Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Use and governs the processing of personal data by convobix on behalf of customers who are subject to GDPR, UK GDPR, or similar data protection laws.
Definitions
"Personal Data", "Data Subject", "Processing", "Controller", and "Processor" have the meanings given in the GDPR. "Customer Data" means any personal data submitted to the Service by or on behalf of Customer.
Scope and Roles
The parties acknowledge that: (a) Customer is the Controller of Customer Data; (b) convobix is the Processor of Customer Data; and (c) convobix may engage Sub-processors to assist in providing the Service.
Processor Obligations
convobix shall: process Customer Data only on documented instructions from Customer; ensure persons authorised to process Customer Data are under confidentiality obligations; implement appropriate technical and organisational security measures; assist Customer in responding to Data Subject requests; notify Customer without undue delay upon becoming aware of a Personal Data Breach.
Sub-processors
Customer grants general authorisation to engage Sub-processors. Current Sub-processors are listed at convobix.io/legal/sub-processors. convobix will provide notice of new Sub-processors at least 14 days in advance.
International Transfers
Where Processing involves a transfer of Personal Data to a third country, the transfer shall be subject to Standard Contractual Clauses (SCCs) as adopted by the European Commission, or another approved transfer mechanism.
Technical & Organisational Measures
convobix maintains comprehensive security measures including: encryption at rest (AES-256) and in transit (TLS 1.3); role-based access controls; annual penetration testing; SOC 2 Type II compliance program; incident response procedures; and employee security training.