Skip to content

Privacy Policy

What personal data CommsOperator holds, why, for how long, who sees it, and how to ask us to change or delete it. Plain summaries above every section. Hosted in Germany by default.

Version
2.0
Effective
2026-08-26
Last updated
2026-08-26
Provider
WomenTech LLC
In short: we run the website and the access-request form, so for those we decide how data is used. Inside a customer workspace, your organization decides and we follow its instructions. We do not sell personal data, we do not use your organization's workspace data for our own marketing, and we do not train AI on it. The shared instance lives in Germany. Questions go to privacy@commsoperator.com and a person answers. In short boxes are a plain-language guide. If a summary and the full text differ, the full text applies.

CommsOperator is operated by WomenTech LLC, a Delaware limited liability company, of 16192 Coastal Highway, Lewes, DE 19958, United States ("we", "us"). This policy explains what personal data we handle, why, and what you can ask us to do about it. It covers the CommsOperator website, the application, the desktop and mobile clients, the browser extension, and the embeddable widgets.

Two roles, two policies. When you visit our website or ask for access, we are the data controller and this policy applies. When your organization uses CommsOperator to handle its own contacts and mail, your organization is the controller and we are its processor under the data processing addendum.

1. Who we are and how to reach us

In short: WomenTech LLC is the company behind CommsOperator. Ivo Radulovski is our named representative for EEA and UK data protection matters. Write to privacy@commsoperator.com and a person replies.

Controller: WomenTech LLC, a Delaware limited liability company, of 16192 Coastal Highway, Lewes, DE 19958, United States. Privacy contact: privacy@commsoperator.com. Legal contact: legal@commsoperator.com. We have not appointed a data protection officer; privacy requests are handled by the operating team and answered by a person.

Our representative for data protection matters under Article 27 GDPR and the UK GDPR is Ivo Radulovski, reachable at privacy@commsoperator.com. If you are an EEA or UK data subject you may contact the representative or us directly, and you retain the right to complain to your local supervisory authority at any time.

2. Data we handle as controller

In short: visit the site or ask for access and we keep what you typed, your IP address, and page usage, to reply to you and to fix the site. The table shows why we hold each item and the legal basis.

How to read this table: each row is one kind of data, what it looks like, why we hold it, and the GDPR Article 6 ground we rely on.

CategoryExamplesWhy we hold itLegal basis (GDPR Art. 6)
Access requestsName, work email, company, role, described use case, qualification answers, IP address, browser user agentTo review whether a private-beta request is a fit and to replyLegitimate interest (assessing and responding to a business enquiry); pre-contractual steps at your request
Contact and sales enquiriesName, email, company, messageTo answer you and keep a record of the conversationLegitimate interest; pre-contractual steps
Resource downloadsWork email, name, company, role, the resource requested, self-reported sourceTo deliver the requested document and follow up about itConsent (given by ticking the box) and legitimate interest
Calculator reportsWork email, the figures you enteredTo send the report you asked forConsent
Account dataName, email, workspace membership, role, authentication records, session dataTo operate your account and secure itContract; legitimate interest (security)
Billing dataCompany, billing contact, subscription and payment statusTo invoice and to meet accounting dutiesContract; legal obligation
Website usagePages viewed, referrer, coarse device information, interaction recordings from Microsoft ClarityTo understand which pages work and to fix problemsLegitimate interest, with advertising and analytics storage denied by default
Support and incident recordsCorrespondence with our team, error reportsTo support you and investigate faultsContract; legitimate interest

3. Data we handle as processor

In short: what your organization puts into its workspace belongs to your organization. We only process it to run the service, on your instructions. We do not sell it, market with it, or train AI on it.

When your organization uses CommsOperator, it decides what to put in: mailbox content synchronized from Microsoft 365, contacts and companies, deals, campaign lists and suppression records, knowledge base content, task and meeting records, and files you upload. We process that data only to provide the service, on your documented instructions, under the data processing addendum. We do not sell it, we do not use it for our own marketing, and we do not use it to train AI models.

4. Automated processing and AI

In short: the AI drafts. People decide. Nothing the AI does on its own has legal weight for any individual. Automatic delivery is off by default and exists only where an administrator explicitly turns it on: for a fixed template, for the chat widget, or for the flag-gated auto-send level described in the AI transparency statement.

CommsOperator uses AI to classify conversations, draft replies, plan outreach, summarize meetings, and answer questions from your knowledge base. AI output is a proposal. A person approves before an AI-drafted message is sent, except where an administrator has explicitly enabled one of three things: automatic delivery for a fixed template, auto-reply on the website chat widget, or the agent auto-send level, which sits behind a feature flag and is described in the AI transparency statement.

  • AI processing runs on the OpenAI API. Under OpenAI's API data usage policy, content sent through the API is not used to train OpenAI's models.
  • We train no models on customer data, and we do not build cross-customer profiles.
  • Prompts carry only the context needed for the task: the conversation, matching knowledge content, and relevant CRM fields.
  • Every AI step is logged with its input, output, decision, and outcome, and every human override is recorded.
  • An administrator can switch AI off for a workspace entirely.
  • There is no automated decision-making producing legal or similarly significant effects on individuals within the meaning of GDPR Article 22.
  • For EU AI Act Article 50 transparency, automatically sent AI-drafted messages to recipients likely to be in the EEA are held for human approval by default; where a workspace opts out, an AI-origin disclosure line is appended to the message.

5. Sharing

In short: we do not sell your data and we do not hand it to advertisers. It reaches the providers on the subprocessors page, the integrations you connect, our advisers under confidentiality, and the authorities where the law requires it.

