Skip to content

Limited-time launch: lifetime access from $49.

View lifetime deal

GDPR and Data Processing Addendum

Legal reference

Last updated: October 9, 2026

This page explains how Communicate supports the EU General Data Protection Regulation (GDPR) and the UK GDPR, and it is also our Data Processing Addendum (DPA). Communicate is operated by TinyCheque, Inc. and all customer data is stored on Railway in the United States. If you need a signed copy for your records, email [email protected].

Our position on GDPR

GDPR has no official certification, so we do not claim to be "GDPR certified". What we can say is that the controls GDPR expects are in place: encryption at rest and in transit, self-serve data export and deletion, workspace isolation, data minimization, no sale of personal data, and no training of third-party AI models on your data.

This page works alongside our Privacy Policy at https://communicate.so/privacy, our Terms of Service at https://communicate.so/terms, and our Security page at https://communicate.so/security. If this page and those pages disagree on how we process personal data for a customer, this page takes priority for that processing.

Controller and processor roles

Account data: we are the controller

For details about the businesses and people who sign up for and manage a Communicate workspace, such as names, emails, billing details, and product usage, TinyCheque, Inc. is the controller. Our Privacy Policy describes that processing.

End-user conversation data: you are the controller, we are the processor

For the knowledge sources you upload and the conversations your own end users have with your AI agent or your team, you are the controller and Communicate is your processor. The Data Processing Addendum below governs that processing.

Where your data is hosted

All of Communicate runs on Railway in its US West region. Our application, databases, file storage, and search indexes are hosted there, and that is where customer data is stored. We do not currently offer EU-only data hosting.

A few subprocessors handle personal data in transit to do one job, such as sending an email or generating an AI or voice reply. They do not hold your workspace data. Two of them, Amazon Web Services for email and 60db for voice, process that data in India. Every subprocessor and its location is listed in the Subprocessors section.

If you or your end users are in the European Economic Area, the United Kingdom, or Switzerland, personal data will be transferred to and processed in the United States, and in India for email delivery and voice features. The next section explains how we protect those transfers.

International data transfers

For personal data transferred from the EEA to the United States or India, we rely on the European Commission Standard Contractual Clauses (SCCs) adopted by Decision (EU) 2021/914. Where we act as your processor, Module Two (controller to processor) applies. Where you are yourself a processor, Module Three (processor to processor) applies.

  • United Kingdom: the UK International Data Transfer Addendum to the SCCs, issued by the UK Information Commissioner, applies.
  • Switzerland: the SCCs apply with the adjustments required by the Swiss Federal Act on Data Protection, with the Swiss Federal Data Protection and Information Commissioner as the competent authority.
  • Supplementary measures: encryption in transit and at rest, workspace-level access controls, and the commitments in this addendum on government access requests.

The SCCs are incorporated into this addendum by reference. For the SCCs, the data exporter is the customer, the data importer is TinyCheque, Inc., the governing law is that of Ireland, and disputes go to the courts of Ireland. TinyCheque, Inc. is not currently certified under the EU-U.S. Data Privacy Framework, so we do not rely on it.

Lawful bases for our own processing

Where we are the controller of account data, we rely on these legal bases under Article 6 GDPR:

PurposeLegal basis
Creating your account and running the servicePerformance of a contract
Billing, invoices, and tax recordsLegal obligation and performance of a contract
Security, fraud prevention, and error logsLegitimate interests
Product analytics to improve CommunicateLegitimate interests
Optional Meta Pixel and Conversions API measurementConsent, which you can withdraw at https://communicate.so/cookies#marketing-choices

Subprocessors

You give us general authorization to use the subprocessors below. Each one is bound by written terms that protect personal data to a standard no lower than this addendum.

SubprocessorPurposeLocation
RailwayHosting and infrastructure for the application and data.United States
OpenRouterLLM inference for the AI agent. Used for inference only, not training.United States
Amazon Web Services (Amazon SES)Sends account, notification, and conversation emails. Processes recipient addresses and email content in transit.India
60dbSpeech-to-text and text-to-speech for voice features, when a workspace uses voice. Processes voice audio and text in transit.India
Dodo PaymentsBilling and merchant of record. Handles card details and the PCI boundary.United States
MetaOptional Pixel and Conversions API measurement, only after marketing consent. Never receives conversation content or knowledge sources.United States

We will update this list and the date at the top of this page at least 30 days before a new subprocessor starts processing customer personal data. You can object to a new subprocessor on reasonable data-protection grounds by emailing [email protected] within that period. If we cannot reasonably address the objection, you may stop using the affected part of the service and close your workspace.

