NAYA.ai

Data Processing

Data Processing Statement

A public summary of NAYA’s Article 28-style processor commitments and the steps required to put an executed DPA in place.

Last updated: 29 August 2026NAYA SYSTEMS LTD · 16665484
On this page
  1. 1. Roles
  2. 2. Processing description
  3. 3. Documented instructions
  4. 4. Confidentiality
  5. 5. Security
  6. 6. Subprocessors
  7. 7. International transfers
  8. 8. Data-subject requests
  9. 9. Security incidents and compliance assistance
  10. 10. Deletion and return
  11. 11. Information, audits and records
  12. 12. Customer obligations
  13. 13. Requesting a DPA

This statement summarizes how NAYA SYSTEMS LTD approaches processing personal data on behalf of business customers. It is intended to support customer due diligence and contract discussions. It is not a signed data processing agreement and does not by itself satisfy Article 28 UK GDPR or EU GDPR. An executed DPA is available on request and should be put in place before regulated customer personal data is processed where required.

1. Roles

For customer-supplied lead, contact, CRM, call and scheduling data processed to deliver contracted services, the customer normally acts as controller and NAYA normally acts as processor. NAYA may act as controller for limited independent purposes such as account administration, security, fraud prevention, billing, legal compliance and establishing or defending claims.

The Order and executed DPA govern the final role allocation. A customer must not instruct NAYA to process data unlawfully.

2. Processing description

ElementTypical scope, subject to the Order
Subject matterAI-assisted voice, lead response, qualification, follow-up, scheduling, CRM synchronization, support and related service operations
DurationThe subscription term plus a limited period for return, deletion, backups, legal obligations and dispute handling
Nature and purposeHosting, transmitting, organizing, recording where enabled, transcribing, summarizing, classifying, routing, synchronizing, securing and supporting customer-directed workflows
Data subjectsCustomer prospects, leads, contacts, customers, personnel, authorised users and call participants
Personal dataNames, work details, phone numbers, email addresses, CRM and lead fields, call metadata, audio and transcripts where enabled, summaries, qualification answers, scheduling data, messages, suppression preferences and technical records
Sensitive dataNot intended unless the Order expressly authorises it and appropriate safeguards are agreed

3. Documented instructions

NAYA will process customer personal data only on documented instructions in the Order, DPA, configured workflows and written customer directions, including instructions concerning international transfers, unless law requires otherwise. If NAYA believes an instruction infringes applicable data-protection law, it will inform the customer where legally permitted.

4. Confidentiality

NAYA will ensure that personnel authorised to process customer personal data are subject to appropriate confidentiality obligations and receive access only as needed for their role.

5. Security

NAYA will maintain appropriate technical and organisational measures proportionate to processing risk. The executed DPA or security schedule should identify the measures applicable to the contracted deployment. NAYA does not claim a certification or control that has not been expressly documented and verified.

Customers remain responsible for secure credentials, user access, endpoint security, integration settings, data minimisation and lawful campaign configuration.

6. Subprocessors

NAYA may use subprocessors for hosting, infrastructure, storage, communications, AI processing, support and other service functions. Where the customer gives general written authorisation, NAYA will provide the notice and objection process stated in the DPA before adding or replacing a subprocessor that processes customer personal data.

NAYA will impose data-protection obligations on subprocessors that provide an equivalent level of protection for the processing they perform and remains responsible to the customer as required by the DPA and applicable law.

A current contractual subprocessor schedule should be supplied with or incorporated into the executed DPA. This public page is not represented as a complete subprocessor register.

7. International transfers

Where customer personal data is transferred to a restricted country, NAYA will use a lawful transfer mechanism appropriate to the transfer, such as an adequacy regulation, approved contractual clauses or another available mechanism, and will apply supplementary measures where required. Deployment-specific transfer details and safeguards should be recorded in the DPA and subprocessor schedule.

8. Data-subject requests

Taking account of the nature of processing, NAYA will provide reasonable assistance to enable the customer to respond to requests for access, correction, deletion, restriction, objection or portability. If NAYA receives a request relating to customer-controlled data, it will normally refer the request to the customer and will not respond substantively except on the customer’s instruction or where law requires.

9. Security incidents and compliance assistance

NAYA will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled data, in accordance with the executed DPA. NAYA will provide information reasonably available to help the customer assess the incident and meet applicable notification obligations.

NAYA will provide reasonable assistance with security obligations, data-protection impact assessments and prior regulatory consultation, taking into account the nature of processing and information available. Charges may apply for assistance outside standard service scope where the DPA or Order permits.

10. Deletion and return

At the end of the service, NAYA will, at the customer’s choice and subject to the DPA, return or delete customer personal data and delete remaining copies unless law requires retention. Data in protected backups may remain until overwritten in the ordinary cycle, provided it is put beyond routine use and remains protected.

Suppression data may be retained where necessary to respect objections and prevent renewed contact, subject to role allocation and legal requirements.

11. Information, audits and records

NAYA will make available information reasonably necessary to demonstrate compliance with the processor obligations in the executed DPA and will support audits or inspections on the terms stated there. Audit arrangements should protect security, confidentiality, other customers and operational continuity, and normally use existing independent reports or remote evidence before on-site inspection.

12. Customer obligations

The customer must provide lawful instructions, ensure a valid lawful basis, deliver required notices, keep data accurate and proportionate, honor data-subject rights, operate suppression lists, assess campaign and recording rules, and configure retention and access appropriately. The customer is responsible for the lawfulness of its contact lists, scripts, offers, integrations and use cases.

13. Requesting a DPA

Email hello@nayaai.io with the subject “DPA Request.” Include the contracting entity, expected use case, countries, integrations and categories of personal data so the correct schedule can be prepared.

Legal or privacy question?

Email NAYA’s current legal and privacy contact. Use “Privacy Request” or “DPA Request” in the subject when relevant.

hello@nayaai.io