Data Processing Agreement

Table of Contents
  1. Definitions
  2. Scope of Processing
  3. Obligations of the Processor
  4. Sub-Processors
  5. Data Transfers
  6. Security Measures
  7. Data Breach Notification
  8. Data Subject Rights
  9. Audit Rights
  10. Term and Termination
  11. Return and Deletion of Data

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller", "you") and Convora AI ("Processor", "we", "us") for the use of the Convora platform. This DPA sets out the terms under which we process personal data on your behalf.

This DPA applies where and only to the extent that Convora processes personal data on behalf of the Controller in the course of providing the Service, and such personal data is subject to data protection laws.

1. Definitions

2. Scope of Processing

The Processor shall process personal data only as necessary to provide the Service and in accordance with the Controller's documented instructions.

Category Details
Purpose of processing Providing AI chatbot services, including document ingestion, conversation handling, lead capture, and analytics
Types of personal data Names, email addresses, IP addresses, chat messages, browser information, and any data voluntarily provided by Data Subjects through the chat widget
Categories of Data Subjects Website visitors who interact with the chat widget, and the Controller's authorized users
Duration of processing For the duration of the Service agreement, plus up to 30 days for data deletion after termination
Nature of processing Collection, storage, retrieval, AI inference, analysis, and deletion

3. Obligations of the Processor

Convora AI, as the Processor, shall:

4. Sub-Processors

The Controller provides general authorization for the Processor to engage the following sub-processors:

Sub-Processor Purpose Location
Qdrant Cloud Vector database for storing and retrieving document embeddings EU / US (cloud regions)
Google Cloud (Gemini) AI model inference for generating chat responses United States
Groq AI model inference for fast response generation United States

The Processor shall:

The Controller may object to a new sub-processor by notifying the Processor within 14 days of receiving notice. If the objection cannot be resolved, the Controller may terminate the Service.

5. Data Transfers

Where personal data is transferred to countries outside the Controller's jurisdiction:

6. Security Measures

The Processor implements the following technical and organizational measures:

7. Data Breach Notification

In the event of a Data Breach, the Processor shall:

8. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests, including:

The Processor shall promptly notify the Controller if it receives a request directly from a Data Subject, and shall not respond to such requests without the Controller's authorization unless required by law.

9. Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA:

10. Term and Termination

11. Return and Deletion of Data

Upon termination of the Service or upon the Controller's request:

Need a signed DPA?

Contact us at hello@convora.ai to request a countersigned copy of this Data Processing Agreement.