Converight Sub-processor List
Last updated: 27 August 2026 · Applies to: Converight v1.1.0 Data processor: Thinkdata Labs LLP, trading as Converight
This document lists every third party that processes, stores, or transmits customer data on behalf of Thinkdata Labs LLP.
Under GDPR terms: the customer is the controller of the data in their Intercom workspace; Thinkdata Labs LLP is the processor; every party listed below is a sub-processor.
We will give 30 days' notice before adding a sub-processor that processes
customer content. To be notified, email security@converight.com.
The contracting entity, for the DPA your legal team will want to put this in:
| Legal entity | Thinkdata Labs LLP |
| Registration number | AAI-9081 |
| Registered office | #176, First Floor, Sector-10, Panchkula, Haryana 134109, India |
| Jurisdiction | India |
| Contact | security@converight.com |
"Converight" is a trading name, not a counterparty. Contract with the LLP.
Because Thinkdata Labs LLP is established in India, which has no EU adequacy decision, transfers of EU or UK personal data rely on the mechanism set out in our Data Processing Addendum. Whether GDPR Art. 27 requires us to appoint an EU/UK representative is under legal review and this document will name one, or record that it is not required, once that is settled.
Sub-processors that handle customer content
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Intercom Inc. | Source system. Converight reads from the customer's own Intercom workspace under a read-only OAuth grant. | Conversations, contacts, companies, tags, articles, admins, teams | Per the customer's own Intercom region (US / EU / AU) |
| Amazon Web Services (S3) | Archive storage. Every archived record is stored encrypted, under Object Lock. | Encrypted record payloads and generated export bundles | Configured region — single region at launch |
| Render Services, Inc. | Runs the API, worker and dashboard; hosts the managed PostgreSQL and Redis instances. | Application metadata, and — in plaintext, so the archive can be searched — the identifiers attached to each archived record: end-user names, email addresses, conversation titles, tags, and pseudonymous Intercom contact IDs. Also the email addresses of your own Converight users, the audit log including the email address of whoever performed each action, wrapped key material and job state. Archived conversation content is not here; it is encrypted in S3. | US (Virginia) |
On the Render row. An earlier version of this list described that store as "metadata … no archived record content". True about content, and it undersold what is there: the archive is searchable, and search needs names and email addresses in a form a database can index. So they are held in plaintext, and saying "metadata" invited a reader to assume otherwise.
A security questionnaire asking "is any personal data stored outside your encrypted archive?" gets yes, and it should get it from this page rather than from a diligence call three weeks into an evaluation.
Erasure reaches this store: crypto-shredding nulls the name, email, title and tag columns as well as destroying the record's key, and removes the link joining that conversation to an Intercom contact ID once no readable version of it remains. An erased conversation leaves nothing recording that a particular person took part in it.
Sub-processors that do not handle customer content
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Razorpay Software Private Limited | Subscription billing. Razorpay is an Indian entity, as is Thinkdata Labs LLP, so this involves no cross-border transfer of billing data. | Billing contact, company name, payment details. Card data goes directly to Razorpay and never touches Converight infrastructure. |
| Sentry (optional; disabled unless a DSN is configured) | Error tracking. | Stack traces and request metadata. Cookies, tokens, and key material are redacted before transmission; archived record content is never sent. |
| Amazon Web Services (SES) | Sends sign-in links and team invitations. Transactional mail only — we operate no lists and send no marketing. | Email addresses and one-time sign-in links. No customer archive data. |
| Cloudflare, Inc. | Authoritative DNS for converight.com. | DNS queries only. Cloudflare's proxy is not enabled, so no request content passes through it. |
If the Cloudflare proxy is ever enabled, Cloudflare terminates TLS and therefore sees every request and response in transit, including archived record content on its way to the dashboard. That moves it into the table above — a sub-processor handling customer content — and requires 30 days' notice to customers. It is a compliance decision, not just a networking one.
What each party can and cannot see
- Archived conversation content exists in exactly one place: the S3 archive bucket, encrypted with a per-record data key. AWS holds ciphertext; the keys that decrypt it are wrapped and held in Converight's PostgreSQL database. Neither store is sufficient on its own.
- PostgreSQL never stores archived record content. It stores pointers, checksums, wrapped keys, job state, the audit log, and a deliberately minimal search index (record type, display name or subject, tags, dates, state) — see Data handling for the exact fields and why they are there.
- Converight staff cannot alter or delete an archived object. S3 Object Lock applies to every principal, including our own administrative accounts.
Open items
- No cross-region replication of the archive bucket. A single-region AWS outage is an availability event, not a data-loss one, but it is stated here rather than left to be discovered in a questionnaire.
- The GDPR Art. 27 representative question is under legal review, as noted above.
