Privacy Policy

The steps we take to ensure your privacy and protection with Convosight

  • 1. Who we are

    Convosight Analytics Private Limited, of 55, 2nd Floor, Westend Marg, Saidulajab, Near Saket Metro Station, South West Delhi, New Delhi, 110030, with offices in India, the United States and Singapore (“Convosight”, “we”, “us”), provides social and market intelligence products and services including ConvoTrack, ARIA, Persona, research reports and application programming interfaces (the “Services”).

    This policy explains how we handle personal information relating to our customers, the individuals authorised to use the Services, and visitors to our websites. We are the controller of that information. Where we process information solely on a customer's documented instructions — for example research briefs or files a customer supplies — we act as a processor, and the customer agreement and data processing addendum govern that processing.

    If we analyse your publicly available social media content, this is not the notice that applies to you. See our Public Content Notice.

  • 2. What we collect

    1. Account and business data — name, work email, employer, role, credentials, and subscription and billing details.

    2. Customer inputs — research briefs, files, prompts, feedback and support content.

    3. Technical data — IP address, device and browser information, cookies and similar technologies, usage events and logs.

    4. Integration and connector data — prompts, API parameters, authentication tokens, source selections, generated responses, session and job identifiers, and related logs arising from APIs, AI-assistant connectors and other integrations.

    5. Public social content and licensed market datasets used to produce our research. These are described in the Public Content Notice.

    Content on a social media platform is available to us only to the extent that the platform, and the privacy settings the individual has applied, make it publicly accessible. The relationship between an individual and each platform is governed by that platform's own terms and privacy policy, and the settings the platform offers are the most direct control over who can see their content.

  • 3. Why we use it, and our legal basis

    1. Providing, administering, supporting and billing for the Services — performance of a contract.

    2. Producing consumer, category, brand and market intelligence, including analysis of public social content — our legitimate interests in operating a business-to-business research service.

    3. Securing the Services, preventing misuse and resolving disputes — our legitimate interests.

    4. Communicating with business contacts about our products — our legitimate interests, or consent where required.

    5. Meeting legal, tax and regulatory obligations — compliance with a legal obligation.

    Before relying on legitimate interests we assess necessity, reasonable expectations, sensitivity, potential impact and available safeguards. You may object to processing based on legitimate interests (section 7).

    We may use de-identified service data and user feedback to test and improve our systems. We do not use customer data or source content to train general-purpose models unless the customer agreement and source rights expressly permit it. We do not make decisions producing legal or similarly significant effects about any individual by automated means.

  • 4. Who we share it with

    1. Service providers and sub-processors that host, secure, support or help deliver the Services, under contracts limiting their use of the information.

    2. Customers and their authorised users, who receive contracted research, reports, insights, metrics, summaries, limited source evidence and API responses.

    3. Approved integration and AI-assistant partners and third-party model providers, where prompts, context and responses pass between us and the provider to complete a user's request.

    4. Our affiliates, professional advisers, auditors, and counterparties to a corporate transaction, subject to confidentiality.

    5. Public authorities where required by law or to protect rights, safety and the integrity of the Services.

    Providers acting on our behalf may use information only to provide their services to us. We do not authorise third-party providers to use customer data or public social content supplied by Convosight to train their general-purpose models.

  • 5. AI assistants, connectors and model providers

    Certain features allow an authorised user to access the Services through a third-party AI assistant — for example, a connected assistant such as ChatGPT or Claude — or use models supplied by third-party AI service providers. In those cases, prompts, selected context, technical identifiers and generated responses pass between Convosight and the relevant provider to complete the user's request.

    What our connector receives. Requests reaching us through a connector contain the user's question and the reference numbers needed to keep a conversation together — one for the conversation and, on a follow-up, one for the answer it relates to. Our input schemas accept nothing else: no profile information, no location, and no other content from the user's conversation with the assistant.

    What our connector returns. A reference while the answer is being prepared, then the answer itself, the public social content it draws on, and the user's remaining query allowance for the period. Supporting content is returned as published — post and comment text, the publishing account's public handle and display name, public engagement counts, sentiment scoring and links to the original on the source platform; for video, a transcription of what is said.

