NAYA.ai

Business Terms

Terms and Conditions

The B2B terms governing NAYA Orders, services, AI functionality, customer calling obligations, fees, intellectual property, confidentiality and liability.

Last updated: 30 August 2026NAYA SYSTEMS LTD · 16665484
On this page
  1. 1. About NAYA
  2. 2. Contract documents and order of precedence
  3. 3. Business authority and authorised users
  4. 4. Services and licence
  5. 5. Customer dependencies and implementation
  6. 6. Acceptable use
  7. 7. AI functionality, disclosure and limitations
  8. 8. Outbound calling, marketing and recording compliance
  9. 9. Customer data and service data
  10. 10. Data protection
  11. 11. Third-party services and integrations
  12. 12. Fees, usage, billing and taxes
  13. 13. Suspension
  14. 14. Intellectual property
  15. 15. Confidentiality
  16. 16. Security
  17. 17. Warranties and disclaimers
  18. 18. Service levels and service credits
  19. 19. Indemnities
  20. 20. Limitation of liability
  21. 21. Term, renewal and termination
  22. 22. Changes to these Terms
  23. 23. General
  24. 24. Governing law and disputes
  25. 25. Contact

These Terms and Conditions (the Terms) govern use of the NAYA website and any services supplied by NAYA SYSTEMS LTD under an Order. They are written for business customers. Consumer statutory rights, where they apply and cannot be excluded, are not affected.

1. About NAYA

NAYA is operated by NAYA SYSTEMS LTD, registered in England and Wales under company number 16665484, with registered office at 98 Newhouse Road, Stoke-On-Trent, England, ST2 8BL (NAYA, we, us or our). Contact: hello@nayaai.io.

2. Contract documents and order of precedence

An Order means an order form, proposal, statement of work or other document signed or expressly accepted by NAYA and the customer that identifies the services, subscription term, fees, included usage and any additional terms.

The contract consists of the Order, these Terms and the Data Processing Addendum (DPA) where NAYA processes Customer Personal Data for the customer. The DPA is automatically incorporated into the contract when the customer accepts the Order or these Terms and applies before that processor activity begins. A separately signed, negotiated data processing agreement may expressly replace the public DPA.

If the contract documents conflict, the DPA or replacement data processing agreement prevails for data-protection matters, the Order prevails for commercial and service-specific matters, and these Terms apply to the remainder.

Website descriptions and plan cards are illustrative unless an Order incorporates them. No online description creates a service level, usage allowance or price commitment by itself.

3. Business authority and authorised users

The person accepting an Order confirms that they have authority to bind the customer. The customer is responsible for its authorised users, credentials, configurations and all activity conducted through its account, except to the extent caused by NAYA’s breach of contract.

The customer must keep credentials confidential, use reasonable access controls and promptly notify NAYA of suspected unauthorised access.

4. Services and licence

Subject to payment and compliance with the contract, NAYA grants the customer a limited, non-exclusive, non-transferable and non-sublicensable right during the subscription term to access and use the services for the customer’s internal business purposes and the use cases stated in the Order.

NAYA may update the services to improve security, performance, legal compliance or functionality, provided that it does not materially reduce the core contracted functionality during a current paid term without reasonable notice.

5. Customer dependencies and implementation

The customer must provide timely access to information, systems, personnel, telephone numbers, CRM or scheduling environments, approved scripts, campaign rules and other dependencies reasonably needed to configure the services. Delays or defects in customer-controlled dependencies may affect implementation dates, performance and outcomes.

The customer is responsible for the accuracy, legality and quality of customer data, campaign instructions, representations, offers, scripts and business rules supplied to NAYA.

