Converight — Immutable Conversation Compliance

Legal and Trust Centre

Everything Converight publishes about how it handles customer data, and where to ask for what it does not publish.

The documents

Document Where Access
Data Processing Addendum /dpa Public
Annex I, Module Two (SCCs) Inside the DPA, at Schedule 4 Public template. Customer-specific execution copy is private
Standard Transfer Assessment /transfer-assessment Public summary. Detailed assessment is controlled
Transfer documents register /transfer-documents Public register. Dated evidence copies are private
Sub-processor list /subprocessors Public
Security measures /security Public
Data subject rights /data-subject-rights Public
Record of processing /record-of-processing Public
Data handling detail /data-handling Public
SOC 2 evidence mapping /docs/soc2-evidence Public
Privacy Policy /privacy Public
Terms of Service /terms Public
Operational evidence register Internal compliance repository Private. Selected evidence under NDA
Customer Adoption Record Generated during onboarding Customer-specific and private

What is deliberately not published, and why

The detailed transfer assessment. It describes root key custody, administrative access, authentication status, control gaps and vendor dependencies. That is an accurate description of where a determined attacker would start, and publishing it would be a worse decision than any gap it records. Available through procurement under NDA.

The operational evidence register. Member identities, account permissions, screenshots, authentication details. Same reason.

Completed Customer Adoption Records. They identify a specific customer and what they told us about their own processing. They belong to that customer, are stored against their account and their audit log, and they get a downloadable copy.

The rule we apply: a document setting out what Converight has committed to is published. A document identifying who holds access, and the evidence behind it, is provided under NDA.

Current position, stated plainly

United States customers whose use does not involve a Restricted Transfer: supported. A US-established customer can still create one — through an EEA or UK establishment, or because its own processing is subject to EU or UK GDPR — and the pre-connection questions are there to find that before a workspace connects rather than after.

EEA and UK customers, and anyone unsure: we accept enquiries, and we do not yet connect workspaces. The transfer assessment records an outcome of pending while counsel completes the Article 3(2) question and the destination-law analysis. Until that outcome is affirmative, the application refuses the connection — this is enforced in the product, not only stated in a policy.

We have not completed a SOC 2 examination. Nothing on this site is an audit, attestation, certification or opinion on readiness.

Who we are

Converight is operated by Thinkdata Labs LLP, LLP registration AAI-9081, #176 First Floor, Sector-10, Panchkula, Haryana 134109, India. Privacy contact: privacy@converight.com.

Asking for something

You want Email
The detailed transfer assessment, under NDA privacy@converight.com
A customer-specific DPA execution copy privacy@converight.com
A security questionnaire completed security@converight.com
Sub-processor change notifications security@converight.com
To report a vulnerability or incident security@converight.com
A data subject request privacy@converight.com