Compliance

GDPR & data protection

Last updated: 19 July 2026

Konvox handles business-contact data for a living, so we treat the GDPR as a feature, not a footnote. This page is the plain-English summary; the Privacy Policy is the full detail.

Built for the EU, with a real EU footprint

Konvox is owned and provided by Ventrax LLC (Wyoming, United States). Our EU partner, ANAX HOLDING, s.r.o. (IČO 10876197, Brno, Czech Republic), carries out our EU operations and is our appointed EU representative under Article 27 GDPR - a real, contactable EU presence for data subjects and supervisory authorities, not a mailbox service. Customer data and our contact database are hosted within the European Union.

What we handle, and our role

We work with business-contact data - professionals in their work capacity (name, role, business email, employer, public professional profile). It is B2B, work-related, and drawn from public sources; we do not process special-category data and we are not aimed at consumers. Under the GDPR that is still personal data, so we handle it with a clear legal basis and full respect for people’s rights.

Two roles

Controller of our own business-contact database (we decide why and how it’s built and used). Processor for the contacts and campaigns our customers run through us - governed by our Data Processing Agreement (DPA), available to customers on request.

Our lawful basis

For our business-contact database and B2B outreach we rely on legitimate interests (Art. 6(1)(f)) - the GDPR expressly recognises direct marketing as a legitimate interest (Recital 47). We keep it proportionate: only work-related data, only in a business context, minimised, and with an easy, always-available way to object and be suppressed. We maintain a legitimate-interests assessment and can produce it. For customer accounts we rely on contract; for legal duties, legal obligation.

Your rights

You can access, correct, erase, restrict, object to, or port your data, and object to direct marketing at any time. Email hello@konvox.io and we respond within one month. Where we act as a processor, we forward your request to the customer who controls that data and assist them.

Received a message and want out?

Use the unsubscribe link, or email hello@konvox.io. We stop immediately, add you to our suppression list so Konvox won’t contact you again, and erase your data on request.

How we keep it safe

For our customers

If you use Konvox to reach your own contacts, you are the controller and we are your processor. We provide a DPA, our current sub-processor list on request, and the tooling (suppression, unsubscribe, verification) to help you run compliant outbound. You remain responsible for having a lawful basis to contact the people you upload and for the content of your campaigns - see our Terms of Service.

Supervisory authority

You can complain to the supervisory authority of the EU member state where you live or work. Given where our EU representative sits, a natural point of contact is the Czech authority:

Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
uoou.gov.cz

We’d welcome the chance to help first: hello@konvox.io. You can also address our EU partner and Article 27 representative, ANAX HOLDING, s.r.o. (Příkop 843/4, 602 00 Brno, Czech Republic), on any data-protection matter.