Data Processing Addendum
Last updated: 12 September 2026
This Data Processing Addendum (“DPA”) forms part of the Converight Terms of Service or another agreement governing the Services (“Agreement”).
This DPA becomes effective when Customer accepts or executes the Agreement.
This DPA is between:
- the customer identified in the Agreement (“Customer”); and
- Thinkdata Labs LLP, trading as Converight, LLP registration number AAI-9081 (“Converight”).
1. Definitions
Applicable Data Protection Law means any law governing Personal Data processed under the Agreement. It includes EU, UK and applicable US state privacy laws.
Customer Personal Data means Personal Data processed by Converight on Customer’s behalf through the Services.
Customer Personal Data excludes Personal Data that Converight processes as an independent Controller. This includes account, billing, security and business-contact information.
EU GDPR means Regulation (EU) 2016/679.
Personal Data, Controller, Processor, Processing and Data Subject have the meanings given by Applicable Data Protection Law.
Restricted Transfer means a transfer requiring an adequacy decision, appropriate safeguard or other transfer mechanism under Applicable Data Protection Law.
Security Incident means a breach of security affecting Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data.
Services means Converight’s read-only Intercom backup, archive, search, retrieval, export, Legal Hold and audit services.
Subprocessor means a third party engaged by Converight or its Subprocessors to process Customer Personal Data.
2. Roles and scope
2.1 Customer acts as Controller. Converight acts as Processor for Customer Personal Data.
2.2 Customer determines the purposes of Processing, connected workspaces, retention periods, Legal Holds and responses to Data Subject requests.
2.3 Converight acts as an independent Controller for account, billing, security and business-contact information processed for its own purposes.
2.4 Intercom is Customer’s separately engaged service provider. Intercom is not a Subprocessor appointed by Converight.
3. Customer instructions
3.1 Converight shall Process Customer Personal Data only on Customer’s documented instructions.
3.2 The Agreement, this DPA and Customer’s use of the Services constitute documented instructions.
3.3 Instructions include:
a. obtaining records through Customer’s read-only Intercom authorisation;
b. encrypting, indexing, storing and synchronising those records;
c. searching, viewing, exporting and placing records under Legal Hold;
d. processing restriction, retention, erasure and disconnection instructions; and
e. engaging authorised Subprocessors.
3.4 Converight shall inform Customer if an instruction infringes Applicable Data Protection Law.
3.5 Converight shall inform Customer if it cannot follow an instruction.
4. Customer responsibilities
Customer shall:
a. have a lawful basis for the Processing;
b. provide required notices to Data Subjects;
c. ensure its instructions comply with Applicable Data Protection Law;
d. select and document appropriate retention periods;
e. determine whether a Legal Hold, restriction or erasure obligation applies;
f. avoid submitting data that the Services are unsuitable to process;
g. maintain the security of its accounts and authorised users; and
h. notify Converight before initiating a Restricted Transfer.
5. Confidentiality and access
5.1 Converight shall restrict access to personnel who require it to provide, secure or support the Services.
5.2 Authorised personnel shall be bound by confidentiality obligations.
5.3 Converight personnel may have administrative access to the application, database, keys and infrastructure.
5.4 Converight shall log human views, searches, exports and downloads of archived records.
6. Security
6.1 Converight shall maintain technical and organisational measures proportionate to the risks of Processing.
6.2 Schedule 2 describes those measures.
6.3 Converight may modify the measures if the modification does not materially reduce overall security.
6.4 Limited search-index information is processed without application-level encryption.
6.5 That information includes names, emails, conversation titles and tags. Render provides infrastructure-level encryption for PostgreSQL.
6.6 The archive uses per-record AES-256-GCM encryption and a wrapped key hierarchy.
6.7 The ROOT_KEK is stored in a Render environment group. It is not held in AWS KMS or an independent HSM.
7. Subprocessors
7.1 Customer grants Converight general written authorisation to engage the Subprocessors listed in Schedule 3.
7.2 Converight shall provide at least 30 days’ notice before adding or replacing a Subprocessor that processes Customer Personal Data.
