Data Processing Agreement

# Data Processing Agreement

**Effective Date:** Automatically, upon acceptance of the ComOS [Terms of Service](/legal/terms-of-service), for any Merchant who processes Personal Data through the Platform.
**Last Updated:** September 22, 2026

**Between:**
- **Data Controller**: The Merchant ("you," "Controller")
- **Data Processor**: **ComOS Federation, Inc.**, a Delaware corporation (incorporated; effective July 20, 2026), operating the ComOS platform ("ComOS," "we," "Processor"). ComOS Federation, Inc. is the Processor, and all obligations under this DPA are those of the corporation.

---

## 1. Introduction

This Data Processing Agreement ("DPA") is **incorporated by reference into the ComOS [Terms of Service](/legal/terms-of-service)** ("Agreement") and takes effect automatically — with no separate signature or request required — for any Merchant who processes Personal Data on behalf of Data Subjects protected by applicable Data Protection Laws. It governs the processing ComOS performs as a Processor on the Merchant's behalf.

This DPA reflects the parties' commitment to comply with applicable Data Protection Laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the California Consumer Privacy Act ("CCPA").

---

## 2. Definitions

**"Data Protection Laws"** means all applicable laws relating to data protection and privacy, including GDPR, UK GDPR, CCPA, and other applicable regulations.

**"Personal Data"** means any information relating to an identified or identifiable natural person processed by ComOS on behalf of the Merchant through the Platform.

**"Processing"** means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

**"Data Subject"** means the identified or identifiable natural person to whom Personal Data relates.

**"Sub-processor"** means any third party engaged by ComOS to process Personal Data on behalf of the Merchant.

**"Standard Contractual Clauses" or "SCCs"** means the standard contractual clauses approved by the European Commission for international data transfers.

---

## 3. Scope and Roles

### 3.1 Controller and Processor

- **Merchant is the Data Controller** for Personal Data collected through their use of the Platform (e.g., customer data, order data)
- **ComOS is the Data Processor** processing such data on the Merchant's behalf

### 3.2 ComOS as Controller

ComOS acts as an independent Data Controller for:
- Merchant account information
- Billing and payment data
- Usage analytics
- Data collected for our own business purposes

This DPA governs only the processing where ComOS acts as Processor.

---

## 4. Processing Details

### 4.1 Subject Matter

Processing of Personal Data necessary to provide the ComOS platform services.

### 4.2 Duration

Processing continues for the term of the Agreement plus any retention period required by law or specified in Section 10.

### 4.3 Nature and Purpose

| Purpose | Description |
|---------|-------------|
| Order Processing | Store and process customer orders |
| Customer Management | Maintain customer profiles and history |
| Communications | Send transactional emails on Merchant's behalf |
| Analytics | Generate reports and insights for Merchant |
| AI Features | Power AI-driven features (e.g., recommendations) |
| Support | Assist with customer service inquiries |

### 4.4 Categories of Data Subjects

- Merchant's customers
- Merchant's prospective customers
- Merchant's employees and contractors (if applicable)

### 4.5 Types of Personal Data

- Contact information (name, email, phone, address)
- Transaction data (orders, payments, refunds)
- Communication records
- Device and usage data
- Any other data Merchant collects through the Platform

### 4.6 Special Categories of Data

The Platform is not designed to process special categories of data (e.g., health, biometric, religious data). Merchant agrees not to collect such data unless they have implemented appropriate safeguards.

---

## 5. Processor Obligations

ComOS shall:

### 5.1 Lawful Processing

Process Personal Data only on documented instructions from the Controller, unless required by law. If required by law to process data otherwise, we will inform the Controller before processing (unless prohibited by law).

### 5.2 Confidentiality

Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.

### 5.3 Security Measures

Implement appropriate technical and organizational measures to protect Personal Data, including:

| Measure | Implementation |
|---------|----------------|
| Encryption | TLS 1.3 in transit, AES-256 at rest |
| Access Control | Role-based access, MFA required |
| Monitoring | Intrusion detection, audit logging |
| Testing | Regular security assessments and penetration testing |
| Incident Response | Documented procedures and response team |
| Employee Training | Security awareness training for all staff |

### 5.4 Sub-processors

- Engage Sub-processors only with Controller's authorization (see Section 6)
- Impose equivalent data protection obligations on Sub-processors
- Remain liable for Sub-processor compliance

### 5.5 Data Subject Rights

Assist the Controller in responding to Data Subject requests to exercise their rights under Data Protection Laws, including:
- Access
- Rectification
- Erasure
- Restriction
- Portability
- Objection

### 5.6 Compliance Assistance

Assist the Controller with:
- Data protection impact assessments
- Prior consultations with supervisory authorities
- Demonstrating compliance with Data Protection Laws

### 5.7 Audits

Upon reasonable notice, allow for and contribute to audits and inspections conducted by the Controller or an authorized auditor. ComOS may charge reasonable fees for audit assistance beyond standard reporting.

