Back to Home

Data Processing Addendum

Last updated: August 8, 2026

1. Parties and roles

This Addendum applies when an organization buys ConvoSparr for its team. In that arrangement the Organization is the data controller for its members' practice data, and Tarsonix Technologies (OPC) Private Limited, which operates ConvoSparr, is the processor acting on its instructions.

It does not change individual accounts. Where a person buys ConvoSparr for themselves, we remain the controller and our Privacy Policy governs.

It is incorporated by reference into the Business Terms, so an Organization that accepted those has accepted this.

2. Subject matter, duration, nature and purpose

We process the Organization's personal data to provide sales-conversation practice: running live voice sessions, producing transcripts, scoring them, and making the results available to the members and administrators the Organization designates. Processing lasts for as long as the Organization's subscription is live, plus the retention window in section 10.

3. Categories of data subjects and personal data

Data subjects are the Organization's members. The personal data comprises:

  • Identity and account data: name, work email address, role and group.
  • Session audio, while a practice session is running.
  • Transcripts of those sessions.
  • Scores, dimension ratings and coaching notes produced from them.
  • Usage metadata: timestamps, durations, credits consumed, device and IP metadata.

We do not ask for special-category data and instruct members not to speak it during sessions. Call audio is not retained today; if that changes, this Addendum and the in-app monitoring notice are updated first.

4. Processing on documented instructions

We process personal data only on the Organization's documented instructions, including the Business Terms, the configuration chosen in the product, and any further written instruction we accept. If we believe an instruction breaches data-protection law we will say so rather than act on it.

5. Confidentiality

Everyone we authorise to process this data is bound by confidentiality obligations and has access only where their role requires it.

6. Security measures

We apply the technical and organisational measures described in section 5 of our Privacy Policy, including encryption in transit, access control and least-privilege service credentials, row-level isolation between organizations in the database, and audit logging of administrative actions. Those measures are stated in one place on purpose, so the two documents cannot describe different security postures.

7. Subprocessors

The Organization authorises the subprocessors listed on our Subprocessors page, which names each provider, its legal entity, what it does, and what data it sees. We update that page when the list changes and will notify an Organization that has asked to be told. Each subprocessor is bound by terms no less protective than these.

8. Assistance with data-subject requests

Members retain their statutory rights of access, rectification, erasure and portability regardless of the Organization's ownership of the data commercially. Because a team account disables self-serve deletion, those requests come to us or to the Organization and we handle them together. Write to privacy@convosparr.com. We verify identity before acting, and we tell the Organization when we act on one of its members' requests.

9. Personal data breach notification

We notify the Organization without undue delay after becoming aware of a personal data breach affecting its data, with the information it needs to meet its own notification obligations, and we keep it updated as we learn more.

10. Deletion and return

Data is kept while the subscription is live. On cancellation the Organization has a 90-day window to request an export, after which the data is permanently deleted, including from backups on their normal rotation. A departed member's data stays with the Organization for the same period rather than leaving with them.

11. Audits and information

On reasonable written request, and no more than once a year unless a regulator requires otherwise, we provide the information needed to demonstrate compliance with this Addendum.

12. International transfers

We are established in India and our subprocessors are largely in the United States and the United Kingdom, so personal data is transferred internationally. Those transfers rely on the appropriate safeguards described in our Privacy Policy, including standard contractual clauses where they apply.

13. Contact

Tarsonix Technologies (OPC) Private Limited
Data protection: privacy@convosparr.com
For a countersigned copy of this Addendum, write to the same address.