Legal & Compliance

Privacy Policy

Learn how Nidaa collects, processes, and protects your personal data and customer voice communications.

Effective Date: September 1, 2026Version: 2.4

Zero Data Selling

We never sell, rent, or monetize your customer phone numbers, call audio, or contact lists.

Enterprise Encryption

All telephony logs, API payloads, and recordings are encrypted with TLS 1.3 in transit and AES-256 at rest.

Telecom Compliance

Engineered in compliance with Algerian Law 18-07, EU GDPR, and regional telecommunications regulations.

Full User Rights

Granular controls for access, data export, instant opt-out blacklists, and complete data deletion.

1. Introduction and Data Controller

Nidaa Technologies ("Nidaa", "we", "us", or "our"), operating the domain nidaa.io and associated applications, provides enterprise Voice-as-a-Service (VaaS), automated outbound dispatch, interactive voice response (IVR), Cash on Delivery (COD) confirmations, voice one-time password (OTP) verification, and multimodal ledger OCR extraction.

This Privacy Policy outlines the types of personal and organizational data we collect, our lawful bases for processing, how such information is secured, and your rights as a registered client, API consumer, or call recipient.

For clients and users residing in Algeria, processing conforms to Law No. 18-07 of June 10, 2018 relative to the protection of physical persons in the processing of personal data. For European and international operations, processing adheres to the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).

2. Roles: Data Controller vs. Data Processor

To ensure absolute transparency regarding responsibilities under global data protection laws, Nidaa operates in two distinct legal capacities:

A. Data Controller: We act as the Data Controller for direct account registration details, corporate billing data, direct communications with our sales and technical support staff, and technical telemetry collected from visits to nidaa.io.

B. Data Processor: When our business clients upload recipient contact lists, customer ledgers, order records, or audio variable parameters to execute automated voice calls, Nidaa acts strictly as a Data Processor. The client remains the primary Data Controller responsible for obtaining lawful recipient opt-in and consent.

3. Categories of Information We Collect

We collect information across distinct functional tiers to deliver and secure our voice telecom infrastructure:

A. Direct Account & Identity Data

When you register for a Nidaa account, subscribe to a tier, or request an enterprise API key, we collect:

  • Full legal name, business email address, and direct phone number.
  • Company legal name, commercial registry (Registre de Commerce), and fiscal identification (NIF/NIS).
  • Billing address, invoice history, and tokenized payment records (handled by PCI-DSS compliant payment gateways).

B. Voice, Telephony & Campaign Data

When utilizing our automated calling, OTP, and conversational routing infrastructure, we process:

  • Destination phone numbers, recipient names, and custom appointment/order dynamic variables.
  • Call Detail Records (CDRs): timestamp, call duration, SIP termination status codes, network latency, and carrier route identifiers.
  • DTMF Keypad Inputs (e.g., recipient pressing "1" to confirm a delivery, or "2" to reschedule).
  • Call Audio Recordings & AI Transcripts: processed strictly when the client enables the recording/transcription feature for customer service auditing.
  • Scanned Document Images (كناش / Paper Ledgers): uploaded via the Nidaa Mobile App for multimodal OCR lead extraction. Raw images are transiently processed and automatically discarded.

C. Technical, Device & Security Telemetry

When interacting with our dashboard or developer endpoints, our servers automatically log:

  • Public IP addresses, HTTP request headers, and user-agent metadata.
  • API request latency, rate-limiting counters, and webhook delivery status.
  • Essential authentication session cookies and localized interface preferences.

4. Legal Bases for Processing

We only collect and process personal data when permitted by applicable legal frameworks:

1. Performance of a Contract: Processing is essential to set up your account, terminate SIP voice calls, deliver OTP authentication tokens, and generate service billing.

2. Compliance with Legal Obligations: Telecommunications regulations require the retention of anonymized or pseudo-anonymized Call Detail Records (CDRs) for network integrity, fraud deterrence, and statutory lawful interception rules.

3. Legitimate Interests: Detecting telecom toll fraud, preventing illegal robocalling and harassment campaigns, securing our private WireGuard VPN gateways, and continuously training latency-optimization algorithms.

4. Consent: Where explicit consent is mandated by local law (such as opt-in marketing broadcasts, client recording notifications, or voluntary participation in preview AI voice models).

