Convenience translation. This English text is a convenience translation. The legally binding version is the German one. In the event of any discrepancy or dispute, the German version prevails.
As of: April 2026
The controller responsible for data processing on this platform is:
Comms Connect GmbH
Tal 30, 80331 Munich, Germany
Represented by: Rainer Roloff
"Comms OS" / "CommsOS" is a trademark and product of Comms Connect GmbH.
E-mail: info@comms-connect.de
Phone: +49 89 4522 1556
Data protection enquiries: privacy@commsos.de
The Comms OS platform is operated using the following service providers:
Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. The Vercel Edge Network may process HTTP requests globally. Application data is not stored at Vercel.
Supabase Inc., USA. The Supabase instance for Comms OS runs in the AWS region eu-central-1 (Frankfurt am Main). All application data (database, file storage, authentication) is processed and stored exclusively in the EU.
For security reasons, this platform uses SSL or TLS encryption. You can recognise an encrypted connection by the browser's address bar switching from "http://" to "https://". Data you transmit to us cannot be read by third parties.
A user account is required to use Comms OS. The following data is collected during registration:
Authentication is handled via Supabase Auth. Session data is stored in the browser's localStorage. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
The following data is processed in connection with the use of Comms OS:
Processing takes place exclusively for the purpose of the contractually agreed analysis and optimisation of your telecom/IT procurement. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Comms OS processes customer data as a processor under a Data Processing Agreement pursuant to Art. 28 GDPR. The following sub-processors are used:
Supabase Inc.
Registered office: Singapore | Data region: EU (Frankfurt, AWS eu-central-1) | DPA + EU Standard Contractual Clauses (SCC) | available at supabase.com/legal/dpa
Vercel Inc.
Registered office: USA | Frontend hosting & edge network (EU region Frankfurt), no persistent storage of content data | DPA + SCC | available at vercel.com/legal/dpa
Resend, Inc.
Registered office: USA | Transactional e-mail delivery (login codes, system notifications, signature invitations and one-time codes) | EU sending region | DPA + SCC | available at resend.com/legal/dpa
A Data Processing Agreement (DPA) can be provided on request; see also commsos.de/en/avv.
Your data is stored for the duration of the business relationship. After the cooperation ends, data is deleted unless statutory retention obligations apply (6 years under the German Commercial Code (HGB), 10 years under the German Fiscal Code (AO) for documents relevant under commercial and tax law).
You have the following rights vis-à-vis us regarding your personal data:
To exercise your rights, please contact privacy@commsos.de.
You also have the right to lodge a complaint with the competent supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
Comms OS uses exclusively technically necessary session cookies required to operate the platform. No tracking cookies, analytics cookies or third-party cookies are used.
A cookie banner is therefore not required, as no cookies requiring consent are used.
Governing language
This English text is a convenience translation. The legally binding version is the German one. In the event of any discrepancy or dispute, the German version prevails.
If you receive a document for signature via CommsOS Sign, the company that sent you the document is the controller responsible for processing your personal data. The sender is identified in the document and the email. Comms Connect GmbH operates CommsOS and processes the data as a processor under Article 28 GDPR.
The data processed includes your name, email address, stated role, confirmation of your authority to represent the company, signature image, completed fields and attachments. It also includes the times of the invitation, opening, code confirmation and signature, your IP address, the approximate location derived from it, browser and operating system details, and reading duration.
The processing provides evidence of who signed what and when, protects against misuse and enables digital sealing. The evidence is recorded in an audit trail within the PDF. Only a hash value of the completed PDF is transmitted to the timestamping service ssl.com. The controller's legal basis is generally Article 6(1)(b) or (f) GDPR.
After code confirmation, a strictly necessary session cookie is set. It is valid for 30 minutes, and its validity is extended when you are active. No tracking takes place. Invitation, code, reminder and completion emails are sent via Resend, as described in section 6. The data is stored with Supabase in Frankfurt, within the EU.
The controller retains the signed document and its audit trail in accordance with its retention obligations. Please exercise your data protection rights, such as access or erasure, by contacting the sender. Requests sent to support@commsos.de will be forwarded to the sender.
For technical error diagnosis and stability monitoring of our portal we use Sentry (Functional Software, Inc., USA). In the event of an error, technical crash and performance data (e.g. error message, affected code location, browser/device type, version) are processed. Processing takes place in a data center in the European Union (ingest.de.sentry.io); default transmission of personal data is disabled (sendDefaultPii: false) and no session replay is performed. The legal basis is our legitimate interest in stable, error-free operation (Art. 6(1)(f) GDPR). A data processing agreement is in place with the provider; EU Standard Contractual Clauses (SCC) apply to transfers to the USA. More information: sentry.io/privacy.