CommsOS

Convenience translation. This English text is a convenience translation. The legally binding version is the German one. In the event of any discrepancy or dispute, the German version prevails.

Data Processing Agreement (DPA)

Pursuant to Art. 28 GDPR · Version 2026-04

You conclude this agreement with a single checkbox.

When you first sign in to the portal, you accept it together with the GTC and the Privacy Policy. Nothing to fill in, sign or send back. The portal records who accepted, when and in what capacity, and shows it to you in your profile.

The agreement applies between you and Comms Connect GmbH for the use of Comms OS. It is tailored to the actual processing scenario (telecom analysis, tender and procurement management, asset and customer portal functions) and includes:

  • Description of the subject matter, duration, nature and purpose of the processing (Annex 1)
  • List of sub-processors including EU region and SCC status (Annex 2)
  • Technical and organisational measures covering confidentiality, integrity, availability, incident management and sub-processor control (Annex 3)
  • Escalation and data protection contact points (Annex 4)

At a glance

EU-only data processing

All data hosted in AWS Frankfurt. Region pinning enforced.

Tenant segregation

Database-level RLS plus a dedicated subdomain per customer (TenantGuard).

Schrems II compliant

SCC Module 3 + documented TIAs for Supabase, Vercel, Resend.

Liability capped

12× monthly fee, min EUR 25k / max EUR 500k; intent/gross negligence excluded.

Incident within 72 h

Reporting channel at privacy@commsos.de, 24/7 phone escalation.

RTO 8 h / RPO 24 h

Concrete values per category, verified annually via restore tests.

Audit options

Remote audit any time, on-site max. 1×/year, SOC 2 review available.

Clear exit options

Sub-processor objection → 30-day resolution period → 60-day special termination.

The full contract text

Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

between

The Controller

the company for which access to the CommsOS portal is registered. The company name and

address follow from the registration; the representing person and the point in time follow

from the acceptance record that the portal keeps for every acceptance.

  • Controller — hereinafter referred to as Controller

and

Comms Connect GmbH

Represented by: Rainer Roloff (Geschäftsführer)

Tal 30

80331 München, Germany

Commercial Register: HRB 295951, Amtsgericht München

VAT ID: DE451966748

Phone: +49 89 4522 1556

E-mail (general): info@comms-connect.de

Product support: support@commsos.de

Data protection: privacy@commsos.de

“Comms OS“ is a trademark and product of Comms Connect GmbH.

  • Processor — hereinafter referred to as Processor

1. Subject Matter and Duration of the Processing

1.1 Subject matter

The processing is based on the agreement between the parties (the “Main Agreement“) on the use of the SaaS platform “Comms OS“ provided by Comms Connect GmbH for the analysis and optimisation of telecommunications and IT contracts, for the conduct of tender and procurement processes, and for the management of the related assets and providers. All processing activities are described in Annex 1 – Data Processing.

1.2 Duration

The processing begins once the Main Agreement and this Data Processing Agreement have been signed. The processing continues for an indefinite period until this Agreement or the Main Agreement is terminated by either party.


2. Nature, Purpose and Data Subjects of the Processing

The nature and purpose of the processing, the type of data, the categories of data subjects and the retention periods are described in Annex 1. The processing operations actually carried out for the Controller are specified in the Main Agreement.


3. Obligations of the Processor

(1) The Processor shall process personal data solely as contractually agreed or as instructed by the Controller, unless the Processor is legally required to carry out a specific processing operation. Where such an obligation applies, the Processor shall inform the Controller thereof prior to the processing, unless such notification is legally prohibited. The Processor shall not use the data made available for processing for any other purpose, in particular not for its own purposes.

(2) The Processor confirms that it is familiar with the relevant general data protection provisions. It shall observe the principles of proper data processing.

(3) The Processor undertakes to maintain strict confidentiality when processing the data.

