Data Processing Addendum
Last updated September 24, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and the operator of CMD-OS (“CMD-OS”). It applies whenever CMD-OS processes personal data on the Customer's behalf. Accepting the Terms accepts this DPA; no signature is needed. If you need a countersigned copy, email the contact address on our Contact page.
1. Definitions
“Data Protection Law” means the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and the California Consumer Privacy Act as amended (“CCPA”), as they apply. “Customer Personal Data” means personal data in the Customer's workspace that CMD-OS processes to provide the Service. “Controller”, “processor”, “data subject”, “personal data breach” and “processing” have the meanings in the GDPR.
2. Roles and instructions
- The Customer is the controller of Customer Personal Data and CMD-OS is its processor.
- CMD-OS processes Customer Personal Data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use and configuration of the Service. CMD-OS will tell the Customer if it believes an instruction breaks Data Protection Law.
- The Customer is responsible for having a lawful basis for the data it puts in the Service and for giving data subjects any notices required — for example on its own website where it embeds a CMD-OS lead form.
3. Details of the processing (Annex I)
| Subject matter and duration | Providing the Service, for as long as the Customer has an account, plus the deletion period in section 9 |
| Nature and purpose | Hosting, storing, organising, displaying, searching, syncing and transmitting data as the Customer directs; AI processing only if the Customer turns on the AI module |
| Categories of data subjects | The Customer's clients, contacts, prospects and leads; people who submit its lead forms or book through its booking pages; recipients of its proposals and invoices; people named in its notes, email and content |
| Categories of personal data | Contact details, business details, correspondence and email metadata, meeting details, financial documents (proposals and invoices), notes and content, form answers, and — for public-page visitors — IP address and browser details |
| Special categories | None intended. The Customer should not store them unless it has a lawful basis to do so |
4. CMD-OS's obligations
- Ensure that anyone authorised to process Customer Personal Data is bound by confidentiality.
- Implement the technical and organisational measures in Annex II (below) and keep them up to date.
- Assist the Customer, taking into account the nature of the processing, in responding to data subjects exercising their rights — the Service lets the Customer find, export, correct and delete records itself.
- Assist the Customer with security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32–36), using the information available to CMD-OS.
- Make available the information needed to demonstrate compliance with this DPA, and allow for and contribute to audits — normally by written answers and documentation, and on-site only where required by a supervisory authority or after a breach, on reasonable notice and at the Customer's cost.
5. Subprocessors
The Customer gives general authorisation for CMD-OS to use the subprocessors on the Subprocessors page. CMD-OS imposes data-protection terms on each of them at least as protective as this DPA, remains responsible for their performance, and gives at least 30 days' notice of any new or replacement subprocessor. The Customer may object on reasonable data-protection grounds within that period; if the parties can't resolve the objection, the Customer may terminate and receive a refund of prepaid fees for the remaining period.
6. Personal data breaches
CMD-OS will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed. CMD-OS will keep the Customer updated and take reasonable steps to contain and remedy the breach.
7. International transfers
- Where Customer Personal Data is transferred outside the EEA, the UK or Switzerland to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 — Module Two (controller to processor), and Module Three (processor to processor) where the Customer is itself a processor — which are incorporated by reference. Clause 7 (docking) applies; in Clause 9 option 2 (general authorisation, 30 days' notice) applies; the optional wording in Clause 11 does not apply; Clauses 17 and 18 are governed by and brought in the courts of Ireland. Annexes I and II are sections 3 and Annex II of this DPA; Annex III is the Subprocessors page.
- For UK transfers, the UK International Data Transfer Addendum (version B1.0) issued by the Information Commissioner applies to those clauses, with the tables completed from this DPA. For Swiss transfers, references to the GDPR are read as references to the FADP and the competent authority is the FDPIC.
- Where a recipient is certified under the EU–US Data Privacy Framework (or its UK Extension or the Swiss–US framework), that certification may be relied on instead.
8. California (CCPA) service-provider terms
For personal information subject to the CCPA, CMD-OS acts as a service provider and will not:
- sell or share it (including for cross-context behavioural advertising);
- retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship with the Customer;
- combine it with personal information received from others, except as the CCPA permits.
CMD-OS will comply with the CCPA, provide the same level of privacy protection it requires, notify the Customer if it can no longer meet its obligations, and allow the Customer to take reasonable steps to stop and remediate unauthorised use.
9. Return and deletion
The Customer can export all Customer Personal Data at any time (Settings → Account & data). When the Customer deletes its account, CMD-OS deletes Customer Personal Data from live systems immediately and from backups within 30 days, unless the law requires it to keep some of it.
10. General
Liability under this DPA is subject to the limits in the Terms, except where Data Protection Law does not allow it. If this DPA conflicts with the Terms, this DPA prevails; if it conflicts with the Standard Contractual Clauses, the clauses prevail.
Annex II — Technical and organisational measures
- Tenant isolation: every workspace table is protected by PostgreSQL row-level security; a query without a workspace in scope is refused before it runs. Isolation is covered by automated tests.
- Encryption: TLS for all traffic to the Service; stored credentials for connected services (Google, GitHub, mailboxes) are encrypted with AES-256-GCM and bound to their workspace; storage and backups are encrypted at rest by the database provider.
- Authentication: passwords hashed with bcrypt; signed, HttpOnly session cookies that expire after 30 days; rate limiting on sign-in and sensitive actions.
- Agent access: OAuth 2.1 with PKCE and per-app consent; tokens stored only as SHA-256 hashes, scoped to one workspace, rotated on refresh, revocable at any time; agents cannot delete data.
- Payments: card data is handled only by Stripe (PCI DSS Level 1) and never reaches CMD-OS.
- Data minimisation: no analytics or tracking; lead-form IP addresses cleared after 30 days; link-page clicks record only referring site and country.
- Access control: production access limited to personnel who need it, using individual accounts with multi-factor authentication.
- Resilience: managed database with automated encrypted backups kept for 30 days.
- Deletion and portability: self-serve full export and account deletion.