Convalesce Free Beta Data Processing Addendum
Effective Date: The date Customer accepts the Convalesce Free Beta Terms of Service or otherwise begins using the Service, whichever occurs first.
This Data Processing Addendum (“DPA”) forms part of the Convalesce Free Beta Terms of Service or other written agreement governing Customer's use of Convalesce (the “Agreement”).
This DPA is between:
Convalesce, currently an unincorporated project operated by Samarth KaPatel and Vedanshu Joshi (“Convalesce,” “we,” “us,” or “Processor”);
and
the individual or entity accepting the Agreement or using the Service (“Customer”).
This DPA applies only to the extent Convalesce processes Customer Personal Data on behalf of Customer in connection with the Service.
By accepting the Agreement, Customer also accepts this DPA where applicable.
1. Definitions
For purposes of this DPA:
1.1 “Applicable Data Protection Law”
means privacy, data-protection, and data-security laws applicable to the processing of Customer Personal Data under this DPA, including, where applicable:
- the EU General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”);
- the United Kingdom GDPR and Data Protection Act 2018 (“UK Data Protection Law”);
- the Swiss Federal Act on Data Protection (“Swiss FADP”);
- applicable United States state privacy laws; and
- other applicable privacy or data-protection laws.
1.2 “Customer Data”
has the meaning given in the Agreement and includes data, information, logs, metadata, queries, code, workflow information, execution history, configurations, infrastructure information, records, and other information made available to Convalesce through Customer or Customer-authorized systems.
1.3 “Customer Personal Data”
means any Personal Data contained in Customer Data that Convalesce processes on behalf of Customer.
1.4 “Data Subject”
means an identified or identifiable individual to whom Customer Personal Data relates.
1.5 “Personal Data”
means “personal data,” “personal information,” “personally identifiable information,” or an equivalent term under Applicable Data Protection Law.
1.6 “Process” or “Processing”
has the meaning assigned under Applicable Data Protection Law and includes accessing, retrieving, collecting, storing, organizing, correlating, analyzing, transmitting, redacting, deleting, or otherwise handling Customer Personal Data.
1.7 “Security Incident”
means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data processed by Convalesce.
Security Incident does not include unsuccessful attempts or activities that do not result in compromise of Customer Personal Data, such as unsuccessful login attempts, scans, pings, denial-of-service attempts that do not result in unauthorized access, or other unsuccessful attacks.
1.8 “Subprocessor”
means a third party engaged by Convalesce to Process Customer Personal Data on behalf of Customer in connection with the Service.
2. Scope and Roles
2.1 Customer as Controller
Where Customer determines the purposes and means of Processing Customer Personal Data, Customer is the Controller or equivalent term under Applicable Data Protection Law, and Convalesce acts as Customer's Processor.
2.2 Customer as Processor
Where Customer processes Customer Personal Data on behalf of another Controller, Customer acts as a Processor and Convalesce acts as Customer's Subprocessor.
Customer represents that it is authorized by the applicable Controller to appoint Convalesce as a Subprocessor.
2.3 Processing Instructions
Convalesce will Process Customer Personal Data only:
- to provide the Service;
- as described in the Agreement, this DPA, and Schedule 1;
- according to Customer's documented instructions provided through Customer's configuration and use of the Service;
- as otherwise reasonably necessary to perform an investigation requested by Customer; or
- as required by applicable law.
The Agreement, this DPA, Customer's configuration of the Service, Customer's connection of Third-Party Services, and Customer's requests submitted through the Service constitute Customer's documented instructions to Convalesce.
If Convalesce is required by law to Process Customer Personal Data other than according to Customer's instructions, Convalesce will notify Customer before such Processing unless applicable law prohibits such notice.
3. Processing of Customer Personal Data
3.1 Customer Personal Data Processed on Customer's
Behalf
The subject matter, nature, purpose, duration, categories of Data Subjects, categories of Personal Data, and frequency of Processing are described in Schedule 1.
Convalesce does not intentionally seek Personal Data as a primary purpose of the Service. Customer Personal Data may nevertheless appear within Customer-controlled systems connected to Convalesce.
Convalesce will seek to Process only Customer Personal Data reasonably necessary to:
- provide the Service;
- perform Customer-requested investigations;
- operate and secure the Service;
- troubleshoot technical issues;
- provide support; or
- comply with applicable law.
3.2 Service Usage and Analytics Data
This DPA governs Customer Personal Data that Convalesce Processes on behalf of Customer.
