Legal

Privacy Policy

How CompanyOS handles account, business, employee, and service data.

Version 2026-08-29 · Effective 29 August 2026

1. Who is responsible

CompanyOS, Munzinger Str. 4, 79115 Freiburg, Germany, operates CompanyOS. Contact us about privacy at hemin.faraidun@gmail.com.

For customer account and billing data, the operator is the controller. For employee, applicant, customer, supplier, finance, and other workspace data entered by a customer, that customer is normally the controller and CompanyOS acts as its processor.

2. Data we process

  • Account details, including name, work email, authentication identifiers, and role.
  • Registration security data, including verification records, IP address, and device details.
  • Workspace data used in enabled modules, such as HR, payroll, finance, sales, projects, messages, documents, candidates, and audit records.
  • Billing and subscription identifiers processed with Stripe.
  • Technical logs and error diagnostics used to secure and operate the service.
  • Content sent to an AI provider only when an authorized user enables and uses the relevant AI feature.

3. Why we process data

We process data to provide the contracted service, authenticate users, prevent abuse, maintain tenant isolation, support customers, bill subscriptions, comply with law, and protect the rights and security of users. Depending on the context, the legal basis is contract performance, a legal obligation, legitimate interests in operating a secure B2B service, or consent where consent is required.

4. Service providers

CompanyOS uses providers for hosting, database and authentication, payments, email, error monitoring, background jobs, and optional AI features. These may include Supabase, Stripe, Sentry, the configured SMTP provider, Inngest, Upstash, and AI providers selected for a feature. A provider receives only the data needed for its service. Customers should review the provider and region configuration selected for their deployment.

5. International transfers

Data location depends on the configured hosting region and enabled providers. Where data is transferred outside the EEA or another protected jurisdiction, we use the provider’s contractual transfer safeguards where required.

6. Retention and deletion

We retain data for the active subscription and only as long afterward as needed for legal, security, dispute, backup, and accounting obligations. Registration links expire after 24 hours. Authorized company administrators can export company data and submit a verified company deletion request. Deletion may be delayed where law requires records to be retained; retained records are restricted and removed when that obligation ends.

7. Security

Controls include authenticated access, role checks, tenant-scoped database policies, private storage with time-limited links, audit logging, secret management, and redaction of sensitive error-monitoring fields. No service can guarantee absolute security.

8. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may complain to a supervisory authority. Employees and other users should usually contact their employer first because it controls workspace data. Account owners may also use the company export and deletion process or contact hemin.faraidun@gmail.com.

9. Cookies and changes

See our Cookie Notice. Material policy changes receive a new version and effective date; where required, users will be asked to accept the new version.

← Back to CompanyOS