Privacy Policy

Last updated: August 15, 2026

1. INTRODUCTION

Your privacy is very important to us at Naayya, and we are dedicated to protecting it and maintaining your trust. This Privacy Policy explains our online information practices and the choices you have regarding how your information is collected and used when you interact with Naayya S.A.R.L.-S ("Naayya," "we," "us," or "our") through our platform and services at https://www.naayya.com (the "Website").

In this policy, "Personal Data" refers to information that can identify you as an individual, and "processing" means any operation performed on Personal Data, such as collection, storage, use, or sharing. Other terms not defined here have the meanings given in our Terms of Service.

We use Personal Data to provide, secure, support, and improve the Naayya platform and services as described in this Privacy Policy. This Privacy Policy explains our processing practices, but it does not replace any separate consent choices you may have under applicable law for optional analytics, advertising, or similar tracking.

Our role in processing your Personal Data may vary depending on the context:

  • As a Data Processor: When we deliver services to our partners or subscribers, we may process Personal Data on their behalf. In these cases, our partners are responsible for their own privacy policies and for informing their end users.
  • As a Data Controller: For our own marketing, account management, and direct interactions with you, Naayya acts as the Data Controller and is responsible for your Personal Data as described in this policy.

We encourage you to read this Privacy Policy in full to understand how your information is handled. If you have any questions or concerns about our privacy practices, please contact us at support@naayya.com.

If you do not agree with the processing that is necessary to provide, secure, and support the Naayya platform and services, please do not use the platform or services. Optional analytics and advertising choices can be managed separately where those controls are available.

2. DEFINITIONS

The following definitions apply throughout this Privacy Policy. Words with capitalized initial letters have the meanings set out below, whether used in singular or plural form:

  • Account: A unique account created for you to access our platform and services.
  • Company: Refers to Naayya S.A.R.L.-S, the legal entity responsible for the Website and services (also referred to as "Naayya," "we," "us," or "our").
  • Cookies: Small files placed on your device by our Website, used for various purposes including remembering your preferences and tracking usage.
  • Data Controller: For the purposes of the GDPR, the Company that determines the purposes and means of processing your Personal Data.
  • Data Processor: A natural or legal person who processes Personal Data on behalf of the Data Controller.
  • Device: Any device that can access the Naayya platform, such as a computer, smartphone, or tablet.
  • GDPR: The General Data Protection Regulation (EU) 2016/679, which governs data protection and privacy in the European Union.
  • Personal Data: Any information relating to an identified or identifiable natural person. This includes, for example, your name, email address, identification number, location data, or other factors specific to your identity.
  • Platform: The Naayya Website and any related applications or services provided by Naayya.
  • Service: The Website and all related features, content, and services offered by Naayya.
  • Service Provider: Any third party or individual who processes data on behalf of Naayya to help provide the Service, such as hosting, analytics, or payment processing providers. For GDPR purposes, Service Providers are considered Data Processors.
  • Usage Data: Data collected automatically, either generated by your use of the Service or from the Service infrastructure itself (for example, duration of a page visit or device/browser information).
  • User/You: The individual accessing or using the Naayya platform or services, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under GDPR, you may be referred to as the Data Subject or User.

Any other terms used in this Privacy Policy that are defined in Article 4 of the GDPR (such as controller, processor, data subject, and others) shall have the same meaning as defined in the GDPR.

3. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to all users of the Naayya platform and services. It does not cover information related to employees, which is governed by internal policies, or service providers, which may be subject to separate agreements. This Privacy Policy is part of, and subject to, our Terms of Use. Any capitalized terms not defined here have the meanings given in our Terms of Use.

4. WHAT PERSONAL DATA DO WE COLLECT?

We may collect personal data that you provide directly to us, such as:

  • Name
  • Email address
  • Username
  • Password
  • Phone number
  • Address
  • Optional health disclosures you choose to store in your account, such as injury, pregnancy, medical, or other safety-related notes
  • Payment data (processed securely via Stripe; we do not store payment details)
  • Comments, feedback, and survey responses
  • Any other information you choose to provide via forms or communication

We may also collect certain data automatically, depending on your use of the platform and your privacy choices, including:

  • IP address
  • Browser type and device information
  • Pages visited and time spent on pages
  • Referring website
  • Cookies or other tracking identifiers
  • Usage data (e.g., features used, frequency, and duration of activities)
  • Crash reports, error diagnostics (such as stack traces, browser state, and page URL at the time of an error), and log files

