Last updated: July 15, 2026
This Data Processing Agreement ("DPA") is entered into between the business using Commora's AI agents to communicate with its customers (the "Client," acting as data controller) and Commora AI LLC ("Commora," acting as data processor/"service provider"). This DPA forms part of, and is incorporated by reference into, the Terms and Conditions that govern the Client's use of Commora's platform (the "Agreement"). By creating a Commora account or otherwise using the Service, the Client agrees to this DPA.
As between Commora and the Client, the Client is the controller of Personal Data submitted to or collected through the Service, and determines the purposes and means of processing that data. Commora is a processor (and, under the CCPA, a "service provider") that processes Personal Data solely on the Client's documented instructions, as set out in the Agreement, this DPA, and the Client's configuration of the Service (for example, the knowledge base, hours, and automations the Client sets up in the Commora dashboard).
Commora will not sell or share Personal Data, and will not process it for any purpose other than providing, securing, and improving the Service, or as required by law.
Subject matter: Commora's provision of AI-agent messaging, booking, and related services to the Client's customers.
Duration: for as long as the Agreement is in effect, plus the retention periods described in Section 9 of this DPA and Section 8 of the Privacy Policy.
Nature and purpose: receiving, storing, and responding to inbound customer messages across the channels the Client has enabled; qualifying leads; scheduling and confirming appointments; sending reminders and follow-ups; and providing the Client with a dashboard to review conversations and usage.
Data subjects: the Client's customers, prospective customers, and other individuals who message the Client's AI agents.
Categories of Personal Data: name, phone number, email address, message content and timestamps, appointment details, and — only where the Client's customer voluntarily provides it in conversation — limited service-preference information (for example, the treatment or appointment type requested). Commora does not intentionally collect government IDs, payment card numbers, or health/medical record data through its agents; where a Client's industry involves sensitive categories of data, the Client is responsible for not routing that data through the Service beyond what is reasonably necessary to deliver the booking.
Commora will:
The Client authorizes Commora to engage the following sub-processors to deliver the Service. Each is bound by contract to protect Personal Data consistent with this DPA and to use it only to provide the relevant function.
| Sub-processor | Function |
|---|---|
| Meta Platforms, Inc. | WhatsApp, Instagram & Messenger message delivery |
| Twilio Inc. | SMS delivery |
| Stripe, Inc. | Billing & payment processing |
| Anthropic, PBC | AI language model that powers agent replies |
| Railway Corp. | Application hosting & database infrastructure |
| Google LLC | Sign-in (OAuth), calendar & review integrations where enabled |
Commora will give the Client reasonable advance notice before adding or replacing a sub-processor with access to Personal Data (for example, by posting an update to this page or notifying the Client by email). If the Client reasonably objects on data-protection grounds, Commora will work with the Client in good faith to address the objection, which may include ceasing to use that sub-processor for the Client's data or, if no resolution is reached, allowing the Client to terminate the affected part of the Service.
Commora maintains a multi-tenant platform in which each Client's data is logically scoped to that Client's workspace at the application layer, and access to the dashboard and conversation data requires authentication. Data in transit is encrypted (HTTPS/TLS). Access to production systems is limited to personnel who need it to operate and support the Service, and Commora's underlying infrastructure runs on Railway, a SOC 2-audited hosting provider.
Commora is a small, growing company and does not yet hold a third-party security certification (such as SOC 2 or ISO 27001) of its own, and database-level row security is on Commora's roadmap but not yet fully implemented; application-layer access controls are in place today. Commora will notify the Client of material changes to its security posture that affect this paragraph upon reasonable request. No method of storage or transmission is 100% secure, and Commora cannot guarantee absolute security.
If Commora becomes aware of a confirmed unauthorized access to, or disclosure of, Personal Data processed on the Client's behalf (a "Breach"), Commora will notify the Client without undue delay, and in any case no later than 5 business days after Commora confirms the Breach, so the Client has time to meet its own legal notification deadlines, including the 10-day deadline under Puerto Rico's Act No. 111-2005. The notice will describe, to the extent then known, the nature of the Breach, the categories and approximate number of data subjects and records affected, and the steps Commora is taking to investigate and contain it. Commora will cooperate with the Client's reasonable requests for information needed for the Client to meet its own notification obligations.
Upon termination of the Agreement, and subject to the retention schedule in Section 8 of the Privacy Policy, Commora will delete or, at the Client's written request made within 30 days of termination, make available for export, the Personal Data processed on the Client's behalf. Conversation and contact data tied to a closed account is deleted within 90 days of account closure, and financial/billing records are retained separately for up to 7 years to meet tax and accounting requirements, consistent with the Privacy Policy. Commora may retain Personal Data beyond these windows where required by law or to establish, exercise, or defend legal claims.
Where a data subject contacts Commora directly to exercise a data protection right (such as access, correction, or deletion), Commora will either direct the individual to the relevant Client or, where legally required, assist the Client in responding, taking into account the nature of the processing. The Client remains responsible for determining how to respond to its customers' requests.
On reasonable prior written notice, and no more than once per calendar year absent a suspected Breach, Commora will provide the Client with a written summary of its relevant technical and organizational measures sufficient to demonstrate compliance with this DPA. Commora will reasonably cooperate with a Client-conducted audit or questionnaire concerning the Service, provided it does not disrupt Commora's operations or expose other clients' data.
Commora and its sub-processors listed in Section 6 primarily store and process data in the United States. Commora does not currently transfer Client Personal Data outside the United States other than as necessary for a sub-processor's own infrastructure (for example, a global platform such as Meta, Google, or Anthropic). If this changes in a way that requires additional safeguards under applicable law, Commora will implement appropriate transfer mechanisms.
Each party will indemnify, defend, and hold harmless the other party from third-party claims, damages, and reasonable costs arising from its own breach of this DPA. Without limiting the foregoing: the Client will indemnify Commora for claims arising from the Client's failure to obtain any consent required to submit Personal Data to the Service, or from the Client's own violation of applicable data protection or telemarketing/messaging law (such as TCPA consent requirements) in how it uses the Service; and Commora will indemnify the Client for claims arising directly from Commora's material breach of this DPA. This Section does not create liability broader than, and is subject to, any limitation of liability set out in the Agreement.
This DPA takes effect when the Client begins using the Service and remains in effect for as long as Commora processes Personal Data on the Client's behalf under the Agreement. This DPA is governed by the same governing law provision as the Terms and Conditions.