7.3 Customer may object during that period on reasonable data-protection grounds.
7.4 The parties shall work in good faith to address the objection.
7.5 If no reasonable solution exists, Customer may terminate the affected Services before the change takes effect.
7.6 Converight shall impose materially equivalent data-protection obligations on each direct Subprocessor.
7.7 Each direct Subprocessor shall impose equivalent obligations on any authorised onward Subprocessor.
7.8 Converight remains responsible to Customer for each direct Subprocessor’s performance.
8. Data Subject requests
8.1 Converight shall promptly forward requests relating to Customer Personal Data to Customer.
8.2 Converight shall not respond unless Customer instructs it or applicable law requires a response.
8.3 Converight shall reasonably assist Customer with access, portability, erasure, rectification, restriction and objection requests.
8.4 Access and portability are supported through searchable records and JSON, CSV or PDF exports.
8.5 Rectification occurs by correcting the source record in Intercom. Converight archives the corrected state as a new version.
8.6 Erasure occurs through destruction of the record key and nulling of searchable identifiers.
8.7 Erasure within Converight does not erase data held in Intercom, Customer systems or other integrations.
8.8 Upon Customer’s instruction, Converight shall restrict the selected contact or record.
While active, the restriction blocks search, viewing, export and ordinary access. The encrypted record remains stored.
8.9 Converight shall record the restriction ground, target, actor, timestamps and reason for placing or lifting the restriction.
9. Legal Holds
9.1 Converight shall place or release Legal Holds only on Customer’s documented instruction.
9.2 A Legal Hold may prevent scheduled erasure or cryptographic shredding.
9.3 If an erasure instruction affects a held record, Converight shall report the conflict to Customer.
9.4 Customer shall determine whether the hold or erasure obligation prevails.
9.5 Converight shall not independently determine whether an Article 17 exception applies.
10. Security Incidents
10.1 Converight shall notify Customer without undue delay after becoming aware of a Security Incident.
10.2 Converight shall notify Intercom of any known or suspected security breach involving Intercom data within 72 hours after becoming aware of it.
10.3 The Customer notice shall describe, where available:
a. the nature of the Security Incident;
b. affected Data Subjects and records;
c. likely consequences;
d. remediation and mitigation measures; and
e. an appropriate contact point.
10.4 Converight may provide information in phases as it becomes available.
10.5 Converight shall reasonably assist Customer with required notifications.
10.6 Converight shall document Security Incidents and corrective actions.
11. Compliance assistance
Converight shall reasonably assist Customer with:
a. data-protection impact assessments;
b. transfer assessments;
c. consultations with supervisory authorities;
d. security-risk assessments;
e. records of Processing; and
f. responses to regulatory inquiries.
12. Audit and information rights
12.1 Converight shall provide information reasonably necessary to demonstrate compliance.
12.2 Customer may conduct one audit each year upon reasonable written notice.
12.3 Additional audits may occur following a Security Incident or credible evidence of material non-compliance.
12.4 Customer shall first use available policies, reports and questionnaires where these reasonably satisfy its requirements.
12.5 Audits shall avoid unreasonable disruption and protect other customers’ information.
12.6 Customer bears its audit costs. Converight bears its ordinary costs of providing existing materials.
12.7 Intercom may audit Converight’s Processing as required by the applicable Intercom developer terms.
13. Retention, return and erasure
13.1 Customer selects the archive retention period, subject to a 365-day technical minimum.
13.2 Retention changes apply prospectively. Existing objects retain their original retain-until dates.
13.3 Active Legal Holds preserve affected records until Customer releases the hold.
13.4 Upon disconnection:
a. new backups stop;
b. the stored Intercom access token is destroyed;
c. Customer may export its archive during the post-disconnection period;
d. eligible records are cryptographically shredded after that period and operational acknowledgement; and
e. shredding occurs only if no unresolved critical alert remains open for the workspace.
