Legal

Privacy Policy

Last updated: April 2026

Nawa Labs FZ-LLCRAKEZ License No. 47026996

1. Information We Collect

Information You Provide

We collect information you provide directly to us when you create an account, connect social media platforms, configure your AI voice settings, or contact our support team. This includes:

  • Your name and email address
  • Payment information (processed securely through Stripe)
  • AI voice configuration and preferences

Platform Data

When you connect social media platforms (YouTube, Instagram), we access your public profile information and comment data through official platform APIs. We collect:

  • Comment text and author metadata
  • Timestamps and engagement metrics
  • Public profile information

This data is collected solely to provide our AI moderation and reply generation services.

Automatically Collected Data

We automatically collect usage data including interaction logs with our AI engine, feature usage patterns, performance metrics, and device/browser information. This data helps us improve our agentic AI system and optimize the 3-tier intelligence engine for better response quality.

Third-Party Data We Process

When you connect your YouTube channel, NAWA syncs publicly available comments on your videos. This includes commenter display names, profile images, comment text, and timestamps. This data is:

  • Processed by our AI models (Anthropic Claude for English, IBM ALLaM for Arabic) for sentiment classification, intent detection, and reply generation
  • Stored in our database for the duration of your subscription
  • Not shared with any party other than the AI providers listed in Section 3
  • Subject to removal requests: any YouTube commenter can request removal of their data from NAWA by emailing privacy@trynawa.com

When you connect your Instagram Business or Creator account, NAWA receives comments on your Instagram posts via Meta's webhook system. This includes commenter usernames, comment text, and timestamps. This data is:

  • Processed by our AI models for sentiment classification, intent detection, and reply generation
  • Stored in our database for the duration of your subscription
  • Not shared with any party other than the AI providers listed in Section 3
  • Subject to removal: any Instagram commenter can request removal of their data from NAWA by emailing privacy@trynawa.com

By connecting your Instagram account, you authorise NAWA to process comments on your posts for AI classification and community management. This processing is necessary for the performance of our contract with you (GDPR Article 6(1)(b)) and is conducted under your authorisation as the account owner.

By connecting your YouTube channel, you authorise NAWA to process publicly available comments on your videos for AI classification and audience intelligence. This processing is necessary for the performance of our contract with you (GDPR Article 6(1)(b)) and is conducted under the creator's authorisation as the channel owner.

We acknowledge that it is not practically possible to individually notify every YouTube commenter that their publicly available comment is being processed by NAWA. We rely on the "disproportionate effort" exemption under GDPR Article 14(5)(b), as commenter data is obtained from a publicly accessible source (YouTube) and individual notification would involve disproportionate effort given the volume of comments processed.

2. How We Use Your Data

Your data is used exclusively to provide and improve the NAWA service. This includes:

  • Generating AI-powered replies that match your voice
  • Performing sentiment analysis and content moderation
  • Building and maintaining your AI voice profile
  • Providing analytics and community insights
  • Processing payments

Semantic Caching

Our semantic caching system stores anonymized response patterns to improve reply quality and reduce AI processing costs. Cached data is used only for your account and is never shared across users or used to train external AI models.

Aggregated Data

We may use aggregated, anonymized usage statistics to improve our platform, publish benchmarks, or develop new features. This data cannot be used to identify any individual user or their content.

Automated Processing and AI

NAWA uses artificial intelligence to process comments on your connected social media channels. This includes:

  • Sentiment classification (positive, negative, neutral)
  • Intent detection (question, praise, complaint, collaboration, spam)
  • Arabic dialect identification (Gulf, Egyptian, Levantine, Maghreb, MSA)
  • AI-generated reply suggestions that match your configured voice

These processes are automated but do not produce decisions with legal effects or similarly significant consequences for commenters. Reply suggestions require your explicit approval before being posted to any platform.

You have the right to request human review of any AI classification. Contact privacy@trynawa.com to exercise this right.

3. Data Sharing & Third-Party Processors

We do not sell your personal data. We do not share your content, comments, or AI-generated replies with any third party for advertising or marketing purposes.

