This Data Processing Addendum, including its Annexes and the Standard Contractual Clauses (the “DPA”), forms part of the Convoy Master SaaS Subscription Agreement, or any other written agreement governing Customer's use of the Convoy hosted service (the “ Agreement”), between the entity identified as the “Customer” and Convoy AI Inc. (“Convoy”). It applies solely to the extent Convoy Processes Customer Personal Data in connection with the Service. By entering into the Agreement or this DPA, Customer enters into this DPA on behalf of itself and, to the extent required by Applicable Data Protection Laws, in the name and on behalf of its Authorized Affiliates. Capitalized terms not defined in this DPA have the meaning given in the Agreement. For purposes of this DPA only, “Customer” includes Customer and its Authorized Affiliates.
1. Definitions
1.1 “Applicable Data Protection Laws” means all data protection and privacy laws applicable to a party in its role in Processing Customer Personal Data under the Agreement, which may include, to the extent applicable, the European Data Protection Laws and the CCPA.
1.2 “Authorized Affiliate” means a Customer Affiliate authorized to use the Service under the Agreement that has not signed its own agreement with Convoy.
1.3 “CCPA” means the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100 et seq.), as amended (including by the California Privacy Rights Act), and its implementing regulations.
1.4 “Customer Data” has the meaning in the Agreement and includes Inputs, Outputs, and other data Customer Processes through the Service.
1.5 “Customer Personal Data” means any personal data or personal information (as defined under Applicable Data Protection Laws) contained within Customer Data and Processed by Convoy on Customer's behalf.
1.6 “European Data Protection Laws” means (a) Regulation 2016/679 (the “EU GDPR”); (b) the EU GDPR as incorporated into United Kingdom law (the “UK GDPR”); and (c) the Swiss Federal Act on Data Protection (the “Swiss DPA”); in each case as amended, superseded, or replaced.
1.7 “Inputs” and “Outputs” have the meanings given in the Agreement.
1.8 “Model Providers” has the meaning in the Agreement. Model Providers engaged to Process Customer Personal Data are Subprocessors under this DPA.
1.9 “Restricted Transfer” means a transfer of Customer Personal Data subject to European Data Protection Laws to a country outside the European Economic Area, the United Kingdom, or Switzerland that is not subject to an adequacy determination.
1.10 “Security Addendum” means Convoy's then-current security addendum describing its technical and organizational measures, available on request at contact@cnvy.aiand summarized in Annex C. Until a Security Addendum is published, Annex C is the controlling description of Convoy's technical and organizational measures.
1.11 “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by Convoy.
1.12 “Service” has the meaning in the Agreement.
1.13 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to EU Commission Implementing Decision 2021/914 of 4 June 2021, as amended.
1.14 “Subprocessor” means any processor engaged by Convoy to Process Customer Personal Data, including Model Providers and infrastructure providers.
1.15 “UK Addendum” means the International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018, as amended.
1.16 The terms “controller”, “data subject”, “supervisory authority”, “processor”, “process/processing”, “ personal data”, and “personal information” have the meanings in Applicable Data Protection Laws. The term “controller” includes “business”; “data subject” includes “consumer”; and “processor” includes “service provider” (in each case as defined by the CCPA).
2. Processing of Personal Data
2.1 Scope and Roles. This DPA applies when Convoy Processes Customer Personal Data as a processor in providing the Service to Customer, who acts as either a controller or a processor, as applicable, of Customer Personal Data.
2.2 Customer Processing. Customer agrees that (i) it will comply with its obligations under Applicable Data Protection Laws in Processing Customer Personal Data and in any instructions it issues to Convoy; and (ii) it has provided notice and obtained (or will obtain) all consents, rights, and lawful bases necessary for Convoy to Process Customer Personal Data and to submit Inputs to Model Providers in providing the Service.
