Convenience translation. This English text is a convenience translation. The legally binding version is the German one. In the event of any discrepancy or dispute, the German version prevails.
Pursuant to Art. 28 GDPR · Version 2026-04
You conclude this agreement with a single checkbox.
When you first sign in to the portal, you accept it together with the GTC and the Privacy Policy. Nothing to fill in, sign or send back. The portal records who accepted, when and in what capacity, and shows it to you in your profile.
The agreement applies between you and Comms Connect GmbH for the use of Comms OS. It is tailored to the actual processing scenario (telecom analysis, tender and procurement management, asset and customer portal functions) and includes:
EU-only data processing
All data hosted in AWS Frankfurt. Region pinning enforced.
Tenant segregation
Database-level RLS plus a dedicated subdomain per customer (TenantGuard).
Schrems II compliant
SCC Module 3 + documented TIAs for Supabase, Vercel, Resend.
Liability capped
12× monthly fee, min EUR 25k / max EUR 500k; intent/gross negligence excluded.
Incident within 72 h
Reporting channel at privacy@commsos.de, 24/7 phone escalation.
RTO 8 h / RPO 24 h
Concrete values per category, verified annually via restore tests.
Audit options
Remote audit any time, on-site max. 1×/year, SOC 2 review available.
Clear exit options
Sub-processor objection → 30-day resolution period → 60-day special termination.
between
The Controller
the company for which access to the CommsOS portal is registered. The company name and
address follow from the registration; the representing person and the point in time follow
from the acceptance record that the portal keeps for every acceptance.
and
Comms Connect GmbH
Represented by: Rainer Roloff (Geschäftsführer)
Tal 30
80331 München, Germany
Commercial Register: HRB 295951, Amtsgericht München
VAT ID: DE451966748
Phone: +49 89 4522 1556
E-mail (general): info@comms-connect.de
Product support: support@commsos.de
Data protection: privacy@commsos.de
“Comms OS“ is a trademark and product of Comms Connect GmbH.
The processing is based on the agreement between the parties (the “Main Agreement“) on the use of the SaaS platform “Comms OS“ provided by Comms Connect GmbH for the analysis and optimisation of telecommunications and IT contracts, for the conduct of tender and procurement processes, and for the management of the related assets and providers. All processing activities are described in Annex 1 – Data Processing.
The processing begins once the Main Agreement and this Data Processing Agreement have been signed. The processing continues for an indefinite period until this Agreement or the Main Agreement is terminated by either party.
The nature and purpose of the processing, the type of data, the categories of data subjects and the retention periods are described in Annex 1. The processing operations actually carried out for the Controller are specified in the Main Agreement.
(1) The Processor shall process personal data solely as contractually agreed or as instructed by the Controller, unless the Processor is legally required to carry out a specific processing operation. Where such an obligation applies, the Processor shall inform the Controller thereof prior to the processing, unless such notification is legally prohibited. The Processor shall not use the data made available for processing for any other purpose, in particular not for its own purposes.
(2) The Processor confirms that it is familiar with the relevant general data protection provisions. It shall observe the principles of proper data processing.
(3) The Processor undertakes to maintain strict confidentiality when processing the data.
(4) Persons who may gain knowledge of the data processed under this Agreement must commit themselves in writing to confidentiality, unless they are already subject to an equivalent statutory duty of secrecy.
(5) The Processor warrants that persons it deploys for the processing are made familiar with the relevant data protection provisions and the terms of this Agreement before the processing begins.
(6) In connection with the commissioned processing, the Processor shall support the Controller, to the extent necessary, in fulfilling its data protection obligations, in particular in preparing and maintaining the record of processing activities and in carrying out data protection impact assessments. The necessary information and documentation shall be kept available and provided to the Controller without undue delay upon request.
(7) If the Controller is subject to an inspection by supervisory authorities or other bodies, or if data subjects assert rights against it, the Processor undertakes to support the Controller to the extent necessary, insofar as the processing carried out under this Agreement is concerned.
(8) The Processor may provide information to third parties or to data subjects only with the Controller's prior consent. It shall forward any requests addressed directly to it to the Controller without undue delay.
(9) The processing shall, as a rule, take place within the EU or the EEA. Any transfer to a third country may only take place with the Controller's consent and subject to the conditions set out in Chapter V GDPR.
