1. Parties and application
Version 1.0. Last updated: 6 October 2026.
This Data Processing Agreement (DPA) is between CONVRO LTD (CONVRO), the provider of Reesponder, and the business identified as the Customer in its Reesponder order or account. CONVRO is registered in England and Wales under company number 17444294, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
This DPA forms part of the Terms of Service where CONVRO processes personal data on the Customer’s behalf. It applies when incorporated into the Customer’s accepted Terms or a separate written agreement. Merely visiting this page does not enter a contract. A representative accepting it must have authority to bind the Customer.
This DPA governs that processing throughout the provision of the Service and until the relevant personal data is returned or deleted. It prevails over conflicting general terms on the processing of Customer Personal Data. Mandatory transfer clauses and mandatory data-protection law prevail over this DPA. An existing separately signed DPA continues to apply unless the parties agree to replace it.
2. Definitions and roles
Data Protection Law means the UK GDPR and the Data Protection Act 2018, and the EU GDPR or other applicable personal-data legislation to the extent it governs the processing. Terms such as controller, processor, personal data, processing, data subject and personal data breach have their meanings under that law.
Customer Personal Data means personal data processed by CONVRO on behalf of the Customer through Reesponder, including relevant Knowledge, conversations, website and customer context, Action inputs and results, and human-handoff information. Subprocessor means another processor engaged by CONVRO to process that data for the Customer.
The Customer ordinarily acts as controller and CONVRO as processor. Where the Customer is itself a processor, CONVRO acts as its subprocessor, and the Customer must have the relevant controller’s authority to appoint CONVRO and give the instructions in this DPA. The Customer remains responsible for communicating any additional binding controller instructions to CONVRO.
This DPA does not cover processing for which CONVRO determines its own purposes as an independent controller, such as managing its customer relationship, billing and required accounting records, or protecting its own legal rights. That processing is described in the Privacy Policy. A provider’s role depends on the particular activity, rather than its label alone.
3. Documented instructions
CONVRO shall process Customer Personal Data only on the Customer’s documented instructions, including instructions about international transfers, unless processing is required by applicable law. In that case, CONVRO shall inform the Customer of the legal requirement before processing, unless the law prohibits that information on important grounds of public interest.
The initial instructions are this DPA, the Customer’s order, and the Customer’s supported configuration and use of Reesponder: connecting websites, supplying Knowledge, receiving conversations, configuring approved Actions, selecting retention and requesting support. Further instructions may be given in writing to [email protected]. An instruction is not expanded merely because a visitor asks the assistant to perform an unsupported operation.
CONVRO shall promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law. It may suspend the affected processing while the parties resolve the issue. Requests that require additional functionality or materially change the agreed service must be agreed separately; this does not remove CONVRO’s existing statutory or contractual duties.
CONVRO shall not sell Customer Personal Data or use it for its own unrelated advertising. CONVRO does not use Customer Knowledge, Visitor conversations or live customer context to train a CONVRO-owned general-purpose foundation model. External AI processing remains subject to the subprocessor and transfer requirements below; this statement does not represent that every external provider has zero retention.
4. Customer responsibilities
The Customer determines the purpose of its assistant, the websites and sources it connects, the information it makes available, and the systems and recipients involved in its Actions and support workflows. It is responsible for a lawful basis, required notices, lawful instructions and any necessary consent, including for browser storage or analytics on its own websites.
The Customer shall provide only data necessary for its use case, keep its access credentials and authorised-user permissions secure, and review the accuracy and suitability of Knowledge and connected information. Opaque identifiers should be used instead of direct identifiers where practical. The Customer shall not instruct CONVRO to process unsupported sensitive information.
The Customer is responsible for assessing whether a data-protection impact assessment is needed, making decisions about data-subject requests and regulatory notifications, and ensuring that its selected endpoints and recipients are authorised. CONVRO shall provide the assistance required by this DPA; these Customer responsibilities do not reduce CONVRO’s obligations as processor.
5. Confidentiality and access
CONVRO shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality commitments or an appropriate statutory duty of confidentiality. Access shall be limited to persons who need it to deliver, support or secure the agreed processing, and removed when no longer required.
Support or incident investigation may require access to relevant Customer Personal Data. Such access remains subject to this DPA, documented instructions and access controls. CONVRO shall not treat operational access as permission to use that data for unrelated purposes.
6. Security of processing
CONVRO shall implement appropriate technical and organisational measures under Article 32 of the UK GDPR and EU GDPR, where applicable, taking account of the state of the art, implementation costs, and the nature, scope, context, purposes and risks of the processing. Schedule B describes the measures relevant to Reesponder.
Measures shall address confidentiality, integrity, availability and resilience, appropriate restoration following incidents, and regular assessment of their effectiveness. CONVRO may adapt measures as the service and risks change, provided this does not materially reduce the agreed overall protection.