It does not govern Personal Data that Convalesce collects and Processes for its own purposes where Convalesce independently determines the purposes and means of Processing.
Such information may include Personal Data collected directly from users of the Service for purposes such as:
- account administration;
- authentication;
- Service security;
- fraud and abuse prevention;
- product analytics;
- feature usage measurement;
- understanding how users interact with the Service;
- session and application activity analysis;
- troubleshooting;
- product development; and
- improving the Service.
To the extent Convalesce independently determines the purposes and means of such Processing, Convalesce acts as an independent Controller or equivalent role under Applicable Data Protection Law.
Convalesce's collection and use of such Personal Data is described in the Convalesce Privacy Policy.
For clarity, the use of product analytics or similar technologies by Convalesce for its own purposes does not, by itself, cause such information to become Customer Personal Data governed by this DPA.
4. Customer Responsibilities
Customer is responsible for complying with Applicable Data Protection Law in connection with Customer's use of the Service.
Customer represents and warrants that:
1. Customer has a lawful basis and all necessary rights, permissions, notices, and authorizations to provide or make Customer Personal Data accessible to Convalesce; 2. Customer is authorized to connect each system, account, environment, warehouse, database, repository, API, or other service connected to Convalesce; 3. Customer's instructions to Convalesce comply with Applicable Data Protection Law; 4. Customer has provided any notices to Data Subjects required by applicable law; and 5. Customer will not instruct Convalesce to Process Customer Personal Data in violation of applicable law.
Customer is responsible for determining whether Convalesce is appropriate for Customer's particular legal, regulatory, security, and contractual requirements.
5. Specially Regulated and Sensitive Data
The Free Beta Service is not designed or offered specifically for the processing of information subject to specialized regulatory requirements unless Convalesce expressly agrees otherwise in writing.
Unless expressly authorized by Convalesce in writing, Customer will not intentionally use the Service to provide Convalesce with:
- protected health information subject to HIPAA;
- complete payment-card information subject to PCI DSS requirements;
- Social Security numbers or equivalent government identification numbers;
- biometric identifiers used for unique identification;
- passwords in plaintext;
- private cryptographic keys;
- highly sensitive authentication secrets;
- information concerning children where specialized children's privacy requirements apply; or
- other information requiring specialized regulatory handling beyond the protections described in this DPA.
Convalesce recognizes that such information may nevertheless appear incidentally within Customer-controlled systems.
Where Convalesce incidentally encounters such information, Convalesce will Process it only as reasonably necessary to provide the Service and subject to this DPA.
Customer remains responsible for determining whether Customer's use of Convalesce is appropriate for such information.
6. Data Minimization and AI Processing
6.1 Investigation-Based Processing
Convalesce will seek to access and retain Customer Personal Data only where reasonably necessary to provide the Service, perform an investigation, maintain security, troubleshoot the Service, or comply with applicable law.
Row-level information may be retrieved where reasonably necessary for an investigation.
6.2 PII Redaction
Before investigation context is submitted by Convalesce to its external AI model provider, Convalesce applies processing within its own cloud environment intended to identify and redact or mask personally identifying information.
Customer acknowledges that automated redaction technologies cannot be guaranteed to identify or remove every possible item of Personal Data.
Accordingly, redaction reduces but does not eliminate the possibility that Personal Data may appear in information submitted to an AI Subprocessor.
6.3 No Generalized Model Training
During the Free Beta, Convalesce will not use Customer Personal Data to train generalized artificial-intelligence or machine-learning models.
Convalesce will not instruct its AI Subprocessors to use Customer Personal Data to train generalized models.
This restriction does not prevent Convalesce from using:
- operational metrics;
- security information;
- service-performance information;
- technical telemetry;
- Feedback;
- aggregated information; or
- de-identified information that cannot reasonably be used to identify a Data Subject, Customer, or Customer's underlying Customer Data
to operate, secure, evaluate, or improve the Service.
7. Security Measures
Convalesce will maintain reasonable technical and organizational measures intended to protect Customer Personal Data against unauthorized access, acquisition, use, disclosure, alteration, or destruction.
The technical and organizational measures currently implemented for the Free Beta are described in Schedule 2.
Because Convalesce is a Beta Service, these measures may evolve as the Service develops.
Convalesce may replace a security control with an alternative control provided that the overall level of protection is not materially reduced where prohibited by Applicable Data Protection Law.
