Privacy Policy
Last updated: 11 August 2026
The two roles, and why the distinction matters
For your archived conversations, we are a processor. The data originates in your Intercom workspace, it belongs to you, and we act only on your instructions. You are the controller. We never use it for our own purposes, never analyse it to improve the product, and never train models on it.
For your account, we are a controller. Your email address, company name and billing details are ours to hold because you have a relationship with us.
Almost everything below turns on that distinction. If you are an end user whose conversation was archived, we are not the right people to ask — your request goes to the company you spoke to, and we will help them act on it.
Data we hold as controller
- Account and identity: your email address, name, company name and role.
- Billing: company name, billing contact and subscription status. Card details go directly to Razorpay and never reach our systems.
- Security and audit: sign-in times, IP address and user agent, and a record of every access to archived data — retained because an audit trail nobody can alter is the product.
- Support: correspondence you send us.
Our lawful basis is performance of our contract with you, and our legitimate interest in keeping the service secure and accountable.
Data we hold as processor
Whatever exists in the Intercom workspace you connect: conversations and their full message content, contacts, companies, tags, help-centre articles, and the teammates and teams involved. That content may contain personal data about your customers, and its nature is determined by you, not by us.
We read it under a read-only OAuth grant. We cannot write to, modify or delete anything in your Intercom workspace.
How it is protected
- Every archived record is encrypted with its own key before it is stored. The keys are wrapped by a workspace key, which is wrapped by a root key held outside the database.
- Records are written to Amazon S3 under Object Lock, so they cannot be altered or deleted by anyone — including us — for the retention period you set.
- The database that holds pointers and wrapped keys stores no archived message content. Neither store is sufficient on its own.
- Every human view, search, export and download of archived data is written to a hash-chained audit log that rejects edits and deletions at the database level.
Who else processes it
Our sub-processors are listed in full, with what each one can and cannot see, at our sub-processor list. We give 30 days’ notice before adding a sub-processor that handles customer content. To be notified, email security@converight.com.
International transfers
Thinkdata Labs LLP is established in India, which has no EU adequacy decision. Archived content is stored in the AWS region configured for your account, and is accessible to our staff in India for support and operations.
We do not yet publish a Data Processing Addendum, and this policy therefore names no transfer mechanism. Both are with counsel. Until they are settled we are not accepting customers established in the EEA or UK, and we would rather say that plainly than describe a safeguard we cannot yet produce.
If you are outside the EEA and UK but your own customers are inside them, tell us during procurement — that changes what you need from us, and we will tell you exactly where the review stands rather than guess. Email privacy@converight.com.
Retention and deletion
You choose the retention period for archived records; the default is 365 days. Records under an active Legal Hold are preserved past that point until the hold is released.
Disconnecting a workspace destroys the stored access token immediately and stops all backups. Your archive is retained for the documented period after cancellation and then crypto-shredded.
How erasure actually works. Because archived objects are under Object Lock, they cannot be deleted on request — by you, by us, or by AWS. An erasure request instead destroys the encryption key for each affected record. The object remains locked and becomes permanently unreadable by anyone, which achieves erasure in substance while keeping the immutability guarantee intact.
Your rights
Where we are the controller of your account data, you may request access, correction, erasure, restriction, portability, or object to processing. Write to privacy@converight.com and we will respond within 30 days.
Where we are a processor, requests about archived content should go to the company whose workspace holds it. If you contact us directly we will pass the request to them and support them in answering it.
You may complain to a supervisory authority. In the EEA or UK that is the authority for your country of residence.
Contact
Thinkdata Labs LLP, trading as Converight.
Registered office: #176, First Floor, Sector-10, Panchkula, Haryana 134109, India
LLP registration number: AAI-9081
Privacy: privacy@converight.com · Security: security@converight.com
Whether Article 27 requires us to appoint an EEA/UK representative is under the same legal review. This policy will name one, or record that it is not required, once that is settled.