5. Sub-processors and Third-Party Disclosures

Nidaa does not sell, rent, or trade your data. We share information only with trusted enterprise partners who are bound by rigorous data processing agreements (DPAs):

A. Telecommunication Carriers & Local Operators

Voice calls, SMS verifications, and voice OTPs are routed through authorized telecommunications carriers (such as Algérie Télécom and regional Tier-1 SIP interconnect partners). Carriers receive destination phone numbers solely to terminate the physical phone connection.

B. Cloud & Hosting Infrastructure

Our application servers, database instances, and private VPN relays are hosted in enterprise data centers (including Google Cloud / Firebase and OVHcloud) located in Europe and Algeria, protected by SOC 2 and ISO 27001 certifications.

C. Speech Synthesis & Multimodal AI Engines

Text-to-Speech (TTS) variables and ledger OCR recognition are executed via dedicated enterprise AI pipelines under strict confidentiality terms. Customer data is NEVER used to train public foundation models.

D. Legal & Regulatory Disclosures

We may disclose metadata if legally compelled by a valid judicial subpoena, court order, or official request from competent regulatory authorities (such as the ARPCE in Algeria or European law enforcement agencies).

6. Data Retention and Purging

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with statutory retention laws:

- Client Account Data: Retained throughout the duration of active commercial engagement and archived for up to 5 years following account closure to satisfy corporate financial audit standards.

- Campaign Contact Lists: Stored within the client dashboard and retained until explicitly deleted or updated by the client.

- Call Audio Recordings: Retained according to client-defined lifecycle rules (defaulting to 30 days), after which they are permanently deleted from object storage.

- Multimodal Ledger OCR Images: Temporary image files uploaded from the mobile application are permanently destroyed within 7 calendar days after human verification and contact extraction.

- Telecommunications CDRs: Retained for 12 months in compliance with mandatory telecom fraud prevention and regulatory traceability requirements.

7. Technical & Organizational Security Measures

We apply defense-in-depth architectural safeguards to defend customer data against unauthorized access, destruction, or interception:

- Encryption in Transit: All dashboard interactions, API queries, and webhooks require TLS 1.3 with modern cryptographic cipher suites.

- Encryption at Rest: Databases, object storage buckets, and cached variable audio fragments are protected by AES-256 disk encryption.

- Isolated Telecom Tunneling: Cloud PBX servers communicate with local Algerian telecom hardware exclusively through authenticated, encrypted WireGuard VPN tunnels.

- Access Control & Auditing: Least-privilege role-based access control (RBAC), multi-factor authentication (MFA) enforcement for operational staff, and immutable access logging.

- Continuous Vulnerability Management: Automated dependency auditing, static application security testing (SAST), and regular system penetration testing.

8. Your Legal Rights & Choices

Subject to the laws of your jurisdiction (including Algerian Law 18-07 and the GDPR), you hold fundamental rights regarding your data:

- Right to Access: You may request a complete export of the personal information we hold about you.

- Right to Rectification: You may correct inaccurate or incomplete profile and billing records directly through your dashboard.

- Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your account and related records. Please see our dedicated Data Deletion page for step-by-step instructions.

- Right to Restrict or Object to Processing: You can limit how we process specific subsets of data or decline non-essential telemetry.

- Call Recipient Opt-Out: If you are an individual end-user who received an automated voice notification from a company using Nidaa and wish to be permanently removed, you can submit your phone number to our Global Blacklist via contact@nidaa.io, ensuring no client on Nidaa can call your number.

9. Updates to This Privacy Policy

We may periodically update this policy to mirror technological advancements, telecom regulatory changes, or new platform features. When changes are published, the "Last Updated" and "Version" timestamps at the top of this document will reflect the revision date.

Material alterations affecting your rights will be communicated through email notifications or prominent banners on the Nidaa Web Dashboard prior to their effective date.

Data Protection Officer & Privacy Inquiries

If you have questions, require legal compliance documents, or wish to exercise your data protection rights, our dedicated compliance team is ready to assist you.

Direct Compliance Emailprivacy@nidaa.io
Nidaa Legal & Data Privacy DepartmentAlgiers, Algeria / Regional Operational Hubs