(4) Persons who may gain knowledge of the data processed under this Agreement must commit themselves in writing to confidentiality, unless they are already subject to an equivalent statutory duty of secrecy.

(5) The Processor warrants that persons it deploys for the processing are made familiar with the relevant data protection provisions and the terms of this Agreement before the processing begins.

(6) In connection with the commissioned processing, the Processor shall support the Controller, to the extent necessary, in fulfilling its data protection obligations, in particular in preparing and maintaining the record of processing activities and in carrying out data protection impact assessments. The necessary information and documentation shall be kept available and provided to the Controller without undue delay upon request.

(7) If the Controller is subject to an inspection by supervisory authorities or other bodies, or if data subjects assert rights against it, the Processor undertakes to support the Controller to the extent necessary, insofar as the processing carried out under this Agreement is concerned.

(8) The Processor may provide information to third parties or to data subjects only with the Controller's prior consent. It shall forward any requests addressed directly to it to the Controller without undue delay.

(9) The processing shall, as a rule, take place within the EU or the EEA. Any transfer to a third country may only take place with the Controller's consent and subject to the conditions set out in Chapter V GDPR.


4. Security of Processing

(1) The data security measures described in Annex 3 are established as binding. They define the minimum level owed by the Processor.

(2) The data security measures may be adapted in line with technical and organisational developments, provided the level agreed here is not undercut. Material changes shall be communicated to the Controller without undue delay.

(3) If the security measures taken no longer meet the Controller's requirements, the Processor shall notify the Controller without undue delay.

(4) The Processor warrants that the data processed under this Agreement is strictly segregated from other data holdings.


5. Rectification, Restriction and Erasure of Data

(1) The Processor shall rectify, erase or restrict data processed under this Agreement only in accordance with the contractual arrangements made or upon instruction from the Controller.

(2) The Processor shall comply with the Controller's corresponding instructions at all times, including after termination of this Agreement.

(3) Instructions from the Controller shall be given in writing to the persons named in Annex 4 – Contact Persons.


6. Sub-processing

(1) The Controller authorises the engagement of the sub-processors listed in Annex 2. The Processor shall inform the Controller in writing or by e-mail at least four weeks in advance of any intended engagement of further sub-processors or any change to existing engagements.

(2) The Controller has a right to object to the engagement of new sub-processors, which it may exercise within four weeks of receiving the information. If the Controller does not object within that period, approval is deemed granted.

(2a) If the Controller raises a justified objection within the period under para. 2 (in particular due to third-country concerns, insufficient safeguards or regulatory requirements), the parties shall jointly and in good faith seek a mutually acceptable solution within 30 days of receipt of the objection (e.g. an alternative sub-processor, additional safeguards). If no agreement is reached within that period, either party is entitled to terminate the Main Agreement and this Agreement for cause with 60 days' notice, without either party owing damages arising from this circumstance.

(3) The Controller's rights must also be effectively enforceable against the sub-processor.

(4) If the sub-processor fails to comply with its data protection obligations, the Processor shall be liable to the Controller for this.


7. Rights and Obligations of the Controller

(1) The Controller alone is responsible for assessing the lawfulness of the commissioned processing and for safeguarding the rights of data subjects.

(2) The Controller shall issue all orders, partial orders or instructions in documented form. In urgent cases, instructions may be given verbally. The Controller shall confirm such instructions in documented form without undue delay.

(3) The Controller shall inform the Processor without undue delay if it identifies errors or irregularities when reviewing the results of the processing.

(4) The Controller is entitled to verify, to a reasonable extent, the Processor's compliance with data protection provisions and the contractual arrangements. The following forms of verification are available:

a. Remote audit (at any time, including on an ad hoc basis): submission of a written questionnaire to datenschutz@commsos.de. The Processor shall respond within 10 business days. In addition, the Controller may request access to current SOC 2 Type II or ISO 27001 reports of the sub-processors used, to the extent these are available to the Processor.

b. On-site audit: at most once per calendar year, upon at least 4 weeks' prior notice, during the Processor's business hours. Ad hoc on-site audits (e.g. following a personal data breach) are permitted without this frequency limitation, but must likewise be announced in advance.

c. Third-party auditor: for any form of verification, the Controller may be represented by an independent, qualified third party (e.g. an external data protection officer or an audit firm) that has previously entered into a confidentiality undertaking towards the Processor.

