1. Parties and roles
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer organisation (“Controller”) and CompanyOS, Munzinger Str. 4, 79115 Freiburg, Germany (“Processor”, “CompanyOS”). The Controller determines the purposes and means of processing personal data in its workspace. CompanyOS processes that data only on documented instructions from the Controller, as described in the Terms of Service and this DPA.
Contact for DPA and privacy matters: hemin.faraidun@gmail.com.
2. Subject matter and duration
Processing covers personal data entered into enabled CompanyOS modules (such as HR, payroll, finance, sales, projects, messages, documents, and recruiting) for the duration of the subscription and any retention period required by law or agreed export/deletion process.
3. Nature and purpose of processing
CompanyOS hosts, stores, organises, transmits, and deletes personal data as necessary to provide the contracted software service, including authentication, tenant isolation, backups, support, billing integration, and security monitoring with redaction of sensitive fields.
4. Categories of data subjects and personal data
- Controller’s employees, contractors, and applicants
- Controller’s customers, suppliers, and business contacts where entered in the workspace
- Users authorised by the Controller to access the service
Data may include contact details, employment records, payroll-related fields, financial records, communications, documents, and audit logs depending on enabled modules.
5. Controller obligations
The Controller is responsible for lawful bases, transparency toward data subjects, retention decisions within its organisation, access control inside its tenant, and exporting records before deletion where statutory retention applies.
6. Processor obligations
- Process personal data only on documented instructions from the Controller
- Ensure personnel with access are bound by confidentiality
- Implement appropriate technical and organisational measures (see section 8)
- Assist the Controller with data subject requests where applicable
- Notify the Controller without undue delay after becoming aware of a personal data breach
- Delete or return personal data at the end of the service, subject to legal retention
7. Sub-processors
The Controller authorises CompanyOS to engage sub-processors listed below. CompanyOS remains responsible for sub-processor performance. Material changes to sub-processors will be communicated as described in the Privacy Policy or individual contract where required.
| Provider | Purpose | Region | Data categories |
|---|---|---|---|
| Supabase | Database, authentication, file storage, and edge functions | EU (Frankfurt) — configurable | All workspace records, auth identifiers, uploaded files |
| Stripe | Subscription billing and payment processing | EU / global — Stripe entity depends on account | Billing contact, payment method metadata, subscription IDs |
| Sentry | Error monitoring and performance diagnostics | EU (de.sentry.io) | Redacted technical logs — PII stripped before transmission |
| SMTP provider | Transactional email (activation, portal links, notifications) | Depends on operator configuration | Recipient email, message content for system emails |
| Inngest | Background jobs and scheduled workflows | EU / US — depends on deployment | Job payloads scoped to tenant operations |
| Upstash | Rate limiting and caching (when enabled) | EU — when configured | Ephemeral request metadata, no HR content by design |
| AI providers | Optional AI features when explicitly used by an authorised user | Provider-specific | Only content the user submits to an enabled AI feature |
8. Security measures
- Authenticated access with role-based permissions and tenant-scoped database policies
- Private file storage with time-limited access links
- Audit logging for permission and governance actions
- Secret management and environment separation for production
- Error monitoring with PII redaction before transmission to Sentry (EU region)
- Verified company deletion workflow with cooling-off period and legal-hold support
9. International transfers
Data location depends on configured hosting and providers. Where transfers outside the EEA occur, appropriate contractual safeguards (such as Standard Contractual Clauses) are used where required by applicable law.
10. Audits and documentation
CompanyOS makes reasonable information about security and processing available to Controllers. Formal on-site audits may be arranged subject to confidentiality, frequency limits, and mutual agreement.
11. Countersigned copies
This published DPA applies to all B2B customers using the service. For procurement records, request a countersigned copy at hemin.faraidun@gmail.com. Final entity details must be configured before commercial launch — see also our Impressum.
12. Related documents
This DPA supplements the Terms of Service and Privacy Policy. In case of conflict regarding processing of Controller workspace data, this DPA prevails over general privacy wording to the extent required by applicable data protection law.