> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rc.cleverhub.co/llms.txt
> Use this file to discover all available pages before exploring further.

# How We Handle Data

> How Hello Clever secures business, transaction, and consumer data, respects data sovereignty laws, and uses data responsibly for AI and ML.

Hello Clever prioritises the security, privacy, and sovereignty of every piece of data entrusted to us, from business information to transaction details and consumer data. As a global fintech provider, we comply with data sovereignty laws across regions and use data responsibly, particularly in AI and ML. This page explains how we manage each type of data, the measures that keep it secure and compliant, and how we use data responsibly for AI and ML research.

<Note>
  Our data handling is built on stringent security protocols, adherence to compliance standards including SOC 2, and a commitment to transparency and ethics in data-driven product innovation.
</Note>

***

## Business data

We handle business data with care, storing sensitive information about your company and operations securely and limiting access to authorised personnel.

<CardGroup cols={2}>
  <Card title="Purpose-driven collection" icon="filter">
    We collect only the business information necessary for account creation, service delivery, and compliance, keeping data exposure minimal.
  </Card>

  <Card title="Data encryption" icon="lock">
    All business data is encrypted in transit and at rest, so it stays secure across every stage of processing.
  </Card>

  <Card title="Access control" icon="user-lock">
    Strict role-based access control limits who can reach your data, and all access is logged and monitored.
  </Card>

  <Card title="Compliance and transparency" icon="clipboard-check">
    SOC 2-aligned processes and regular audits keep our practices current, and businesses can request their data handling and security logs.
  </Card>
</CardGroup>

***

## Transaction data

Transaction data is highly sensitive, so we have rigorous systems to process every transaction accurately, securely, and in line with industry standards.

<CardGroup cols={2}>
  <Card title="End-to-end encryption" icon="shield-halved">
    Every transaction is encrypted from initiation to confirmation, preventing unauthorised interception.
  </Card>

  <Card title="Tokenisation" icon="key">
    Sensitive transaction details are replaced with a unique identifier, keeping original data inaccessible to unauthorised parties.
  </Card>

  <Card title="Multi-layer authentication" icon="user-shield">
    Transaction verification uses multiple layers of authentication to guard against fraud and unauthorised access.
  </Card>

  <Card title="Real-time fraud monitoring" icon="magnifying-glass-chart">
    Rule-based and machine learning detection flags unusual patterns in real time, auto-blocking high-risk transactions and routing others for review. Our [Flagright](https://flagright.com) partnership sharpens this further.
  </Card>
</CardGroup>

***

## Consumer data privacy and sovereignty

Protecting consumer data is a top priority. We comply with global privacy regulations and data sovereignty laws so personal information is managed responsibly and within each region’s legal requirements.

<CardGroup cols={2}>
  <Card title="Data minimisation" icon="filter">
    We collect only the consumer data needed to process transactions and deliver services.
  </Card>

  <Card title="Explicit consent" icon="circle-check">
    Any use beyond essential transaction purposes requires explicit consumer consent, with full transparency and control.
  </Card>

  <Card title="Privacy by design" icon="user-shield">
    Privacy is a core principle of our systems, keeping consumer data secure through every stage of processing.
  </Card>

  <Card title="Secure storage and access" icon="lock">
    Consumer data is encrypted, stored on compliant servers, and reachable only by authorised personnel, with audit logs tracking interactions.
  </Card>

  <Card title="Data sovereignty" icon="globe">
    Data is stored in the appropriate regional data centres. EU customer data is stored in the EU, and Australian data within Australia.
  </Card>

  <Card title="Data subject requests" icon="file-shield">
    Consumers can access, rectify, or erase their data, and we respond promptly in line with GDPR, CCPA, and regional privacy laws.
  </Card>
</CardGroup>

***

## Responsible use of data for AI and ML

We believe in the responsible, transparent, and ethical use of data for AI, ML, and product research, using these technologies to improve our services while protecting data privacy and consumer rights.

<CardGroup cols={2}>
  <Card title="Anonymisation first" icon="user-slash">
    All data used to train AI and ML models is anonymised, with no personally identifiable information included.
  </Card>

  <Card title="Consent-driven" icon="handshake">
    Any data use beyond essential services is handled with explicit consumer consent, aligned with privacy expectations and regulation.
  </Card>

  <Card title="Fair and bias-free models" icon="scale-balanced">
    Strict standards detect and reduce bias, keeping our services fair and equitable for all consumers.
  </Card>

  <Card title="Transparent and monitored" icon="eye">
    We communicate clearly about how data may be used, and our models are regularly evaluated against ethical standards.
  </Card>
</CardGroup>

<Tip>
  For merchants, responsible AI and ML translate into stronger fraud prevention, richer anonymised customer insights, and ethical product development you can confidently stand behind.
</Tip>

***

## Our ongoing commitment

Our approach is grounded in security, privacy, compliance, and responsible innovation. Our team trains regularly on data security, privacy, sovereignty, and responsible AI, and we keep improving our infrastructure and processes to meet and exceed industry standards. To discuss your specific data security needs, reach out to our support team.


## Related topics

- [Get Started with Hello Clever](/getting-started/overview.md)
- [We’re SOC 2 Compliant](/platform-overview/compliance/soc-2-compliant.md)
- [Clever AI Actionable Insights](/clever-ai/actionable-insights.md)