### 5.8 Data Breach Notification

Notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a Personal Data breach, providing:
- Description of the breach
- Categories and approximate number of Data Subjects affected
- Likely consequences
- Measures taken or proposed to address the breach

---

## 6. Sub-processors

### 6.1 Authorized Sub-processors

Controller authorizes the use of the Sub-processors listed in **Appendix A**. ComOS maintains an up-to-date list at: [comos-portal.com/legal/subprocessors](/legal/subprocessors)

### 6.2 Changes to Sub-processors

ComOS will notify the Controller at least 14 days before engaging a new Sub-processor by:
- Updating the Sub-processor list
- Sending email notification to the account's primary contact

### 6.3 Objection to Sub-processors

Controller may object to a new Sub-processor within 14 days of notification by emailing support@comos-federation.com with reasonable grounds. If the objection cannot be resolved, Controller may terminate the affected services without penalty.

---

## 7. International Data Transfers

### 7.1 Transfer Mechanisms

For transfers of Personal Data outside the EEA/UK to countries without an adequacy decision, ComOS relies on:

- **Standard Contractual Clauses (SCCs)**: As approved by the European Commission (Decision 2021/914)
- **UK International Data Transfer Addendum**: For UK transfers

### 7.2 SCCs Incorporation

The SCCs are incorporated by reference into this DPA:
- **Module Two** (Controller to Processor) applies
- ComOS is the "data importer"
- Controller is the "data exporter"

### 7.3 Supplementary Measures

ComOS implements supplementary measures including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Transparency about government access requests

---

## 8. Controller Obligations

The Controller shall:

- Comply with Data Protection Laws in its use of the Platform
- Ensure lawful basis for processing (e.g., consent, contract)
- Provide appropriate privacy notices to Data Subjects
- Respond to Data Subject requests (with Processor assistance)
- Ensure accuracy of Personal Data
- Not use the Platform to process data beyond what is necessary

---

## 9. Data Subject Requests

### 9.1 Processor Response

If ComOS receives a request from a Data Subject regarding the Controller's data, we will:
- Promptly notify the Controller
- Not respond directly unless authorized by the Controller
- Provide reasonable assistance to fulfill the request

### 9.2 Self-Service

The Platform provides tools for Controllers to respond to many Data Subject requests directly, including data export and deletion.

---

## 10. Data Retention and Deletion

### 10.1 During the Agreement

Personal Data is retained as long as necessary to provide the services and as specified in the Agreement.

### 10.2 Upon Termination

Upon termination of the Agreement:
- **30 days**: Controller may export all data
- **90 days**: Data deleted from production systems
- **1 year**: Data purged from backups

### 10.3 Exceptions

ComOS may retain data as required by law or for legitimate business purposes (e.g., billing records, legal claims).

---

## 11. Liability

Liability under this DPA is subject to the limitations in the Agreement. Each party is liable for damages caused by its breach of Data Protection Laws.

---

## 12. Governing Law

This DPA is governed by the same law as the Agreement, except that:
- GDPR claims are governed by the law of the EU Member State of the Controller's establishment
- UK GDPR claims are governed by the laws of England and Wales

---

## 13. Changes to This DPA

ComOS may update this DPA to reflect changes in law or our practices. Material changes will be notified 30 days in advance.

---

## Appendix A: Authorized Sub-processors

| Sub-processor | Service | Location | Data Processed |
|---------------|---------|----------|----------------|
| Google Cloud (GCP) | Cloud infrastructure and hosting | USA | All Platform data |
| MongoDB Atlas | Database hosting | USA | All Platform data |
| Google Vertex AI (Gemini) | AI model provider — powers in-Platform AI features | USA | Data processed by AI features |
| Stripe | Payment processing | USA | Payment and transaction data |
| Resend | Transactional and marketing email delivery | USA | Email addresses, message content |

This list is authoritative and matches the "Service Providers" list in the [Privacy Policy](/legal/privacy-policy) §4.1. Amazon Web Services and OpenAI are **not** ComOS sub-processors; any prior reference to them was a template artifact and has been removed.

**Last Updated:** September 22, 2026

For the current list, visit: [comos-portal.com/legal/subprocessors](/legal/subprocessors)

---

## Appendix B: Technical and Organizational Measures

### B.1 Access Control

- Role-based access control (RBAC)
- Multi-factor authentication required
- Principle of least privilege
- Regular access reviews

### B.2 Encryption

- TLS 1.3 for data in transit
- AES-256 for data at rest
- Encryption key management with regular rotation

### B.3 Network Security

- Firewall protection
- Intrusion detection and prevention
- DDoS mitigation
- Network segmentation

### B.4 Application Security

- Secure development lifecycle
- Code reviews and static analysis
- Dependency vulnerability scanning
- Regular penetration testing

### B.5 Operational Security

- 24/7 monitoring and alerting
- Incident response procedures
- Business continuity and disaster recovery
- Regular backups with encryption

### B.6 Physical Security

- Data centers with physical access controls
- Video surveillance
- Biometric access for sensitive areas
- Environmental controls

### B.7 Personnel Security

- Background checks for employees
- Confidentiality agreements
- Security awareness training
- Access revocation upon termination