Neither this DPA nor a security statement constitutes a claim of independent certification, a guarantee that incidents cannot occur, or a promise of a dedicated hosting region, blanket encryption at rest or a particular accreditation that has not been expressly agreed.
7. Subprocessors and authorisation
The Customer gives general written authorisation for CONVRO to use the subprocessors disclosed to it in the service-specific subprocessor record described in Schedule C, subject to this section. This is not blanket authorisation for undisclosed recipients. CONVRO shall provide the current record to the Customer before the relevant authorisation and keep it available and up to date throughout the processing relationship.
CONVRO shall notify the Customer in writing of an intended addition or replacement at least 30 days before the new subprocessor begins processing Customer Personal Data. Notice shall identify the entity, its function, the relevant processing locations and applicable transfer arrangements. Updates shall be sent to the Customer’s account or designated privacy contact; a silent update to this page is not sufficient notice.
The Customer may object within that period on reasonable data-protection grounds. CONVRO shall discuss the objection and seek an appropriate alternative or mitigation. An unresolved objection shall be addressed before the disputed processing begins. If no suitable arrangement can be reached, the Customer may terminate the affected service without an early-termination penalty and receive a proportionate refund of prepaid fees for its unused period.
Before a subprocessor handles Customer Personal Data, CONVRO shall put in place a binding written agreement imposing equivalent applicable data-protection obligations, including confidentiality, security, assistance, deletion and lawful transfers. CONVRO remains responsible to the Customer for the subprocessor’s performance of those obligations.
Confidential commercial details may be supplied privately. Confidentiality must not prevent the Customer from knowing the actual identity of its subprocessors, fulfilling its legal duties, responding to individuals where required, or cooperating with a supervisory authority.
8. International processing and transfers
CONVRO is established in the United Kingdom. Reesponder does not promise that all processing remains exclusively in the UK or European Economic Area. External processing may involve other countries; the service-specific record shall identify the applicable locations and transfer arrangements, including relevant remote access.
CONVRO shall not make a restricted transfer of Customer Personal Data unless it is covered by the Customer’s documented instructions and a lawful transfer mechanism. Where required, this means an applicable adequacy decision or appropriate safeguards, such as the relevant EU Standard Contractual Clauses and UK Addendum or the UK International Data Transfer Agreement, together with a transfer assessment and necessary supplementary measures.
The parties shall complete or enter into the applicable transfer instrument where necessary, using the correct parties, roles, modules and schedules. CONVRO shall make relevant information about the safeguards available to the Customer. This DPA does not itself execute those instruments, establish that an unnamed destination is adequate, or replace a required transfer assessment.
If the applicable safeguards can no longer be met, CONVRO shall inform the Customer and suspend the affected transfer unless and until a lawful alternative is established. Customer-directed transfers to its own connected systems remain subject to the Customer’s responsibilities and do not permit CONVRO to bypass restrictions on its own onward transfers.
9. Requests from individuals
Taking account of the nature of the processing, CONVRO shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise rights under Data Protection Law, including access, correction, deletion, restriction, portability and objection where applicable.
If CONVRO receives a request relating to Customer Personal Data, it shall notify the Customer without undue delay and refer the requester to the Customer where appropriate. CONVRO shall not independently decide how to answer on the Customer’s behalf unless authorised or required by law. It may take reasonable steps to verify the request and locate the relevant data without collecting unnecessary additional information.
The Customer should identify the workspace, website, relevant conversation or other record and the action requested using a secure channel. Available export, deletion and retention functions may be used first; CONVRO shall assist where those functions do not resolve the request. A retention expiry may mean that conversation content is no longer available.
10. Personal data breaches
CONVRO shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification shall not be delayed solely because the investigation is incomplete. CONVRO shall take appropriate steps to contain, investigate and mitigate the breach and provide updates as material information becomes available.
To the extent available, notification shall describe the nature of the breach, the categories and approximate numbers of affected individuals and records, likely consequences, measures taken or proposed, and a contact for further information. CONVRO shall assist the Customer with its assessment, documentation and legally required notifications, taking account of the information available to CONVRO.
The Customer determines its own notification obligations as controller. CONVRO shall not notify individuals on the Customer’s behalf without instructions, unless required by law. A breach notification is not, by itself, an admission of liability. Routine blocked attacks without a breach of Customer Personal Data are not treated as personal data breaches.
11. Impact assessments and regulatory assistance
Taking account of the nature of processing and the information available to it, CONVRO shall assist the Customer with compliance concerning security, breach notification, communication to individuals, data-protection impact assessments and prior consultation with a supervisory authority under Articles 32 to 36, where applicable.
Assistance may include relevant descriptions of processing, measures, subprocessor arrangements, transfer safeguards and incident facts. The Customer remains responsible for its own assessment and decisions. The parties may agree reasonable costs for additional bespoke assistance beyond the ordinary service, but cost arrangements must not frustrate mandatory assistance or the exercise of legal rights.