(5) The costs arising from such verifications shall generally be borne by the Controller, unless the verification reveals a material breach of this Agreement by the Processor.


8. Notification Obligations

(1) The Processor shall notify the Controller without undue delay of any breach of the security of personal data processed under this Agreement. The notification shall be made no later than 72 hours after the Processor becomes aware of the relevant event. It must contain at least the following information:

a. a description of the nature of the personal data breach, where possible including the categories and approximate number of data subjects and records concerned;

b. the name and contact details of a point of contact for further information;

c. a description of the likely consequences of the breach;

d. a description of the measures taken or proposed to address the breach.

(2) Significant disruptions in the performance of the processing, as well as violations of data protection provisions, must likewise be reported without undue delay.

(3) The Processor warrants that it will support the Controller, to the extent necessary, in fulfilling the Controller's obligations under Art. 33 and 34 GDPR.


9. Scope of the Controller's Right to Issue Instructions

(1) The Controller reserves a comprehensive right to issue instructions regarding the processing carried out under this Agreement.

(2) The Processor shall notify the Controller without undue delay if it considers an instruction issued by the Controller to violate applicable law. The Processor is entitled to suspend implementation of the relevant instruction until it is confirmed or amended by the Controller.

(3) The Processor shall document the instructions given to it and their implementation.


10. Termination of the Processing

(1) If, upon termination of the processing relationship, data processed under this Agreement remains under the Processor's control, the Processor shall, at the Controller's choice, either destroy the data or hand it over to the Controller. The Controller shall make this choice within 2 weeks of being requested to do so.

(2) The Processor is obliged to procure the prompt destruction or return of data by sub-processors as well.

(3) The Processor shall document the proper destruction of the data and provide evidence thereof to the Controller without undue delay.

(4) Documentation evidencing proper data processing shall be retained by the Processor for at least until the end of the third calendar year following termination of the Agreement.


11. Liability

(1) For damages suffered by a person as a result of unlawful or incorrect data processing under this processing relationship, the Controller and the Processor shall be jointly and severally liable pursuant to Art. 82 GDPR.

(2) The Processor bears the burden of proving that damage was not caused by a circumstance for which it is responsible, insofar as the relevant data was processed by it under this Agreement.

(3) The Processor's liability towards the Controller arising out of or in connection with this Agreement is — subject to para. 4 — limited in aggregate amount to twelve (12) times the average monthly net fee paid by the Controller under the Main Agreement during the twelve months preceding the event giving rise to the damage, with a minimum of EUR 25,000 and a maximum of EUR 500,000 per event of damage and per calendar year. Multiple events of damage arising from a related cause shall be deemed a single event of damage.

(4) The limitation of liability under para. 3 shall not apply to damages arising from (i) injury to life, body or health, (ii) intent or gross negligence, (iii) breach of material contractual obligations (cardinal obligations) — the latter, however, limited to the foreseeable damage typical for this type of contract — and (iv) claims under mandatory law (in particular direct claims by supervisory authorities or data subjects under Art. 82 GDPR).

(5) For the duration of this Agreement, the Processor shall maintain adequate cyber liability and financial loss liability insurance and shall, upon the Controller's request, provide corresponding evidence of insurance.