8. Confidentiality and Access
Convalesce will limit access to Customer Personal Data to individuals and service providers who reasonably require such access to operate, maintain, secure, troubleshoot, or support the Service.
Persons authorized by Convalesce to access Customer Personal Data will be subject to appropriate confidentiality obligations.
Convalesce will not disclose Customer Personal Data to third parties except:
- according to Customer's instructions;
- to authorized Subprocessors;
- as reasonably necessary to provide the Service;
- as required by law; or
- as otherwise permitted by the Agreement and Applicable Data Protection Law.
9. Subprocessors
9.1 General Authorization
Customer provides Convalesce with general authorization to engage Subprocessors as reasonably necessary to provide the Service.
Convalesce will require each Subprocessor that Processes Customer Personal Data on Convalesce's behalf to be subject to contractual data-protection obligations appropriate to the services performed and the requirements of Applicable Data Protection Law.
Convalesce remains responsible for its obligations under this DPA notwithstanding its use of Subprocessors, to the extent required by Applicable Data Protection Law.
9.2 Current Subprocessors
As of the Effective Date, Convalesce uses the following Subprocessor:
| Subprocessor | Services and Purpose | Customer Information Processed | Primary Processing / Hosting Information |
|---|---|---|---|
| Google LLC / Google Cloud Platform, including Vertex AI / Gemini | Cloud infrastructure, compute, storage, networking, secrets management, service logging, and AI inference used in Convalesce investigations | Customer Data required to operate Convalesce. Investigation context submitted to Vertex AI/Gemini is subject to Convalesce's PII-redaction process before submission. | Convalesce's primary configured Google Cloud hosting region is us-central1 (Iowa, United States). Google may Process information in other locations as permitted under its applicable Google Cloud data-processing and service terms. |
Google may engage its own subprocessors in accordance with Google's applicable contractual terms.
9.3 Changes to Subprocessors
During the Free Beta, the current Subprocessor list will be maintained directly in this DPA.
If Convalesce intends to add or replace a Subprocessor that will Process Customer Personal Data, Convalesce will provide Customer with reasonable notice where required by Applicable Data Protection Law.
Notice may be provided through:
- email;
- the Service;
- an update to this DPA or the Agreement; or
- another reasonable electronic method.
Where Applicable Data Protection Law requires an opportunity to object, Customer may object on reasonable data-protection grounds.
Convalesce and Customer will attempt in good faith to address a valid objection.
If a reasonable solution is not available, Convalesce may:
- elect not to use the relevant Subprocessor for Customer;
- discontinue the affected functionality; or
- permit Customer to stop using the affected Service.
Because the Service is currently provided as a Free Beta, Convalesce is not required to redesign the Service or provide an alternative Subprocessor where doing so would be technically or commercially unreasonable, except to the extent required by applicable law.
10. Data Subject Requests
Customer is responsible for responding to requests from Data Subjects exercising rights under Applicable Data Protection Law.
Taking into account the nature of the Processing and the information reasonably available to Convalesce, Convalesce will provide reasonable assistance to Customer where required by Applicable Data Protection Law.
Such assistance may currently be performed manually.
If a Data Subject submits a request directly to Convalesce concerning Customer Personal Data for which Customer is the Controller, Convalesce may direct the Data Subject to Customer unless Convalesce is legally required to respond directly.
Convalesce will not independently respond to a Data Subject request concerning Customer-controlled Personal Data except:
- at Customer's documented direction; or
- where required by applicable law.
Requests concerning Personal Data that Convalesce Processes as an independent Controller will be handled as described in the Privacy Policy and Applicable Data Protection Law.
11. Security Incidents
Convalesce will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.
To the extent information is reasonably available, notification may include:
- the nature of the Security Incident;
- categories of Customer Personal Data affected;
- categories of Data Subjects potentially affected;
- known or reasonably anticipated consequences;
- measures taken or proposed to address the Security Incident; and
- available contact information for follow-up.
Information may be provided in phases as an investigation develops.
Convalesce's notification of a Security Incident does not constitute an admission of fault, liability, or violation of law.
Customer is responsible for determining whether notice must be provided to regulators, Data Subjects, or other persons, except where applicable law places that obligation directly on Convalesce.
12. Data Protection Impact Assessments
and Regulatory Assistance
Taking into account the nature of Processing and information available to Convalesce, Convalesce will provide reasonable information and assistance to Customer where required by Applicable Data Protection Law concerning:
- data-protection impact assessments;
- consultations with supervisory authorities; and
- Customer's compliance obligations relating directly to Convalesce's Processing of Customer Personal Data.
