Privacy Policy
What personal data CommsOperator holds, why, for how long, who sees it, and how to ask us to change or delete it. Plain summaries above every section. Hosted in Germany by default.
- Version
- 2.0
- Effective
- 2026-08-26
- Last updated
- 2026-08-26
- Provider
- WomenTech LLC
CommsOperator is operated by WomenTech LLC, a Delaware limited liability company, of 16192 Coastal Highway, Lewes, DE 19958, United States ("we", "us"). This policy explains what personal data we handle, why, and what you can ask us to do about it. It covers the CommsOperator website, the application, the desktop and mobile clients, the browser extension, and the embeddable widgets.
1. Who we are and how to reach us
Controller: WomenTech LLC, a Delaware limited liability company, of 16192 Coastal Highway, Lewes, DE 19958, United States. Privacy contact: privacy@commsoperator.com. Legal contact: legal@commsoperator.com. We have not appointed a data protection officer; privacy requests are handled by the operating team and answered by a person.
Our representative for data protection matters under Article 27 GDPR and the UK GDPR is Ivo Radulovski, reachable at privacy@commsoperator.com. If you are an EEA or UK data subject you may contact the representative or us directly, and you retain the right to complain to your local supervisory authority at any time.
2. Data we handle as controller
How to read this table: each row is one kind of data, what it looks like, why we hold it, and the GDPR Article 6 ground we rely on.
| Category | Examples | Why we hold it | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Access requests | Name, work email, company, role, described use case, qualification answers, IP address, browser user agent | To review whether a private-beta request is a fit and to reply | Legitimate interest (assessing and responding to a business enquiry); pre-contractual steps at your request |
| Contact and sales enquiries | Name, email, company, message | To answer you and keep a record of the conversation | Legitimate interest; pre-contractual steps |
| Resource downloads | Work email, name, company, role, the resource requested, self-reported source | To deliver the requested document and follow up about it | Consent (given by ticking the box) and legitimate interest |
| Calculator reports | Work email, the figures you entered | To send the report you asked for | Consent |
| Account data | Name, email, workspace membership, role, authentication records, session data | To operate your account and secure it | Contract; legitimate interest (security) |
| Billing data | Company, billing contact, subscription and payment status | To invoice and to meet accounting duties | Contract; legal obligation |
| Website usage | Pages viewed, referrer, coarse device information, interaction recordings from Microsoft Clarity | To understand which pages work and to fix problems | Legitimate interest, with advertising and analytics storage denied by default |
| Support and incident records | Correspondence with our team, error reports | To support you and investigate faults | Contract; legitimate interest |
3. Data we handle as processor
When your organization uses CommsOperator, it decides what to put in: mailbox content synchronized from Microsoft 365, contacts and companies, deals, campaign lists and suppression records, knowledge base content, task and meeting records, and files you upload. We process that data only to provide the service, on your documented instructions, under the data processing addendum. We do not sell it, we do not use it for our own marketing, and we do not use it to train AI models.
4. Automated processing and AI
CommsOperator uses AI to classify conversations, draft replies, plan outreach, summarize meetings, and answer questions from your knowledge base. AI output is a proposal. A person approves before an AI-drafted message is sent, except where an administrator has explicitly enabled one of three things: automatic delivery for a fixed template, auto-reply on the website chat widget, or the agent auto-send level, which sits behind a feature flag and is described in the AI transparency statement.
- AI processing runs on the OpenAI API. Under OpenAI's API data usage policy, content sent through the API is not used to train OpenAI's models.
- We train no models on customer data, and we do not build cross-customer profiles.
- Prompts carry only the context needed for the task: the conversation, matching knowledge content, and relevant CRM fields.
- Every AI step is logged with its input, output, decision, and outcome, and every human override is recorded.
- An administrator can switch AI off for a workspace entirely.
- There is no automated decision-making producing legal or similarly significant effects on individuals within the meaning of GDPR Article 22.
- For EU AI Act Article 50 transparency, automatically sent AI-drafted messages to recipients likely to be in the EEA are held for human approval by default; where a workspace opts out, an AI-origin disclosure line is appended to the message.
