Your conversations are private.
We keep it that way.
Practice only works when people can fail safely. Practice sessions are private: nobody but the person sees them. Your organization does see each person's development per capability and progress through programs. This page spells out who can see what.
Security
ISO 27001 Certified
Our Information Security Management System is independently audited and certified by Brand Compliance. The certificate is available in our Trust Center.
Encryption by Default
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Voice recordings and transcripts are never stored unencrypted.
Hosted in the EU
All customer data is stored and processed in the European Union — on AWS or Azure, in the Frankfurt (Germany) region. No customer data leaves the EU.
Enterprise Access
SSO via SAML 2.0 and OIDC, SCIM provisioning, and enforced MFA for administrative access.
Tested, Not Assumed
Independent penetration testing; summary reports available under NDA.
When Something Goes Wrong
Documented incident-response process: affected customers are notified in line with GDPR breach-notification duties. Status page at status.converz.co.
Privacy
GDPR
We process personal data under a Data Processing Agreement available to every customer, with documented legal bases, records of processing, and support for data-subject requests (access, correction, deletion, export). Our DPO can be reached at privacy@converz.co.
Retention & Deletion
You control how long recordings and transcripts are kept. You set the default retention period; deletion on request and removal from backups follow the windows you define. When a contract ends, all customer data is deleted or returned on the terms you set.
Zero Model Training
We do not use your data — recordings, transcripts, or anything derived from them — to train our AI models. Your team's communication style stays inside your organization.
And Our Subprocessors Don't Either
Converz uses third-party AI models for conversation and analysis. Under our enterprise agreements with these providers, your data is not used to train their models, is not retained beyond processing, and is processed under DPAs.
Built to develop your people — never to police them.
Converz analyzes conversations so each person knows what to practice next. That only works if your people trust it. So the boundaries are structural, not just promised:
Individuals see their own coaching first.
Practice sessions and personal feedback belong to the employee: nobody else sees a session, a recording or a transcript. Managers do see each person's development per capability and their progress through programs, not a surveillance feed.
Not an assessment file.
Converz data is designed for development. We advise in our documentation and DPA against its use as the basis for dismissal or formal performance scoring.
Employee transparency built in.
People can see what is analyzed about them and why — no hidden scoring.
Works council ready.
Under the Dutch Works Councils Act (WOR art. 27), systems that observe employee performance typically require works-council consent. We support that conversation: a ready-made works-council information pack covering what Converz does and doesn't do with employee data, plus a DPIA template for your privacy team.
Compliant with the EU AI Act.
Our position, in plain terms:
- 01
Skills, not psyches
Analysis is based on observable conversational behavior (structure, phrasing, timing) — not emotion recognition or biometric inference, which the Act prohibits in the workplace.
- 02
Limited or high risk, depending on how you configure it
Limited risk when per-person evaluations never reach anyone with authority over that person, high risk when they do. Either way the corresponding transparency obligations are met — users always know they are talking to an AI.
- 03
Documentation for your compliance review
Risk classification rationale, model documentation and human-oversight measures are available in the Trust Center.
Your rules, your guardrails.
Converz isn't a black box. You control the AI's persona, knowledge base, and boundaries — from the tone of a difficult roleplay to the compliance requirements of a regulated industry.
Granular RBAC
Role-based access control across the organization, aligned with the visibility defaults above.
Persona Safety
Configurable guardrails that keep AI conversation partners professional and on-brand.
Audit Logs
Comprehensive logging of sessions, access, and administrative actions, exportable to your SIEM.
Everything your security review needs.
Standard documentation pack: ISO certificate, DPA, subprocessor list, pen-test summary, AI Act documentation, works-council pack. Most security questionnaires answered from the Trust Center; the rest, our team turns around fast.