This Privacy Policy explains how NAYA SYSTEMS LTD handles personal data when people visit nayaai.io, contact NAYA, evaluate or buy NAYA services, use a NAYA service, or are included in data supplied by a NAYA customer.
1. Who we are and how to contact the DPO
NAYA SYSTEMS LTD is registered in England and Wales under company number 16665484. Its registered office is 98 Newhouse Road, Stoke-On-Trent, England, ST2 8BL.
NAYA is registered with the UK Information Commissioner’s Office and has appointed a Data Protection Officer (DPO). For privacy questions, rights requests or the DPO, email hello@nayaai.io with the subject “Data Protection Officer” or “Privacy Request.” NAYA does not publish the DPO’s personal name or a separate DPO inbox on this site.
2. When NAYA is controller and when it is processor
NAYA is a controller only where it decides why and how personal data is processed for its own purposes. Those purposes are account administration, billing, service security, fraud prevention, legal compliance, website and business-relationship administration, and establishing, exercising or defending legal claims.
For customer-controlled leads, contacts, CRM data, call audio, transcripts, summaries, scheduling and campaign data, the customer is normally the controller and NAYA is normally the processor acting on the customer’s documented instructions. The customer legal entity is identified in its Order or account. The Data Processing Addendum applies before processor activity begins as described in the Terms.
If a NAYA-powered service contacted you for a customer, that customer is normally the first point of contact for your rights request. NAYA will refer or assist with the request as required by the customer’s instructions, the DPA and applicable law.
3. Personal data NAYA may process
Website and technical data
- IP address and approximate network location;
- browser, device, operating-system and language information;
- referral URL, pages viewed, event timestamps and basic interaction data;
- where the visitor positively allows Analytics, a random browser identifier, session information, pages visited, referral source, approximate geographic area, browser and device characteristics, timestamps, scrolling, outbound-link interactions and configured website events processed through Google Analytics 4;
- security, diagnostic, server-log and fraud-prevention data;
- a sessionStorage flag that remembers whether the visual intro has played during the current browser session; and
- the consent-interface version, timestamp, source, method and Analytics choice stored in the visitor’s browser.
NAYA does not intentionally send names, email addresses, telephone numbers, form contents, lead records or other directly identifying information to Google Analytics. Query strings and fragments are removed from page locations before a page view is transmitted.
Enquiry, account and relationship data
- name, work email, work telephone number, role, employer and professional profile;
- correspondence, meeting notes, support requests and communication preferences;
- account, contract, Order, invoice and payment-status information, but not card data collected on this main website; and
- evidence of notices, consent, objections, opt-outs and suppression preferences.
Customer Personal Data
Depending on a customer’s configured service, NAYA may process:
- names, work details, telephone numbers, email addresses and lead-list fields;
- CRM records, lead source, campaign, qualification and routing fields;
- call metadata, call audio, transcripts, summaries and disposition data;
- scheduling information and appointment details;
- messages, follow-up history, consent evidence, opt-outs and suppression records; and
- scripts, prompts, knowledge materials and documented customer instructions.
Customers must not provide special-category or criminal-offence data unless the Order expressly permits it and the customer has documented an appropriate lawful basis, any required UK GDPR Article 9 and Data Protection Act 2018 Schedule 1 condition, safeguards and any required data protection impact assessment. Customer authorisation alone is not such a condition.
4. Sources of personal data
NAYA may receive data directly from the individual; from the organisation they work for; from a NAYA customer; from customer-selected CRM, telephony, email or scheduling integrations; from public professional or business sources; from service and security logs; and from service providers supporting the website and contracted services.
When a customer supplies contact data obtained elsewhere, the customer is responsible for ensuring that it was collected, disclosed, maintained and supplied lawfully, and for retaining evidence of the applicable notice, permission, channels, technology, withdrawal and suppression state.
Where personal data is obtained indirectly, NAYA will provide the information required by applicable law within a reasonable period and, in any event, no later than one month after obtaining it, at the time of the first communication with the individual, or before the data is disclosed to another recipient, as applicable.
