Data Processing Addendum (DPA)

Last updated: July 7, 2026

When This DPA Applies

This DPA applies to all Customers who process personal data through Conversify and are subject to GDPR, UK GDPR, or other applicable data protection laws. It forms part of the Terms of Service.

1. Definitions

  • “Controller”, “Processor”, “Data Subject”, “Personal Data” have the meanings given in the GDPR.
  • “Customer” means the business entity that uses the Service and determines the purposes and means of Processing.
  • “Conversify” means AppBrewers, the provider of the Service.
  • “Subprocessor” means any third party engaged by Conversify to Process Personal Data.
  • “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
  • 2. Roles and Scope of Processing

  • Subject matter: Provision of AI-powered communication automation services
  • Duration: For the term of the Customer’s subscription
  • Nature and purpose: Processing messages, contact information, and conversation data to generate automated responses, route conversations, manage appointments
  • Types of Personal Data: Names, phone numbers, email addresses, message content, conversation metadata
  • Categories of Data Subjects: The Customer’s customers, patients, clients, prospects
  • 3. Conversify’s Obligations as Processor

  • Process Personal Data only on behalf of and per the Customer’s documented instructions
  • Not Process Personal Data for its own purposes
  • Ensure personnel are subject to confidentiality obligations
  • Implement appropriate technical and organisational measures
  • Assist the Customer with Data Subject rights requests
  • Notify Personal Data Breaches within 48 hours
  • Allow for and contribute to audits
  • Delete or return all Personal Data after the end of the Services
  • 4. Customer’s Obligations as Controller

  • Ensure valid legal basis under GDPR for Processing
  • Obtain all necessary consents from Data Subjects
  • Be responsible for accuracy and legality of Personal Data
  • Not provide Special Categories of Personal Data without notifying Conversify
  • Configure the Service for data minimisation, retention, and access controls
  • Inform end users they are interacting with an AI system (EU AI Act)
  • 5. Technical and Organisational Security Measures

  • Encryption in transit: TLS 1.2+
  • Encryption at rest: AES-256
  • Access controls: RBAC with least privilege
  • Authentication: MFA for administrative access
  • Logging: Audit logs with anomaly review
  • Network security: Firewalls, IDS/IPS, vulnerability scanning
  • Data separation: Logical separation between Customers
  • Incident response: Documented plan with escalation
  • Personnel training: Regular data protection training
  • Vendor management: Due diligence for Subprocessors
  • Retention and deletion: Configurable retention and secure deletion
  • Business continuity: Backups and disaster recovery
  • 6. Personal Data Breach Notification

    Conversify shall notify the Customer within 48 hours of becoming aware of a Personal Data Breach, including nature, consequences, and measures taken. Customers may report suspected breaches using the breach notification tool in the GDPR Portal, which creates an audit record and alerts the Conversify compliance team. GDPR Art. 33 requires notifying the supervisory authority within 72 hours.

    7. Data Subject Rights Assistance

    Customers can manage data subject requests using the self-serve tools in the GDPR Portal, including:

  • Submitting and tracking requests for access, rectification, erasure, restriction, objection, and portability with a 30-day SLA
  • Providing Personal Data in a structured, machine-readable format (export)
  • Deleting the Data Subject’s Personal Data upon instruction
  • Restricting or suspending processing upon instruction
  • Viewing the Record of Processing Activities (Art. 30) for the Customer’s account
  • 8. Subprocessors

    General authorisation granted. List maintained at /subprocessors. 30 days’ advance notice for additions. Customer may object and terminate with pro-rata refund.

    9. International Data Transfers

  • Adequacy decisions (Art. 45 GDPR)
  • Standard Contractual Clauses (Art. 46 GDPR)
  • Other appropriate safeguards
  • 10. Deletion and Return of Personal Data

    Delete all Personal Data within 30 days of termination, with export available prior. Written confirmation upon request.

    11. Audit Rights

    Annual audit with 30 days’ notice. SOC 2 / ISO 27001 report may be provided in lieu.

    12. EU AI Act Compliance

  • Customer responsible for classifying its AI deployment
  • Customer must inform end users of AI interaction at first interaction
  • Conversify provides configurable disclosure tools
  • Conversify does not guarantee low-risk classification or compliance
  • 13. Limitation of Liability

    Subject to Terms of Service limitations. Does not limit liability where prohibited by GDPR.

    14. Miscellaneous

  • This DPA forms part of the Terms of Service. Controls in case of conflict for Personal Data.
  • Governed by laws of Malta. Rome I/II for EU customers.
  • Amendments must be in writing.
  • English version controls.
  • 15. Contact

    Data Protection Officer
    AppBrewers
    dpo@conversify.app
    Malta

    A1. Annex I: Subprocessors

  • Cloud infrastructure: Google Cloud / Firebase
  • Messaging platforms: Meta Platforms (WhatsApp, Instagram)
  • AI model providers: OpenAI / Google AI
  • Payment processing: Stripe
  • Email delivery: SendGrid / Brevo
  • Full list at /subprocessors.

    A2. Annex II: Standard Contractual Clauses

    For transfers outside the EEA/UK, Conversify shall enter into the Standard Contractual Clauses (Module Two: Controller to Processor) as adopted by European Commission Implementing Decision (EU) 2021/914. Request a copy at dpo@conversify.app.

    Data Processing Addendum | Conversify