Privacy Policy
How ConveRact handles account information, customer-controlled conversation data, provider events, usage records, and privacy requests.
01
Public sandbox trials
Public sandbox prompts, bounded conversation history, generated responses, service traces, and technical context are stored under random session and run IDs for up to 180 days. Common email-address and phone-number patterns are redacted before storage, but visitors should not submit sensitive or confidential information.
A sandbox record is eligible for reviewed AI improvement only when the request carries the disclosed improvement permission. Sandbox records remain separate from tenant customer conversations and do not trigger messages, calls, bookings, payments, or other external actions.
02
Scope and roles
This Privacy Policy explains how the ConveRact service operator handles information for website visitors, account users, prospects, and support contacts. For customer conversation content and connected business data, the customer generally acts as controller and ConveRact acts as processor.
A customer’s own privacy notice governs how that customer uses AI services with its end users. Questions about an end-user conversation should normally be directed to the business operating that workspace.
03
Information we collect
We collect account and profile details, workspace configuration, billing contacts, authentication events, support communications, device and usage information, and the content customers submit to configured services.
Connected providers may deliver messages, sender identifiers, delivery events, call metadata, recordings or transcripts, commerce records, calendar details, and tool results according to the customer’s configuration and provider permissions.
04
How information is used
Information is used to provide and secure the service, authenticate users, route conversations, execute approved tools, generate responses, process subscriptions, deliver support, detect abuse, measure reliability, and comply with law.
Customer content is not used for unrelated advertising. Model-provider data use depends on the configured provider, account type, and contractual settings; workspace administrators should review provider terms before enabling a route.
05
Legal bases and choices
Processing may rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal duties, or consent where required. Marketing communications include an unsubscribe option.
Administrators can control users, channels, knowledge, providers, retention-related configuration, and integrations. Browser cookie choices are described in the Cookie Policy.
06
Sharing and subprocessors
Information is shared with infrastructure, communications, AI model, voice, email, analytics, customer support, and payment providers only as needed for configured functionality. It may also be disclosed for legal compliance, security, corporate transactions, or with customer direction.
Production deployment should maintain a current subprocessor list, contractual protections, regional transfer mechanisms, and advance notice commitments appropriate to customer agreements.
07
Security and tenant isolation
Controls include role-based access, tenant-scoped authorization, encrypted transport, protected credentials, audit logs, backups, monitoring, and incident response procedures. No system can guarantee absolute security.
Customers should use unique accounts, strong authentication, least-privilege roles, secure provider credentials, and prompt offboarding. Suspected compromise should be reported immediately.
08
Retention and deletion
Account, conversation, audit, billing, and integration records are retained for the period needed to provide the service, satisfy the customer’s configuration, resolve disputes, protect security, and meet legal duties.
Deletion requests are subject to identity verification, tenant authority, backup cycles, fraud prevention, financial record rules, and other lawful exceptions. Production retention schedules should be stated in the applicable customer agreement.
09
Rights and contact
Depending on location, individuals may have rights to access, correct, delete, restrict, object, port, or withdraw consent. Requests relating to customer-controlled conversation data may be forwarded to the relevant workspace owner.
Complaints may be raised with the applicable data protection authority. Privacy requests can be sent to the verified contact published below.
Questions about this policy?
A verified legal-contact address has not been configured. Do not publish this policy as final until it is set.