12. Information, audits and inspections
CONVRO shall make available the information necessary to demonstrate compliance with this DPA and applicable Article 28 obligations, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
The parties should first use available written evidence and agree a proportionate scope, secure access method and reasonable notice. Routine inspections should minimise disruption and protect other customers’ data and confidential systems. Auditors shall be appropriately qualified, independent and subject to confidentiality; any objection to an auditor must not be used to prevent an effective audit.
Routine inspections may ordinarily be coordinated once in a 12-month period. Additional access remains available where required by law or an authority, following a relevant breach, or where there are reasonable grounds to suspect non-compliance. Urgent legal or regulatory needs take precedence over ordinary notice and scheduling arrangements. Nothing in this section limits a supervisory authority’s powers.
13. Retention during the service
Standard maximum full-transcript retention is up to 7 days for Core, 30 days for Business and 90 days for Scale. A supported shorter retention setting takes precedence as applied by the service. Retention is distinct from usage accounting or a billable conversation window.
Expired conversation content is removed through scheduled processing. Relevant stored context, conversation-linked Action inputs and results, and internal human-handoff content are subject to associated cleanup. Limited execution, delivery, usage and audit metadata may remain separately where necessary and lawful; it is not a promise that the full transcript remains retrievable.
Administrative Action test records are scheduled for cleanup after 24 hours. Expired identity-verification records are removed through scheduled cleanup. Knowledge and configuration remain while needed for the connected service unless removed earlier or deleted through the account lifecycle.
Exports, messages already delivered to the Customer’s mailbox and records in Customer-selected systems are separate copies under the Customer’s control. The Customer is responsible for their retention. Deleting a Reesponder record does not reverse a completed external operation or erase those independent copies.
14. Return and deletion at the end of processing
At the Customer’s choice, CONVRO shall return or delete Customer Personal Data after the relevant processing service ends and delete existing copies, unless applicable law requires retention. The Customer should request a return before closing its workspace or before applicable retention expires; CONVRO shall assist with a securely delivered, reasonably usable export of data that is still held. CONVRO cannot return content already lawfully deleted.
Where no return is requested, deletion is the default instruction. Account termination schedules active-workspace deletion after the service’s 12-day closure period, subject to applicable legal obligations. The Customer may request earlier deletion or a different supported return arrangement in writing. A suspension, removal of a website, or cancellation of future renewal is not necessarily immediate deletion of the entire account.
Residual backup copies shall remain restricted from ordinary use and be deleted or overwritten through the applicable backup lifecycle. If a backup is restored, applicable deletion and retention instructions shall be reapplied. CONVRO shall provide information about that lifecycle and confirm completion of deletion on request; any specifically agreed backup retention periods shall be set out in the service-specific processing record.
Records that must legally be retained shall be limited to that purpose, kept protected and removed when the requirement ends. Independently controlled accounting or business records described in the Privacy Policy are not retained copies of the Customer’s complete conversation archive.
15. Connected services and sensitive information
The Customer’s instructions may require Reesponder to send information to its selected systems, execute configured Actions or deliver support requests to its team. The Customer shall authorise those recipients and the data needed for the operation. Read-only lookups, identity checks and customer confirmation for supported write Actions serve different purposes; a confirmation is not blanket consent to unrelated processing.
A Customer-selected endpoint is not automatically a CONVRO-appointed subprocessor. Its role and contractual relationship depend on who selects and engages it. Any provider separately engaged by CONVRO to process Customer Personal Data remains subject to Section 7.
The ordinary service is not intended for payment-card details, passwords in conversations, identity documents, complete medical records, special-category data or criminal-offence data. Such data must not be supplied unless the processing is expressly supported and agreed in writing with the necessary legal conditions and safeguards. Reesponder is not intended for independently making decisions producing legal or similarly significant effects about individuals.
16. Changes, liability and governing law
Updates to this DPA shall follow the applicable notice and acceptance arrangements in the Terms or a separately agreed contract. Updates shall not remove mandatory rights or protections. Subprocessor changes must follow Section 7 even where a general Terms-update process also applies. Customers may request a dated copy of the version governing their relationship.
The Terms govern commercial liability and disputes except where mandatory Data Protection Law or binding transfer clauses require otherwise. This DPA does not waive rights of individuals or authorities, transfer a party’s statutory responsibility to another party, or create a contractual cap on liability that cannot lawfully be limited.
This DPA is governed by the laws of England and Wales, with the jurisdiction stated in the Terms, subject to mandatory law and any governing-law or jurisdiction provisions in applicable transfer instruments.
