//Legal

Data Processing Addendum

Last updated: 29 July 2026. This addendum forms part of the agreement between Emelum and each ConvoSell customer, and sets out how we process personal data on your behalf.

Roles

For personal data contained in the conversations, carts, orders, and CRM records processed through ConvoSell, the customer is the controller and Emelum is the processor. Emelum processes that data only on the customer's documented instructions, which include the configuration made in the product and the use of the service under the Terms of Service.

Scope and duration

Subject matter: delivery of agentic sales, support, and returns handling. Duration: the term of the customer agreement. Categories of data subject: the customer's prospects, customers, and staff users. Categories of data: contact details, conversation content, order and cart data, and CRM record identifiers. Emelum does not require special-category data and asks customers not to submit it.

Confidentiality and personnel

Personnel with access to customer data are bound by confidentiality obligations and receive access only where needed to operate or support the platform.

Security measures

We apply the technical and organisational measures described on our Security page, including encryption in transit, row-level access control, project-scoped data isolation, least-privilege administrative access, and an audit trail of automated agent actions.

Sub-processors

Emelum engages the categories of sub-processor below to deliver the service. Each is bound by written terms no less protective than this addendum. We will give notice of material changes to this list so that customers can object on reasonable grounds.

CategoryPurposeRegion
Cloud hosting and databaseRuns the application and stores conversation and account dataEU
Model inference providersGenerates agent responses from conversation contextEU / US (SCCs)
Transactional email deliverySends notifications and demo-request confirmationsEU / US (SCCs)
Product analyticsAggregated website and product usage measurementEU

Named entities for each category are provided on request at hello@emelum.com.

International transfers

Where personal data is transferred outside the EEA, the transfer relies on Standard Contractual Clauses or an adequacy decision, together with supplementary measures where appropriate.

Assistance and audit

We assist the customer with data subject requests, data protection impact assessments, and regulator engagement, taking into account the nature of processing and the information available to us. On reasonable written notice, and no more than once a year unless required by a supervisory authority, we make available the information needed to demonstrate compliance with this addendum.

Incidents

We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds.

Deletion and return

On termination, and at the customer's choice, we delete or return customer personal data within 30 days, except where storage is required by law. Backups age out on their normal cycle.

Questions about this document? Email hello@emelum.com.