(1) The data security measures described in Annex 3 are established as binding. They define the minimum level owed by the Processor.
(2) The data security measures may be adapted in line with technical and organisational developments, provided the level agreed here is not undercut. Material changes shall be communicated to the Controller without undue delay.
(3) If the security measures taken no longer meet the Controller's requirements, the Processor shall notify the Controller without undue delay.
(4) The Processor warrants that the data processed under this Agreement is strictly segregated from other data holdings.
(1) The Processor shall rectify, erase or restrict data processed under this Agreement only in accordance with the contractual arrangements made or upon instruction from the Controller.
(2) The Processor shall comply with the Controller's corresponding instructions at all times, including after termination of this Agreement.
(3) Instructions from the Controller shall be given in writing to the persons named in Annex 4 – Contact Persons.
(1) The Controller authorises the engagement of the sub-processors listed in Annex 2. The Processor shall inform the Controller in writing or by e-mail at least four weeks in advance of any intended engagement of further sub-processors or any change to existing engagements.
(2) The Controller has a right to object to the engagement of new sub-processors, which it may exercise within four weeks of receiving the information. If the Controller does not object within that period, approval is deemed granted.
(2a) If the Controller raises a justified objection within the period under para. 2 (in particular due to third-country concerns, insufficient safeguards or regulatory requirements), the parties shall jointly and in good faith seek a mutually acceptable solution within 30 days of receipt of the objection (e.g. an alternative sub-processor, additional safeguards). If no agreement is reached within that period, either party is entitled to terminate the Main Agreement and this Agreement for cause with 60 days' notice, without either party owing damages arising from this circumstance.
(3) The Controller's rights must also be effectively enforceable against the sub-processor.
(4) If the sub-processor fails to comply with its data protection obligations, the Processor shall be liable to the Controller for this.
(1) The Controller alone is responsible for assessing the lawfulness of the commissioned processing and for safeguarding the rights of data subjects.
(2) The Controller shall issue all orders, partial orders or instructions in documented form. In urgent cases, instructions may be given verbally. The Controller shall confirm such instructions in documented form without undue delay.
(3) The Controller shall inform the Processor without undue delay if it identifies errors or irregularities when reviewing the results of the processing.
(4) The Controller is entitled to verify, to a reasonable extent, the Processor's compliance with data protection provisions and the contractual arrangements. The following forms of verification are available:
a. Remote audit (at any time, including on an ad hoc basis): submission of a written questionnaire to datenschutz@commsos.de. The Processor shall respond within 10 business days. In addition, the Controller may request access to current SOC 2 Type II or ISO 27001 reports of the sub-processors used, to the extent these are available to the Processor.
b. On-site audit: at most once per calendar year, upon at least 4 weeks' prior notice, during the Processor's business hours. Ad hoc on-site audits (e.g. following a personal data breach) are permitted without this frequency limitation, but must likewise be announced in advance.
c. Third-party auditor: for any form of verification, the Controller may be represented by an independent, qualified third party (e.g. an external data protection officer or an audit firm) that has previously entered into a confidentiality undertaking towards the Processor.
(5) The costs arising from such verifications shall generally be borne by the Controller, unless the verification reveals a material breach of this Agreement by the Processor.
(1) The Processor shall notify the Controller without undue delay of any breach of the security of personal data processed under this Agreement. The notification shall be made no later than 72 hours after the Processor becomes aware of the relevant event. It must contain at least the following information:
a. a description of the nature of the personal data breach, where possible including the categories and approximate number of data subjects and records concerned;
b. the name and contact details of a point of contact for further information;
c. a description of the likely consequences of the breach;
d. a description of the measures taken or proposed to address the breach.
(2) Significant disruptions in the performance of the processing, as well as violations of data protection provisions, must likewise be reported without undue delay.
(3) The Processor warrants that it will support the Controller, to the extent necessary, in fulfilling the Controller's obligations under Art. 33 and 34 GDPR.
(1) The Controller reserves a comprehensive right to issue instructions regarding the processing carried out under this Agreement.
(2) The Processor shall notify the Controller without undue delay if it considers an instruction issued by the Controller to violate applicable law. The Processor is entitled to suspend implementation of the relevant instruction until it is confirmed or amended by the Controller.
