Purpose

This page describes how ConveYour handles customer data used in its services, including data processed by AI-enabled features. It is intended to give customers a clear understanding of ownership, permitted use, retention, access, and the safeguards that apply to their information.

Customer data ownership

Customer data remains the property of the customer or the individual or organization that provided it, as applicable. ConveYour does not claim ownership of customer data simply because it processes that data to provide the service.

"Customer data" includes information a customer submits to ConveYour, information generated through customer use of the service, and information processed by AI-enabled features on the customer's behalf.

Permitted use

ConveYour uses customer data only as necessary to provide, secure, support, maintain, and improve the contracted service, and as otherwise authorized by the customer or required by law.

ConveYour does not sell customer data.

ConveYour does not use customer data to train generalized AI models for other customers without the customer's explicit written permission.

ConveYour employees and contractors may access customer data only when they have a legitimate business need and appropriate authorization, such as providing support, investigating an incident, or maintaining the service.

AI-enabled processing

When a customer uses an AI-enabled feature, ConveYour may send the minimum data needed to the approved service provider that powers the feature. ConveYour evaluates relevant providers and contracts for appropriate privacy, confidentiality, and security commitments.

ConveYour seeks to limit the personal data included in AI prompts and workflows to what is necessary for the requested function. Customers should avoid submitting unnecessary sensitive information and should configure their workflows in line with their own privacy and employment obligations.

Privacy and security

ConveYour applies reasonable technical and organizational safeguards to protect customer data against unauthorized access, disclosure, alteration, or loss. These safeguards include access controls, authentication, encryption where appropriate, logging, and security incident procedures.

ConveYour processes personal data in accordance with its privacy notice, customer agreement, data-processing terms, and applicable law.

Retention and deletion

ConveYour retains customer data only for as long as needed to provide the service, meet legal or contractual obligations, resolve disputes, enforce agreements, and maintain reasonable security and business records.

Upon termination of a customer's account or upon a valid deletion request, ConveYour will delete or return customer data in accordance with the applicable agreement, subject to any limited retention required by law, legitimate security needs, or backup-system schedules.

ConveYour documents its retention practices and reviews them periodically.