5. HOW DO WE COLLECT YOUR DATA?

We collect your personal data in several ways, depending on how you interact with Naayya:

  • Directly from you: When you create an account, fill out forms, make a booking, communicate with us, or otherwise use our services, you provide us with personal data.
  • From third parties: If you access our platform through a third-party application (such as a social login, app store, or social networking site), we may collect personal data that you have made available via your privacy settings on those platforms.
  • Automatically as you use our platform: We collect technical and operational information such as your IP address, device and browser information, session state, route or screen name, request identifiers, and service error details needed to deliver, secure, and troubleshoot the platform. Where permitted by law or based on your consent choices, we may also collect analytics or advertising-related data such as page views, interactions, referrer information, and cookie or similar identifiers.
  • Log files: We collect operational log data, which may include IP addresses, browser types, timestamps, request metadata, and other service diagnostics used to detect abuse, investigate incidents, and keep the platform reliable. We do not treat optional advertising or product analytics as automatically required to provide the service.
  • Crash reports: If you submit crash reports, we may collect diagnostic information about your device and the activities that led to the crash.
  • Cookies and tracking technologies: We use cookies and similar technologies to collect data about your interactions with our platform. For more information, please see our Cookie Policy.
  • Online forms: We may collect personal data via forms based on your interaction with us. Each form will explain the purpose for collecting such data.
  • Social media platforms: Our platform may include buttons or widgets for social media platforms (such as Facebook, Instagram, or X). These features may collect your IP address and set cookies to function properly. Your interactions with these platforms are governed by their respective privacy policies.
  • Direct interaction: We may collect personal data from you as part of your direct interactions with us, such as when you contact support or sales.

6. WHY WE COLLECT AND HOW WE USE YOUR DATA

We do not sell your personal data. We collect and process your data only as permitted by applicable data protection and privacy laws. In many cases, we need to collect and process certain personal data to provide you with access to Naayya's services. When you register or use our platform, you may be asked to provide consent for us to process your data, and you can withdraw this consent at any time.

We use your data for a variety of purposes, including:

  • To provide and operate our services: We use your data to create and manage your account, deliver our platform features, process bookings and payments, provide customer support, and communicate with you about your account or transactions. This processing is necessary for the performance of our contract with you.
  • To ensure security and prevent misuse: We process data to protect Naayya and our users from fraud, unauthorized access, and other unlawful activities. This includes monitoring for suspicious activity and enforcing our terms and policies. The legal basis is our legitimate interest in maintaining a secure platform.
  • To improve and develop our services: We use service telemetry, support interactions, operational metrics, and feedback to understand failures, identify trends, and improve the platform. We may also use aggregated or de-identified data for these purposes. Where the analysis relies on non-essential cookies, advertising technologies, or identifiable product analytics, we ask for consent where required by law.
  • For internal record-keeping and evidence: We keep records of your interactions with us, including communications, transactions, and support requests, to maintain evidence of our relationship, resolve disputes, and comply with our policies. This is based on our legitimate interests and legal obligations.
  • To promote and market our services: With your consent or where permitted by law, we may use your contact details to send you information about Naayya's offerings, updates, or promotions. We may also use anonymized or aggregated data to help us understand our audience and improve our marketing. Third-party service providers may assist us with these activities, but they will not use your data for their own purposes.
  • To comply with legal obligations: We may use and disclose your data as required by law, such as for accounting, tax, regulatory, or legal process purposes. This includes responding to lawful requests from authorities or courts.

Some businesses using Naayya may require a verified phone number before you can complete a booking or related account-completion flow. In those cases, we process and store that phone number to support booking administration, account security, and operational contact related to the services you use. Verifying a phone number does not by itself subscribe you to marketing messages, and any separate marketing or promotional messaging consent is handled independently where required by law.

To troubleshoot verification failures and evidence security-sensitive booking requirements, we keep the full phone verification troubleshooting record for up to 30 days, retain a minimized audit record for up to 12 months, and delete these records sooner when the related account is deleted.

You may object to certain types of processing or withdraw your consent at any time by contacting us. We will always respect your choices as required by law.

