Privacy Policy
Navia AI Assistant / naviaassist.com
Last updated: 25 July 2026
This Privacy Policy explains how Navia EOOD / Navia LTD, UIC/EIK 208760135, operating the website naviaassist.com and the Navia AI Assistant service, collects, uses, stores, shares and protects personal data.
For the purposes of this Privacy Policy, “Navia”, “we”, “us” or “our” refers to Navia EOOD / Navia LTD.
Contact email: info@naviaassist.com
This Privacy Policy should be read together with our Cookie Policy, AI Disclaimer, Terms and Conditions, and Return and Refund Policy.
1. Who we are
Navia is a digital technology company providing AI-powered business-assistant solutions, website integrations, lead-qualification tools, automation systems, website development and related digital services.
The Navia AI Assistant is an AI-powered chat assistant that can be integrated into websites to:
- Answer visitor questions.
- Guide website visitors.
- Collect inquiries.
- Collect voluntarily provided contact information.
- Identify potential customer needs.
- Qualify potential business leads.
- Generate conversation summaries.
- Help businesses respond to customer inquiries.
- Display conversations and structured lead information through an administrative dashboard.
The Navia AI Assistant is not a human operator. It generates automated responses based on user input, business-specific information, configured instructions and third-party artificial-intelligence technology.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with:
- Visitors to naviaassist.com.
- Users interacting with the Navia AI Assistant on naviaassist.com.
- Visitors interacting with a Navia AI Assistant installed on a client website.
- Customers who purchase a service from Navia.
- Customers who complete the NAVIA onboarding process.
- Clients using the Navia AI Assistant on their websites.
- Client representatives accessing a NAVIA administrative dashboard.
- Persons who contact Navia by email, telephone, chat or form.
- Business leads generated through the Navia AI Assistant.
- Persons requesting an offer, demonstration, consultation or other service.
When the Navia AI Assistant is installed on a client’s website, that website owner may have a separate Privacy Policy. The website owner is responsible for informing its visitors about its own processing activities and the use of the Navia AI Assistant.
3. Roles under data-protection law
Depending on the circumstances, Navia may act as a data controller or data processor.
3.1. Navia as data controller
Navia generally acts as a data controller when it determines why and how personal data is processed, including when:
- Operating naviaassist.com.
- Responding to inquiries submitted directly to Navia.
- Managing prospective and existing customer relationships.
- Processing NAVIA purchases and onboarding submissions.
- Managing NAVIA administrative accounts.
- Processing information for service security and fraud prevention.
- Maintaining accounting, tax and transaction records.
- Managing support requests.
- Protecting Navia’s legal rights.
- Analysing and improving Navia’s own services.
3.2. Navia as data processor
When the Navia AI Assistant is installed on a client’s website and processes visitor information on that client’s behalf, the client will generally act as the data controller and Navia will generally act as a data processor.
In that situation:
- The client determines the purposes for which visitor information is collected.
- The client is responsible for selecting an appropriate legal basis.
- The client is responsible for informing its website visitors.
- The client must provide the required information in its Privacy Policy or other notices.
- Navia processes personal data according to the client’s documented instructions, the applicable agreement and legal obligations.
- The client is responsible for responding to relevant data-subject requests, with Navia providing reasonable assistance where required.
The precise roles may depend on the particular processing activity and contractual arrangement. Controller and processor responsibilities should be defined in the applicable agreement or data-processing terms.
4. Categories of personal data we may collect
The categories of data processed depend on how a person interacts with Navia or a client using the Navia AI Assistant.
4.1. Contact information
We may process:
- Name.
- Email address.
- Telephone number.
- Company name.
- Job title or professional role.
- Website address.
- Social-media profile.
- Preferred contact method.
- Other contact details voluntarily provided through a chat, form, email or telephone conversation.
4.2. Inquiry and communication information
We may process:
- Messages sent through the Navia AI Assistant.
- Questions asked by users.
- Email correspondence.