13.5 Token revocation or authentication failure alone does not constitute a deletion instruction.
13.6 Cryptographic shredding destroys the key required to decrypt the record.
13.7 The encrypted object may remain until its Object Lock period expires.
13.8 Converight shall null associated plaintext search fields during erasure.
13.9 Converight maintains a separate erasure ledger so erasures can be reapplied after database restoration.
13.10 At Customer’s request, Converight shall certify the return or erasure actually completed.
The certificate shall identify records delayed by a Legal Hold, critical alert or other documented blocker.
14. International transfers
14.1 Customer authorises Processing in India and the United States, as described in the Schedules.
14.2 Where the EU GDPR applies, a Restricted Transfer may begin only after the required transfer mechanism and assessment are in place.
14.3 Where Converight’s relevant Processing is not directly subject to the EU GDPR under Article 3, Module Two applies to Customer-to-Converight transfers.
14.4 If Article 3 directly applies to Converight’s relevant Processing, Module Two shall not apply unless legally available.
14.5 Converight shall not begin the Restricted Transfer until another available Article 46 mechanism is identified.
14.6 For transfers to Render, Render’s Data Privacy Framework participation applies where legally available.
14.7 Render’s DPA and Module Three SCCs apply as a contractual fallback.
14.8 The AWS DPA and processor-to-processor SCCs apply to transfers through AWS.
14.9 The parties shall complete and document any assessment required by the applicable transfer instrument.
14.10 For UK Restricted Transfers, the following terms are incorporated:
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses.
14.11 Tables 1 to 3 of the UK Addendum are completed through the Agreement and Schedules.
14.12 For Table 4, neither party may terminate solely because the ICO issues a revised Approved Addendum.
14.13 The applicable transfer instrument prevails over conflicting terms.
15. US state privacy laws
15.1 Schedule 5 applies where Customer Personal Data is subject to an applicable US state privacy law.
15.2 Under Schedule 5, Converight acts as Customer’s Processor, Service Provider or Contractor, as applicable.
15.3 Schedule 5 prevails over conflicting provisions concerning Customer Personal Data subject to US state privacy law.
16. Liability and indemnity
Liability under this DPA is subject to the Agreement’s limitations.
Indemnity and liability are governed by the Terms. This DPA creates no separate indemnity.
This does not restrict rights that cannot lawfully be limited, including any liability and redress owed to a Data Subject under the EU Standard Contractual Clauses or the UK Addendum, which remain unaffected.
17. Term and precedence
17.1 This DPA continues while Converight processes Customer Personal Data.
17.2 This DPA prevails over the Agreement regarding Customer Personal Data.
17.3 An applicable transfer instrument prevails regarding a Restricted Transfer.
17.4 Schedule 5 prevails for Processing subject to applicable US state privacy law.
17.5 The Agreement’s governing law otherwise applies.
Schedule 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Read-only backup, archive, search, retrieval, export, Legal Hold, audit and erasure services |
| Duration | Agreement term, configured retention, post-disconnection period and applicable Legal Holds |
| Data Subjects | Customer personnel, administrators, customers, prospects, contacts and conversation participants |
| Personal Data | Names, emails, identifiers, conversations, messages, titles, tags, companies, articles, timestamps and audit information |
| Sensitive data | Not intentionally requested or filtered; may appear incidentally in free-text content |
| Processing | Collection, copying, encryption, storage, indexing, search, retrieval, export, versioning, restriction and erasure |
| Frequency | Initial full backup, then daily synchronisation: conversations and contacts fetched incrementally by update time; other record types re-listed and stored only when changed |
| Archive | AWS S3, us-east-1, Northern Virginia |
| Search index | Render PostgreSQL, Virginia |
| Export retention | Seven days |
| Database recovery | Seven-day point-in-time recovery and 90-day logical backups |
| Audit log | Append-only; actor email addresses retained indefinitely |
| Disconnection | Eligible records are shredded after 30 days, acknowledgement and resolution of critical alerts |
Schedule 2 — Technical and organisational measures
- Per-record AES-256-GCM encryption.
- Wrapped record, workspace and root-key hierarchy.
- ROOT_KEK stored in a Render environment group.
- ROOT_KEK excluded from PostgreSQL and database backups.
