Converight — Immutable Conversation Compliance

Transfer documents register

Register date: 12 September 2026 · Owner: Thinkdata Labs LLP Companion to the Standard Transfer Assessment and the DPA.

One row per leg: the parties, the mechanism relied on, the document that establishes it, and the status.

Dated evidence copies are held privately — invoices, executed agreements, certification records and configuration evidence. They are provided under NDA through procurement. This page is the index, not the evidence.

Leg Parties Mechanism Document Verified Status
Customer to Thinkdata Customer → Thinkdata Labs LLP Module Two if legally available; other Article 46 mechanism if required DPA, SCCs, completed assessment, Customer Adoption Record — Pending counsel
Thinkdata to AWS India Thinkdata Labs LLP → Amazon Web Services India Private Limited AWS DPA Invoice, AWS DPA, Customer Agreement, Service Terms 12 Sep 2026 Mechanism verified; dated evidence archive pending
AWS onward infrastructure AWS India / AWS → Amazon Data Services, Inc. AWS Subprocessor terms and processor-to-processor SCCs AWS DPA and AWS Subprocessor list 12 Sep 2026 Mechanism verified; dated evidence archive pending
Thinkdata to Render Thinkdata Labs LLP → Render Services, Inc. DPF where applicable; Module Three SCCs as fallback Render invoice, Terms, DPA, UK Addendum and DPF record 14 Sep 2026 Mechanism verified; dated copies of Terms, DPA and sub-processor list held; DPF record pending
Amazon SES Thinkdata Labs LLP → AWS India; US infrastructure AWS DPA and processor-to-processor SCCs Same AWS package; service configuration 12 Sep 2026 Mechanism verified; dated evidence archive pending
Sentry No current transfer Not enabled Configuration showing disabled status 12 Sep 2026 Closed while disabled

Notes on three rows

The module differs by leg, and both are correct. Module Two governs customer-to-Converight, where the customer is controller and Converight processor. Module Three governs Converight-to-Render, where Converight is the processor and Render its sub-processor. A reader comparing the two documents is looking at two transfers, not a contradiction.

Render's mechanism, in the form of words to use:

Render Services, Inc. processes Customer Personal Data in the United States. Render relies on the EU-US Data Privacy Framework where applicable. Its DPA incorporates the EU SCCs, including Module 3 for processor-to-Subprocessor transfers, as a fallback. It also incorporates the UK Addendum for UK Restricted Transfers.

The SCCs are the operative fallback. This register does not rest on the DPF alone: a framework can be annulled, and a position resting on one alone fails with it.

AWS:

Thinkdata Labs LLP contracts with Amazon Web Services India Private Limited. Archive data is stored in AWS us-east-1, operated by Amazon Data Services, Inc. The AWS Data Processing Addendum is incorporated into the AWS Service Terms an India-address account is governed by, and applies to that account.

The India-to-India contract is not itself a Chapter V transfer. Customer Personal Data nonetheless remains governed by the original protections after it reaches Thinkdata, which is why the onward leg to Amazon Data Services, Inc. is recorded as a row of its own rather than folded into the AWS row above it.

Two findings that are not transfer terms

No fixed upstream breach-notification deadline. Render promises notice "without undue delay" with no outer limit, while Converight owes Intercom notice within 72 hours of becoming aware of a breach involving Intercom data. Converight therefore cannot depend on a specified upstream notice period when meeting that obligation, and detection and monitoring stand independently of Render telling us.

A Render service or database cannot change region. Moving requires a new instance and a data migration. This does not affect the current transfer; it is recorded because it prices any future EU-hosting option, and that is easier to accept now than mid-negotiation.