6. Acceptable use

The customer must not, and must not permit anyone else to:

  • use the services unlawfully, deceptively, fraudulently, discriminatorily or to harass, threaten or cause harm;
  • contact a person without the consent, lawful basis, authority, notice or screening required for that campaign and jurisdiction;
  • impersonate another person or organisation, conceal the identity of the responsible caller, spoof caller identification unlawfully or misrepresent the purpose of an interaction;
  • upload special-category personal data, criminal-offence data, highly sensitive financial-account, health, biometric, children’s or government-identification data unless the Order expressly permits it, an appropriate lawful basis and safeguards are documented, and, for special-category or criminal-offence data, the customer has identified any required UK GDPR Article 9 condition and Data Protection Act 2018 Schedule 1 condition; customer authorisation alone is not such a condition;
  • use NAYA to make decisions about employment, housing, credit, insurance, healthcare, education, legal rights or access to essential services without a separate written assessment, any data protection impact assessment required by UK GDPR Article 35 or other applicable high-risk criteria, and appropriate human oversight;
  • test, scan, circumvent, overload or interfere with security or service availability;
  • reverse engineer, decompile, extract models or prompts, scrape the service, or use outputs to build a competing model or service, except to the extent a restriction is prohibited by law;
  • introduce malware or infringe intellectual-property, privacy or other rights; or
  • resell, lease or provide the service to third parties except as an authorised managed service expressly stated in an Order.

NAYA may investigate suspected misuse and may suspend affected access where reasonably necessary to protect people, systems or legal compliance.

7. AI functionality, disclosure and limitations

The services may use artificial intelligence, automated workflows and synthetic voice or text to answer calls, qualify enquiries, route conversations, follow up, schedule meetings and synchronize information with connected systems.

AI output is probabilistic and may be incomplete, inaccurate, delayed or inappropriate for a particular context. The customer must review and approve material instructions, scripts, qualification rules, disclosures and escalation paths. The customer must maintain meaningful human oversight for consequential decisions and must not treat an AI output as legal, financial, medical or other professional advice.

Before deployment, the customer must configure and test a clear, accessible notice that identifies the customer and, where applicable, NAYA; states that the interaction uses AI or a synthetic voice; explains any recording, transcription and analysis and their purpose; and provides an accessible route to request human contact and object or opt out. The customer must keep that notice active and accurate throughout the deployment.

Unless a different campaign-specific notice is approved and legally appropriate, the opening disclosure should communicate substantially: “This call uses an AI assistant for [business]. It is recorded and transcribed for [purpose]. You can ask for a person or say stop at any time.” The customer must not remove, obscure or contradict that disclosure.

In the United Kingdom, these duties may arise from UK GDPR transparency and fairness requirements, PECR, recording and direct-marketing rules, sector obligations and the parties’ contract; these Terms do not represent that UK law creates one universal standalone AI-announcement rule. Different or additional disclosure duties may apply under foreign law.

The customer must not use NAYA for a decision based solely on automated processing that produces legal effects concerning a person or similarly significantly affects them unless the processing is lawful and any applicable safeguards are implemented, including meaningful information, a route to obtain human intervention, to express a point of view and to challenge the decision.

8. Outbound calling, marketing and recording compliance

Before using the services for outbound calls, messages or follow-up, the customer must determine and document the laws that apply to each campaign, audience, channel, technology and geography.

Live marketing calls

For live marketing calls to UK numbers, the customer must screen against the Telephone Preference Service (TPS) and Corporate Telephone Preference Service (CTPS), as applicable, and against its own do-not-call, objection and suppression lists before calling, unless valid and sufficiently specific permission lawfully displaces the relevant preference-service restriction. Consent or permission does not remove separate duties to identify the caller and customer, observe applicable calling times and frequency limits, provide recording, transcription, analysis and AI notices where required, offer accessible human contact and opt-out routes, honour objections and revocations promptly, and maintain suppression records sufficient to prevent repeat contact.