2.3 Convoy Processing.When Convoy Processes Customer Personal Data as a processor on Customer's behalf, Convoy will (i) comply with Applicable Data Protection Laws applicable to it as a processor, and (ii) Process Customer Personal Data only in accordance with Customer's documented instructions, which consist of the Agreement, this DPA, and Customer's and its Authorized Users' use and configuration of the Service. Customer's documented instructions include Convoy's receipt, queuing, batching, transmission, and submission of Inputs to Model Providers for processing, and the return of Outputs. Convoy is not responsible for determining whether Customer's instructions comply with applicable law, but will notify Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws. Customer acknowledges that Customer Personal Data is Processed on an automated basis through the Service and Model Providers and that Convoy does not monitor or review the content of Inputs or Outputs.
2.4 Restricted Use; No Model Training.Convoy will not (i) sell or share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than providing the Service and the purposes set out in this DPA and the Agreement; or (iii) use the content of Customer Personal Data to train Convoy's or any third party's foundation or machine-learning models. Convoy may use Usage Data and aggregated or de-identified data that does not identify Customer or any individual, as permitted by the Agreement. Where a Model Provider offers a setting or commitment against training on submitted data, Convoy will use commercially reasonable efforts to enable or pass through that setting.
2.5 Details of Processing. The subject matter, nature, and purpose of the Processing, the duration, the categories of data subjects, and the types of Customer Personal Data are set out in Annex A.
3. Confidentiality
3.1 Personnel. Convoy will ensure that any personnel it authorizes to Process Customer Personal Data are subject to an appropriate duty of confidentiality.
4. Subprocessing
4.1 Authorization. Customer provides Convoy a general authorization to engage Subprocessors to Process Customer Personal Data in accordance with this Section, including Model Providers and the Subprocessors listed on the Subprocessor List(the “Subprocessor List”).
4.2 Subprocessor Obligations.Convoy will (i) enter into a written agreement with each Subprocessor imposing data-protection and security obligations no less protective than those in this DPA; and (ii) remain liable for each Subprocessor's acts and omissions to the same extent Convoy would be liable if performing the services directly.
4.3 Subprocessor Changes. Convoy will update the Subprocessor List and notify Customer (via the mechanism indicated on the Subprocessor List) at least thirty (30) days before authorizing a new Subprocessor to Process Customer Personal Data; provided that Convoy may add or replace a Model Provider on shorter notice where reasonably necessary to maintain the Service, with notice as soon as practicable.
4.4 Subprocessor Objections. Customer may object to a new Subprocessor on reasonable grounds relating to data protection by notifying Convoy in writing within ten (10) days after notice under Section 4.3. The parties will discuss the objection in good faith. If not resolved within thirty (30) days, Customer may, as its sole and exclusive remedy, terminate the affected Order Form(s) with respect to the features that cannot be provided without the Subprocessor, and Convoy will provide a pro rata refund of any prepaid, unused fees for the terminated portion. Customer acknowledges that objecting to a Model Provider integral to the Service may prevent Convoy from providing the Service.
5. Assistance
5.1 Data Subject Requests.Taking into account the nature of the Processing, Convoy will provide controls within the Service and/or reasonable assistance to enable Customer to respond to a data subject request (“DSR”). If Convoy receives a DSR relating to Customer Personal Data, Convoy will, unless legally compelled, promptly forward it to Customer and will not respond except to refer the data subject to Customer.
5.2 Data Protection Impact Assessments. Convoy will provide reasonably requested information to enable Customer to carry out data protection impact assessments and related consultations with supervisory authorities required by Applicable Data Protection Laws, to the extent Customer does not otherwise have access to the relevant information.
5.3 Legal Requests. If Convoy receives a subpoena, court order, warrant, or other legal demand from a public or judicial authority seeking Customer Personal Data, Convoy will attempt to redirect the authority to Customer and, where compelled to disclose, will give Customer reasonable prior notice to allow Customer to seek a protective order, unless legally prohibited.