12. Special Right of Termination

(1) The Controller may terminate the Main Agreement and this Agreement for cause at any time without notice if the Processor commits a material breach of data protection provisions or the terms of this Agreement. Material breaches include, in particular:

a. unauthorised disclosure of personal data to third parties without a legal basis or instruction,

b. persistent refusal of a justified audit under sec. 7 para. 4 or of an instruction under sec. 9,

c. unlawful or unannounced engagement of a sub-processor in violation of sec. 6,

d. intentional or grossly negligent causing of a notifiable personal data breach,

e. repeated (at least three) breaches of this Agreement within 12 months, provided each was objected to by the Controller and not remedied.

(2) For immaterial or first-time breaches, the Controller shall set the Processor a reasonable cure period of at least 10 business days. If the breach is not remedied in time, the Controller is entitled to terminate for cause.

(3) Termination for cause must be declared in writing (or by e-mail in text form) and must state the reasons.


13. Miscellaneous

(1) Both parties are obliged to treat as confidential all knowledge obtained in the course of the contractual relationship regarding trade secrets and data security measures of the other party, even after termination of the Agreement.

(2) Ancillary agreements require written form. Text form by e-mail is sufficient unless mandatory written form is required by law.

(3) The right of retention pursuant to § 273 BGB (German Civil Code — statutory right to withhold performance) is excluded with respect to the data processed under this Agreement and the associated data carriers.

(4) Should individual parts of this Agreement be invalid, the validity of the remainder of the Agreement shall not be affected. The invalid provision shall be replaced by a legally permissible provision that comes closest to the economic purpose of the invalid provision.

(5) In the event of any conflict between this Data Processing Agreement and the Main Agreement, the provisions of this Data Processing Agreement shall prevail on data protection matters.


14. Governing Law and Venue

(1) This Agreement is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and excluding rules of private international law to the extent their conflict-of-laws provisions are subject to derogation.

(2) The exclusive venue for all disputes arising out of or in connection with this Agreement is Munich, provided the Controller is a merchant (Kaufmann), a legal entity under public law or a special fund under public law within the meaning of § 38 ZPO (German Code of Civil Procedure — provision permitting an exclusive-venue agreement between merchants). The Processor is additionally entitled to bring proceedings at the Controller's general place of jurisdiction.


Signatures

Place, date München, 13/09/2026
_________________________ _________________________
Controller Processor (Comms Connect GmbH)
[Name] Rainer Roloff (Geschäftsführer)

Annex 1 – Data Processing

Processing activity: Telecom cost analysis and contract optimisation

Process: Invoice analysis

Analysis and optimisation of the Controller's telecommunications invoices and contracts:

  • Upload and processing of telecom invoices (mobile, fixed line, internet)
  • Analysis of tariff structures, options and usage
  • Preparation of optimisation recommendations
  • Preparation of reports and dashboards
  • Implementation of agreed contract changes with telecom providers
Categories of data subjects Type of data Duration of processing Place of processing
Employees of the Controller who use business telecom contracts Personnel master data (name, department, cost centre), communication data (phone numbers, e-mail), contract information (tariffs, options, terms), invoice data (costs, usage) Term of contract + 10-year retention obligation for invoice data (§ 257 HGB — German Commercial Code, retention of business records), thereafter deletion within 6 months EU (Supabase EU region, Frankfurt)

Process: Asset management

Recording and management of telecom assets (SIM cards, devices, contracts):

  • Assignment of SIM cards and devices to employees
  • Overview of contract terms and notice periods
  • Inventory reports
Categories of data subjects Type of data Duration of processing Place of processing
Employees of the Controller who use business telecom contracts or devices Personnel master data (name, department), device data (IMEI, serial number), SIM data (phone number, SIM no.), contract assignments Term of contract + 3 years (statute of limitations), thereafter deletion within 6 months EU (Supabase EU region, Frankfurt)

Process: Customer portal & team management (SaaS)

Provision of a tenant-exclusive, web-based customer portal (dedicated subdomain per Controller, e.g. “customer.commsos.de“) for self-service administration:

