GDPR Compliance

How Conversify handles personal data under the EU General Data Protection Regulation.

The short version

We are Conversify, a product of AppBrewers, established inside the European Union. Your customers’ messages and contact details are personal data. Under GDPR, you are the controller of that data and we are the processor. That relationship is written into a Data Processing Addendum that forms part of our Terms of Service. And the tools GDPR expects a processor to support - export, deletion, retention limits, records, breach procedure - are built into the product, not buried in support tickets.

Who we are, and who you are

Conversify (AppBrewers) is established in the European Union. We built an AI front desk that answers, books and sells over WhatsApp, Instagram, Messenger, email and web chat for small service businesses. That work involves processing messages on behalf of those businesses, which makes us a processor under GDPR Article 28.

You, the business using Conversify, decide why the messages are processed and whom to reply to. That makes you the controller of your customers’ personal data. This division of roles matters because it sets what each side owes the other, and it is spelled out in the DPA:

  • We process personal data only on your documented instructions, and never for our own purposes.
  • We apply confidentiality obligations to our personnel and security measures to the infrastructure.
  • We assist you in responding to data subject requests and in meeting your other GDPR duties.
  • We notify you without undue delay if a personal data breach affects the data we process for you.

Read the full Data Processing Addendum for the article-by-article detail. It applies automatically to every customer, and it covers GDPR as well as UK GDPR.

GDPR tools built into the product

Compliance obligations written in a PDF are worth little if the tooling does not exist to carry them out. The GDPR portal inside every Conversify account puts the day-to-day obligations within reach:

Data subject request handling

When a customer of yours asks what data you hold, or asks for it to be deleted, you log the request in the GDPR portal. It tracks the 30-day response deadline so nothing slips, and keeps a record of what was done. EU law expects each request handled and logged. This is where that happens.

Data export

Export the data associated with your account on demand. Useful for requests, for audits, and for backing up your own records.

Data deletion

Delete your account data yourself, from the same portal. No ticket, no waiting on us to action it.

Configurable retention

You choose how long conversations are kept. After that, they are deleted automatically. If a conversation matters for a booking that happened six months ago, set the retention to match. If your customers expect short retention, set it short. The default is not forever.

Records of processing (Art. 30 ROPA)

The portal maintains a record of what categories of data are processed, on what lawful basis, and for how long. That is the Art. 30 record you would otherwise build by hand.

Breach notification workflow

If a personal data breach ever occurs, the workflow points at the 72-hour supervisory authority notification and the notification of affected data subjects, so the steps are ready before you need them.

The portal is included with every plan. No add-on, no upgrade, no separate purchase.

Where data lives, and who helps us process it

Conversify runs on Google Cloud (Firebase) for hosting, database, authentication, and file storage. A small number of subprocessors carry out specific parts of the service: message delivery networks, AI language model providers, payment processing, and transactional email. Every one of them is listed on our subprocessors page, along with what they do and their processing locations.

When we add or replace a subprocessor, we give at least 30 days’ notice by email, so you can object or terminate the service before the change takes effect.

One specific case deserves a straight answer, because it is on more buyers’ checklists every month: AI inference. Message content is processed by an AI language model (Google Gemini) to generate the replies your customers receive. Our privacy policy documents exactly what is shared with Google: message content for response generation, and nothing beyond it. Calendar data, for example, is never sent to the AI service at all, and no data obtained through Google APIs is used to train general models.

AI transparency

GDPR runs on transparency, so the AI in Conversify does not pretend to be human. In every conversation it discloses that it is AI, once per contact, woven naturally into the conversation. Voice replies carry an audible disclosure, and AI-generated email carries a visible notice plus a machine-readable header.

This also lines the product up with the EU AI Act’s transparency obligations, which we describe separately on our AI Act compliance page.

Your rights, and your customers’ rights

Individuals whose data we process have the usual GDPR rights: access, rectification, erasure, restriction, portability, and objection. How those rights reach us depends on who is asking:

  • Requests about data Conversify holds as a controller (for example, your own account data or billing information): email us at support@conversify.app. We respond within 30 days.
  • Requests about data we hold as a processor for you (your customers’ messages and contact details): those requests belong to you as controller. Log the request in the GDPR portal, use the export and deletion tools to action it, and the portal records that it was handled.

Our full data practices, including what we collect as a controller and the legal bases we rely on, are in the privacy policy.

Questions

Data protection questions, DPAs for your own legal review, subprocessor notifications, anything else: support@conversify.app.

Last updated: August 30, 2026.

    GDPR Compliance for AI Customer Messaging | Conversify