Legal

Data Processing Agreement (DPA / AVV)

Processor terms for B2B customers using CompanyOS to process personal data on their instructions.

Version 2026-08-29 · Effective 29 August 2026

1. Parties and roles

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer organisation (“Controller”) and CompanyOS, Munzinger Str. 4, 79115 Freiburg, Germany (“Processor”, “CompanyOS”). The Controller determines the purposes and means of processing personal data in its workspace. CompanyOS processes that data only on documented instructions from the Controller, as described in the Terms of Service and this DPA.

Contact for DPA and privacy matters: hemin.faraidun@gmail.com.

2. Subject matter and duration

Processing covers personal data entered into enabled CompanyOS modules (such as HR, payroll, finance, sales, projects, messages, documents, and recruiting) for the duration of the subscription and any retention period required by law or agreed export/deletion process.

3. Nature and purpose of processing

CompanyOS hosts, stores, organises, transmits, and deletes personal data as necessary to provide the contracted software service, including authentication, tenant isolation, backups, support, billing integration, and security monitoring with redaction of sensitive fields.

4. Categories of data subjects and personal data

  • Controller’s employees, contractors, and applicants
  • Controller’s customers, suppliers, and business contacts where entered in the workspace
  • Users authorised by the Controller to access the service

Data may include contact details, employment records, payroll-related fields, financial records, communications, documents, and audit logs depending on enabled modules.

5. Controller obligations

The Controller is responsible for lawful bases, transparency toward data subjects, retention decisions within its organisation, access control inside its tenant, and exporting records before deletion where statutory retention applies.

6. Processor obligations

  • Process personal data only on documented instructions from the Controller
  • Ensure personnel with access are bound by confidentiality
  • Implement appropriate technical and organisational measures (see section 8)
  • Assist the Controller with data subject requests where applicable
  • Notify the Controller without undue delay after becoming aware of a personal data breach
  • Delete or return personal data at the end of the service, subject to legal retention

7. Sub-processors

The Controller authorises CompanyOS to engage sub-processors listed below. CompanyOS remains responsible for sub-processor performance. Material changes to sub-processors will be communicated as described in the Privacy Policy or individual contract where required.

ProviderPurposeRegionData categories
SupabaseDatabase, authentication, file storage, and edge functionsEU (Frankfurt) — configurableAll workspace records, auth identifiers, uploaded files
StripeSubscription billing and payment processingEU / global — Stripe entity depends on accountBilling contact, payment method metadata, subscription IDs
SentryError monitoring and performance diagnosticsEU (de.sentry.io)Redacted technical logs — PII stripped before transmission
SMTP providerTransactional email (activation, portal links, notifications)Depends on operator configurationRecipient email, message content for system emails
InngestBackground jobs and scheduled workflowsEU / US — depends on deploymentJob payloads scoped to tenant operations
UpstashRate limiting and caching (when enabled)EU — when configuredEphemeral request metadata, no HR content by design
AI providersOptional AI features when explicitly used by an authorised userProvider-specificOnly content the user submits to an enabled AI feature

8. Security measures

  • Authenticated access with role-based permissions and tenant-scoped database policies
  • Private file storage with time-limited access links
  • Audit logging for permission and governance actions
  • Secret management and environment separation for production
  • Error monitoring with PII redaction before transmission to Sentry (EU region)
  • Verified company deletion workflow with cooling-off period and legal-hold support

9. International transfers

Data location depends on configured hosting and providers. Where transfers outside the EEA occur, appropriate contractual safeguards (such as Standard Contractual Clauses) are used where required by applicable law.

10. Audits and documentation

CompanyOS makes reasonable information about security and processing available to Controllers. Formal on-site audits may be arranged subject to confidentiality, frequency limits, and mutual agreement.

11. Countersigned copies

This published DPA applies to all B2B customers using the service. For procurement records, request a countersigned copy at hemin.faraidun@gmail.com. Final entity details must be configured before commercial launch — see also our Impressum.

12. Related documents

This DPA supplements the Terms of Service and Privacy Policy. In case of conflict regarding processing of Controller workspace data, this DPA prevails over general privacy wording to the extent required by applicable data protection law.

← Back to CompanyOS