  • Login and authentication (login via an 8-digit one-time code (OTP) sent by e-mail)
  • Invitation and management of the Controller's own team members, including role/permission assignment
  • Access to analyses, dashboards and reports
  • Document upload
  • Communication with the Processor (tasks, notes, internal comments)
  • Audit trail of all administrative actions
Categories of data subjects Type of data Duration of processing Place of processing
Contact persons, administrators and invited team members of the Controller Contact data (name, e-mail, phone), authentication data (e-mail address for delivery of the one-time code, OTP), role/permission information, invitation and acceptance timestamps, usage data (login times, IP addresses, user agent) Term of contract, deletion within 3 months after termination; audit logs up to 3 years EU (Supabase EU region Frankfurt, Vercel EU Edge)

Process: Tender and procurement management (RFP / Procurement)

Preparation, execution and evaluation of procurement and tender processes for the Controller:

  • Creation of procurement projects and tenders (RFPs) based on the Controller's requirements
  • Invitation of selected providers to a separate, tenant-segregated bidder portal
  • Recording of offers, prices, and technical and commercial terms
  • Negotiation rounds, scoring evaluation, award recommendation
  • Documentation of the award decision and handover to contract and asset management
Categories of data subjects Type of data Duration of processing Place of processing
On the buyer side: decision-makers and technical contacts of the Controller Name, business contact data, role/function, activities in the award process Project duration + award documentation period (generally 3 years after the award decision) EU (Supabase EU region Frankfurt)
On the provider side: named contacts of the invited providers Name, business e-mail, phone, function, offers submitted, negotiation contributions, bidder portal login Project duration + award documentation period (generally 3 years after the award decision); thereafter anonymisation of bidder statistics is possible EU (Supabase EU region Frankfurt)

*Note on the provider side:* The processing of providers' personal data takes place on behalf of, and within the legal responsibility of, the Controller as the awarding entity. Providers are invited to participate by the Controller as part of its procurement process; the Processor provides only the technical platform for this purpose.


Annex 2 – Sub-processors

The Controller's personal data is processed and stored exclusively in the European Union (Frankfurt am Main region). The Processor has validly entered into binding Data Processing Agreements (DPAs) with all sub-processors listed below and, where the contracting party is established outside the EU/EEA, the EU Standard Contractual Clauses (SCCs, Module 3 “Processor-to-Processor“) pursuant to Implementing Decision (EU) 2021/914, as amended from time to time. Additional technical and organisational safeguards (encryption, region pinning, need-to-know) are documented and mitigate any residual risks of a third-country transfer in accordance with the requirements of the EDPB.

No. Company Registered office Purpose Place of processing and storage Data Safeguards
1 Supabase Inc. 970 Toa Payoh North #07-04, Singapore 318992 Database (Postgres), authentication, object storage for uploaded documents **EU – Frankfurt am Main (AWS region eu-central-1)**; technically enforced region pinning, no transfer to other regions All data listed in Annex 1 DPA + SCC concluded; encryption at rest (AES-256) and in transit (TLS 1.2+); RLS-based tenant segregation; access by Supabase personnel only upon the Processor's request and logged (SOC 2 Type II)
2 Vercel Inc. 440 N Barranca Ave #4133, Covina, CA 91723, USA Delivery of the web frontend (static assets, edge routing) **EU Edge region (Frankfurt)** for end-customer requests; no persistent storage of personal content data, only transient request pass-through; logs (IP, user agent, path) pinned to the EU region Connection metadata, no substantive content data DPA + SCC concluded; HTTPS enforced; logs limited to a 30-day TTL; no access to database or storage content
3 Resend (Resend, Inc.) 2261 Market St #4667, San Francisco, CA 94114, USA Transactional e-mail delivery (login codes, system notifications) **EU sending region (Frankfurt)** Recipient e-mail, display name, content of the respective system e-mail DPA + SCC concluded; logs limited to the EU region; bounce data 30 days

Region pinning: The Processor reviews the correct configuration of the EU region binding for all sub-processors at least annually and documents the result.