5. Purposes and lawful bases when NAYA is controller
| Purpose | Typical lawful basis |
|---|---|
| Operate, secure and troubleshoot the website and NAYA’s own systems | Legitimate interests in operating a secure business service; legal obligation where applicable |
| Respond to enquiries and arrange demonstrations | Legitimate interests in responding to requested business communications; steps at the individual’s request before contract |
| Measure and improve the main website through Google Analytics 4 | Consent; GA4 is not activated unless the visitor allows Analytics |
| Administer accounts, Orders and business relationships | Contract; legitimate interests in administering business relationships |
| Bill, account, audit and maintain business records | Contract, legal obligation and legitimate interests |
| Prevent misuse, fraud and security incidents | Legitimate interests and legal obligation |
| Send NAYA’s own business marketing | Consent where required, or legitimate interests where permitted, subject to PECR and opt-out rights |
| Comply with law and establish, exercise or defend claims | Legal obligation and legitimate interests |
NAYA does not rely on this table as a lawful basis for customer-controlled campaign processing. When NAYA is processor, the customer determines the purpose and lawful basis and NAYA acts on documented instructions.
6. AI, training and automated decisions
NAYA’s voice and AI processing uses hosted AI models from OpenAI and Anthropic where configured, together with locally hosted AI on NAYA-controlled servers in Luxembourg. NAYA performs call recording, transcription and text-to-speech locally within that infrastructure. Telnyx AI, automatic speech recognition, transcription and text-to-speech features are disabled for NAYA’s service.
NAYA does not use Customer Personal Data, call audio, transcripts, contacts or identifiable service records for general or cross-customer model training. NAYA contractually requires relevant hosted AI providers not to use call audio, transcripts, prospect data or Customer Personal Data to train general-purpose AI models. Customer-specific AI self-training is disabled by default and may be enabled only on the customer’s documented instruction for that customer’s isolated account. The DPA continues to apply.
The public website does not make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects. Customers must not configure NAYA for such decisions unless the processing is lawful, any required DPIA has been completed, and applicable safeguards include meaningful information, human intervention and a route to challenge the decision.
7. Calls, recordings, transcripts and objections
Calls processed through NAYA’s configured voice service are recorded. At the start of each call, the deployed notice is designed to identify the relevant business, state the AI or synthetic-voice nature of the interaction, explain recording, transcription and purpose, and provide an immediate route to object, opt out or request human contact.
An immediate objection or opt-out is supported and adds the telephone number to an applicable do-not-call or suppression list. The customer remains responsible for configuring and testing the notice and for meeting campaign-specific consent, transparency, recording, preference-service, identification and suppression requirements.
Only authorised customer personnel and authorised NAYA personnel who need access for service delivery, support, security or review may access customer leads, recordings and transcripts.
8. Recipients and providers
NAYA may disclose personal data to the following categories where necessary for the relevant purpose:
| Provider or category | Role and use |
|---|---|
| NAYA-controlled Luxembourg infrastructure | Hosts NAYA voice and local AI processing, including recording, transcription and text-to-speech |
| Microsoft Azure | Cloud infrastructure and compute supporting configured NAYA services |
| Amazon Web Services, including S3 | Cloud hosting, object storage, media and backup support where configured |
| Telnyx | Voice API, SMS and telephone-number purchasing and provisioning; Telnyx AI, ASR, transcription and TTS are disabled |
| Twilio | Voice API and telephony; routing and processing location are configuration and provider dependent, and default or provider processing may include the United States until another regional configuration is verified |
| Vapi | Voice-agent orchestration where configured for an approved customer workflow |
| ElevenLabs | Synthetic-voice services where configured for an approved customer workflow |
| OpenAI and Anthropic | Hosted AI model processing where configured for an approved service workflow; Customer Personal Data is not used for general or cross-customer model training by NAYA |
| Inframail | Dedicated email infrastructure, mailboxes, domains and email-delivery support |
| Stripe | Payment processing where enabled; no Stripe script or payment form is currently loaded on the main public website |
| Manus and its hosting, CDN, storage and security infrastructure | Delivers and protects the main website and its media |
| Google Analytics 4, Google Ireland Limited and relevant Google affiliates including Google LLC | Consent-based audience measurement for the main website; Google acts as a processor under the applicable Google data-processing terms |
| Customer-selected CRM, scheduling and other integrations | Receives Customer Personal Data only as configured or instructed by the customer |
| Professional advisers, banks, accounting providers, insurers and authorities | Used where reasonably necessary for NAYA’s controller purposes or required by law |
The main nayaai.io site loads GA4 only after a visitor positively allows Analytics. Meta Pixel and Microsoft Clarity are not loaded on the main site, and NAYA does not collect card details there. No Stripe script or payment form is currently loaded on the main site. A separate application at scale.nayaai.io/qualify has its own technologies and is described separately below.