Service Providers

We share data with the following categories of service providers strictly as needed to operate NAWA:

ProviderPurposeData SharedLocationTransfer Basis
Supabase (AWS)Database, authentication, edge functionsAccount data, comments, platform tokensSingapore / United StatesSCCs + DPA
Anthropic (Claude)AI reply generation (English)Comment text, voice profile contextUnited StatesSCCs + DPA
IBM / HUMAIN (ALLaM)Arabic language AI classificationArabic comment text (anonymized)Saudi ArabiaAdequacy (GCC)
StripePayment processingBilling information, payment methodsUnited StatesSCCs + PCI DSS
ResendTransactional and lifecycle emailEmail address, nameUnited StatesSCCs + DPA
Google (YouTube API, OAuth, GA4)Platform integration, authentication, analyticsOAuth tokens, channel data, page viewsUnited StatesSCCs + DPA
Meta (Instagram Graph API)Platform integration, webhooks, OAuthOAuth tokens, account metadata, commentsUnited States / IrelandSCCs + DPA
PostHogProduct analyticsAnonymized usage events, page viewsEuropean UnionEU hosting (no transfer)
Meta (Pixel)Marketing attributionPage views, conversion eventsUnited StatesConsent-gated + SCCs
ByteDance (TikTok Pixel)Marketing attributionPage views, conversion eventsSingapore / United StatesConsent-gated + SCCs
LinkedIn / Microsoft (Insight Tag)Marketing attributionPage views, conversion eventsUnited StatesConsent-gated + SCCs
VercelWeb hosting, CDN, edge middlewareHTTP requests, static assetsGlobal (edge network)SCCs + DPA
Cloudflare (Turnstile)Bot protection, CDNIP address, browser fingerprintGlobal (edge network)SCCs + DPA

All service providers are bound by data processing agreements (DPAs) that require them to protect your data and use it only for the purposes we specify. Cross-border transfers are governed by Standard Contractual Clauses (SCCs) as approved by the European Commission and recognized by the UAE Data Office under Federal Decree-Law No. 45 of 2021 (PDPL). Marketing pixels (Meta, TikTok, LinkedIn) only fire after explicit user consent via our cookie consent banner. We may disclose information if required by law, regulation, or valid legal process.

4. Your Rights (GDPR / UAE PDPL)

Under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the UAE Personal Data Protection Law (PDPL, Federal Decree-Law No. 45 of 2021 as amended), you have comprehensive rights over your personal data.

Your Rights Include

  • Access: Request all personal data we hold about you
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Export your data in a portable format
  • Restriction: Restrict certain processing activities
  • Object: Object to processing based on legitimate interest, including direct marketing. You can opt out of marketing communications at any time through your dashboard preferences or by contacting privacy@trynawa.com.
  • Withdrawal: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at privacy@trynawa.com. We will respond to your request within 30 days. For GDPR-related requests, our Data Protection Officer can be reached at the same address. For UAE PDPL inquiries, we maintain a dedicated compliance team familiar with UAE-specific requirements.

Lawful Basis for Processing

We process personal data under the following legal bases:

Processing ActivityLegal Basis
Account data (email, name)Performance of contract (GDPR Art. 6(1)(b), PDPL Art. 4)
YouTube comment syncPerformance of contract with creator + creator authorisation
Instagram comment syncPerformance of contract with account owner + account owner authorisation
AI classification of commentsPerformance of contract (GDPR Art. 6(1)(b))
Payment processingPerformance of contract + legal obligation (GDPR Art. 6(1)(b)(c))
Email communications (transactional)Performance of contract (GDPR Art. 6(1)(b))
Email communications (marketing)Consent (GDPR Art. 6(1)(a), PDPL Art. 5)
Analytics (GA4, PostHog)Consent (GDPR Art. 6(1)(a), ePrivacy Art. 5(3))
Marketing pixels (Meta, TikTok, LinkedIn)Consent (GDPR Art. 6(1)(a), ePrivacy Art. 5(3))
Support ticketsPerformance of contract (GDPR Art. 6(1)(b))
Security loggingLegitimate interest (GDPR Art. 6(1)(f))

