Last updated: August 27, 2026 · Operated by Naqla for Technical Development (sole proprietorship, Egypt · CR 11907 · Tax 584750897 · owner Ashraf Ali El-Sayed Ahmed Hassan)
Naqla Assistant ("Naqla", "we", "our", or "the Service") is an AI-powered customer-communication service operated by Naqla for Technical Development (نقلة للتطوير التقني), a sole proprietorship registered in the Arab Republic of Egypt — Commercial Register No. 11907, Ismailia Investment Commercial Registry Office; Tax Registration No. 584750897; owner Ashraf Ali El-Sayed Ahmed Hassan; registered address Building 42, Ankara Street, Sheraton, Cairo, Egypt. This Privacy Policy explains how we collect, use, share, and safeguard information when you — or your customers — interact with the Service across WhatsApp, Facebook Messenger, Instagram, TikTok, email, and your website.
Our roles. For the messages and end-customer data that flow through a business's connected accounts, we act as a data processor on behalf of that business (the business is the controller of its own customers' data). For the account, security, billing, and usage data of the business owners who sign up to Naqla, we act as the data controller.
We collect the data required to operate the Service:
We do not collect payment card numbers or government IDs. We do not seek to collect special-category (sensitive) personal data; where a customer voluntarily sends such content in a message, it is processed only as part of that conversation.
Information is used to operate and improve the Service, specifically to:
Automated inferences. To help you manage customer conversations, the Service uses AI to derive business-assistance signals, including: a customer mood/urgency flag, a sales "lead score" with temperature, stage, intent and a suggested next action, and classification of messages as an order, lead, or inquiry. These inferences are used to prioritize conversations, schedule follow-ups, and — for customers who arrived from a Click-to-WhatsApp ad — attribute conversions back to the originating ad. They do not make legal or similarly significant automated decisions about the customer.
We never sell or rent your data or your customers' data, and we never share it with third parties for their own marketing or advertising purposes.
The Service relies on the following processors and platforms to function. Each operates under its own privacy and security terms, and receives only the data needed for its specific function:
| Provider | Purpose | Data shared |
|---|---|---|
| Meta Platforms (Facebook, Instagram, WhatsApp Cloud API, Marketing API) | Send/receive messages & comments, read profile/Page data, read & manage connected ad accounts | Message & comment content, identifiers, ad-account operations |
| Anthropic, PBC (Claude AI) | Understand messages and draft replies | Conversation content & context; images where relevant. Not used to train models on your data. |
| Google LLC (Gemini AI) | Reply generation (fallback), lead scoring, voice/image processing | Conversation content, audio/image content where relevant |
| OpenAI OpCo, LLC | Reply generation (fallback) and voice transcription | Conversation content, audio where relevant |
| OpenRouter, Inc. | Model-routing layer used for some AI requests | Conversation content routed to the selected model |
| Telegram Messenger Inc. | Operational alerts / escalations to the business owner | Customer name, message content, lead/order status |
| Formagrid Inc. (Airtable) | Booking / order record storage for businesses that enable it | Customer name, phone, and booking details extracted from conversations |
| Hetzner Online GmbH | Server hosting & data storage | All stored Service data (hosting) |
Some businesses connect their WhatsApp through a Business Solution Provider (for example Gupshup); where used, that provider processes the WhatsApp messages for that business. We share only the minimum data necessary for each provider's function.
A note on AI context: to answer accurately, a business may enable a connected knowledge source (such as an Airtable table of its own records). When enabled, relevant records from that source are included in the context sent to the AI provider to generate a reply. This is data the business itself provided for this purpose.
A business using Naqla may choose to connect its own Google account. None of the following happens unless that business signs in with Google and grants the specific permission, and it can be withdrawn at any time.
| Permission | What Naqla does with it | What Naqla cannot do |
|---|---|---|
| gmail.send | Sends a reply typed in Naqla from the business's own email address, so customers answer the address they already know. | Cannot open, read, search or delete the mailbox. Incoming mail reaches Naqla only as a forwarded copy delivered to a Naqla address. |
| calendar.events | Checks whether a time is already taken, then writes the appointment the customer agreed in chat to the calendar the owner selected. | Cannot create or delete calendars, and does not read calendars the owner did not select. |
| adwords | Lists the Google Ads accounts the owner authorised, creates the conversion action Naqla uploads into, and reads performance so the business can see its real cost per customer. | Google publishes a single scope for the Google Ads API; no narrower one exists. |
| datamanager | Uploads an offline conversion event to the business's own conversion action when a conversation becomes a booking or a sale, so bidding learns from real buyers. | Ingests events only. Does not read, edit or delete customer data, and is not used for Campaign Manager 360, Search Ads 360, Display & Video 360 or Google Analytics. |
Limited Use. Naqla's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. This data is never sold, never used for advertising to you, never transferred except to provide the feature the owner asked for or where required by law, and never used to train AI models.
Withdrawing access. Press Disconnect on the relevant card in Naqla → Channels, or remove Naqla at myaccount.google.com/permissions. The stored token is deleted immediately and all access stops. See also our Data Deletion page.
Naqla is operated from Egypt, and our servers are hosted in the European Union (Hetzner, Germany). To generate AI replies and related features, message content and, where relevant, media are sent to service providers located in the United States (Anthropic, OpenAI, Google, OpenRouter) and other jurisdictions (Telegram, Airtable). This means your data and your customers' data may be processed outside your country, where data-protection laws may differ. We only transfer the minimum data necessary and rely on each provider's contractual and technical safeguards for such processing.
Message logs and interaction data are retained for up to 90 days to support your dashboard history and troubleshooting, unless a longer period is needed for a specific feature you use (for example, saved bookings or order records) or is required by law. You may request deletion of your data at any time (see Section 8 and our Data Deletion Instructions).
We implement appropriate technical and organizational measures to protect data against unauthorized access, alteration, or disclosure, and data is transmitted to Meta and our providers over encrypted (HTTPS/TLS) connections. Access to stored data is limited to the authorized business users of each account, authorized Naqla personnel, and our contracted service providers acting on our behalf. Account and team passwords are stored only as one-way hashes. No method of transmission or storage is completely secure, and we continue to improve our safeguards over time.
If we receive a request from a public authority for user data, we apply the following policy:
To date, we have not received or responded to any such requests.
You have the right to:
End customers of a connected business may also request deletion of their personal data (messages, phone number, name, profile picture) using the contact below or the Data Deletion page.
For any questions, privacy concerns, or data requests, contact us:
We may update this Privacy Policy from time to time; the "Last updated" date above reflects the latest version.