NAYA.ai

Responsible AI

AI Transparency Statement

How NAYA describes AI interactions, synthetic outputs, human oversight, deployment responsibilities and the limitations of automated systems.

Last updated: 30 August 2026NAYA SYSTEMS LTD · 16665484
On this page
  1. 1. What NAYA AI may do
  2. 2. NAYA’s AI and voice infrastructure
  3. 3. Beginning-of-call disclosure and human contact
  4. 4. Immediate objection, opt-out and suppression
  5. 5. Synthetic voice, generated content and limitations
  6. 6. Customer data and model training
  7. 7. Automated decisions and human oversight
  8. 8. Sensitive data, DPIAs and restricted uses
  9. 9. Outbound calling and electronic communications
  10. 10. EU AI Act qualification
  11. 11. Governance and review
  12. 12. Contact and DPO

This statement explains how NAYA uses and presents artificial intelligence in its sales and communications services, the safeguards expected in deployment and the choices available to a person interacting with a NAYA-powered workflow.

1. What NAYA AI may do

Depending on the customer’s Order and configuration, NAYA may use AI and automated workflows to answer or place calls; exchange messages; understand requests; ask qualification questions; route enquiries; create call recordings, transcripts, summaries and CRM entries; prepare follow-up; check availability; schedule meetings; and support human operators.

Not every deployment uses every feature. The customer determines the permitted purpose, workflow, audience and instructions, subject to the contract and law.

2. NAYA’s AI and voice infrastructure

NAYA’s voice and AI processing may use hosted models from OpenAI and Anthropic together with locally hosted AI on NAYA-controlled servers in Luxembourg. NAYA performs call recording, transcription and text-to-speech locally within that infrastructure.

Telnyx is used for Voice API, SMS and number purchasing and provisioning. Telnyx AI, automatic speech recognition, transcription and text-to-speech features are disabled. Twilio is used for Voice API and telephony; regional routing is configuration and provider dependent, and default or provider processing may include the United States until another regional configuration is verified.

3. Beginning-of-call disclosure and human contact

Calls processed through NAYA’s configured voice service are recorded. The configured beginning-of-call disclosure is designed to communicate substantially: “This call uses an AI assistant for [business]. It is recorded and transcribed for [purpose]. You can ask for a person or say stop at any time.” A campaign-specific variation must still identify the relevant business and, where applicable, NAYA; state the AI or synthetic-voice nature of the interaction; explain recording, transcription and purpose; and provide an accessible route to request human contact, object or opt out.

Customers must configure and test that notice before deployment and keep it accurate. In the United Kingdom, transparency and notice duties may arise from UK GDPR fairness and transparency, PECR, recording and direct-marketing rules, sector obligations and the contract. This statement does not represent that UK law creates one universal standalone AI-announcement requirement. Foreign law may impose different or additional duties.

4. Immediate objection, opt-out and suppression

A person may object, opt out or request human contact during a NAYA-powered interaction. An immediate objection or opt-out is supported and adds the telephone number to an applicable do-not-call or suppression list so the customer can prevent renewed contact.

The customer operating the campaign is normally responsible for honouring the request, maintaining suppression evidence and ensuring it is applied across relevant systems and channels. Concerns may also be sent to hello@nayaai.io with enough information to identify the interaction without including unnecessary sensitive data.

5. Synthetic voice, generated content and limitations

NAYA may generate synthetic speech or text. It must not be presented deceptively as a particular real person. Customers must not use NAYA to impersonate a person, conceal responsible caller identity, fabricate endorsements or evidence, or mislead someone about the nature or purpose of an interaction.

AI is probabilistic. It may misunderstand speech, make an incorrect inference, omit context or produce an inaccurate response. Background noise, accents, unusual names, incomplete customer materials and changing connected systems can affect performance. Customers must test workflows, review scripts and knowledge sources, monitor outcomes and maintain suitable human escalation.

6. Customer data and model training

Depending on configuration, the service may process names, contact details, CRM and lead fields, call metadata, audio, transcripts, summaries, qualification responses, scheduling information and customer-approved knowledge materials under the contract and Data Processing Addendum.

NAYA does not use Customer Personal Data, audio, transcripts, contacts or identifiable service records for general or cross-customer model training. Customer-specific AI self-training is disabled by default and may be enabled only on the customer’s documented instruction for that customer’s isolated account.

Only authorised customer personnel and authorised NAYA personnel who need access for service delivery, support, security or review may access customer leads, recordings and transcripts.

7. Automated decisions and human oversight

NAYA is intended to assist routine sales and service workflows. Customers must not use it as the sole decision maker for employment, housing, credit, insurance, healthcare, education, legal rights or access to essential services without a separate lawful assessment.

Where a deployment involves a decision based solely on automated processing that produces legal effects concerning a person or similarly significantly affects them, the customer must determine whether it is permitted and implement applicable safeguards, including meaningful information, a route to obtain human intervention, to express a point of view and to challenge the decision.

8. Sensitive data, DPIAs and restricted uses

Customers must minimise the data supplied and avoid special-category or criminal-offence data unless the Order expressly permits it, an appropriate lawful basis and applicable UK GDPR Article 9 or Data Protection Act 2018 Schedule 1 condition are documented, and appropriate safeguards are implemented. Customer authorisation alone is not such a condition.

The customer must complete a data protection impact assessment where UK GDPR Article 35 or other applicable high-risk criteria require one, including where new technology and the nature, scope, context or purposes are likely to create a high risk to people. Prior written approval and enhanced safeguards may be required for regulated or sensitive uses.

9. Outbound calling and electronic communications

For UK live marketing calls, customers must address TPS and CTPS screening, prior objections, internal suppression, caller and customer identification, permitted timing, recording, transparency and accessible opt-out duties. Valid specific permission does not remove duties that apply independently.

Automated, prerecorded, artificial-voice and AI marketing calls to UK numbers require the prior specific consent applicable under PECR regulation 19, together with separate identification, disclosure, recording, human-contact, opt-out and suppression controls. Email, SMS, WhatsApp and similar marketing messages are subject to PECR regulation 22, including applicable consent or limited existing-customer conditions, sender identification, unsubscribe and suppression.

US campaigns may be subject to TCPA, FCC and Telemarketing Sales Rule requirements, National and state do-not-call rules, caller identification, consent and revocation, calling-hour restrictions, and state AI or recording laws. Other countries may impose different rules. Customers must assess each campaign, technology, audience and geography before launch.

10. EU AI Act qualification

The EU AI Act may apply depending on territorial scope, the provider and deployer roles, the system’s capabilities and the particular use case. Requirements can vary for directly interactive systems, synthetic content, high-risk uses and prohibited practices. NAYA does not represent that every deployment falls into one category or automatically complies.

Customers must provide deployment facts needed to assess territorial reach and classification, and must not use NAYA for a prohibited or high-risk use without documented assessment, appropriate governance, transparency, human oversight and any required conformity or registration steps.

11. Governance and review

Customers should define responsible owners, escalation criteria, approved scripts and knowledge, testing, monitoring, incident handling, consent and suppression evidence, retention and review before launch. NAYA may suspend a workflow that presents a credible legal, safety, security or abuse risk.

This statement will be reviewed as services, evidence and legal requirements change. Material changes will be reflected in the updated date and communicated where required.

12. Contact and DPO

For AI, privacy or data-protection questions, email hello@nayaai.io with the subject “AI Transparency,” “Privacy Request” or “Data Protection Officer.”

Legal or privacy question?

Email NAYA’s current legal and privacy contact. Use “Privacy Request” or “DPA Request” in the subject when relevant.

hello@nayaai.io