5. Data Retention

We retain your data for as long as necessary to provide the Service and comply with legal obligations. Specific retention periods are outlined below:

Data TypeRetention Period
Account dataDuration of active account
Comment data & AI repliesDuration of subscription
AI chat conversations90 days, then auto-purged
Support tickets1 year after resolution
Semantic cache entries7 days after account deletion
Personal data (post-deletion)Erased within 30 days
Payment records7 years (UAE financial regulations)
Analytics & usage logs90 days (aggregated indefinitely)
Anonymized statisticsIndefinite (non-identifiable)

6. Security

Technical Measures

We implement industry-standard security measures to protect your data:

  • All data encrypted in transit using TLS 1.3
  • Data at rest encrypted using AES-256
  • Infrastructure hosted on SOC 2 Type II certified cloud providers
  • All API access authenticated and rate-limited

Organizational Measures

Access to user data is restricted to authorized personnel on a need-to-know basis. We conduct regular security audits, penetration testing, and vulnerability assessments.

Breach Notification

In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by GDPR and PDPL regulations, providing details about the nature of the breach and steps being taken to mitigate its impact.

7. YouTube API Services & Google Limited Use Disclosure

YouTube API Services

NAWA uses YouTube API Services. By connecting your YouTube account, you also agree to be bound by the Google Privacy Policy.

Google API Services User Data Policy

NAWA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use Disclosure

NAWA accesses YouTube data (channel comments, video metadata, and reply posting) exclusively to provide AI-powered community management features. We limit our use of YouTube data as follows:

  • We only access, use, store, or share YouTube data that is necessary to provide the features described in this policy
  • We do not use YouTube data for advertising or to serve ads
  • We do not allow humans to read YouTube data unless we have your affirmative agreement, it is necessary for security purposes, or it is required by law
  • We do not transfer or sell YouTube data to third parties

You can revoke NAWA's access to your YouTube data at any time via your Google Account permissions page or through your NAWA account settings.

8. Meta Platform Data (Instagram)

NAWA uses the Instagram Platform APIs. By connecting your Instagram account, you also agree to be bound by Meta's Privacy Policy and Platform Terms.

Meta Platform Terms Disclosure

NAWA's use and transfer of information received from Instagram APIs adheres to Meta's Platform Terms, including the restrictions on prohibited use and sharing of platform data.

Limited Use Disclosure

NAWA accesses Instagram data (comments on your Instagram media, basic account metadata, and reply posting) exclusively to provide AI-powered community management features. We limit our use of Instagram data as follows:

  • We only access, use, store, or share Instagram data that is necessary to provide the features described in this policy
  • We do not use Instagram data for advertising or to serve ads
  • We do not allow humans to read Instagram data unless we have your affirmative agreement, it is necessary for security purposes, or it is required by law
  • We do not transfer or sell Instagram data to third parties
  • We do not use Instagram data for eligibility determinations
  • We do not use Instagram data to discriminate against individuals
  • We do not facilitate surveillance using Instagram data
  • We do not attempt to re-identify or de-anonymize Instagram data

You can revoke NAWA's access to your Instagram data at any time via your Instagram Account permissions page or through your NAWA account settings. Upon revocation, NAWA will cease accessing your Instagram data and will delete it within 30 days in accordance with Section 5 of this policy.

9. Children's Privacy

NAWA is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. Our Terms of Service require that users be at least 18 years old or the age of majority in their jurisdiction.

If we discover that we have collected personal data from a person under 18, we will delete that data promptly. If you believe a minor has provided us with personal data, please contact us at privacy@trynawa.com.

10. Contact & Data Controller

The data controller for the purposes of GDPR and UAE PDPL is:

Nawa Labs FZ-LLC

RAKEZ Business Zone
Ras Al Khaimah, United Arab Emirates
License No. 47026996

General inquiries: hello@trynawa.com

Privacy & data subject requests: privacy@trynawa.com

Support: support@trynawa.com

We aim to respond to all inquiries within 48 hours and to all formal data subject requests within 30 days.