6. Security
6.1 Security Measures. Convoy has implemented and will maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in the Security Addendum and summarized in Annex C. Convoy may update its measures, provided that the updates do not materially diminish the overall security of Customer Personal Data or the Service.
6.2 Security Breach Notification. On becoming aware of a Security Incident, Convoy will (a) notify Customer without undue delay and in no event later than seventy-two (72) hours after becoming aware; and (b) promptly take reasonable steps to contain, investigate, and mitigate the Security Incident. Convoy will reasonably cooperate with and assist Customer regarding any required notifications to supervisory authorities or data subjects, taking into account the nature of the Processing and the information available to Convoy.
7. Audits and Records
7.1 Audit Program.On written request and at no additional cost, Convoy will make available documentation evidencing its compliance with this DPA in the form of the audits or certifications it maintains (for example, SOC 2 Type II or ISO/IEC 27001), performed at least annually by independent third-party security professionals (each, an “Audit Report”).
7.2 Audit.Only to the extent Customer cannot reasonably verify Convoy's compliance through the Audit Reports, or where required by Applicable Data Protection Laws, Customer may request to audit Convoy's applicable controls on an annual basis. The parties will mutually agree the reasonable start date, scope, duration, and security and confidentiality controls for any audit. The Audit Report and any audit results are Convoy's Confidential Information and may be shared with a third party only with Convoy's prior written agreement.
8. Transfer of Personal Data
8.1 Restricted Transfers. Where the transfer of Customer Personal Data to Convoy is a Restricted Transfer, it is governed by the Standard Contractual Clauses, which are deemed incorporated into and completed in accordance with Annex B.
8.2 Alternative Transfer Mechanisms. If a court or supervisory authority of competent jurisdiction with binding authority determines that the measures in this DPA cannot be relied on to lawfully transfer Customer Personal Data, the parties will reasonably cooperate to implement an alternative transfer mechanism. If Convoy adopts an alternative mechanism (including any successor framework), it will apply instead of the SCCs to the extent it complies with European Data Protection Laws and extends to the relevant territories.
9. Retention, Deletion, and Return
9.1 Retention. Convoy will retain queued Inputs, Outputs, and other Customer Personal Data only as long as reasonably necessary to provide the Service and as described in the Agreement, the Documentation, and this DPA.
9.2 Deletion. The Service includes controls Customer may use during the term to delete Customer Personal Data. Subject to the Agreement, Convoy will delete Customer Personal Data when Customer uses such controls to instruct deletion.
9.3 Termination.On expiration or termination of the Agreement and following Customer's written request made within thirty (30) days, Convoy will delete or return Customer Personal Data within its possession or control, and delete existing copies (including from backups on Convoy's standard cycle), except to the extent retention is required by law.
10. CCPA Compliance
10.1 The parties acknowledge that Convoy Processes Customer Personal Data as a “service provider.” Convoy will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, including outside the direct business relationship between the parties; or (c) combine Customer Personal Data with personal information obtained from other sources except as permitted by the CCPA. Convoy certifies that it understands and will comply with these restrictions and will notify Customer if it determines that it can no longer meet its obligations under the CCPA. Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.
11. General
11.1 This DPA replaces any prior data processing addendum between the parties relating to the Service. Convoy may update this DPA from time to time, with the updated version posted at this page or a successor site, provided that no update materially diminishes the privacy or security of Customer Personal Data.
11.2 If any part of this DPA is held unenforceable, the validity of the remaining parts is not affected.
11.3 Convoy's obligations extend to Authorized Affiliates, subject to: (a) Customer is solely responsible for communicating instructions on behalf of, and for the compliance of, its Authorized Affiliates; and (b) any Authorized Affiliate claim must be brought by Customer on the Affiliate's behalf, unless Applicable Data Protection Laws require otherwise, and is subject to the liability limitations in the Agreement, including any aggregate cap.