    When ARIA is used through a connected AI assistant, our servers generate short-lived technical identifiers — such as a session ID and a job ID — to support multi-turn conversations and background answer retrieval. These identifiers are not linked to a user's identity beyond their authenticated Convosight account, are not used for advertising or cross-service tracking and expire automatically.

    Conversation history — answers, and the questions that produced them — is stored against the user's Convosight account so a conversation can be resumed on another device, and is retained as described in section 6. A user can disconnect an assistant at any time through that assistant's settings, and can ask us to delete their conversation history by contacting us (section 10). The user's conversation with the assistant itself is processed by that assistant under its own terms and privacy notice; providers that process information on our behalf are bound by our sub-processor terms.

  • 6. How long we keep it, security and transfers

    We keep information for as long as needed for the purposes above and for our contractual, security, dispute-resolution and legal-compliance requirements. In general:

    1. Account and business data — for the term of the customer relationship and 30 days afterwards, except where a longer period is required by law, for example for tax and accounting records.

    2. Raw customer inputs — for the term of the customer relationship and 30 days afterwards, or as set out in the customer agreement.

    3. Technical and website logs — for the term of the customer relationship and 90 days afterwards.

    4. Connector requests, including conversation history — for the term of the customer relationship and 30 days afterwards.

    Retention of public social content is described in the Public Content Notice. Where a source platform requires a shorter deletion or refresh period, we apply that period. Retention schedules are available to customers on request.

    We maintain administrative, technical and organisational safeguards including access controls, encryption in transit and at rest where appropriate, logging and monitoring, vulnerability management, incident response, and oversight of vendors and sub-processors. No method of transmission or storage is completely secure.

    Information may be stored in or accessed from countries other than the one you are in. Where we transfer personal data out of the European Economic Area or the United Kingdom we rely on appropriate safeguards. Details are available on request.

  • 7. Your rights

    7.1 EU / EEA and United Kingdom

    You have the right to access your personal data, to have it corrected or erased, to restrict or object to our processing (including processing based on legitimate interests), to receive a portable copy, and to withdraw consent where we rely on it. You may lodge a complaint with your supervisory authority.

    7.2 United States

    Depending on your state of residence you may have the right to know, access, correct, delete and obtain a portable copy of your personal information; to opt out of its sale or sharing, of targeted advertising and of certain profiling; to limit the use of sensitive personal information; to appeal a refusal; and not to be discriminated against for exercising these rights.

    We do not sell or share personal information as those terms are defined under US state privacy laws. Information that we have a reasonable basis to believe an individual lawfully made available to the general public, or that is available from widely distributed media, is excluded from the definition of personal information under those laws, and we treat public social content on that basis.

    7.3 India

    Where the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 apply, Convosight is the Data Fiduciary for the processing it controls. You have the right to access information about the processing of your personal data, to correction and erasure, to grievance redressal, and to nominate another individual to exercise your rights. Where processing is based on consent you may withdraw it at any time, including through a registered Consent Manager.

    Grievance Officer: Rohit Mahajan, email: rohit@convosight.com. We will respond within the timelines prescribed by law. If you are not satisfied, you may approach the Data Protection Board of India.

    7.4 How to exercise your rights

    Submit a request to reachus@convosight.com. We may verify your identity first. Some requests are limited by legal exemptions, source-platform requirements and the rights of others. If we refuse a request you may appeal to legal@convosight.com.

  • 8. Cookies

    We use cookies and similar technologies on our websites for authentication, security, analytics and preference management. See Cookie Policy for details and your choices.

  • 9. Changes

    We may update this policy and will post the revised version with a new effective date. Where a change materially reduces the protection applying to information you gave us directly, we will make reasonable efforts to notify you and, where the law requires it, obtain your consent first.

  • 10. Contact

    reachus@convosight.com, or by post to Convosight Analytics Private Limited, 55, 2nd Floor, Westend Marg, Saidulajab, Near Saket Metro Station, South West Delhi, New Delhi, 110030.