- Information supplied through contact or onboarding forms.
- Requested products or services.
- Project details.
- Business needs.
- Budget information.
- Preferences.
- Objections or concerns.
- Desired implementation time.
- Conversation history and summaries.
- Follow-up notes.
- Information voluntarily supplied during an inquiry.
4.3. Technical information
We may process:
- IP address.
- Browser type.
- Device type.
- Operating system.
- Referring page.
- Website domain where the assistant is used.
- Date and time of interactions.
- Visitor or session identifier.
- Language selection.
- Error and diagnostic logs.
- Security events.
- Rate-limit information.
- Chat interaction history.
- Information necessary to detect spam, abuse or unauthorized access.
4.4. Administrative-account information
For persons with access to a NAVIA administrative dashboard, we may process:
- Username.
- Hashed password.
- Assigned role.
- Client account.
- Access permissions.
- Login and session information.
- Login timestamps.
- Security events.
- Administrative actions performed within the system.
Passwords should be stored in hashed form rather than readable plain text.
4.5. AI-generated information
The system may generate or suggest:
- Conversation summaries.
- Structured lead fields.
- Apparent user intent.
- Requested-service categories.
- Suggested lead status.
- Lead priority or score.
- Apparent urgency.
- Follow-up recommendations.
- Conversation analysis.
AI-generated information may be incomplete or inaccurate. It should be reviewed by a human before being used for important or consequential decisions.
4.6. Order and payment information
When a customer purchases a service through naviaassist.com, we may process:
- Customer name.
- Billing address.
- Email address.
- Telephone number.
- Company and tax details where supplied.
- Selected product or plan.
- WooCommerce order number.
- Order date.
- Order status.
- Payment status.
- Currency and amount paid.
- Invoice information.
- Transaction identifier.
- Payment method type.
- Refund, dispute or chargeback information.
- Information required for accounting, tax and fraud-prevention purposes.
Payments made through the current website checkout are one-time payments. The current checkout does not create automatic recurring payments or automatic renewals.
Payments are processed through third-party providers such as Stripe. Navia does not store full payment-card numbers or card security codes on its own servers.
4.7. Onboarding and configuration information
When a customer completes the NAVIA onboarding process, we may process information such as:
- Business name and website.
- Industry and country.
- Main and secondary languages.
- Public business contact information.
- Social-media and booking links.
- Assistant name and branding preferences.
- Logo or other brand assets.
- Welcome content.
- Business description.
- Services and product categories.
- Common customer questions.
- Customer objections.
- Assistant goals.
- Lead-collection preferences.
- Preferred communication tone.
- Prohibited or restricted assistant behaviour.
- Allowed website domains.
- Technical systems and website platform.
- Terms and Privacy Policy links.
- Integration instructions.
- Additional business instructions.
Customers should not provide permanent passwords or unnecessary administrator credentials through the onboarding form.
Where temporary website access is required, access should be provided using an appropriately limited temporary account or another secure method agreed with Navia.
5. How we collect personal data
We may collect personal data:
- Directly from you when you use the Navia AI Assistant.
- When you complete a contact, checkout or onboarding form.
- When you purchase a service through WooCommerce and Stripe.
- When you contact us by email or telephone.
- When you request an offer, demonstration or consultation.
- When you create or access a NAVIA administrative account.
- From a NAVIA client when the client configures its assistant or administrative users.
- Automatically through technical logs, security systems and browser technologies.
- From the website on which the Navia AI Assistant is installed.
- From authorized integrations used to provide the requested service.
- From public business sources where lawful and relevant.
Where information is not obtained directly from the individual, the source and applicable processing details may be provided where required by law.
6. Why we process personal data
6.1. To provide the Navia AI Assistant
We may process information to:
- Enable chat functionality.
- Generate responses.
- Maintain context during a conversation.
- Store conversation history.
- Identify returning sessions.
- Apply business-specific instructions.
- Create lead records.
- Display conversations and leads in the administrative dashboard.