Third-country transfer: Under the current setup, access to plaintext data from third countries is not provided for. In the event of government-ordered access attempts from third countries, the Processor and its sub-processors undertake to pursue all available legal remedies and to inform the Controller without undue delay, to the extent legally permissible.

Transfer Impact Assessment (TIA): The Processor has carried out a documented Transfer Impact Assessment for each of the sub-processors listed above in accordance with EDPB Recommendations 01/2020 (Schrems II-compliant). The TIAs assess the processing, third-country law, additional technical, organisational and contractual safeguards, and the residual risk, and are updated at least annually and on an ad hoc basis. Upon the Controller's written request, the current TIAs will be provided within 10 business days.


Annex 3 – Technical and Organisational Measures (TOMs)

As-of date of the measures documented here: the date of conclusion of the Agreement. The Processor reviews the TOMs at least annually and on an ad hoc basis (incidents, new processing activities, changes to sub-processors) and documents the result internally.

Confidentiality (Art. 32(1)(b) GDPR)

Physical access control (premises)

Technical measures Organisational measures
Access to business premises via electronic locking system Visitors are registered and accompanied
No on-premises data processing on own servers – production systems exclusively hosted with the sub-processor (Annex 2) Clean-desk policy in areas handling customer data

System access control (login/authentication)

Technical measures Organisational measures
End-user login exclusively via short-lived 8-digit one-time codes (OTP) sent by e-mail; no persistent passwords Documented authentication policy for end users (OTP validity period, lockout after failed attempts)
Multi-factor authentication (MFA) for all administrative access (Supabase, Vercel, Cloudflare, GitHub) Documented password and authentication policy for administrative access (minimum length, reuse prohibition, mandatory password manager)
Encrypted storage of administrative authentication data (Argon2 via Supabase Auth) Confidentiality undertaking (NDA) signed by all employees and external contributors in writing before starting work
Automatic session timeouts and re-authentication for sensitive actions Mandatory data protection and information security training upon joining and annual refreshers; training records are retained
Full-disk encryption on all endpoint devices (FileVault / BitLocker) Documented onboarding and offboarding process (access revoked within 24 hours of departure, device return, key and token rotation)
Central device management with enforced screen lock and automatic security updates

Authorisation control (permission management)

Technical measures Organisational measures
Row Level Security (RLS) on all database tables containing personal data Need-to-know and least-privilege principle
Tenant segregation: each customer sees only its own data (technically enforced) Documented role and permission concept
Strict separation of admin and customer roles **Regular recertification of access rights (at least every six months)**, result is documented
Service keys used exclusively server-side, never in the frontend Privileged accounts (owner / admin) are managed separately and reviewed annually
Audit logging of all administrative data access

Segregation control

Technical measures Organisational measures
Logical tenant segregation through Row Level Security (RLS) at database level Documented tenant concept
Additional tenant isolation at URL/subdomain level: each Controller is assigned its own subdomain (e.g. "customer.commsos.de")
Server-side TenantGuard enforces, on every authenticated request, that the logged-in user is authorised for the subdomain (auth-tenant match)
Fully separate Supabase projects for production, staging and development Strict prohibition on processing production customer data in test/development environments
Customer-specific storage buckets with their own access rules
Strict separation of the bidder/provider portal (separate auth role, its own RLS policies, no access to buyer/tenant data)

Integrity (Art. 32(1)(b) GDPR)

Transfer control

Technical measures Organisational measures
TLS 1.2+ / HTTPS enforcement for all data transfers (HSTS) Documented encryption policy
Encryption at rest (AES-256 via Supabase / AWS KMS) Documented data export processes (only for authorised customer admins)
Private storage buckets with short-lived signed URLs Prohibition on sending personal data via unencrypted channels

Input control

Technical measures Organisational measures
Automatic timestamps (created_at, updated_at, user who made the change) on all tables containing personal data Documented change and approval processes
Audit logs (Supabase + application layer) for administrative actions Traceability of all data changes through unique user identification

