Trust Centre

Your business runs on conversations.
We treat them like they're yours.

Green Weka captures your calls, emails and messages so nothing slips through. That only works if you can trust us completely with what we hold. This page explains — plainly — how we secure it, who touches it, and what your rights are.

Security contact
Operated by
Web 3 Limited, New Zealand
Last updated
22 July 2026
Overview Compliance Data handling Subprocessors Documents Controls FAQ

Compliance & verification

We don't ask you to take our word for it. These are the assessments and verifications we've completed with third parties.

Google CASA Tier 2

Passed Google's Cloud Application Security Assessment — the independent security audit required to access Gmail data.

Google OAuth verified

Approved by Google's restricted-scope review for Gmail access, including how we store and process your email.

Microsoft verified publisher

Verified by Microsoft as a legitimate publisher for Outlook and Microsoft 365 integrations.

Payments by Stripe

We never see or store your card details. All payments are handled by Stripe, a certified PCI Level 1 provider.

How your data is handled

Every conversation follows the same protected path through our system. Here's the whole journey.

Captured

Calls, emails and messages are captured over encrypted connections (TLS 1.2+, SRTP for voice). Nothing travels in the clear.

Processed

Transcription and analysis run with specialist AI providers, listed in full below. Your data is processed only to serve you — never sold, never used for advertising.

Stored

Your data is stored encrypted at rest on secure cloud infrastructure, isolated per account. Call recordings are moved into our own encrypted storage — not left sitting with third parties.

Accessed

Only you and the team members you invite can see your communications. Internal access is least-privilege — limited to what's needed to run and support the service.

Deleted

Close your account and your data is deleted from our systems within 30 days. Third-party processors delete their copies on their own published schedules.

Who touches your data

These are the categories of third-party service we use to run Green Weka, what each does with your data, and where. The full named list is available to customers and prospective customers on request — email security@greenweka.com.

ProviderPurposeRegion
Cloud infrastructureHosting, databases and encrypted storageGlobal (US provider)
Telephony carriersCall carriage and recording over encrypted trunksNew Zealand / Australia
Speech processingConverting speech to text, and the assistant's voiceAustralia / United States
AI analysisSummarisation and extraction — no training on your dataUnited States
Real-time communicationsVoice and video session infrastructureAustralia / United States
AuthenticationLogin credentials onlyAustralia (Sydney)
PaymentsCard processing — we never see your card detailsUnited States

Policies & documents

Everything in writing, in one place.

Security controls

A concise list of the measures in place.

Infrastructure

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest
  • Encrypted voice media (SRTP)
  • Content Security Policy enforced
  • Enterprise-grade DDoS protection
  • Serverless architecture — no servers to patch

Product

  • Per-account data isolation
  • Team roles & seat-based access
  • OAuth-only integration access — we never store your passwords
  • Verified caller ID
  • Account deletion on request

Organisational

  • Least-privilege internal access
  • Security review for all third-party providers
  • Incident response process
  • Regular dependency & vulnerability updates
  • Independent security assessment passed (Google CASA Tier 2)
  • NZ company, subject to the NZ Privacy Act 2020

Questions people actually ask

Is my data used to train AI models?

No. We never train models on your data, and we've configured our AI providers so they don't either. Our AI analysis provider does not train on customer data as a matter of policy, and we've opted out of the model-improvement programs run by our speech providers. Your conversations are processed to serve you — nothing else.

Who can listen to my call recordings?

You, and the team members you've invited to your account. That's it. Recordings are stored in our own encrypted storage, isolated per account. Internally, access is least-privilege — limited to what's strictly needed to run and support the service, never for browsing.

Where is my data stored?

Your communications, transcripts and recordings are stored encrypted on secure cloud infrastructure. Call media and real-time voice are processed in Australia, close to home. Green Weka is operated by Web 3 Limited, a New Zealand company, so your data is protected under the NZ Privacy Act 2020.

Is call recording legal for my business?

In New Zealand, it's generally lawful to record a call you're a party to — NZ operates on a "one-party consent" basis, though the Privacy Act 2020 still requires you to handle recordings responsibly. In Australia, the rules are set state-by-state under surveillance devices legislation and some states are stricter, so the safest practice everywhere is to let callers know they're being recorded. This is general information, not legal advice — if you're unsure, check the rules for your state or get advice.

What happens to my data if I cancel?

Close your account and your data — recordings, transcripts, emails, messages, contacts — is deleted from our systems within 30 days. If you want a copy of anything first, ask us before you close.

How do I report a security issue?

Email security@greenweka.com. Every report goes straight to the engineering team and we aim to acknowledge within one business day.

Still have a question?

Security, privacy or compliance — ask us directly at security@greenweka.com