When This DPA Applies
This DPA applies to all Customers who process personal data through Conversify and are subject to GDPR, UK GDPR, or other applicable data protection laws. It forms part of the Terms of Service.
1. Definitions
2. Roles and Scope of Processing
3. Conversify’s Obligations as Processor
4. Customer’s Obligations as Controller
5. Technical and Organisational Security Measures
6. Personal Data Breach Notification
Conversify shall notify the Customer within 48 hours of becoming aware of a Personal Data Breach, including nature, consequences, and measures taken. Customers may report suspected breaches using the breach notification tool in the GDPR Portal, which creates an audit record and alerts the Conversify compliance team. GDPR Art. 33 requires notifying the supervisory authority within 72 hours.
7. Data Subject Rights Assistance
Customers can manage data subject requests using the self-serve tools in the GDPR Portal, including:
8. Subprocessors
General authorisation granted. List maintained at /subprocessors. 30 days’ advance notice for additions. Customer may object and terminate with pro-rata refund.
9. International Data Transfers
10. Deletion and Return of Personal Data
Delete all Personal Data within 30 days of termination, with export available prior. Written confirmation upon request.
11. Audit Rights
Annual audit with 30 days’ notice. SOC 2 / ISO 27001 report may be provided in lieu.
12. EU AI Act Compliance
13. Limitation of Liability
Subject to Terms of Service limitations. Does not limit liability where prohibited by GDPR.
14. Miscellaneous
15. Contact
Data Protection Officer
AppBrewers
dpo@conversify.app
Malta
A1. Annex I: Subprocessors
Full list at /subprocessors.
A2. Annex II: Standard Contractual Clauses
For transfers outside the EEA/UK, Conversify shall enter into the Standard Contractual Clauses (Module Two: Controller to Processor) as adopted by European Commission Implementing Decision (EU) 2021/914. Request a copy at dpo@conversify.app.