Privacy Policy

Last updated: July 7, 2026

1. Introduction

Conversify (“we”, “our”, “us”), operated by AppBrewers, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our AI-powered communication platform (the “Service”). This policy applies to both business customers (“Customers”) and individuals who interact with the Service as end users (“End Users”).

We act as a data processor for Customer data and as a data controller for our own business data. Customers act as data controllers for the personal data they process through the Service and are responsible for ensuring they have a lawful basis for all processing activities.

2. Information We Collect

We may collect the following categories of information:

  • Customer Account Data: Business name, contact name, email address, phone number, WhatsApp Business number, billing information
  • Configuration Data: Prompts, templates, FAQs, knowledge sources, workflow rules, escalation contacts, and integration settings you provide
  • Conversation Data: Messages, responses, and metadata processed through the Service on behalf of Customers, including end user messages sent via WhatsApp, Instagram, email, and other channels
  • Usage Data: Information about how you use the Service, including logs, analytics, IP addresses, and device information
  • End User Data: Names, phone numbers, email addresses, and message content of individuals who interact with the Service through Customer-configured channels
  • Data minimisation: Customers are responsible for minimising the personal data they input into the Service and for not inputting special category data (e.g., health data, biometric data, racial or ethnic origin) unless they have a valid lawful basis and have configured the Service appropriately.

    3. How We Use Your Information

    We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process conversations and generate automated responses on behalf of Customers
  • Route and escalate conversations according to Customer configurations
  • Improve, personalise, and troubleshoot the Service
  • Communicate with Customers about their account, billing, and support
  • Comply with legal obligations and protect against misuse
  • We do not sell personal data. We process Conversation Data solely as instructed by the Customer under the terms of our Data Processing Addendum (DPA), where applicable.

    4. Lawful Bases for Processing (GDPR)

    For individuals in the European Economic Area, we process personal data under the following lawful bases:

  • Performance of a contract (Art. 6(1)(b)): To deliver the Service under our Terms of Service
  • Legitimate interests (Art. 6(1)(f)): For security, fraud prevention, and service improvement
  • Legal obligation (Art. 6(1)(c)): To comply with applicable law
  • Consent (Art. 6(1)(a)): For optional analytics or marketing communications
  • Customers are responsible for establishing and documenting their own lawful basis for processing End User data through the Service.

    5. Data Security

    We implement administrative, technical, and physical security measures designed to protect personal information, including encryption in transit and at rest, access controls, and regular security reviews. However, no security system is perfect or impenetrable, and we cannot guarantee absolute security.

    Customers are responsible for configuring their own access controls, reviewing audit logs, and implementing additional safeguards appropriate to the sensitivity of data they process.

    6. Data Retention and Deletion

    We retain Customer data for the duration of the subscription and for a reasonable period thereafter to allow for account closure, legal compliance, and dispute resolution. Customers may configure retention periods and export or delete all data using the self-serve tools in the HIPAA Portal and GDPR Portal.

    Conversation Data is retained according to Customer-configured retention settings and our DPA. End Users may request deletion of their personal data by contacting the relevant Customer or by submitting a data subject request through the Customer's GDPR Portal.

    7. Your Privacy Rights

    Depending on your location, you may have the following rights regarding your personal information:

  • Access to your personal information and copies of your data
  • Correction of inaccurate or incomplete personal information
  • Deletion of your personal information (right to be forgotten)
  • Restriction of processing your personal information
  • Data portability (receiving your data in a structured, machine-readable format)
  • Right to object to processing based on legitimate interests
  • Right to withdraw consent at any time (where processing is based on consent)
  • Right to lodge a complaint with a supervisory authority
  • To exercise these rights, data subjects may submit a request through the Customer's GDPR Portal, which tracks requests with a 30-day response SLA as required by GDPR. Customers can also manage data subject requests, export data, restrict processing, and report breaches using the self-serve tools in the GDPR Portal.

    For US residents, additional rights may apply under state privacy laws (e.g., CCPA/CPRA), including the right to know, delete, and opt out of the sale or sharing of personal information.

    8. AI Processing and Transparency

    The Service uses artificial intelligence to generate responses and automate conversations. Under the EU AI Act and similar regulations, Customers are responsible for informing End Users that they are interacting with an AI system at the latest at the time of first interaction. Conversify provides configurable disclosure tools, but compliance with AI transparency obligations is the Customer’s responsibility.

    AI-generated content may be inaccurate, incomplete, or unsuitable. We do not warrant the accuracy of AI outputs, and Customers must implement appropriate human review processes.

    AI Service Provider: Conversify integrates with Google Gemini (Google AI) as its third-party AI service provider for natural language processing and automated response generation. The specific model used is Google Gemini (currently gemini-2.5-flash). Google user data obtained via Google APIs (such as Google Calendar) is processed separately from the AI integration. Calendar event data is synced bidirectionally between Google Calendar and our internal database via Google Calendar API and is used for appointment availability checking and conflict detection within our booking system. Calendar data is never transmitted to the Gemini AI service for processing or model training.

    Google API Services Compliance: The use and transfer of raw or derived user data received from Google APIs (including Google Calendar API) will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Conversify does not transfer Google user data obtained from Google APIs to any AI service for training generalized models. Google Calendar data is used solely for appointment synchronization and availability checking within our booking system.

    9. International Data Transfers

    Your data may be processed in countries other than your own, including Malta, EU member states, the United States, and other jurisdictions where our service providers operate. We use Standard Contractual Clauses (SCCs) or other appropriate safeguards for international transfers where required by law.

    10. Children’s Privacy

    Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

    11. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the “Last updated” date. For significant changes, we will also attempt to notify you by email or in-app notification at least 14 days before the changes take effect.

    12. Contact Us

    If you have questions or comments about this Privacy Policy, or to exercise your privacy rights, please contact us at:

    Conversify Support
    support@conversify.app
    AppBrewers
    Malta / Spain

    Privacy Policy | Conversify