Optional Health Disclosures

If you choose to add health information in your account, this may include injuries, pregnancy, medical conditions, or other safety-related notes. Because this information may qualify as special-category personal data under the GDPR, we apply additional restrictions to it.

This feature is optional. We store this information within restricted account systems, keep it out of general customer-list and instructor-roster views, and allow you to edit or delete it at any time in your account health settings. We only store this optional health data after you explicitly consent to that storage in your account settings. When you give or withdraw that consent, we keep a minimal record of the notice version shown, the time, the source, and limited technical metadata such as IP address and user agent so we can evidence your privacy choices. Where this data is treated as special-category personal data under applicable law, we process it only for this optional feature and with the additional restrictions described in this policy.

Please only provide the minimum information you want us to keep on file. If you no longer want us to hold this data, you can remove it directly from your account or contact support@naayya.com.

Email, SMS, and WhatsApp Communications

We send different categories of communications for different purposes. The legal basis and controls depend on the category:

  • Transactional emails (contractual necessity): Booking confirmations and cancellations, appointment reminders, payment receipts, security alerts, and other account-related notices required to provide the service you use.
  • Service emails (legitimate interests): Important service updates, product or policy changes, and operational notices needed to keep your account functional, secure, and up to date.
  • Marketing emails (consent, or soft opt-in where permitted by law): Promotional offers and campaign messages. You can opt out at any time.
  • Editorial newsletter — The Signal by Naayya (soft opt-in, ePrivacy Art. 13(2) / GDPR Recital 47): A weekly editorial newsletter for business owners, managers, and teachers. When you create an account in one of those B2B roles, we automatically enroll you in The Signal because it is reasonably expected as part of running a Naayya account. Every issue includes a one-click unsubscribe link, and you can opt out at any time via that link or via your account email preferences. The Signal is delivered via Resend (see Section 16, Sub-processors).
  • Operational SMS or WhatsApp updates (your channel preference plus service necessity/legitimate interests, depending on the message): Where supported, you may choose to receive booking, payment, reminder, or similar operational updates on your verified phone number by SMS or WhatsApp. These channel preferences are stored separately from the verified-phone requirement itself.
  • Promotional SMS or WhatsApp messages (consent where required by law): Optional re-engagement or promotional phone messages, such as waitlist spot promotions, are managed separately from operational phone updates and can be turned off independently.

What legitimate interest means: We process limited personal data for communications that are reasonably expected as part of running a secure and reliable service, while balancing those interests against your rights and freedoms.

You can manage communication preferences in your account settings where available, use the unsubscribe link in marketing emails, or contact support@naayya.com. We process unsubscribe requests as soon as reasonably possible and no later than 10 business days.

Turning off promotional channels does not stop transactional or service communications that are necessary to provide your account, bookings, payments, security notices, or other core service updates. If a business requires a verified phone number for booking administration, that requirement remains separate from whether you choose SMS or WhatsApp as optional delivery channels.

Optional Google Workspace Connection

A business owner or staff member with the business's integration permission may choose to connect their own Google account to Naayya for three visible features: reading Gmail messages, creating user-requested Gmail drafts, reading busy/free Google Calendar availability, and reading Google Drive files that the user actively selects. Google's narrowest general Gmail permission for creating drafts also permits sending at the provider level. Naayya does not expose or call a Gmail send action, does not modify Google Calendar, and uses the narrow Google Drive per-file permission rather than broad access to every Drive file.

Gmail, Calendar, and Drive content is requested from Google when the user invokes a relevant feature. Naayya does not copy that content into a permanent content database. We store the connected Google account identity, granted permissions, enabled features, an encrypted refresh credential, and content-free provider action audit records. For draft creation, that audit contains a request identifier, one-way request fingerprint, status, recipient count, and Google draft identifier, but no recipients, subject, message body, or raw MIME content. Access is limited to the Naayya profile that connected the Google account.

Google Workspace data is used only to provide or improve the specific user-facing productivity feature requested by that user. It is not sold, used for advertising, transferred to data brokers, used for credit decisions, or used to train or improve a general machine-learning or artificial-intelligence model. If an AI feature processes Google Workspace data, it may do so only for the requesting user's visible feature and not for a model shared across customers. Human access is prohibited except with the user's documented permission for specific support, or where necessary for security or legal compliance.

