Privacy & GDPR
Conviro provides built-in tools to help you comply with GDPR, KVKK (Turkish data protection law), and other privacy regulations.
Cookie Consent
Conviro includes a configurable cookie consent banner for your website:
- Go to Dashboard -> Settings -> Privacy -> Cookie Consent.
- Enable the cookie banner.
- Customize the text, button labels, and categories (Necessary, Analytics, Marketing).
- Choose the display style (banner, popup, or floating bar).
- The banner automatically blocks non-essential cookies until the visitor consents.
Cookie Categories
| Category | Examples | Can Be Declined? |
|---|---|---|
| Necessary | Session cookies, authentication | No |
| Analytics | Google Analytics, Conviro analytics | Yes |
| Marketing | Ad tracking, retargeting pixels | Yes |
PII Redaction
Conviro can automatically detect and redact Personally Identifiable Information in chat transcripts:
- Email addresses -- detected and masked (e.g. j*@email.com)
- Phone numbers -- masked (e.g. +49 1234)
- Credit card numbers -- fully redacted
- Custom patterns -- define regex patterns for industry-specific PII
Enable PII redaction at Dashboard -> Settings -> Privacy -> PII Redaction.
Data Retention
Configure how long conversation data is stored:
- Go to Dashboard -> Settings -> Privacy -> Data Retention.
- Set retention periods:
- Chat transcripts -- 30 days, 90 days, 1 year, or custom
- Contact data -- until manually deleted or auto-purge after X days
- Analytics data -- aggregated data is retained; raw data follows your retention policy
- Data is automatically purged after the retention period expires.
Data Subject Access Requests (DSAR)
When a customer requests access to or deletion of their data:
- Go to Dashboard -> Settings -> Privacy -> DSAR.
- Search by email or name.
- Export -- generate a ZIP file with all data related to the individual.
- Delete -- permanently remove all data for the individual across all chatbots.
- The action is logged in the compliance audit trail.
KVKK Compliance (Turkey)
Conviro supports KVKK-specific requirements:
- Turkish-language consent forms and privacy notices
- VERBiS registration support
- Data controller / data processor agreement templates
- Cross-border transfer documentation
Compliance Audit Trail
Every privacy-related action (consent given, data exported, data deleted, retention policy changed) is logged in an immutable audit trail at Dashboard -> Settings -> Privacy -> Audit Log.
Tips
- Enable PII redaction from day one -- it is much harder to redact retroactively.
- Set data retention policies that match your industry requirements (e.g. healthcare may require longer retention).
- Review the audit trail monthly to ensure compliance processes are working correctly.
- Display a clear privacy policy link in your widget's pre-chat screen.