Terms of Service

Last updated: July 7, 2026

Important Summary

Conversify is an AI-powered automation tool, not a professional advisor, emergency service, or regulated decision system. You are responsible for how you configure and use it, for obtaining all required consents, and for reviewing its outputs. Do not rely on Conversify for medical, legal, financial, or emergency situations.

1. Acceptance of Terms

By accessing or using Conversify (“the Service”), operated by AppBrewers (“Conversify”, “we”, “us”, or “our”), you agree to be bound by these Terms of Service (“Terms”). If you are using the Service on behalf of a business, you represent that you have authority to bind that business. If you disagree with any part of these Terms, you may not access or use the Service.

2. Description of Service

Conversify is an AI-powered communication platform that enables businesses to automate customer interactions across WhatsApp, Instagram, email, and related integrations. The Service supports appointment scheduling, general business information delivery, service information, basic troubleshooting, product recommendations, and conversation management.

The Service uses artificial intelligence and automated systems to generate responses, route conversations, and perform actions based on configurations you provide. The Service is a tool intended to assist your business operations; it is not a substitute for human judgment, professional advice, or emergency services.

3. No Professional Advice

Conversify is not intended to provide, and must not be used to provide, medical, health, psychological, psychiatric, legal, financial, tax, insurance, lending, investment, or other licensed professional advice. The Service must not be used for:

  • Medical diagnosis, treatment recommendations, clinical triage, or health assessments
  • Legal opinions, legal document preparation, or legal strategy
  • Financial, investment, or tax advice
  • Insurance recommendations, pricing, or eligibility determinations
  • Credit decisions, lending recommendations, or creditworthiness assessments
  • Any other regulated professional decisions requiring a licence, certification, or authorisation
  • Outputs generated by the Service are general automated responses based on your configuration and training data, not professional opinions. You must not present Conversify outputs as professional advice to end users.

    4. No Emergency or Critical Use

    Conversify is not an emergency service and must not be used for emergency communications, urgent medical situations, crisis response, suicide prevention, or any time-critical communication where delay, error, misclassification, or non-delivery could result in harm to any person.

    Fallback escalation required. You must configure and maintain at least one monitored fallback escalation contact (such as an email address, WhatsApp number, or phone number) to which the Service can route conversations that it identifies as risky, urgent, or outside its configured scope. You are responsible for monitoring that contact and responding to escalations.

    Any prompts, messages, or disclaimers within the Service that advise end users to contact local emergency services (e.g., “If this is an emergency, call 112 or 911”) are supplementary safety measures only and do not make the Service suitable for emergency use, crisis response, or any situation requiring guaranteed, immediate, or error-free communication.

    Emergency escalation feature. Conversify may detect user messages containing predefined crisis-related keywords and, in response, may send a standard safety message instructing the user to contact local emergency services and may notify the relevant practice staff. Conversify does not evaluate, classify, triage, or prioritize emergency calls or medical situations, does not dispatch emergency services, does not determine urgency or severity, and does not provide medical advice or clinical assessment. Any review, follow-up, or escalation decision is made by the practice staff, not by Conversify.

    5. AI Safeguards and Misuse

    Conversify implements technical and procedural safeguards intended to detect and deter prohibited or unsafe use, including content filters, prompt guardrails, and monitoring. However, no safeguard system is foolproof, and such measures may fail, be circumvented, or produce false negatives.

    If you or any end user bypasses, attempts to bypass, or unintentionally circumvents these safeguards-whether through prompt manipulation, configuration changes, integration misuse, or any other method-you (the Customer) remain solely responsible for all resulting content, communications, outputs, actions, decisions, and consequences.

    6. Human Oversight and Customer Accountability

    You are solely responsible for:

  • Configuring all prompts, automations, workflows, routing logic, and escalation rules
  • Selecting, reviewing, and maintaining knowledge sources, FAQs, templates, and training data
  • Setting up and managing integrations with third-party platforms (WhatsApp, Instagram, email, calendars, etc.)
  • Reviewing, approving, monitoring, and auditing communications sent through the Service
  • Ensuring that all automated outputs are appropriate before they reach end users
  • Maintaining the accuracy and currency of all business information provided to the Service
  • Conversify does not review, pre-approve, or warrant the correctness of your configurations or outputs. You must implement your own human review processes appropriate to your use case and risk level.

