Data Processing Agreement (DPA)
Last updated: July 13, 2026
Preamble
This Data Processing Agreement (the "DPA") is an integral attachment to the Terms of Service of CommentTap and is concluded between the Controller — a User of the Service who processes personal data of Contacts/Leads through the Service — and the Processor: Michał Kołnierzak conducting business under the name "KOLM MICHAŁ KOŁNIERZAK", ul. Milenijna 43/2, 03-130 Warsaw, Poland, NIP 5361929091, REGON 367735680 (the "Processor", "Operator").
The DPA is concluded upon acceptance of the Terms and starting to use the Service in a way that leads to processing of Contacts' personal data. It implements the requirements of Art. 28 GDPR.
1. Subject matter and scope
- The Controller entrusts the Processor with processing personal data to the extent and for the purpose necessary to provide the Services under the Terms.
- The Processor processes data only on the Controller's documented instructions (which include the use of the Service's features and the Terms), unless required otherwise by EU or Member State law.
2. Nature, purpose, duration, data and categories of persons
- Purpose: providing SaaS features for running social-media communication campaigns (replies to comments, DMs, keyword triggers, lead collection and management, analytics).
- Nature: operations on data in the IT systems of the Processor and its subprocessors (storage, recording, organising, transmission to Platforms, erasure).
- Duration: for the term of the agreement for the Services (the Terms), subject to section 7.
- Types of data: platform identifiers (provider user id, username, display name), email address, content of comments, story replies and messages, tags, notes, custom fields (lead fields), lead status, opt-out status and text, interaction timestamps, delivery and link-click history. The Service does not require or provide for entering special categories of data (Art. 9 GDPR).
- Categories of persons: the Controller's Contacts/Leads interacting with their Platform profiles.
3. Obligations of the Processor
- process data only on the Controller's documented instructions;
- ensure that persons authorised to process data have committed to confidentiality or are under a statutory duty of confidentiality;
- apply technical and organisational measures ensuring security appropriate to the risk (Art. 32 GDPR) — see section 4;
- respect the conditions for engaging subprocessors (section 5);
- assist the Controller, by appropriate measures, in responding to data subjects' requests (Chapter III GDPR);
- assist the Controller in complying with Art. 32–36 GDPR (security, breach notification, impact assessments, prior consultation);
- at the end of the Services, delete or return the data per section 7;
- make available information necessary to demonstrate compliance with Art. 28 GDPR and allow audits (section 6);
- promptly inform the Controller if, in its opinion, an instruction infringes GDPR or other data protection law.
4. Security measures (Art. 32 GDPR)
The Processor applies in particular: encryption in transit (TLS), role-based access control on a need-to-know basis, authentication, password hashing, backups, event logging, environment separation, and processing with providers offering an adequate level of security.
5. Subprocessors
The Controller grants the Processor general authorisation to engage subprocessors to provide the Services. The current subprocessors include:
- Supabase — database, authentication, file storage — EU/EEA, Frankfurt (Germany).
- Railway — application and API hosting — EU/EEA, EU West, Amsterdam (Netherlands).
- Stripe — payments (billing data, not campaign content) — EU + USA (SCC/DPF).
- Brevo — transactional/notification emails — EU/EEA.
- Meta Platforms — Instagram/Facebook API integration — EU + USA (SCC/DPF).
- Sentry — error and performance monitoring (diagnostics) — EU + USA (SCC/DPF).
The Processor imposes on subprocessors data-protection obligations equivalent to this DPA. It will inform the Controller of intended additions or changes of subprocessors, allowing a reasoned objection within 14 days.
6. Audit
The Processor makes available information necessary to demonstrate compliance with Art. 28 GDPR. The Controller may carry out an audit (including inspection) after agreeing a date and scope in advance, in a way that does not disrupt the Processor's operations, no more than once a year (and ad hoc after a confirmed data breach), preserving confidentiality. The Processor may first provide reports/certificates (e.g. of infrastructure providers).
7. End of processing and data deletion
At the end of the Services the Processor, at the Controller's choice, deletes or returns the personal data and deletes existing copies, unless EU or Member State law requires storage. By default data is deleted within 30 days after the agreement ends, following the export window.
8. Personal data breaches
The Processor notifies the Controller of any personal data breach without undue delay after becoming aware of it, providing information enabling the Controller to fulfil its obligations under Art. 33–34 GDPR. Contact: security@commenttap.com, privacy@commenttap.com.
9. Transfers outside the EEA
Any transfer of data outside the EEA takes place only with safeguards compliant with Chapter V GDPR (in particular Standard Contractual Clauses — SCC, and/or the DPF), as described in section 8 of the Privacy Policy.
10. Liability and final provisions
- Liability of the parties is governed by GDPR and the Terms.
- Matters not covered are governed by GDPR and Polish law.
- In case of conflict between this DPA and the Terms on data-protection matters, this DPA prevails.