Data Processing Agreement

Processing on your instructions, in writing.

Incorporated by reference for every paid account, with no signature ritual required, though we'll countersign a copy if your procurement process wants one. Effective August 13, 2026.

1. Roles and scope

This DPA is part of the Terms of Service for every paid account and covers personal data Conovo processes on the customer's behalf. For that data the customer (and, where the customer is a platform, its business users) determines purposes and means, acting as the controller or business; Conovo processes only on documented instructions, as the processor or service provider. The instructions are the service itself: generate, deliver, and execute contracts as configured through the API and console, nothing more.

2. What is processed

Contract documents and templates; the field values filled into them; recipient names, email addresses, and (where phone-verified signing is used) mobile numbers; and the audit trail of contract events. Data subjects are the customer's users and the people their contracts name. The privacy policy describes each processing surface, including exactly what the AI subprocessor sees.

3. Confidentiality and personnel

Personal data is treated as the customer's confidential information. Access is limited to personnel who need it to operate the service, bound by confidentiality obligations. We never sell it, use it for advertising, or train AI models on it.

4. Subprocessors

The current list, with what each service does, is published on the security page. Account owners are notified before a new subprocessor is added and may object on reasonable data protection grounds; if we can't resolve the objection, the customer may terminate the affected service. Subprocessors are bound by data protection terms no weaker than these.

5. Security

The measures are architectural and published on the security page: tenant isolation enforced in middleware, short-lived scoped tokens, secrets hashed at rest, content-free logging by construction, TLS in transit, encryption at rest, private document storage with no public URLs, and signed webhooks. We maintain and improve these measures and won't materially weaken them during a term.

6. Breach notice

If we become aware of a personal data breach affecting the customer's data, we notify the account owner without undue delay after confirming it, with what happened, what data and data subjects are affected, and what we're doing about it, updated as we learn more. Notice is not an admission of fault.

7. Data subject requests and assistance

Requests from data subjects that reach us directly are routed to the customer within a reasonable time, because the controller decides them. The service itself is most of the assistance: contract data is exportable by API, retention is configurable per account, and the audit trail answers who-did-what questions. We provide reasonable further assistance with data protection assessments and regulator inquiries at the customer's expense where the effort is material.

8. Retention, return, and deletion

During the term, retention follows the account's configured window. On termination, the customer has 30 days to export its data by API; after that we delete personal data within a further 60 days, with one exception stated plainly: executed contracts are legal records, and their metadata and audit trails are retained so the record of execution stays reproducible for the parties. Deletion requests during the term go to privacy@conovo.co.

9. International transfers and audit

Processing happens in the United States on the infrastructure named on the security page. For customers subject to EU/UK transfer rules, standard contractual clauses are available on request and, once executed, form part of this DPA. Once per year, on reasonable notice, the customer may audit our compliance with this DPA, first through our documentation and written answers, which resolve most questions; anything further is scheduled so it doesn't put other tenants' data at risk.

10. Precedence and changes

If this DPA conflicts with the Terms of Service on a data protection question, this DPA wins. Changes follow the same rule as the terms: account owners get notice of material changes before they take effect. Effective August 13, 2026.

Data Processing Agreement | Conovo