Convalesce is not responsible for Customer's overall compliance program or for conducting Customer's data-protection impact assessment on Customer's behalf.
13. Verification of Compliance
Upon reasonable request, Convalesce will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA to the extent required by Applicable Data Protection Law.
Convalesce may first satisfy such requests through:
- this DPA;
- security documentation;
- written responses;
- applicable Subprocessor documentation; and
- other reasonably available compliance information.
If Applicable Data Protection Law requires Customer to conduct an additional audit or inspection and the information provided by Convalesce is insufficient to satisfy that requirement, Convalesce will permit or contribute to an appropriately limited audit.
Any such audit must, unless prohibited by applicable law:
- be limited to matters directly relevant to Convalesce's Processing of Customer Personal Data;
- be coordinated with reasonable advance notice;
- occur during normal business hours;
- minimize disruption to Convalesce;
- protect confidential information belonging to Convalesce and other customers;
- comply with reasonable security requirements;
- not involve penetration testing, vulnerability exploitation, destructive testing, or access to other customers' environments; and
- not provide Customer with access to proprietary source code, model weights, security secrets, credentials, or information unrelated to Customer's own data.
Customer will bear its own costs associated with an audit and, to the extent permitted by applicable law, reasonable costs incurred by Convalesce in providing extraordinary audit assistance.
Nothing in this Section grants Customer broader audit rights than required by Applicable Data Protection Law.
14. Government and Legal Requests
If Convalesce receives a legally binding request from a public authority for Customer Personal Data, Convalesce will, unless legally prohibited:
- review the request;
- seek to limit disclosure to information legally required;
- notify Customer where permitted; and
- provide reasonable information concerning the request where legally permitted.
Convalesce will not voluntarily provide Customer Personal Data to a government authority except where authorized by Customer or required by law.
15. Return and Deletion of Customer
Personal Data
Upon:
- Customer's valid deletion request;
- termination of Customer's account; or
- termination of the Agreement,
Convalesce will delete Customer Personal Data from Convalesce-controlled active systems within 60 days, unless retention is required by applicable law or reasonably necessary to:
- investigate security incidents;
- prevent fraud or abuse;
- resolve an active legal dispute;
- exercise or defend legal claims; or
- comply with a lawful obligation.
Convalesce does not currently create separate application-level backups of Customer Data as part of the Free Beta Service.
Underlying cloud infrastructure may implement technical redundancy, replication, or other resilience mechanisms according to the applicable Subprocessor's services and contractual terms.
Information retained solely because of such infrastructure mechanisms will remain protected under applicable contractual and security requirements and will not be intentionally restored for ordinary Service use after a valid deletion request except where reasonably necessary for disaster recovery, security, or legal compliance.
This Section applies to Customer Personal Data processed on Customer's behalf. Retention of Personal Data that Convalesce Processes as an independent Controller is described separately in the Privacy Policy.
16. Sale, Advertising, and Independent
Commercial Use
Convalesce will not:
- sell Customer Personal Data;
- rent Customer Personal Data;
- use Customer Personal Data for cross-context behavioral advertising;
- disclose Customer Personal Data for targeted advertising unrelated to providing the Service; or
- monetize Customer Personal Data independently from providing and improving the Service as permitted under this DPA.
To the extent an Applicable U.S. Data Protection Law defines Convalesce as a “service provider,” “contractor,” or “processor,” Convalesce will Process Customer Personal Data only for the limited and specified purposes described in the Agreement and this DPA and will comply with applicable restrictions imposed on such service providers, contractors, or processors.
Convalesce will not combine Customer Personal Data with Personal Data obtained from unrelated third parties or from Convalesce's independent interactions with Data Subjects except where permitted by Applicable Data Protection Law and reasonably necessary to provide or secure the Service.
Personal Data that Convalesce collects and Processes as an independent Controller is governed by the Privacy Policy and Applicable Data Protection Law rather than this Section.
17. International Data Transfers
17.1 General
Customer acknowledges that Convalesce's primary hosting infrastructure is located in the United States.
Where Customer Personal Data is transferred internationally, the parties will use a lawful transfer mechanism where required by Applicable Data Protection Law.
