For companies

Data & Security

Last updated: 13 July 2026

This page explains, in plain terms, what happens to your organisation's data when you use SwiftCue — for the teams (and their legal, HR and IT partners) who need to know before rolling it out. For the formal detail, see our Privacy Policy and Terms of Use.

What data we handle

  • Your team: rep names, WhatsApp numbers and optional emails that you add.
  • Assessments: the transcripts, scores and coaching notes from practice roleplays, and the audio recordings of those voice notes and live calls.
  • Account & usage: manager logins and analytics about how the Service is used.

We do not sell your data, and we do not use your team's assessment content to train third-party AI models.

What happens to a practice conversation

  1. A rep records a voice note (or takes a live call) over WhatsApp.
  2. The audio is transcribed (Deepgram), and the transcript is scored by an AI customer/grader (Anthropic).
  3. The score and a coaching "Hot Brief" are returned to the rep in seconds.
  4. The transcript and audio are stored so managers can review and coach from the dashboard.

Where your data is stored

Our application and database run on Fly.io in Johannesburg, South Africa. Audio recordings are stored in Fly's Tigris object storage. Some processing (transcription, AI grading, messaging) is performed by the sub-processors below, which may operate outside South Africa.

Sub-processors

ProviderRole
AnthropicAI grading and AI-customer roleplay
DeepgramSpeech-to-text and text-to-speech
Twilio (incl. SendGrid)WhatsApp, voice calls, transactional email
Fly.io (incl. Tigris)Hosting, database and audio storage

Consent model

Reps give consent over WhatsApp before any assessment runs, and are told that practice sessions may be recorded for coaching. You remain responsible, as the employer, for informing your staff and meeting your obligations under applicable law. We're happy to support your internal consent process.

Retention & your control

  • Audio and assessment history are retained so managers can review them over time.
  • Managers can void an assessment (which removes it from stats) and recordings can be deleted on request.
  • On request or at the end of your contract, we will delete or return your data.

Security controls

  • Encryption in transit (HTTPS/TLS) everywhere.
  • Hashed passwords and token-based authentication for the dashboard.
  • Role-based access and tenant isolation — each store only sees its own data; internal cost data is never exposed to managers.
  • Signed webhooks — inbound WhatsApp and voice callbacks are cryptographically verified.
  • Rate limiting on public and authentication endpoints, and restricted access to production systems.
  • Security headers, and least-privilege handling of secrets.

Questions or a DPA?

If your legal or security team needs a data-processing agreement or has specific questions, contact privacy@swiftcue.io and we'll help.

See it on your own team

Run a free 2-week pilot — live in a day, no app for your reps to install, and a performance dashboard from day one.

Request a pilot →