Kommit is not "GDPR certified" — there is no such certification. What we do is operate the platform in a way that fits inside your GDPR controller-processor model and gives you the levers GDPR requires you to be able to pull on.
Kommit's role under GDPR
For customer data that flows through your workflows:
- —You are the data controller. You decided what to collect and why.
- —Kommit is a data processor. We process the data on your
instructions, under a Data Processing Addendum (DPA). Our standard
DPA is published at
/dpa.
For data about your Kommit users (teammates who log in to the dashboard), Kommit is the controller for the minimum we need to operate the platform (email, role, sign-in audit) and a processor for everything else you send through it.
What Kommit gives you
- —Data minimisation (Art. 5). A workflow only touches the data you wire into its steps — Kommit doesn't auto-collect from connected systems beyond what a workflow uses.
- —Access and erasure (Art. 15 / 17). You can export and delete the data Kommit holds from the dashboard. See [#data-deletion-and-retention] for what's enforced automatically today and what still requires a manual step — that article is honest about the difference.
- —Human review of automated decisions (Art. 22). If a workflow makes decisions that significantly affect people, put a human approval step on it. That's a core product feature, not an add-on.
- —Records of processing (Art. 30). Every workflow run is logged; the run log export covers processor-side activity.
- —Security (Art. 32). TLS in transit, encryption at rest, role-based access to the dashboard.
- —Breach notification (Art. 33–34). We commit to 72-hour notification in the DPA. We have not had a notifiable breach.
International transfers — read this part
Kommit's application infrastructure is hosted in the EU, but some of
our sub-processors — including the LLM providers that power AI steps
in workflows — process data in the United States under the EU
Standard Contractual Clauses. We do not claim EU-only data
residency today. In-region processing is on the roadmap; until it
ships, plan your transfer assessment on the basis that US
sub-processors are in the path. The current list is published at
/subprocessors, and we notify customers 30 days before adding one.
DPIA support
If you're running a Data Protection Impact Assessment that covers
workflows Kommit runs, contact security@getkommit.ai. We maintain a
DPIA template fragment for the Kommit portion of an assessment. It's
not a substitute for your own DPIA, but it covers the platform-side
answers consistently.