17.2 European Economic Area
Where Customer transfers Personal Data subject to the GDPR to Convalesce in a country that does not benefit from an applicable adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses for international transfers adopted under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”).
The applicable module will be:
- Module Two – Controller to Processor, where Customer is a Controller and Convalesce is a Processor; or
- Module Three – Processor to Processor, where Customer is a Processor and Convalesce is a Subprocessor.
For purposes of the EU SCCs:
- Customer is the data exporter;
- Convalesce is the data importer;
- the docking clause in Clause 7 applies;
- for Clause 9, general written authorization for Subprocessors applies;
- the Subprocessor process described in Section 9 applies;
- the optional language in Clause 11 does not apply unless otherwise required;
- Annex I is completed using the information contained in Schedule 1;
- Annex II is completed using the information contained in Schedule 2; and
- Annex III is completed using the Subprocessor information contained in Section 9.2.
For Clause 17, the EU SCCs will be governed by the law of the EU Member State in which Customer is established where that law permits third-party beneficiary rights under the SCCs.
If Customer is not established in an EU Member State, or the relevant law does not permit such rights, the laws of Ireland will apply.
For Clause 18, disputes under the EU SCCs will be resolved by the courts corresponding to the law selected under Clause 17.
The competent supervisory authority will be determined in accordance with Clause 13 of the EU SCCs.
17.3 United Kingdom
Where a transfer is subject to UK Data Protection Law and requires an international-transfer safeguard, the parties incorporate the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (“UK Addendum”).
For purposes of the UK Addendum:
- Customer is the exporter;
- Convalesce is the importer;
- the EU SCC selections specified in Section 17.2 apply as appropriate;
- the information in this DPA and its Schedules supplies the relevant information required by the UK Addendum; and
- Part 2, Mandatory Clauses of the applicable Approved Addendum are incorporated by reference as permitted by the UK Addendum.
If the UK Addendum is replaced or revised by the competent UK authority, the parties will apply the successor mechanism to the extent required by applicable law.
17.4 Switzerland
Where a transfer is governed by the Swiss FADP and requires an international-transfer safeguard, the EU SCCs described above will apply with the modifications necessary for them to address transfers governed by Swiss law.
References to the GDPR will be interpreted to include the Swiss FADP where applicable, references to EU Member States will be interpreted to include Switzerland where necessary, and the competent Swiss supervisory authority will be the Federal Data Protection and Information Commissioner where required.
17.5 Other Jurisdictions
Where another Applicable Data Protection Law requires a specific international-transfer mechanism, the parties will cooperate in good faith to implement a legally valid mechanism where reasonably necessary for Customer's continued use of the Service.
18. Conflict and Order of Precedence
If there is a conflict between this DPA and the Agreement concerning the Processing of Customer Personal Data, this DPA will control to the extent of that conflict.
If there is a conflict between:
1. applicable mandatory international-transfer clauses; 2. this DPA; and 3. the Agreement,
the documents will control in that order solely to the extent necessary to resolve the conflict. Nothing in the Agreement or this DPA modifies the EU SCCs or UK Addendum in a manner prohibited by their terms.
The Privacy Policy governs Convalesce's Processing of Personal Data in its capacity as an independent Controller and does not modify Convalesce's obligations as a Processor or Subprocessor under this DPA.
19. Liability
To the maximum extent permitted by Applicable Data Protection Law, each party's liability arising from or relating to this DPA is subject to the exclusions and limitations of liability contained in the Agreement.
Nothing in this Section limits rights or liabilities that cannot lawfully be limited under:
- Applicable Data Protection Law;
- the EU SCCs;
- the UK Addendum; or
- another mandatory international-transfer mechanism.
20. Term and Termination
This DPA remains in effect for as long as Convalesce Processes Customer Personal Data on behalf of Customer.
Termination of the Agreement will terminate this DPA, except provisions that by their nature must survive termination, including requirements relating to:
- confidentiality;
- deletion;
- international transfers;
- liability; and
- legal compliance.
21. Future Incorporation and Assignment
Customer acknowledges that Convalesce is currently an unincorporated project operated by Samarth KaPatel and Vedanshu Joshi.
If Convalesce is subsequently incorporated or its business or assets are transferred to a corporation or other legal entity, Convalesce may assign this DPA and the associated Processing responsibilities to that entity to the extent permitted by applicable law.
Any successor that assumes this DPA will become responsible for Convalesce's obligations under this DPA from the effective date of the assignment.
