Privacy Policy

Effective Date: September 29, 2026
Last Updated: September 29, 2026

ForceMedic Design LLC (“ForceMedic,” “ConvoPro,” “we,” “us,” or “our”) operates the ConvoPro platform, a multi-tenant Conversation-as-a-Platform (CaaP) and AI-orchestration service (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use the Service and our related websites.

We are committed to protecting your privacy. If you have questions or requests regarding this Policy or our data practices, contact us at support@convopro.io.

1. Scope and Our Role

This Policy applies to personal information we process in connection with the Service.

Controller and processor roles. ConvoPro is used by organizations (“Customers”) that utilize isolated workspaces (“Tenants”) and invite their own users. Our role depends on the data:

  • As a processor (service provider): When we process content and data that a Customer or its authorized users submit to, upload to, or generate through the Service (“Customer Content”), we act on that Customer’s behalf and under its instructions. The Customer is the controller of that data. If you are an individual whose personal information appears in a Customer’s Tenant, please direct privacy requests to that Customer, who is responsible for it. We will support our Customers in responding to such requests as required by law.

  • As a controller: When we process account registration data, billing information, and information about visitors to our websites, we act as the controller of that information.

2. Information We Collect

2.1 Information you provide directly:

  • Account and registration data, such as name, email address, and organization;

  • Authentication information, including credentials (stored only in hashed or encrypted form) and multi-factor authentication (MFA) configuration (MFA secrets are stored encrypted);

  • Customer Content you create, upload, or transmit through the Service, such as conversations, prompts, uploaded files and documents, forms, and agent, flow, and connector configurations;

  • Communications with our support team; and

  • Billing and payment information, which is processed by third-party payment processors.

2.2 Information collected automatically when you use the Service:

  • Log and technical data, such as IP address, browser type, device and operating system information, and timestamps;

  • Usage data, such as features accessed and conversation metadata (for example, identifiers, titles, and token/usage counts);

  • Approximate location inferred from IP address using a locally hosted geolocation database (no IP address is sent to an external geolocation provider for this lookup); and

  • Cookies and similar technologies used to authenticate sessions and remember preferences (see Section 6).

2.3 Information from integrations you enable. If you configure a Connector, the Service will send and receive data to and from the connected third-party system (for example, a CRM, productivity, accounting, code-repository, property-data, or web-search service) using credentials you supply, at your direction.

2.4 What we do not collect for advertising. We do not use third-party advertising cookies, and we do not sell your personal information.

3. How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, and secure the Service;

  • Authenticate users and maintain account and Tenant security;

  • Process AI requests and generate AI outputs you request (see Section 4);

  • Process transactions and send related billing information;

  • Send administrative, technical, and service-related communications;

  • Respond to your questions, comments, and support requests;

  • Monitor and analyze usage to operate, troubleshoot, and improve the Service;

  • Detect, investigate, and prevent fraudulent, unauthorized, or unlawful activity, and enforce our Terms; and

  • Comply with legal obligations.

Where required by applicable law, our legal bases for processing include performance of a contract, our legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where applicable.

We do not use Customer Content to train ForceMedic’s own artificial intelligence models.

4. Artificial Intelligence Processing

The Service uses artificial intelligence to provide its features. To generate outputs, the Service transmits relevant inputs — which may include conversation content, system prompts, retrieved documents, tool results, and, in some cases, file contents — to third-party AI model providers.

4.1 AI model providers. The Service uses the following AI model providers: OpenAI, Anthropic, Google (Gemini), Microsoft Azure OpenAI, and xAI. A provider receives data only when an AI request is run against that provider. API keys for these providers are provided for and managed by ConvoPro.

4.2 Provider data-handling terms. Based on each provider’s published documentation, these providers do not train their models on the data submitted through the Service’s API integrations by default, and retain such data only for limited periods for abuse-monitoring and compliance purposes (generally up to 30 days; Google up to 55 days). These terms are set by the providers and may change at their discretion.

4.3 Local file handling. Many document and data file types — including common text-based documents, structured spreadsheet and data files, and text-based PDFs — are processed within the Service and are not sent to an external AI provider for content extraction. Images, video, and PDFs without a usable text layer may be sent to a third-party AI provider’s file-processing interface to be analyzed.

4.4 What we retain about AI usage. Our usage and billing records store metadata such as the provider, model, token counts, cost, associated identifiers, and timestamps. Raw prompts and completions are not stored in those billing records.

4.5 Code execution. Where AI features execute generated code or process repository files, that execution occurs in sandboxed environments configured without outbound network access.

5. How We Share Information

We do not sell, rent, or trade your personal information. We share information only in the following circumstances:

5.1 Sub-processors and service providers. We use trusted third parties to host and operate the Service and to provide specific features. These may include providers of cloud infrastructure and managed data services, AI model services, email and web push delivery, web search and data lookup, and payment processing. An up-to-date list of our sub-processors is available upon request.

