Privacy Policy

Last Updated: June 20, 2025

This Privacy Policy describes how Make Industry, LLC, doing business as ConvoPath ("ConvoPath," "we," "us," or "our") collects, uses, and protects your information when you use our AI chatbot creation and management platform.

1. Introduction

ConvoPath is committed to protecting your privacy and handling your personal information transparently. This Privacy Policy explains our practices regarding data collection, use, sharing, and protection when you use our Service.

1.1 Scope of This Policy

This Privacy Policy applies to:

  • Information collected through our website and platform
  • Data processed when you use our Service
  • Communications between you and ConvoPath

1.2 Data Controller vs. Data Processor

  • For Customer Data: We act as a data controller
  • For End User Data: Our Customers act as data controllers, and we act as a data processor
  • End Users interacting with Customer chatbots should refer to the Customer's privacy policy

2. Information We Collect

2.1 Information You Provide Directly

Account Information:

  • Name and email address
  • Company information
  • Authentication credentials
  • Communication preferences
  • Payment information (processed securely through Stripe)

Service Content:

  • Chatbot configurations and settings
  • Training data you upload
  • Custom knowledge base content
  • Support requests and correspondence

2.2 Information Collected Automatically

Usage Data:

  • How you interact with our Service
  • Features you use and frequency of use
  • Time spent on different sections
  • Error logs and performance data

Technical Information:

  • IP address and general location data
  • Device and browser information
  • Operating system information
  • Referring website information

Cookies and Tracking:

  • Session cookies for authentication
  • Preference cookies for settings
  • Analytics cookies (Google Analytics)
  • Performance monitoring data

2.3 End User Data (Data Processing)

When End Users interact with Customer chatbots, we process:

  • Conversation logs and messages
  • Session data and interaction patterns
  • Technical data (IP addresses, browser info)

Important: We process this data solely on behalf of our Customers. Customers are responsible for obtaining appropriate consents and maintaining privacy policies for their End Users.

3. Legal Basis for Processing (GDPR)

We process personal data based on the following legal grounds:

3.1 Contract Performance

  • Providing the ConvoPath Service
  • Processing payments and managing subscriptions
  • Customer support and communications

3.2 Legitimate Interests

  • Improving our Service and user experience
  • Security monitoring and fraud prevention
  • Analytics and performance optimization
  • Marketing to existing customers

3.3 Legal Compliance

  • Complying with applicable laws and regulations
  • Responding to legal requests and court orders
  • Tax and accounting requirements

3.4 Consent

  • Marketing communications (where required)
  • Optional data processing activities
  • Cookies and tracking (where required)

4. How We Use Your Information

4.1 Service Provision

  • Create and manage your account
  • Process your chatbot configurations
  • Enable chatbot functionality and responses
  • Provide customer support
  • Process payments and manage billing

4.2 Service Improvement

  • Analyze usage patterns to enhance features
  • Monitor performance and fix issues
  • Develop new features and capabilities
  • Conduct research and analytics

4.3 Security and Compliance

  • Detect and prevent fraud or abuse
  • Protect against security threats
  • Comply with legal obligations
  • Maintain audit logs and records

4.4 Communications

  • Send service-related notifications
  • Provide customer support
  • Share product updates and announcements
  • Send marketing communications (with consent)

5. Data Sharing and Disclosure

5.1 We Share Data With:

Service Providers:

  • Stripe (payment processing)
  • Google Analytics (website analytics)
  • Cloud hosting providers (data storage and processing)
  • Email service providers (communications)
  • Customer support tools

Business Transfers:

  • In connection with mergers, acquisitions, or asset sales
  • Data will remain subject to existing privacy commitments

Legal Requirements:

  • When required by law or legal process
  • To protect our rights, property, or safety
  • To prevent fraud or illegal activities

5.2 We Do NOT:

  • Sell or rent your personal information
  • Share your data for third-party marketing
  • Use your training data for our own purposes
  • Share customer data between different customers

6. Data Security

6.1 Security Measures

We implement comprehensive security measures:

  • Encryption: Data encrypted in transit and at rest
  • Authentication: Multi-factor authentication available
  • Access Controls: Limited employee access on need-to-know basis
  • Monitoring: Continuous security monitoring and threat detection
  • Audits: Regular security assessments and updates

6.2 Incident Response

  • We maintain an incident response plan
  • Affected users will be notified of significant breaches
  • We cooperate with law enforcement when appropriate

6.3 Third-Party Security

  • All service providers must meet our security standards
  • We regularly review third-party security practices
  • Data processing agreements include security requirements

7. Data Retention

7.1 Customer Data

  • Account Data: Retained while your account is active and for a reasonable period after termination
  • Billing Data: Retained as required by applicable tax and accounting laws
  • Support Data: Retained for a reasonable period to improve service quality

