Data processing agreement
Last updated 11 September 2026.
When your visitors send you reports through Comment, you decide what happens to that data and we carry out your instructions. In the language of the GDPR you are the controller and we are your processor. This page is the agreement that governs that, and it forms part of the terms of service.
Getting a signed copy. Email privacy@commentunderscore.com and ask. We will send this agreement as a document to countersign, with the EU Standard Contractual Clauses (Module 2, controller to processor) and the UK International Data Transfer Addendum annexed for the transfer to the United States. Tell us your entity name and address and we will fill them in.
The contracting entity on our side is named in the box on the terms page; while it is being established we will confirm it in writing before you sign anything.
1. What we process, and why
- Subject matter and duration. Providing Comment to you, for as long as your account exists, plus the short wind-down in section 8.
- Nature and purpose. Receiving, storing, displaying, redacting, and exporting website feedback and the captured context attached to it, so your team can triage and fix what a reporter pointed at.
- Categories of data subjects. Visitors and testers who report a problem on your website, and the members of your own team who use the dashboard.
-
Categories of personal data. The free text a reporter writes; the page
address without its query string; the role, tag, accessible name and coarse geometry of
the element they marked; their vector markup; any file they choose to attach; console
errors and failed-request URLs from the capture window; any metadata your own site
attaches, including the optional
user.id,user.emailanduser.namekeys; IP addresses in security logs when a request is refused; and the names, email addresses and password hashes of your team members. The complete inventory is in the privacy notice. - Special-category data. Not expected and not invited. The terms ask you not to route it into Comment.
2. We act on your instructions
We process personal data only on your documented instructions — this agreement, the terms, the settings you choose in the product, and anything else you tell us in writing — unless a law we are subject to requires otherwise, in which case we will tell you first unless that law forbids it.
If we think an instruction breaks data-protection law, we will say so rather than quietly carry it out.
3. Confidentiality
Everyone who can reach your data is bound by confidentiality obligations, and access is limited to the people who need it to run and support the service.
4. Security
We maintain technical and organisational measures appropriate to the risk, taking account of the state of the art and the cost of implementation. What those measures actually are — and, just as usefully, which ones we have not built yet — is on the security page, which is part of this agreement by reference. We will not reduce the overall level of protection during your subscription.
5. Subprocessors
You give us general authorisation to engage the subprocessors listed on the subprocessors page. We impose data-protection obligations on each of them no less protective than these, and we remain responsible to you for what they do.
Before adding or replacing one, we will update that page and email your workspace admin. You have 30 days to object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected part of the service and we will refund anything you have paid for the period after termination.
6. Helping you with the people whose data it is
- Data-subject requests. Most of what you need is in the product: you can read, export and erase the reports in your workspace. Where that is not enough, we will help you within a reasonable time. If a data subject comes to us directly, we will point them to you rather than act on it ourselves.
- Impact assessments and prior consultation. We will give you the information you reasonably need for a DPIA, taking into account how little the product collects in the first place.
- Personal-data breaches. If one affects your data, we will tell you without undue delay after becoming aware of it, with what we know and what we are doing about it, and we will keep you updated as we learn more.
7. International transfers
The service runs in the United States. For personal data protected by EU, UK or Swiss law, the transfer is covered by the Standard Contractual Clauses annexed to the signed copy of this agreement, with the UK Addendum where UK law applies. We will also give you what you need for a transfer impact assessment.
There is no EU-hosted option, and this agreement does not pretend to create one. If EU-only storage is a hard requirement for you, Comment is not a fit today — better to know that before you install it than after.
8. Deletion and return
You can export your workspace at any time while the account exists. When it ends, you have 30 days to export; after that we delete your personal data, and copies inside backups age out on the backup cycle rather than being reached into individually. We will confirm deletion in writing if you ask.
9. Demonstrating that we do this
We will make available the information reasonably needed to show we meet these obligations, and answer your security questionnaire in writing. Where written answers are genuinely not enough, an audit can be arranged with reasonable notice, no more than once a year unless a regulator requires otherwise, at your cost and without disrupting other customers.
We have not been independently audited or certified. There is no SOC 2 report and no ISO 27001 certificate to send you, and we would rather say that here than have you discover it three emails into a security review.
10. Order of precedence
Where this agreement conflicts with the terms of service on the handling of personal data, this agreement wins.