← Back to home

Privacy Policy

Effective date: 1 March 2026

1. Who We Are

Conversent ("we", "our", or "us") operates the website and SaaS platform at conversent.app. We are the data controller for the personal data described in this Privacy Policy. Our registered address: Belgrade, Serbia. For questions, contact us at [email protected].

2. Data We Collect

We collect the following categories of personal data:

  • Account data: name, email address, phone number, city, postal code, address
  • Usage data: widget interactions, AI response counts, session identifiers
  • Technical data: IP address, browser type, device type, pages visited, timestamps
  • Payment data: handled by our payment processor; we do not store full card numbers
  • Communications: messages you send us via email or support forms

3. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Contract performance — to provide the service you subscribed to (Art. 6(1)(b) GDPR)
  • Legitimate interests — fraud prevention, security, service improvement (Art. 6(1)(f) GDPR)
  • Legal obligation — tax records, accounting (Art. 6(1)(c) GDPR)
  • Consent — marketing communications (Art. 6(1)(a) GDPR) — you may withdraw at any time

4. How We Use Your Data

  • Create and manage your account
  • Deliver and improve the platform
  • Process payments and send invoices
  • Send transactional emails (verification, password reset, billing)
  • Provide customer support
  • Comply with legal obligations
  • Detect and prevent fraud and abuse

5. Data Sharing

We do not sell your personal data. We may share data with:

  • Cloud infrastructure providers (e.g. AWS, Hetzner) — for hosting
  • Payment processors (e.g. PayPal, NestPay) — for subscription billing
  • Email service providers — for transactional emails
  • AI providers (e.g. OpenAI) — to process AI queries on your behalf
  • Legal authorities — when required by law

All processors are bound by data processing agreements and required to protect your data.

6. International Transfers

Some of our service providers are located outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Data Retention

We retain your personal data for as long as your account is active. After account deletion, we delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes (e.g. tax records are retained for 5 years as required by law).

8. Your Rights (GDPR / ZZPL)

You have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure ("right to be forgotten") — delete your account and data via Settings → Delete Account
  • Restriction — ask us to limit processing of your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw at any time

To exercise your rights, contact us at [email protected]. You also have the right to lodge a complaint with your national data protection authority (in Serbia: Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti; in the EU: your local DPA).

9. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell
  • Delete personal information we hold about you
  • Opt-out of the sale of personal information — we do not sell personal data
  • Non-discrimination for exercising your privacy rights

To submit a request, contact us at [email protected].

10. Cookies and Local Storage

We use browser localStorage to store your authentication token and session preferences. For details on cookies and tracking, see our Cookie Policy. Cookie Policy.

11. Security

We implement industry-standard technical and organisational security measures including encrypted connections (HTTPS/TLS), hashed passwords, access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (e.g. the Commissioner for Information of Public Importance and Personal Data Protection in Serbia, or your local DPA in the EU) without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to you, we will also inform you without undue delay. We maintain an internal incident response procedure to detect, assess, and respond to data breaches.

13. Children's Privacy

Our service is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by email or by displaying a prominent notice on our website. Continued use of the service after changes constitutes acceptance of the updated policy.

15. Contact

For any privacy-related questions or requests, contact us at: [email protected]