Privacy Policy
This policy explains how Conversa handles personal information. It is written to align with South Africa's POPIA and the EU/UK GDPR. It is provided for transparency and is not a substitute for your organisation's own legal advice.
Roles
For customer conversations, contacts and messages inside a workspace, the organisation operating that workspace is the responsible party / data controller and Conversa acts as its operator / processor — processing that data only on the organisation's documented instructions. For the account and billing data of the organisation's own users, Conversa is the responsible party.
Information we process
Account details (name, work email), organisation and membership records, customer contact records and consent status, conversation content across connected channels, delivery and engagement metadata, and technical/usage logs needed to operate and secure the service.
How we use it
To provide the shared inbox, route and deliver messages, generate AI-assisted drafts, produce analytics, enforce consent and suppression, secure the platform, and meet legal obligations. We do not sell personal information.
Lawful basis & consent
Processing relies on performance of the contract, legitimate interests in operating the service, and consent where required. Outbound marketing messaging requires a recorded consent or other lawful basis; opt-outs are captured and enforced through per-contact suppression lists.
Your rights
Data subjects may request access, correction, deletion, restriction, objection and portability. Organisation administrators can export and delete/anonymise contact and conversation data from the workspace; requests to Conversa are routed to the relevant organisation where it acts as operator.
Data retention
Personal information is retained while the workspace is active and as needed for the purposes above or to meet legal obligations, after which it is deleted or anonymised. Retention periods are configurable per organisation.
Sub-processors
We use vetted sub-processors to run the service, including cloud hosting and database (Supabase), application hosting (Vercel), the messaging providers you connect (e.g. Resend for email, Meta for WhatsApp), and Peach Payments for billing. Each is bound by data-protection terms.
International transfers
Some sub-processors may process data outside your country. Where that happens, transfers are made under appropriate safeguards (such as standard contractual clauses) consistent with POPIA and GDPR.
Security
Data is isolated per organisation using row-level security, encrypted in transit, and production access is restricted. Provider secrets are held server-side and never exposed to the browser. No system is perfectly secure; we work to reduce risk and to notify affected parties of material incidents as required by law.
Contact
For privacy questions or to exercise your rights, contact the organisation operating your workspace, or email hello@conversa.app.