Legal
Data Processing Agreement
Version 1.0 - effective 5 August 2026 - last updated: 5 August 2026
This Data Processing Agreement (the DPA) forms part of the agreement between Convira OÜ and the customer whenever the customer uses Convira to process personal data of other people and the GDPR applies to that processing. It sets out the terms required by Article 28 GDPR. A countersigned copy is available on request at support@convira.ai.
1. Status and how this agreement applies
Drafting status. This DPA was prepared in-house by Convira OÜ and has not yet been reviewed by external counsel. It will be before the first enterprise signature. It follows the structure Article 28(3) GDPR requires and is published so a review can start from the real text rather than from an email exchange. It is not legal advice to you; if you are assessing it for your own compliance, involve your own advisers.
This DPA applies automatically, without signature, to every customer that uses the Service to process personal data of others while subject to the GDPR as a controller. It is incorporated into the Terms of Service by the reference at section 6 of the Terms. If you need an executed copy for your records, email support@convira.ai and we will countersign.
2. Parties and roles
The parties are the customer (the Controller) and Convira OÜ, Järvevana tee 9, Kesklinn, 11314 Tallinn, Estonia, registry code 17268095 (the Processor). For personal data the customer processes through the Service, the customer determines the purposes and means and Convira OÜ processes on the customer's behalf. For the customer's own account, billing, and security data, Convira OÜ is an independent controller as described in the Privacy Policy; that processing is outside this DPA.
3. Subject matter, duration, nature and purpose
The subject matter is the processing needed to provide the Convira service: running the tasks the customer starts, storing what the Service is designed to store, and transmitting content to the providers the customer's use invokes. The nature of the processing follows the product's architecture, described on the Security page: content of runs on the local runtime or a self-hosted Private Box stays on the customer's hardware; cloud run content passes through Convira's infrastructure in transit to the AI model provider and is not stored by Convira; end-to-end encrypted collaboration content is stored only in encrypted form that Convira cannot read. The purpose is providing the Service and nothing else. The duration is the term of the customer's subscription plus the wind-down period in section 12.
4. Personal data and data subjects
The customer decides, run by run, what the agent is given, so the categories of personal data and data subjects are determined by what the customer submits. They may include contact details, correspondence, documents, and any other personal data contained in the content the customer provides; data subjects may include the customer's own staff, customers, suppliers, and other people appearing in that content. The customer must not submit special categories of personal data (Article 9 GDPR) unless it has a lawful basis to process them and they are necessary for the task; the Service does not require them.
5. Processing on documented instructions
Convira OÜ processes personal data under this DPA only on the customer's documented instructions, unless EU or Estonian law requires otherwise, in which case Convira OÜ informs the customer before processing unless that law forbids it. The customer's instructions are: this DPA, the Terms of Service, the configuration the customer selects in the product, and each run the customer or its authorized users start, which is an instruction to perform that task. If Convira OÜ considers an instruction to infringe data protection law, it will inform the customer without undue delay and may suspend the instruction until it is confirmed or changed.
6. Confidentiality
Convira OÜ ensures that every person it authorizes to process personal data under this DPA is bound by a contractual or statutory duty of confidentiality that survives the end of their engagement, and that access is limited to what the person's role requires.
7. Security of processing
Convira OÜ implements and maintains the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as Article 32 GDPR requires. Convira OÜ may update those measures over time, provided the protection of personal data is not materially reduced. The current measures are published on the Security page, which is Annex II to this DPA, so there is exactly one place kept current.
8. Subprocessors
The customer gives general written authorization for the subprocessors listed at Subprocessors, which is Annex III to this DPA. Before a new subprocessor processes customer personal data, Convira OÜ updates that page and its change date at least 30 days in advance; customers who want change notices by email can request them at support@convira.ai. The customer may object to a new subprocessor on reasonable data protection grounds within that period; if the objection cannot be resolved, the customer may terminate the affected part of the Service and receives a pro-rata refund of prepaid fees for it. Convira OÜ imposes data protection obligations on each subprocessor that are materially equivalent to this DPA and remains fully liable to the customer for each subprocessor's performance.
