How We Protect Data
Last updated: 27 September 2026
Convero is operated by SecurePath Technologies Limited. This page describes safeguards and data handling in the product for businesses using WhatsApp, Instagram, Messenger and M-Pesa.
Business and customer roles
A business using Convero decides why it communicates with its customers and which services it enables. Convero processes those conversations to provide the configured service. We manage our own business account, billing and support records. The Kenya Data Protection Act 2019 gives individuals rights concerning their personal data; see our Privacy Policy for how to contact us.
Access and credentials
Convero uses tenant-scoped database access to limit which business records an application request can read. New Meta and M-Pesa integration credentials are encrypted when stored, using a key supplied separately from the database; older records may require migration. These are safeguards, not a guarantee against every software error, compromised account or data breach. Businesses should limit staff access and protect the accounts they connect to Convero.
Payments and records
Convero can store an M-Pesa payment request, its status, payer number, amount, reference, receipt and information used for reconciliation. It can also retain encrypted callback evidence for replay and review, then redact the raw callback body through a scheduled process. Customers enter their M-Pesa PIN on Safaricom's prompt; Convero does not ask for that PIN.
Operational events, audit entries and payment records are separate from a lead's conversation. Removing a lead does not necessarily remove all of those records. Our data deletion page explains the normal delete and erasure paths.
Requests
For access, correction, objection or erasure questions, contact the business you messaged or email hello@convero.ai. Tell us the business and channel involved so we can locate the right records and verify the request.