Security & data protection
Health tourism sales teams handle sensitive patient information. Here is how Upsense is built to protect it — and what we commit to as a company.
Tenant isolation
Every company's data lives behind database-level row security. Isolation is enforced by the database itself (PostgreSQL Row Level Security), not only by application code — so a bug in the app cannot expose another company's records.
Access control
Role-based permissions decide who can see which pipeline, conversation and patient record. Managers see their team; reps see the leads assigned to them. Every permission is configurable per company.
Audit log
Actions that change a record — assignment, stage change, message sent, data export — are written to an audit trail with the acting user and a timestamp, so any change can be traced back.
Data retention
You own your data. It is retained for as long as your account is active and deleted on request, within the periods described in our privacy policy. Backups are encrypted and rotated.
Compliance
Upsense is built to be KVKK and GDPR compliant: a lawful basis for processing, data subject requests (access, correction, deletion), data processing agreements, and transparency about the sub-processors we use.
Transport & storage
All traffic runs over TLS. Data at rest is encrypted, and credentials and channel tokens are stored in an encrypted secret store — never in plain text.
Security questions?
If you are evaluating Upsense for a clinic or an agency and need detail on data handling, write to us — we answer security questionnaires.
Contact us