5. Sharing
We do not sell personal data and we do not share it for cross-context behavioural advertising. We share data with the service providers listed on the subprocessors page, each bound by a written contract; with the integrations your organization connects, on your instruction; with professional advisers under confidentiality; and where law requires it. In a merger or acquisition, data would transfer to the acquirer under the same commitments, and we would notify you.
6. International transfers
The shared instance stores data in Germany: application servers in Falkenstein, Germany and the database in AWS eu-central-1, Frankfurt, Germany. Enterprise customers may have a dedicated instance in the EU or the United States. Because our legal entity is in the United States and some subprocessors are US-based, personal data may be transferred outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses (2021/914) with the UK International Data Transfer Addendum where relevant, and on the EU-US Data Privacy Framework where a subprocessor is certified. A transfer impact assessment is available to customers on request.
7. Retention
How to read this table: each row names a class of record and states how long we keep it and what happens at the end.
| Data | Retention |
|---|---|
| Access requests and enquiries | Up to 24 months from the last contact, then deleted or reduced to a non-identifying record |
| Resource download and calculator leads | Until you unsubscribe or object, and in any case no more than 24 months from the last interaction |
| Account and workspace data | For the term of the agreement. Deleted within 30 days of account deletion or the end of the agreement, unless you ask us to export it first |
| Sessions and one-time codes | Sessions expire after 7 days; one-time codes after 10 minutes |
| Suppression records (unsubscribes, bounces, opt-outs) | Kept for as long as the workspace exists. Deleting them would mean contacting someone who asked us not to |
| AI agent activity logs | A six-month working window is applied per workspace; audit records needed to evidence approvals are kept for the term |
| Widget visitor technical data | Device and network details captured by an embedded widget (screen, timezone, language list, connection, IP and the city it resolves to) are stripped from the submission after 90 days. The feedback itself is the customer's record and is kept for the term |
| Billing and accounting records | As long as tax and accounting law requires, generally up to 10 years |
| Backups | Backup copies age out on the provider's rolling schedule; a deletion request is applied to live systems immediately and to backups as they cycle |
8. Your rights
Depending on where you live, you may have the following rights:
Access. Access the personal data we hold about you.
Correction. Ask us to fix data that is wrong or incomplete.
Deletion. Ask us to delete your data.
Restriction and objection. Ask us to restrict processing, or object to it.
Portability. Receive your data in a portable form.
Withdrawal of consent. Withdraw consent you gave, at any time, without affecting processing already carried out.
California residents may additionally request disclosure of categories collected and opt out of sale or sharing; we do not sell or share personal data as those terms are defined under the CCPA and CPRA, and we do not offer financial incentives for data.
To exercise a right, write to privacy@commsoperator.com. We answer within 30 days and ask for enough information to identify you, no more. If your data is held in a customer's workspace, we will refer you to that customer as the controller and assist them in responding. You may complain to your supervisory authority at any time.
9. Cookies and similar technologies
We use a session cookie to keep you signed in and a small number of local storage entries for preferences such as the colour theme. Microsoft Clarity is loaded on the website with advertising and analytics storage denied by default. We set no advertising cookies and run no cross-site tracking. Details are in the cookie notice.
Where a customer embeds one of our widgets on their own website, the widget reads technical details from the visitor's browser and sends them with any submission: the page and referrer, the browser, operating system and device type, and, unless capture is switched off, the screen size and colour depth, the timezone, the language list, touch and connection type, and the IP address, from which we derive an approximate city. Taken together these amount to a device fingerprint. If the visitor's browser sends a Do Not Track signal we discard the identifying fields before storing anything, and the customer can switch that capture off for their whole workspace. What is stored is stripped after 90 days. The customer embedding the widget is the controller for this data and decides what notice to give on their own site.
10. Security
We encrypt data in transit with TLS and encrypt credentials, OAuth tokens, and integration secrets at rest with AES-256-GCM. Workspaces are isolated and access requires an explicit membership record. Administrative actions are logged. The security page lists every control with its status, including the ones that are partial or planned.
11. Children
CommsOperator is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data reached us, write to the privacy address and we will delete it.
12. Changes
We update this policy when the product or the law changes. The date at the top is the last substantive change. For material changes affecting customers we give notice by email or in the application before the change takes effect. Previous versions are available from legal@commsoperator.com on request.
Have a question about this policy or your data? Email us at privacy@commsoperator.com.