Trust

Business software data security - how Ragnos AI protects customer data

Your business holds phone numbers, payment history and health declarations for hundreds of people. This page sets out where that sits, who can reach it, and what you can take with you.

No certifications claimedFull export, any timeRole-based access

Where your data lives

Customer data is held on the enterprise cloud infrastructure of the underlying platform Ragnos AI is built on, encrypted in transit and at rest, with access controlled by the role-based permissions you configure. The specific hosting details are provided in writing during onboarding.

Access control

Who on your team can see what

Two layers: the role, and an optional restriction to the user’s own contacts.

Owner, admin, sales and front desk - four permission sets

Each set defines what a user can see and do. A front-desk login can work today’s bookings without being able to export your customer list; a sales login can work its own pipeline without reaching revenue reporting or intake forms.

Restricting a user to their own contacts

On top of the role, a user can be limited to only the contacts assigned to them. A staff member sees their clients and nobody else’s. This is the default configuration wherever staff should only see their own clients.

Permissions are set per user rather than per role template, so an unusual arrangement - a part-time manager who covers two branches, a staff member who also does sales - does not force you into giving somebody more access than they need.

Sensitive data

Health data, intake forms and consent forms

intake form responses and liability consent forms are a different category from a phone number. They describe someone’s health, and they are held because your business has a duty of care, not because they are useful for marketing.

They are stored against the customer record behind owner and manager permissions, with high-risk answers flagged so the staff member who needs to know sees it. Staff who do not need to open a intake form cannot open one. They are never used to segment a marketing campaign, and they are never exported into a messaging tool.

The legal wording is yours. Ragnos AI provides the form structure, the flagging and the storage. The text of your intake form and your liability consent form must be written or approved by your own lawyer. We will not supply wording for a liability document.

Messaging

WhatsApp messages and how long they are kept

Worth being precise here, because part of this is genuinely not in our hands.

  • Conversations are stored against the customer record so your team has context when someone messages again
  • Messages sent through the WhatsApp Business Platform also pass through Meta, whose retention policies are their own and outside our control
  • Opt-outs are honoured immediately and permanently across every sequence in the account
  • There are no group broadcasts anywhere in the platform, so no customer’s number is ever exposed to another customer
  • A customer’s conversation history is deleted with their record if you ask us to delete them
Exit

If you ever leave - exporting your data

You can export your full customer list, conversation history and form responses to CSV at any time, without asking permission and without an exit fee.

This is published deliberately, and it is unusual - most vendors leave it vague. The reasoning is straightforward: a business that cannot leave is a business that stays for the wrong reason, and a vendor that knows you cannot leave has no incentive to keep improving.

If you do leave, we will help with the export rather than making it difficult. It is your data.

Questions

Frequently asked questions

Are you ISO 27001 or SOC 2 certified?

No. Ragnos AI does not hold those certifications and we are not going to imply otherwise - claiming a certification you do not hold is a legal problem, not just a marketing one. What we can describe is the underlying platform infrastructure and our own operational controls, which is what this page does.

Where is our customer data physically stored?

On the infrastructure of the underlying platform Ragnos AI is built on, which operates enterprise cloud hosting with encryption in transit and at rest. We will give you the specific current details in writing during onboarding rather than publishing a claim here that could go out of date.

Can Ragnos AI staff see our customer data?

Support staff can access your account when helping you, which is how support works. Access is limited to the people who need it and is not used for anything other than supporting you. If you need that in a contractual clause, ask and we will put it in writing.

What happens to WhatsApp messages?

Conversations are stored against the customer record so your team has context. Meta retains messages according to its own policies, which are outside our control and worth reading if that matters to you.

Can we delete a customer entirely?

Yes. A customer can be deleted on request, including their messages, forms and history. Some records may be retained where you have a legal obligation to keep them - your consent form, for example - and that decision is yours, not ours.

What if we want to leave?

Export everything, including the full customer list, conversations and form responses, in CSV. There is no exit fee and no hostage-taking. The ability to leave is what keeps a vendor honest.

Ask us a security question

If you have a specific requirement - a clause, a retention period, a data location - ask before you buy rather than after.

No card needed. No obligation. English or Arabic.