9. UK restricted transfers and international processing
NAYA-controlled voice and AI infrastructure operates in Luxembourg. Provider processing may occur elsewhere depending on service configuration and routing. In particular, Twilio regional routing is not represented as active; default or provider processing may include the United States.
Where UK restricted-transfer rules apply, NAYA will rely on applicable UK adequacy regulations or an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum, together with a proportionate transfer-risk assessment and supplementary measures where required. EU restricted transfers will use an applicable adequacy decision, standard contractual clauses or another lawful mechanism.
Google Analytics information may be processed outside the United Kingdom and European Economic Area under applicable Google data-processing terms and safeguards. Depending on the processing and destination, those safeguards may include the UK Extension to the EU–US Data Privacy Framework and approved contractual safeguards.
NAYA will not intentionally route call audio, transcripts or other Customer Personal Data outside the United Kingdom or European Economic Area unless the Order, documented customer instruction or a written deployment approval permits it and an applicable transfer mechanism and assessment are in place. Provider default routing, including possible United States processing by Twilio, must be addressed before the affected workflow is approved for production.
10. Retention, return and deletion
Operational Customer Personal Data may be retained for up to 12 months after the relevant service interaction unless the Order, Customer instruction, configured period or law requires a shorter or longer period. Within that outer period, NAYA applies criteria including the active subscription and service purpose; security and support needs; statutory accounting and recordkeeping duties; consent and suppression requirements; claims and limitation periods; data sensitivity; and the time needed to delete data from active systems and protected backups.
NAYA and each customer must maintain an appropriate documented retention schedule. Customer-configurable periods and early deletion should be used where appropriate. When NAYA is processor, return or deletion on termination is governed by the customer’s instructions and the DPA. Data in protected backups may remain until overwritten in the ordinary backup cycle, provided it is put beyond routine use and remains protected. Suppression data may be retained only as needed to honour an objection and prevent renewed contact.
GA4 user-level and event-level retention is controlled in the NAYA Analytics property. Before GA4 is enabled in production, NAYA must confirm or set Analytics Admin → Data settings → Data retention → Event data retention to the intended two-month period. Aggregated reports may remain available for longer. This policy does not represent an unverified property setting as already active.
11. Security
NAYA uses technical and organisational measures selected in light of the nature, context and risks of processing. These include role- and need-based access, confidentiality obligations, authentication and access management, service security, incident handling, deletion and review controls to the extent described in the DPA. NAYA does not claim an ISO, SOC, encryption or infrastructure configuration that has not been verified for the relevant deployment.
Customers remain responsible for their own credentials, devices, integrations, access permissions, campaign configurations and lawful data handling.
12. Your rights
Depending on the law and circumstances, you may have rights to access, correct, erase or restrict personal data; object to processing; receive portable data; withdraw consent without affecting earlier lawful processing; and receive safeguards relating to restricted transfers. You have an unconditional right to object to processing for direct marketing.
To exercise a right or contact the DPO, email hello@nayaai.io with the subject “Privacy Request” or “Data Protection Officer.” NAYA may need to verify identity and clarify the request. If NAYA processes the data only for a customer, it may refer the request to that customer and assist them.
13. Marketing and communication choices
You may opt out of NAYA’s own marketing at any time using the unsubscribe method provided or by emailing hello@nayaai.io. NAYA may retain limited suppression information to respect that choice. Service, security, billing and legal notices are not marketing and may still be sent where necessary.
For NAYA’s product-update newsletter, NAYA relies on the individual’s consent under PECR regulation 22 and Article 6(1)(a) UK GDPR. NAYA records the submitted email address, consent wording or version, timestamp and source to demonstrate and administer that consent. NAYA retains the address and a limited suppression record until unsubscribe, or longer only where reasonably necessary to prevent renewed marketing or establish, exercise or defend legal claims. NAYA currently sends no welcome email and uses no third-party newsletter platform.