(3) The Processor shall document the instructions given to it and their implementation.
(1) If, upon termination of the processing relationship, data processed under this Agreement remains under the Processor's control, the Processor shall, at the Controller's choice, either destroy the data or hand it over to the Controller. The Controller shall make this choice within 2 weeks of being requested to do so.
(2) The Processor is obliged to procure the prompt destruction or return of data by sub-processors as well.
(3) The Processor shall document the proper destruction of the data and provide evidence thereof to the Controller without undue delay.
(4) Documentation evidencing proper data processing shall be retained by the Processor for at least until the end of the third calendar year following termination of the Agreement.
(1) For damages suffered by a person as a result of unlawful or incorrect data processing under this processing relationship, the Controller and the Processor shall be jointly and severally liable pursuant to Art. 82 GDPR.
(2) The Processor bears the burden of proving that damage was not caused by a circumstance for which it is responsible, insofar as the relevant data was processed by it under this Agreement.
(3) The Processor's liability towards the Controller arising out of or in connection with this Agreement is — subject to para. 4 — limited in aggregate amount to twelve (12) times the average monthly net fee paid by the Controller under the Main Agreement during the twelve months preceding the event giving rise to the damage, with a minimum of EUR 25,000 and a maximum of EUR 500,000 per event of damage and per calendar year. Multiple events of damage arising from a related cause shall be deemed a single event of damage.
(4) The limitation of liability under para. 3 shall not apply to damages arising from (i) injury to life, body or health, (ii) intent or gross negligence, (iii) breach of material contractual obligations (cardinal obligations) — the latter, however, limited to the foreseeable damage typical for this type of contract — and (iv) claims under mandatory law (in particular direct claims by supervisory authorities or data subjects under Art. 82 GDPR).
(5) For the duration of this Agreement, the Processor shall maintain adequate cyber liability and financial loss liability insurance and shall, upon the Controller's request, provide corresponding evidence of insurance.
(1) The Controller may terminate the Main Agreement and this Agreement for cause at any time without notice if the Processor commits a material breach of data protection provisions or the terms of this Agreement. Material breaches include, in particular:
a. unauthorised disclosure of personal data to third parties without a legal basis or instruction,
b. persistent refusal of a justified audit under sec. 7 para. 4 or of an instruction under sec. 9,
c. unlawful or unannounced engagement of a sub-processor in violation of sec. 6,
d. intentional or grossly negligent causing of a notifiable personal data breach,
e. repeated (at least three) breaches of this Agreement within 12 months, provided each was objected to by the Controller and not remedied.
(2) For immaterial or first-time breaches, the Controller shall set the Processor a reasonable cure period of at least 10 business days. If the breach is not remedied in time, the Controller is entitled to terminate for cause.
(3) Termination for cause must be declared in writing (or by e-mail in text form) and must state the reasons.
(1) Both parties are obliged to treat as confidential all knowledge obtained in the course of the contractual relationship regarding trade secrets and data security measures of the other party, even after termination of the Agreement.
(2) Ancillary agreements require written form. Text form by e-mail is sufficient unless mandatory written form is required by law.
(3) The right of retention pursuant to § 273 BGB (German Civil Code — statutory right to withhold performance) is excluded with respect to the data processed under this Agreement and the associated data carriers.
(4) Should individual parts of this Agreement be invalid, the validity of the remainder of the Agreement shall not be affected. The invalid provision shall be replaced by a legally permissible provision that comes closest to the economic purpose of the invalid provision.
(5) In the event of any conflict between this Data Processing Agreement and the Main Agreement, the provisions of this Data Processing Agreement shall prevail on data protection matters.
(1) This Agreement is governed by the law of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG) and excluding rules of private international law to the extent their conflict-of-laws provisions are subject to derogation.
(2) The exclusive venue for all disputes arising out of or in connection with this Agreement is Munich, provided the Controller is a merchant (Kaufmann), a legal entity under public law or a special fund under public law within the meaning of § 38 ZPO (German Code of Civil Procedure — provision permitting an exclusive-venue agreement between merchants). The Processor is additionally entitled to bring proceedings at the Controller's general place of jurisdiction.