You can disconnect Google at any time in Integrations. Disconnecting deletes the encrypted refresh credential and connector state for that Naayya profile and business. Google treats revocation as one project-wide grant for the Google account, so Naayya revokes Google access when the last Naayya binding for that Google account is removed; an earlier business binding is removed without interrupting another binding that still uses the same account. Files, messages, and Calendar availability that remain in your Google account are managed through Google. Naayya's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

7. HOW WE SHARE AND DISCLOSE YOUR DATA

We do not sell your personal data. However, we may share the information we collect in the following ways:

  • Businesses you book with: We may share the account, booking, attendance, and contact details needed to provide the booking service with the business you choose to book with, including a verified phone number where that business requires one for booking administration or operational follow-up.
  • Vendors and Service Providers: We may share your data with trusted third-party vendors and service providers who help us operate our platform, deliver services, process payments, send communications, or support our marketing and analytics efforts. These providers are only permitted to use your data as necessary to perform their services for us.
  • Aggregate or De-identified Information: Where legally permissible, we may use and share information about users in aggregated or de-identified form that cannot reasonably be used to identify you, for analytics, research, or business purposes.
  • Advertising Partners: We may work with third-party advertising partners to show you relevant ads. These partners may set and access their own cookies or similar technologies and may collect information about your use of our platform and other online services over time.
  • Third-Party Partners: We may share information with third-party partners to receive additional publicly available information about you or to enhance our services.
  • Referrals: If you sign up for our services through a referral, we may share information with your referrer to let them know you used their referral link.
  • Analytics Providers: We use analytics services (such as Google Analytics and PostHog) to help us understand how our platform is used. These providers may use cookies and similar technologies to collect non-identifying information about your use of our services. For more information, see their privacy policies.
  • Business Transfers: If we are involved in a merger, acquisition, financing, sale of assets, bankruptcy, or similar event, your information may be transferred to a successor or acquirer as part of that transaction.
  • Legal Requirements and Protection: We may share your data to comply with applicable laws, regulations, legal processes, or governmental requests; to enforce our Privacy Policy and Terms of Service; to detect, prevent, or address fraud, security, or technical issues; to respond to your requests; or to protect the rights, property, or safety of Naayya, our users, or the public.
  • With Your Consent: We may share your information for other purposes if you have given us your explicit consent.

8. THIRD-PARTY SERVICES

Our platform may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy policies before providing any information.

9. EMBEDDED WIDGET AND PLUGIN

Naayya provides an embeddable calendar widget that businesses may integrate into their own websites. When you interact with a Naayya widget embedded on a third-party website:

  • Data collection: The widget may collect usage data such as page views, interactions, device information, and IP address to provide and improve the booking service.
  • Cookies: The widget uses essential cookies required for functionality (such as session management). Analytics cookies are not set by the widget unless you navigate to the main Naayya website.
  • Data Processor role: When data is collected through an embedded widget, Naayya acts as a Data Processor on behalf of the business (the Data Controller). The business is responsible for their own privacy policy and for informing their users about data collection.
  • Cookie consent: The website embedding our widget is responsible for obtaining any required cookie consent from their users before loading the widget, in accordance with applicable laws such as GDPR and ePrivacy Directive.

Businesses using our embedded widget should include information about Naayya in their privacy policy and ensure compliance with applicable data protection laws.

10. DATA SECURITY

We implement technical and organizational measures to protect your data, including:

  • Encryption of data in transit and at rest where feasible
  • Secure authentication methods
  • Regular security audits and compliance checks
  • Access controls and staff training

While we strive to protect your data, no service is completely secure. We cannot guarantee that unauthorized access, hacking, or data loss will never occur.

11. DATA RETENTION

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, or as required by law. You can request account deletion directly from your account settings in the Naayya app. Deletion requests are processed with a 30-day grace period. Once processed, we delete the related authentication account and anonymize profile/contact personal data while retaining limited historical business and financial records where required for legal compliance, tax, accounting, dispute resolution, fraud prevention, and security.

Email address retention follows the same rule: we keep contact email data while an account is active and remove or anonymize it when deletion is completed, except where retention is required by law. We also keep minimal suppression or preference records when necessary to honor unsubscribe requests, prevent unintended re-subscription, and comply with legal obligations.