- Additional authenticated data binding ciphertext to record identity.
- SHA-256 integrity verification.
- S3 Object Lock in governance mode by default.
- Compliance mode where configured.
- Provider-level PostgreSQL encryption.
- Application-level OAuth token encryption.
- Logical separation between customer workspaces.
- Owner and Viewer access roles.
- Passwordless, time-limited authentication.
- Append-only, hash-chained audit logging.
- Human viewing, search, export and download logging.
- Automated daily backups and failure alerts.
- Cryptographic shredding and index nulling.
- External erasure ledger.
- Read-only OAuth permissions.
- No machine-learning training using archived content.
- Record-level restriction across retrieval, search and export.
- Operational acknowledgement and critical-alert checks before shredding.
Schedule 3 — Authorised sub-processors
| Legal entity | Service and purpose | Processing location |
|---|---|---|
| Amazon Web Services India Private Limited | Contracting Subprocessor for AWS S3 archive, exports, backups and Amazon SES transactional email | India as contracting location; selected services operate in us-east-1 |
| Amazon Data Services, Inc. | AWS onward infrastructure Subprocessor supporting us-east-1 |
Northern Virginia, United States |
| Render Services, Inc. | Application hosting, PostgreSQL, Key Value and environment secrets | Virginia, United States |
| Render Services, Inc. onward Subprocessors | Infrastructure supporting Render services, as identified in Render’s current Subprocessor list | United States |
Sentry is disabled and is not authorised unless enabled after notice under Section 7.
Intercom is Customer’s separate processor. Cloudflare presently provides DNS without proxying Customer Personal Data.
Schedule 4 — EU SCC information
Selected modules
- Module Two applies conditionally to Customer-to-Converight transfers.
- Module Three applies to Converight-to-Render transfers.
- Processor-to-processor SCCs apply under the AWS DPA.
- Clause 7 docking applies to the Customer-to-Converight transfer.
- Clause 9 Option 2 applies.
- Subprocessor notice period: 30 days.
- Clause 11 optional language does not apply.
- Irish law and courts apply where no other permitted EEA selection is made.
Annex I.A: Parties
Data exporter: Customer identified in the Agreement. Role: Controller.
Data importer: Thinkdata Labs LLP, trading as Converight. Address: #176, First Floor, Sector-10, Panchkula, Haryana 134109, India. Contact: privacy@converight.com. Role: Processor.
Annex I.B: Transfer
Schedule 1 completes Annex I.B.
The transfer includes names, emails, titles and tags processed in application-level plaintext through Render in Virginia.
Archive content is protected by per-record AES-256-GCM encryption and a wrapped key hierarchy.
Annex I.C: Supervisory authority
The competent supervisory authority is identified by Customer under Clause 13.
Annex II
Schedule 2 completes Annex II.
Annex III
Schedule 3 completes Annex III.
This is the public template. A customer-specific execution copy — carrying the customer’s legal name and address, privacy contact, competent supervisory authority, acceptance date and applicable transfer details — is generated when the customer accepts this DPA. It is stored against the customer’s account with a snapshot of the exact text accepted, can be downloaded by the account owner from Settings → Legal, and is not published.
Schedule 5 — US State Privacy Schedule
1. Scope and definitions
1.1 This Schedule applies when Converight processes Customer Personal Data subject to US State Privacy Law.
1.2 “US State Privacy Law” means any applicable US state law governing consumer Personal Data. It includes the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and comparable comprehensive state privacy laws.
1.3 “Business Purpose” means the purposes described in Section 3.
1.4 “Consumer,” “Controller,” “Contractor,” “Personal Information,” “Processor,” “Sale,” “Service Provider,” “Share” and “Targeted Advertising” have the meanings given by applicable US State Privacy Law.
1.5 Personal Data includes Personal Information where California law applies.
1.6 Other capitalised terms have the meanings given in the DPA.
2. Roles
2.1 Customer acts as:
a. the Controller under applicable US State Privacy Law; and
b. the Business where the California Consumer Privacy Act applies.