Signatures
| Place, date | München, 13/09/2026 |
| _________________________ | _________________________ |
| Controller | Processor (Comms Connect GmbH) |
| [Name] | Rainer Roloff (Geschäftsführer) |
Analysis and optimisation of the Controller's telecommunications invoices and contracts:
| Categories of data subjects | Type of data | Duration of processing | Place of processing |
|---|---|---|---|
| Employees of the Controller who use business telecom contracts | Personnel master data (name, department, cost centre), communication data (phone numbers, e-mail), contract information (tariffs, options, terms), invoice data (costs, usage) | Term of contract + 10-year retention obligation for invoice data (§ 257 HGB — German Commercial Code, retention of business records), thereafter deletion within 6 months | EU (Supabase EU region, Frankfurt) |
Recording and management of telecom assets (SIM cards, devices, contracts):
| Categories of data subjects | Type of data | Duration of processing | Place of processing |
|---|---|---|---|
| Employees of the Controller who use business telecom contracts or devices | Personnel master data (name, department), device data (IMEI, serial number), SIM data (phone number, SIM no.), contract assignments | Term of contract + 3 years (statute of limitations), thereafter deletion within 6 months | EU (Supabase EU region, Frankfurt) |
Provision of a tenant-exclusive, web-based customer portal (dedicated subdomain per Controller, e.g. “customer.commsos.de“) for self-service administration:
| Categories of data subjects | Type of data | Duration of processing | Place of processing |
|---|---|---|---|
| Contact persons, administrators and invited team members of the Controller | Contact data (name, e-mail, phone), authentication data (e-mail address for delivery of the one-time code, OTP), role/permission information, invitation and acceptance timestamps, usage data (login times, IP addresses, user agent) | Term of contract, deletion within 3 months after termination; audit logs up to 3 years | EU (Supabase EU region Frankfurt, Vercel EU Edge) |
Preparation, execution and evaluation of procurement and tender processes for the Controller:
| Categories of data subjects | Type of data | Duration of processing | Place of processing |
|---|---|---|---|
| On the buyer side: decision-makers and technical contacts of the Controller | Name, business contact data, role/function, activities in the award process | Project duration + award documentation period (generally 3 years after the award decision) | EU (Supabase EU region Frankfurt) |
| On the provider side: named contacts of the invited providers | Name, business e-mail, phone, function, offers submitted, negotiation contributions, bidder portal login | Project duration + award documentation period (generally 3 years after the award decision); thereafter anonymisation of bidder statistics is possible | EU (Supabase EU region Frankfurt) |
*Note on the provider side:* The processing of providers' personal data takes place on behalf of, and within the legal responsibility of, the Controller as the awarding entity. Providers are invited to participate by the Controller as part of its procurement process; the Processor provides only the technical platform for this purpose.
The Controller's personal data is processed and stored exclusively in the European Union (Frankfurt am Main region). The Processor has validly entered into binding Data Processing Agreements (DPAs) with all sub-processors listed below and, where the contracting party is established outside the EU/EEA, the EU Standard Contractual Clauses (SCCs, Module 3 “Processor-to-Processor“) pursuant to Implementing Decision (EU) 2021/914, as amended from time to time. Additional technical and organisational safeguards (encryption, region pinning, need-to-know) are documented and mitigate any residual risks of a third-country transfer in accordance with the requirements of the EDPB.
| No. | Company | Registered office | Purpose | Place of processing and storage | Data | Safeguards |
|---|---|---|---|---|---|---|
| 1 | Supabase Inc. | 970 Toa Payoh North #07-04, Singapore 318992 | Database (Postgres), authentication, object storage for uploaded documents | **EU – Frankfurt am Main (AWS region eu-central-1)**; technically enforced region pinning, no transfer to other regions | All data listed in Annex 1 | DPA + SCC concluded; encryption at rest (AES-256) and in transit (TLS 1.2+); RLS-based tenant segregation; access by Supabase personnel only upon the Processor's request and logged (SOC 2 Type II) |
| 2 | Vercel Inc. | 440 N Barranca Ave #4133, Covina, CA 91723, USA | Delivery of the web frontend (static assets, edge routing) | **EU Edge region (Frankfurt)** for end-customer requests; no persistent storage of personal content data, only transient request pass-through; logs (IP, user agent, path) pinned to the EU region | Connection metadata, no substantive content data | DPA + SCC concluded; HTTPS enforced; logs limited to a 30-day TTL; no access to database or storage content |
| 3 | Resend (Resend, Inc.) | 2261 Market St #4667, San Francisco, CA 94114, USA | Transactional e-mail delivery (login codes, system notifications) | **EU sending region (Frankfurt)** | Recipient e-mail, display name, content of the respective system e-mail | DPA + SCC concluded; logs limited to the EU region; bounce data 30 days |
Region pinning: The Processor reviews the correct configuration of the EU region binding for all sub-processors at least annually and documents the result.