Health disclosures are kept only while they remain in your account. You can edit or delete them at any time in your health settings. If you request account deletion, we clear both the dedicated health disclosure records and any legacy disclosure fields as part of the deletion workflow. If you withdraw health-disclosure consent, we delete the saved health disclosures from your account. We do not retain health disclosures for tax, accounting, or ordinary business-history purposes, although we may retain minimal consent-history records to evidence your choices and comply with legal obligations.

For an optional Google Workspace connection, Google content is read on demand and is not kept in a permanent Naayya content database. OAuth request state expires after 10 minutes and is removed by daily retention cleanup. Connection metadata, the encrypted refresh credential, and content-free provider action audit records remain while the connection is active. They are deleted when the connecting profile is deleted, with shared-grant-aware Google revocation completed before the last binding is deleted; disconnecting immediately removes the selected profile and business binding.

12. YOUR RIGHTS AND CHOICES

Depending on your location, you may have the following rights regarding your personal data:

  • Right to access your data
  • Right to rectify inaccurate or incomplete data
  • Right to request deletion of your data
  • Right to restrict or object to processing
  • Right to data portability
  • Right to withdraw consent for marketing communications

You can manage your cookie preferences in your browser settings and unsubscribe from marketing emails at any time. You can also submit and cancel account deletion requests in your account settings during the grace period. If you need help with rights requests, contact support@naayya.com.

If you unsubscribe from marketing communications, we will apply your request without undue delay and no later than 10 business days.

If you previously added optional health disclosures, you can withdraw that consent by deleting those entries in your account health settings, using the consent-withdrawal control in health settings, or by contacting support@naayya.com.

13. CHILDREN'S PRIVACY

Our platform is not intended for use by children. We do not knowingly collect personal data from children under the age of 16. If we become aware that a child has provided us with personal data, we will take steps to delete such information. Parents or guardians who believe their child has provided us with personal data should contact us at support@naayya.com.

14. INTERNATIONAL DATA TRANSFERS

Core application data is primarily hosted in the European Union. Some of our vendors or support workflows may involve limited processing or access outside the EEA, including for analytics, communications, AI tooling, customer support, or infrastructure operations. Where those transfers occur, we use appropriate safeguards such as standard contractual clauses or other lawful transfer mechanisms as required by applicable law.

15. ANALYTICS, ERROR MONITORING, AND COOKIES

We use several categories of telemetry across our website, browser-based flows, and mobile apps. Each category has a distinct legal basis, scope, and set of controls.

15.1 Operational Telemetry (always active)

We use operational logs, error monitoring, and performance monitoring (Sentry and Vercel Speed Insights) to keep the platform secure, detect abuse, investigate failures, measure performance, and troubleshoot issues. This telemetry does not use cookies or browser storage. Data may include error messages, stack traces, route names, device/browser metadata, request identifiers, timestamps, IP address, and page load performance metrics.

When an error occurs, we may automatically capture a short replay buffer (approximately 30 seconds of page interaction before the error) to help our engineers understand and fix the issue. These error replays mask all text inputs and form fields. We also sample a small percentage of page loads for performance tracing to monitor response times, page load speed, and Core Web Vitals.

We also use Vercel Speed Insights to measure real-world page performance (Core Web Vitals). Speed Insights is cookieless, uses no browser storage, and collects only anonymized performance metrics. This data is never used for advertising.

Legal basis: Legitimate interest in maintaining a secure, reliable, and performant service (GDPR Art. 6(1)(f)).

Controls: Operational telemetry cannot be disabled as it is essential for service reliability and quality.

15.2 Product Analytics on Signed-In Surfaces

On signed-in product surfaces (such as your dashboard, account settings, admin tools, and booking management), we use PostHog to understand product usage patterns, feature quality, and friction points. This includes:

  • Page views and navigation: Which pages you visit, time spent on pages, and how you move through the product.
  • Interaction tracking: Clicks, form interactions, and other page-level engagement to understand how features are used and identify usability issues.
  • Session replay: Visual recordings of your product sessions with all text inputs, form fields, and sensitive content masked. Session replays help us identify bugs, improve workflows, and understand how features are actually used.

This data is linked to your account identity and uses browser storage (localStorage and cookies) to maintain session continuity as you navigate between pages.

Legal basis: Legitimate interest in improving the product for authenticated users (GDPR Art. 6(1)(f)).

