Security & Compliance
Every CCA Integrations plan comes with enterprise-grade encryption, EU data residency, and GDPR-aligned data handling out of the box.
CCA Integrations is built GDPR-first. All conversation data is processed in EU-based data centres. We act as a Data Processor under Article 28 GDPR and provide a Data Processing Agreement (DPA) to all customers. Data subjects can request export or deletion of their data at any time through our self-service portal or by contacting support.
All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. Conversation logs, contact records, and analytics data are stored in isolated, access-controlled environments. We conduct regular penetration testing and vulnerability assessments with third-party security firms.
Employee access to customer data follows a strict least-privilege model. All access is logged and audited. Multi-factor authentication is enforced for all internal systems. Production environments are separated from development and staging environments.
Conversation data is retained according to our data retention policy. Enterprise customers can configure custom retention windows. You can delete all stored data at any time from your dashboard or by contacting our support team.
We maintain a public list of approved subprocessors. When we engage new subprocessors, Enterprise customers are notified in advance and have the right to object. All subprocessors are contractually bound to the same data protection standards we uphold.
In the event of a data breach, we follow a documented incident response plan. Affected customers are notified within 72 hours as required by GDPR Article 33. We maintain a dedicated security contact: support@ccaintegrations.com.
Enterprise customers receive a full DPA and security documentation package. See Enterprise plan →
Contact security team