Third-country transfer: Under the current setup, access to plaintext data from third countries is not provided for. In the event of government-ordered access attempts from third countries, the Processor and its sub-processors undertake to pursue all available legal remedies and to inform the Controller without undue delay, to the extent legally permissible.
Transfer Impact Assessment (TIA): The Processor has carried out a documented Transfer Impact Assessment for each of the sub-processors listed above in accordance with EDPB Recommendations 01/2020 (Schrems II-compliant). The TIAs assess the processing, third-country law, additional technical, organisational and contractual safeguards, and the residual risk, and are updated at least annually and on an ad hoc basis. Upon the Controller's written request, the current TIAs will be provided within 10 business days.
As-of date of the measures documented here: the date of conclusion of the Agreement. The Processor reviews the TOMs at least annually and on an ad hoc basis (incidents, new processing activities, changes to sub-processors) and documents the result internally.
| Technical measures | Organisational measures |
|---|---|
| Access to business premises via electronic locking system | Visitors are registered and accompanied |
| No on-premises data processing on own servers – production systems exclusively hosted with the sub-processor (Annex 2) | Clean-desk policy in areas handling customer data |
| Technical measures | Organisational measures |
|---|---|
| End-user login exclusively via short-lived 8-digit one-time codes (OTP) sent by e-mail; no persistent passwords | Documented authentication policy for end users (OTP validity period, lockout after failed attempts) |
| Multi-factor authentication (MFA) for all administrative access (Supabase, Vercel, Cloudflare, GitHub) | Documented password and authentication policy for administrative access (minimum length, reuse prohibition, mandatory password manager) |
| Encrypted storage of administrative authentication data (Argon2 via Supabase Auth) | Confidentiality undertaking (NDA) signed by all employees and external contributors in writing before starting work |
| Automatic session timeouts and re-authentication for sensitive actions | Mandatory data protection and information security training upon joining and annual refreshers; training records are retained |
| Full-disk encryption on all endpoint devices (FileVault / BitLocker) | Documented onboarding and offboarding process (access revoked within 24 hours of departure, device return, key and token rotation) |
| Central device management with enforced screen lock and automatic security updates |
| Technical measures | Organisational measures |
|---|---|
| Row Level Security (RLS) on all database tables containing personal data | Need-to-know and least-privilege principle |
| Tenant segregation: each customer sees only its own data (technically enforced) | Documented role and permission concept |
| Strict separation of admin and customer roles | **Regular recertification of access rights (at least every six months)**, result is documented |
| Service keys used exclusively server-side, never in the frontend | Privileged accounts (owner / admin) are managed separately and reviewed annually |
| Audit logging of all administrative data access |
| Technical measures | Organisational measures |
|---|---|
| Logical tenant segregation through Row Level Security (RLS) at database level | Documented tenant concept |
| Additional tenant isolation at URL/subdomain level: each Controller is assigned its own subdomain (e.g. "customer.commsos.de") | |
| Server-side TenantGuard enforces, on every authenticated request, that the logged-in user is authorised for the subdomain (auth-tenant match) | |
| Fully separate Supabase projects for production, staging and development | Strict prohibition on processing production customer data in test/development environments |
| Customer-specific storage buckets with their own access rules | |
| Strict separation of the bidder/provider portal (separate auth role, its own RLS policies, no access to buyer/tenant data) |
| Technical measures | Organisational measures |
|---|---|
| TLS 1.2+ / HTTPS enforcement for all data transfers (HSTS) | Documented encryption policy |
| Encryption at rest (AES-256 via Supabase / AWS KMS) | Documented data export processes (only for authorised customer admins) |
| Private storage buckets with short-lived signed URLs | Prohibition on sending personal data via unencrypted channels |
| Technical measures | Organisational measures |
|---|---|
