Data Processing Agreement
Our data processing agreement (DPA) for personal data
Last updated: August 18, 2026 · Version 2026-08-18
This Data Processing Agreement (the "DPA" or "Processing Agreement") is entered into between the Controller and the Processor identified below and forms an integral part of Connver's Terms of Service. It governs the processing of personal data that the Processor carries out on behalf of the Controller, in accordance with Mexico's Federal Law on Protection of Personal Data Held by Private Parties ("LFPDPPP"), in force since March 21, 2025, and its applicable regulations.
In the event of any conflict between the Spanish version and any translation, the Spanish version prevails.
1. Parties
Data controller: the Connver tenant (team account) that contracts the Service and determines the purposes and means of processing the personal data of its contacts (the "Controller"), acting as such under article 3, section XIV, of the LFPDPPP.
Data processor: Voltaflow LLC, a limited liability company organized in the State of Wyoming, USA, with registered address at 1021 E Lincolnway, 7729, Cheyenne, WY 82001, US (the "Processor" or "Voltaflow"), which processes personal data on behalf of and under the documented instructions of the Controller.
Contact for matters under this DPA and for exercising rights: hi@connver.com.
2. Purpose and scope
The Controller instructs the Processor to process the personal data of the contacts the Controller manages through the Service, solely to provide and operate Connver on the Controller's behalf.
The data subject to processing is: (a) messages exchanged through the connected channels (WhatsApp and others); (b) each contact's record (name, phone number and any other data the Controller registers); and (c) the product catalog and associated configurations. Expressly excluded are the Controller's own billing data, which is processed by Paddle.com Market Ltd as Merchant of Record, and the Controller's user account data, for which Voltaflow is the data controller in its capacity as Service provider.
3. Documented instructions
The Processor will process personal data solely in accordance with the Controller's documented instructions, which are understood to be contained in the Terms of Service, this DPA and the configurations the Controller makes within the Service (automations, policies, agent persona and other settings).
The Processor will not use the data for purposes other than those instructed and, in particular, will not use it to train third-party models or for purposes unrelated to providing the Service to the Controller. Any instruction that the Processor believes infringes the LFPDPPP will be communicated to the Controller; the Processor may suspend its execution until it receives confirmation or correction.
4. Confidentiality
The Processor and its personnel will keep the processed personal data confidential, including after processing ends, in accordance with article 20 of the LFPDPPP.
Access to the data is limited to those who need it to provide the Service, under confidentiality obligations and the least-privilege principle.
5. Sub-processors
The Processor may use sub-processors to provide the Service. The current list of sub-processors is the one described in the "Subprocessors" section of Connver's Privacy Notice, available at /privacidad, and is incorporated by reference into this DPA.
Each sub-processor is bound by confidentiality and security obligations equivalent to those in this DPA. The Processor will notify the Controller of any addition or replacement of sub-processors by updating the Privacy Notice and will honor the Controller's right to object on legitimate grounds by writing to hi@connver.com. In the event of a justified objection, the Processor may, at its election, stop using that sub-processor for the Controller's data or allow the Controller to terminate the contract without penalty.
6. Security measures
The Processor implements and maintains the technical, administrative and physical security measures necessary to protect personal data against damage, loss, alteration, destruction or unauthorized use, access or processing, in accordance with article 18 of the LFPDPPP.
Such measures include, without limitation: encryption in transit (TLS) and at rest, tenant isolation via Postgres Row Level Security, available multi-factor authentication and the least-privilege principle in internal accesses.
7. Assistance with ARCO rights
The Processor will assist the Controller, to the extent reasonably possible and through appropriate technical and organizational measures, in handling Access, Rectification, Cancellation and Opposition (ARCO) requests submitted by data subjects.
The Controller is the data subjects' point of contact and is responsible for processing requests. The Processor will make the Service's mechanisms available to the Controller and, where necessary, will address specific requests the Controller sends to hi@connver.com.
8. Security breaches
In the event of a security breach affecting the personal data processed on the Controller's behalf, the Processor will notify the Controller without undue delay and, in any case, within a period that allows the Controller to meet its obligations before the competent authority (the Secretariat of Anti-Corruption and Good Governance) and before data subjects, in accordance with article 19 of the LFPDPPP.
The notification will include, where available, the nature of the breach, the categories and approximate number of data subjects and records affected, the measures taken or proposed to contain it, and a point of contact for further information.
9. Duration, deletion and return
This DPA remains in force while the Service is provided to the Controller and the Processor processes personal data on its behalf.
Upon termination of the Service, the Processor will retain the data for the 90-calendar-day retention period described in the Privacy Notice, after which it will delete or anonymize it, except for legal retention obligations. At the Controller's request and where technically feasible, the Processor will facilitate export of the data before deletion.
10. Liability
The parties' liability is governed by article 53 of the LFPDPPP and, where applicable, by the limitation of liability section of the Terms of Service.
The Controller declares that it holds the legal bases necessary for processing its contacts' personal data and is responsible for the instructions it issues. The Processor is liable for damages it causes when it has failed to comply with the obligations of this DPA or has acted outside the Controller's documented instructions.
11. Acceptance and contact
This DPA is accepted by checking the acceptance box during the Service onboarding process, and is recorded with the current version indicated at the top of this document. Future amendments will be notified in accordance with the Terms of Service and will require new acceptance.
Voltaflow LLC · 1021 E Lincolnway, 7729, Cheyenne, WY 82001, US · hi@connver.com.