Convo

Data Processing Agreement

Last updated August 16, 2026

1. Scope & Relationship to the Terms

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Amrex Systems (“Processor,” “we”) and the Customer (“Controller,” “you”) using Convo. It applies whenever we process personal data on your behalf as part of operating the Convo widget on your website. Where this DPA conflicts with the Terms on data-processing matters, this DPA controls.

2. Definitions

  • “Personal Data” means any information relating to an identified or identifiable natural person, processed by us under this DPA.
  • “Processing” means any operation performed on Personal Data, such as collection, storage, use, or deletion.
  • “Data Subject” means the individual to whom Personal Data relates, typically a Visitor chatting with your widget.
  • “Subprocessor” means a third party we engage to process Personal Data on your behalf, listed in Section 7.
  • “Controller” and “Processor” carry the meanings given under applicable data protection law (e.g. GDPR Art. 4).

3. Roles of the Parties

For Personal Data collected through your Convo widget, including Visitor messages, names, emails, and conversation metadata, you act as Controller and we act as Processor. You determine what the widget is used for and what you tell your visitors; we process the resulting data only to deliver and operate the service, and as documented in this DPA.

4. Subject Matter, Duration & Nature of Processing

Subject matter: Operating the Convo chat widget, including generating AI responses, routing conversations, and providing the Customer dashboard.

Duration: For as long as your account is active, plus any period required after termination to retain data as described in Section 8.

Nature & purpose: Collection, storage, transmission to AI model providers for response generation, and display of conversation data within your dashboard.

Categories of data subjects: Visitors to your website who interact with the widget, and your own team members who use the dashboard.

Categories of data: Chat messages, names and email addresses (where provided), conversation timestamps and status, and technical data such as IP address and browser type.

5. Processor Obligations

  • Process Personal Data only on your documented instructions, as reflected in this DPA and your configuration of Convo, unless required otherwise by law.
  • Ensure personnel with access to Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures, described in Section 6.
  • Assist you, where reasonably possible, in responding to Data Subject requests (access, correction, deletion) relating to your widget’s conversation data.
  • Notify you without undue delay after becoming aware of a Personal Data breach affecting your data.
  • Delete or return Personal Data at the end of the relationship, as described in Section 8.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

6. Security Measures

We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit
  • Access controls restricting Personal Data to personnel who need it to operate the service
  • Authentication requirements for the Customer dashboard
  • Logging and monitoring of production systems handling Personal Data
  • Regular review of Subprocessors’ own security practices

7. Subprocessors

You authorize us to engage the Subprocessors listed below to help deliver Convo. We remain responsible for their handling of Personal Data under the same standard set out in this DPA. If we add or replace a Subprocessor in a way that materially changes how your data is handled, we’ll update this page and, for material changes, notify Customers by email.

SubprocessorPurposeLocation
Google FirebaseAuthentication, real-time database, hostingUnited States / EU (multi-region)
SupabaseDatabase and file storageUnited States / EU (region-dependent)
AI model provider (Google, OpenAI, or Anthropic)Generating chat responses from conversation contentUnited States
Payment processorProcessing the one-time license feeUnited States

If you supply your own AI provider API key, that provider processes conversation data under your own agreement with them rather than as our Subprocessor.

8. International Transfers

Where Personal Data is transferred outside your or your Visitors’ jurisdiction, we rely on appropriate safeguards recognized under applicable law, such as Standard Contractual Clauses, either directly or through the equivalent commitments our Subprocessors provide.

9. Deletion & Return of Data

Upon termination of your account, we will delete or anonymize Personal Data processed on your behalf within a reasonable period, except where retention is required by law or for legitimate billing and security records. You may request export of your conversation data before account closure by contacting us.

10. Audit Rights

On reasonable request, and no more than once per year absent a specific security concern, we will provide information reasonably necessary to demonstrate compliance with this DPA, such as a summary of our security practices. We’ll work with you in good faith on the format and scope of any such review.

11. Liability

Liability arising under this DPA is subject to the limitations of liability set out in the Terms of Service.

12. Changes to This DPA

We may update this DPA as Convo’s processing activities evolve, for example when a Subprocessor changes. We’ll update the “last updated” date above and notify Customers by email for material changes.

13. Contact Us

Questions about this DPA, or requests related to Subprocessors and data transfers? Reach us at legal@useconvo.com.

Also see our Privacy Policy and Terms of Service.