Nexwift360

سياسة الخصوصية

Privacy Policy — Nexwift360

كيف تعالج نكسويفت البيانات الشخصية في منصّة نكسويفت360، بموجب نظام حماية البيانات الشخصية في المملكة العربية السعودية (PDPL).

معرّف الوثيقةNXW360-PUB-PRIVACY-POLICY
رقم النسخة1.0
تاريخ الإصدار2026-09-21
المراجعة القادمة2027-09-21
المالكمسؤول حماية البيانات
التصنيفعامّة

هذه السياسة تخصّ منصّة نكسويفت360 وحدها. ارتباطات منصّة آرام منتج منفصل تحكمه سياسة الخصوصية المنشورة في مركز الثقة على nexwift.com/en/trust-center/privacy-policy/.

النصّ الإنجليزي أدناه هو النصّ المُلزِم قانوناً. الوثائق النظامية في نكسويفت تُنشر بالإنجليزية بسياسة الشركة القائمة، وهذه المقدّمة العربية للإيضاح فقط.

ملخّص عربي: نكسويفت مُتحكِّمة في بيانات زوّار الموقع والفوترة، ومُعالِجة لبيانات محادثات عملائك بتعليمات موثّقة منك · بيانات بطاقتك لا تصل خوادمنا إطلاقاً — تُدخَل مباشرةً لدى مزوّد الدفع المرخّص، ولا نحتفظ إلا بمرجع دفع مبهم وسجلّات الفواتير · لا نستقبل ولا نخزّن رقم البطاقة الكامل ولا تاريخ الانتهاء ولا رمز الأمان · التشفير أثناء النقل وفي التخزين، والحذف عند الطلب خلال 30 يوماً · حقوقك بموجب النظام السعودي: الاطّلاع والتصحيح والحذف والتقييد والاعتراض ونقل البيانات وسحب الموافقة · للشكاوى: الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا).

1. Introduction and Scope

Nexwift ("we", "us", "Nexwift") provides the Nexwift360 platform, a self-service subscription service through which a customer hires AI employees that respond to the customer's own end customers across connected channels. This Privacy Policy explains how we process personal data in connection with the Nexwift360 platform and website and the related billing and support services, the roles we take under the Kingdom of Saudi Arabia's Personal Data Protection Law (the "PDPL"), and the rights available to data subjects.

This Policy applies to the Nexwift360 platform only. Aram engagements are a separate product and are governed by the Nexwift Privacy Policy published in the Trust Center at https://nexwift.com/en/trust-center/privacy-policy/.

This notice applies to:

  • Visitors to the Nexwift360 website.
  • Authorised users of the Nexwift360 dashboard (staff of our customer organisations).
  • End users who interact with a customer's Nexwift360 deployment over connected messaging channels ("beneficiaries").
  • Prospects and contacts communicating with Nexwift for commercial or support purposes.

2. Our Role: Controller and Processor

Nexwift is committed to compliance with the PDPL, the implementing regulations issued by SDAIA, and any subsequent guidance issued by the Saudi competent authority.

ScenarioNexwift's RoleController
Website visits, marketing, prospect enquiries, billing, contract administrationData ControllerNexwift
Personal data processed through a customer's Nexwift360 deployment (conversations, attachments and associated content, knowledge-base content)Data ProcessorThe customer organisation
Employees, contractors and operational telemetryData ControllerNexwift

For services delivered through the Nexwift360 platform, Nexwift processes personal data only on the documented instructions of the customer Controller, as set out in the applicable Data Processing Agreement published in the Nexwift Trust Center. Nothing in this statement displaces the customer Data Controller's primary responsibility under PDPL for its own beneficiaries.

3. Categories of Personal Data

CategoryExamples
Website visitor dataIP address, browser type, pages visited, referrer, session duration
Dashboard user dataName, work email, role, authentication events, actions taken
Beneficiary contact dataChannel handle (e.g., phone number, messaging identifier), display name where provided
Text conversation contentInbound and outbound messages, attachments, timestamps
Knowledge-base contentCustomer-supplied documents used to ground AI responses (which may contain personal data supplied by the customer)
Billing and commercial dataCompany details, invoicing contacts, payment references

4. Billing and Payment Data

Where a Customer pays by card, card details are entered directly into the licensed payment provider's environment and never reach Nexwift systems. Nexwift retains only an opaque payment reference issued by the provider, sufficient to charge a subsequent cycle and to reconcile a payment, together with invoice records. Full card numbers, expiry dates and security codes are neither received nor stored. Invoice records are retained for the period required by applicable tax legislation in the Kingdom of Saudi Arabia.

