Legal
GDPR
How CommunicationOS meets the GDPR. The lawful bases we rely on, the rights a person has, who to write to, and why the default deployment involves no transfer out of the EU.
Last updated 22 August 2026
In plain language
GDPR commitment summary
This guide explains how we uphold European data protection principles across our software architecture.
- We process data under contract performance obligations, to provide inbox aggregation, search indexing and the AI features you switch on.
- When your end customers submit deletion or export requests, the admin dashboard gives you the tools to answer them quickly.
- Our Data Protection Officer watches our compliance work and answers privacy questions directly at [email protected].
- The default cloud environment keeps every customer database inside the EU, with no transfer of message content to a third country.
The summary is here to save you time. The text below it is the part that binds us.
1. Why this page exists
The privacy policy says what we do with data. The DPA is the contract that binds us when we do it for you. This page answers the questions a data protection officer asks in the middle of a vendor review, with the article references so nobody has to guess which clause we mean.
2. Who is controller and who is processor
For the message content inside your connected accounts, you are the controller under Article 4(7) and we are the processor under Article 4(8). You choose the channels, the people, the retention rule and the AI features. We carry out those decisions.
For a narrow set of our own records we are the controller: your account details, billing records, our security logs and product telemetry. We decide those purposes ourselves and the privacy policy describes them.
3. Lawful bases
These are the bases we rely on for the processing we control. For the message content you control, you pick the basis and record it in your own register.
| Processing | Basis | Article |
|---|---|---|
| Running the workspace, storing and indexing the messages you connect | Performance of a contract | 6(1)(b) |
| Account creation, authentication, two-factor enrolment | Performance of a contract | 6(1)(b) |
| Invoicing, VAT records, seven year accounting retention | Legal obligation | 6(1)(c) |
| Abuse detection, rate limiting, incident investigation, audit logging | Legitimate interest in a secure service | 6(1)(f) |
| Product email about releases, incidents and policy changes | Legitimate interest in an informed customer | 6(1)(f) |
| Marketing email to a prospect who asked for access | Consent, withdrawable in one click | 6(1)(a) |
| Optional third-party drafting model, switched off by default | Your instruction as controller | 28(3)(a) |
A legitimate interest assessment is on file for each 6(1)(f) entry and we share it on request. We do not rely on legitimate interest for anything involving your message content.
4. What we hold and about whom
Categories of data subject: your staff, your customers, your suppliers, and any person who messages a connected account. Categories of data: names, phone numbers, email addresses, network handles, profile images, message bodies, attachments, voice notes and their transcripts, group membership, timestamps and IP addresses.
We do not ask for special category data under Article 9 and the product does not need it. Business conversations sometimes contain it anyway. When they do, the encryption, the per-thread permissions and the audit log in the DPA apply to it without any change on your side.
5. Rights, and how to use them
| Right | Article | How it works here |
|---|---|---|
| Access | 15 | Search every channel for a person, then export the result |
| Rectification | 16 | Edit contact records. Message bodies stay as sent, with a correction note |
| Erasure | 17 | Deletion covers the message store, the search index and any PersonaLearn adapter built from it |
| Restriction | 18 | Freeze a thread so it cannot be read, exported or fed to a model |
| Portability | 20 | JSON and MBOX exports, machine readable and documented |
| Objection | 21 | Write to us for our own processing, or to the workspace owner for theirs |
If you hold a CommunicationOS account, write to [email protected]. We answer inside 30 days under Article 12(3), usually inside five working days, and there is no charge.
5.1 A request about one of your customers
This is the case that comes up most. Somebody who messaged your business writes to us and asks for their data.
We are the processor, so we do not answer on the merits and we do not go looking through your workspace. We tell the person to contact you, and we tell your administrators within three working days so the Article 12 clock does not run out while nobody knows. Then you handle it in the product: search your connected networks for the identifier, export what you find, delete what you must.
A deletion you run removes the message content, the media, the transcripts, the index entries and anything derived from them, including the adapter weights if PersonaLearn had seen the thread. It reaches backups within 14 days. We do not keep a shadow copy.
6. Transfers outside the EU
In the default setup there is no transfer. Primary storage is Frankfurt or Amsterdam, backups write to the other EU region, inference for summaries and translation runs with a French provider, and transcription runs on our own hardware in Frankfurt.
One subprocessor established outside the EU appears on the list, restricted to an EU inference region, and it stays switched off until you turn it on. If you do turn it on, the transfer runs under the Standard Contractual Clauses of 4 June 2021, Module Three, with a transfer impact assessment we share on request and supplementary measures including zero retention and no training rights.
Enterprise customers who self-host process everything inside their own perimeter.
7. Data protection officer and representative
Our Data Protection Officer can be reached at [email protected] or by post at CommunicationOS BV, DPO, Hoveniersstraat 30, 2018 Antwerp, Belgium. A person reads that address. It is not a ticket queue and it is not answered by a model.
We are established in Belgium, so our lead supervisory authority is the Belgian Data Protection Authority and no Article 27 representative is needed.
8. Records, assessments and impact
We keep an Article 30 record of processing activities and share the parts relevant to you during a vendor review. We have completed a data protection impact assessment for the AI features, since they process message content at scale, and the summary goes out with the compliance pack.
There is no automated decision-making with legal effect under Article 22. The AI layer produces drafts, summaries and scores for a person to act on. Nothing in the product decides anything about a data subject on its own.
9. Retention
You set the retention rule for message content, from 30 days to permanent. Our own records follow the schedule in the privacy policy: seven years for audit and accounting, 90 days for server logs, 35 days for backups.
10. Complaints
Start with us. If we get it wrong, or you are not happy with the answer, you can complain to a supervisory authority.
Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, Belgium.
www.dataprotectionauthority.be
You can also complain to the authority in the member state where you live or work. Doing so does not affect any other remedy you have.
11. Documents
- Data processing addendum, including the security measures and the subprocessor list
- Privacy policy, including retention periods
- Security page, including the audit status and the compliance pack
- Security policy set, penetration test summary and DPIA summary under NDA from the contact page. The SOC 2 Type II report joins them when that audit closes
CommunicationOS BV, Hoveniersstraat 30, 2018 Antwerp, Belgium.