Version 2.0 - Effective: July 1, 2026
Convor is provided by TopSoft4U Łukasz Kolasa, Augusta Fieldorfa 21/35, 21-500 Biała Podlaska, Poland, REGON 385744400, Tax ID / NIP PL5372652411 ("TopSoft4U", "Convor", "we", "us").
For matters connected with privacy and personal data, contact us at [email protected]. We have not appointed a formal Data Protection Officer. This mailbox is the contact point for data protection requests.
We are the controller for personal data processed for our own purposes, including website visitors, newsletter subscribers, contact-form senders, Convor account users, billing contacts, support contacts, and product security logs.
For chat visitors who use a Convor widget embedded on a customer's website, the customer that operates that website is normally the controller. In that case we process visitor chat data as the customer's processor under the customer's instructions and the applicable data processing agreement.
If you are a chat visitor and want to exercise rights connected with a conversation on a customer's website, you may contact that customer directly. We will support the customer in handling the request where Convor stores or processes the relevant data.
Account and operator data: name, email address, password or authentication credentials, email verification status, profile image, organization membership, role, permissions, operator display name, availability status, timezone, skills, dashboard layout, notification settings, API keys, SSO configuration data, security settings, audit logs, and support interactions.
Organization and billing data: organization name, slug, plan, subscription status, trial status, billing contact details, company name, tax identifier, billing events, invoice metadata, and payment-related identifiers received from Lemon Squeezy. We do not store full card numbers.
Website, contact, and newsletter data: email address, name, department, message content, subscription source, confirmation token, confirmation status, IP-derived rate-limit signals, and technical request metadata needed to protect the forms from abuse.
Widget visitor and conversation data: visitor identifier, browser fingerprint, first and last seen timestamps, session count, page history, referrer, user agent, approximate country and city, chat messages, message metadata, files and uploads, reactions, CSAT ratings, notes, tags, bans, consent records, and any identity traits the customer chooses to attach through the widget SDK.
Technical and security data: IP address, user agent, request headers, session records, reset tokens, logs, error reports, webhook deliveries, push subscription endpoints, Expo push tokens, and audit records.
We process account, organization, dashboard, billing, and support data to perform our contract with the customer or to take steps before entering into a contract.
We process data needed for security, fraud prevention, rate limiting, service reliability, abuse prevention, audit logs, debugging, and business communication on the basis of our legitimate interests.
We process data needed for invoices, tax records, accounting, legal claims, and regulatory obligations because the law requires it or because it is necessary to establish, exercise, or defend legal claims.
We process newsletter subscriptions, optional marketing communications, optional analytics cookies, and optional marketing cookies on the basis of consent. You can withdraw consent at any time.
Account, organization, billing, and technical data may be required to create an account, provide paid plans, secure the service, or meet legal obligations. Contact-form, newsletter, optional analytics, optional marketing, and most integration data are voluntary, but refusing or removing them may limit the related feature.
Where Convor acts as processor for customer-controlled visitor data, the customer's legal basis applies. We process that data under the customer's documented instructions.
We use personal data to provide the Convor service, authenticate users, manage organizations, route conversations, deliver real-time messages, display visitor context to operators, provide analytics, process billing, send transactional emails, provide support, secure the service, investigate abuse, and maintain auditability.
We use newsletter and contact-form data to respond to messages, route inquiries to the right team, and send requested updates after double opt-in where applicable.
We use technical logs, rate-limit records, and error telemetry to diagnose faults, prevent abuse, and protect the service. Error telemetry is configured not to send default PII and to scrub common personal data fields before events leave the application.
Convor offers AI-assisted replies, summaries, suggested responses, categorization, sentiment analysis, translation, and chatbot features. Depending on the customer's configuration, conversation content and related context may be sent to an AI provider to generate these features.
Customers may use Convor platform AI or bring their own API key. BYOK settings may include encrypted provider credentials, selected model, provider type, base URL, and usage statistics. When a customer uses its own provider credentials or self-hosted compatible endpoint, that provider relationship is controlled by the customer.
We do not use customer conversation content to train our own AI models. Convor does not make solely automated decisions on behalf of TopSoft4U that produce legal or similarly significant effects for individuals.
We also do not claim that third-party AI providers are free from their own processing obligations; their processing depends on the selected provider, configuration, and applicable provider terms.