7.2 End User Data

  • Conversation Logs: Retained as directed by Customers
  • Analytics Data: Aggregated data retained indefinitely
  • Individual Data: Deleted when Customer requests or account terminates

7.3 Deletion Timeline

  • Account Deletion: Data deleted within 90 days of request
  • Legal Hold: Some data may be retained longer if required by law
  • Anonymized Data: May be retained indefinitely for analytics

8. Your Privacy Rights

8.1 Access and Control

You have the right to:

  • Access: Request copies of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a portable format
  • Restriction: Limit how we process your data
  • Objection: Object to processing based on legitimate interests

8.2 Marketing Preferences

  • Opt out of marketing emails at any time
  • Unsubscribe links in all marketing communications
  • Contact us to update your preferences

8.3 Exercising Your Rights

To exercise your privacy rights:

  • Contact us at https://convopath.com/contact
  • We will respond within 30 days
  • Identity verification may be required
  • Some requests may have limitations under applicable law

9. International Data Transfers

9.1 Data Locations

  • Primary data processing occurs in the United States
  • Some service providers may process data in other countries
  • All transfers include appropriate safeguards

9.2 Transfer Mechanisms

For transfers outside your country, we use:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by relevant authorities
  • Other legally recognized transfer mechanisms

10. Cookies and Tracking Technologies

10.1 Types of Cookies We Use

Essential Cookies:

  • Authentication and session management
  • Security and fraud prevention
  • Core Service functionality

Performance Cookies:

  • Google Analytics (website usage)
  • Error tracking and performance monitoring
  • Service optimization data

Preference Cookies:

  • User interface settings
  • Language and region preferences
  • Customization options

10.2 Cookie Management

  • Most browsers allow you to control cookies
  • Disabling cookies may affect Service functionality
  • Third-party cookies are subject to their privacy policies

11. California Privacy Rights (CCPA)

11.1 California Residents' Rights

Under the California Consumer Privacy Act, you have the right to:

  • Know what personal information we collect and use
  • Delete your personal information
  • Opt-out of sale of personal information
  • Non-discrimination for exercising your rights

11.2 We Do Not Sell Personal Information

ConvoPath does not sell personal information as defined by CCPA.

11.3 Exercising CCPA Rights

California residents can exercise their rights by contacting us at https://convopath.com/contact

12. Children's Privacy

12.1 Age Restrictions

  • Our Service is not intended for individuals under 18
  • We do not knowingly collect data from children under 13
  • If we discover such collection, we will delete the data promptly

12.2 Parental Notice

If you believe we have collected information from a child under 13, please contact us immediately.

13. Data Processing for Customers

13.1 Customer Responsibilities

As a Customer using ConvoPath, you are responsible for:

  • Obtaining necessary consents from your End Users
  • Maintaining appropriate privacy policies
  • Complying with applicable privacy laws (GDPR, CCPA, etc.)
  • Providing accurate information about data processing

13.2 Data Processing Agreement

  • Business customers may request a separate Data Processing Agreement
  • This covers our role as data processor for End User data
  • Contact us for enterprise-grade data processing terms

14. Third-Party Services

14.1 Integrated Services

Our Service integrates with third-party providers:

  • Stripe: Payment processing (see Stripe's privacy policy)
  • Google Analytics: Website analytics (see Google's privacy policy)
  • OpenAI: AI language processing (see OpenAI's privacy policy)

14.2 Third-Party Links

  • Our Service may contain links to third-party websites
  • We are not responsible for third-party privacy practices
  • Please review their privacy policies before providing information

15. Updates to This Privacy Policy

15.1 Policy Changes

We may update this Privacy Policy to reflect:

  • Changes in our data practices
  • New legal requirements
  • Service improvements and updates

15.2 Notification of Changes

  • Significant changes will be announced via email or Service notifications
  • Continued use constitutes acceptance of changes
  • You may close your account if you disagree with changes

15.3 Version History

The "Last Updated" date at the top indicates when this policy was last revised.

16. International Users

16.1 Data Protection Authorities

If you are in the European Economic Area, you have the right to lodge a complaint with your local data protection authority.

16.2 EU Representative

For substantial EU operations, we will appoint an EU representative as required by GDPR.

17. Data Breach Notification

17.1 Our Commitment

  • We will notify affected users of significant data breaches as soon as reasonably practicable
  • We will provide information about the breach and remedial actions
  • Notification timing will comply with applicable legal requirements

17.2 Regulatory Notification

We will notify relevant authorities as required by applicable law.

18. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or your personal information:

Contact Us:

https://convopath.com/contact

Response Time:

We will respond to privacy inquiries within 2 business days and formal requests within 30 days.


This Privacy Policy is designed to be transparent about our data practices while protecting both our business interests and your privacy rights. If you have questions about any aspect of this policy, please don't hesitate to contact us.