Conveo procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ If you are located in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, the following provisions apply: Legal Basis for Processing: We process your personal information under the direction of our Enterprise Customers, who determine the lawful basis for processing.” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Conveo is headquartered in Belgium, and our data, including personal and company data, is hosted in Europe. We ensure appropriate safeguards are in place to protect your data in compliance with applicable data protection laws.” | Captured 2026-07-20Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ International Transfers. Conveo uses the EU Standard Contractual Clauses (EU 2021/914) (and UK IDTA/US addenda as applicable) for cross‑border transfers.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We retain personal data only as long as is allowed necessary for its lawful purpose. Once data is no longer needed, we securely dispose of it. Our electronic systems are backed up and archived for a set period, after which the data is permanently deleted.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Data Return/Deletion. Upon termination or at Customer’s request, Conveo will delete or return Customer Data, subject to legal retention obligations.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ Retain Participant Data beyond the period necessary for its permitted purpose.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If you and Conveo have executed a separate DPA, that agreement is leading. Otherwise Conveo acts as data processor (or sub-processor) only to the extent it processes Personal Data on behalf of the Customer. The Customer is responsible for ensuring it has a lawful basis and all required consents for the collection and submission of Personal Data through the Service. Subprocessors. Current Subprocessors are listed at https://trust.conveo.ai/subprocessors .” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We disclose personal information in the following circumstances: With Enterprise Customers on whose behalf we have collected that information” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ With vendors who perform work for us, such as web hosting and fraud prevention” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may use third-party providers to monitor and analyze the use of our Service. No study questions, stimuli, or analysis data is shared with these providers.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If required by law or legal process, including requests by public authorities” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ When studies involve third-party respondent providers, Conveo is not responsible for the actions or data handling practices of these providers. By using our panel providers, including Prolific, Respondent.io, Dynata, and iVOX, the Enterprise Customer agrees to and complies with the terms of service and privacy policies of these third-party respondent providers. It is the responsibility of the Enterprise Customer to ensure that the use of third-party respondents complies with all applicable laws and regulations.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ With third-party processors who are contractually bound to keep the information confidential and use it only for research or statistical purposes” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If necessary to protect the rights, property, and safety of Conveo, our users, or others” | Captured 2026-07-20Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.