- Provide requested assistant functionality.
6.2. To respond to inquiries
We may process information to:
- Answer questions.
- Respond to contact requests.
- Prepare offers.
- Provide consultations.
- Contact a person about their inquiry.
- Follow up on a potential business opportunity.
- Arrange a demonstration or meeting.
6.3. To qualify and manage leads
We may process conversation and contact information to:
- Identify user needs.
- Identify the requested service.
- Structure voluntarily supplied contact details.
- Assess apparent urgency or interest.
- Create lead summaries.
- Assign or suggest lead categories.
- Help the relevant business review and respond to inquiries.
AI-generated lead analysis is indicative and should not be treated as an objective fact.
6.4. To notify clients about inquiries
When a relevant inquiry is detected, Navia may send an email notification to the applicable client or website owner.
The notification may contain contact information, inquiry details, a conversation summary or other information required to respond to the visitor.
6.5. To process orders and payments
We may process order and payment information to:
- Operate WooCommerce checkout.
- Process one-time payments through Stripe.
- Confirm payment status.
- Send order-related emails.
- Provide invoices or order records.
- Deliver the purchased service.
- Link a customer’s order to their onboarding submission.
- Process refund requests.
- Handle failed or duplicate payments.
- Respond to payment disputes or chargebacks.
- Prevent payment fraud.
- Comply with accounting and tax obligations.
6.6. To configure and deliver purchased services
We may process onboarding and business information to:
- Configure the customer’s AI assistant.
- Prepare business-specific instructions.
- Customize branding and language.
- Set lead-collection behaviour.
- Integrate the assistant into an approved website.
- Test the assistant.
- Activate the purchased service.
- Provide agreed support or modifications.
6.7. To operate administrative accounts
We may process account information to:
- Authenticate users.
- Apply access permissions.
- Display client-specific information.
- Maintain account security.
- Record important administrative events.
- Investigate unauthorized access.
6.8. To improve and maintain the service
We may process limited technical or interaction information to:
- Diagnose errors.
- Improve system performance.
- Improve response quality.
- Test configured behaviour.
- Improve prompts and workflows.
- Optimize user experience.
- Monitor service availability.
- Investigate reported problems.
This does not mean that every conversation is manually reviewed or used to train an artificial-intelligence model.
6.9. To secure the service
We may process technical information to:
- Apply rate limits.
- Prevent spam and automated abuse.
- Protect API usage.
- Protect client and user information.
- Prevent unauthorized access.
- Detect suspicious activity.
- Investigate security incidents.
- Maintain technical logs.
- Enforce applicable terms.
6.10. To comply with legal obligations
We may process and retain certain information to comply with:
- Accounting and tax rules.
- Data-protection obligations.
- Valid legal requests.
- Court orders.
- Regulatory requirements.
- Fraud-prevention requirements.
- Record-keeping obligations.
6.11. To establish, exercise or defend legal claims
We may retain and use relevant information when reasonably necessary to:
- Enforce agreements.
- Resolve disputes.
- Respond to complaints.
- Investigate fraud or abuse.
- Establish, exercise or defend legal claims.
7. Legal bases for processing
Depending on the context, we process personal data on one or more of the following legal bases.
7.1. Performance of a contract or pre-contractual steps
We may process information when necessary to:
- Respond to a request for an offer or service.
- Process an order.
- Process a one-time payment.
- Complete onboarding.
- Configure and deliver a purchased service.
- Provide requested support.
- Operate a client’s administrative account.
7.2. Legitimate interests
We may process information where necessary for legitimate interests such as:
- Operating and securing our services.
- Responding to business inquiries.
- Preventing fraud, spam and abuse.
- Maintaining technical logs.
- Improving service performance.
- Managing customer relationships.
- Protecting legal rights.
- Supporting clients.
- Generating and managing relevant business leads.
Before relying on legitimate interests, we consider the nature of the data, reasonable expectations of individuals and possible effects on their rights and freedoms.
