Legal and Trust Centre
Everything Converight publishes about how it handles customer data, and where to ask for what it does not publish.
The documents
| Document | Where | Access |
|---|---|---|
| Data Processing Addendum | /dpa | Public |
| Annex I, Module Two (SCCs) | Inside the DPA, at Schedule 4 | Public template. Customer-specific execution copy is private |
| Standard Transfer Assessment | /transfer-assessment | Public summary. Detailed assessment is controlled |
| Transfer documents register | /transfer-documents | Public register. Dated evidence copies are private |
| Sub-processor list | /subprocessors | Public |
| Security measures | /security | Public |
| Data subject rights | /data-subject-rights | Public |
| Record of processing | /record-of-processing | Public |
| Data handling detail | /data-handling | Public |
| SOC 2 evidence mapping | /docs/soc2-evidence | Public |
| Privacy Policy | /privacy | Public |
| Terms of Service | /terms | Public |
| Operational evidence register | Internal compliance repository | Private. Selected evidence under NDA |
| Customer Adoption Record | Generated during onboarding | Customer-specific and private |
What is deliberately not published, and why
The detailed transfer assessment. It describes root key custody, administrative access, authentication status, control gaps and vendor dependencies. That is an accurate description of where a determined attacker would start, and publishing it would be a worse decision than any gap it records. Available through procurement under NDA.
The operational evidence register. Member identities, account permissions, screenshots, authentication details. Same reason.
Completed Customer Adoption Records. They identify a specific customer and what they told us about their own processing. They belong to that customer, are stored against their account and their audit log, and they get a downloadable copy.
The rule we apply: a document setting out what Converight has committed to is published. A document identifying who holds access, and the evidence behind it, is provided under NDA.
Current position, stated plainly
United States customers whose use does not involve a Restricted Transfer: supported. A US-established customer can still create one — through an EEA or UK establishment, or because its own processing is subject to EU or UK GDPR — and the pre-connection questions are there to find that before a workspace connects rather than after.
EEA and UK customers, and anyone unsure: we accept enquiries, and we do not yet connect workspaces. The transfer assessment records an outcome of pending while counsel completes the Article 3(2) question and the destination-law analysis. Until that outcome is affirmative, the application refuses the connection — this is enforced in the product, not only stated in a policy.
We have not completed a SOC 2 examination. Nothing on this site is an audit, attestation, certification or opinion on readiness.
Who we are
Converight is operated by Thinkdata Labs LLP, LLP registration AAI-9081,
#176 First Floor, Sector-10, Panchkula, Haryana 134109, India.
Privacy contact: privacy@converight.com.
Asking for something
| You want | |
|---|---|
| The detailed transfer assessment, under NDA | privacy@converight.com |
| A customer-specific DPA execution copy | privacy@converight.com |
| A security questionnaire completed | security@converight.com |
| Sub-processor change notifications | security@converight.com |
| To report a vulnerability or incident | security@converight.com |
| A data subject request | privacy@converight.com |
