Privacy Policy

Draft under legal review — working entity data; last updated 8 September 2026

How Converise processes personal data on this website and in the Converise application.

1. Who we are

The controller of your personal data is Converise sp. z o.o. (w organizacji) with its registered office at [ADDRESS], KRS [KRS], NIP [NIP] (“Converise”, “we”). Contact: support@converise.io. This policy covers the Converise website (the “Website”) and the Converise application (the “Application”).

2. When we are not the controller — workspace content and warehouse data

Where our customer's team uses the Application, the content saved in the customer's workspace (experiment records, hypotheses, comments and similar) and any personal data contained in the customer's own data warehouse connected to the Application are processed by Converise on behalf of that customer as a processor, under the Data Processing Agreement available at /dpa. For those data, the customer is the controller and requests concerning them should be addressed to the customer.

Two facts worth knowing even so: warehouse queries are executed inside the customer's warehouse and Converise ingests only aggregated, non-identifying results — end-user identifiers never reach Converise; and the Application contains no analytics or tracking of any kind.

3. What we process, why, and on what legal basis

Account and authentication — e-mail address, password hash or Google/Microsoft sign-in identity, account identifier; identity data are stored exclusively in our authentication platform, while the product database stores only pseudonymous identifiers. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Providing the Application (workspaces, collaboration, notifications) — account identifier references, content you enter, in-app notifications. Legal basis: performance of a contract (Art. 6(1)(b)).

Alert e-mails — recipient e-mail addresses (resolved at send time; additional recipients entered by the workspace are stored) and alert content. Legal basis: performance of a contract; legitimate interest for additional recipients (Art. 6(1)(b), (f)).

Support and feedback — your e-mail address and message content (support mailbox); anything you submit through the feedback form (Google Forms). Legal basis: legitimate interest — responding to enquiries (Art. 6(1)(f)).

Error monitoring — server exception messages and stack traces (EU-region monitoring; request headers, cookies and IPs are not captured). Legal basis: legitimate interest — keeping the service working (Art. 6(1)(f)).

Security and accountability — an append-only audit trail of account and workspace actions (identifiers and event types only, never content values) and a register of warehouse queries (metadata and volumes). Legal basis: legitimate interest and legal obligations regarding security of processing (Art. 6(1)(f), (c); Art. 32).

Backups and disaster recovery — encrypted full-database copies, including authentication data. Legal basis: legitimate interest and security of processing (Art. 6(1)(f); Art. 32).

The Website currently runs no analytics and sets no tracking cookies. If we introduce website analytics or advertising measurement in the future, it will operate only with your consent given in a cookie banner, and this policy will be updated beforehand.

4. Cookies

Cookies and similar technologies are described in the Cookie Policy available at /cookies, including how the Application keeps your session without cookies.

5. Recipients of data

We use the following categories of processors and providers: authentication and database hosting (Supabase — data at rest in the EEA, Ireland), application hosting and serverless compute (Vercel — compute in the EEA, Dublin; global edge network), key management and encrypted backup storage (Google Cloud — EEA, Belgium), transactional e-mail (Resend — US), and error monitoring (Sentry — EEA data residency, Frankfurt). The current list of sub-processors relevant to customer data is published in the Data Processing Agreement at /dpa.

6. International transfers

Our data plane is located in the EEA. Where a provider is a US company, transfers rely on the EU–US Data Privacy Framework or on Standard Contractual Clauses: Vercel (DPF + SCCs), Supabase (SCCs with UK addendum), Google (DPF + SCCs), Resend (DPF + SCCs), Sentry (DPF; EU data residency in use). Copies of the relevant safeguards can be requested at the contact address above.

7. How long we keep data

Account data — for the life of the account; deletion of the account is immediate and permanent.

Workspace content — for the life of the workspace; deletion of a workspace is immediate and permanent.

In-app notifications — 90 days.

Audit trail and query register — 24 months at full fidelity; thereafter only a minimised, content-free archive (identifiers and event types) kept for security analytics.

Backups — daily copies 35 days, weekly copies 180 days. Data deleted from live systems persist inside encrypted backups until those copies expire; backups are not restored except for disaster recovery, and re-deletion is part of the restoration procedure.

Support correspondence — as long as needed to handle the matter, then up to the limitation period of possible claims.

8. Your rights

You have the right of access, rectification, erasure, restriction, data portability, and objection to processing based on legitimate interest, as well as the right to withdraw any consent at any time without affecting the lawfulness of processing before withdrawal. In practice: you can view and edit your data in the Application; a workspace owner can export the entire workspace as a JSON file at any time; deleting your account removes your data immediately. To exercise any right, you can also write to support@converise.io. You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

We do not make automated decisions producing legal or similarly significant effects concerning you. The Application refreshes experiment evidence automatically on schedules configured by the customer — this processes workspace and warehouse data as described in section 2, without profiling of individuals.

9. Security

We apply technical and organisational measures appropriate to the risk, including: encryption in transit and at rest, envelope encryption of warehouse credentials with keys held in a cloud KMS, per-workspace access control verified by automated tests, deny-all database policies for non-application access, an append-only audit trail, encrypted off-site backups with restore testing, multi-factor authentication on all operator accounts, and a documented incident response procedure.

10. Children

The Website and the Application are not directed at children under 16 and we do not knowingly process their data.

11. Changes

We will announce changes to this policy on the Website and — for registered users — by e-mail. The current version applies from [EFFECTIVE DATE].