Your risk team will want to know where your data lives and who can see it.
These are plain answers to the questions we’re asked first. When you’re ready to connect Salesforce, we’ll send the full security pack with data flows and subprocessors.
| Hosting | Application data is hosted in Sydney, Australia, and the website is delivered through a global edge network. |
| Access | Every record belongs to one organisation, and rules in the database stop one client or partner from seeing another’s data. |
| Staff access | Every Conversera staff member signs in with multi-factor authentication. Each approval, export and change is logged with a name and a time, and nobody can edit that log. |
| Partners | Delivery partners see a campaign code name and only the assets and fields they need to do the work. |
| Model training | Client data is never used to train AI models. |
| Consent | Consent wording is recorded for each country and each lead, and an opt-out applies across every programme we run. |
| CRM connections | Salesforce connects only with your admin’s approval, and the access tokens are stored as secrets outside the application database. |
| Deletion | Retention is set for each client, and when you ask us to delete data we do it and keep a record that it happened. |
To request the security pack, send us a note or email success@conversera.ai.