Automated, artificial-voice and AI marketing calls

Before making an automated, prerecorded, artificial-voice or AI-generated marketing call to a UK number, the customer must obtain and retain the prior specific consent required by PECR regulation 19. That consent must cover the customer or brand, purpose, channel and relevant automated, artificial-voice or AI technology. Consent does not replace the separate identification, disclosure, recording, human-contact, opt-out, objection and suppression duties described in these Terms.

For United States campaigns, the customer must satisfy the applicable Telephone Consumer Protection Act (TCPA) and Telemarketing Sales Rule (TSR) requirements, including consent, caller identification, National and state do-not-call restrictions, internal suppression, revocation and permitted calling hours.

Electronic marketing

Email, SMS, WhatsApp and similar electronic marketing messages must comply with PECR regulation 22 and other applicable law. The customer must obtain applicable consent or document the limited existing-customer conditions on which it relies, accurately identify the sender, provide a valid and accessible unsubscribe method in each marketing message, honour withdrawals promptly and screen against its suppression records before sending. Automated calling consent does not by itself establish consent for electronic marketing, and electronic-marketing consent does not by itself establish consent for automated calls.

Contact-list and permission warranty

The customer warrants that every contact, list and permission it supplies or instructs NAYA to use was collected, disclosed, maintained and supplied lawfully for the proposed campaign. Evidence must be sufficient to demonstrate the source; the exact notice and consent wording and version; timestamp; named customer or brand; purpose; channels and technology covered; affirmative selection where required; and subsequent withdrawal, objection and suppression history. The customer must provide that evidence to NAYA promptly on reasonable request.

The customer must also avoid emergency numbers and prohibited or restricted sectors and use cases, and obtain campaign-specific legal advice where the legal position is uncertain. The customer is the caller, sender, seller or campaign sponsor for its communications unless an Order expressly states otherwise. NAYA does not warrant that a customer’s script, list, offer or campaign is lawful in every jurisdiction.

9. Customer data and service data

Customer Data means information, content and personal data submitted to or generated through the services on the customer’s behalf, including lead or contact records, telephone numbers, CRM fields, call audio, transcripts, call summaries, qualification answers, scheduling information and campaign instructions, where enabled.

The customer retains its rights in Customer Data and grants NAYA only the limited rights needed to host, transmit, process and copy Customer Data to provide, secure and support the contracted services under the contract and DPA. NAYA will not use Customer Data, call audio, transcripts, contact records or identifiable service records for general or cross-customer model training, unrelated marketing, an independent contact database or profiling for an independent purpose.

Customer-specific AI self-training is disabled by default. It may be enabled only on the customer’s documented instruction for that customer’s isolated account and remains governed by the DPA. NAYA’s independent-controller use of personal data derived from the customer relationship is limited to account administration, billing, service security, fraud prevention, legal compliance and establishing, exercising or defending legal claims.

NAYA may generate technical, security, usage and performance data about operation of the service (Service Data). NAYA may use Service Data to operate, secure, troubleshoot and improve the services, provided that any disclosure outside NAYA does not identify the customer or an individual except as permitted by the contract or law.

10. Data protection

Each party must comply with the data-protection laws applicable to its role. For customer-controlled leads, CRM data, call audio, transcripts, summaries, scheduling and campaign data (Customer Personal Data), the customer is normally the controller and NAYA is normally the processor acting on documented instructions.

The binding Data Processing Addendum applies before NAYA begins processor activity, is incorporated as stated in section 2 and prevails for data-protection matters. The customer is responsible for privacy notices, lawful basis, data minimisation, accuracy, suppression, data-subject communications, documented instructions, any required UK GDPR Article 9 or Data Protection Act 2018 Schedule 1 condition, and any data protection impact assessment required by UK GDPR Article 35 or other applicable high-risk criteria.

11. Third-party services and integrations

The services may connect to customer-selected telephony, CRM, email, scheduling, analytics, hosting or other third-party services. The customer authorises NAYA to exchange Customer Data with those services as needed for the configured workflow.

