Who this covers
Nia is used by a business to answer its own customers on WhatsApp. The business decides what to collect and why; Nia processes it on that business's instructions. Questions about a particular business's use of Nia should go to that business.
This policy is published by Nia and applies to the Nia service at niainteract.com.
What Nia holds
- WhatsApp messages sent to and from the business's number, including attachments, and their delivery state.
- Contact details the customer provides in the chat: phone number, name, and any tags or fields the business chooses to record.
- Consent and opt-out state, so a customer who opts out of marketing messages is not sent them again.
- Documents and content the business uploads to teach Amina, its Nia assistant, how to answer.
- Phone number lists the business uploads for a broadcast.
- Accounts for the business's own staff: name, email, role, and sign-in state.
- Records of privileged actions taken in the product, of what WhatsApp reported back, and of AI usage and cost.
What Nia does not do
- No selling of data, and no advertising profiles.
- No use of one business's data to answer another business's customers.
- No use of customer conversations to train a general-purpose AI model.
AI processing
To draft a reply, the text of the conversation and the business's own uploaded content are sent to the AI provider configured for that business. Providers are used to process the data for that purpose only. Amina drafts and sends replies; the business can take any conversation over and answer itself.
Where the data is kept
Nia stores data with third-party cloud hosting providers under contract. Access to those systems is limited to the people who operate Nia, by named account.
How long it is kept
Each business sets its own retention periods in Nia, under Settings, then Data & privacy. The automatic retention sweep is off until the business switches it on, and it is off for every business that has never opened that page. While it is off, Nia deletes nothing of its own accord: data is kept until the business removes it, asks for it to be removed, or closes its account.
Switching the sweep on is the business's decision, not Nia's, and only that business's own data is affected by it.
Rights and requests
A person may ask the business they were messaging for a copy of their data, or for it to be erased. The business raises that request in Nia, decides it, and Nia carries it out. Erasure replaces the content of the person's messages with a redaction marker, removes the phone number and email from the contact record, and minimises the usage records that pointed to it. How to do this is set out on the data deletion page.
Security
- Access is by named account and role, and every business's data is kept separate from every other business's.
- A user can add an authenticator app to their own account, from their profile page in Nia. Once they have, Nia asks for a code from that app at sign-in as well as their password.
- Privileged actions are recorded in an audit log the business can review.
- Credentials for WhatsApp and other connected services are stored encrypted and referenced by name; the values are never shown in the product or written to logs.
Browser extension
If a business uses the Nia Web Assistant browser extension, what that extension can read and send to Nia is set out on the extension disclosure page.
Changes and contact
When this policy changes, the date at the top of this page changes with it.
Questions about a business's use of Nia go to that business. Questions for Nia itself go through the support contact published in your Nia workspace; if your business has not set one, ask the person who owns your Nia account.