//Legal
Data Processing Addendum
Last updated: 29 July 2026. This addendum forms part of the agreement between Emelum and each ConvoSell customer, and sets out how we process personal data on your behalf.
Roles
For personal data contained in the conversations, carts, orders, and CRM records processed through ConvoSell, the customer is the controller and Emelum is the processor. Emelum processes that data only on the customer's documented instructions, which include the configuration made in the product and the use of the service under the Terms of Service.
Scope and duration
Subject matter: delivery of agentic sales, support, and returns handling. Duration: the term of the customer agreement. Categories of data subject: the customer's prospects, customers, and staff users. Categories of data: contact details, conversation content, order and cart data, and CRM record identifiers. Emelum does not require special-category data and asks customers not to submit it.
Confidentiality and personnel
Personnel with access to customer data are bound by confidentiality obligations and receive access only where needed to operate or support the platform.
Security measures
We apply the technical and organisational measures described on our Security page, including encryption in transit, row-level access control, project-scoped data isolation, least-privilege administrative access, and an audit trail of automated agent actions.
Sub-processors
Emelum engages the categories of sub-processor below to deliver the service. Each is bound by written terms no less protective than this addendum. We will give notice of material changes to this list so that customers can object on reasonable grounds.
| Category | Purpose | Region |
|---|---|---|
| Cloud hosting and database | Runs the application and stores conversation and account data | EU |
| Model inference providers | Generates agent responses from conversation context | EU / US (SCCs) |
| Transactional email delivery | Sends notifications and demo-request confirmations | EU / US (SCCs) |
| Product analytics | Aggregated website and product usage measurement | EU |
Named entities for each category are provided on request at hello@emelum.com.
International transfers
Where personal data is transferred outside the EEA, the transfer relies on Standard Contractual Clauses or an adequacy decision, together with supplementary measures where appropriate.
Assistance and audit
We assist the customer with data subject requests, data protection impact assessments, and regulator engagement, taking into account the nature of processing and the information available to us. On reasonable written notice, and no more than once a year unless required by a supervisory authority, we make available the information needed to demonstrate compliance with this addendum.
Incidents
We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds.
Deletion and return
On termination, and at the customer's choice, we delete or return customer personal data within 30 days, except where storage is required by law. Backups age out on their normal cycle.
Questions about this document? Email hello@emelum.com.