This Data Processing Addendum ("DPA") forms part of the agreement between Converge LLC ("Converge") and the client organization identified in the applicable order form or subscription agreement (the "Client") for the Converge platform and related services (the "Agreement"). It applies wherever Converge processes personal data on the Client's behalf that is subject to the GDPR, the UK GDPR, or the Swiss FADP.
The Client accepts this DPA by signing an order form that references it, by signing the signature block at the end of this document, or by continuing to use the platform after Converge has provided it. A Word version is available for signature, and a countersigned copy can be requested from info@startconverge.com.
1. Scope and precedence
1.1 This DPA applies to Client Personal Data (defined below) that Converge processes to provide the services under the Agreement.
1.2 If this DPA conflicts with the Agreement, this DPA prevails on data protection matters. If the Standard Contractual Clauses incorporated by section 11 conflict with this DPA, the Standard Contractual Clauses prevail.
1.3 This DPA does not apply to personal data for which Converge is an independent controller, such as the Client's account and billing contacts, which is governed by Converge's Privacy Policy.
2. Definitions
"Data Protection Laws" means, as applicable to the processing: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as it forms part of the law of the United Kingdom, together with the UK Data Protection Act 2018 (the "UK GDPR"); and the Swiss Federal Act on Data Protection (the "FADP").
"Client Personal Data" means personal data contained in content the Client or its users upload to, create in, or collect through the platform, including data about session participants, as described in Annex I.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
"Sub-processor" means a third party engaged by Converge to process Client Personal Data.
"Controller", "processor", "data subject", "personal data", "personal data breach", "processing" and "supervisory authority" have the meanings given in the GDPR.
3. Roles and Client responsibilities
3.1 For Client Personal Data, the Client is the controller and Converge is the processor. Where the Client itself acts as a processor for its own customers, the Client is the processor and Converge is a sub-processor, and the Client warrants that its customer's instructions and authorisations permit the processing described in this DPA.
3.2 The Client is responsible for: (a) the lawfulness of its instructions and of the processing it directs; (b) providing session participants with any privacy notices required by Data Protection Laws and obtaining any consents required, including for the recording of audio and video where the Client enables recording; (c) the accuracy and content of the recruiting criteria, session guides, and questions it configures; and (d) determining whether any special categories of personal data will be processed and, if so, establishing a lawful basis before the engagement begins.
4. Processing on instructions
4.1 Converge processes Client Personal Data only on the Client's documented instructions, which consist of the Agreement, this DPA, the Client's configuration and use of the platform, and any further written instructions the Client provides. Converge will not process Client Personal Data for its own purposes.
4.2 Converge does not sell Client Personal Data, does not use it for advertising, and does not use it to train, fine-tune, or improve machine learning models, whether its own or a third party's.
4.3 If Converge believes an instruction infringes Data Protection Laws, it will inform the Client promptly and may suspend the affected processing until the instruction is confirmed or amended. If Converge is required by law to process Client Personal Data otherwise than as instructed, it will inform the Client before doing so unless the law prohibits it.
5. Confidentiality and security
5.1 Converge ensures that personnel authorised to process Client Personal Data are bound by written confidentiality obligations and receive security and privacy training on hire and annually.
5.2 Converge implements and maintains the technical and organisational measures described in Annex II. Converge may update those measures from time to time provided the overall level of protection does not fall below that described in Annex II.
6. Sub-processors
6.1 The Client gives Converge general authorisation to engage the Sub-processors listed in Annex III and published at startconverge.com/trust.
6.2 Converge will give the Client at least thirty (30) days' notice before adding or replacing a Sub-processor that processes Client Personal Data, by email to the Client's account contact or by updating the published list and notifying the Client. The Client may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith within thirty (30) days, either party may terminate the affected services on notice, and Converge will refund any prepaid fees for the unused portion of the term.
6.3 Converge imposes on each Sub-processor written data protection obligations that are no less protective than those in this DPA and remains responsible to the Client for each Sub-processor's performance.
7. Assistance to the Client
7.1 Data subject requests. The platform lets the Client access, correct, export, and delete Client Personal Data in the ordinary course. If Converge receives a request directly from a data subject relating to Client Personal Data, it will refer the request to the Client within five (5) business days and will not respond substantively except as instructed by the Client or required by law. Converge will provide reasonable assistance so the Client can respond within the time limits in Data Protection Laws.
7.2 Security, impact assessments, and consultation. Taking into account the nature of the processing and the information available to it, Converge will provide reasonable assistance to the Client in meeting its obligations under Articles 32 to 36 of the GDPR, including by providing the information in Annex II and its most recent SOC 2 report. Converge may charge reasonable fees for assistance that goes materially beyond providing existing documentation.
8. Personal data breaches
8.1 Converge will notify the Client without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Client Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Converge may provide the information in phases as it becomes available.
8.2 Converge will take reasonable steps to contain and remediate the breach and will cooperate with the Client's investigation and any notifications the Client must make. Converge will not notify a supervisory authority or data subjects on the Client's behalf unless the Client instructs it to or the law requires it.
