Legal review required. These documents describe the current implementation and require review by a qualified lawyer. Deployment-specific provider terms and the signed customer agreement must also be checked; this page is not legal advice.
This page summarises the DPA. A signable copy is available from privacy@culvion.ai. Where this page and the signed agreement differ, the signed agreement governs.
Roles
Where you use Culvion to process personal data about your own contacts, you are the controller and Culvion is the processor. Where we process data about you as our customer or website visitor, we are the controller — that is covered by the Privacy Policy.
Subject matter and duration
We process personal data for as long as you have an account, plus the retention windows described below.
- Categories of data subject: your contacts, leads and prospects; your own users.
- Categories of data: identifiers, contact details, communication content, engagement metadata.
- Purpose: providing the Culvion service you have subscribed to.
Our obligations as processor
- Process personal data only on your documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures described below.
- Assist you with data-subject requests, security incidents and impact assessments.
- Delete or return personal data at the end of the agreement.
- Make available the information needed to demonstrate compliance.
Security measures
- Application-level encryption for designated sensitive fields using a configured, versioned key; separate per-record managed keys are not implemented.
- Tenant isolation enforced at the database level by row-level security.
- HTTPS for the public website; internal-service transport depends on the deployment configuration.
- Role-based access control, with step-up re-authentication required for export and erasure.
- Audit logging of privileged actions.
- Rate limiting and bot protection on public endpoints.
Sub-processors
We use the processors listed on the Sub-processors page. We will give notice before adding a new one, and you may object on reasonable data-protection grounds.
International transfers
Processing regions and applicable transfer arrangements must be confirmed in the signed agreement for the configured providers and upstream model routes.
Deletion
The live erasure workflow clears covered contact fields, messages, lead payloads and transcripts after scope and legal-hold checks. It retains an audit tombstone and does not destroy a unique key for each record. Backups may still contain earlier data until they expire. After a restore, operators must replay the erasure tombstones before returning the restored data to service. Provider-deletion intent is logged, not sent automatically to external deletion APIs; provider follow-up and completion require separate verification. Customer-specific return, retention and deletion commitments belong in the signed agreement.
Incidents
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification duties.
Audit
We will respond to reasonable audit requests with documentation. On-site audits are by agreement and at your cost, subject to confidentiality.
Last updated: 5 October 2026.
