Legal

Data Handling Policy

This page explains how HeyNaj Flow handles customer data when operating as a service provider for client deployments.

Last Updated: July 11, 2026

This Data Processing Addendum / Data Handling Policy ("DPA") forms part of the agreement between HeyNaj Flow and the customer using the Service.

1. Parties

This DPA is between the customer using the Service and Renzhu Rhy Tayko, operating as HeyNaj Flow.

2. Purpose

This DPA explains how HeyNaj Flow processes personal data on behalf of customers and summarizes the data-handling practices used in connection with the Service.

3. Roles of the Parties

For customer data processed through the Service, the customer is generally the controller or business that decides why and how the data is used, and HeyNaj Flow is generally the processor or service provider acting on the customer's instructions.

HeyNaj Flow may also act as an independent controller for its own business purposes such as billing, legal compliance, fraud prevention, security, service administration, and direct communications with customer representatives.

4. Service Description

HeyNaj Flow provides AI-assisted website chat, optional voice interaction, lead capture, routing, knowledge syncing, notifications, booking handoff, optional dashboard or app tools, and managed setup or support services.

In the standard service model, the customer provides materials through a secured Google Drive folder or another approved channel, and HeyNaj Flow configures the deployment based on those materials.

5. Categories of Personal Data

6. Categories of Data Subjects

Depending on how the customer uses the Service, data subjects may include customer personnel, leads, prospects, website visitors, end users interacting with a deployed HeyNaj Flow widget, and other individuals whose information the customer provides through the Service.

7. Nature and Purpose of Processing

8. Customer Instructions and Responsibilities

HeyNaj Flow will process customer data only on documented customer instructions, as necessary to provide the Service, as required by law, or as otherwise permitted by written agreement.

9. Confidentiality

HeyNaj Flow will ensure that people authorized to process customer data are subject to confidentiality obligations or appropriate duties of confidentiality.

10. Security Measures

HeyNaj Flow will use commercially reasonable technical and organizational measures designed to protect customer data, taking into account the nature of the data and the risks involved.

No security measure is perfect or absolute.

11. Subprocessors

The customer authorizes HeyNaj Flow to use subprocessors as reasonably necessary to provide the Service, including providers for hosting, storage, document management, communications, analytics, AI processing, booking tools, support tooling, and workflow infrastructure.

Depending on deployment, subprocessors may include Google services, Google Drive, AppSheet, OpenAI, Gemini, and other support, infrastructure, or workflow providers reasonably needed to operate the Service.

12. International Transfers

Because the Service may rely on global cloud and software providers, customer data may be processed in countries other than the customer's own country. Where required, HeyNaj Flow will use reasonable steps and appropriate safeguards for such transfers.

13. Data Subject Rights Assistance

Taking into account the nature of the processing, HeyNaj Flow will provide reasonable assistance, where legally required and commercially appropriate, so the customer can respond to valid data-subject requests.

14. Security Incident Assistance

Taking into account the nature of the processing and the information available, HeyNaj Flow will provide reasonable assistance with security incidents involving customer data, legally required breach-response support, relevant investigations into confirmed incidents, and other reasonable compliance-related cooperation tied to the Service.

15. Return or Deletion of Data

After termination or expiration of the Service, and subject to applicable law, technical limitations, contractual obligations, and reasonable retention practices, HeyNaj Flow will delete or return customer data as agreed with the customer.

16. AI and Knowledge Materials

The customer acknowledges that AI-assisted output depends in part on the knowledge materials, configuration, and rules used in the deployment. Inconsistent, conflicting, or outdated materials may lead to inconsistent responses.

Customer business content submitted for a deployment is not used by HeyNaj Flow to train public-facing open AI models for general use, except where the customer separately instructs, authorizes, or enables a workflow that clearly requires that use.

17. Sensitive or Regulated Data

Unless expressly agreed in writing and properly configured, the customer should not use the Service to process highly sensitive personal data, health data, children's data, government identification numbers, payment card data, regulated financial data, or other data requiring specialized safeguards.

18. Audit and Information Rights

Upon reasonable written request, HeyNaj Flow will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, proportionality, and administrative limits. If a formal audit right is needed, it should be addressed in a separate written agreement.

19. Contact

For questions about this DPA or our data-handling practices, contact heynajflow@gmail.com.