Data Processing Agreement
Draft under legal review — working entity data; last updated 8 September 2026
This Data Processing Agreement forms an integral part of the Converise Terms of Service and applies whenever Converise processes personal data on behalf of the Customer.
§ 1. Scope, roles and definitions
1. This DPA forms an integral part of the Terms of Service of the Converise Application (the “Terms”) and applies whenever, in connection with the performance of the Agreement, the Provider processes personal data on behalf of the Customer. Capitalised terms not defined here have the meaning given in the Terms.
2. Within the scope of this DPA the Customer is the controller (or a processor acting on behalf of another controller, in which case the Customer warrants it is authorised to engage the Provider as a further processor) and the Provider is the processor within the meaning of Article 28 GDPR.
3. This DPA covers two categories of personal data processed on the Customer's behalf: (1) Customer Content — personal data contained in the data, files, information and materials saved by the Customer and its authorised users within the Account, (2) Warehouse Data — personal data contained in the Customer's own data warehouse to which the Customer connects the Application, accessed by the Provider strictly as described in Annex 1(B).
4. For the avoidance of doubt: the account and authentication data of individual users of the Application (e-mail address, authentication identity) are processed by the Provider as an independent controller, as described in the Privacy Policy, and are outside the scope of this DPA.
§ 2. Subject matter, duration, nature and purpose
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex 1.
§ 3. Documented instructions
1. The Provider processes personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by EU or Member State law; in such a case the Provider informs the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest.
2. The Customer's documented instructions consist of: (1) the Agreement, the Terms and this DPA, (2) the Customer's configuration actions performed in the Application by its authorised users — in particular connecting a data warehouse, defining a data source and its column mapping, binding experiments, enabling or disabling scheduled refreshes, and triggering previews or refreshes manually. Each such action constitutes an instruction to execute the corresponding read-only queries and processing described in Annex 1(B).
3. The Provider shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions.
§ 4. Confidentiality
The Provider ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is necessary for performing the Agreement.
§ 5. Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks for data subjects, the Provider implements the technical and organisational measures described in Annex 2 and keeps them under review. The Provider may update Annex 2, provided the changes do not lower the overall level of protection.
§ 6. Sub-processors
1. The Customer grants the Provider general written authorisation to engage sub-processors for the processing covered by this DPA. The list of sub-processors engaged at the date of this DPA is set out in Annex 3.
2. The Provider informs the Customer of any intended addition or replacement of a sub-processor by e-mail at least 14 (fourteen) days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. If the objection cannot be resolved, the Customer may terminate the Agreement to the extent it concerns the service that cannot be provided without the new sub-processor.
3. The Provider imposes on each sub-processor, by way of a contract or another legal act, data protection obligations providing at least the level of protection required by this DPA, and remains fully liable to the Customer for the performance of the sub-processor's obligations.
§ 7. Assistance with data subject rights
1. Taking into account the nature of the processing, the Provider assists the Customer, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests for exercising data subject rights (Articles 12–22 GDPR).
2. The primary means of assistance are self-service functions of the Application: in-app viewing and editing of Customer Content, the JSON export of the entire workspace available to the workspace owner, and deletion of records, workspaces and accounts. Requests that cannot be satisfied through these functions are handled by the Provider on the Customer's documented request without undue delay.
3. If a data subject addresses a request directly to the Provider in respect of data covered by this DPA, the Provider forwards it to the Customer without undue delay and does not respond on the merits without the Customer's authorisation, unless required by law.
§ 8. Personal data breach
1. The Provider notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA.
2. The notification contains, insofar as available at that time: the nature of the breach (including, where possible, the categories and approximate numbers of data subjects and records concerned), the likely consequences, the measures taken or proposed, and a contact point; information may be provided in phases as it becomes available.
3. The Provider documents breaches and their handling in accordance with its incident response procedure and provides the Customer with the information reasonably needed for the Customer's own obligations under Articles 33–34 GDPR.
§ 9. Data protection impact assessments
Taking into account the nature of the processing and the information available to it, the Provider provides the Customer with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities (Articles 35–36 GDPR) relating to the processing covered by this DPA.
§ 10. Deletion and return of data
1. During the term of the Agreement the Customer may at any time export Customer Content using the workspace JSON export.
2. Upon deletion of a workspace or an Account, or upon termination of the Agreement, the Provider deletes the Customer Content promptly and permanently; copies contained in encrypted backups expire automatically no later than within 35 days (daily backups) or 180 days (weekly backups) and are not restored except for disaster recovery, in which case deleted data are re-deleted as part of the restoration procedure.
3. Warehouse Data are not stored by the Provider beyond the aggregated, non-identifying results described in Annex 1(B); there is therefore nothing further to return or delete on termination beyond the deletion described in section 2.
4. The Provider may retain data to the extent and for the period required by EU or Member State law, and minimised operational records (audit trail and query register entries containing identifiers and metadata only) in accordance with its published retention schedule.
§ 11. Audits and information
1. The Provider makes available to the Customer information necessary to demonstrate compliance with Article 28 GDPR, in the first place through its security and compliance documentation.
2. The Provider allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer (not being a competitor of the Provider), subject to: at least 30 days' prior written notice, at most once in any 12-month period (except after a personal data breach affecting the Customer), during business hours, at the Customer's cost, under confidentiality, and in a manner that does not give access to data of the Provider's other customers.