9. Deletion and return
9.1 During the term, the Client controls deletion of Client Personal Data through the platform, including session data and recordings. On the Client's written request, Converge will permanently delete a session and its associated files from Converge's infrastructure and from Sub-processor storage under Converge's control.
9.2 Within thirty (30) days after termination or expiry of the Agreement, Converge will delete all Client Personal Data, unless the Client requests its return before that date, in which case Converge will make it available for export in the platform's standard formats before deleting it. Client Personal Data may persist in encrypted backups for up to ninety (90) days after deletion and is removed as those backups expire. Converge may retain Client Personal Data only where and for as long as the law requires, and will continue to protect it under this DPA.
10. Audit and records
10.1 Converge will make available to the Client, on request and under confidentiality, the information reasonably necessary to demonstrate compliance with this DPA, including its current SOC 2 Type II report, a summary of its most recent penetration test, and responses to a reasonable security questionnaire not more than once per year.
10.2 If that information is insufficient to demonstrate compliance, or a supervisory authority requires it, the Client or an independent auditor it appoints (who is not a competitor of Converge) may audit Converge's relevant controls once in any twelve-month period, on at least thirty (30) days' written notice, during normal business hours, without unreasonable disruption, and subject to confidentiality. The Client bears the cost of the audit unless it reveals a material breach of this DPA.
10.3 Converge maintains a record of the processing it carries out on the Client's behalf as required by Article 30(2) of the GDPR.
11. International transfers
11.1 Converge is established in the United States. To the extent the processing involves a transfer of Client Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties rely on the mechanisms in this section.
11.2 EEA transfers. The SCCs are incorporated into this DPA by reference and apply as follows: Module Two (controller to processor) applies where the Client is a controller, and Module Three (processor to processor) applies where the Client is a processor; the Client is the "data exporter" and Converge is the "data importer"; Clause 7 (docking clause) does not apply; in Clause 9, Option 2 (general written authorisation) applies with a notice period of thirty (30) days; the optional language in Clause 11(a) does not apply; in Clause 13, the supervisory authority is the authority identified in Annex I; in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; in Clause 18, disputes are resolved before the courts of Ireland; Annex I and Annex II of the SCCs are completed by Annex I and Annex II of this DPA; and Annex III of the SCCs is completed by Annex III of this DPA.
11.3 UK transfers. The UK Addendum is incorporated by reference and applies to transfers subject to the UK GDPR. Table 1 of the UK Addendum is completed with the parties' details in Annex I; Table 2 refers to the SCCs as configured in section 11.2; Table 3 refers to Annexes I to III of this DPA; and in Table 4, neither party may end the UK Addendum when the Information Commissioner issues a revised version, except as permitted by section 19 of the UK Addendum.
11.4 Swiss transfers. For transfers subject to the FADP, the SCCs apply with these adjustments: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the governing law and forum in Clauses 17 and 18 are Switzerland where Swiss law so requires; and the term "member state" is read to include Switzerland so that Swiss data subjects may enforce their rights in Switzerland.
11.5 If Converge becomes certified under the EU-US Data Privacy Framework or a successor framework recognised by an adequacy decision, Converge may rely on that certification for the relevant transfers, and the SCCs will continue to apply as a fallback if the framework is invalidated. If any transfer mechanism in this section ceases to be valid, the parties will cooperate in good faith to adopt a replacement without undue delay.
12. Data location
12.1 By default, Converge hosts and stores Client Personal Data on Amazon Web Services in the United States. Sub-processors process data in the locations listed in Annex III.
12.2 Where the order form specifies a different hosting region, Converge will provision a dedicated deployment in that region and will not move Client Personal Data at rest outside it without the Client's written agreement. Sub-processors listed in Annex III may still process data in their stated locations unless the order form excludes them.
13. AI-assisted features
13.1 The platform includes AI-assisted features such as summarisation, thematic analysis, transcription, translation, and a session assistant. The Client controls which of these features are used in its sessions.
13.2 AI providers act as Sub-processors under written terms that prohibit the use of Client Personal Data to train or improve their models and that limit retention to what is needed to provide the service. Where the feature allows it, Converge refers to participants by internal identifiers rather than names in data sent to AI providers.
13.3 AI output is provided to the Client's users as draft material for human review. Converge does not use AI features to make decisions that produce legal or similarly significant effects on data subjects, and the Client agrees not to use the platform to do so.
14. Liability
Each party's liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, and the same aggregate cap applies to liability under the Agreement and this DPA together. Nothing in this section limits either party's liability to data subjects under Clause 12 of the SCCs or liability that cannot be limited by law.
15. Term and general
15.1 This DPA remains in force for as long as Converge processes Client Personal Data, regardless of the expiry or termination of the Agreement.
15.2 Converge may update this DPA to reflect changes in Data Protection Laws or in the platform by publishing a new version at startconverge.com/dpa and notifying the Client. Changes that materially reduce the Client's protections require the Client's agreement.
15.3 Except as required by the SCCs, this DPA is governed by the law that governs the Agreement. If any provision is held invalid, the remainder continues in effect and the parties will replace the invalid provision with a valid one that most closely achieves its purpose.
