Last updated: 28 September 2026
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ConvoHut and the customer. It applies when ConvoHut processes personal data in Customer Data on the customer’s behalf.
The customer is the controller (or business, data fiduciary, responsible party or equivalent). ConvoHut is the processor (or service provider, data intermediary, operator or equivalent). Where the customer is itself a processor, ConvoHut is a sub-processor.
2. Details of processing
| Item | Details |
|---|---|
| Subject matter and duration | Providing the Service for the term of the Terms, plus up to 60 days for export and deletion, and backup roll-off after that. |
| Nature and purpose | Storing, organising, transmitting and displaying Customer Data to send and receive WhatsApp messages, run automations and campaigns, and provide the shared inbox, analytics and support. |
| Data subjects | The customer’s contacts, customers and leads; the customer’s users. |
| Personal data | Names, phone numbers, email addresses, consent status and records, message content and metadata, tags and notes, and data in connected sheets and stores that the customer maps into ConvoHut. |
| Special categories | Health-related information may be processed where the customer is a healthcare provider, for example appointment details and anything patients send in replies. The customer must limit this to what is necessary, have a lawful basis, and must not include clinical details in templates. ConvoHut doesn’t sign HIPAA Business Associate Agreements, so US covered entities must not use the Service for protected health information. |
3. Our obligations
ConvoHut will:
- process personal data only on the customer’s documented instructions, including in the Terms and the customer’s configuration of the Service, unless the law requires otherwise (in which case we’ll tell the customer unless the law prohibits it);
- tell the customer if we believe an instruction breaches data protection law;
- ensure people authorised to process personal data are bound by confidentiality;
- implement appropriate technical and organisational security measures, as described on our Security page;
- assist the customer, taking into account the nature of processing, with data subject requests, security, breach notification, impact assessments and consultations with regulators;
- delete or return personal data at the end of the Service, as set out in section 8;
- make available information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-processors
The customer authorises ConvoHut to use the sub-processors listed on our Sub-processors page. ConvoHut will impose data protection terms on each sub-processor that are no less protective than this DPA, and remains responsible for their performance.
We will give at least 30 days’ notice of a new sub-processor by updating the list and emailing the account owner of every workspace. If the customer reasonably objects on data protection grounds, we’ll work with the customer to find a solution. If we can’t, the customer may terminate the affected Service and receive a pro-rata refund of prepaid fees.
Meta, Google, Shopify and Zapier are services the customer engages directly under its own agreements with them. They are not ConvoHut’s sub-processors, and are listed for transparency.
5. International transfers
ConvoHut may process personal data in Australia and in the countries where its sub-processors operate. Where a transfer from the European Economic Area, Switzerland or the United Kingdom needs a transfer mechanism, the parties agree to the European Commission’s Standard Contractual Clauses (Module 2, controller to processor, and Module 3, processor to processor, as applicable), with the UK International Data Transfer Addendum and Swiss amendments where relevant. The Clauses are incorporated by reference. For the Clauses, the parties choose the law and courts of Ireland, and the details in this DPA complete the annexes.
6. Security incidents
ConvoHut will notify the customer without undue delay, and in any case within 72 hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data in Customer Data. We’ll provide the information reasonably available to help the customer meet its obligations, including under Australia’s Notifiable Data Breaches scheme, the GDPR, and the laws of Singapore, India and other countries, and we’ll take reasonable steps to contain and remedy the breach.
We’ll send an initial notice as soon as we confirm a breach, and updates as we learn more. Where we both hold the affected information, we’ll agree which of us notifies under section 26WJ of the Privacy Act. Unless agreed otherwise, the customer notifies regulators and affected individuals, and we’ll give it the information it needs.
7. Audits
On request, ConvoHut will answer reasonable security questionnaires and provide available documentation, no more than once a year unless there has been a breach or a regulator requires it. If that isn’t enough to demonstrate compliance, the customer may carry out an audit at its own cost, on 30 days’ notice, during business hours, subject to confidentiality and without access to other customers’ data.
8. Deletion and return
During the term, the customer can export or delete Customer Data. For 30 days after the Service ends, the customer can ask us to export it. ConvoHut then deletes it from live systems within 30 days, unless the law requires us to keep it. Backups are overwritten on their normal cycle. Messages held by Meta are retained under the customer’s agreement with Meta, which Meta says is up to 30 days.
9. Country terms
- Australia: ConvoHut will handle personal information in Customer Data in a way consistent with the Australian Privacy Principles, including APP 11 security.
- New Zealand: ConvoHut holds personal information solely as the customer’s agent for storage and processing, within the meaning of section 11 of the Privacy Act 2020.
- United States: ConvoHut is a service provider and will not sell or share personal information, retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in the Terms, or combine it with other data except as permitted by law. ConvoHut will notify the customer if it can no longer meet its obligations.
- India: ConvoHut processes personal data under this valid contract, as required by section 8(2) of the Digital Personal Data Protection Act 2023.
- Singapore: ConvoHut is a data intermediary and will protect, retain and notify breaches as required of data intermediaries under the PDPA.
- South Africa: ConvoHut is an operator and will treat personal information as confidential and secure it as required by sections 20 and 21 of POPIA.
10. Precedence
If there is a conflict, the Standard Contractual Clauses prevail, then this DPA, then the Terms. Liability under this DPA is subject to the limits in the Terms, except where the law or the Standard Contractual Clauses don’t allow it.
Alite Projects Pty Ltd (ABN 38 698 554 148), trading as ConvoHut. Melbourne, Victoria, Australia. Questions: abhishek@convohut.com.
