This Data Processing Addendum / Data Handling Policy ("DPA") forms part of the agreement between HeyNaj Flow and the customer using the Service.
1. Parties
This DPA is between the customer using the Service and Renzhu Rhy Tayko, operating as HeyNaj Flow.
- Provider: Renzhu Rhy Tayko, doing business as HeyNaj Flow
- Address: Batinguel, Dumaguete City, Negros Oriental 6200, Philippines
- Email: heynajflow@gmail.com
2. Purpose
This DPA explains how HeyNaj Flow processes personal data on behalf of customers and summarizes the data-handling practices used in connection with the Service.
3. Roles of the Parties
For customer data processed through the Service, the customer is generally the controller or business that decides why and how the data is used, and HeyNaj Flow is generally the processor or service provider acting on the customer's instructions.
HeyNaj Flow may also act as an independent controller for its own business purposes such as billing, legal compliance, fraud prevention, security, service administration, and direct communications with customer representatives.
4. Service Description
HeyNaj Flow provides AI-assisted website chat, optional voice interaction, lead capture, routing, knowledge syncing, notifications, booking handoff, optional dashboard or app tools, and managed setup or support services.
In the standard service model, the customer provides materials through a secured Google Drive folder or another approved channel, and HeyNaj Flow configures the deployment based on those materials.
5. Categories of Personal Data
- names, email addresses, phone numbers, and company information;
- chat messages, inquiry content, voice messages, audio interaction data, lead details, and summaries;
- booking-related details;
- uploaded business documents, FAQs, and other submitted knowledge materials;
- information about customer representatives who provide instructions or materials;
- optional dashboard or support-tool activity; and
- other personal data the customer chooses to provide through the Service.
6. Categories of Data Subjects
Depending on how the customer uses the Service, data subjects may include customer personnel, leads, prospects, website visitors, end users interacting with a deployed HeyNaj Flow widget, and other individuals whose information the customer provides through the Service.
7. Nature and Purpose of Processing
- host and operate the Service;
- ingest, store, review, and sync knowledge materials;
- process chat and voice interactions where enabled;
- generate AI-assisted responses based on configured rules and inputs;
- notify the customer of leads, inquiries, or abandoned interactions;
- provide logs, summaries, transcripts, notifications, and agreed support or admin tools;
- support troubleshooting, maintenance, and security; and
- improve reliability, detect misuse, and maintain the technical environment, subject to applicable law and contractual commitments.
8. Customer Instructions and Responsibilities
HeyNaj Flow will process customer data only on documented customer instructions, as necessary to provide the Service, as required by law, or as otherwise permitted by written agreement.
- have a lawful basis to collect and submit customer data;
- make sure instructions are lawful;
- decide whether the Service is appropriate for the intended use case;
- keep materials in the secured folder or other approved submission channel accurate and up to date; and
- review knowledge sources, FAQs, prompts, fallback responses, booking links, promotions, and lead-capture settings.
9. Confidentiality
HeyNaj Flow will ensure that people authorized to process customer data are subject to confidentiality obligations or appropriate duties of confidentiality.
10. Security Measures
HeyNaj Flow will use commercially reasonable technical and organizational measures designed to protect customer data, taking into account the nature of the data and the risks involved.
- access controls and authentication protections;
- limited-access practices;
- secured third-party platforms and approved file-submission channels;
- logging and monitoring;
- data segregation where applicable;
- backup and recovery measures;
- vendor management; and
- incident-handling procedures.
No security measure is perfect or absolute.
11. Subprocessors
The customer authorizes HeyNaj Flow to use subprocessors as reasonably necessary to provide the Service, including providers for hosting, storage, document management, communications, analytics, AI processing, booking tools, support tooling, and workflow infrastructure.
Depending on deployment, subprocessors may include Google services, Google Drive, AppSheet, OpenAI, Gemini, and other support, infrastructure, or workflow providers reasonably needed to operate the Service.
12. International Transfers
Because the Service may rely on global cloud and software providers, customer data may be processed in countries other than the customer's own country. Where required, HeyNaj Flow will use reasonable steps and appropriate safeguards for such transfers.
13. Data Subject Rights Assistance
Taking into account the nature of the processing, HeyNaj Flow will provide reasonable assistance, where legally required and commercially appropriate, so the customer can respond to valid data-subject requests.
14. Security Incident Assistance
Taking into account the nature of the processing and the information available, HeyNaj Flow will provide reasonable assistance with security incidents involving customer data, legally required breach-response support, relevant investigations into confirmed incidents, and other reasonable compliance-related cooperation tied to the Service.
15. Return or Deletion of Data
After termination or expiration of the Service, and subject to applicable law, technical limitations, contractual obligations, and reasonable retention practices, HeyNaj Flow will delete or return customer data as agreed with the customer.
16. AI and Knowledge Materials
The customer acknowledges that AI-assisted output depends in part on the knowledge materials, configuration, and rules used in the deployment. Inconsistent, conflicting, or outdated materials may lead to inconsistent responses.
Customer business content submitted for a deployment is not used by HeyNaj Flow to train public-facing open AI models for general use, except where the customer separately instructs, authorizes, or enables a workflow that clearly requires that use.
17. Sensitive or Regulated Data
Unless expressly agreed in writing and properly configured, the customer should not use the Service to process highly sensitive personal data, health data, children's data, government identification numbers, payment card data, regulated financial data, or other data requiring specialized safeguards.
18. Audit and Information Rights
Upon reasonable written request, HeyNaj Flow will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, proportionality, and administrative limits. If a formal audit right is needed, it should be addressed in a separate written agreement.
19. Contact
For questions about this DPA or our data-handling practices, contact heynajflow@gmail.com.