9. Assistance with data subject rights
Taking into account the nature of the processing, Convira OÜ assists the customer with appropriate technical and organizational measures in fulfilling requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). The architecture shapes what that assistance looks like: content of runs on the local runtime or a Private Box, and the contents of cloud runs, live on the customer's hardware rather than on Convira's systems, so the customer answers those requests from its own records. For the data Convira OÜ does hold, requests to support@convira.ai are answered without undue delay, and where a request reaches Convira OÜ directly from a data subject it is forwarded to the customer rather than answered on the customer's behalf.
10. Breach notification and assistance
Convira OÜ notifies the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting customer personal data. The notice describes, to the extent then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, and is supplemented as more becomes known. Convira OÜ provides the customer reasonable assistance with the customer's obligations under Articles 33 to 36 GDPR, including data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to it.
11. International transfers
Convira OÜ is established in the EU and hosts its database and API infrastructure in the EU, as described on the subprocessors page. Some subprocessors process personal data outside the European Economic Area, in particular AI model providers in the United States. Each such transfer is covered by a Chapter V GDPR mechanism: an adequacy decision of the European Commission (including the EU-US Data Privacy Framework where the provider is certified), or the EU Standard Contractual Clauses concluded between Convira OÜ and that subprocessor with their annexes completed. Copies of the relevant transfer mechanisms are available on request at support@convira.ai.
12. Return and deletion
On termination or expiry of the Service, Convira OÜ deletes the customer personal data it holds within 90 days, unless EU or Estonian law requires longer retention, in which case the data is retained only for as long and to the extent that law requires and remains protected under this DPA. Because run content on the local runtime, on a Private Box, and of cloud runs is stored on the customer's hardware, its return does not depend on Convira OÜ: the customer already holds it. Retention periods for the categories Convira OÜ does hold are described in the Privacy Policy.
13. Audits and information rights
Convira OÜ makes available to the customer the information necessary to demonstrate compliance with Article 28 GDPR: this DPA, the published security documentation, the subprocessor list, completed security questionnaires on request, and copies of third-party assessments as they become available. Where that information is insufficient, the customer may conduct an audit, itself or through an independent auditor bound to confidentiality, no more than once per year on at least 30 days notice, during business hours, at the customer's cost, and without access to other customers' data or to information whose disclosure would itself weaken security. Findings are shared with Convira OÜ and treated as confidential.
14. Liability, term and order of precedence
This DPA starts when the customer's use of the Service brings it into effect under section 1 and lasts for as long as Convira OÜ processes customer personal data under it. Each party's liability under this DPA is subject to the exclusions and limitations in the Terms of Service, except where the GDPR does not permit them to be limited. If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of customer personal data, this DPA prevails; on everything else, the Terms prevail.
15. Annexes
- Annex I - details of the processing. Parties: as in section 2. Subject matter, nature, purpose, and duration: as in section 3. Categories of personal data and data subjects: as in section 4. Frequency: continuous, driven by the customer's use. Competent supervisory authority: the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or the authority competent for the customer under Article 56 GDPR.
- Annex II - technical and organizational measures. The measures described on the Security page, including encryption in transit and at rest, isolation of untrusted tool execution, access control, and the data-location model per runtime.
- Annex III - subprocessors. The list at Subprocessors, including what each provider does and the personal data it can process. The list has exactly one home, so it is referenced rather than duplicated here.
16. Contact
Questions about this DPA, requests for a countersigned copy, and subprocessor change notifications: support@convira.ai.
Convira OÜ
Järvevana tee 9, Kesklinn, 11314 Tallinn, Harju County, Estonia
Registry code 17268095
support@convira.ai