Privacy policy

Last updated 1 August 2026

Convylo is a service businesses use to build a chatbot for their website. This page explains what data we handle, why, and what you can do about it. It is written for people, not for lawyers.

Who controls the data

Convylo is operated by Loyalty.lt, MB (company code 307165534). Contact: hello@convylo.com.

Two different roles matter here. When you use Convylo, we are the data controller. When your bot talks to a visitor on your website, you are the controller and we are a processor acting on your instructions.

What we handle

  • Account data: email address, password hash, organization name and your role in it.
  • Your bot's content: everything you add as knowledge — website text, documents, notes.
  • Conversations: the exchange between your bot and your visitors, the language and the time.
  • Contacts: the email address, phone number or name a visitor chose to give in a conversation, together with the time consent was recorded.
  • Invoicing details: company name, company code, VAT code, address and the email invoices go to.
  • Technical records: sign-in times, the audit log, error records.

Why we handle it

  • To make the service work — performance of a contract.
  • To issue invoices and meet accounting obligations — legal obligation.
  • To detect abuse and protect accounts — legitimate interest.
  • A visitor's contact details are stored only when the visitor types them; the time consent was given is recorded alongside.

Who else sees it

We do not sell data and we do not use it for advertising.

We pass on only what the service needs to function:

  • The AI provider — the conversation text and extracts from your knowledge, so the bot can answer. Your data is not used to train models.
  • Invoicing and payments — Loyalty (issuing invoices) and NeoPay (payments).
  • Integrations you connect yourself — for example Google or Outlook Calendar, Slack or email.
  • Nothing is shared with anyone else unless the law requires it.

How long we keep it

  • Account and organization data — while you have an account.
  • Conversations and contacts — until you delete them, or until the organization is deleted.
  • Invoices and accounting records — 10 years, as the law requires.
  • The audit log — 12 months.
  • Deleting an organization removes its data, except what we must keep for accounting.

Your rights

You have the right to access your data, correct it, delete it, restrict processing, object to processing and take your data elsewhere.

Most of this you can do yourself: the Audit log section contains a full export of your data, and deleting an organization removes its data. For anything else, write to hello@convylo.com — we answer within 30 days.

If you believe we handle your data improperly, you can complain to the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt).

Security

  • Each organization's data is isolated; a request carrying another organization's identifier returns nothing.
  • Integration secrets are stored encrypted and never shown again.
  • Passwords are stored as hashes, not as text.
  • Traffic is encrypted in transit (TLS).

Cookies

convylo.com sets no tracking or analytics cookies and loads nothing from third-party servers.

The Convylo app uses a necessary cookie to keep you signed in. Your language and your light or dark theme are kept in your browser's own storage.