Data Processing Addendum
The contract that says exactly how we handle personal data on your behalf: GDPR Article 28 terms, security measures, subprocessors, EU SCCs and UK Addendum, 72-hour breach notice, audits, deletion.
- Version
- 2.0
- Effective
- 2026-08-26
- Last updated
- 2026-08-26
- Provider
- WomenTech LLC
This addendum forms part of the agreement between Customer (the controller) and WomenTech LLC, a Delaware limited liability company, of 16192 Coastal Highway, Lewes, DE 19958, United States (the processor) for CommsOperator. It applies where we process personal data on Customer's behalf and is available for signature on request.
1. Definitions and roles
"Personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in the EU General Data Protection Regulation. "Data protection law" means the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and the CCPA and CPRA where applicable. Customer is the controller (or a processor acting for another controller) and we are the processor. Under the CCPA we act as a service provider and do not sell or share personal information.
2. Subject matter and duration
We process personal data to provide CommsOperator for the term of the agreement plus the deletion window in section 11.
3. Nature and purpose of processing
How to read this table: each row is one thing the service does with personal data and why.
| Processing activity | Purpose |
|---|---|
| Mailbox synchronization | Making Customer's Microsoft 365 mail available in a shared workspace with statuses, owners, and search |
| CRM storage | Holding contacts, companies, deals, and their activity timeline |
| Campaign delivery | Rendering, approving, and sending messages from Customer's own mailboxes or a configured provider, and recording suppression |
| AI assistance | Classification, drafting, summarization, and knowledge answers on Customer's instruction |
| Support and operations | Diagnosing faults, restoring service, and responding to Customer requests |
4. Categories of data subjects and personal data
Data subjects: Customer's employees and users; Customer's contacts, prospects, customers, members, sponsors, speakers, applicants, and correspondents; visitors to Customer's websites who use the widgets or forms.
Personal data: identification and contact details; professional details such as employer, role, and profile links; message content and attachments; interaction records including opens, clicks, replies, and meeting notes; consent and suppression status; technical data such as IP address and user agent; and any other data Customer chooses to import. Customer is responsible for not importing special-category data; the service is not designed for it.
5. Our obligations
- Process personal data only on Customer's documented instructions, including the agreement, the product configuration Customer chooses, and support requests, unless law requires otherwise, in which case we tell Customer first unless prohibited.
- Ensure personnel with access are bound by confidentiality and receive appropriate training.
- Implement the technical and organisational measures in section 9 and not materially reduce them during the term.
- Assist Customer, taking account of the nature of processing and the information available to us, with data subject requests, security, breach notification, impact assessments, and prior consultation.
- Make available the information needed to demonstrate compliance and allow audits under section 10.
- Notify Customer without undue delay if we believe an instruction infringes data protection law.
6. Customer obligations
Customer warrants it has a lawful basis for the personal data it imports and the messages it sends, provides required notices to data subjects, honours objections and opt-outs, configures roles and access appropriately, and does not instruct us to process data unlawfully.
7. Subprocessors
Customer gives general authorisation for the subprocessors listed on the subprocessors page. We impose data protection obligations on each subprocessor that are no less protective than this addendum and remain liable for their performance. We give at least 30 days' notice before adding or replacing a subprocessor; Customer may object on reasonable data protection grounds within that period, and if we cannot offer an alternative, Customer may terminate the affected part of the service without penalty for the remainder of the term.
8. International transfers
Where personal data is transferred out of the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this addendum by reference. Clause 7 (docking) applies; Clause 9(a) option 2 (general written authorisation, 30 days) applies; Clause 11 does not include the optional independent dispute resolution body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland. Annexes I, II, and III are populated by this addendum's sections 3, 4, 9, and the subprocessors page.
For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to those Clauses, with Tables 1 to 4 completed by this addendum and the ending date as the end of the agreement. For Swiss transfers, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
9. Technical and organisational measures
How to read this table: each row names a security area and the concrete measure in place for it.
| Area | Measure |
|---|---|
| Encryption | TLS for all traffic including database connections; AES-256-GCM encryption of stored credentials, OAuth tokens, and integration secrets |
| Access control | Workspace isolation with explicit membership records; role-based permissions across modules; mailbox and conversation level grants; hashed, scoped API tokens |
| Authentication | Password (scrypt with per-user salt) or emailed one-time code; server-side sessions with HTTP-only, Secure cookies and a 7-day expiry |
| Application security | Content Security Policy and other security headers; request forgery protection; schema validation of inputs; parameterised database access; HTML sanitisation; signature verification on inbound webhooks |
| Availability | Health and readiness probes; circuit breakers on outbound integrations; immutable releases with rollback; graceful shutdown; managed database backups with point-in-time restore |
| Monitoring | Structured request logging with correlation identifiers; error monitoring with personal data stripped; Prometheus metrics on an authenticated endpoint; audit log of administrative actions |
| Segregation | Separate production and development environments; production secrets restricted to the host and not present in the repository |
| Personnel | Access on a need-to-know basis; confidentiality obligations; removal on role change |
| Deletion | Cascade deletion on workspace removal; deletion within 30 days of request from live systems; backups cycle out on the provider schedule |
10. Audits
On request and no more than once a year, we provide the information reasonably needed to demonstrate compliance with this addendum, including our security documentation and completed questionnaires. Where that is insufficient for a supervisory authority or a documented regulatory requirement, Customer may conduct an audit at its own cost on 30 days' notice, during business hours, under confidentiality, without disrupting the service and without access to other customers' data.
11. Deletion and return
During the term, and for 30 days after it ends, Customer may export Customer Data through the product or by asking us. After that period we delete Customer Data from live systems within 30 days, and from backups as they cycle, unless law requires retention. Suppression records may be retained in a minimised form so that opt-outs continue to be honoured.
12. Personal data breach
We notify Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Data, at the account's administrative contact. The notice describes the nature of the breach, categories and approximate numbers affected where known, likely consequences, and measures taken. We assist Customer with its own notification duties. Report a suspected breach to office@commsoperator.com.
13. Liability and precedence
Liability under this addendum is subject to the limitations in the terms of service, except where data protection law does not permit that. If this addendum conflicts with the terms of service on the processing of personal data, this addendum prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.