    7. Acceptable Use and Prohibited Conduct

    You must not, and must not permit any end user to:

  • Attempt to bypass, disable, or circumvent any safeguard, filter, guardrail, or security measure
  • Engage in prompt injection, jailbreak attempts, or extraction of hidden instructions, system prompts, or internal configuration data
  • Impersonate any person, organisation, or entity, or engage in deceptive or fraudulent conduct
  • Use abusive automation, bot networks, or automated scraping that violates platform policies
  • Conduct unlawful surveillance, data harvesting, or unauthorised data collection
  • Manipulate, coerce, or deceive end users into taking actions against their interests
  • Send spam, unsolicited commercial messages, or communications that violate GDPR, TCPA, CAN-SPAM, or similar laws
  • Harass, threaten, intimidate, or harm any person through the Service
  • Use the Service in any way that violates applicable law, third-party platform policies, or the rights of others
  • 8. Sensitive and High-Risk Use Cases

    You must not use Conversify for high-risk or regulated automated decisions, including:

  • Healthcare diagnosis, triage, treatment recommendations, or clinical decision-making
  • Hiring, firing, or worker-management decisions that materially affect employment
  • Creditworthiness assessments, lending decisions, or insurance pricing/eligibility
  • Benefits, social services, or government programme eligibility determinations
  • Any automated decision that materially affects a person’s legal rights, safety, access to essential services, or economic interests
  • If you believe your use case requires an exception, you must contact us in writing before deployment. We may grant or deny such requests at our sole discretion. Any approved high-risk use must be implemented in full compliance with applicable law, including but not limited to GDPR Article 22, the EU AI Act, and applicable US federal and state laws. Using the Conversify platform does not, by itself, make your deployment low-risk, compliant, or lawful.

    9. EU AI Act Transparency Obligations

    Customers and deployers of Conversify who are subject to the EU AI Act (Regulation (EU) 2024/1689) must:

  • Clearly inform end users when they are interacting with an AI system, in a clear, distinguishable, and accessible manner, at the latest at the time of first interaction
  • Maintain any required disclosures for AI-generated content, including labelling of synthetic or AI-generated media where applicable
  • Comply with any transparency, logging, documentation, or registration obligations that apply to their specific deployment context
  • Conversify automatically applies AI disclosure markings to all AI-generated text, voice, and email content in compliance with Article 50(2) of the AI Act. This includes visible disclosure footers on text messages, audible disclosures on voice responses, and machine-readable metadata headers on email outputs. Our full AI Act compliance statement is available at conversify.app/ai-act. The responsibility for ensuring compliance with the EU AI Act and any other applicable AI regulation in your specific deployment context rests solely with you. Conversify does not guarantee that your deployment is low-risk, exempt, or compliant merely because you use the platform.

    10. US Privacy and Health Law Allocation

    You are solely responsible for determining whether your use of the Service is subject to HIPAA (Health Insurance Portability and Accountability Act), state health privacy laws, or other US data protection regulations. If your use requires a Business Associate Agreement (BAA) or similar arrangement, you must:

  • Subscribe to the HIPAA Portal add-on ($39/month, coming soon) on the Add-ons page
  • Sign the BAA electronically via the HIPAA Portal before processing any protected health information (PHI)
  • Configure the Service in accordance with the BAA terms, including AI disclosure greetings, emergency escalation contacts, and data retention settings available in the HIPAA Portal
  • Complete staff training acknowledgment in the HIPAA Portal, confirming all staff with PHI access have received HIPAA training
  • Report any suspected or confirmed data breach using the breach notification tool in the HIPAA Portal
  • Not use the Service in ways that would require regulatory assurances we have not expressly provided in writing
  • Conversify does not claim to be “HIPAA compliant” in the absence of a signed BAA. Do not input PHI into the Service unless you have a signed BAA with us and have configured the Service in accordance with its terms. The full BAA text is available at /baa.

    The HIPAA Portal also provides a compliance check tool, audit trail viewer, patient data export, and data deletion tools to support your regulatory obligations.

    11. Messaging and Consent Compliance

    You are solely responsible for:

  • Obtaining all required consents, notices, and lawful bases for sending messages via SMS, WhatsApp, Instagram, email, or any other channel
  • Securing and documenting opt-in permissions from recipients before initiating automated messaging
  • Honouring opt-out requests, unsubscribe requests, and suppression lists promptly
  • Complying with GDPR, the TCPA (Telephone Consumer Protection Act), CAN-SPAM Act, and any other applicable messaging, telecommunications, or data protection laws
  • Complying with the terms of service and policies of each third-party messaging platform you integrate (e.g., Meta/WhatsApp Business Terms, Instagram Platform Policies)
  • Conversify is not responsible for verifying that you have obtained the necessary consents or that your messaging practices are lawful. We may suspend or terminate your account if we receive credible notice that your messaging practices violate applicable law or platform policies.

    12. Third-Party Services and Outages

    Conversify depends on third-party channels, providers, and infrastructure to deliver its Service, including but not limited to:

  • Meta Platforms (WhatsApp, Instagram) and their APIs
  • Email service providers and SMTP infrastructure
  • Cloud hosting and CDN providers
  • AI model and API vendors (e.g., large language model providers)
  • Calendar, scheduling, and payment integration providers
  • Conversify is not liable for outages, delivery delays, message blocking, policy changes, account suspensions, API deprecations or changes, model degradation, rate limiting, or errors caused by these third parties. Service availability is contingent on the continued availability and cooperation of these third-party providers.

