Privacy Policy

This policy explains how Conversa handles personal information. It is written to align with South Africa's POPIA and the EU/UK GDPR. It is provided for transparency and is not a substitute for your organisation's own legal advice.

Roles

For customer conversations, contacts and messages inside a workspace, the organisation operating that workspace is the responsible party / data controller and Conversa acts as its operator / processor — processing that data only on the organisation's documented instructions. For the account and billing data of the organisation's own users, Conversa is the responsible party.

Information we process

Account details (name, work email), organisation and membership records, customer contact records and consent status, conversation content across connected channels, delivery and engagement metadata, and technical/usage logs needed to operate and secure the service.

How we use it

To provide the shared inbox, route and deliver messages, generate AI-assisted drafts, produce analytics, enforce consent and suppression, secure the platform, and meet legal obligations. We do not sell personal information.

Lawful basis & consent

Processing relies on performance of the contract, legitimate interests in operating the service, and consent where required. Outbound marketing messaging requires a recorded consent or other lawful basis; opt-outs are captured and enforced through per-contact suppression lists.

Your rights

Data subjects may request access, correction, deletion, restriction, objection and portability. Organisation administrators can export and delete/anonymise contact and conversation data from the workspace; requests to Conversa are routed to the relevant organisation where it acts as operator.

Data retention

Personal information is retained while the workspace is active and as needed for the purposes above or to meet legal obligations, after which it is deleted or anonymised. Retention periods are configurable per organisation.

Sub-processors

We use vetted sub-processors to run the service, including cloud hosting and database (Supabase), application hosting (Vercel), the messaging providers you connect (e.g. Resend for email, Meta for WhatsApp), and Peach Payments for billing. Each is bound by data-protection terms.

International transfers

Some sub-processors may process data outside your country. Where that happens, transfers are made under appropriate safeguards (such as standard contractual clauses) consistent with POPIA and GDPR.

Security

Data is isolated per organisation using row-level security, encrypted in transit, and production access is restricted. Provider secrets are held server-side and never exposed to the browser. No system is perfectly secure; we work to reduce risk and to notify affected parties of material incidents as required by law.

Contact

For privacy questions or to exercise your rights, contact the organisation operating your workspace, or email hello@conversa.app.