11.4 In a conflict between this DPA and the data-privacy provisions of any agreement between the parties relating to the Service, this DPA prevails; provided that, to the extent the SCCs conflict with any provision of this DPA, the SCCs control. If the parties enter a Business Associate Agreement (“BAA”), the BAA prevails solely with respect to PHI (as defined therein); the Service is not intended for PHI absent such a BAA and the Agreement.
11.5 To the maximum extent permitted by law, each party's liability arising out of or related to this DPA (including the Annexes and the SCCs), whether in contract, tort, or otherwise, remains subject to the limitation-of-liability section of the Agreement, and any reference to a party's liability means the aggregate liability of that party and its Affiliates under the Agreement and this DPA. Any regulatory penalties incurred by Convoy that arise from Customer's failure to comply with its obligations reduce Convoy's liability under the Agreement as if those penalties were liabilities to Customer.
11.6 This DPA is governed by the governing-law and jurisdiction provisions of the Agreement, unless Applicable Data Protection Laws require otherwise.
11.7 The obligations under this DPA and the Standard Contractual Clauses survive for as long as Convoy Processes Customer Personal Data on Customer's behalf.
Annex A — Description of the Processing / Transfer
List of Parties
Data exporter:The entity identified as the “Customer” in the Agreement and this DPA. Contact details: those associated with Customer's Convoy account or as specified in the Agreement. Role: Controller (SCC Module 2) or Processor (SCC Module 3).
Data importer: Convoy AI Inc. Contact: contact@cnvy.ai. Role: Processor.
Description of the Processing / Transfer
Categories of data subjects:Individuals whose personal data is included in Inputs or Outputs submitted to or generated through the Service at Customer's direction, which may include Customer's contacts, prospects, customers, business partners, vendors, and employees or agents (who are natural persons), Customer's Authorized Users and End Users, and any other individuals whose personal data is contained in Customer Data.
Categories of personal data: The types of Customer Personal Data are determined and controlled by Customer in its sole discretion and may include name, contact details, identifiers, and any other personal data contained in the Inputs Customer submits to the Service and the resulting Outputs.
Sensitive data: Subject to the restrictions in the Agreement (which prohibit submitting protected health information, payment-card data, or government-classified information absent a written addendum), Customer determines and controls whether any special categories of personal data are submitted.
Frequency of the transfer:Continuous or one-off, depending on Customer's use of the Service.
Nature, subject matter, and duration: Nature: hosting, storage, queuing, batching, transmission, and submission of Inputs to Model Providers for artificial-intelligence and large-language-model processing, the return of Outputs, and related support. Subject matter: Customer Personal Data within Inputs and Outputs. Duration: the term of the Agreement and any post-term period during which Convoy Processes Customer Personal Data.
Purposes:To provide, secure, support, and meter the Service in accordance with the Agreement and Customer's documented instructions (including processing initiated by Authorized Users), and as otherwise documented and agreed by the parties.
Retention period: For the term of the Agreement and any post-term period during which Convoy Processes Customer Personal Data, after which Customer Personal Data is deleted in accordance with Section 9.
Competent Supervisory Authority
Determined in accordance with the EU GDPR by reference to Customer's place of establishment or its EU representative, as applicable.
Annex B — Standard Contractual Clauses (Modules 2 and 3)
Subject to Section 8.1, where the transfer of Customer Personal Data to Convoy is a Restricted Transfer and Applicable Data Protection Laws require appropriate safeguards, the transfer is governed by the SCCs, deemed incorporated into and forming part of this DPA as follows:
(a) Transfers protected by the EU GDPR
- Module Two applies where Customer is the controller of Customer Personal Data, and Module Three applies where Customer is the processor of Customer Personal Data;
- in Clause 7, the optional docking clause applies, and Authorized Affiliates may accede to the SCCs on the same terms as Customer, subject to mutual agreement;
- in Clause 9, Option 2 (general written authorization) applies, with the process and notice period for Subprocessor changes set out in Section 4.3;
- in Clause 11, the optional independent-dispute-resolution language does not apply;
- in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland;
- in Clause 18(b), disputes are resolved before the courts of Ireland;
- Annex I to the SCCs is completed with the information in Annex A to this DPA; and
- Annex II to the SCCs is completed with the information in the Security Addendum and Annex C, subject to Section 6.1.