    13. Output Accuracy and Reliance Disclaimer

    AI-generated and automated outputs may be inaccurate, incomplete, outdated, misleading, unsuitable, or unavailable. You must not rely on Conversify outputs without appropriate human judgment and oversight. Conversify does not warrant that:

  • Outputs will be accurate, complete, or current
  • Outputs will be suitable for any particular purpose
  • The Service will correctly classify, route, or prioritise conversations in all cases
  • Automated bookings, recommendations, or responses will be error-free
  • You are responsible for reviewing outputs before they are sent to end users, or for implementing review processes appropriate to your risk tolerance.

    14. Privacy, Security, and Data Minimisation

    We design the Service with privacy-by-design principles in mind, including data minimisation, purpose limitation, retention controls, and access restrictions. However:

  • You are responsible for determining what data you input into the Service and for minimising the personal data you process
  • You are responsible for configuring retention periods, access controls, and data deletion appropriate to your legal obligations - these tools are available in the HIPAA Portal and GDPR Portal
  • We do not guarantee that our security measures will prevent all unauthorised access, breaches, or data loss
  • Our Privacy Policy and any applicable Data Processing Addendum (DPA) govern the processing of personal data; this Terms document does not override those agreements
  • For GDPR compliance, the GDPR Portal provides tools for data subject request management (access, rectification, erasure, restriction, objection, portability), a Record of Processing Activities (Art. 30), breach notification (Art. 33/34), subprocessor disclosures (Art. 28), data export, and data retention configuration. Data subjects or their authorised representatives may submit requests through the portal, which are tracked with a 30-day response SLA.

    For subprocessor disclosures, see our Subprocessors page. We provide advance notice of subprocessor changes as described in our Data Processing Addendum.

    We do not claim that the Service is “fully GDPR compliant” or “fully compliant” with any specific regulation for your particular deployment. Compliance depends on how you configure and use the Service.

    15. Subscription and Payment

    Our services are provided on a subscription or one-time payment basis, as described on our pricing page. You agree to pay all fees associated with your chosen plan. Unless otherwise stated, payments are non-refundable except as required by applicable law. We may change our pricing with at least 30 days’ notice before the change takes effect.

    16. Conversations and Usage

    What is a Conversation?

    A “conversation” is defined as all messages exchanged between your business and a single customer. The conversation ends when either:

  • The customer sends a closing message (e.g., “thanks”, “goodbye”, “bye”, “see you later”, etc.), OR
  • No messages are exchanged for 6 consecutive hours - whichever comes first.
  • A new conversation begins after the previous one ends. This definition applies across all channels (WhatsApp, Instagram, Messenger, Web Chat).

    Example:

    • 9:00 AM: Customer sends “Can I book an appointment?”
    • 10:30 AM: You reply “Yes, Tuesday at 3pm works”
    • 2:45 PM: Customer says “Thanks, see you then”

    This is 1 conversation (ends at the “thanks, see you then” message).

    If the customer messages again at 8:00 PM, that would be a new conversation (the previous one ended at 2:45 PM).

    Example with timeout:

    • 9:00 AM: Customer asks about availability
    • 10:15 AM: You reply with options
    • Customer does not respond further
    • The conversation ends at 4:15 PM (6 hours after the last message)

    Message Limits by Plan

    • Starter: 5,000 messages/month
    • Growth: 20,000 messages/month
    • Pro: 50,000 messages/month
    • Business: 100,000 messages/month
    • Enterprise/Call Center: Custom limits - contact sales

    Exceeding your monthly conversation limit may result in service interruption or require an upgrade to a higher plan. Contact support for volume discounts.

    17. Suspension, Restriction, and Termination

    We may suspend, disable, limit, restrict, or terminate your account, workflows, integrations, or specific features immediately and with or without notice if we determine, in our sole discretion, that:

  • You have breached these Terms or engaged in prohibited conduct
  • Your use poses a risk of abuse, privacy breach, safety harm, or legal exposure
  • Your use violates third-party platform policies (e.g., Meta/WhatsApp/Instagram terms)
  • You are using the Service for a prohibited high-risk or regulated use case
  • Your account or integrations have been compromised or are being misused
  • Regulatory, legal, or law enforcement requirements compel such action
  • You may terminate your account at any time by contacting us. Upon termination, your right to use the Service ceases immediately. We may delete your data after a reasonable grace period, as described in our Privacy Policy.

    18. Intellectual Property

    The Service, including its software, design, branding, and documentation, is the property of AppBrewers and is protected by intellectual property laws. You retain ownership of the content, data, and configurations you upload to the Service. We retain ownership of the platform and any improvements, modifications, or derivatives we develop.