22. Contact
Questions concerning this DPA or Convalesce's Processing of Customer Personal Data may be directed to:
Convalesce Operated by Samarth KaPatel and Vedanshu Joshi
Privacy Contact: privacy@convalesce.io
Schedule 1
Details of Processing
A. Parties
Data Exporter
The Customer identified through the Convalesce account, Agreement, signup information, or other applicable service records.
Role: Controller or Processor, depending on Customer's relationship to the Customer Personal Data.
Data Importer
Convalesce, an unincorporated project operated by Samarth KaPatel and Vedanshu Joshi.
Role: Processor or Subprocessor.
Contact: [PRIVACY EMAIL]
B. Subject Matter of Processing
Processing Customer Personal Data as reasonably necessary to provide Convalesce's data-infrastructure investigation and analytical functionality.
C. Duration
For the period Customer uses the Service and for up to 60 days following termination or a valid deletion request, subject to the limited exceptions described in this DPA.
D. Nature of Processing
Processing may include:
- accessing;
- retrieving;
- transmitting;
- temporarily storing;
- organizing;
- correlating;
- querying;
- analyzing;
- redacting;
- masking;
- generating investigation context;
- submitting redacted context for AI inference;
- generating investigation outputs;
- securing;
- troubleshooting; and
- deleting
Customer Personal Data.
E. Purpose of Processing
To provide, operate, secure, troubleshoot, and support Convalesce's investigation functionality for Customer-authorized data infrastructure and workflows.
F. Categories of Data Subjects
Because Convalesce does not determine the contents of Customer-controlled systems, Data Subjects may include any individuals whose information appears in a connected system, including:
- Customer employees;
- contractors;
- consultants;
- users;
- customers;
- end users;
- business contacts;
- vendors;
- partners; and
- other individuals whose information appears in Customer-controlled infrastructure.
G. Categories of Personal Data
Convalesce does not intentionally require specific categories of Personal Data to provide its core investigation functionality.
Depending on Customer's systems, Customer Personal Data may include:
- names;
- business contact information;
- email addresses;
- usernames;
- user identifiers;
- IP addresses;
- device or system identifiers;
- log information;
- authentication-related metadata;
- database records;
- query contents;
- workflow information;
- execution history;
- infrastructure metadata;
- application information;
- source-code-related context;
- configuration information;
- incident-related information; and
- other Personal Data contained in Customer-controlled systems.
Row-level data may be processed where reasonably necessary for a Customer-requested investigation.
H. Sensitive Personal Data
The Free Beta Service is not designed specifically for intentionally submitted Sensitive or Special Category Personal Data.
Customer must not intentionally provide specially regulated information described in Section 5 without Convalesce's express authorization.
Such information may nevertheless be encountered incidentally within Customer-controlled systems.
I. Processing Frequency
Processing occurs as initiated by Customer, triggered by Customer-authorized investigations, or otherwise reasonably necessary to operate and secure the Service.
Schedule 2
Technical and Organizational Measures
Convalesce currently maintains the following technical and organizational measures for the Free Beta:
1. Encryption
- Encryption of information in transit.
2. Authentication
- Multi-factor authentication for internal and administrative access.
3. Authorization
- Role-based access controls.
- Least-privilege service accounts.
- Restrictions on founder and employee access to Customer Data.
4. Secrets Management
- Integration credentials and secrets are managed through Google Secret Manager.
5. Environment Controls
- Separation of relevant development and production environments.
6. Logging
- Audit logging appropriate to the operation and security of the Service.
7. AI Data Controls
- PII-redaction processing occurs within Convalesce's Google Cloud environment before investigation context is submitted to Vertex AI/Gemini.
- Convalesce does not use Customer Personal Data to train generalized models during the Free Beta.
8. Integration Controls
- Customers may revoke connected integrations.
- Following successful revocation, Convalesce stops initiating new requests using the revoked authorization.
9. Data Retention Controls
- Customer Personal Data is retained only as reasonably necessary for the Service.
- Customer Data is scheduled for deletion within 60 days following a valid deletion request or account termination, subject to the limited exceptions described in this DPA.
- Convalesce does not currently create separate application-level backups of Customer Data as part of the Free Beta.
10. Primary Hosting
Convalesce's primary Google Cloud deployment is configured in:
Google Cloud region: us-central1 Primary location: Iowa, United States
Use of Google Cloud remains subject to Google's applicable infrastructure, data-processing, security, resilience, and subprocessor arrangements.