Availability and Resilience (Art. 32(1)(b) GDPR)

Technical measures Organisational measures
Daily automatic backups by the database provider (Supabase managed backups) Documented backup and disaster-recovery plan
**In addition, hourly full database backups** stored independently of the Processor's cloud account; the last 14 states per processing system are retained Second backup copy independent of the cloud provider — also protects against account loss or accidental deletion on the provider's side
**At least annual documented restore tests** to verify recoverability Defined recovery and response times per processing activity
Geo-redundant delivery via the Vercel Edge Network Escalation paths in the event of an outage (alerting → management → customer)
Automatic scaling and health monitoring

Recovery target values (RTO / RPO):

Category RPO (max. tolerable data loss) RTO (max. tolerable downtime)
Core production functions (auth, analytics dashboard, data retrieval) **≤ 24 hours** **≤ 8 hours**
File uploads / reports / documents ≤ 24 hours ≤ 24 hours
Audit logs and historical reports ≤ 24 hours ≤ 72 hours

Compliance with these values is verified and documented as part of the at-least-annual restore tests.

Process for Regular Review (Art. 32(1)(d) GDPR)

Technical measures Organisational measures
Automated security updates and dependency scanning (e.g. Dependabot, Aikido) Annual review of this TOM catalogue and the effectiveness of the measures
Mandatory code review before production deployment Data protection and information security are integral parts of the development and release process (privacy by design / by default)
Quarterly compliance scan (Aikido, Supabase Advisors, Prowler) Ad hoc reviews following security incidents or changes to sub-processors

Incident and Personal Data Breach Management

Measure Description
**Documented incident response plan** Defined roles (incident lead, communications, forensics), escalation levels and response times
**Reporting chain** Initial analysis within 24 hours of becoming aware; notification to the Controller under sec. 8 of this Agreement within 72 hours
Central incident mailbox privacy@commsos.de (subject line "SECURITY INCIDENT") plus telephone escalation
Lessons-learned obligation After every notifiable incident, causes, measures and improvements are documented and fed back into the TOMs
External support External data protection consultants and IT forensics providers engaged as needed

Sub-processor Control

Measure Description
Written data processing agreement with each sub-processor listed in Annex 2 including SCCs where a third-country transfer is involved
Annual review of sub-processors Evaluation of audit reports (e.g. SOC 2, ISO 27001) or self-assessments
Region-pinning verification At least annual check of the EU region configuration

Annex 4 – Contact Persons

Processor (Comms Connect GmbH)

Responsible contact (management):

Rainer Roloff (Geschäftsführer)

E-mail: info@comms-connect.de

Phone: +49 89 4522 1556

Operational product contact (instructions, technical and contract-related enquiries regarding the ongoing operation of “Comms OS“):

support@commsos.de

(processed on business days, response generally within two business days)

Data protection enquiries (Art. 13/14, 15–22, 33 GDPR):

privacy@commsos.de

(monitored mailbox, incoming messages processed on business days)

Personal data breach notifications (24/7):

privacy@commsos.de with subject line “SECURITY INCIDENT“, or by phone at +49 89 4522 1556

Controller

Responsible contact:

[Name]

E-mail: [Email address]

Phone: [Phone number]

If your procurement department requires a signed copy

That is not required — acceptance in the portal is sufficient. If your internal policies nevertheless require a signature: open the version, sign it and send it to privacy@commsos.de. We will countersign within two business days.

Privacy Policy

This text reflects the current state of the processing and is updated whenever sub-processors or TOMs change. If it changes materially, the portal asks for renewed acceptance once — never otherwise. The current list of sub-processors used is available at /subprocessors (German only).

Questions about the DPA or data protection matters: privacy@commsos.de

Governing language

This English text is a convenience translation. The legally binding version is the German one. In the event of any discrepancy or dispute, the German version prevails.