This is a binding Data Processing Addendum (DPA) that forms part of the contract between the customer legal entity identified in the applicable Order or account (Customer) and NAYA SYSTEMS LTD, company number 16665484 (NAYA), whenever NAYA processes Customer Personal Data on behalf of Customer.
1. Binding effect and precedence
This DPA is automatically incorporated into the Order and the Terms and Conditions when Customer accepts either document and NAYA processes Customer Personal Data for Customer. Acceptance of the Order or Terms records acceptance of this DPA. It applies before that processor activity begins and does not require a separate signature.
The parties may execute a separately signed, negotiated data processing agreement that expressly replaces this DPA. If documents conflict on data-protection matters, the replacement data processing agreement or this DPA prevails, followed by the Order and then the Terms.
2. Definitions and roles
Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018, PECR, the EU GDPR where applicable, and other binding privacy or data-protection law applicable to the processing.
Customer Personal Data means personal data contained in Customer Data that NAYA processes on Customer’s behalf, including customer-controlled leads, contacts, CRM data, call audio, transcripts, summaries, scheduling data, campaign data and suppression records.
Controller, processor, personal data, personal data breach, processing, data subject and supervisory authority have the meanings given by Applicable Data Protection Law.
For Customer Personal Data, Customer is normally the controller and NAYA is normally the processor. Customer is the legal entity identified in the Order or account. NAYA may be an independent controller only for its own account administration, billing, service security, fraud prevention, legal compliance and establishing, exercising or defending legal claims; those independent purposes are governed by the Privacy Policy, not this DPA.
3. Scope and Article 28 particulars
The details required by Article 28 are in Annex 1. Processing begins when NAYA first receives or accesses Customer Personal Data and continues for the contracted service term plus the period reasonably required to return or delete data, complete protected backup cycles, comply with law or resolve a documented dispute.
4. Customer instructions and responsibilities
NAYA will process Customer Personal Data only on Customer’s documented instructions in the contract, configured workflows and authorised written directions, including instructions about restricted transfers, unless UK or other applicable law requires processing. Where legally permitted, NAYA will inform Customer before processing required by law.
NAYA will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. NAYA may suspend the affected processing while the parties resolve the issue and is not required to carry out an unlawful instruction.
Customer is responsible for the lawfulness, fairness and accuracy of its instructions and Customer Personal Data; its lawful bases, notices, consent and suppression processes; data minimisation; and any required UK GDPR Article 9 condition, Data Protection Act 2018 Schedule 1 condition or data protection impact assessment. Customer authorisation alone is not a condition for processing special-category or criminal-offence data.
5. Confidentiality and access
NAYA will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations, receive access only for their role and need, and process the data only as permitted by this DPA. Access to leads, call recordings and transcripts is limited to authorised Customer personnel and authorised NAYA personnel who need access for support, review, security or delivery of the contracted service.
6. Security measures
NAYA will maintain appropriate technical and organisational measures proportionate to the nature, scope, context and risks of the processing. The current supported commitments are described in Annex 2. NAYA may update those measures where the update does not materially reduce the overall level of protection.
Customer remains responsible for secure credentials, user lifecycle and permissions, endpoint security, integration configuration, campaign controls and the security of Customer-controlled systems.
7. Subprocessors
Customer gives NAYA general written authorisation to appoint the subprocessors listed in Annex 3 and to add or replace subprocessors that are reasonably necessary to provide the services.
Before a new or replacement subprocessor begins processing Customer Personal Data, NAYA will provide advance notice through an account or Order contact, service notice, or an update to the public schedule accompanied by reasonable notice. Customer may object on reasonable, documented data-protection grounds within the period stated in the notice. The parties will work in good faith on a commercially reasonable alternative. If no reasonable alternative is available, either party may terminate the affected processing or service element on written notice without affecting accrued rights.
NAYA will impose written data-protection obligations on each subprocessor that are no less protective than the obligations applicable to the relevant processing under this DPA. NAYA remains responsible to Customer for the subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law.
8. Data-subject requests
Taking account of the nature of the processing, NAYA will provide reasonable technical and organisational assistance to help Customer respond to requests for access, correction, deletion, restriction, objection, portability or safeguards concerning solely automated decisions.
If NAYA receives a request relating to Customer Personal Data, it will normally refer the requester to Customer and will not respond substantively except on Customer’s documented instruction or where law requires. Customer remains responsible for verifying the requester and deciding the response.
9. Personal data breaches
NAYA will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and, in any event, no later than 72 hours after awareness unless applicable law permits a longer period and NAYA explains the reason for delay. This outer period does not delay an earlier notice or prevent NAYA from supplying information in phases as the investigation develops.
