Legal
Data processing agreement
When you use Komma, the employee data in it is yours. You decide what goes in and why; we only act on your instructions. The agreement that puts that in writing is signed as standard — this page explains what is in it and how to get it.
This page is a summary, not the agreement. A data processing agreement is a contract between two named parties and only exists once it is signed. Nothing on this page binds anyone.
The document itself still has to be drafted and reviewed. Ask for it at hej@kommahr.com and we will send whatever is current — before a demo, not after.
01Who is who
You are the data controller. It is your organisation's data about your own employees and applicants, and you decide what is collected and what it is used for.
Komma is the data processor. We store and process it to deliver the service, on your documented instructions and nothing else. We do not use your employee data for our own purposes, we do not sell it, and we do not train anything on it — the same commitment the AI principles make about Karma.
02What the agreement covers
Article 28 requires the agreement to state each of these, and ours does:
- Subject matter and duration — delivering the Komma platform, for as long as the main agreement runs
- Nature and purpose — storing and processing HR data so the modules you have bought can do their work
- Categories of data subject — employees, managers, applicants, and any other users you create
- Categories of data — identity and contact details, employment terms, absence, time, pay components, documents, assessments, learning records [confirm against what the platform actually stores]
- Special categories — health data appears the moment sickness absence is recorded, so it is in scope and has to be named [confirm the list]
- Your obligations and rights — including the right to audit and the instructions we act on
03The security measures behind it
Article 32 asks for appropriate technical and organisational measures. These are the ones the platform is built with — the same ones described on the security page:
- All operation and storage on servers in the EU
- Roles defined down to field level, scoped by department, location or legal entity
- A simulation view, so you can see what a role can reach before you grant it
- Single sign-on through Microsoft Entra ID
- An audit log covering every read, change and export, with a user, a timestamp and a field — and no way to edit it
- Retention deadlines per data type, with deletion or anonymisation happening automatically
[Add the measures a security annex needs and a web page does not describe: encryption at rest and in transit, backup and restore, key handling, staff confidentiality undertakings, penetration testing and business continuity.]
04Sub-processors
We use a small number of sub-processors, each under a written agreement imposing the same obligations we have to you. The full list is an annex to the agreement:
- Hosting: [provider, service, country]
- Backup and monitoring: [provider, country]
- Email and notifications: [provider, country]
- Support tooling: [provider, country]
- AI model provider behind Karma: [provider, where it runs, and whether prompts are retained]
We tell you before adding or replacing one, with time to object. [state the notice period]
05Requests from your employees
Access, correction, deletion and portability requests go to you, because you are the controller. Our job is to help you answer them, and the platform is built so you can: one employee record, a full change history and export in a machine-readable format. If a request reaches us directly we pass it to you rather than answering it.
06If something goes wrong
If we become aware of a personal data breach we notify you without undue delay, with what we know: what happened, which categories and roughly how many people, the likely consequences and what we are doing about it.
Reporting to the supervisory authority within 72 hours is the controller's duty — yours — and our obligation is to get you what you need in time to do it. [state our notification deadline to you in hours]
07Audits
You are entitled to verify that we do what we say. [Set out how: a completed security questionnaire, a third-party report, an on-site audit, notice period, frequency and who pays.]
08When the agreement ends
You get a full export in a machine-readable format, and what remains is deleted — including from backups on their normal cycle. [state the window for the export, the deletion deadline, the backup cycle, and any data law requires us to keep]
09How to get the agreement
Write to hej@kommahr.com. We would rather your DPO or IT team read it before a demo than after a contract, and we are happy to meet them first — there is a route for exactly that on the contact page.
If you have your own paper you would rather use, send it. It is a fair thing to want, and it is easier to work through in week one than in month four.