Signature block (where signed separately)
Converge LLC
Name: ______________________
Title: ______________________
Date: ______________________
Signature: __________________
Client: ______________________
Name: ______________________
Title: ______________________
Date: ______________________
Signature: __________________
Annex I: Parties and description of processing
A. List of parties
Data exporter (Client): the client organization named in the order form, acting as controller (or as processor under section 3.1). Contact: the Client's account administrator or the data protection contact named in the order form.
Data importer (Converge): Converge LLC, 10040 E. Happy Valley Rd, Scottsdale, AZ 85255, United States. Contact: info@startconverge.com. Role: processor (or sub-processor under section 3.1).
B. Description of processing
| Categories of data subjects | The Client's users (administrators, moderators, observers); participants invited to or recruited for the Client's sessions; where the Client uses in-depth interviews, interviewees. |
|---|---|
| Categories of personal data | Identity and contact data (name, email address, username); role and organisation; contributions made in sessions (written responses, comments, votes, ratings, rankings, uploads); audio and video recordings and transcripts where recording is enabled; technical data (IP address, device and browser information, timestamps); where the Client uses the recruiting integration, the profile and screener information supplied by the panel according to the Client's criteria. |
| Special categories of data | None required by the platform. Processed only where the Client's research design or recruiting criteria include them, in which case the Client is responsible for a lawful basis and any required safeguards, and Converge applies the measures in Annex II. |
| Frequency of the transfer | Continuous, for the duration of the Agreement. |
| Nature of the processing | Hosting, storage, transmission, display, recording, transcription, translation, AI-assisted analysis and summarisation, reporting, export, and deletion. |
| Purpose of the processing | Providing the Converge platform to the Client for facilitated research and stakeholder engagement sessions and for the analysis and reporting of their results. |
| Duration of processing and retention | The term of the Agreement, plus the deletion period in section 9. Within the term, retention is controlled by the Client through the platform. |
| Transfers to Sub-processors | As listed in Annex III, for the purposes and durations stated there. |
C. Competent supervisory authority
The supervisory authority of the EEA member state in which the Client is established or, where the Client is not established in the EEA, the authority of the member state in which the Client's EU representative is established or in which the data subjects concerned are located. For UK transfers, the Information Commissioner. For Swiss transfers, the Federal Data Protection and Information Commissioner.
Annex II: Technical and organisational measures
| Encryption | TLS for all data in transit. Encryption at rest for databases, file storage, recordings, and backups using cloud-provider managed encryption. |
|---|---|
| Access control | Role-based permissions inside the platform from observer to administrator; single sign-on (SAML 2.0, Okta) and SCIM provisioning available; multi-factor authentication for accounts; least-privilege access to production systems with periodic access reviews. |
| Tenant separation | Client workspaces are logically separated in the shared environment. Dedicated single-tenant deployments with their own infrastructure are available under the order form. |
| Data minimisation | Sessions can allow anonymous participation with no name or email collected; anonymity can be locked by the moderator; where the feature allows it, participants are referred to by internal identifiers in data sent to AI providers. |
| Availability and resilience | Automated encrypted backups; documented business continuity and disaster recovery plans; cloud infrastructure with network protection and content delivery in front of the platform. |
| Testing and assurance | Annual SOC 2 Type II examination by an independent CPA firm; annual penetration testing by an independent firm; continuous vulnerability scanning of the cloud environment with findings tracked to closure. |
| Secure development | Documented software development lifecycle with code review and change management; vulnerability management policy with remediation timelines. |
| Logging and monitoring | Centralised logging of platform activity and administrative actions; monitoring for security events; a documented incident response plan with client notification procedures. |
| Personnel | Background checks on hire; written confidentiality obligations; security and privacy awareness training on hire and annually; a documented set of information security, data protection, data retention, and AI governance policies. |
| Vendor management | Due diligence before engaging Sub-processors; written data protection terms with each; periodic review; the published list in Annex III. |
| Deletion | Client-controlled deletion of sessions, responses, and recordings; permanent deletion of a session and its files on request; deletion of all Client Personal Data within thirty days of termination, with backups expiring on a rolling cycle. |
| Assistance to the Client | Referral of data subject requests within five business days; export of Client data in standard formats; provision of the SOC 2 report, penetration test summary, and questionnaire responses to support the Client's assessments. |
Annex III: Sub-processors
The current list is maintained at startconverge.com/trust. As of the date of this version:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, file storage, transactional email, logging | United States |
| Cloudflare, Inc. | Network security, content delivery, hosting of uploaded video | United States |
| Zoom Video Communications, Inc. | Live audio and video, recording, transcription | United States |
| Anthropic, PBC | AI analysis and the in-session AI assistant | United States |
| OpenAI, L.L.C. | AI analysis and transcript summaries | United States |
| DeepL SE | Machine translation of session content | Germany |
| User Interviews, Inc. | Participant recruiting panel (only where the Client uses recruiting) | United States |
| Nylas, Inc. | Calendar sync for interview scheduling (only where the Client connects a calendar) | United States |
| Stripe, Inc. | Payment processing (Client billing data only) | United States |
| Google LLC (Google Workspace) | Business email and documents for support correspondence | United States |