Third-party services are governed by their own terms and privacy practices. NAYA is not responsible for a third party’s service, content, availability or changes, except to the extent NAYA expressly assumes responsibility in an Order.

12. Fees, usage, billing and taxes

Fees, currency, billing cadence, payment terms, included usage, overage rates and subscription term are stated in the Order. Unless the Order says otherwise, fees are invoiced in advance, overages are invoiced in arrears, payment is due within 14 days, and fees are non-cancellable and non-refundable except where the contract or mandatory law says otherwise.

Late undisputed amounts may accrue interest at the lower of 4% above the Bank of England base rate or the maximum lawful rate, from the due date until payment. The customer must notify NAYA of a good-faith invoice dispute promptly and pay all undisputed amounts.

Fees exclude VAT, sales, use, withholding and similar taxes. The customer is responsible for taxes arising from its purchase, excluding taxes on NAYA’s net income. If withholding is legally required, the customer must provide evidence and cooperate to reduce it lawfully.

NAYA may revise fees for a renewal term by giving reasonable notice before renewal.

13. Suspension

NAYA may suspend access to the affected services if: payment is materially overdue after notice; use poses a credible security, legal or operational risk; the customer materially breaches acceptable-use or calling requirements; a provider or authority requires suspension; or suspension is reasonably necessary to prevent harm.

Where practicable, NAYA will give notice and limit suspension to the affected service. Suspension does not remove the customer’s payment obligations for the committed term unless the suspension results solely from NAYA’s uncured breach.

14. Intellectual property

NAYA and its licensors retain all rights in the services, software, workflows, designs, documentation, models, prompts, know-how and improvements. Except for the limited rights expressly granted, no rights are transferred.

The customer retains rights in Customer Data, customer marks and customer-created materials. If the customer provides feedback, it grants NAYA a perpetual, worldwide, royalty-free right to use that feedback without identifying the customer or disclosing confidential information.

15. Confidentiality

Each recipient must protect the other party’s non-public business, technical and commercial information using at least reasonable care, use it only for the contract, and disclose it only to personnel and advisers who need to know and are bound by confidentiality duties.

Confidential information excludes information that the recipient can show was lawfully known without restriction, independently developed, received lawfully from another source, or made public without breach. Legally compelled disclosure is permitted after advance notice where lawful and reasonable cooperation at the discloser’s cost.

16. Security

NAYA will maintain appropriate technical and organisational measures proportionate to the nature of the service and data. No internet service is completely secure, and NAYA does not promise absolute security. The customer remains responsible for endpoint security, user access, configuration, credential management and secure operation of its connected systems.

17. Warranties and disclaimers

Each party warrants that it has authority to enter the contract. NAYA warrants that it will provide the services with reasonable care and skill and substantially in accordance with any applicable documentation.

Except as expressly stated and to the maximum extent permitted by law, the services are provided “as is.” NAYA disclaims implied warranties of satisfactory quality, fitness for a particular purpose, non-infringement and uninterrupted or error-free operation. NAYA does not guarantee sales, revenue, conversion, appointment or other business outcomes, or that AI output will always be accurate.

18. Service levels and service credits

No service level or uptime commitment applies unless an Order expressly states one. If an Order includes service levels or service credits, those credits are the customer’s sole and exclusive monetary remedy for the relevant service-level failure, without limiting termination rights for a material uncured breach.

19. Indemnities

The customer will defend and indemnify NAYA against third-party claims, regulatory demands, losses and reasonable costs to the extent caused by Customer Data, campaign content, customer instructions, unlawful calls or messages, failure to obtain required consent or provide required disclosure, customer products or offers, or the customer’s breach of acceptable-use obligations. This indemnity does not apply to the extent the matter was caused by NAYA’s breach of the contract, negligence or wilful misconduct.

