Privacy Policy
Last updated 22 July 2026
This policy explains what personal data Convene collects, why we collect it, and what rights you have over it. It covers our website, our desktop applications, and the meeting service itself.
1. Who is responsible
For personal data about visitors to our website and people who hold a Convene account, we are the controller. Where an organisation uses Convene to run its meetings, that organisation is the controller of its meeting content and we act as its processor.
2. What we collect
Information you give us
- Account data — name, email address, password hash or identity-provider identifier, and workspace membership.
- Billing data — company name, billing address, and tax identifiers. Card details go directly to our payment processor; we never see or store full card numbers.
- Support data — anything you send us in a support conversation.
Information we collect automatically
- Meeting metadata — who joined, when, from which client version, and connection quality measurements. This is how we diagnose call problems.
- Device and log data — IP address, operating system, browser or app version, and timestamps of requests.
- Cookies — see our Cookie Policy.
Meeting content
Live audio and video are encrypted in transit between participants. We do not store meeting media unless a participant with the necessary permission starts a recording, in which case the recording and any transcript are stored for the retention period the workspace administrator has configured.
3. Why we use it
- To provide the Service — routing calls, authenticating you, and syncing your workspace. Legal basis: performance of a contract.
- To keep it secure — detecting abuse, fraud, and unauthorised access. Legal basis: legitimate interests.
- To improve it — aggregate analysis of reliability and feature usage. Legal basis: legitimate interests.
- To communicate — service notices, and marketing where you have opted in. Legal basis: contract, or consent for marketing.
- To meet legal obligations — tax, accounting, and lawful requests. Legal basis: legal obligation.
We do not sell personal data, and we do not use meeting content to train models.
4. Who we share it with
We share personal data with service providers who process it on our behalf under written contracts — cloud hosting, our authentication provider, our payment processor, our email provider, and error-monitoring tooling. We also disclose data where required by law, and in connection with a merger or acquisition, in which case we will give notice before your data becomes subject to a different policy.
5. International transfers
We may process personal data in countries other than your own. Where we transfer data out of the UK or EEA, we rely on an adequacy decision or on Standard Contractual Clauses together with a transfer risk assessment.
6. How long we keep it
- Account data — for as long as the account exists, then up to 90 days.
- Meeting metadata — 13 months.
- Recordings and transcripts — the retention period set by the workspace administrator.
- Billing records — as long as tax law requires, typically six to seven years.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict processing; and to withdraw consent. Where an organisation controls the data, we will refer your request to it.
To exercise a right, contact privacy@example.com. You also have the right to complain to your data protection authority.
8. Security
We encrypt data in transit and at rest, restrict internal access on a need-to-know basis, log administrative access, and test our systems regularly. No system is perfectly secure, but we will notify affected users and regulators of a qualifying breach within the time limits the law sets.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
10. Changes
We will post any update here and change the date above. If a change materially affects how we use personal data, we will give notice by email or in the product.
11. Contact
Write to privacy@example.com. Replace this with your real contact address, and add your registered company name, address, and any Data Protection Officer or EU/UK representative details, before publishing.