emergency numbers, first responders, or crisis intervention services. Beneficiaries in an emergency must contact the appropriate local emergency service directly.

9. Export and Deletion Rights

Consistent with our Data Ownership framing, customers can:

  • Export recordings and transcripts held in the customer's Aram workspace, in the formats supported by the platform.
  • Delete individual recordings and transcripts, or request bulk deletion, through their administrator.
  • Terminate the service and request return-or-destruction of Customer Data, subject to (a) one archival copy retained for legal compliance and (b) copies in routine backups, which remain protected by the applicable Data Processing Agreement until backup expiry.

Following termination, Customer Data held in active systems is made available for export for a defined window (typically thirty (30) days from the effective date of termination) after which it is scheduled for deletion in accordance with Section 5, subject to the archival and backup exceptions above.

Data-subject requests (access, rectification, erasure) from beneficiaries are handled by the customer as Data Controller; Nexwift supports the customer in fulfilling those requests within the timeframes required by applicable law.

10. Sub-Processors

Recording, real-time media transport, transcription, and storage rely on categorical sub-processors — EU-based cloud infrastructure provider(s), WebRTC/media infrastructure provider(s), telephony provider(s) where SIP is used, and AI inference provider(s) for transcription and summarisation. Nexwift imposes on each sub-processor data-protection obligations substantially equivalent to those in the Data Processing Agreement and notifies customers of material changes as governed by the Data Processing Agreement.

11. Governing Law

This notice, and any dispute concerning the voice or video features it describes, is governed by the laws of the Kingdom of Saudi Arabia. The competent Saudi courts and authorities have jurisdiction. Nothing in this notice displaces the customer Data Controller's primary responsibility under PDPL or any other applicable law.

12. Reservations

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms. Commitments described here are made on a commercially reasonable efforts basis. Financial remedies for service-level shortfalls are governed exclusively by the Service Level Agreement, where service credits are the customer's sole financial remedy. Scheduled maintenance, customer-caused issues, third-party platform outages outside our control, and force majeure are excluded. Nexwift reserves the right to suspend service for acceptable-use, non-payment, or security-risk reasons, and to update the sub-processor set as described in Section 10.

13. Contact and Complaints

Purpose Contact
Data protection and privacy info@nexwift.com (attn: Data Protection Officer)
Security matters info@nexwift.com (attn: Chief Information Security Officer)
General enquiries info@nexwift.com

Beneficiaries should generally address privacy concerns first to the customer with whom they are interacting, as that customer is the Data Controller. Beneficiaries also retain the right to lodge a complaint with the competent supervisory authority — in the Kingdom of Saudi Arabia, the Saudi Data and Artificial Intelligence Authority (SDAIA) — or with the competent authority in another applicable jurisdiction.

Launch login modal Launch register modal