Legal
GDPR and data rights
Convyx is designed around data minimization. We collect account data needed to operate the service, conversion metadata needed to process and display jobs, and files you explicitly upload. We do not use uploaded files to train machine-learning models.
Retention and deletion
You select a retention window per conversion, subject to plan limits. The countdown starts after completion. Expired source and result objects are hard-deleted from the underlying S3-compatible store by the worker sweep. “Delete immediately” includes a five-minute download grace period.
Security controls
Production traffic is intended to use TLS. Objects are stored under isolated user/job keys, downloads use expiring signed URLs, and production storage can enforce AES-256 SSE-S3. API keys are hashed rather than stored in plaintext.
Processors and international use
Convyx relies on infrastructure providers to host the application and S3-compatible storage, and on Polar when paid billing is configured. The exact deployment provider can vary. Enterprise customers can request a Data Processing Addendum describing the applicable processing arrangement before sending regulated workloads.
Access, correction, portability, and erasure
To make a data-subject request, email [email protected] from the address associated with the account. We may need to verify identity before disclosing or deleting account data. Requests are handled within the time required by applicable law.
For the complete categories of data and purposes, read the Privacy Policy. Technical controls are described on the Security page.