ClickCease Data, Privacy & Security FAQs - Help Center - WhatConverts

Data, Privacy & Security FAQs

This article answers common questions about data privacy, HIPAA compliance, encryption, and security features in WhatConverts. It covers how sensitive information is handled, protected, and accessed within the platform.

Why can’t I see the lead’s name or phone number in my email alerts?

In HIPAA-enabled accounts, email notifications omit all potential personal identifying information (PII). Standard email is not a secure method for transmitting protected health information (PHI), so identifying data is removed from alerts.

What information is removed from HIPAA email notifications?

Email notifications do not include customer or patient names, email addresses, phone numbers, addresses, form contents, chat contents, or call transcriptions.

Can I download call recordings from a HIPAA-enabled account?

No. Call recordings cannot be downloaded when HIPAA is enabled.

How do I access full lead details in a HIPAA-enabled account?

You must log in to your WhatConverts dashboard to view complete lead details and listen to call recordings.

Does enabling HIPAA compliance automatically make me HIPAA-compliant?

No. While WhatConverts provides technical safeguards, you must also sign a Business Associate Agreement (BAA) and ensure your internal processes meet HIPAA requirements.

What is a BAA and why do I need one?

A Business Associate Agreement (BAA) is a legal contract required under HIPAA. It outlines how WhatConverts safeguards protected health information. A signed BAA is required to store patient data in the platform.

 

How is my data protected in WhatConverts?

Data is encrypted both at rest (while stored) and in transit (while being transmitted to and from the platform).

Who can see the leads in my account?

Only authorized users added to the account can access leads. Access can be restricted further using User Roles.

Does WhatConverts log access to sensitive data?

Yes. When users access potential PHI in leads or call recordings, that access is logged.

Why was I automatically logged out of my account?

For security purposes, users are automatically logged out after 15 minutes of inactivity to prevent unauthorized access.

Can I use webhooks or Keragon with a HIPAA-enabled account?

Yes, but some information may be restricted. Webhooks must be sent to secure (HTTPS) URLs, and the receiving platform must also be HIPAA-compliant.

Are call recordings and transcripts encrypted?

Yes. When HIPAA is enabled, call recordings and transcripts are encrypted and accessible only within the secure dashboard.

Related Topics

Get a FREE presentation of WhatConverts

One of our marketing experts will give you a full presentation of how WhatConverts can help you grow your business.

Schedule a Demo
ready to get marketing clarity?

Grow your business with WhatConverts

14 days free trial Easy setup Dedicated support
G2 Best Results Summer 2025 Badge
G2 Best Relationship Summer 2025 Badge
G2 Best Usability Summer 2025 Badge
G2 Most Implementable Summer 2025 Badge
G2 Momentum Leader Summer 2025 Badge