NAYA will provide information reasonably available to help Customer assess the nature, affected data and people, likely consequences and mitigation. NAYA’s notice is not an admission of fault or liability. Customer is responsible for notifications to individuals and authorities unless the parties agree otherwise or law requires NAYA to notify directly.
10. Compliance assistance
Taking account of the nature of processing and information available to NAYA, NAYA will provide reasonable assistance with Customer’s security obligations, breach assessments and notifications, data protection impact assessments, prior consultation with a supervisory authority and safeguards for solely automated decisions producing legal effects or similarly significant effects.
NAYA will provide information reasonably necessary for Customer to assess whether a deployment meets UK GDPR Article 35 or other applicable high-risk criteria. Customer remains responsible for determining whether a DPIA or consultation is required and for documenting its decision.
11. Return, deletion and retention
During the service term, Customer may request deletion or return of Customer Personal Data where supported by the service and consistent with the contract. On termination or expiry, NAYA will, at Customer’s choice, return or delete Customer Personal Data from active systems within 30 days and delete remaining copies unless applicable law requires retention.
Retention periods must follow the documented Customer or internal retention schedule, the configured service period, necessity and legal requirements. Customer-configurable periods and early deletion should be used where appropriate. Data in protected backups may remain after the 30-day active-system period until overwritten in the ordinary backup cycle, provided it is put beyond routine use and remains protected. Suppression data may be retained only as needed to honour objections and prevent renewed contact.
12. Information, audits and records
NAYA will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to reasonable audits or inspections by Customer or an independent auditor bound by confidentiality.
Audits must be proportionate, scheduled on reasonable notice, avoid unnecessary disruption and protect the security and confidentiality of other customers. Unless a personal data breach, supervisory-authority request or credible evidence of material non-compliance reasonably requires otherwise, the parties will normally use current documentation, questionnaires, remote evidence and available independent reports before an on-site inspection. Customer bears its audit costs and NAYA may charge reasonable costs for assistance beyond standard evidence, except where an audit identifies NAYA’s material breach.
NAYA will maintain the processor records required by UK GDPR Article 30 and cooperate with a competent supervisory authority as required by law.
13. Restricted transfers
NAYA-controlled voice and AI infrastructure is operated on servers in Luxembourg. Telephony, communications and other provider processing may occur in other locations depending on configuration and provider routing; Twilio default or provider processing may include the United States until a different regional configuration is verified for the deployment.
Where Customer Personal Data is subject to UK restricted-transfer rules, NAYA will rely on applicable UK adequacy regulations or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum, as applicable. For a restricted transfer from an EU controller to NAYA as processor, the parties incorporate the then-current European Commission Controller-to-Processor Standard Contractual Clauses (Module Two) unless another valid transfer mechanism applies. The UK Addendum applies to those clauses for a restricted transfer governed by UK law where appropriate. The Order and Annex 1 supply the parties, processing and transfer details to the extent required. NAYA will support a proportionate transfer-risk assessment and implement supplementary technical, contractual or organisational measures where required.
14. Results-focused optimisation
NAYA may use anonymised extracts derived from interaction transcripts, together with relevant performance signals, to train, tune and evaluate models and workflows so that the Services deliver better results. These improvements may include more accurate lead qualification, improved conversion rates, increased bookings and other outcomes configured by the Customer.
Before any transcript material is used for this purpose, NAYA removes names, telephone numbers, email addresses and other information reasonably capable of identifying an individual. Identifiable contact details are not included in optimisation datasets.
This optimisation may be enabled by default where disclosed in the applicable Order, service description or account settings. The Customer may disable it at any time through the available settings or by written request. Once disabled, newly generated transcript material will not be used for this purpose.
Any processing required to produce the anonymised extracts remains subject to this Addendum, including its security obligations and the Customer’s documented instructions.
15. Liability and termination
Liability arising under this DPA is governed by the liability provisions of the contract. Termination of this DPA does not remove accrued rights or obligations concerning Customer Personal Data already processed. Sections that by their nature must survive, including confidentiality, deletion, audit, transfer and liability provisions, will survive as necessary.