Customers using NAYA for calls or messages must operate their own consent and suppression processes and comply with applicable PECR, preference-service, do-not-call, identification, recording and calling-time requirements.
14. Cookies and similar technologies
Cookies are small files stored by a browser. Similar technologies include local storage, session storage, pixels, scripts, server-side events and other methods that store, access or communicate device or interaction information. A technology is not automatically exempt from consent or transparency requirements merely because it is server-side, cookieless or session-based; its purpose, operation and applicable law must be assessed.
Current main-site technology
The current main nayaai.io site uses or requests the following:
| Technology | Provider | Purpose | Current behavior |
|---|---|---|---|
naya_intro_played | NAYA | Prevents the visual intro replaying during the same browser session | Session storage; removed when the browser session ends |
naya_cookie_preferences consent record | NAYA | Remembers the consent version, timestamp, source, method and visitor’s Analytics choice and supports later withdrawal or change | Browser local storage; retained until replaced or cleared |
_ga | Google Analytics | Stores a random browser identifier after Analytics consent | Up to two years, subject to Google’s cookie controls and the visitor’s browser settings |
_ga_F1L052C2N5 | Google Analytics | Maintains session state for the approved NAYA web stream after Analytics consent | Up to two years, subject to Google’s cookie controls and the visitor’s browser settings |
| CDN and media requests | Manus/CDN infrastructure | Delivers page content, images, 3D models and frames | Necessary content-delivery requests; no NAYA-managed cookie observed |
GA4 is blocked until the visitor positively allows Analytics. Before that decision, the main site does not inject gtag.js, send Google Analytics requests or cookieless pings, or create GA cookies. After consent, NAYA uses GA4 to understand pages visited, referral source, approximate geography, browser and device characteristics, timestamps, scrolling, outbound-link interactions and configured website events. Names, email addresses, telephone numbers, form contents and lead records are not intentionally sent. Analytics is not used for advertising personalisation; advertising-related Google consent states remain denied. Meta Pixel and Microsoft Clarity are not loaded on the main site.
Separate Scale booking application
“Book a Strategy Call” links open scale.nayaai.io/qualify, which is a separate deployment. The verified audit observed Meta/Facebook Pixel and _fbp, Microsoft Clarity, Manus Analytics / Umami, and local-storage entries for theme and referral information on that application.
The main-site preference centre applies only to nayaai.io and does not control or claim compliance for the separate Scale deployment. Scale requires its own consent and tracker-blocking implementation. Visitors who do not wish to use that flow may email hello@nayaai.io.
Managing preferences
On non-article routes, the first choice offers Essential only or Allow all. On individual blog articles, Continue with essential only reveals the article without loading GA4, while Allow analytics reveals the article and activates GA4. A valid current-version choice carries across the main site. Use the persistent Cookie preferences control in the footer to allow or withdraw Analytics as easily as the original decision. Withdrawal disables future GA events and removes NAYA-accessible _ga cookies where technically possible. Necessary storage remains active. Browser controls may also block or delete cookies and storage, although blocking necessary resources can affect requested site functions.
15. Children
The website and services are intended for business use and are not directed to children. Customers must not knowingly use the services to target children or provide children’s personal data unless the Order expressly permits the use and all required safeguards and consents are in place.
16. United States privacy rights
Residents of certain US states may have additional rights, such as rights to know, access, correct or delete personal information, receive a portable copy, opt out of specified sale, sharing or targeted advertising, or appeal a decision. These rights vary by state and are subject to exceptions. Requests may be sent to hello@nayaai.io. NAYA will not discriminate against a person for exercising an applicable privacy right.
17. Complaints
Please contact NAYA or the DPO first so the concern can be investigated. You may also complain to the UK Information Commissioner’s Office or, where applicable, the data-protection authority in the country where you live or work.
18. Changes
NAYA may update this policy to reflect changes in law, services or processing. The updated date identifies the current version. Material changes will be communicated where required; consent will not be inferred merely from continued use where consent is legally required.
19. Contact
Email: hello@nayaai.io — subject “Data Protection Officer” or “Privacy Request” Registered office: 98 Newhouse Road, Stoke-On-Trent, England, ST2 8BL
Legal or privacy question?
Email NAYA’s current legal and privacy contact. Use “Privacy Request” or “DPA Request” in the subject when relevant.
hello@nayaai.io