Data Processing Addendum

This addendum forms part of the agreement between you, the customer, and TinyCheque, Inc. for the use of Communicate. It applies whenever we process personal data on your behalf that is subject to the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection. It meets the requirements of Article 28 GDPR. It takes effect when you accept our Terms of Service and needs no separate signature.

Subject matter and duration

We process personal data to provide Communicate to you, for as long as you use the service and until the data is deleted as described under Return and deletion.

Nature and purpose

Storing knowledge sources, indexing them for retrieval, generating AI replies, routing conversations between the AI and your team, sending notifications, and producing analytics for your workspace.

Categories of data subjects

  • Your end users who chat with your AI agent or team.
  • Your workspace members.
  • People named in the knowledge sources you choose to upload.

Categories of personal data

  • Conversation messages and their metadata, such as timestamps and channel.
  • Contact details an end user submits, such as name and email.
  • Technical data such as IP address, browser, and device.
  • Any personal data contained in knowledge sources you upload.

Communicate is not designed for special category data under Article 9 GDPR, such as health or biometric data. Do not upload it or ask end users for it unless you have a lawful basis and appropriate safeguards in place.

Our obligations as your processor

  1. Instructions: we process personal data only on your documented instructions, which are this agreement and your configuration of the service, unless the law requires otherwise. If we think an instruction breaks data-protection law, we will tell you.
  2. Confidentiality: everyone at TinyCheque, Inc. who can access personal data is bound by confidentiality obligations.
  3. Security: we apply the technical and organizational measures listed in the next section.
  4. Subprocessors: we use subprocessors only as described in the Subprocessors section and remain responsible for their performance.
  5. Data subject requests: we help you answer requests from your end users, mainly through self-serve export and deletion in your workspace. If an end user contacts us directly, we will pass the request to you.
  6. Assistance: we give reasonable help with your data protection impact assessments and consultations with supervisory authorities, based on the information available to us.
  7. Personal data breaches: we notify you without undue delay after we become aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
  8. Return and deletion: when you delete content or close your workspace, we delete the related personal data within 30 days, unless the law requires us to keep it. You can export your data at any time before deletion.
  9. Audits: we make available the information needed to show compliance with this addendum. If that is not enough, you may run an audit once a year, with 30 days written notice, at your own cost, under confidentiality terms.
  10. Government access: if an authority requests your personal data, we will challenge requests we believe are unlawful and, where the law allows, tell you before we disclose anything.

Technical and organizational measures

  • Encryption of data at rest in our storage layer, and HTTPS/TLS for data in transit.
  • Workspace isolation: every query and AI retrieval is scoped to the workspace that owns the data.
  • Hashed passwords and TOTP two-factor authentication available on every account.
  • Role-based access for workspace members.
  • No storage of card numbers or CVVs. Card details go directly to Dodo Payments.
  • No training of shared or third-party AI models on your data.
  • Self-serve workspace export and full cascading deletion.
  • Error and audit logs used to detect and investigate abuse and incidents.

We do not currently hold SOC 2 or ISO 27001 certification. See https://communicate.so/security for the full, current list of what we protect and what we do not claim.

Your rights under GDPR

If we hold your personal data as a controller, you can ask us to access, correct, delete, restrict, or port it, object to processing, or withdraw consent. We respond to verified requests within one month. You also have the right to complain to your local data protection authority.

If you are an end user who chatted with a business that uses Communicate, that business controls your data. Please send your request to them first. If you contact us, we will forward it to them and help them respond.

To make a request, email [email protected]. We may need to verify your identity before acting on it.

Retention

  • Workspace data is kept while your account is active.
  • Deleted content and closed workspaces are removed within 30 days.
  • Billing records are kept for 7 years to meet tax and accounting law.

Contact

  • Email: [email protected]
  • Postal address: TinyCheque, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.

For a countersigned copy of this addendum, a completed copy of the SCCs annexes, or vendor security questionnaires, email us with your company name and the email of your workspace owner.