Access & privacy

Control who gets in, and answer every data request

Two-factor authentication required per role. Five built-in roles plus your own. Deletion requests that end in a certificate, and a customer data export you can hand to the person who asked for it.

500 conversations, no credit card.

Two-factor authentication

A second factor, required for the people you choose

Atender uses authenticator apps — the six-digit codes from an app on the phone. You turn it on once for the workspace in Settings, Security, and scope it by role: Owners, Team leads, everyone else. The people a policy covers cannot get in until they have enrolled, so there is no grace period to chase. If someone loses their phone, an admin resets their two-factor and they enrol again.

Roles and permissions

Five roles out of the box, and your own when you need them

Every person in the workspace has a role, and the role decides what they can open and do. Five are built in. When none of them is the right shape for a group of people — a refunds desk, an outsourced night shift — build a custom role from named permissions and give it only what that group needs.

  • Owner — runs the workspace, including billing and security
  • Team Lead — runs a team and the settings that team depends on
  • Agent — answers customers
  • Reader — can look at the work without changing it
  • Analytics — reporting only
  • Custom roles — built from named permissions, per workspace
Deletion requests

Deletion requests, with an evidence trail

When someone asks to be deleted, you raise a numbered request — DR-1, DR-2 and on — and the product walks it through to the end. It removes the contact and the conversations, recordings and transcripts linked to them.

  • 1 — The request is raised and its scope is frozen
  • 2 — A grace window runs before anything is removed
  • 3 — The person running it types the confirmation back
  • 4 — The removal is recorded step by step as it runs
  • 5 — The archive is kept for 30 days, then goes too
  • 6 — A deletion certificate closes the request
Customer data export

Hand over everything you hold on one customer

The export is a ZIP with a manifest listing what is inside and an exclusions report naming what was left out. You choose whether to include call audio, attachments and internal notes, and whether conversations come out as PDF or as Markdown.

A reason is required before it runs. Every download is recorded, and the link stops working after seven days. Teams use it for access requests from customers, for legal cases, and when working through a security incident.

  • ZIP parts, with a manifest and an exclusions report
  • Options: call audio, attachments, internal notes
  • Conversations as PDF or Markdown
  • Needs the privacy permission and a written reason
  • Downloads logged; links expire after 7 days
Also worth knowing

Three smaller things people ask about

A caller opt-out deletes the audio

If a caller asks not to be recorded, the recording of that call is deleted.

One conversation, on its own

A single conversation can be exported as a PDF or as Markdown, without running a full customer data export.

Sign-in today

An email address and a password, with two-factor on top. No single sign-on yet.

The full terms are in our privacy policy and terms.

Access & privacy — FAQ

What we do, and what we do not do yet.

See Atender in action

Try the full platform for free. Or book a demo and we will walk you through it.

500 conversations, no credit card.