5. Lawful Basis for Processing

We rely on the following bases under PDPL:

  • Contractual necessity — to provide the services described in the customer's agreement with Nexwift, being for Nexwift360 the Subscription Terms, or to respond to a prospect's request.
  • Legitimate interest — to secure our services, prevent abuse, maintain operational telemetry, and improve platform quality on a de-identified basis.
  • Legal obligation — tax, accounting, and regulatory record-keeping.
  • Consent — where required (for example, non-essential website cookies, or optional marketing communications). Consent may be withdrawn at any time.
  • Documented Controller instructions — where Nexwift acts as Processor, the lawful basis is determined by the customer Controller and reflected in the Data Processing Agreement.

Processing is limited to specified, explicit, and legitimate purposes. Repurposing requires a fresh lawful basis.

6. How the Nexwift360 Platform Handles Conversations

The Nexwift360 platform does not request personal identifiers from beneficiaries by default. Outbound queries to AI inference providers carry only the minimum data required to generate a response — typically the message text, retrieved knowledge-base context, and the system prompt. Logging and operational telemetry exclude personal data by default.

6.1 Text Conversations

Text conversations across connected messaging channels are routed through the platform, presented to the customer's staff in the dashboard, and — where the customer has enabled AI-assisted or AI-automated responses — processed for reply generation. Conversation content is stored for the applicable retention period.

6.2 Customer Responsibility for Beneficiary Notice and Consent

The customer, as Data Controller, is responsible for notifying its beneficiaries of the use of AI and of the categories of personal data collected, and for obtaining any consent or providing any notice required under applicable law before the interaction proceeds.

7. Data Ownership

The customer owns its customer data, configurations, knowledge-base content, transcripts, and generated summaries. Nexwift owns the Nexwift360 platform, its models, and aggregated operational telemetry that does not identify any individual.

8. Website Analytics

We use analytics on the website to understand aggregate traffic patterns and improve content. Non-essential analytics and marketing cookies are set only where you consent through the cookie banner. You may decline non-essential cookies without losing access to the site.

9. Sub-Processors

Where Nexwift acts as Processor, we engage a limited set of sub-processors under written agreements imposing data-protection obligations substantially equivalent to those in our Data Processing Agreements. Sub-processors are organised in the following categories:

  • EU-based cloud infrastructure provider(s) — compute, network, storage, and backup.
  • AI inference provider(s) — hosted large-language-model and embeddings APIs for response generation and retrieval.
  • Messaging channel platform(s) — for transport of messages on public channels used by the customer.
  • Error monitoring provider(s) — EU-region-hosted, with personal data scrubbed at source before transmission.

Nexwift remains liable for the performance of its sub-processors' data-protection obligations. Customers may request the current sub-processor register through their account contact. Sub-processor governance, including notice of changes, is addressed in the applicable Data Processing Agreement published in the Nexwift Trust Center.

10. International Transfers

The Nexwift360 platform is hosted on infrastructure located outside the Kingdom of Saudi Arabia. Cross-border transfers of personal data are conducted in accordance with PDPL and its implementing regulations, and rely on the transfer mechanisms recognised by SDAIA — including, where required, appropriate contractual safeguards, purpose limitation, and, where applicable, the data subject's explicit consent or another lawful basis. Any onward transfer by a sub-processor is governed by the contractual safeguards described in Section 9.

11. Retention

Personal data is retained only as long as necessary for the purpose for which it was collected, plus any legally required retention. Customer-specific retention requirements set out in a Data Processing Agreement override the defaults where they require shorter retention. At end of retention, data is securely deleted using methods appropriate to its classification. On-request deletion is executed within 30 days of a confirmed request, subject to any overriding legal retention. Backup copies expire under the documented backup retention window.

