GDPR and Data Processing Addendum
Legal reference
Last updated: October 9, 2026
This page explains how Communicate supports the EU General Data Protection Regulation (GDPR) and the UK GDPR, and it is also our Data Processing Addendum (DPA). Communicate is operated by TinyCheque, Inc. and all customer data is stored on Railway in the United States. If you need a signed copy for your records, email [email protected].
Our position on GDPR
GDPR has no official certification, so we do not claim to be "GDPR certified". What we can say is that the controls GDPR expects are in place: encryption at rest and in transit, self-serve data export and deletion, workspace isolation, data minimization, no sale of personal data, and no training of third-party AI models on your data.
This page works alongside our Privacy Policy at https://communicate.so/privacy, our Terms of Service at https://communicate.so/terms, and our Security page at https://communicate.so/security. If this page and those pages disagree on how we process personal data for a customer, this page takes priority for that processing.
Controller and processor roles
Account data: we are the controller
For details about the businesses and people who sign up for and manage a Communicate workspace, such as names, emails, billing details, and product usage, TinyCheque, Inc. is the controller. Our Privacy Policy describes that processing.
End-user conversation data: you are the controller, we are the processor
For the knowledge sources you upload and the conversations your own end users have with your AI agent or your team, you are the controller and Communicate is your processor. The Data Processing Addendum below governs that processing.
Where your data is hosted
All of Communicate runs on Railway in its US West region. Our application, databases, file storage, and search indexes are hosted there, and that is where customer data is stored. We do not currently offer EU-only data hosting.
A few subprocessors handle personal data in transit to do one job, such as sending an email or generating an AI or voice reply. They do not hold your workspace data. Two of them, Amazon Web Services for email and 60db for voice, process that data in India. Every subprocessor and its location is listed in the Subprocessors section.
If you or your end users are in the European Economic Area, the United Kingdom, or Switzerland, personal data will be transferred to and processed in the United States, and in India for email delivery and voice features. The next section explains how we protect those transfers.
International data transfers
For personal data transferred from the EEA to the United States or India, we rely on the European Commission Standard Contractual Clauses (SCCs) adopted by Decision (EU) 2021/914. Where we act as your processor, Module Two (controller to processor) applies. Where you are yourself a processor, Module Three (processor to processor) applies.
- United Kingdom: the UK International Data Transfer Addendum to the SCCs, issued by the UK Information Commissioner, applies.
- Switzerland: the SCCs apply with the adjustments required by the Swiss Federal Act on Data Protection, with the Swiss Federal Data Protection and Information Commissioner as the competent authority.
- Supplementary measures: encryption in transit and at rest, workspace-level access controls, and the commitments in this addendum on government access requests.
The SCCs are incorporated into this addendum by reference. For the SCCs, the data exporter is the customer, the data importer is TinyCheque, Inc., the governing law is that of Ireland, and disputes go to the courts of Ireland. TinyCheque, Inc. is not currently certified under the EU-U.S. Data Privacy Framework, so we do not rely on it.
Lawful bases for our own processing
Where we are the controller of account data, we rely on these legal bases under Article 6 GDPR:
Subprocessors
You give us general authorization to use the subprocessors below. Each one is bound by written terms that protect personal data to a standard no lower than this addendum.
We will update this list and the date at the top of this page at least 30 days before a new subprocessor starts processing customer personal data. You can object to a new subprocessor on reasonable data-protection grounds by emailing [email protected] within that period. If we cannot reasonably address the objection, you may stop using the affected part of the service and close your workspace.
Data Processing Addendum
This addendum forms part of the agreement between you, the customer, and TinyCheque, Inc. for the use of Communicate. It applies whenever we process personal data on your behalf that is subject to the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection. It meets the requirements of Article 28 GDPR. It takes effect when you accept our Terms of Service and needs no separate signature.
Subject matter and duration
We process personal data to provide Communicate to you, for as long as you use the service and until the data is deleted as described under Return and deletion.
Nature and purpose
Storing knowledge sources, indexing them for retrieval, generating AI replies, routing conversations between the AI and your team, sending notifications, and producing analytics for your workspace.
Categories of data subjects
- Your end users who chat with your AI agent or team.
- Your workspace members.
- People named in the knowledge sources you choose to upload.
Categories of personal data
- Conversation messages and their metadata, such as timestamps and channel.
- Contact details an end user submits, such as name and email.
- Technical data such as IP address, browser, and device.
- Any personal data contained in knowledge sources you upload.
Communicate is not designed for special category data under Article 9 GDPR, such as health or biometric data. Do not upload it or ask end users for it unless you have a lawful basis and appropriate safeguards in place.
Our obligations as your processor
- Instructions: we process personal data only on your documented instructions, which are this agreement and your configuration of the service, unless the law requires otherwise. If we think an instruction breaks data-protection law, we will tell you.
- Confidentiality: everyone at TinyCheque, Inc. who can access personal data is bound by confidentiality obligations.
- Security: we apply the technical and organizational measures listed in the next section.
- Subprocessors: we use subprocessors only as described in the Subprocessors section and remain responsible for their performance.
- Data subject requests: we help you answer requests from your end users, mainly through self-serve export and deletion in your workspace. If an end user contacts us directly, we will pass the request to you.
- Assistance: we give reasonable help with your data protection impact assessments and consultations with supervisory authorities, based on the information available to us.
- Personal data breaches: we notify you without undue delay after we become aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
- Return and deletion: when you delete content or close your workspace, we delete the related personal data within 30 days, unless the law requires us to keep it. You can export your data at any time before deletion.
- Audits: we make available the information needed to show compliance with this addendum. If that is not enough, you may run an audit once a year, with 30 days written notice, at your own cost, under confidentiality terms.
- Government access: if an authority requests your personal data, we will challenge requests we believe are unlawful and, where the law allows, tell you before we disclose anything.
Technical and organizational measures
- Encryption of data at rest in our storage layer, and HTTPS/TLS for data in transit.
- Workspace isolation: every query and AI retrieval is scoped to the workspace that owns the data.
- Hashed passwords and TOTP two-factor authentication available on every account.
- Role-based access for workspace members.
- No storage of card numbers or CVVs. Card details go directly to Dodo Payments.
- No training of shared or third-party AI models on your data.
- Self-serve workspace export and full cascading deletion.
- Error and audit logs used to detect and investigate abuse and incidents.
We do not currently hold SOC 2 or ISO 27001 certification. See https://communicate.so/security for the full, current list of what we protect and what we do not claim.
Your rights under GDPR
If we hold your personal data as a controller, you can ask us to access, correct, delete, restrict, or port it, object to processing, or withdraw consent. We respond to verified requests within one month. You also have the right to complain to your local data protection authority.
If you are an end user who chatted with a business that uses Communicate, that business controls your data. Please send your request to them first. If you contact us, we will forward it to them and help them respond.
To make a request, email [email protected]. We may need to verify your identity before acting on it.
Retention
- Workspace data is kept while your account is active.
- Deleted content and closed workspaces are removed within 30 days.
- Billing records are kept for 7 years to meet tax and accounting law.
Contact
- Email: [email protected]
- Postal address: TinyCheque, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.
For a countersigned copy of this addendum, a completed copy of the SCCs annexes, or vendor security questionnaires, email us with your company name and the email of your workspace owner.