    You grant us a limited, non-exclusive licence to process your content solely as necessary to operate, maintain, and improve the Service for you, as further described in our Privacy Policy and DPA.

    19. Disclaimer of Warranties

    The Service is provided “as is” and “as available” without warranty of any kind, whether express, implied, or statutory. To the fullest extent permitted by law, we disclaim all warranties, including but not limited to implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranty that the Service will be uninterrupted, secure, accurate, or error-free.

    20. Limitation of Liability

    To the fullest extent permitted by law, AppBrewers shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits, data, business, or goodwill, arising from or related to your use of, or inability to use, the Service. This includes, without limitation, damages arising from:

  • Inaccurate, incomplete, or misleading AI-generated outputs
  • Failed, delayed, or misrouted messages or escalations
  • Third-party outages, API changes, or platform suspensions
  • Your configurations, prompts, training data, or templates
  • Your failure to obtain consents, review outputs, or maintain human oversight
  • Prohibited or high-risk use cases you deploy despite these Terms
  • Your failure to sign or maintain required Business Associate Agreements (BAAs), Data Processing Agreements (DPAs), or other compliance documentation
  • Routing of Protected Health Information (PHI) or other regulated data through channels that are not covered by a signed BAA
  • Your failure to comply with HIPAA, GDPR, the EU AI Act, CCPA, or any other applicable data protection, privacy, or AI regulation in your jurisdiction
  • Fines, penalties, investigations, or enforcement actions by any regulator, including but not limited to the HHS Office for Civil Rights (OCR), the Information Commissioner’s Office (ICO), the European Data Protection Board (EDPB), the FTC, or any EU national supervisory authority
  • Claims by your customers, patients, or end users arising from your use of the Service in a manner that violates applicable law
  • You are solely responsible for determining whether the Service is appropriate for your use case and for ensuring that your deployment of the Service complies with all applicable laws, regulations, and industry standards in your jurisdiction. Conversify provides tools and configuration options to support compliance, but these tools do not constitute legal advice and do not guarantee compliance. You should consult qualified legal counsel to assess your specific obligations.

    Where applicable law does not allow the exclusion or limitation of liability, our total aggregate liability for all claims arising from the Service shall not exceed the amount you paid us in the twelve (12) months preceding the claim.

    21. Indemnity

    You agree to indemnify, defend, and hold harmless AppBrewers, its officers, directors, employees, and agents from and against any and all claims, lawsuits, demands, fines, penalties, investigations, losses, damages, liabilities, costs, and expenses (including reasonable legal fees) arising from or related to:

  • Your prompts, configurations, workflows, templates, and training data
  • Uploaded knowledge sources, FAQs, or content
  • Recipient lists, contact data, or messaging practices
  • Attempts to bypass or circumvent AI safeguards or security measures
  • Use of the Service for emergency, crisis, or critical communications
  • Deployment of prohibited or high-risk regulated use cases
  • Unlawful messaging, spam, or violation of consent requirements
  • Privacy violations, data breaches, or non-compliant data processing
  • HIPAA violations, including failure to sign or maintain BAAs, or routing PHI through non-BAA-covered channels
  • GDPR violations, including failure to maintain DPAs with sub-processors or lawful bases for processing
  • EU AI Act violations, including failure to disclose AI interaction to end users where required
  • Any regulatory fine, penalty, or enforcement action arising from your deployment or configuration of the Service
  • Any breach of these Terms or applicable law
  • We reserve the right, at our own expense, to assume the exclusive defence and control of any matter otherwise subject to indemnification by you, in which case you will cooperate with us in asserting any available defences.

    22. Governing Law and Dispute Resolution

    These Terms shall be governed and construed in accordance with the laws of Malta, without regard to its conflict of law provisions. For customers based in the European Union, the provisions of Regulation (EC) No 593/2008 (Rome I) and Regulation (EC) No 864/2007 (Rome II) shall apply where relevant.

    For customers based in the United States, these Terms shall be governed by the laws of Malta, and any disputes shall be resolved in the courts of Malta, except where US mandatory consumer protection laws require otherwise.

    Before initiating formal proceedings, both parties agree to attempt to resolve disputes through good-faith negotiations for at least 30 days.

    23. Changes to Terms

    We reserve the right to modify these Terms at any time. We will provide notice of material changes by posting the updated Terms on this page and updating the “Last updated” date. For significant changes that affect your rights or obligations, we will also attempt to notify you by email or in-app notification at least 14 days before the changes take effect.

    Your continued use of the Service after the effective date constitutes acceptance of the updated Terms. If you do not agree to the changes, you must stop using the Service.

    24. Contact Information

    For any questions about these Terms, please contact us at:

    Conversify Legal Department
    legal@conversify.app
    AppBrewers
    Malta

    Terms of Service | Conversify