Legal
GDPR
Last updated 22 August 2026
CommunicationOS is built for organizations that keep communications as records, which means the GDPR is a design constraint rather than a page on a website. This is how it works in practice.
Roles
For product data, the customer is the controller and CommunicationOS is the processor. We act on documented instructions. For our own website and marketing, we are the controller.
Data residency
Production data is stored in the region the customer selects. The European Union is the default. Enterprise customers can pin storage and processing to a single region, including for AI inference.
International transfers
Where a subprocessor sits outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses together with a transfer impact assessment. The current list is on the subprocessors page.
Data subject requests
The product has the tooling a controller needs to answer a request without opening a support ticket: search across every connected network, export of one person's records, and deletion that reaches the storage layer rather than hiding a row in an interface. Requests we receive directly are routed to the relevant customer.
Retention and deletion
Retention is configured by the customer per workspace. Deletion is honoured within thirty days unless a legal hold is in force, in which case the hold is recorded with who applied it and when.
Special categories
Chat archives can contain special category data because people write about their health, their beliefs and their families in the same thread as a purchase order. Customers should treat an indexed archive accordingly and configure access roles to match.
AI processing
Summarisation, classification, transcription and drafting are processing activities carried out on the customer's instruction. Customer content is not used to train shared or foundation models. A customer may point the AI layer at their own model provider or a self-hosted model instead.
Breach notification
We notify affected customers without undue delay and in any case within seventy two hours of becoming aware of a personal data breach, with the facts we have at the time rather than after an internal review has concluded.
Records and audits
We maintain Article 30 records and make them available to customers under the DPA. Enterprise customers may audit once per year on reasonable notice.