Last Updated: June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between ConvoGPT AI (“Processor”, “ConvoGPT AI”, “we”, “us”, or “our”) and the customer (“Controller”, “Customer”, “you”, or “your”) using ConvoGPT AI services.
This DPA applies where ConvoGPT AI processes Personal Data on behalf of the Customer in connection with the Services.
For the purposes of this Agreement:
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, or deletion.
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means the entity that processes Personal Data on behalf of the Controller.
Applicable Data Protection Laws means all applicable privacy and data protection laws, including but not limited to the General Data Protection Regulation (GDPR), UK GDPR, and applicable U.S. privacy laws.
This DPA applies to Personal Data processed by ConvoGPT AI while providing:
AI Voice Agents
AI Employees
CRM Services
Lead Management
SMS Automation
Email Automation
Workflow Automation
Customer Support Automation
Related Software Services
The Customer acts as the Data Controller.
ConvoGPT AI acts as the Data Processor.
The Customer is responsible for determining:
What Personal Data is collected
The purpose of processing
The legal basis for processing
Compliance with applicable laws
ConvoGPT AI processes Personal Data solely on documented instructions from the Customer.
ConvoGPT AI shall:
Process Personal Data only for providing contracted services
Follow Customer instructions where legally permitted
Not sell Customer Personal Data
Not use Customer Personal Data for unrelated purposes
Depending on Customer usage, Personal Data may include:
Names
Email addresses
Telephone numbers
Business information
CRM records
Communication records
Call recordings
Appointment information
Customer interaction history
The Customer determines which categories of data are processed.
ConvoGPT AI shall ensure that personnel authorized to process Personal Data:
Are subject to confidentiality obligations
Receive appropriate security awareness training
Access Personal Data only when required for legitimate business purposes
ConvoGPT AI implements reasonable technical and organizational safeguards, including:
Access controls
Authentication mechanisms
Secure communication channels
Monitoring and logging
Data backup procedures
Infrastructure security controls
Security measures are reviewed periodically and updated where appropriate.
The Customer authorizes ConvoGPT AI to engage third-party subprocessors necessary for delivering the Services.
Examples may include:
Cloud infrastructure providers
Payment processors
Communication providers
Analytics providers
Customer support platforms
ConvoGPT AI remains responsible for ensuring subprocessors provide appropriate safeguards.
Where Personal Data is transferred internationally, ConvoGPT AI shall implement appropriate safeguards consistent with applicable data protection laws.
Such safeguards may include:
Standard Contractual Clauses
Contractual commitments
Other legally recognized transfer mechanisms
To the extent legally required, ConvoGPT AI shall provide reasonable assistance to enable the Customer to respond to requests relating to:
Access
Correction
Deletion
Restriction
Portability
Objection to processing
The Customer remains responsible for responding to data subject requests.
If ConvoGPT AI becomes aware of a confirmed security incident affecting Customer Personal Data, we will:
Investigate the incident
Take reasonable mitigation measures
Notify affected Customers when required by law
Notifications will be provided without undue delay following confirmation of the incident.
Upon termination of Services, Customer data may be retained for a reasonable period to satisfy:
Legal obligations
Regulatory requirements
Backup and recovery processes
Subject to applicable law, Customers may request deletion of Personal Data by contacting:
Upon reasonable written request, ConvoGPT AI may provide information necessary to demonstrate compliance with this DPA.
Any audit requests must:
Be reasonable in scope
Not interfere with normal operations
Protect confidential information of other customers
Liability under this DPA shall be subject to the limitations of liability set forth in the applicable Terms & Conditions.
This DPA shall be governed by the same governing law specified in the ConvoGPT AI Terms & Conditions.
For privacy or data protection inquiries, please contact:
Privacy Team
privacy@convogpt.ai
General Support
support@convogpt.ai
ConvoGPT AI
Greenville, South Carolina, USA
Provision of AI-powered business automation services.
For the duration of the Customer’s use of the Services.
Collection, storage, organization, retrieval, communication, automation, and management of Customer data.
Customer employees
Leads
Prospects
End customers
Business contacts
Names
Email addresses
Phone numbers
CRM records
Communication history
Appointment details
Call recordings (where enabled)
Providing AI automation, communication, CRM, lead management, and customer support services.