Annex 1 — Processing details
| Particular | Description |
|---|---|
| Subject matter | AI-assisted voice, lead response, qualification, follow-up, scheduling, CRM synchronisation, email or SMS support and related service operations described in the Order |
| Duration | The contracted service term and the limited period needed for return, deletion, ordinary backup expiry, legal obligations and documented disputes |
| Nature and purpose | Receiving, hosting, transmitting, organising, recording, transcribing, converting text to speech, summarising, classifying, routing, synchronising, securing, supporting and deleting Customer Personal Data for Customer-directed workflows |
| Data subjects | Customer prospects, leads, contacts, customers, call participants, personnel and authorised users |
| Personal data | Names, work details, phone numbers, email addresses, CRM and lead fields, campaign and source data, call metadata, audio, transcripts, summaries, qualification answers, scheduling data, messages, consent evidence, opt-outs, suppression preferences and technical records |
| Special-category and criminal-offence data | Not intended unless the Order expressly authorises the use and Customer documents an appropriate lawful basis, applicable Article 9 and Schedule 1 condition, safeguards and any required DPIA |
| Customer instructions | The Order, Terms, configured workflows, authorised account settings and documented written directions accepted by NAYA |
Annex 2 — Technical and organisational measures
| Area | Supported commitment |
|---|---|
| Access control | Role- and need-based access for authorised Customer and NAYA personnel; access is reviewed and removed when no longer required |
| Personnel | Confidentiality obligations and access limited to authorised support, review, security and service-delivery needs |
| Authentication and account management | Access-management and authentication controls appropriate to the service; Customer controls its authorised users, credentials and connected systems |
| Service and infrastructure security | Security controls selected in light of the service, data and risk; monitoring, maintenance and vulnerability handling form part of service operations |
| Data minimisation and optimisation | Processing is limited to configured purposes. Transcript-derived material used for results-focused optimisation is anonymised in accordance with section 14 before inclusion in optimisation datasets. |
| Incident handling | Procedures to investigate, contain, remediate and notify Customer of relevant personal data breaches in accordance with section 9 |
| Availability and recovery | Operational safeguards and recovery arrangements proportionate to the service; no absolute availability or recovery guarantee is created by this Annex |
| Deletion and return | Customer instructions, configured periods, early deletion where appropriate, termination handling and ordinary protected-backup expiry as described in section 11 |
| Review | Measures are reviewed in light of service changes, incidents, risks and legal requirements |
| Change control | Material production, access, provider and workflow changes are reviewed, authorised, documented and tested proportionately before release |
This Annex does not claim ISO, SOC, encryption or a specific infrastructure configuration that has not been independently verified for the relevant deployment.
Annex 3 — Current subprocessor schedule
| Provider | Function | Location and transfer qualification | Notice mechanism |
|---|---|---|---|
| Microsoft Azure | Cloud infrastructure, compute and supporting platform services where enabled for Customer Personal Data | Region and routing depend on the configured deployment. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Amazon Web Services (AWS), including S3 | Cloud hosting, object storage, media and backup support where enabled for Customer Personal Data | Region and routing depend on the configured deployment. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Telnyx | Voice API, SMS and telephone-number purchasing and provisioning. Telnyx AI, ASR, transcription and text-to-speech features are disabled for NAYA’s service. | Location and routing depend on the configured telephony service. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Twilio | Voice API and telephony | Region and provider routing are configuration dependent. EU regional routing is not represented as active; default or provider processing may include the United States. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Vapi | Voice-agent orchestration where enabled for an approved Customer workflow | Processing location depends on the configured service. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| ElevenLabs | Synthetic-voice services where enabled for an approved Customer workflow | Processing location depends on the configured service. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| OpenAI | Hosted AI model processing where enabled for an approved Customer workflow | Processing location depends on the configured service. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Anthropic | Hosted AI model processing where enabled for an approved Customer workflow | Processing location depends on the configured service. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Inframail | Dedicated email infrastructure, mailboxes, domains and email-delivery support | Processing location depends on the configured email service. A UK or EU restricted-transfer safeguard will be used where required. | Advance notice through an account or Order contact, service notice, or an updated public schedule accompanied by reasonable notice |
| Stripe | Payment processing where enabled; Stripe is not currently loaded as a payment form on the main public website | Processing location depends on the configured payment service. Stripe acts under its applicable role and terms. | Advance notice before Stripe processes Customer Personal Data as a NAYA subprocessor |
NAYA performs recording, transcription and text-to-speech locally on NAYA-controlled infrastructure in Luxembourg. A listed optional provider is a subprocessor under this DPA only when enabled for the deployment and actually processing Customer Personal Data on NAYA’s behalf for the contracted service; providers used only for NAYA’s own controller activities are not subprocessors for that data.
Contact and DPO
Questions, audit requests, subprocessor objections and data-protection communications may be sent to hello@nayaai.io with the subject “Data Protection Officer” or “DPA Request.”
Legal or privacy question?
Email NAYA’s current legal and privacy contact. Use “Privacy Request” or “DPA Request” in the subject when relevant.
hello@nayaai.io



