This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Convi Terms of Service or other agreement between the merchant ("Customer" / "Controller") and Nextwave Digital Ltd, a company incorporated in British Columbia, Canada, with registered office at 202A – 7080 River Rd, Richmond, BC V6X 1X5, Canada ("Convi" / "Processor"), governing the processing of personal data in connection with the Convi AI shopping-assistant service (the "Service"). Where the Customer is subject to the EU GDPR, the UK GDPR, and/or the Swiss FADP, this DPA applies to Convi's processing of personal data on the Customer's behalf. Convi will provide this DPA to any merchant on request, and will counter-sign a merchant's own DPA on request.
1. Definitions
Capitalized terms not defined here have the meaning given in applicable data protection law. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings in the EU GDPR. "Sub-processor" means any third party engaged by Convi to process Personal Data. "SCCs" means the EU Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914. "Data Subject" here means the Customer's end-shoppers and other individuals whose Personal Data is processed via the Service.
2. Roles and scope of processing
2.1 With respect to shopper conversation data processed via the Service, the Customer is the Controller and Convi is the Processor. Convi acts as an independent Controller only for merchant-account data it collects to operate and bill the Service, which is governed by the Convi Privacy Policy, not this DPA.
2.2 Convi will process Personal Data only on the Customer's documented instructions (including the Agreement, this DPA, and the Customer's configuration of the Service), unless required by law — in which case Convi will inform the Customer first unless legally prohibited.
2.3 The subject matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.
2.4 The Customer is responsible for the lawfulness of the Personal Data it provides and of Convi's processing on its instructions, including having a lawful basis and providing any required notices to Data Subjects.
3. Security
3.1 Convi will implement and maintain the technical and organizational measures set out in Annex 2, appropriate to the risk under Article 32 GDPR.
3.2 Convi ensures that personnel authorized to process Personal Data are bound by confidentiality.
4. Customer obligations
The Customer will (a) configure and use the Service in compliance with data protection law; (b) provide only the Personal Data necessary for the Service; and (c) not instruct Convi to process Personal Data in violation of data protection law.
5. Sub-processors
5.1 The Customer provides general authorization for Convi to engage Sub-processors. The current list of Sub-processors is published at conviapp.com/subprocessors and incorporated into this DPA.
5.2 Convi will update that list before a new Sub-processor begins processing Personal Data. The Customer may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection, and if it cannot be resolved, the Customer may stop using the affected part of the Service.
5.3 Convi imposes data-protection obligations on each Sub-processor by written contract and remains responsible for each Sub-processor's compliance with this DPA.
5.4 AI Sub-processors. Convi's AI Sub-processor — currently OpenAI, L.L.C. — processes conversation content solely to generate responses for the Customer's shoppers and does not use it to train or improve its own models. All AI processing is governed by this DPA; there is no separate AI addendum.
6. Personal data breach notification
Convi will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer's Personal Data, and will provide information reasonably necessary for the Customer to meet its own breach-notification obligations.
7. Data protection impact assessments
Taking into account the nature of processing and the information available, Convi will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with Supervisory Authorities (Articles 35–36 GDPR).
8. Audit rights
8.1 Convi will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, such as security documentation and, where available, third-party audit reports or certifications.
8.2 The Customer may audit Convi's compliance with this DPA once per year, on reasonable prior written notice. Where Convi makes available documentation or third-party certifications that address the Customer's questions, the Customer will rely on those in lieu of an on-site audit.
9. Data subject rights
Taking into account the nature of processing, Convi will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, objection). Where a Data Subject contacts Convi directly, Convi will refer them to the Customer.
10. Third-party and government disclosure requests
If Convi receives a legally binding request from a public authority to disclose Personal Data, Convi will, unless legally prohibited, notify the Customer and challenge requests that are unlawful or overbroad.
11. International transfers
11.1 Convi processes Personal Data in the United States (Google Cloud) and engages US-based Sub-processors. Where Convi (operating from Canada, which benefits from an EU adequacy decision for commercial organizations) transfers Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, such transfers are made under the SCCs (Module Two and/or Module Three, as applicable), together with the UK International Data Transfer Addendum and the Swiss addendum, incorporated into this DPA at Annex 4.
11.2 Convi ensures each onward transfer to a Sub-processor in such a country is likewise covered by the SCCs or the Sub-processor's own valid transfer mechanism.
12. Deletion and return; liability
12.1 On termination of the Service, Convi will delete or return the Customer's Personal Data within 90 days, except where retention is required by law, and will delete existing copies. The Customer may request earlier deletion at any time.
12.2 Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA does not limit any rights a Data Subject has under data protection law.
12.3 In the event of conflict, this DPA prevails over the Agreement with respect to processing of Personal Data; the SCCs prevail over this DPA.
Annex 1 — Details of processing
- Subject matter: provision of the Convi AI shopping-assistant Service.
- Duration: for the term of the Agreement, plus the deletion period in section 12.1.
- Nature and purpose: answering shopper questions, product discovery, order-status assistance, and related analytics, via AI processing of conversation content.
- Categories of Data Subjects: the Customer's end-shoppers and storefront visitors.
- Categories of Personal Data: conversation and chat message content; shopper name and email where provided; order details (such as order email or number) where the shopper supplies them; IP-derived geolocation (country, city, timezone — raw IP not stored); inferred conversation metadata (intent, sentiment, summary).
- Special categories: none requested or required; the Customer must not submit special-category data via the Service.
Annex 2 — Technical and organizational measures
- Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256, via Google Cloud).
- Access controls: role-based access, least privilege, and authentication for administrative access.
- Network and infrastructure security via Google Cloud Platform.
- Logging and monitoring, including error monitoring.
- Confidentiality obligations for personnel with access to Personal Data.
Annex 3 — Sub-processors
As published at conviapp.com/subprocessors, incorporated by reference.
Annex 4 — Standard Contractual Clauses
The SCCs (Commission Implementing Decision (EU) 2021/914), with Module Two (controller-to-processor) and Module Three (processor-to-processor) as applicable, together with the UK International Data Transfer Addendum and the Swiss addendum, are incorporated into this DPA by reference and apply to transfers described in section 11.