Privacy policy
This policy explains how Convs (convs.io and the panel at app.convs.io) processes personal data: yours as a user, and the data of people who end up in your CRM.
Contents
Who is responsible for the data
Convs is provided by ITWorks Katarzyna Bańcer, ul. Sikorskiego 9a, 02-864 Warsaw, Poland, tax ID (NIP) 1231178164, REGON 145833271. For anything about personal data, write to kontakt@convs.io.
The roles depend on the kind of data:
- For your own account data (such as name, email, sign-in) we are the controller.
- Leads and people you add or connect (Meta lead forms, Google Sheets, shop orders, the CRM) belong to your business. You are their controller and we process them on your behalf as a processor.
A data processing agreement (DPA) is available on every plan. Write to kontakt@convs.io.
What data we process
- Account: name, email, a password hash (never the password itself) and sign-in sessions.
- Organisations and team: organisation names, members and their roles.
- A connected Meta account (Facebook Login for Business): access tokens, and the ad accounts, Pages, lead forms and datasets you choose.
- A connected Google account: only the openid, email and drive.file scopes. Access covers only the Google Sheets files you pick in the Google Picker. We read the rows of those sheets.
- Orders your shop sends us (for example Shoper).
- SMS accounts you connect: SMSAPI, Twilio, an HTTP gateway, smsportal.app.
- Leads from Meta Instant Forms: name, email, phone and every form answer. Submission content is stored encrypted.
- People in the CRM: contact details, stage, history, notes, tasks and owner.
- Campaign spend and ad data (campaigns, ad sets, ads) read from Meta.
- Automation runs: steps, results and the data needed to carry them out.
Why we process data
We process account data to provide the service you ask for (Art. 6(1)(b) GDPR) and to keep the service secure (Art. 6(1)(f) GDPR).
We process leads and people only to do what you set up in the panel: fetch submissions, keep the CRM, send events to Meta, send an SMS or a webhook, build the campaign report. We do this on your instructions, under the data processing agreement.
We do not sell data, use it for advertising or build profiles from it.
Google data
Convs’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.- We use Google data only to import the rows of the sheets you choose into your own organisation.
- We never use it for advertising and never sell it.
- People do not read this data, except with your consent for support, or when security or the law requires it.
Meta data and sending to Meta
From Meta we read the resources you choose after signing in with Facebook Login for Business: leads from Instant Forms, Page and form details, ad spend and ad data.
We send events to the Meta Conversions API only when you create a flow. Email and phone are normalised and hashed with SHA-256 before sending. Meta Platforms Ireland Ltd then receives this data under Meta’s terms.
Who receives data
- Contabo GmbH: the provider of the server the service runs on (data centre in France).
- Meta Platforms Ireland Ltd: events from the flows you create.
- The SMS provider you connect (SMSAPI, Twilio, your HTTP gateway or smsportal.app): the number and text of automation messages.
- The addresses you enter in automation webhooks: the data you set up in them.
We share data with no one else unless the law requires it.
Where and how data is stored
The service runs on our own server in the European Union (Contabo GmbH, data centre in France). Data lives in an SQLite database on that server.
Secrets, OAuth tokens and lead and form content are encrypted with AES-256-GCM.
We take a backup every night and keep it for 14 days on the same server.
How long we keep data
- Contact details stored on a lead are erased after 30 days. The lead ID and its stages stay, so the lead is never counted twice.
- People in the CRM are erased after the organisation’s retention period (6 to 120 months, default 24) since their last activity.
- Automation run data is erased after 30 days.
- You can erase a person in the panel at any time.
- We delete an account on request sent to kontakt@convs.io, within 30 days.
Your rights
Under the GDPR you have the right to:
- access your data,
- have it corrected,
- have it erased,
- restrict processing,
- data portability,
- object to processing,
- complain to the Polish supervisory authority, the President of the Personal Data Protection Office (PUODO).
Write to kontakt@convs.io. If you are a person in one of our customers’ CRMs, contact the business that collected your data first. We will help them handle your request.
Changes to this policy
When we change this policy, we update the date at the top of the page.