7.3. Consent
We may rely on consent where required, including for:
- Optional cookies or analytics.
- Certain marketing communications.
- Optional processing that is not necessary to provide the requested service.
- Processing special-category data where an applicable consent condition is appropriate.
Where processing is based on consent, consent must be freely given, specific, informed and expressed through an affirmative action.
Merely continuing to browse the website or remaining silent will not automatically constitute consent where valid consent is legally required.
Consent may be withdrawn at any time without affecting the lawfulness of processing performed before withdrawal.
7.4. Legal obligation
We may process personal data where required by Bulgarian or European Union law, including tax, accounting, regulatory, data-protection and lawful-disclosure obligations.
7.5. Legal claims
Where applicable, processing may be necessary for the establishment, exercise or defence of legal claims.
8. Use of artificial intelligence
The Navia AI Assistant uses artificial intelligence to generate responses, analyse conversations and structure lead information.
Users should understand that:
- The assistant is not human.
- Responses are generated automatically.
- AI outputs may be inaccurate, incomplete or outdated.
- AI outputs may not be suitable for a specific situation.
- Important information should be independently verified.
- AI-generated content should not be treated as professional advice.
- A human should review important lead or business decisions.
The Navia AI Assistant does not provide legal, medical, financial, tax, psychological, safety-critical or other regulated professional advice.
Users should be informed that they are interacting with an AI system at or before their first interaction, unless this is obvious from the circumstances.
Further information is available in our AI Disclaimer.
9. OpenAI API and other AI providers
Navia may use third-party artificial-intelligence providers, including the OpenAI API, to generate responses and process messages.
When a user sends a message, the message and relevant conversation context may be transmitted to the AI provider to generate a response.
We aim to transmit only information reasonably necessary to provide the requested functionality. Users should not submit unnecessary sensitive or confidential information through the chat.
The provider’s processing may be subject to contractual data-protection terms, security measures and applicable transfer safeguards.
The specific providers used may change where reasonably necessary to maintain or improve the service. Material changes affecting personal-data processing will be reflected in this Privacy Policy or other appropriate notices.
10. Automated analysis and decisions
The Navia AI Assistant may automatically generate:
- Conversation summaries.
- Suggested lead categories.
- Suggested lead scores or priorities.
- Apparent intent.
- Structured contact or project fields.
- Follow-up suggestions.
These outputs are intended to assist human review.
Navia does not intend to use the assistant to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Clients must not use AI-generated scores or suggestions as the sole basis for legally significant decisions without an appropriate legal assessment, safeguards and human review.
11. Who may receive personal data
Personal data may be made available on a need-to-know basis to:
- Authorized Navia personnel.
- Technical support and system administrators.
- The relevant client or website owner.
- Authorized client administrative users.
- Hosting and infrastructure providers.
- AI and API providers.
- Email-delivery providers.
- Payment providers such as Stripe.
- WooCommerce and related checkout infrastructure.
- Security and fraud-prevention providers.
- Professional legal, accounting or tax advisers where necessary.
- Public authorities where disclosure is legally required.
We do not sell personal data.
12. Sharing with NAVIA clients
If a person interacts with the Navia AI Assistant on a client’s website, information from that interaction may be shared with the relevant client.
This may include:
- Contact details voluntarily submitted by the visitor.
- Inquiry information.
- Requested service.
- Project details.
- Budget or timing information.
- Conversation history.
- Conversation summary.
- Suggested lead status.
The client is responsible for using that information lawfully and securely.
13. Payment providers
Stripe may process payment and transaction information to:
- Process one-time payments.
- Authenticate transactions.
- Prevent fraud.
- Confirm payment status.
- Process approved refunds.
- Handle payment disputes or chargebacks.
- Comply with legal and regulatory obligations.
Navia does not store full payment-card numbers or card security codes on its own infrastructure.
Stripe may process information under its own privacy terms and may act as an independent controller for certain activities.
