Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller", "you") and Convora AI ("Processor", "we", "us") for the use of the Convora platform. This DPA sets out the terms under which we process personal data on your behalf.
This DPA applies where and only to the extent that Convora processes personal data on behalf of the Controller in the course of providing the Service, and such personal data is subject to data protection laws.
1. Definitions
- "Controller" — the entity that determines the purposes and means of processing personal data (you, the customer)
- "Processor" — the entity that processes personal data on behalf of the Controller (Convora AI)
- "Data Subject" — an identified or identifiable natural person whose personal data is processed
- "Personal Data" — any information relating to a Data Subject that is processed by the Processor on behalf of the Controller
- "Sub-Processor" — a third party engaged by the Processor to process personal data on behalf of the Controller
- "Data Breach" — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data
- "Service" — the Convora AI chatbot platform and related services
2. Scope of Processing
The Processor shall process personal data only as necessary to provide the Service and in accordance with the Controller's documented instructions.
| Category | Details |
|---|---|
| Purpose of processing | Providing AI chatbot services, including document ingestion, conversation handling, lead capture, and analytics |
| Types of personal data | Names, email addresses, IP addresses, chat messages, browser information, and any data voluntarily provided by Data Subjects through the chat widget |
| Categories of Data Subjects | Website visitors who interact with the chat widget, and the Controller's authorized users |
| Duration of processing | For the duration of the Service agreement, plus up to 30 days for data deletion after termination |
| Nature of processing | Collection, storage, retrieval, AI inference, analysis, and deletion |
3. Obligations of the Processor
Convora AI, as the Processor, shall:
- Process personal data only on documented instructions from the Controller, unless required by applicable law
- Ensure that persons authorized to process personal data have committed themselves to confidentiality
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
- Not engage another processor without prior written authorization of the Controller
- Assist the Controller in responding to requests from Data Subjects exercising their rights
- Assist the Controller in ensuring compliance with data breach notification obligations
- Delete or return all personal data to the Controller after the end of the provision of services, at the Controller's choice
- Make available to the Controller all information necessary to demonstrate compliance with these obligations
- Not process personal data for any purpose other than providing the Service
- Not use personal data to train AI models or for any secondary purpose
4. Sub-Processors
The Controller provides general authorization for the Processor to engage the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Qdrant Cloud | Vector database for storing and retrieving document embeddings | EU / US (cloud regions) |
| Google Cloud (Gemini) | AI model inference for generating chat responses | United States |
| Groq | AI model inference for fast response generation | United States |
The Processor shall:
- Notify the Controller of any intended changes to sub-processors at least 30 days in advance
- Ensure that sub-processors are bound by data protection obligations no less protective than those in this DPA
- Remain fully liable to the Controller for the performance of sub-processors' obligations
The Controller may object to a new sub-processor by notifying the Processor within 14 days of receiving notice. If the objection cannot be resolved, the Controller may terminate the Service.
5. Data Transfers
Where personal data is transferred to countries outside the Controller's jurisdiction:
- The Processor shall ensure appropriate safeguards are in place (such as Standard Contractual Clauses or equivalent mechanisms)
- Transfers to sub-processors in the United States are covered by appropriate data transfer mechanisms
- The Processor shall inform the Controller of any legally binding request for disclosure of personal data by a law enforcement authority, unless prohibited
- The Processor shall conduct transfer impact assessments where required
6. Security Measures
The Processor implements the following technical and organizational measures:
- Encryption: TLS 1.3 for data in transit; AES-256 for data at rest
- Access control: Role-based access, JWT authentication, and principle of least privilege
- Isolation: Logical tenant isolation ensuring no cross-tenant data access
- Monitoring: Continuous security monitoring and anomaly detection
- Backup: Regular encrypted backups with tested restoration procedures
- Personnel: Background checks and security training for all staff with data access
- Incident response: Documented incident response procedures with defined escalation paths
- Vulnerability management: Regular security assessments and timely patching of vulnerabilities
7. Data Breach Notification
In the event of a Data Breach, the Processor shall:
- Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach
- Provide the following information (to the extent available):
- Nature of the breach, including categories and approximate number of Data Subjects affected
- Name and contact details of the Processor's data protection contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate its effects
- Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach
- Document all breaches, including facts, effects, and remedial actions taken
8. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests, including:
- Right of access: Providing copies of personal data upon request
- Right to rectification: Correcting inaccurate personal data
- Right to erasure: Deleting personal data when requested
- Right to restriction: Restricting processing in certain circumstances
- Right to data portability: Providing data in a structured, machine-readable format
- Right to object: Ceasing processing where the Data Subject objects
The Processor shall promptly notify the Controller if it receives a request directly from a Data Subject, and shall not respond to such requests without the Controller's authorization unless required by law.
9. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA:
- The Processor shall make available all information necessary to demonstrate compliance
- The Controller may conduct audits, including inspections, with reasonable advance notice (minimum 30 days)
- Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations
- The Controller shall bear its own costs for conducting audits
- The Processor may satisfy audit requests by providing relevant third-party certifications, audit reports (e.g., SOC 2), or other documentation
10. Term and Termination
- This DPA shall remain in effect for the duration of the Service agreement between the parties
- This DPA shall automatically terminate upon termination or expiration of the Service agreement
- Obligations relating to data deletion, confidentiality, and liability shall survive termination
- Either party may terminate this DPA if the other party materially breaches its obligations and fails to cure within 30 days of written notice
11. Return and Deletion of Data
Upon termination of the Service or upon the Controller's request:
- The Processor shall, at the Controller's choice, return all personal data in a standard machine-readable format or securely delete all personal data
- Deletion shall be completed within 30 days of termination or request
- The Processor shall certify deletion in writing upon the Controller's request
- The Processor may retain personal data to the extent required by applicable law, in which case it shall inform the Controller and continue to protect such data in accordance with this DPA
- Backup copies shall be deleted in accordance with the Processor's backup rotation schedule (maximum 30 days)
Need a signed DPA?
Contact us at hello@convora.ai to request a countersigned copy of this Data Processing Agreement.