Built to be trusted with candid input.
Sessions on Converge capture what people really think. That only works when clients and participants can rely on how the data is handled. This page sets out our commitments, our controls, and every third party that touches your session data.
Report requests, our published policies, and live control status are served from our Drata trust center, which is updated automatically from our compliance program.
SOC 2 Type II
Examined annually by an independent CPA firm across security, availability, processing integrity, confidentiality, and privacy. Report available under NDA.
Encrypted everywhere
TLS for every connection. Encryption at rest for databases, file storage, recordings, and backups.
Enterprise identity
SAML 2.0 and Okta single sign-on, SCIM provisioning, and multi-factor authentication available for accounts.
AI without training
AI providers process session content under commercial terms that prohibit training on it. Output is reviewed by people.
GDPR and UK GDPR commitments.
Converge is a US company that works with organisations across the EEA, UK, and Switzerland. Here is how the platform fits your obligations.
- Our role
- For everything contributed inside a session, the organization running it is the controller and Converge is the processor. We act only on documented instructions. For account and billing data, we are the controller.
- Data processing agreement
- Our standard Data Processing Addendum is published at startconverge.com/dpa. It incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, and sets out our security measures, sub-processor terms, and breach notification duties. Clients accept it by reference in their order form or sign it separately.
- Where data is processed
- Our platform is hosted on Amazon Web Services in the United States (Ohio) by default. Transfers from the EEA, UK, and Switzerland rely on the safeguards above. Where a client agreement requires it, we provision a dedicated single-tenant deployment in an AWS region of the client's choosing, including the EU.
- Participant anonymity
- Sessions can allow anonymous joining, so participants contribute without a name or email. Moderators can lock anonymity so identities are not shown in results.
- Consent and recording
- Clients can require participants to acknowledge a consent notice, in their own words, before joining, including notice of recording where a session is recorded.
- Data subject requests
- We help clients answer access, correction, and deletion requests about session data within the timeframes in the DPA. Requests sent to us directly are referred to the client and assisted.
- Retention and deletion
- Clients delete session data and recordings from inside the platform. On request we permanently delete a session and its files from our infrastructure and from AI provider storage. Automatic deletion windows, such as 90 days after a session ends, are available on dedicated deployments.
- Sub-processor changes
- The list below is our current set of sub-processors. Clients with a DPA are notified of additions in line with its terms and may object.
What AI does with session content, and what it never does.
Converge uses AI to summarise and theme responses, transcribe recordings, translate live sessions, and answer researchers' questions about a session. Content is sent to the providers listed below only to perform those functions.
- Providers are bound by commercial terms that prohibit using submitted content to train models.
- Where the feature allows it, participants are referenced by internal IDs rather than names in AI prompts.
- AI output is a draft for a human researcher. No decision with legal or similarly significant effects on a person is made by these systems.
- The in-session AI assistant and AI-generated deliverables are enabled per session by the client.
Every third party that may process your data.
Last updated September 23, 2026. Location is the provider's principal place of business. Providers that serve only our marketing website, such as its host and demo-scheduling tool, never see platform or session data and are covered in our Privacy Policy instead.
| Sub-processor | Purpose | Data involved | Location | Applies to |
|---|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage, transactional email, logging | All platform data and backups | United States | Platform |
| Cloudflare | Network security, content delivery, hosting of uploaded video | Network traffic; participant video and image submissions | United States | Platform |
| Zoom Video Communications | Live audio and video, recording, transcription | Live audio and video; recordings and transcripts, written directly to Converge storage | United States | Platform |
| Anthropic | AI analysis and the in-session AI assistant | Session text and transcripts | United States | Platform |
| OpenAI | AI analysis and transcript summaries | Session text and transcripts | United States | Platform |
| DeepL | Machine translation of session content | Session text submitted for translation | Germany | Multi-language sessions |
| User Interviews | Participant recruiting panel | Recruiting criteria, screener responses, recruited participants' profile data | United States | Clients using recruiting |
| Nylas | Calendar sync for scheduling interviews | Connected calendar account and availability | United States | Clients who connect a calendar |
| Stripe | Payment processing | Client billing details; no participant data | United States | Client billing |
| Google Workspace | Business email and documents | Support and account correspondence | United States | Client support |
How we run security day to day.
Independent testing
Annual penetration testing by an independent firm, continuous vulnerability scanning of our AWS environment, and findings tracked to closure.
Access control
Least-privilege access to production, periodic access reviews, role-based permissions inside the platform from observer to administrator, and logging of administrative access to production systems.
Tenant separation
Client workspaces are logically separated in a shared environment. Dedicated single-tenant deployments with their own infrastructure are available.
Resilience
Automated encrypted backups, documented business continuity and disaster recovery plans, and an incident response plan with client notification procedures.
People
Background checks on hire, security awareness training on onboarding and annually, and a documented set of security, privacy, and AI governance policies.
Secure development
A defined software development lifecycle with code review and change management, and a responsible disclosure process for reported vulnerabilities.
Need something for a vendor review?
Our SOC 2 Type II report and penetration test summary are available under NDA through our Drata trust center, alongside our published policies and live control status. Our Data Processing Addendum is published and can be signed by reference. For a countersigned copy or a completed security questionnaire, write to info@startconverge.com and tell us what your review needs.
To report a security vulnerability, email the same address with "Security" in the subject line. We acknowledge reports promptly and do not pursue good-faith researchers.