14. International data transfers
Some service providers may process personal data outside Bulgaria or the European Economic Area.
Where personal data is transferred outside the EEA, Navia will use an applicable transfer mechanism where required, which may include:
- An adequacy decision adopted by the European Commission.
- Standard Contractual Clauses.
- Supplementary contractual, technical or organizational safeguards.
- Another transfer mechanism permitted by applicable law.
International transfers will be limited to what is reasonably necessary for the relevant service.
15. Data storage and retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required by law or necessary for legal claims, security or contractual obligations.
15.1. Chat conversations
Chat conversations may generally be stored for up to 60 days where that retention setting is implemented.
A different period may apply where:
- The relevant client has selected another lawful retention period.
- A conversation has become part of an active customer inquiry.
- Retention is required for security investigation.
- Retention is required to resolve a complaint.
- Retention is necessary for legal claims.
- Applicable law requires longer retention.
Because the current technical system must enforce any published retention promise, Navia should verify that automatic deletion or anonymization is operating before relying on the 60-day period.
15.2. Lead information
Lead information may be retained while an inquiry is active and for a reasonable follow-up period afterward.
Longer retention may apply where necessary for:
- An ongoing customer relationship.
- Contractual obligations.
- Legal claims.
- Demonstrating how an inquiry was handled.
- A client’s documented lawful retention requirements.
15.3. Customer, order and accounting records
Customer, order, invoice, transaction and refund records may be retained for the periods required by applicable accounting, tax and commercial law.
15.4. Onboarding and client-configuration information
Onboarding and configuration information may be retained for as long as necessary to:
- Configure and provide the purchased service.
- Maintain the client’s assistant.
- Provide agreed support.
- Demonstrate the agreed configuration.
- Resolve disputes.
- Meet contractual or legal obligations.
15.5. Administrative accounts
Administrative-account information may be retained while the account is active and for a reasonable period after deactivation where necessary for security, audit or legal purposes.
15.6. Technical and security logs
Technical, security and rate-limit logs may be retained for a limited period necessary to diagnose errors, prevent abuse, investigate incidents and protect the service.
15.7. Consent records
Where processing is based on consent, relevant consent records may be retained for as long as reasonably necessary to demonstrate compliance.
When information is no longer required, it should be deleted, anonymized or securely restricted, subject to technical and legal limitations.
16. Security measures
Navia applies technical and organizational measures intended to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.
Measures may include:
- HTTPS encryption in transit.
- Access controls.
- Role-based permissions.
- Hashed passwords.
- Restricted administrative access.
- Domain restrictions.
- Rate limiting.
- Server-side protection of API credentials.
- Separation of client information.
- Security logging.
- Technical monitoring.
- Backup and recovery measures where applicable.
- Regular system review.
- Contractual controls with service providers.
No online system can guarantee absolute security.
Users and clients are responsible for protecting their login credentials, using appropriate passwords and preventing unauthorized access to their accounts and email inboxes.
17. Cookies and browser storage
Navia may use cookies, local storage, session storage and similar browser technologies to:
- Maintain website functionality.
- Maintain the WooCommerce cart and checkout.
- Process a requested payment.
- Remember language selection.
- Remember a visitor or session identifier.
- Maintain conversation continuity.
- Store limited chat information in the browser.
- Remember cookie preferences.
- Prevent fraud and abuse.
Optional technologies requiring consent will only be used after the user has made a valid choice.
Users can control or delete cookies and browser storage through their browser settings. Removing them may affect chat continuity, cart contents, language preferences or other website functionality.
Further information is available in our Cookie Policy.
18. Email notifications
When a relevant lead or inquiry is identified, Navia may send an email notification to the applicable client or website owner.
A notification may contain:
- Name.
- Email address.
- Telephone number.
- Requested service.
- Project information.
- Budget or timing.
- Conversation summary.
- Conversation context.
- Suggested lead status.
Order and onboarding emails may contain customer, order and onboarding-status information.