17. Data-protection contact
For documented instructions, a subprocessor record, transfer information, a dated copy of this DPA, audit coordination, or assistance with return, deletion or a data-subject request, contact CONVRO. Include your workspace and the nature of the request; do not include unnecessary sensitive data or access secrets in the initial email.
CompanyCONVRO LTD
Email[email protected]
Registered office71–75 Shelton Street, Covent Garden,
London, WC2H 9JQ, United Kingdom
Company number17444294
Read this DPA together with the Terms of Service and Privacy Policy. Questions from visitors about a Customer’s website or business should ordinarily be directed to that Customer as controller.
Schedule A. Description of processing
Subject matter and purpose
Provision of Reesponder’s customer-support assistant and associated workspace: answering from approved business information, understanding page and customer context, performing configured operations, handing requests to the Customer’s team, and providing relevant conversation review and service analytics.
Nature and operations
Collection, receipt, organisation, storage, retrieval, selection of relevant Knowledge, analysis, generation of responses and summaries, transmission to authorised recipients, supported export, restriction and deletion. Processing is ongoing while the service is used, with individual requests and operations triggered by the Customer, its authorised users or website visitors.
Categories of people
Visitors, prospective and existing customers of the Customer, persons mentioned in their requests or Customer-supplied material, and the Customer’s staff or authorised users where their information is included in the processor activities.
Types of personal data
- Conversation messages, replies, summaries and feedback, with timestamps and conversation references.
- Website identifiers, page paths and relevant page information; pseudonymous visitor, session and customer identifiers.
- Names, email addresses and phone numbers supplied for support or a configured operation.
- Relevant business content and personal information contained in Knowledge documents or connected sources.
- Configured Action fields, verification information, order or product references, returned results and relevant transaction or enquiry details.
- Technical, security, usage and outcome information to the extent processed on the Customer’s behalf, including network identifiers where collected.
Duration and instructions
For the term of the relevant service and the limited period needed for authorised return or deletion, subject to Sections 13 and 14. The actual data and operations depend on the Customer’s sources, configuration and documented instructions. Unsupported sensitive categories are excluded unless separately agreed under Section 15.
Schedule B. Technical and organisational measures
The following describes relevant measures and the security obligations for the agreed processing. Service-specific evidence and further details may be provided securely under Section 12. It is not a list of certifications or an assertion that every Customer-selected system implements the same measures.
- Access control and separation: authenticated customer access, workspace membership and permission checks, tenant-scoped data access, and domain-bound website installations. Operational access shall follow least-privilege principles.
- Credentials and tokens: password hashing and hash-only storage of opaque authentication tokens; supported integration secrets protected by server-side encryption and controlled keys. Revocation and expiry limit continued use of access credentials.
- Transmission: HTTPS for public service and supported API communication; controlled communication with infrastructure and authorised providers. Connected destinations must meet the service’s applicable endpoint and security requirements.
- Operation integrity: validation of supported inputs and destinations, signed webhook verification and idempotency controls, and required identity or confirmation safeguards for supported Actions. These do not substitute for the Customer’s business permissions.
- Minimisation and lifecycle: relevant-source selection for AI requests, supported shorter retention, expiry of verification records, scheduled transcript and related-content cleanup, and workspace deletion procedures.
- Service protection: abuse and rate controls, operational monitoring and bounded diagnostic information, maintained software and controlled changes. Credentials shall be kept out of public bundles and ordinary source control.
- Resilience and recovery: appropriate backup and recovery arrangements, restricted backup access, restoration procedures and assessment of their effectiveness, with retention instructions reapplied following restoration.
- Organisation and response: confidentiality obligations, access review, procedures for incidents and data-subject assistance, and regular assessment of security measures in light of identified risks.
The Customer’s responsibilities include securing its devices and accounts, limiting team access, protecting its API endpoints and mailboxes, and supplying only the information needed for its use case.
Schedule C. Service-specific subprocessor record
CONVRO shall supply the record identifying the subprocessors used for the Customer’s processing separately, rather than publishing commercially sensitive infrastructure details on this page. The record forms part of the authorisation process in Section 7 and must include the actual entity names and contact information, their processing functions, relevant countries and applicable transfer safeguards. Describing a provider only as “AI infrastructure” or “hosting” is not a substitute for identifying it to the Customer.
Relevant functions may include hosting and storage, network delivery and security, AI inference and operational email delivery. Only providers that actually process Customer Personal Data in the agreed service belong in the record. Marketing-site analytics and independent payment processing must not be presented as if every such provider receives Visitor conversations.
The record shall reflect the actual processing and be supported by the applicable written subprocessor and transfer arrangements. The Customer may request the record and supporting information using the contact below. CONVRO’s obligation to provide it before authorisation does not depend on the Customer first making a request.
The Customer may designate a privacy contact to receive notices and shall keep that contact or its account email current. Confidentiality arrangements shall preserve disclosures required by law, cooperation with authorities and the Customer’s ability to assess compliance.