Data Processing Agreement

Last updated: July 17, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Servicebetween iCubeTech Services ("Data Processor" or "we") and the workspace owner ("Data Controller" or "you") for the use of Convora CRM.

This DPA applies to the processing of personal data that you submit to or collect through Convora CRM on behalf of your organization.

1. Definitions

  • "Personal Data" — Any information relating to an identified or identifiable natural person, including lead data submitted through the platform
  • "Processing" — Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion
  • "Data Controller" — The workspace owner who determines the purposes and means of processing personal data
  • "Data Processor" — iCubeTech Services, which processes personal data on behalf of the Data Controller
  • "Sub-processor" — A third party engaged by the Data Processor to process personal data

2. Scope & Purpose of Processing

2.1 Categories of Data Subjects

  • Leads and prospects submitted via forms, webhooks, or ad platform integrations
  • Workspace users (administrators, team leads, members)

2.2 Types of Personal Data

  • Contact information (name, email address, phone number)
  • Form submission data and custom field values
  • Source and attribution data (campaign, ad set, platform identifiers)
  • Lead status, assignment, and activity history
  • User account credentials (email, hashed password)

2.3 Purpose of Processing

We process personal data solely for the purpose of:

  • Providing the Convora CRM service as described in the Terms of Service
  • Receiving and storing lead data from connected sources
  • Routing and assigning leads based on configured rules
  • Sending conversion events to advertising platforms on your behalf
  • Providing analytics and reporting functionality

3. Obligations of the Data Processor

iCubeTech Services shall:

  • Process personal data only on documented instructions from the Data Controller
  • Ensure that persons authorized to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Not engage sub-processors without prior authorization from the Data Controller
  • Assist the Data Controller in responding to data subject requests
  • Delete or return all personal data upon termination of the service, at the Data Controller's request
  • Make available all information necessary to demonstrate compliance with this DPA

4. Obligations of the Data Controller

The Data Controller shall:

  • Ensure that personal data is collected lawfully and with appropriate consent
  • Provide clear instructions regarding the processing of personal data
  • Ensure compliance with applicable data protection laws
  • Notify data subjects about the processing of their data as required by law

5. Security Measures

We implement the following technical and organizational measures:

5.1 Technical Measures

  • Encryption of data in transit using TLS/HTTPS
  • Secure password storage using bcrypt hashing
  • JWT-based session authentication with configurable expiry
  • Multi-tenant data isolation at the database level (org_id scoping)
  • Authenticated webhook endpoints with unique keys per workspace
  • Role-based access control (Super Admin, Org Admin, Team Lead, Member)

5.2 Organizational Measures

  • Access to production systems is restricted to authorized personnel
  • Regular review of access permissions and security configurations
  • Incident response procedures for data breaches

6. Sub-processors

We currently use the following sub-processors:

Sub-processorPurposeLocation
Vercel Inc.Application hosting and deploymentUnited States
VPS ProviderPostgreSQL database hostingAs configured
Meta Platforms, Inc.Lead ads retrieval and conversion API (when connected by Data Controller)United States
Google LLCGoogle Ads conversion tracking (when connected by Data Controller)United States
HostingerTransactional email delivery (SMTP)International

We will notify you before adding or replacing sub-processors. You may object to a new sub-processor within 14 days of notification.

7. Data Subject Rights

We will assist you in fulfilling data subject requests including:

  • Right of access — providing copies of personal data
  • Right to rectification — correcting inaccurate data
  • Right to erasure — deleting personal data
  • Right to data portability — exporting data in a structured format
  • Right to object — ceasing processing upon valid objection

Data subject requests should be directed to support@icubetechservices.com. We will respond within 30 days.

8. Data Breach Notification

  • We will notify the Data Controller of any personal data breach without undue delay, and no later than 72 hours after becoming aware of it
  • The notification will include the nature of the breach, categories of data affected, estimated number of data subjects, and measures taken to mitigate the breach
  • We will cooperate with the Data Controller in investigating and remediating the breach

9. International Data Transfers

Where personal data is transferred outside of India, we ensure appropriate safeguards are in place, including:

  • Use of service providers that maintain adequate data protection standards
  • Contractual obligations with sub-processors regarding data protection
  • Compliance with applicable data transfer regulations

10. Data Retention & Deletion

  • Personal data is retained for the duration of the service agreement
  • Upon termination or request, personal data will be deleted within 30 days
  • Backups containing personal data are purged according to our backup retention schedule
  • The Data Controller may request a copy of their data before deletion

11. Audit Rights

The Data Controller has the right to audit our compliance with this DPA. Audit requests should be submitted in writing with at least 30 days' notice. We will provide reasonable cooperation and access to relevant information.

12. Term & Termination

This DPA remains in effect for the duration of data processing activities. It automatically terminates when we no longer process personal data on your behalf. Obligations regarding data deletion, confidentiality, and security survive termination.

13. Governing Law

This DPA shall be governed by the laws of India, including the Information Technology Act, 2000 and applicable data protection regulations. Disputes shall be subject to the exclusive jurisdiction of the courts in Ahmedabad, Gujarat, India.

14. Contact

For questions regarding this DPA, contact: