Convo by HOXE · Legal

Data Processing Agreement

Last updated: 25 June 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Hoxe Technologies Pvt. Ltd. (“HOXE”, the Processor) and the customer (“you”, the Data Fiduciary / Controller) for personal data processed through Convo. It applies whenever we process personal data on your behalf.

In plain terms: you decide why and how your buyers’ data is collected and used through your bot; HOXE only processes it to provide Convo to you, on your instructions. This DPA sets out our obligations to you and yours to us.

1. Definitions

“Personal data”, “Data Fiduciary”, “Data Processor” and “Data Principal” have the meanings given in the DPDP Act, 2023. Where you are subject to the GDPR/UK GDPR, “controller” and “processor” apply equivalently and the addendum in section 11 applies.

2. Roles & scope of processing

3. Your obligations as Data Fiduciary

4. Our obligations as Processor

5. Sub-processors

You authorise us to use sub-processors to provide the service. Current sub-processors include:

We impose data-protection terms on each sub-processor no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of a new sub-processor; you may object on reasonable data-protection grounds, and we will work in good faith to address it.

6. Data-principal requests

If a data principal contacts us directly about your data, we will not respond on the merits (except to confirm receipt) and will promptly forward the request to you, then assist you in handling it.

7. International transfers

Some sub-processors operate outside India. Transfers are made in line with the DPDP Act and only to destinations not restricted by the Government of India. The GDPR addendum (section 11) provides additional transfer safeguards where applicable.

8. Audit

On reasonable written request and no more than once a year (or after a breach), we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality.

9. Return & deletion

On termination, you may export your data for a limited period, after which we delete or anonymise personal data processed on your behalf, except where retention is required by law.

10. Liability

Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits a data principal’s statutory rights or either party’s liability that cannot be excluded under law.

11. GDPR / UK GDPR addendum

Where you process EEA/UK personal data as a controller, this DPA incorporates the equivalent Article 28 processor obligations, and the parties agree to apply Standard Contractual Clauses for any restricted transfer, with this section completing the required details. Contact privacy@hoxe.net to execute a counter-signed version if your procurement requires one.

12. General

This DPA is governed by the laws of India. If any conflict arises between this DPA and the Terms regarding personal-data processing, this DPA prevails. Questions: privacy@hoxe.net.