1. Who we are
The Konvox service (“Konvox”, “we”, “us”) is owned and provided by:
Ventrax LLC
A Wyoming limited liability company, United States
Contact for privacy matters: hello@konvox.io
Our EU partner - the entity carrying out our EU operations and our representative in the European Union under Article 27 GDPR - is:
ANAX HOLDING, s.r.o.
Company ID (IČO): 10876197
Registered seat: Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic
Registered in the Commercial Register kept by the Regional Court in Brno.
You (and supervisory authorities) may address ANAX HOLDING, s.r.o. on any matter related to our processing of personal data, in addition to or instead of contacting us directly.
Because we offer the Service to businesses in the EU and process personal data of people in the EU, we are subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) under its Article 3(2), and we have appointed the EU representative above. Personal data is hosted within the European Union.
2. Our two roles
Konvox is a business-to-business service. We are not aimed at consumers. Depending on the data, we act in one of two capacities under the GDPR:
For our own database of business contacts - professionals in their work capacity (name, role, business email, employer, public professional profile) - we are the controller. We decide why and how this data is collected and used.
When a customer uploads their own contacts and runs campaigns through Konvox, that customer is the controller of that data and we act as their processor, handling it only on their documented instructions. This is governed by our Data Processing Agreement (DPA), available to customers on request.
3. Personal data we process
Business contact data (as controller). Names, job titles, business email addresses, employer/company, public professional profile links (e.g., professional networks), and similar work-related information about professionals. We collect this from public sources - company websites, public professional networks, and public registers. We do not process special categories of data (health, race, political opinions, etc.), and we do not target consumers. That data being publicly available does not remove it from GDPR protection, which is why we handle it under a clear legal basis and honour every right below.
Customer campaign data (as processor). Contacts, lists, message content, and engagement data (deliveries, opens, replies) that a customer uploads or generates when using the service, processed on that customer’s behalf.
Customer account data (as controller). The name, business email, company, login credentials, and settings of the people who register for and use Konvox, plus billing information handled by our payment processor.
Technical and usage data. Log data, device/browser information, and cookies necessary to run and secure the service.
4. Legal bases
- Legitimate interests (Art. 6(1)(f)). For building and offering our business-contact database and for B2B direct outreach. The GDPR expressly recognises direct marketing as a possible legitimate interest (Recital 47). We limit ourselves to work-related data in a business context, we minimise what we hold, and we offer a one-click way to object and be suppressed. We have carried out and can produce a balancing assessment.
- Performance of a contract (Art. 6(1)(b)). To provide the service to our customers and manage their accounts and billing.
- Legal obligation (Art. 6(1)(c)). Where the law requires us to keep or disclose data (e.g., accounting, responding to lawful requests).
- Consent (Art. 6(1)(a)). Where we ask for it (e.g., certain cookies or optional communications). You can withdraw consent at any time.
5. How we use personal data
- To provide and operate the Konvox service and run our customers’ campaigns on their instructions.
- To match a customer’s ideal-customer profile to relevant business contacts from our database.
- To protect deliverability and sending reputation (verification, warm-up, SPF/DKIM/DMARC, suppression).
- To provide support, billing, and account administration.
- To secure the service, prevent abuse, and comply with the law.
6. Sharing and sub-processors
We do not sell personal data. We share it only with service providers who help us run Konvox, under contract and only as needed, in these categories: cloud hosting (within the EU), email delivery, AI text generation, payment processing, and error monitoring / analytics. Customers can request our current list of sub-processors, which also forms part of the DPA. We may also disclose data where legally required, or to protect our rights and users.
7. Where your data is stored and international transfers
Customer data and our contact database are hosted within the European Union. Because the Service is provided by a US company, limited access from outside the EEA may occur to operate the Service; for any such transfer, and where a sub-processor necessarily processes data outside the EEA, we rely on an appropriate transfer mechanism under the GDPR (an adequacy decision or the European Commission’s Standard Contractual Clauses with supplementary measures).
8. Retention
We keep personal data only as long as needed for the purposes above. Customer account and campaign data are kept for the life of the account and then deleted or returned per the DPA, subject to legal retention periods (e.g., accounting records). Business contacts in our database are reviewed and refreshed periodically; contacts that object or bounce are suppressed and retained only to honour that suppression.
9. Your rights
Wherever we handle your personal data you have the right to: access it; have it corrected; have it erased; restrict or object to processing (including objecting to direct marketing at any time); data portability; and to withdraw consent where processing is based on it. You also have the right to lodge a complaint with a supervisory authority (see §12).
To exercise any right, email hello@konvox.io. We respond within one month. Where we act as a processor for a customer, we will forward your request to that customer (the controller) and assist them.
Your details came from public professional sources and are used for B2B outreach under legitimate interests. You can opt out at any time - use the unsubscribe link in the message, or email hello@konvox.io. We will stop, add you to our suppression list so you aren’t contacted again through Konvox, and erase your data on request.
10. Cookies
Our website and app use cookies that are strictly necessary to operate and secure the service, and (where you allow it) a limited set for analytics. You can control non-essential cookies through your browser or any consent control we provide.
11. Security
We use appropriate technical and organisational measures: EU hosting, encryption in transit, access controls and least-privilege, authenticated sending (SPF/DKIM/DMARC), and monitoring. No system is perfectly secure, but we work to protect your data and will notify affected parties and the authority of a qualifying breach as the GDPR requires.
12. Complaints and supervisory authority
You can lodge a complaint with the supervisory authority of the EU member state where you live, work, or where the issue occurred. Given where our EU representative is established and where most of the people in our database are based, a natural point of contact is the Czech Data Protection Authority:
Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
uoou.gov.cz
We would appreciate the chance to resolve any concern first - please reach us at hello@konvox.io.
13. Changes
We may update this policy as the service or the law evolves. We will change the “last updated” date above and, for material changes affecting customers, notify them. Continued use after an update means you accept the revised policy.
14. Contact
Questions about this policy or your data? Email hello@konvox.io.