Convo is fully compliant with the General Data Protection Regulation (GDPR). This guide explains your data rights and how to exercise them when using Convo.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of EU residents. GDPR gives you control over your personal data and how it's used.
Who does GDPR apply to? If you're an EU resident or your organization operates in the EU, GDPR protections apply to your use of Convo—regardless of where Convo's servers are located.
Under GDPR, you have eight fundamental rights regarding your personal data:
You have the right to know what personal data we collect, why we collect it, how we use it, and who we share it with. This information is available in our Privacy Policy and this guide.
You can request a copy of all personal data we hold about you. This includes your account information, conversation transcripts, meeting metadata, and usage history.
If any of your personal data is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly in your account settings.
You can request deletion of your personal data. When you delete your account, all associated data is permanently removed from our systems within 30 days.
You can ask us to limit how we use your personal data while we investigate a complaint or verify the accuracy of your data.
You can receive your personal data in a structured, commonly used format (JSON, CSV) and have it transferred to another service provider.
You can object to processing of your personal data for direct marketing, scientific research, or legitimate interests purposes.
You have the right not to be subject to decisions based solely on automated processing. Convo's AI provides suggestions, but you make all final decisions.
To view and access your personal data:
To update inaccurate or incomplete information:
You can delete specific conversations or your entire account:
Important: Account deletion is permanent and cannot be undone. Your subscription will be cancelled, and all conversation data, settings, and history will be permanently deleted.
To receive a copy of your data in a portable format:
What's included in data exports:
Name, email address, password (encrypted), account creation date, subscription tier, billing information (stored by Stripe).
Audio transcripts, meeting participants, timestamps, conversation summaries, AI-generated suggestions, action items.
Feature usage statistics, API call counts, session duration, device information, app version, error logs.
Google Calendar events (if connected), video platform metadata, calendar access tokens (encrypted).
Under GDPR, we must have a legal basis to process your personal data. Convo processes data under these bases:
Processing necessary to provide Convo's services under our Terms of Service (e.g., transcribing meetings, storing conversations, providing AI assistance).
When you grant explicit consent for specific processing activities (e.g., connecting Google Calendar, enabling cloud transcription, sharing data with integrations).
Processing necessary for our legitimate business interests (e.g., improving product features, preventing fraud, ensuring security) balanced against your privacy rights.
Processing required to comply with legal requirements (e.g., tax records, responding to lawful requests from authorities).
Convo retains personal data only as long as necessary for the purposes outlined:
Default: 30 days. Configurable from immediate deletion to 7 years for compliance needs. Automatically deleted based on your retention settings.
Retained while your account is active. Deleted within 30 days after account deletion, except where legally required to retain (e.g., billing records for 7 years).
Aggregated analytics retained for 2 years. Individual usage logs deleted after 90 days.
Backups containing your data are retained for 90 days for disaster recovery purposes, then permanently deleted.
If you're in the EU, your data may be transferred outside the European Economic Area (EEA):
For GDPR-related questions or concerns, you can contact our Data Protection Officer:
Email: dpo@itsconvo.com
Mail: Data Protection Officer, Convo Inc., [Address]
Response Time: We respond to GDPR requests within 30 days
If you believe we're not handling your personal data properly, you have the right to lodge a complaint:
Email privacy@itsconvo.com with your concern. We aim to resolve issues directly within 30 days.
If not satisfied with our response, you can file a complaint with your local data protection authority:
If you're using Convo for your organization, you have additional responsibilities:
Enterprise customers can request a signed DPA:
We continuously improve our GDPR compliance. Recent updates include:
Learn more about data protection at Convo:
Our privacy team can help you understand your GDPR obligations and configure Convo for compliance. Contact us at privacy@itsconvo.com.