Skip to content
Trust & Compliance

Your conversations are private.

We keep it that way.

Practice only works when people can fail safely. Practice sessions are private: nobody but the person sees them. Your organization does see each person's development per capability and progress through programs. This page spells out who can see what.

At a glance
ISO 27001Certified & audited
HostingEU only — never leaves
AI trainingZero — your data isn't used
Works councilWOR-ready pack included

Security

ISO 27001 Certified

Our Information Security Management System is independently audited and certified by Brand Compliance. The certificate is available in our Trust Center.

Encryption by Default

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Voice recordings and transcripts are never stored unencrypted.

Hosted in the EU

All customer data is stored and processed in the European Union — on AWS or Azure, in the Frankfurt (Germany) region. No customer data leaves the EU.

Enterprise Access

SSO via SAML 2.0 and OIDC, SCIM provisioning, and enforced MFA for administrative access.

Tested, Not Assumed

Independent penetration testing; summary reports available under NDA.

When Something Goes Wrong

Documented incident-response process: affected customers are notified in line with GDPR breach-notification duties. Status page at status.converz.co.

Privacy

GDPR

We process personal data under a Data Processing Agreement available to every customer, with documented legal bases, records of processing, and support for data-subject requests (access, correction, deletion, export). Our DPO can be reached at privacy@converz.co.

Retention & Deletion

You control how long recordings and transcripts are kept. You set the default retention period; deletion on request and removal from backups follow the windows you define. When a contract ends, all customer data is deleted or returned on the terms you set.

Zero Model Training

We do not use your data — recordings, transcripts, or anything derived from them — to train our AI models. Your team's communication style stays inside your organization.

And Our Subprocessors Don't Either

Converz uses third-party AI models for conversation and analysis. Under our enterprise agreements with these providers, your data is not used to train their models, is not retained beyond processing, and is processed under DPAs.

Practice, not surveillance

Built to develop your people — never to police them.

Converz analyzes conversations so each person knows what to practice next. That only works if your people trust it. So the boundaries are structural, not just promised:

Individuals see their own coaching first.

Practice sessions and personal feedback belong to the employee: nobody else sees a session, a recording or a transcript. Managers do see each person's development per capability and their progress through programs, not a surveillance feed.

Not an assessment file.

Converz data is designed for development. We advise in our documentation and DPA against its use as the basis for dismissal or formal performance scoring.

Employee transparency built in.

People can see what is analyzed about them and why — no hidden scoring.

Works council ready.

Under the Dutch Works Councils Act (WOR art. 27), systems that observe employee performance typically require works-council consent. We support that conversation: a ready-made works-council information pack covering what Converz does and doesn't do with employee data, plus a DPIA template for your privacy team.

EU AI Act

Compliant with the EU AI Act.

Our position, in plain terms:

  1. 01

    Skills, not psyches

    Analysis is based on observable conversational behavior (structure, phrasing, timing) — not emotion recognition or biometric inference, which the Act prohibits in the workplace.

  2. 02

    Limited or high risk, depending on how you configure it

    Limited risk when per-person evaluations never reach anyone with authority over that person, high risk when they do. Either way the corresponding transparency obligations are met — users always know they are talking to an AI.

  3. 03

    Documentation for your compliance review

    Risk classification rationale, model documentation and human-oversight measures are available in the Trust Center.

Governance

Your rules, your guardrails.

Converz isn't a black box. You control the AI's persona, knowledge base, and boundaries — from the tone of a difficult roleplay to the compliance requirements of a regulated industry.

Granular RBAC

Role-based access control across the organization, aligned with the visibility defaults above.

Persona Safety

Configurable guardrails that keep AI conversation partners professional and on-brand.

Audit Logs

Comprehensive logging of sessions, access, and administrative actions, exportable to your SIEM.

Everything your security review needs.

Standard documentation pack: ISO certificate, DPA, subprocessor list, pen-test summary, AI Act documentation, works-council pack. Most security questionnaires answered from the Trust Center; the rest, our team turns around fast.