1. Who we are
Converxio is a product operated by IADS Solutions LLC, a limited liability company incorporated in the State of Florida, United States. For the purposes of this policy, "the Service" refers to the conversational CRM platform over WhatsApp and the related tools we offer to businesses to answer, qualify, book and follow up with their customers on WhatsApp with the support of artificial intelligence.
- Legal entity: IADS Solutions LLC
- Registered address: 8325 NE 2nd Ave, Suite 349, Miami, FL 33138, USA
- Website: https://converxio.app
- Application: https://app.converxio.app
- Contact email: support@converxio.app
- Phone: +1 786 852 5626
2. What personal data do we process?
2.1 Data of our customers (the businesses that contract the Service)
- Trade name and legal entity name.
- Corporate email, phone and address.
- Billing data (tax ID — NIT / CIF / RUT / RFC / CUIT, etc.).
- Access credentials (email + password stored with bcrypt hashing; never in plain text).
- Service usage data (logs, IP addresses, login dates).
- Payment data, processed by our payment gateways. We do not store card numbers.
2.2 Data of end contacts (our customers' customers)
When our customer connects their WhatsApp Business number to Converxio, we process:
- The end contact's phone number.
- WhatsApp name and profile data.
- The content of the messages exchanged.
- Attached media (images, documents, audio).
- Tags, notes and custom fields the customer assigns.
3. What do we use the data for?
| Purpose | Legal basis |
|---|---|
| Providing the Service (operation of the CRM and the AI agent) | Performance of a contract |
| Billing and collection | Legal and contractual obligation |
| Technical support to the customer | Performance of a contract |
| Operating and improving the Service (aggregated, anonymized metadata only — see §3.1) | Legitimate interest |
| Operational communications (changes, maintenance) | Performance of a contract |
| Our own marketing (newsletters) | Consent (opt-in) |
| Compliance with legal and tax obligations | Legal obligation |
We do not sell or transfer personal data to third parties for commercial purposes.
3.1 Aggregated learning and AI models
To operate and improve the Service we may generate aggregated, anonymized statistics and learnings (for example, which kinds of responses work best in a given sector). To do so we use aggregated metadata and outcomes only: never the content of messages, nor data that identifies your business or the end contacts. Each customer's content remains isolated by tenant_id through Row Level Security and is not cross-referenced or shared with other customers' content.
The AI model providers we use process the data solely to generate the requested response and, under their enterprise terms of service, do not use it to train their foundation models.
4. Who do we share the data with?
We share data only with the strictly necessary providers to operate the Service (sub-processors), all bound by data processing agreements (DPA) and selected for their security safeguards. We group them by function:
| Provider category | Function | Region | Safeguard |
|---|---|---|---|
| Cloud infrastructure | Database, storage and hosting, with isolation by tenant_id through Row Level Security | EU / USA | DPA |
| WhatsApp messaging | Connection to Meta's WhatsApp Business Cloud API through an authorized Meta Tech Provider | USA / global | DPA — accepted by the customer when connecting their WhatsApp |
| Artificial intelligence models | Generation of the conversational agent's responses | USA | DPA — they do not train their models on Service data (see §3.1) |
| Backups | Encrypted offsite backups | USA | DPA |
| Payment gateway | Payment processing (we do not store card numbers) | By region | PCI-DSS |
We keep the named, up-to-date list of sub-processors available to our customers in the data processing agreement (DPA) and on request at support@converxio.app. Customers may object, on reasonable grounds, to the addition of a new sub-processor.
International transfers: some providers operate outside the customer's country. These transfers are covered by standard contractual clauses (SCC) and/or adequacy decisions under the applicable jurisdiction.
5. How long do we keep the data?
| Data type | Retention period |
|---|---|
| Customer account (while active) | For the duration of the contract + 5 years after cancellation (tax obligation) |
| WhatsApp conversations | Decided by the customer. Default: 1 year from the last message |
| Audit logs | 1 year |
| Backups | 30 days offsite |
| Billing data | 5 years (tax obligation) |
| Data of a contact who requested deletion | Deleted within a maximum of 30 days after the request |
Once the periods elapse, the data is deleted or anonymized.