| Automatic timestamps (created_at, updated_at, user who made the change) on all tables containing personal data | Documented change and approval processes |
| Audit logs (Supabase + application layer) for administrative actions | Traceability of all data changes through unique user identification |
| Technical measures | Organisational measures |
|---|---|
| Daily automatic backups by the database provider (Supabase managed backups) | Documented backup and disaster-recovery plan |
| **In addition, hourly full database backups** stored independently of the Processor's cloud account; the last 14 states per processing system are retained | Second backup copy independent of the cloud provider — also protects against account loss or accidental deletion on the provider's side |
| **At least annual documented restore tests** to verify recoverability | Defined recovery and response times per processing activity |
| Geo-redundant delivery via the Vercel Edge Network | Escalation paths in the event of an outage (alerting → management → customer) |
| Automatic scaling and health monitoring |
Recovery target values (RTO / RPO):
| Category | RPO (max. tolerable data loss) | RTO (max. tolerable downtime) |
|---|---|---|
| Core production functions (auth, analytics dashboard, data retrieval) | **≤ 24 hours** | **≤ 8 hours** |
| File uploads / reports / documents | ≤ 24 hours | ≤ 24 hours |
| Audit logs and historical reports | ≤ 24 hours | ≤ 72 hours |
Compliance with these values is verified and documented as part of the at-least-annual restore tests.
| Technical measures | Organisational measures |
|---|---|
| Automated security updates and dependency scanning (e.g. Dependabot, Aikido) | Annual review of this TOM catalogue and the effectiveness of the measures |
| Mandatory code review before production deployment | Data protection and information security are integral parts of the development and release process (privacy by design / by default) |
| Quarterly compliance scan (Aikido, Supabase Advisors, Prowler) | Ad hoc reviews following security incidents or changes to sub-processors |
| Measure | Description |
|---|---|
| **Documented incident response plan** | Defined roles (incident lead, communications, forensics), escalation levels and response times |
| **Reporting chain** | Initial analysis within 24 hours of becoming aware; notification to the Controller under sec. 8 of this Agreement within 72 hours |
| Central incident mailbox | privacy@commsos.de (subject line "SECURITY INCIDENT") plus telephone escalation |
| Lessons-learned obligation | After every notifiable incident, causes, measures and improvements are documented and fed back into the TOMs |
| External support | External data protection consultants and IT forensics providers engaged as needed |
| Measure | Description |
|---|---|
| Written data processing agreement with each sub-processor listed in Annex 2 | including SCCs where a third-country transfer is involved |
| Annual review of sub-processors | Evaluation of audit reports (e.g. SOC 2, ISO 27001) or self-assessments |
| Region-pinning verification | At least annual check of the EU region configuration |
Responsible contact (management):
Rainer Roloff (Geschäftsführer)
E-mail: info@comms-connect.de
Phone: +49 89 4522 1556
Operational product contact (instructions, technical and contract-related enquiries regarding the ongoing operation of “Comms OS“):
support@commsos.de
(processed on business days, response generally within two business days)
Data protection enquiries (Art. 13/14, 15–22, 33 GDPR):
privacy@commsos.de
(monitored mailbox, incoming messages processed on business days)
Personal data breach notifications (24/7):
privacy@commsos.de with subject line “SECURITY INCIDENT“, or by phone at +49 89 4522 1556
Responsible contact:
[Name]
E-mail: [Email address]
Phone: [Phone number]
That is not required — acceptance in the portal is sufficient. If your internal policies nevertheless require a signature: open the version, sign it and send it to privacy@commsos.de. We will countersign within two business days.
This text reflects the current state of the processing and is updated whenever sub-processors or TOMs change. If it changes materially, the portal asks for renewed acceptance once — never otherwise. The current list of sub-processors used is available at /subprocessors (German only).
Questions about the DPA or data protection matters: privacy@commsos.de
Governing language
This English text is a convenience translation. The legally binding version is the German one. In the event of any discrepancy or dispute, the German version prevails.