Legal
Data Processing Addendum
Last updated: August 28, 2026
This Data Processing Addendum (“DPA”) is part of the agreement between you (the customer) and Command+K (“we”, “us”) formed by our Terms of Service. It applies whenever we process personal data on your behalf — most importantly, data about your own users who interact with assistants and widgets you run on Command+K. Like the rest of our legal documents, it’s written in plain language on purpose; plain language doesn’t make it less binding.
Roles
For personal data you and your end users put into the service, you are the controller and we are your processor: we process that data only to run the service for you. Where you are yourself a processor for someone else (for example, you embed the widget in a product you operate for your own customers), we act as your sub-processor, and you confirm your controller has authorized us. Separately, for the data we need to run our own business — your account, billing, and consent-gated product analytics — we act as an independent controller, as described in our Privacy Policy; that processing is outside this DPA.
What we process, and for how long
Subject matter and purpose. Providing the CMD+K platform: hosting your workspace, running AI assistants and widgets, connecting knowledge sources and MCP tools, and metering usage.
Categories of data. End-user identity you pass to the widget (such as a user ID, name, or email inside a signed token), conversation content between your users and your assistants, content of the knowledge sources you connect, and technical and usage metadata (timestamps, message counts, credit usage).
Data subjects. Your end users and visitors, your team members who use the workspace, and anyone whose personal data appears in the content you or your users submit.
Duration. For the life of your agreement with us, plus the deletion window described below.
Our commitments as your processor
We process your data only on your documented instructions — your agreement with us, your configuration of the service, and any other lawful written instructions you give us — unless the law requires otherwise, in which case we’ll tell you before processing where legally allowed. Everyone we authorize to access your data is bound by confidentiality obligations. We send conversation context to AI model providers solely to generate responses for you, and we do not use your content to train our own models.
Security
We apply technical and organizational measures appropriate to the risk, including: encryption of data in transit and at rest; secrets and credentials stored in a managed vault rather than in application code; per-tenant isolation of workspace data enforced at the database layer (row-level security); access to production limited to the people who operate the service, on a need-to-know basis; and logging of administrative and security-relevant activity. We review and improve these measures as the product and the threat landscape evolve.
Sub-processors
You give us general authorization to use sub-processors to run the service. We currently use:
- Supabase — database and authentication infrastructure (hosted on AWS, us-east-1).
- Cloudflare — application hosting, CDN, and edge network.
- AI model providers — Anthropic, Google, and OpenAI, to generate assistant responses from the conversation context sent to them.
- Stripe — payment processing and billing.
- Resend — transactional and lifecycle email.
- Mixpanel (EU region) — product analytics, only with consent.
- Tawk.to — live support chat on our site and dashboard.
Each sub-processor is bound by data protection obligations no less protective than this DPA and processes data only as needed to provide its service to us. The current list lives on this page; when we add or replace a sub-processor that processes your data, we’ll update this page and notify you in the product or by email, and you may object on reasonable data protection grounds. If we can’t resolve a reasonable objection, you can terminate the affected service and we’ll refund any prepaid fees for the period after termination.
International transfers
Some of the providers above process data outside the EEA, the UK, and Switzerland — including in the United States. Where personal data protected by GDPR (or equivalent UK/Swiss law) is transferred to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum or Swiss adaptations where applicable), which are incorporated into our agreements with those providers and, where required, deemed entered into between you and us.
Helping you meet your obligations
Taking into account the nature of the processing, we’ll assist you with data subject requests (access, correction, deletion, export, objection): if one of your users contacts us directly, we’ll redirect them to you, and we’ll provide the tools or help you need to respond. We’ll also provide reasonable assistance with your data protection impact assessments and consultations with supervisory authorities, using the information available to us.
Breach notification
If we become aware of a personal data breach affecting your data, we’ll notify you without undue delay, describe what happened and what data is affected as the facts become clear, and keep you updated on our response and remediation. We’ll never make you find out from a news article.
Deletion and return
When your agreement ends — or earlier, if you delete a workspace — we delete your data from production systems within 30 days, except where the law requires us to keep specific records (such as invoices). Before then, you can export your data, and if you need help exporting, ask us.
Audits
We’ll make available the information reasonably necessary to demonstrate compliance with this DPA — documentation of our security measures and relevant attestations from our infrastructure providers. Where that genuinely isn’t enough to satisfy a legal requirement, you may request an audit on reasonable notice, no more than once a year, scoped to avoid disrupting the service or exposing other customers’ data, and at your cost.
Changes and precedence
If we change this DPA in a meaningful way, we’ll update this page and the date above and notify you of material changes before they take effect. If this DPA conflicts with the Terms of Service on a data protection matter, this DPA wins. If you require a countersigned copy of this DPA (including the Standard Contractual Clauses) for your records, email us and we’ll arrange it.
Contact
Questions about this DPA, our sub-processors, or data protection generally: support@commandplusk.com.