comment_

Data processing agreement

Last updated 11 September 2026.

When your visitors send you reports through Comment, you decide what happens to that data and we carry out your instructions. In the language of the GDPR you are the controller and we are your processor. This page is the agreement that governs that, and it forms part of the terms of service.

Getting a signed copy. Email privacy@commentunderscore.com and ask. We will send this agreement as a document to countersign, with the EU Standard Contractual Clauses (Module 2, controller to processor) and the UK International Data Transfer Addendum annexed for the transfer to the United States. Tell us your entity name and address and we will fill them in.

The contracting entity on our side is named in the box on the terms page; while it is being established we will confirm it in writing before you sign anything.

1. What we process, and why

2. We act on your instructions

We process personal data only on your documented instructions — this agreement, the terms, the settings you choose in the product, and anything else you tell us in writing — unless a law we are subject to requires otherwise, in which case we will tell you first unless that law forbids it.

If we think an instruction breaks data-protection law, we will say so rather than quietly carry it out.

3. Confidentiality

Everyone who can reach your data is bound by confidentiality obligations, and access is limited to the people who need it to run and support the service.

4. Security

We maintain technical and organisational measures appropriate to the risk, taking account of the state of the art and the cost of implementation. What those measures actually are — and, just as usefully, which ones we have not built yet — is on the security page, which is part of this agreement by reference. We will not reduce the overall level of protection during your subscription.

5. Subprocessors

You give us general authorisation to engage the subprocessors listed on the subprocessors page. We impose data-protection obligations on each of them no less protective than these, and we remain responsible to you for what they do.

Before adding or replacing one, we will update that page and email your workspace admin. You have 30 days to object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected part of the service and we will refund anything you have paid for the period after termination.

6. Helping you with the people whose data it is

7. International transfers

The service runs in the United States. For personal data protected by EU, UK or Swiss law, the transfer is covered by the Standard Contractual Clauses annexed to the signed copy of this agreement, with the UK Addendum where UK law applies. We will also give you what you need for a transfer impact assessment.

There is no EU-hosted option, and this agreement does not pretend to create one. If EU-only storage is a hard requirement for you, Comment is not a fit today — better to know that before you install it than after.

8. Deletion and return

You can export your workspace at any time while the account exists. When it ends, you have 30 days to export; after that we delete your personal data, and copies inside backups age out on the backup cycle rather than being reached into individually. We will confirm deletion in writing if you ask.

9. Demonstrating that we do this

We will make available the information reasonably needed to show we meet these obligations, and answer your security questionnaire in writing. Where written answers are genuinely not enough, an audit can be arranged with reasonable notice, no more than once a year unless a regulator requires otherwise, at your cost and without disrupting other customers.

We have not been independently audited or certified. There is no SOC 2 report and no ISO 27001 certificate to send you, and we would rather say that here than have you discover it three emails into a security review.

10. Order of precedence

Where this agreement conflicts with the terms of service on the handling of personal data, this agreement wins.