NAYA will defend the customer against a third-party claim that the unmodified NAYA service, when used as authorised, infringes that third party’s UK intellectual-property right. NAYA may obtain a right to continue use, modify or replace the affected service, or terminate the affected service and refund prepaid fees for the unused remainder of the committed term. This obligation does not apply to Customer Data, customer instructions, third-party services, unauthorised combinations or modifications, or continued use after NAYA provides a non-infringing alternative.

The indemnified party must give prompt notice, take reasonable steps to mitigate avoidable loss, provide reasonable cooperation, and give the indemnifying party control of the defence. The indemnifying party must keep the indemnified party reasonably informed and must not admit liability for, settle on behalf of, or impose a payment, admission, operational restriction or non-monetary obligation on the indemnified party without its prior written consent, not to be unreasonably withheld or delayed.

20. Limitation of liability

Non-Excludable Liabilities

Nothing in the contract, including the DPA, limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, wilful misconduct, payment obligations, or any liability that cannot lawfully be limited.

Excluded Losses

Subject to Non-Excludable Liabilities, neither party is liable for indirect or consequential loss, loss of profit, revenue, anticipated savings, goodwill or business opportunity, or loss or corruption of data, except that direct restoration costs may be recoverable where caused by breach.

General Cap

Subject to Non-Excludable Liabilities, each party’s aggregate liability arising out of or in connection with the contract is limited to the greater of: (a) the fees paid or payable under the affected Order during the 12 months immediately preceding the event giving rise to liability; and (b) the fees paid or payable during that Order’s first 12 months (General Cap).

IP, Data and Compliance Claims

Subject to Non-Excludable Liabilities, each party’s aggregate liability for breach of confidentiality, data-protection obligations including the DPA, intellectual-property infringement and indemnity obligations is subject to a separate cap equal to 200% of the General Cap. That separate cap applies to those claims instead of, and not in addition to, the General Cap unless an Order expressly states otherwise.

21. Term, renewal and termination

The subscription begins and continues for the term in the Order. It renews only as stated in the Order. Either party may terminate an affected Order for material breach if the breach is not cured within 30 days after written notice, or immediately if the breach cannot be cured. Either party may terminate if the other becomes insolvent or ceases business, subject to applicable law.

Termination for convenience applies only if the Order expressly permits it. On termination, rights to use the service end, outstanding fees become due, and each party must return or delete confidential information as required by the contract and DPA. Provisions intended by their nature to survive will survive, including payment, confidentiality, intellectual property, liability and dispute provisions.

22. Changes to these Terms

NAYA may update these Terms for legal, security or operational reasons. Material changes will apply to a current paid subscription only on renewal unless required sooner by law or needed to address a material security or abuse risk. The version incorporated into a signed Order remains controlling unless the parties agree otherwise.

23. General

Neither party may assign the contract without the other’s consent, not to be unreasonably withheld, except to an affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets, provided the assignee is not a direct competitor and can perform the obligations.

Neither party is liable for delay caused by events beyond its reasonable control, excluding payment obligations. The parties are independent contractors. The contract creates no partnership, agency, employment or third-party beneficiary rights. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder continues. A waiver must be explicit and applies only to the matter waived.

Notices under the contract must be sent to the addresses in the Order; legal notices to NAYA may also be sent to hello@nayaai.io and its registered office.

24. Governing law and disputes

The contract and any non-contractual obligations are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, although either party may seek urgent injunctive relief in any competent court. This choice of law and forum does not limit mandatory rights available to a data subject or the powers, jurisdiction or remedies of the Information Commissioner’s Office or another competent supervisory or regulatory authority.

Before starting proceedings, the parties will use reasonable efforts to escalate and resolve the dispute through senior representatives for at least 15 business days, unless urgent relief or a limitation deadline requires earlier action.

25. Contact

Questions about these Terms may be sent to hello@nayaai.io.

Legal or privacy question?

Email NAYA’s current legal and privacy contact. Use “Privacy Request” or “DPA Request” in the subject when relevant.

hello@nayaai.io