Invoice and payment records are retained for the period required by applicable tax legislation in the Kingdom of Saudi Arabia, as set out in Section 4.

12. Security

We maintain a documented information-security programme aligned to international standards, including encryption in transit and at rest (TLS 1.2 or higher; AES-256-GCM at rest), multi-factor authentication for administrative access, role-based access control and least privilege, audit logging and monitoring, backup and recovery, incident response, vulnerability scanning and remediation, and personnel training. The programme and its supporting documentation are published in the Nexwift Trust Center.

No security programme can guarantee absolute protection against all threats. In the event of a personal-data breach affecting Nexwift-controlled data, we will notify affected data subjects and the competent supervisory authority in accordance with the timelines and thresholds specified by PDPL and its implementing regulations. Where Nexwift acts as Processor, we will notify the customer Controller without undue delay after becoming aware of a breach affecting personal data processed on their behalf, and support the Controller in meeting its own notification obligations.

13. Your PDPL Rights

Subject to PDPL and applicable exceptions, data subjects have the right to:

RightDescription
AccessObtain confirmation of processing and a copy of personal data held.
RectificationRequest correction of inaccurate or incomplete personal data.
ErasureRequest deletion of personal data where the legal basis no longer applies.
RestrictionRequest that processing be temporarily limited.
ObjectionObject to processing based on legitimate interest.
PortabilityReceive personal data in a structured, commonly used format where technically feasible.
Withdraw ConsentWhere processing is based on consent, withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Automated Decision-MakingRequest human review of, and object to, decisions producing legal or similarly significant effects that would be based solely on automated processing.

14. How to Exercise Your Rights

  • Beneficiaries of a customer's deployment: please contact the customer organisation directly, as that organisation is the Data Controller for your data. Nexwift will support the customer in responding without undue delay.
  • Website visitors, prospects, dashboard users, and other data subjects for whom Nexwift is the Controller: please contact us at the address below. Nexwift will acknowledge and respond to data subject requests within the timeframes required by applicable law.

We may request reasonable information to verify identity before acting on a request.

15. AI Safety Notice

AI-generated outputs are advisory and are provided for informational and transactional purposes only. They may be incomplete, inaccurate, or otherwise unsuitable for a particular purpose, and they do not constitute medical, legal, or financial advice. AI outputs must not be relied upon for time-critical safety-of-life decisions.

The platform is designed to keep a human in the loop for consequential decisions: Nexwift does not use the personal data processed through the Nexwift360 platform to take decisions producing legal or similarly significant effects about a beneficiary based solely on automated processing. Where a public-channel reply is generated by AI, the customer may require staff review and approval before publication.

16. Children's Data

The Nexwift360 platform is not directed at, and Nexwift does not knowingly collect personal data from, children under the age of 18 without an appropriate lawful basis (including verified parental or guardian consent where required). Where a customer's deployment interacts with minors, the customer, as Data Controller, is responsible for verifying age, obtaining any required parental or guardian consent, and providing age-appropriate notice.

17. Governing Law and Jurisdiction

This Privacy Policy and any dispute arising out of it are governed by the laws of the Kingdom of Saudi Arabia. The competent Saudi courts and authorities have jurisdiction. This Privacy Policy does not create rights or remedies beyond those provided under PDPL and other applicable law; nothing in it operates as a warranty or an amendment to any contract between Nexwift and its customers, which continues to be governed by its own terms.

18. Complaints

If you believe your personal data has been processed in breach of PDPL, you may lodge a complaint with the Saudi Data & AI Authority (SDAIA) as the competent supervisory authority. We encourage you to contact us first so that we have an opportunity to address your concern.

19. Changes to This Policy

Nexwift may update these terms from time to time. The current version is always available at this URL. Continued use of the platform after publication constitutes acceptance of the updated terms.

20. Contact

Data Protection Officer, Nexwift — info@nexwift.com (attn: Data Protection Officer).

EntityNexwift Company, a limited liability company registered in the Kingdom of Saudi Arabia (شركة نكسويفت)
Unified National Number7050458475
VAT Registration Number313081524800003
AddressAnas Bin Malik, Al Yasmeen District, Riyadh 13326, Kingdom of Saudi Arabia
Emailinfo@nexwift.com

روابط ذات صلة: