Convo by HOXE · Legal
Data Processing Agreement
Last updated: 25 June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Hoxe Technologies Pvt. Ltd. (“HOXE”, the Processor) and the customer (“you”, the Data Fiduciary / Controller) for personal data processed through Convo. It applies whenever we process personal data on your behalf.
1. Definitions
“Personal data”, “Data Fiduciary”, “Data Processor” and “Data Principal” have the meanings given in the DPDP Act, 2023. Where you are subject to the GDPR/UK GDPR, “controller” and “processor” apply equivalently and the addendum in section 11 applies.
2. Roles & scope of processing
- Subject matter: providing the Convo chat and voice service.
- Nature & purpose: answering enquiries from your knowledge base, capturing and scoring leads, running voice calls, and handing leads to your team.
- Categories of data: end-user contact details (name, phone, email), chat messages, voice audio/transcripts, and related metadata.
- Data principals: visitors and callers who interact with your bot.
- Duration: the term of your subscription, plus the deletion period in section 9.
3. Your obligations as Data Fiduciary
- You determine the purposes of processing and warrant you have a lawful basis and have given the required notices and obtained any required consents from your data principals — including for call recording and any follow-up messaging.
- You comply with telecom and anti-spam requirements (e.g. DLT registration, consent and use of your own numbers for outbound communications where required).
- Your instructions to us (including through the product’s settings) are documented by this DPA and your configuration.
4. Our obligations as Processor
- Process on instructions only — we process personal data only to provide the service and per your documented instructions, not for our own purposes, and we do not sell it.
- Confidentiality — personnel with access are bound by confidentiality obligations.
- Security — we maintain reasonable technical and organisational measures (encryption in transit, access controls, logging, reputable hosting); a summary is available on request.
- Assistance — taking into account the nature of processing, we assist you in responding to data-principal requests (access, correction, erasure, etc.) and in meeting your security and breach obligations.
- Breach notification — we notify you without undue delay after becoming aware of a personal-data breach affecting your data, with available details to help you meet your notification duties.
5. Sub-processors
You authorise us to use sub-processors to provide the service. Current sub-processors include:
- Supabase — Database, authentication & storage (Cloud (confirm region) [VERIFY]).
- Vercel — Application & widget hosting (USA / global edge).
- Google (Gemini) — AI model that powers chat & voice replies (Global).
- Vapi — Voice agent orchestration & telephony for Call-now (USA / global [VERIFY]).
- Sarvam — Speech (STT/TTS) and language model for voice replies (India [VERIFY]).
- LiveKit — Real-time audio transport for voice calls (Global [VERIFY]).
- Upstash — Rate-limiting & ephemeral queue/cache (Redis) (Global [VERIFY]).
- Dodo Payments — Subscription billing as Merchant of Record (handles tax and issues your invoice) (Global).
- Resend — Transactional & notification emails (USA).
We impose data-protection terms on each sub-processor no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of a new sub-processor; you may object on reasonable data-protection grounds, and we will work in good faith to address it.
6. Data-principal requests
If a data principal contacts us directly about your data, we will not respond on the merits (except to confirm receipt) and will promptly forward the request to you, then assist you in handling it.
7. International transfers
Some sub-processors operate outside India. Transfers are made in line with the DPDP Act and only to destinations not restricted by the Government of India. The GDPR addendum (section 11) provides additional transfer safeguards where applicable.
8. Audit
On reasonable written request and no more than once a year (or after a breach), we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality.
9. Return & deletion
On termination, you may export your data for a limited period, after which we delete or anonymise personal data processed on your behalf, except where retention is required by law.
10. Liability
Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits a data principal’s statutory rights or either party’s liability that cannot be excluded under law.
11. GDPR / UK GDPR addendum
Where you process EEA/UK personal data as a controller, this DPA incorporates the equivalent Article 28 processor obligations, and the parties agree to apply Standard Contractual Clauses for any restricted transfer, with this section completing the required details. Contact privacy@hoxe.net to execute a counter-signed version if your procurement requires one.
12. General
This DPA is governed by the laws of India. If any conflict arises between this DPA and the Terms regarding personal-data processing, this DPA prevails. Questions: privacy@hoxe.net.