We do not sell personal data and we do not share it for cross-context behavioural advertising. We share data with the service providers listed on the subprocessors page, each bound by a written contract; with the integrations your organization connects, on your instruction; with professional advisers under confidentiality; and where law requires it. In a merger or acquisition, data would transfer to the acquirer under the same commitments, and we would notify you.

6. International transfers

In short: the shared instance is in Germany. Our company is in the US and so are some providers, so some data may leave the EEA under the EU's Standard Contractual Clauses. Ask us for the transfer impact assessment.

The shared instance stores data in Germany: application servers in Falkenstein, Germany and the database in AWS eu-central-1, Frankfurt, Germany. Enterprise customers may have a dedicated instance in the EU or the United States. Because our legal entity is in the United States and some subprocessors are US-based, personal data may be transferred outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses (2021/914) with the UK International Data Transfer Addendum where relevant, and on the EU-US Data Privacy Framework where a subprocessor is certified. A transfer impact assessment is available to customers on request.

7. Retention

In short: enquiries up to 24 months, accounts 30 days after deletion, sessions 7 days, one-time codes 10 minutes, opt-out records for as long as the workspace exists, accounting records up to 10 years.

How to read this table: each row names a class of record and states how long we keep it and what happens at the end.

DataRetention
Access requests and enquiriesUp to 24 months from the last contact, then deleted or reduced to a non-identifying record
Resource download and calculator leadsUntil you unsubscribe or object, and in any case no more than 24 months from the last interaction
Account and workspace dataFor the term of the agreement. Deleted within 30 days of account deletion or the end of the agreement, unless you ask us to export it first
Sessions and one-time codesSessions expire after 7 days; one-time codes after 10 minutes
Suppression records (unsubscribes, bounces, opt-outs)Kept for as long as the workspace exists. Deleting them would mean contacting someone who asked us not to
AI agent activity logsA six-month working window is applied per workspace; audit records needed to evidence approvals are kept for the term
Widget visitor technical dataDevice and network details captured by an embedded widget (screen, timezone, language list, connection, IP and the city it resolves to) are stripped from the submission after 90 days. The feedback itself is the customer's record and is kept for the term
Billing and accounting recordsAs long as tax and accounting law requires, generally up to 10 years
BackupsBackup copies age out on the provider's rolling schedule; a deletion request is applied to live systems immediately and to backups as they cycle

8. Your rights

In short: ask what we hold about you, fix it, delete it, or take it with you. Write to privacy@commsoperator.com and we answer within 30 days.

Depending on where you live, you may have the following rights:

Access. Access the personal data we hold about you.

Correction. Ask us to fix data that is wrong or incomplete.

Deletion. Ask us to delete your data.

Restriction and objection. Ask us to restrict processing, or object to it.

Portability. Receive your data in a portable form.

Withdrawal of consent. Withdraw consent you gave, at any time, without affecting processing already carried out.

California residents may additionally request disclosure of categories collected and opt out of sale or sharing; we do not sell or share personal data as those terms are defined under the CCPA and CPRA, and we do not offer financial incentives for data.

To exercise a right, write to privacy@commsoperator.com. We answer within 30 days and ask for enough information to identify you, no more. If your data is held in a customer's workspace, we will refer you to that customer as the controller and assist them in responding. You may complain to your supervisory authority at any time.

9. Cookies and similar technologies

In short: one cookie keeps you signed in, local storage remembers your theme, and Microsoft Clarity runs with advertising and analytics storage denied by default. No advertising cookies, no cross-site tracking. Embedded widgets read device details from the browser; a Do Not Track signal turns that off.

We use a session cookie to keep you signed in and a small number of local storage entries for preferences such as the colour theme. Microsoft Clarity is loaded on the website with advertising and analytics storage denied by default. We set no advertising cookies and run no cross-site tracking. Details are in the cookie notice.

Where a customer embeds one of our widgets on their own website, the widget reads technical details from the visitor's browser and sends them with any submission: the page and referrer, the browser, operating system and device type, and, unless capture is switched off, the screen size and colour depth, the timezone, the language list, touch and connection type, and the IP address, from which we derive an approximate city. Taken together these amount to a device fingerprint. If the visitor's browser sends a Do Not Track signal we discard the identifying fields before storing anything, and the customer can switch that capture off for their whole workspace. What is stored is stripped after 90 days. The customer embedding the widget is the controller for this data and decides what notice to give on their own site.

10. Security

In short: traffic is encrypted, OAuth tokens and secrets are encrypted before they reach the database, every workspace access needs an explicit membership record, and admin actions are logged. The security page shows every control with its status, including partial and planned ones.

We encrypt data in transit with TLS and encrypt credentials, OAuth tokens, and integration secrets at rest with AES-256-GCM. Workspaces are isolated and access requires an explicit membership record. Administrative actions are logged. The security page lists every control with its status, including the ones that are partial or planned.

11. Children

In short: this is a business product. We do not knowingly hold data about anyone under 16. Tell us if that happened and we delete it.

CommsOperator is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data reached us, write to the privacy address and we will delete it.

12. Changes

In short: when this policy changes, the date at the top moves. Material changes for customers are announced by email or in the application before they take effect. Older versions are available on request.

We update this policy when the product or the law changes. The date at the top is the last substantive change. For material changes affecting customers we give notice by email or in the application before the change takes effect. Previous versions are available from legal@commsoperator.com on request.

Have a question about this policy or your data? Email us at privacy@commsoperator.com.