Privacy, consent and security
Plain language, because this matters. Nayaria is built so that the data it handles is lawful, provable, and safe.
Consent, recorded and provable
Consent is captured as a record with a timestamp, the channel, and the evidence: the exact message a buyer sent, the web form they submitted, or the client's attestation that their own system collected the lead lawfully. When someone starts a conversation with us, that act is itself recorded as consent to reply. The platform tracks any record that is missing consent so it is resolved before outreach, and for any contacted record we can show where it came from and why we were allowed to reach them.
Opt-out, honored instantly
Anyone can stop contact at any time by saying so in plain words, on any channel, in their own language. The moment they do, it is recorded and that address is never contacted again. Opt-outs are kept on an auditable list. Newsletter sign-ups use double opt-in where email is enabled, and every newsletter carries a one-click unsubscribe that takes effect at once.
Calling hours, respected
Automated outbound contact only happens inside the hours permitted where each buyer is, in their own time zone: India follows the TRAI promotional window, and other markets follow their local equivalents. Outside the window, a message waits politely for the next allowed time rather than being dropped or sent late.
Your data, under the laws that apply to it
Personal data is handled in line with the data-protection law that applies where each buyer is, including the EU's GDPR, India's Digital Personal Data Protection Act, the US's CCPA, and comparable regimes elsewhere. We support export and deletion on request, we keep an audit trail of who did what, and we never train or fine-tune any AI model on a client's data. The AI answers by retrieving real records at the moment of the conversation, which keeps answers accurate and keeps the data yours.
Who else touches it, and where it goes
To answer a buyer at all, their message is sent to an AI provider. We use Sarvam AI (India), Groq, OpenRouter and OpenAI, and recorded audio messages a buyer sends are transcribed by Sarvam or OpenAI. Messages travel through the channel your business uses: Meta's WhatsApp Business Platform, and Gupshup, who connect us to it. Email is sent through Resend, payments are handled by Razorpay and Stripe, and the product runs on managed cloud hosting with a managed database. If your business connects its own CRM or calendar, data also goes to that service at your instruction. Some of these providers are outside India, so personal data may be processed abroad under the safeguards their terms and applicable law require. None of them is permitted to use the data for their own purposes, and none of them trains a model on it.
Security, layered and honest
Access is role-based and least-privilege: a client only ever sees their own client. Sign-in supports two-factor authentication. Sessions are signed and time-limited. Sensitive actions are written to an audit trail. Data is encrypted in transit, and at rest when deployed on the recommended managed database. No system is unbreachable, and we will never claim otherwise, but Nayaria is built to current best practice and fails safely.