Data Processing Addendum

This Data Processing Addendum ("DPA") governs how Convoup processes personal data on behalf of our customers.

Data Processing Addendum

This Data Processing Addendum ("DPA") governs how Convoup processes personal data on behalf of our customers.

1. Scope

This DPA applies when Convoup processes personal data on behalf of a customer in connection with the Convoup service.

2. Roles

The customer is the data controller. Convoup is the data processor. Where the customer acts as a processor on behalf of its own customers, the customer remains responsible for its own compliance as controller in that relationship.

3. Processing Details

Convoup processes personal data solely to provide the service as described in our Terms of Service, and in accordance with the customer's documented instructions, except where required by law.

4. Subprocessors

Convoup uses subprocessors to deliver the service, including the WhatsApp Business Platform provided by Meta. A current list of subprocessors is available on request. Convoup will provide notice of any intended addition or replacement of a subprocessor, and the customer may object through the procedures set out in the Terms of Service. Convoup imposes data protection obligations on subprocessors that are no less protective than those in this DPA.

5. Data Security

Convoup implements appropriate technical and organizational measures to protect personal data, including: access controls and least-privilege authorization for personnel; encryption of personal data in transit and at rest; logical tenant isolation so that one customer's data is not accessible to another; security logging and monitoring; regular backups and tested restoration procedures; and a documented incident response process. Measures are reviewed and updated as necessary.

6. International Transfers

Personal data may be processed or stored in locations outside the customer's country, including through subprocessors. Where Convoup transfers personal data across borders, it relies on appropriate safeguards such as standard contractual clauses or other lawful transfer mechanisms recognized under applicable data protection law.

7. Breach Notification

Convoup will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, providing information the customer needs to meet its own breach-notification obligations. Convoup will reasonably cooperate with the customer's investigation and remediation.

8. Data Deletion, Return, and Export

On termination or expiry of the service, and subject to applicable law, Convoup will delete or return the customer's personal data at the customer's choice, and will assist the customer with exporting its data in a structured, commonly used format during the term. Convoup may retain copies only as required by law or for its legitimate record-keeping, in which case it will continue to protect the data.

9. AI Processing

Convoup does not use customer content to train general-purpose AI models. Where AI-assisted features process customer content, they do so only to provide the requested functionality, subject to the customer's instructions and the privacy terms governing the service.

For questions about this DPA, contact For questions about this DPA, contact [email protected]..

Chat with Sales