5.2 Customer-enabled Connectors. Where you enable a Connector (for example, Salesforce, Microsoft 365/SharePoint, HubSpot, Intuit QuickBooks, JobTread, GitHub, or Model Context Protocol servers), data is exchanged with those third-party systems under credentials you provide and at your direction. Those systems process your data under their own terms and privacy policies.

5.3 Legal and safety. We may disclose information when required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of ForceMedic, our users, or the public, or to investigate potential violations of our Terms.

5.4 Business transfers. If ForceMedic is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

We require our service providers to process personal information only as necessary to provide their services to us and consistent with applicable data protection obligations.

6. Cookies and Similar Technologies

We use essential and functional cookies and similar technologies to authenticate sessions, maintain security, and remember your preferences. We do not use third-party advertising cookies and do not engage in cross-site advertising tracking. You can configure your browser to refuse cookies, but some features of the Service may not function properly as a result.

7. Data Retention

We retain personal information for as long as needed to provide the Service and for the purposes described in this Policy, unless a longer retention period is required or permitted by law. Specific retention practices include:

  • Account data: retained while your Account or Tenant is active.

  • Authentication tokens and embedded sessions: automatically expire based on defined time-to-live periods.

  • Conversation history: retained per your configuration; message history for a given thread is subject to size and volume limits.

  • Uploaded files: temporary files are automatically purged after a short period (for example, within 24 hours), while finalized files are retained until deleted.

  • Audit logs: retained by default for approximately 90 days.

  • Operational metrics: retained for a limited period (for example, approximately 90 days).

When your Account is closed, we may delete or de-identify personal information in accordance with these practices, subject to retention required by law or for legitimate business purposes such as fraud prevention or dispute resolution. You may request deletion as described in Section 10.

8. Data Security

We implement administrative, technical, and organizational safeguards designed to protect personal information, including:

  • Encryption in transit using TLS/HTTPS for external connections;

  • Encryption at rest, including always-on encryption for our primary database, file storage, and AI search index (provided by our cloud infrastructure), and additional application-level AES-256-GCM encryption of stored credentials and third-party tokens;

  • Password protection using bcrypt hashing, and encrypted storage of MFA secrets;

  • Multi-factor authentication (MFA) and single sign-on (SSO) support (SAML and OIDC);

  • Least-privilege, role-based access controls and per-route authorization enforcement;

  • Logical multi-tenant isolation, including per-tenant databases;

  • Security monitoring and audit logging of relevant administrative, authentication, and security events. Audit logs are designed to exclude conversation content, and passwords, authentication tokens, API keys, secrets, and similar credentials are redacted or otherwise protected from application logs; and

  • Rate limiting and brute-force protections designed to detect and mitigate credential abuse and repeated failed login attempts. Depending on the authentication method, risk, and circumstances, these protections may include request throttling, temporary account suspension or lockout, anomaly detection, and other appropriate safeguards.

No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.

9. International Data Transfers and Data Residency

The Service and its infrastructure are hosted and operated in the United States and may also be processed in other locations where we or our service providers operate. If you access the Service from outside the United States, your information may be transferred to and processed in the United States and those other locations. Where required by applicable law, we rely on appropriate safeguards for such transfers, such as Standard Contractual Clauses. An up-to-date list of our sub-processors is available upon request.

10. Your Privacy Rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information:

  • Access — request a copy of the personal data we hold about you;

  • Correction — request correction of inaccurate or incomplete data;

  • Deletion — request deletion of your personal data;

  • Portability — request transfer of your data to another service, where applicable;

  • Restriction — request that we limit processing of your data;

  • Objection — object to certain processing based on legitimate interests; and

  • Withdrawal of consent — withdraw consent where processing is based on consent.

If your personal information is contained within a Customer’s Tenant, the Customer is the controller, and we will refer your request to that Customer or support them in responding, as appropriate. To exercise your rights, or if you have questions, contact us at support@convopro.io. We aim to acknowledge and respond to requests as promptly as reasonably practicable and will respond within the time required by applicable law, generally within 30 days where applicable. We will not discriminate against you for exercising your rights.

U.S. state privacy rights. Residents of certain U.S. states may have additional rights, including the right to know, access, delete, and correct personal information, and to opt out of the “sale” or “sharing” of personal information. We do not sell your personal information or share it for cross-context behavioral advertising.

11. Children’s Privacy

The Service is intended for businesses and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@convopro.io and we will take appropriate steps to delete it.

12. Third-Party Websites and Services

The Service may contain links to, or integrate with, third-party websites and services that we do not control. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you use.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date above and provide notice through the Service or by other reasonable means. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ForceMedic Design LLC
Email: support@convopro.io
Subject line: “Privacy Policy Inquiry”

This Privacy Policy is provided to describe ConvoPro’s data practices and should be read together with the ConvoPro Terms and Conditions.