Data protection & DPDP
Last updated 17 June 2026
Convero is built for high-stakes, multi-tenant use. Here is how we align with India's Digital Personal Data Protection Act and Kenya's Data Protection Act.
India — DPDP Act, 2023
We support the roles of Data Fiduciary and Data Principal. Personal data is processed for the specific purpose of running your sales agent, on a lawful basis (consent or legitimate use), and we help you honour Data Principal rights — access, correction, erasure, and grievance redressal.
Kenya — Data Protection Act, 2019
As a Nairobi-based operator, we observe the ODPC's principles of lawful, fair and transparent processing, purpose and storage limitation, and data subject rights, including the conditions for any cross-border transfer.
Tenant isolation
Each client's data is separated at the database level using Postgres row-level security with a non-superuser runtime role — the database itself blocks any cross-tenant read or write, not just the application layer.
Security measures
Role-based access control, an append-only audit log of sensitive actions, encryption in transit, secret-management guardrails, rate limiting, and least-privilege database roles for runtime versus administration.
Retention & deletion
Data is retained only as long as needed. Deleted leads are soft-deleted and then hard-purged after a grace period; usage and audit data are trimmed on a defined schedule. Deletion requests are actioned promptly.
Sub-processors
We use a short list of sub-processors (cloud hosting, Meta — the WhatsApp Business Platform and the Messenger Platform for Instagram and Facebook — and the configured AI model provider), each under data-protection terms. A current list is available on request.
Breach notification
In the event of a personal-data breach, we will notify affected clients and the relevant authorities without undue delay, in line with applicable law.
Contact
Data-protection enquiries and data-subject requests: hello@convero.ai.
This page describes our approach and is not legal advice.
