Legal document
Privacy Policy
Last updated: 2026-09-03
1. Who we are
This policy is issued by NAWAH OFFICE, a sole proprietorship
registered in the commercial registry of the Babylon Chamber of Commerce under
number 95293, operating in software solutions.
Address: Hilla Nader 1, near the medical center — Babil, Iraq. Email: info@nawah.io · Phone: +964 774 944 3694
We act as data controller for our customers' account data, and as data processor on behalf of the merchant for their end-customers' messages.
2. Scope
This policy covers nawah.io, the Smart Reply platform, and any application or service we publish under the Nawah name. When a merchant connects their Facebook Page or Instagram account, we process that page's data as described below and in compliance with the Meta Platform Terms.
3. Data we process
| Type | Source | Purpose |
|---|---|---|
| Text of customer messages and comments | Meta (Facebook / Instagram), with the page owner's permission | Generate a suitable reply and show it to the merchant |
| Sender ID, page ID, public display name | Meta | Attach the message to its conversation and reply to the right sender |
| Public page posts and product descriptions | Meta, or uploaded by the merchant | Build the merchant's knowledge base used to draft replies |
| Merchant name, email, phone | Provided by the merchant at sign-up | Account creation, login, support, billing |
| Technical logs and model usage ledger | Generated automatically during operation | Diagnostics, abuse prevention, usage accounting |
We do not request or intentionally store payment card data, identity documents, health data, or any other special category of data. If an end-customer sends such information inside a message, it is treated as message text and follows the same retention and deletion rules.
4. How we use data — and what we never do
We use the above solely to operate the service the merchant asked for: read the message, draft a reply, present it for review, and send it.
- We do not sell, rent, or trade data with anyone.
- We do not use it for advertising, ad targeting, or marketing profiles.
- We do not train AI models on our customers' conversation content.
- Our staff have no routine access to conversation content; access is limited to a reported fault and is logged.
5. Sharing with third parties
We share the minimum necessary with service providers bound by confidentiality terms:
- Language model providers — only the message text and the context needed to draft a reply; no account data.
- Hosting provider — servers located in the European Union (Germany).
- Meta Platforms — to receive messages and send replies through its APIs.
We may also disclose data where required by applicable law or a valid court order.
6. Storage location and retention
Data is stored on servers within the European Union. Conversation content is kept while the merchant's account is active and operationally needed, for a maximum of 24 months from the message date. Technical logs are deleted within 90 days. When an account is closed, its data is deleted within 30 days, except what must be retained for accounting or legal reasons.
7. Data deletion requests
Anyone — a merchant, or an end-customer who messaged a page using our platform — may request deletion of their data:
- Email info@nawah.io with the subject "Data Deletion Request".
- Include the page or shop you messaged, and your Facebook or Instagram display name.
- We acknowledge within 3 business days, complete deletion within 30 days, and send you a confirmation.
8. Your rights
You may request a copy of your data, its correction, its deletion, restriction of processing, or object to processing. Write to info@nawah.io and we will respond within 30 days at the latest. There is no charge for these requests.
9. Security
- All traffic is encrypted over HTTPS/TLS, and data is encrypted at rest.
- Each merchant's data is isolated by constraints enforced at the database level, not in application code.
- Every inbound Meta request is signature-verified before it is processed.
- No system is perfectly secure; we commit to notifying affected people and any competent authority within 72 hours of becoming aware of a breach affecting their data.
10. Children
Our services are directed at business owners and are not offered to anyone under 18. We do not knowingly collect data from children, and will delete it immediately if we learn that we have.
11. Changes to this policy
We may update this policy. The last-updated date appears at the top of this page, and we will notify merchants by email 14 days before any material change takes effect.
12. Contact
NAWAH OFFICE · Hilla Nader 1, near the medical center — Babil, Iraq
info@nawah.io ·
+964 774 944 3694