Version: 1.1
Effective Date: March 28, 2026
Last Updated: March 28, 2026
This Data Processing Agreement (“DPA”) frames standard personal data processes executing within Convertr properties, notably where:
pursuant to EU GDPR requirements facilitating Service operations.
Convertr hosts interactions enabling Platforms and configurations such as:
Information stays active concurrently corresponding to duration requirements linked inherently to terms execution along applicable post-contract handover windows. Disposals stand conditioned to:
Relevant Customer inputs comprise likely items spanning:
Deliberate gathering of specialized sensitive categories breaks fundamental standards without explicit self-directed compliance buffers strictly borne by Customers.
Targeted cohorts consistently wrap the core prospects, potential clientele, or leads targeted independently via Customer operations.
Convertr processes personal data only based on documented Customer operations. Such actions correlate closely with:
Whenever Convertr suspects explicit processing commands contravening regulations, prompt clarification requests suspend controversial actions pending clear justification or rectification.
Authorized personnel accessing required systems remain explicitly restricted beneath secure protocols enforcing confidentiality laws continuously minimizing exposure solely around technical dependencies.
Consistent protections reflecting modernized feasibility bounds map defensive layers proportionately countering vulnerabilities targeting data handling environments.
Typical alignments comprise notably:
Real-world strength strictly correlates around engaged modules alongside integrations linked remotely.
Convertr supplies proportionate tooling empowering organizational obligations addressing standard regulatory checks, featuring prominently:
Customers agree explicitly towards listed external service branches featured in Annex 2 governing the backend mechanics.
Operational reliance ties downstream partnerships firmly around synchronized data protection criteria mirroring main expectations where applicable.
Convertr assumes proportionate accountability regarding subprocessor interactions mirroring contractual guardrails limiting unexpected liabilities.
Convertr communicates substantive ecosystem evolutions impacting engaged subprocessors within a fair margin beforehand.
Valid disputes trigger dialogue assessing substitute workflows minimizing reliance vulnerabilities or enabling seamless compartmentalized exits.
Deployments crossing EEA lines maintain approved safety assurances leveraging applicable decisions alongside supplemental contracts enforcing local integrities rigorously.
Convertr commits swift notification dispatching upon discovering data integrity faults outlining accessible intelligence maximizing responsive mitigation alongside regulatory compliance routines led effectively by the Customer.
Termination sequences naturally launch processes addressing Customer files utilizing feasible export utilities throughout reversible stages followed shortly by:
Convertr assists structural inquiries documenting foundational conformances facilitating reasonable audits constrained yearly limiting operational hindrances extensively preferring documented oversight primarily unless circumstances mandate critical procedural testing.
Version: 1.1
Effective Date: March 28, 2026
| Provider | Location | Role |
|---|---|---|
| Vercel | EU / US | Hosting convertr.fr landing page and app.convertr.fr dashboard |
| Railway | US | API backend hosting, PostgreSQL database, and Redis caching |
| Provider | Location | Role |
|---|---|---|
| Cloudflare R2 | Depending on region | Files, documents, and creative advertising media storage |
| Provider | Location | Role |
|---|---|---|
| Twilio | US | Sending SMS and providing connected communication services, upon activation |
| Retell AI | US | Voice AI, call handling and transcription, upon activation |
| Provider | Location | Role |
|---|---|---|
| Resend | US | Dispatching automated transactional emails (password reset, reports, confirmations) |
| Provider | Location | Role |
|---|---|---|
| OpenAI | Provider's infrastructure | Generation and logic routing operations dynamically applied based on automated n8n workflows |
| Anthropic | Provider's infrastructure | |
| Mistral | Provider's infrastructure | |
| Google Gemini | Provider's infrastructure |
| Provider | Location | Role |
|---|---|---|
| Mr. Adel BELGROUN (EI) SIREN : 999 268 105 | France / EU | Initial setup, onboarding, integration assistance, guided oversight, troubleshooting maintenance, and potential ad performance tracking if scoped |
| Provider | Role |
|---|---|
| Meta (Facebook / Instagram Ads) | Syncing campaigns and ingesting leads if activated by Customer |
| Google Ads | Syncing campaigns, metrics, and mapped inputs if activated by Customer |
| Provider | Role |
|---|---|
| Google Calendar | Synchronizing meetings via OAuth, directly upon authorization |
| Microsoft Outlook Calendar / Microsoft Graph | Synchronizing meetings via OAuth, directly upon authorization |
The n8n framework runs fundamentally to power localized routing automation.
Maintained directly and operated entirely privately, n8n functions solely as systemic infrastructure, lacking independent vendor classification.