§ 12. International transfers
1. The Provider's data plane is located in the EEA (application database and authentication: Ireland; serverless compute: Dublin; key management and backup storage: Belgium).
2. Transfers of personal data to third countries occur only through the sub-processors listed in Annex 3, each on the basis of a valid transfer mechanism (adequacy — EU–US Data Privacy Framework — or Standard Contractual Clauses), as indicated in Annex 3.
§ 13. Final provisions
1. The Provider's liability under this DPA is subject to the limitations set out in the Terms, to the extent permitted by law.
2. This DPA is governed by Polish law. It applies for as long as the Provider processes personal data on the Customer's behalf.
Annex 1 — Description of processing
A. Customer Content. Subject matter and nature: hosting, storage, display and making available for collaboration of content entered into the Application by the Customer's authorised users; creation of derived records (quality checks, recommendations) from that content. Purpose: provision of the Service described in the Terms. Duration: the term of the Agreement (deletion per § 10). Categories of data subjects: the Customer's authorised users; persons whose personal data the Customer's users include in free-text content; recipients of alert e-mails designated by the Customer. Types of personal data: user identifiers within the workspace; free-text content which may incidentally contain personal data; e-mail addresses of additional alert recipients entered by the Customer.
B. Warehouse Data. Subject matter and nature: execution of read-only SQL queries in the Customer's own data warehouse, generated by the Application from the Customer's configuration; aggregation is performed inside the Customer's warehouse and the Application ingests and stores only variant-level summary rows (metric aggregates per experiment variant and declared segment). End-user (data subject) identifiers are never ingested or stored by the Provider — subject and variant columns are configuration (column names), not data.
Setup-time preview: on an explicit action of the Customer's administrator, the Application transiently displays up to 10 sample rows per configured source to that administrator; the configured unit-ID column and columns heuristically recognised as identifiers are masked; sample rows are processed in memory only, are never persisted and are never included in error reporting or logs.
Purpose: computing experiment evidence (KPI effects, segment effects, quality checks) on the Customer's instruction. Duration: queries are executed only upon the Customer's configuration and triggers (including schedules enabled by the Customer, which run only while the given experiment is active); stored aggregates: the term of the Agreement. Categories of data subjects: the Customer's end users whose events are contained in the connected warehouse — affected only in aggregate form. Types of personal data: as contained in the Customer's warehouse tables selected by the Customer; the Customer shall not connect sources containing special categories of data (Article 9 GDPR) without the Provider's prior written agreement.
Annex 2 — Technical and organisational measures
1. Tenant isolation: authorisation enforced on every request through a per-workspace role model (owner/admin/member/viewer, 19-action permission matrix); every database query is scoped to the workspace through a type-enforced construct; cross-tenant denial is verified in CI across all workspace endpoints, including an insider role matrix.
2. Defence in depth at the database: row-level security enabled deny-all for non-application roles, default platform API grants revoked, the platform data API not routed; the application runtime connects as a least-privilege role (no DDL); migrations are separated.
3. Encryption: TLS in transit; provider-managed encryption at rest; warehouse connector credentials additionally envelope-encrypted (AES-256-GCM) with the key-encryption key held exclusively in a cloud KMS (EU region) — a database copy alone cannot decrypt credentials.
4. Warehouse access minimisation: read-only warehouse scopes; queries bounded by the experiment's time window and hard byte caps; in-warehouse aggregation so that end-user identifiers never reach the application; identifier masking in setup previews; every query the application runs in a customer warehouse is recorded in an internal register (metadata and volumes, not data).
5. Accountability: an append-only audit trail (enforced by a database trigger) with a typed actor (user / API key / system) covering account, configuration, data and decision events; audit payloads contain references only — never content values.
6. Log hygiene: error logs are reduced to bounded single-line summaries; raw error objects and data payloads are excluded from platform logs and from error monitoring (EU-region, with default PII capture disabled).
7. Retention: notifications 90 days; audit trail and query register 24 months at full fidelity, thereafter only in a minimised, content-free archive; deletion of accounts and workspaces is immediate and synchronous.
8. Availability and recovery: two independent daily backups (provider-managed and client-side-encrypted off-site copies with a write-only upload identity; retention 35/180 days), a documented restore procedure with defined RPO/RTO, quarterly restore tests, and dead-man monitoring of the backup schedule.
9. Organisational measures: MFA on all operator accounts, quarterly access reviews with a written log, a documented offboarding and secret-rotation procedure, a documented incident response procedure with an incident register, and EU-pinned compute and data plane.
Annex 3 — Authorised sub-processors
Changes to this list are notified per § 6(2).
Supabase, Inc. (US) — application database and authentication platform; data at rest in the EEA (Ireland), US entity support access; SCCs with UK addendum (published TIA).
Vercel, Inc. (US) — application hosting and serverless compute; functions in the EEA (Dublin), global edge network (TLS termination); EU–US DPF + SCCs.
Google Cloud (Google Cloud EMEA Ltd / Google LLC) — key management (KMS) and encrypted backup storage (GCS); EEA (Belgium), backups stored as client-side-encrypted ciphertext only; EU–US DPF + Cloud DPA with SCCs.
Resend, Inc. (US) — transactional e-mail (alert delivery); US; EU–US DPF + SCCs.
Functional Software, Inc. (Sentry) (US) — server error monitoring; EEA (Frankfurt) data residency; EU–US DPF.