Skip to content

How Kommit supports your GDPR posture

Published May 23, 2026

Kommit is not "GDPR certified" — there is no such certification. What we do is operate the platform in a way that fits inside your GDPR controller-processor model and gives you the levers GDPR requires you to be able to pull on.

Kommit's role under GDPR

For customer data that flows through your workflows:

  • You are the data controller. You decided what to collect and why.
  • Kommit is a data processor. We process the data on your instructions, under a Data Processing Addendum (DPA). Our standard DPA is published at /dpa.

For data about your Kommit users (teammates who log in to the dashboard), Kommit is the controller for the minimum we need to operate the platform (email, role, sign-in audit) and a processor for everything else you send through it.

What Kommit gives you

  • Data minimisation (Art. 5). A workflow only touches the data you wire into its steps — Kommit doesn't auto-collect from connected systems beyond what a workflow uses.
  • Access and erasure (Art. 15 / 17). You can export and delete the data Kommit holds from the dashboard. See [#data-deletion-and-retention] for what's enforced automatically today and what still requires a manual step — that article is honest about the difference.
  • Human review of automated decisions (Art. 22). If a workflow makes decisions that significantly affect people, put a human approval step on it. That's a core product feature, not an add-on.
  • Records of processing (Art. 30). Every workflow run is logged; the run log export covers processor-side activity.
  • Security (Art. 32). TLS in transit, encryption at rest, role-based access to the dashboard.
  • Breach notification (Art. 33–34). We commit to 72-hour notification in the DPA. We have not had a notifiable breach.

International transfers — read this part

Kommit's application infrastructure is hosted in the EU, but some of our sub-processors — including the LLM providers that power AI steps in workflows — process data in the United States under the EU Standard Contractual Clauses. We do not claim EU-only data residency today. In-region processing is on the roadmap; until it ships, plan your transfer assessment on the basis that US sub-processors are in the path. The current list is published at /subprocessors, and we notify customers 30 days before adding one.

DPIA support

If you're running a Data Protection Impact Assessment that covers workflows Kommit runs, contact security@getkommit.ai. We maintain a DPIA template fragment for the Kommit portion of an assessment. It's not a substitute for your own DPIA, but it covers the platform-side answers consistently.

How Kommit supports your GDPR posture — Kommit Helpdesk