Customers can connect Convor to third-party services such as Slack, Discord, Microsoft Teams, Telegram, WhatsApp, Instagram, Messenger, Freshdesk, Stripe, Google Analytics, Segment, Mailchimp, Klaviyo, Shopify, WooCommerce, Zapier, n8n, GitHub, Jira, Trello, Asana, Notion, Pipedrive, Calendly, and similar tools.
When a customer enables an integration, Convor may send or receive the data needed for that integration, such as messages, customer identifiers, webhook payloads, ticket details, payment event metadata, analytics events, or notification content.
The customer is responsible for choosing integrations lawfully, configuring them correctly, and informing its own users and visitors where required.
We do not sell personal data. We share personal data only where needed to operate Convor, comply with law, protect rights and security, or follow a customer's instructions.
Core subprocessors may include hosting, database, cache, realtime messaging, email delivery, payment, observability, and AI providers. The in-product public subprocessor list is the operational source for current processor names, purposes, jurisdictions, and websites.
Current subprocessors include Neon, Upstash, Centrifugo where deployed for realtime delivery, OpenAI, Anthropic, Lemon Squeezy, and Resend where those services are enabled or used for the relevant part of Convor.
We may also disclose data to professional advisers, public authorities, courts, or law-enforcement bodies where legally required or necessary to protect our rights, users, customers, or the service.
We aim to keep primary service data hosted in the European Economic Area where practical. Some subprocessors, payment providers, AI providers, email providers, and observability providers may process data outside the EEA.
Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, processor terms, transfer impact assessments where required, or another lawful transfer mechanism under GDPR.
We keep personal data only as long as needed for the purposes described in this Policy, unless a longer period is required for legal, accounting, security, backup, or dispute purposes.
Conversation history retention depends on the customer's plan and configuration. Current plan defaults include limited history for lower plans and longer or unlimited history for higher plans. Customers may also configure retention overrides for messages, audit logs, and uploads where the product exposes those settings.
Closed or resolved conversations can be deleted by cleanup jobs after the applicable retention window. Orphaned visitors, expired reset tokens, old audit logs, orphaned uploads, successful webhook delivery records, and stale push subscriptions are also subject to cleanup rules.
Contact submissions and newsletter records are retained until no longer needed to respond, administer the list, document consent, or protect against abuse. Billing and tax records are retained for the periods required by applicable law.
Backups and logs may retain deleted data for a limited period before they rotate out. Where immediate deletion is not technically possible from backups, we isolate the data from ordinary use and delete it according to the backup lifecycle.
We use technical and organizational measures designed to protect personal data, including TLS for data in transit, role-based access controls, organization-level tenant boundaries, audit logging, rate limiting, webhook signing, CSRF protections on public forms, password reset safeguards, and access controls for admin-only collections.
Some sensitive credentials, such as AI and integration credentials, are designed to be stored in encrypted or hashed form where the relevant feature supports it. We continue to improve security controls as the product evolves.
No online service can guarantee perfect security. If we become aware of a personal data breach, we will assess it and notify affected customers, users, and authorities where required by law.
Subject to legal conditions and limitations, you may have the right to access, rectify, erase, restrict, object to processing, receive data portability, withdraw consent, and lodge a complaint with a supervisory authority.
Account users can use available export and deletion features in the dashboard where applicable. Visitors can request exports or erasure through the customer that controls the widget deployment; Convor provides tools to export and anonymize visitor data for customers.
To exercise rights where TopSoft4U is the controller, contact [email protected]. We may need to verify your identity and may ask for information needed to locate the relevant account, organization, subscription, message, or visitor record.
You may lodge a complaint with the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO) or another competent supervisory authority in the EEA.
Convor is a business software service and is not directed to children. Customers must not intentionally use Convor to collect children's personal data unless they have a lawful basis and all required notices, consents, and safeguards.
If you believe a child has provided personal data directly to TopSoft4U without appropriate authorization, contact [email protected].
We may update this Privacy Policy when our service, subprocessors, legal obligations, or processing practices change.
Material changes will be communicated by reasonable means, such as email to account administrators, dashboard notice, or website notice. The version and effective date shown on this page identify the currently published policy.
Privacy contact: [email protected]
Support contact: [email protected]
Service provider and controller where stated: TopSoft4U Łukasz Kolasa, Augusta Fieldorfa 21/35, 21-500 Biała Podlaska, Poland, REGON 385744400, Tax ID / NIP PL5372652411.
Effective date: July 1, 2026
Have a question about this document? Visit our contact page and we'll route it to the right team.