Clients are responsible for securing their email accounts and processing received information lawfully.
19. Data-subject rights
Depending on the circumstances and applicable law, individuals may have the right to:
- Request access to their personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion of personal data.
- Request restriction of processing.
- Object to processing based on legitimate interests.
- Receive certain data in a structured, commonly used and machine-readable format.
- Request transmission of eligible data to another controller where technically feasible.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a competent supervisory authority.
- Receive information about applicable safeguards for international transfers.
- Not be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects.
These rights are not absolute and may be limited by applicable legal conditions and exemptions.
20. Exercising your rights
To exercise a privacy right concerning information processed directly by Navia, contact:
A request should include enough information to help identify the relevant data, such as:
- Name and contact information.
- Website or domain where the interaction occurred.
- Approximate date of the conversation.
- Email address or telephone number provided.
- Order number, where applicable.
- Visitor or session identifier, if available.
We may request reasonable information to verify identity before fulfilling a request.
If the information was submitted through a Navia AI Assistant installed on a client’s website, the individual may need to contact that website owner because the client may be the relevant data controller.
Navia will respond within the period required by applicable law.
21. Right to complain
Individuals have the right to lodge a complaint with the competent data-protection authority.
In Bulgaria, the supervisory authority is the:
Commission for Personal Data Protection
Website: https://cpdp.bg/
Individuals may also have the right to contact the supervisory authority in the EU or EEA country where they live, work or believe an infringement occurred.
We encourage individuals to contact us first so that we can attempt to address the concern.
22. Children’s information
The Navia AI Assistant is intended primarily for business communication and general website inquiries. It is not specifically directed at children.
We do not knowingly request personal data from children through naviaassist.com.
Where a client uses the assistant on a website intended for children or likely to be accessed by children, that client is responsible for:
- Assessing the applicable legal requirements.
- Providing age-appropriate information.
- Obtaining parental consent where required.
- Configuring the assistant appropriately.
- Limiting unnecessary data collection.
If we learn that a child’s personal data has been collected unlawfully, we will take reasonable steps to delete or restrict it.
23. Special-category and sensitive information
Users should not submit sensitive or confidential information through the chat unless it is strictly necessary and a valid legal basis applies.
This includes:
- Health information.
- Biometric information.
- Racial or ethnic origin.
- Political opinions.
- Religious or philosophical beliefs.
- Trade-union membership.
- Information about sex life or sexual orientation.
- Genetic information.
- Government identification numbers.
- Financial-account credentials.
- Passwords.
- Confidential legal information.
- Trade secrets.
If such information is submitted unexpectedly, Navia or the relevant client may restrict, delete or otherwise handle it in accordance with applicable law.
24. Personal-data breaches
If Navia becomes aware of a personal-data breach, it will take appropriate steps to:
- Investigate the incident.
- Limit further exposure.
- Preserve relevant evidence.
- Assess the potential risk.
- Notify affected controllers or clients where appropriate.
- Notify the competent supervisory authority where legally required.
- Notify affected individuals where legally required.
- Document the incident and response.
Where GDPR requires notification to a supervisory authority, Navia will act without undue delay and, where feasible, within the applicable 72-hour period.
25. Third-party websites
Navia’s website or AI Assistant may contain links to third-party websites.
Navia is not responsible for the privacy, security or content practices of independent third-party websites. Users should review the applicable Privacy Policy before providing information to another website.
26. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- Changes to our services.
- New providers or integrations.
- Changes to personal-data processing.
- Security improvements.
- Legal or regulatory developments.
- Changes to retention or operational practices.
The updated version will be published on naviaassist.com with a revised “Last updated” date.
Where required, material changes will be communicated through an appropriate additional notice.
Continued use of the website does not replace consent where valid consent is legally required.
27. Contact
For questions, requests or privacy-related concerns, contact:
Navia EOOD / Navia LTD
UIC/EIK: 208760135
Email: info@naviaassist.com
Website: https://naviaassist.com