Security and data handling
Every NUWIAX system is built so the AI sees as little of your customers' data as it needs to do its job.
Data minimization
Order lookup by order number only. Customer names, phone numbers, email addresses and delivery addresses from your order records never reach an AI model. A privacy gate in code enforces this.
Access and secrets
API keys and tokens live in an encrypted credential store, never in code or prompts, and refresh automatically. Client dashboards sit behind identity-based access control. Input is validated, and agents are built to ignore instructions hidden in customer messages or documents.
Retention
Conversation logs and tickets are kept for 30 days by default, or for the period your own policy requires. Backups run nightly.
Platform rules and AI disclosure
Every send step follows the platform's rules, including Meta's 24-hour reply window. Agents never claim to be human, and disclose that they are AI where the law or the client requires it, including under the EU AI Act for EU-facing deployments.
Incidents
Health checks run every 30 minutes. If a workflow fails or a platform rejects a message, we are alerted within that window, and a failure ticket names the cause.
Subprocessors
Services that may process data in the systems we operate. The exact list depends on each client's setup and is confirmed in the statement of work.
- n8n, self-hosted by NUWIAX: automation runtime and data tables
- OpenAI: language models
- Google (Gemini): fallback language models
- Groq: fast and fallback models
- Jina AI: image embeddings for product recognition
- Meta Platforms: Instagram and WhatsApp messaging
- Shopify: catalog and order status from the client's store
- Retell: voice agent calls
- Resend: alert and report email
- Cloudflare: website hosting and dashboard access control
Have a security questionnaire or need a data processing agreement? Email support@nuwiax.com.