Right to object (Art. 21 GDPR): You can object to product analytics at any time from your Account Settings > Privacy. When you object, all product analytics processing — including session replay and interaction tracking — stops immediately for your account. Objecting does not affect your access to any Naayya features.

15.3 Anonymous Page-View Measurement Before Consent (storage-free)

Before you make an optional analytics choice, we use PostHog to count page views on public pages such as our marketing website, business pages, and checkout flows. This limited measurement may include the page path, the current page URL after sensitive query values such as tokens, codes, and email addresses have been redacted, and the timing and basic technical information needed to count page views.

This measurement is anonymous and storage-free: it does not use cookies, localStorage, sessionStorage, or other browser or device storage. It does not include your account identity, create a persistent device or user identifier, or link these page views across sessions. We use it only to understand aggregate public-page traffic and improve the service.

Legal basis: Legitimate interest in understanding aggregate public-page traffic and improving the service (GDPR Art. 6(1)(f)). Because this measurement is storage-free and does not link visits across sessions, it is separate from the optional cookie-based analytics described below.

If you reject optional analytics, or your browser sends a Global Privacy Control (GPC) signal, public PostHog analytics capture stays off. Full analytics — including clicks, form interactions, cross-session measurement, and session replay — begins only after you accept analytics through the cookie banner or cookie settings page.

15.4 Marketing Analytics and Advertising (consent-based)

On public pages, we may additionally use analytics tools (PostHog with cookies, Google Analytics) and advertising tools (Google Ads) that rely on cookies or similar browser identifiers for cross-session tracking, audience insights, and conversion measurement. These tools are optional and are only activated after you provide consent through our cookie banner or cookie settings page. When analytics consent is granted, session replay may also be enabled on public pages to help us understand visitor journeys.

Legal basis: Consent (GDPR Art. 6(1)(a) and ePrivacy Directive Art. 5(3)).

Controls: You can change or withdraw consent at any time from the cookie settings page. Accepting our Terms of Service, creating an account, or signing in does not grant consent for marketing analytics or advertising.

15.5 Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) signal. When your browser sends a GPC signal (Sec-GPC: 1 or navigator.globalPrivacyControl), we automatically opt you out of advertising and data sharing for targeted advertising purposes, regardless of any prior consent choices. This applies to Google Ads and similar advertising technologies. We also keep public PostHog analytics capture off while GPC is active, regardless of any prior analytics choice.

15.6 Your Privacy Choices (US Residents)

US residents can visit our Your Privacy Choices page to opt out of the sale or sharing of personal information for targeted advertising purposes, as required by applicable US state privacy laws including the California Consumer Privacy Act (CCPA/CPRA).

15.7 General

When an account deletion request is completed, we trigger removal or de-identification workflows for linked analytics identities where supported by those providers. Operational security and legal-compliance records may be retained where necessary under applicable law.

16. SUB-PROCESSORS

We use the following main third-party vendors to help provide our services. Please review their privacy policies for more information on how they handle your data:

17. CHANGES TO THIS PRIVACY POLICY

We may update this policy periodically. Significant changes will be communicated on our Website. We encourage you to review this page regularly.

18. CONTACT US

If you have any questions or concerns about this Privacy Policy or your personal data, please contact us at support@naayya.com. We will respond as soon as possible.

19. REGIONAL PRIVACY DISCLOSURES

We operate internationally and apply this policy alongside local privacy laws. Depending on where you live, additional rights and complaint channels may apply.

  • European Union / EEA: We process personal data under GDPR legal bases (such as contract, legitimate interests, consent, or legal obligation as applicable). You may request access, correction, deletion, restriction, portability, or objection, and you may lodge a complaint with your local supervisory authority.
  • United States: For residents of applicable US states (including California CPRA and other state privacy laws), you may request to know/access, correct, or delete certain personal data, and you may exercise applicable opt-out rights where required by law. We do not sell personal data for money.
  • Canada: We handle personal information under applicable Canadian privacy laws (including PIPEDA, where applicable). You may request access/correction and withdraw consent for certain processing, subject to legal or contractual limits.
  • Australia: We process personal information in line with the Australian Privacy Act and the Australian Privacy Principles (APPs), including rights to access and correction.
  • New Zealand: We process personal information in line with the New Zealand Privacy Act 2020 and the Information Privacy Principles, including rights to access and correction.

To exercise rights, contact support@naayya.com. We may need to verify your identity before fulfilling requests.