6. What rights do you have?
In accordance with the LGPD (Brazil), the GDPR (EU), Law 1581 (Colombia) and equivalent laws in the region, you have the right to:
- Access — know what data we hold about you.
- Rectification — correct inaccurate data.
- Erasure ("right to be forgotten") — request that we delete your data.
- Portability — receive your data in a structured format (JSON).
- Objection — object to a processing activity.
- Restriction — request that we only store the data without actively processing it.
- Withdrawal of consent — withdraw permissions granted previously.
- Complaint to the authority — ANPD (Brazil), SIC (Colombia), AEPD (Spain), etc.
How to exercise them
Write to us at support@converxio.app from your registered email. If you are an active customer, you can also:
- Export your data: Settings → My account → Download my data.
- Delete your account: Settings → My account → Request deletion.
Response times: 15 calendar days (LGPD, Brazil) and 30 calendar days (Colombia, GDPR). If we do not respond in time, you may file a complaint with the relevant authority.
7. Security
We apply, at a minimum, the following technical measures:
- Encryption in transit: TLS 1.2+ on all connections.
- Encryption at rest: cloud provider encryption + additional encryption of sensitive tokens.
- Password hashing: bcrypt.
- Access control: Row Level Security by
tenant_idand the principle of least privilege. - Backups: encrypted offsite with 30-day retention.
- Monitoring: availability and access auditing.
- Incident response: notification to the customer without undue delay (see section 8).
No security measure is infallible. We apply safeguards appropriate to the risk, but we cannot guarantee absolute security against unauthorized access. We commit to acting diligently and to notifying incidents in accordance with section 8.
8. Incident notification
If we detect a breach affecting your data:
- We will notify you by email without undue delay once the scope is confirmed.
- We will notify the relevant data protection authority where the law requires it and within the applicable legal deadline (in the EU, 72 hours).
- We will inform you of the scope, the mitigation and the next steps.
9. Minors
The Service is not directed at people under 18 and we do not knowingly collect their data. If we discover that we have received a minor's data without parental consent, we delete it. If our customers use the Service to communicate with minors, it is the customer's sole responsibility to obtain the parental consent required by their jurisdiction.
10. Cookies
The details are in our Cookie Policy. In short:
- Essential (session, security, language preference): always on.
- Analytics (aggregated product usage): opt-in.
- Marketing (re-targeting): opt-in.
11. Changes to this policy
We will notify substantial changes by email with 15 days' notice. Minor changes (corrections or clarifications) are published directly; you can always see the "Last updated" date at the top.
12. Jurisdiction and governing law
IADS Solutions LLC is a US company. This policy is governed by the laws of the State of Florida, United States, and any dispute will be submitted to the competent courts of Miami-Dade County, Florida.
Notwithstanding the above, we respect the rights granted to the customer by the data protection law of their country. In particular:
- Customer in the EU / Spain: GDPR (Regulation 2016/679).
- Customer in Colombia: Law 1581 of 2012 + Decree 1377 of 2013.
- Customer in Chile: Law 19,628 + Law 21,719.
- Customer in Mexico: Federal Law on the Protection of Personal Data Held by Private Parties.
- Customer or contact in California (USA): CCPA / CPRA — the right to know, access, correct and delete your data, and not to have your personal data sold (we do not sell personal data).
- Customer in other countries: the applicable local law, with this policy as a minimum standard.
13. Contact
For any matter related to your personal data (access, rectification, deletion, etc.) or this policy, write to us at:
- Email: support@converxio.app
- Phone: +1 786 852 5626
- Address: IADS Solutions LLC — 8325 NE 2nd Ave, Suite 349, Miami, FL 33138, USA.
This is an English translation provided for convenience. The Spanish version (Política de Privacidad) prevails in the event of any discrepancy.