Data processing agreement (DPA)

Courtesy translation. The French version is the binding one — the contract is governed by Ivorian law and the OHADA uniform acts.

01

Roles of the parties

For the data of people who write to the client’s agents, the client acts as controller and NOVAXIS SARL U as processor, within the meaning of article 28 of the General Data Protection Regulation. Convosia processes that data only on the client’s documented instructions.

02

Subject matter and duration

The processing covers receiving, storing and automatically handling conversations, for the sole purpose of providing the service. It lasts for the term of the contract, extended by the retention periods stated in the privacy policy.

03

Sub-processors

The client authorises the use of the following sub-processors: OpenAI (United States) to generate answers; Resend (United States) to deliver transactional email; Meta Platforms Ireland Limited to deliver WhatsApp messages; Hostinger International Ltd for hosting; Firecrawl (United States) for reading the public pages of the client’s site; Stripe for collection. And, on activation by the client: Slack, Google Drive and Airtable. The up-to-date list, with each provider’s region and the exact nature of the processing, is published on the site’s Security page. Any addition is notified to the client thirty days in advance, with a right of reasoned objection.

04

Security

Encryption of exchanges in transit. Application-level encryption of secrets and access tokens in the database — channel tokens, webhook secrets, the two-factor secret, connector keys. Encryption at rest of the storage medium provided by the host. Strict separation between client workspaces, applied at the data access level and verified by dedicated tests. Named access control, two-factor available, logging of access and sensitive actions. Systematic checking of client-supplied addresses before any outgoing call. Staff with access to data are bound by confidentiality.

05

Data breaches

In the event of a personal data breach, Convosia notifies the client without undue delay and at the latest within seventy-two hours of becoming aware of it, stating the nature of the breach, the categories concerned and the measures taken.

06

Assistance and audit

Convosia assists the client in handling data subject requests and in carrying out impact assessments. The client may request, once a year, the documentation evidencing compliance with these obligations.

07

International transfers

Data is hosted in the United Kingdom, a country covered by a European Commission adequacy decision within the meaning of Article 45 GDPR: the transfer to the host requires no additional safeguard. Transfers to a processor established in a third country not covered by such a decision — several are, and they are named in section 03 — are covered by the standard contractual clauses adopted by the European Commission, supplemented where necessary by additional measures.

08

Return and deletion

At the end of the contract, the client has thirty days to export its data from its workspace. After that, the data is deleted from our active systems, and from backups within ninety days at most.