2.2 Converight acts as:
a. the Processor for Customer Personal Data; and
b. Customer’s Service Provider or Contractor under California law.
2.3 Each party shall comply with the obligations applicable to its role.
2.4 Nothing in this Schedule changes either party’s role under applicable law.
3. Specific Business Purposes
Customer makes Customer Personal Data available to Converight only for:
a. connecting to Customer’s Intercom workspace through read-only OAuth;
b. performing initial and incremental backups;
c. encrypting and storing archived records;
d. preserving records under retention and Legal Hold requirements;
e. maintaining a limited search index;
f. enabling authorised search, viewing and export;
g. supporting Consumer requests;
h. performing cryptographic erasure and identifier nulling;
i. maintaining audit logs and evidentiary integrity;
j. detecting and responding to Security Incidents;
k. maintaining service availability, recovery and integrity; and
l. other Processing documented in the Agreement and initiated by Customer.
Converight shall not materially expand these purposes without Customer’s instructions.
4. Processing instructions
4.1 Converight shall process Customer Personal Data only:
a. for the Business Purposes;
b. on Customer’s documented instructions;
c. as necessary to provide the Services; or
d. as otherwise permitted or required by law.
4.2 Customer’s use and configuration of the Services constitute documented instructions.
4.3 Converight shall notify Customer if it determines that an instruction violates applicable US State Privacy Law.
5. Prohibited Processing
Converight shall not:
a. Sell Customer Personal Data;
b. Share Customer Personal Data for cross-context behavioural advertising;
c. process Customer Personal Data for Targeted Advertising;
d. use or disclose Customer Personal Data outside the Business Purposes;
e. use Customer Personal Data for another commercial purpose;
f. use Customer Personal Data outside its direct relationship with Customer;
g. combine Customer Personal Data with Personal Data obtained from another customer;
h. combine it with Personal Data from Converight’s independent Consumer interactions;
i. use archived content for product analytics or development;
j. use archived content to train machine-learning or artificial-intelligence models;
k. create profiles or inferences concerning Consumers;
l. attempt to reidentify deidentified information; or
m. voluntarily disclose Customer Personal Data except as authorised by Customer.
These restrictions do not prohibit Processing expressly permitted under applicable law.
6. California certification
6.1 Converight certifies that it understands the restrictions imposed by the California Consumer Privacy Act and its regulations.
6.2 Converight certifies that it shall comply with those restrictions.
6.3 Converight shall provide the same level of privacy protection required from a Business.
6.4 Converight shall notify Customer if it can no longer meet these obligations.
6.5 Customer may take reasonable steps to stop and remediate unauthorised Processing.
7. Confidentiality and security
7.1 Each person processing Customer Personal Data shall be subject to confidentiality obligations.
7.2 Converight shall maintain reasonable administrative, technical and organisational safeguards.
7.3 The safeguards include, as applicable:
a. per-record AES-256-GCM encryption;
b. provider-level database encryption;
c. application-level OAuth token encryption;
d. read-only OAuth permissions;
e. workspace separation;
f. access controls;
g. immutable retention;
h. hash-chained audit logging;
i. incident monitoring;
j. Processing restrictions; and
k. cryptographic erasure and identifier nulling.
7.4 Customer remains responsible for its users, instructions, retention choices and account security.
8. Consumer requests
8.1 Converight shall reasonably assist Customer with verified Consumer requests.
8.2 Assistance may include:
a. searching for responsive records;
b. providing access and export functionality;
c. correction through versioning;
d. restricting search, viewing and export;
e. processing cryptographic erasure; and
f. supplying response information.
8.3 Converight shall forward direct requests to Customer.
8.4 Converight shall not substantively respond unless instructed or required by law.
8.5 Converight does not Sell or Share Customer Personal Data.
9. Deletion and return
9.1 Converight shall return or delete Customer Personal Data as described in the DPA.
9.2 Where Object Lock prevents physical deletion, Converight shall:
a. destroy the key required to decrypt the record;
b. null associated searchable identifiers;
c. remove applicable contact-record associations; and
d. prevent further use or disclosure.
