Built to be trusted
with the inbox.
Cloodot sits on your busiest, most personal channel — your customers’ conversations. Here’s exactly how we keep them safe, what we do with the data, and the controls you hold.
Three promises we don’t bend on.
Encrypted in transit & at rest
Every conversation is protected with TLS in transit and encryption at rest. Your customers’ messages are never exposed in the clear.
GDPR-aligned handling
We handle personal data on privacy-first principles aligned with the GDPR — lawful basis, data minimisation, and honouring access, export, and deletion requests.
Never trained on your data
Your conversations are yours. We never use customer data to train external or general-purpose models, and never sell it. Full stop.
Account controls, shipped and on by default.
Two-factor authentication
Authenticator-app 2FA with backup codes, on top of strong password rules, for every account.
Role-based access
Owner, Admin, and Member roles with team-level routing — people see exactly what they should, and nothing more.
Full session control
See every signed-in device with its location and last activity, then revoke any one or sign out everywhere at once.
Export any time, no lock-in
Your conversations and customer records are exportable whenever you like. Leaving is never held hostage.
Human-in-the-loop & audit trail
Handoff rules pass the messy moments to a teammate with the full transcript, so there’s always a person accountable and a clear record of what happened.
Plain answers to the diligence questions.
- What we collect
- The messages your customers send you, the contact details they share, and the account data your team needs to sign in and operate. Nothing you haven’t agreed to.
- Why we process it
- To deliver the product: unifying your channels, powering the AI agent’s replies and actions, and routing conversations to the right teammate.
- AI providers
- The AI agent is powered by large language models. Prompts are sent to model providers only to generate a response for you — never for the providers to train on. See the Privacy Policy for the current subprocessor list.
- Retention & deletion
- Data is retained while your account is active and removed on request. Reach out and we’ll walk you through export and deletion for your workspace.
- Sub-processors
- Cloodot runs on hardened cloud infrastructure and a small set of vetted sub-processors, each listed in the Privacy Policy. We update the list before onboarding a new one.
- Data ownership
- Your conversations and customer records belong to you. We act on your instructions and never repurpose your data for anything you haven’t consented to.
Cloodot aligns its practices with GDPR principles. We don’t claim certifications we don’t hold — if your security team needs a deeper walkthrough of our controls, we’re glad to get on a call.
Doing a security review?
We’ll help.
Send over your questionnaire or book a call — we’d rather answer the hard questions up front than have you guess.