(b) Transfers protected by the UK GDPR
The SCCs implemented under paragraph (a) apply as modified by the UK Addendum, which is incorporated into this DPA. Tables 1–3 in Part 1 of the UK Addendum are completed with the information in Annex A and Annex C, and Table 4 is completed by selecting “neither party.” Any conflict between the SCCs and the UK Addendum is resolved per the UK Addendum.
(c) Transfers protected by the Swiss DPA
The SCCs implemented under paragraph (a) apply with the following modifications: references to “Regulation (EU) 2016/679” are interpreted as references to the Swiss DPA; references to “EU,” “Union,” and “Member State” are replaced with “Switzerland”; references to the “competent supervisory authority” and “competent courts” are replaced with the “Swiss Federal Data Protection and Information Commissioner” and the “applicable courts of Switzerland”; the SCCs are governed by Swiss law; and disputes are resolved before the competent Swiss courts.
(d) Interpretive provisions
Where the SCCs apply, the parties agree the following interpretations; a party complying with them is deemed to comply with the corresponding SCC obligation:
- where Customer is itself a processor acting on behalf of a third-party controller and Convoy would otherwise be required to interact directly with that controller, Convoy may interact solely with Customer, and Customer is responsible for forwarding necessary notifications to and obtaining necessary authorizations from that controller;
- the certification of deletion described in Clause 16(d) of the SCCs will be provided by Convoy to Customer on Customer's written request;
- for purposes of Clause 15(1)(a), Convoy will notify Customer (and not the relevant data subjects) of any government access request, and Customer is solely responsible for notifying data subjects as necessary;
- taking into account the nature of the Processing, Customer agrees that it is unlikely Convoy will become aware that Customer Personal Data is inaccurate or outdated; to the extent Convoy does become aware, it will inform Customer in accordance with Clause 8.4; and
- Customer acknowledges that the Service Processes Customer Personal Data on an automated basis and that Convoy does not monitor or control the content of Inputs or Outputs or the independent data-processing practices of Model Providers.
Annex C — Technical and Organizational Security Measures
This Annex summarizes the technical and organizational measures Convoy maintains. If Convoy has published a Security Addendum (available on request at contact@cnvy.ai), that Security Addendum is the controlling description as provided in Section 1.10; otherwise, this Annex C controls.
| Measure | Description |
|---|---|
| Access control | Role-based access controls, unique credentials, multi-factor authentication for administrative access, and least-privilege provisioning and periodic access reviews. |
| Encryption | Encryption of Customer Personal Data in transit and at rest using industry-standard protocols, including for data queued and transmitted to Model Providers. |
| Tenant segregation | Logical separation of each customer's data in the multi-tenant environment to prevent unauthorized access by other customers. |
| Network and application security | Firewalls, intrusion detection/prevention, vulnerability scanning, secure development practices, and periodic penetration testing. |
| Logging and monitoring | Audit logging of access to and Processing of Customer Personal Data, and monitoring for anomalous activity. |
| Resilience and continuity | Backup, redundancy, and disaster-recovery measures appropriate to the Service. |
| Vendor and Subprocessor management | Diligence and contractual data-protection requirements for Subprocessors, including Model Providers. |
| Personnel | Confidentiality obligations, background screening where permitted, and periodic security and privacy training. |
| Incident response | A documented incident-response program supporting the notification obligations in Section 6.2. |
This DPA is incorporated into and forms part of the Agreement. Where the Agreement is executed, no separate signature to this DPA is required.