1. Who we are

Converxio is a product operated by IADS Solutions LLC, a limited liability company incorporated in the State of Florida, United States. For the purposes of this policy, "the Service" refers to the conversational CRM platform over WhatsApp and the related tools we offer to businesses to answer, qualify, book and follow up with their customers on WhatsApp with the support of artificial intelligence.

2. What personal data do we process?

2.1 Data of our customers (the businesses that contract the Service)

  • Trade name and legal entity name.
  • Corporate email, phone and address.
  • Billing data (tax ID — NIT / CIF / RUT / RFC / CUIT, etc.).
  • Access credentials (email + password stored with bcrypt hashing; never in plain text).
  • Service usage data (logs, IP addresses, login dates).
  • Payment data, processed by our payment gateways. We do not store card numbers.

2.2 Data of end contacts (our customers' customers)

When our customer connects their WhatsApp Business number to Converxio, we process:

  • The end contact's phone number.
  • WhatsApp name and profile data.
  • The content of the messages exchanged.
  • Attached media (images, documents, audio).
  • Tags, notes and custom fields the customer assigns.
Important: regarding end contacts' data, Converxio acts as Data Processor. The Data Controller is our customer. The customer warrants that it has the legal basis and consents required to communicate with its contacts and that its use of the Service complies with WhatsApp's and Meta's policies. We process end contacts' data solely on the customer's instructions.

3. What do we use the data for?

PurposeLegal basis
Providing the Service (operation of the CRM and the AI agent)Performance of a contract
Billing and collectionLegal and contractual obligation
Technical support to the customerPerformance of a contract
Operating and improving the Service (aggregated, anonymized metadata only — see §3.1)Legitimate interest
Operational communications (changes, maintenance)Performance of a contract
Our own marketing (newsletters)Consent (opt-in)
Compliance with legal and tax obligationsLegal obligation

We do not sell or transfer personal data to third parties for commercial purposes.

3.1 Aggregated learning and AI models

To operate and improve the Service we may generate aggregated, anonymized statistics and learnings (for example, which kinds of responses work best in a given sector). To do so we use aggregated metadata and outcomes only: never the content of messages, nor data that identifies your business or the end contacts. Each customer's content remains isolated by tenant_id through Row Level Security and is not cross-referenced or shared with other customers' content.

The AI model providers we use process the data solely to generate the requested response and, under their enterprise terms of service, do not use it to train their foundation models.

4. Who do we share the data with?

We share data only with the strictly necessary providers to operate the Service (sub-processors), all bound by data processing agreements (DPA) and selected for their security safeguards. We group them by function:

Provider categoryFunctionRegionSafeguard
Cloud infrastructureDatabase, storage and hosting, with isolation by tenant_id through Row Level SecurityEU / USADPA
WhatsApp messagingConnection to Meta's WhatsApp Business Cloud API through an authorized Meta Tech ProviderUSA / globalDPA — accepted by the customer when connecting their WhatsApp
Artificial intelligence modelsGeneration of the conversational agent's responsesUSADPA — they do not train their models on Service data (see §3.1)
BackupsEncrypted offsite backupsUSADPA
Payment gatewayPayment processing (we do not store card numbers)By regionPCI-DSS

We keep the named, up-to-date list of sub-processors available to our customers in the data processing agreement (DPA) and on request at support@converxio.app. Customers may object, on reasonable grounds, to the addition of a new sub-processor.

International transfers: some providers operate outside the customer's country. These transfers are covered by standard contractual clauses (SCC) and/or adequacy decisions under the applicable jurisdiction.

5. How long do we keep the data?

Data typeRetention period
Customer account (while active)For the duration of the contract + 5 years after cancellation (tax obligation)
WhatsApp conversationsDecided by the customer. Default: 1 year from the last message
Audit logs1 year
Backups30 days offsite
Billing data5 years (tax obligation)
Data of a contact who requested deletionDeleted within a maximum of 30 days after the request

Once the periods elapse, the data is deleted or anonymized.

6. What rights do you have?

In accordance with the LGPD (Brazil), the GDPR (EU), Law 1581 (Colombia) and equivalent laws in the region, you have the right to:

  • Access — know what data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure ("right to be forgotten") — request that we delete your data.
  • Portability — receive your data in a structured format (JSON).
  • Objection — object to a processing activity.
  • Restriction — request that we only store the data without actively processing it.
  • Withdrawal of consent — withdraw permissions granted previously.
  • Complaint to the authority — ANPD (Brazil), SIC (Colombia), AEPD (Spain), etc.

How to exercise them

Write to us at support@converxio.app from your registered email. If you are an active customer, you can also:

  • Export your data: Settings → My account → Download my data.
  • Delete your account: Settings → My account → Request deletion.

Response times: 15 calendar days (LGPD, Brazil) and 30 calendar days (Colombia, GDPR). If we do not respond in time, you may file a complaint with the relevant authority.

7. Security

We apply, at a minimum, the following technical measures:

  • Encryption in transit: TLS 1.2+ on all connections.
  • Encryption at rest: cloud provider encryption + additional encryption of sensitive tokens.
  • Password hashing: bcrypt.
  • Access control: Row Level Security by tenant_id and the principle of least privilege.
  • Backups: encrypted offsite with 30-day retention.
  • Monitoring: availability and access auditing.
  • Incident response: notification to the customer without undue delay (see section 8).

No security measure is infallible. We apply safeguards appropriate to the risk, but we cannot guarantee absolute security against unauthorized access. We commit to acting diligently and to notifying incidents in accordance with section 8.

8. Incident notification

If we detect a breach affecting your data:

  1. We will notify you by email without undue delay once the scope is confirmed.
  2. We will notify the relevant data protection authority where the law requires it and within the applicable legal deadline (in the EU, 72 hours).
  3. We will inform you of the scope, the mitigation and the next steps.

9. Minors

The Service is not directed at people under 18 and we do not knowingly collect their data. If we discover that we have received a minor's data without parental consent, we delete it. If our customers use the Service to communicate with minors, it is the customer's sole responsibility to obtain the parental consent required by their jurisdiction.

10. Cookies

The details are in our Cookie Policy. In short:

  • Essential (session, security, language preference): always on.
  • Analytics (aggregated product usage): opt-in.
  • Marketing (re-targeting): opt-in.

11. Changes to this policy

We will notify substantial changes by email with 15 days' notice. Minor changes (corrections or clarifications) are published directly; you can always see the "Last updated" date at the top.

12. Jurisdiction and governing law

IADS Solutions LLC is a US company. This policy is governed by the laws of the State of Florida, United States, and any dispute will be submitted to the competent courts of Miami-Dade County, Florida.

Notwithstanding the above, we respect the rights granted to the customer by the data protection law of their country. In particular:

  • Customer in the EU / Spain: GDPR (Regulation 2016/679).
  • Customer in Colombia: Law 1581 of 2012 + Decree 1377 of 2013.
  • Customer in Chile: Law 19,628 + Law 21,719.
  • Customer in Mexico: Federal Law on the Protection of Personal Data Held by Private Parties.
  • Customer or contact in California (USA): CCPA / CPRA — the right to know, access, correct and delete your data, and not to have your personal data sold (we do not sell personal data).
  • Customer in other countries: the applicable local law, with this policy as a minimum standard.

13. Contact

For any matter related to your personal data (access, rectification, deletion, etc.) or this policy, write to us at:

This is an English translation provided for convenience. The Spanish version (Política de Privacidad) prevails in the event of any discrepancy.