9.3 Converight treats completed cryptographic shredding as deletion for service purposes. Residual ciphertext remains subject to Object Lock, retention and lifecycle controls.
9.4 Deletion does not affect data retained:
a. under Customer’s Legal Hold;
b. as required by applicable law; or
c. while a critical alert prevents safe completion.
9.5 An erasure certificate shall identify any such exception.
9.6 Erasure does not delete information held by Intercom or Customer’s other providers.
10. Subprocessors
10.1 Customer authorises the Subprocessors listed in Schedule 3.
10.2 Converight shall maintain written agreements with its direct Subprocessors.
10.3 Those agreements shall impose materially equivalent privacy and security obligations.
10.4 Where California law applies, Subprocessor terms shall include applicable Service Provider or Contractor restrictions.
10.5 Direct Subprocessors shall impose equivalent obligations on onward Subprocessors.
10.6 Converight shall provide at least 30 days’ notice before adding or replacing a Subprocessor.
10.7 Customer may object during that period on reasonable data-protection grounds.
10.8 Converight remains responsible for its direct Subprocessors.
11. Security Incidents
11.1 Converight shall notify Customer without undue delay after becoming aware of a Security Incident.
11.2 Converight shall provide information reasonably needed for Customer’s investigation and notifications.
11.3 Information may be provided in phases.
11.4 Converight shall take reasonable steps to contain, investigate and remediate the Security Incident.
12. Assessments and audits
12.1 Converight shall provide information reasonably necessary to demonstrate compliance.
12.2 Customer may take reasonable steps to verify consistent Processing.
12.3 Customer shall first use available documentation, policies, questionnaires and independent reports.
12.4 Customer may conduct one assessment or audit during each 12-month period.
12.5 Additional audits may occur following:
a. a material Security Incident;
b. a regulator’s binding requirement; or
c. credible evidence of material non-compliance.
12.6 Audits require reasonable advance notice and shall:
a. occur during normal business hours;
b. avoid unreasonable disruption;
c. protect other customers’ information;
d. exclude source code and unrelated systems;
e. be conducted by qualified personnel; and
f. be subject to confidentiality obligations.
12.7 Converight may satisfy an audit through a qualified independent assessor’s report.
12.8 Customer bears its audit costs unless material non-compliance is identified.
13. Data protection assessments
Converight shall provide information reasonably necessary for Customer’s assessments under US State Privacy Law. Assistance is limited to information available to Converight about the Services.
14. Compliance issues
14.1 Converight shall notify Customer if it can no longer comply with this Schedule.
14.2 Customer may instruct Converight to:
a. stop affected Processing;
b. suspend access;
c. return or delete affected data; or
d. take reasonable remedial steps.
14.3 Converight may suspend affected Processing while the parties address the issue.
14.4 Either party may terminate the affected Services if compliance cannot reasonably be restored.
15. Government requests
15.1 Converight shall not voluntarily disclose Customer Personal Data to a public authority.
15.2 Where legally permitted, Converight shall:
a. notify Customer;
b. refer the authority to Customer;
c. review the request’s validity;
d. challenge an unlawful or disproportionate request; and
e. disclose only the minimum legally required information.
15.3 Converight shall document requests and responses unless prohibited by law.
16. Deidentified information
Where Converight processes deidentified information, it shall:
a. maintain the information in deidentified form;
b. implement reasonable measures against reidentification;
c. make any public commitment required by law; and
d. not attempt to reidentify the information.
Converight shall not use deidentified Customer Personal Data for an independent purpose without Customer’s authorisation.
17. Processing details
Schedule 1 describes:
- Processing instructions;
- nature and purpose;
- Personal Data types;
- Data Subject categories;
- Processing duration;
- retention periods; and
- the parties’ rights and obligations.
18. Order of precedence
18.1 This Schedule prevails over conflicting provisions concerning Personal Data subject to US State Privacy Law.
18.2 The remainder of the DPA continues to apply.
18.3 Nothing in this Schedule waives a Consumer right or limits an obligation that cannot lawfully be limited.
