Privacy Policy
Last updated: April 2026
At Convertly, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your personal data in compliance with GDPR and applicable data protection laws.
1. Data Controller
Convertly is owned and operated by BINARY BRAIN TECHNOLOGIES SP. Z O.O. (NIP: 7133142056, REGON: 54334690400000, KRS: 0001207918), based in Poland, with website https://binarybrain.dev. We act as the data controller for personal data processed through Convertly.
2. Sub-processors
We share data with the following sub-processors: Supabase Inc. (EU) — database, authentication, and file storage; Vercel Inc. (Global, EU edge) — application hosting; Paddle.com Market Ltd (UK/EU) — payment processing as Merchant of Record; Resend Inc. (US, SCCs in place) — transactional email delivery; PostHog Inc. (EU) — product analytics (cookieless mode, no advertising tracking); Sentry (US, SCCs in place) — error monitoring and application stability; Upstash Inc. (EU) — rate limiting and caching. We do not sell your data to third parties. All sub-processors process data only as needed to operate Convertly under appropriate data protection agreements.
3. Data We Collect
Account Data: name, email address (provided during registration), authentication data (managed by Supabase Auth), team and workspace information. Quiz Data: quizzes you create, including questions, options, score ranges, and settings. Lead Data: when someone completes your quiz, we collect their responses and any contact information they provide (e.g. name, email). This data is collected on your behalf — see section 11 for details on data controllership for leads. Tracking Data: quiz view counts, completion rates, and engagement metrics. We do not use cookies for tracking quiz viewers. Payment Data: payments are processed by Paddle (paddle.com) as Merchant of Record. We do not store credit card numbers or payment details. Technical Data: browser type, access logs (server-side), error reports.
4. How We Use Your Data
We use the information we collect to: provide, maintain, and improve the Service; send you transactional notifications (e.g. new lead alerts); process payments via Paddle; communicate with you about your account; monitor application stability and fix errors (via Sentry); analyze product usage patterns to improve the Service (via PostHog in cookieless mode); and enforce rate limits to protect service quality (via Upstash).
5. Legal Basis (GDPR Art. 6)
We process personal data based on the following legal grounds: Contract performance (Art. 6(1)(b)) — processing necessary to provide the Service you signed up for, including account management, quiz hosting, and lead delivery. Legitimate interest (Art. 6(1)(f)) — product analytics, error monitoring, rate limiting, security, and service improvement. These interests do not override your fundamental rights. Consent (Art. 6(1)(a)) — marketing communications (opt-in only). You can withdraw consent at any time. Legal obligation (Art. 6(1)(c)) — where required to retain data for tax, accounting, or regulatory compliance.
6. Data Retention
Account data: retained while your account is active + 30 days after deletion. Quiz data: retained while your account is active. Lead data: retained while your account is active; deleted within 30 days of account deletion. Tracking/analytics data: retained for 2 years, then automatically deleted. Payment records: retained as required by law (5 years for tax purposes). Error logs (Sentry): retained for 90 days.
7. Your Rights (GDPR)
You have the right to: access your personal data (Art. 15); rectify inaccurate data (Art. 16); erase your data — 'right to be forgotten' (Art. 17); restrict processing (Art. 18); data portability (Art. 20); object to processing (Art. 21); withdraw consent at any time. To exercise these rights, contact us at support@convertly.buzz. We will respond within 30 days. You also have the right to lodge a complaint with the Polish supervisory authority (UODO — Urzad Ochrony Danych Osobowych).
8. Cookies and Tracking
We use essential cookies only for authentication and session management. We do not use advertising or tracking cookies. Our analytics provider (PostHog) runs in cookieless mode — no consent banner is required. Our error monitoring (Sentry) is configured with sendDefaultPii disabled and does not track users across sites.
9. Data Security
All data is encrypted in transit (TLS 1.2+) and at rest. Row-level security (RLS) ensures workspace data isolation in the database. We implement appropriate technical and organizational measures to protect your personal data. However, no method of transmission over the internet is 100% secure.
10. International Data Transfers
Your data is primarily processed in the EU (Supabase EU region, PostHog EU, Upstash EU). Some data is transferred outside the EU/EEA to the following providers: Resend Inc. (US), Sentry (US), and Vercel Inc. (global CDN with EU edge). For all transfers outside the EU/EEA, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
11. Lead Data — Controller vs. Processor
When you use Convertly to collect leads through quizzes, you (the quiz creator) are the data controller for the personal data of your quiz respondents (leads). Convertly acts as a data processor on your behalf. This means: you are responsible for having a lawful basis to collect lead data (e.g. consent via your quiz); you must inform your leads about how their data will be used; you can export or delete lead data at any time from your dashboard. Our Data Processing Agreement (DPA) governs how we handle lead data on your behalf.
12. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us.
13. Changes to This Policy
We will notify you of material changes via email. The latest version is always available at https://convertly.buzz/privacy.
Contact Us
For privacy-related inquiries, contact us at support@convertly.buzz