Skip to content

Legal

Privacy policy

Last updated 22 August 2026

This policy explains what CommunicationOS does with personal data. It covers this website and the product. Where we act on a customer's instructions as a processor, the Data Processing Agreement governs instead.

Who we are

CommunicationOS BV, registered in Belgium, with offices in Antwerp and Amsterdam. Data protection enquiries go to [email protected].

What we collect on this website

  • What you type into a form. Name, work email, company, team size and anything you write in a message field.
  • Request logs. IP address, user agent and requested path, kept for thirty days for security and abuse handling.

We do not run third-party advertising trackers on this site.

What the product processes

When an organization connects an account, we process the messages, attachments, contact identifiers and metadata that account can see. We do this to provide the service the customer asked for: indexing, search, classification, drafting and export.

The customer decides what to connect and for how long to keep it. We act on their instructions.

What we never do

  • We do not sell personal data.
  • We do not use customer message content to train shared or foundation models. Adaptation is per tenant and stays per tenant.
  • We do not read customer message content except where a named engineer is granted time-bound access for a support request, which is logged.

Legal basis

For website forms, legitimate interest in responding to a business enquiry. For the product, we process on the customer's documented instructions as their processor. The customer is responsible for establishing their own lawful basis.

Retention

Website enquiries are kept for twenty four months. Product data is kept for as long as the customer's plan and configured retention policy say, and is deleted within thirty days of a verified deletion request or account closure, subject to any legal hold the customer has applied.

Where data lives

Production data is stored in the region the customer selects. The default is the European Union. See subprocessors for the full list of third parties and their locations.

Your rights

If you are in the EEA or the UK you have the right to access, correct, delete, restrict, object and port. Ask us and we will act within one month. If we hold your data on behalf of a customer, we will route your request to them and tell you we have done so. You may also complain to your supervisory authority. In Belgium that is the Gegevensbeschermingsautoriteit.

Security

Encryption in transit and at rest, role-based access, immutable audit logging, and least privilege for staff access. See the security overview.

Changes

We will post material changes here and, for customers, give notice by email before they take effect.