Privacy Policy
This Privacy Policy explains how Commenda collects, uses, discloses, retains, and otherwise processes personal data, and describes the rights and choices available to individuals.
Last Updated: August 31, 2026
1. Scope and Our Role
This Privacy Policy applies when you:
- Visit commenda.io or another Commenda website that links to this Privacy Policy (collectively, the “Website”).
- Create or use a Commenda account or interact with the Commenda platform.
- Communicate with us, request information, attend an event, complete a survey, or otherwise interact with us in a business context.
- Receive services from Commenda directly as an individual.
Commenda provides incorporation, entity management, tax, accounting, compliance, and related business services to organisations (“Business Customers”). Depending on the circumstances, Commenda may process personal data as:
- A controller, when we determine why and how personal data is processed, such as for our Website, account administration, security, billing, marketing, and certain direct services; or
- A processor or service provider, when we process personal data on behalf of and under the instructions of a Business Customer.
When Commenda acts as a processor, the relevant Business Customer is responsible for its own privacy notice and for responding to requests concerning that processing. We may refer your request to that Business Customer.
This Privacy Policy does not apply to the privacy practices of third parties that operate independently from Commenda, even if the Website or our services link to or integrate with them. Their privacy notices govern their processing.
2. Who We Are and How to Contact Us
Controller:
Commenda Technologies, Inc. dba Commenda
111 Ellis St, 5th Floor
San Francisco, California 94102
United States
Email: support@commenda.io
Data protection contact: support@commenda.io
European Union Representative
Under Article 27 of the EU General Data Protection Regulation (“EU GDPR”), Commenda has appointed:
Instant EU GDPR Representative Ltd.
Contact person: Adam Brogden
Email: contact@gdprlocal.com
Telephone: +353 1 554 9700
Office 2, 12A Lower Main Street
Lucan, Co. Dublin, K78 X5P8
Ireland
United Kingdom Representative
Under Article 27 of the UK GDPR, Commenda has appointed:
GDPR Local Ltd.
Contact person: Adam Brogden
Email: contact@gdprlocal.com
Telephone: +44 1772 217800
1st Floor Front Suite, 27-29 North Street
Brighton, England
3. Personal Data We Collect
The personal data we collect depends on how you interact with us, the services involved, and applicable legal or contractual requirements. It may include:
- Identity and contact data, such as your name, business contact details, postal address, telephone number, username, profile picture, and signature.
- Account and authentication data, such as account credentials, authentication tokens, permissions, and account settings.
- Business and professional data, such as your employer, title, role, ownership or directorship information, work history, and your relationship to a Business Customer or legal entity.
- Service and compliance data, such as corporate records, incorporation information, tax and government identifiers, filings, registrations, deadlines, beneficial-ownership information, and documents or information needed to provide requested services.
- Connected-account and user content, such as information made available when you connect Google, Microsoft, a calendar, an accounting platform, an ecommerce platform, or another third-party service. Depending on the integration and permissions you choose, this may include names, email addresses, access tokens, calendar events, notes, attachments, tasks, and related metadata.
- Communications and support data, such as correspondence, call or meeting details, support requests, survey responses, and feedback.
- Transaction and billing data, such as billing contact details, invoices, payment status, and transaction records. Payment-card details are generally collected directly by our payment processor rather than stored by Commenda.
- Device, usage, and online-identifier data, such as your IP address, cookie or device identifiers, browser type, operating system, approximate location derived from IP address, referring URLs, pages viewed, actions taken, access times, logs, and diagnostic information. This information may be personal data even when it does not directly identify you by name.
- Marketing and preference data, such as communication preferences, interests, campaign interactions, and cookie choices.
- Information from public or third-party sources, such as public registers, government authorities, Business Customers, service providers, integration partners, and other organisations where permitted by law.
Special-category and criminal-conviction data
We do not intentionally request special-category personal data or criminal-conviction data from general Website visitors. Where such data is necessary for a requested Business Service or required by law, we process only the data reasonably necessary and only where an applicable legal condition permits the processing. Please do not send this type of information unless we request it through an approved channel.
4. How We Obtain Personal Data
We obtain personal data:
- Directly from you, including when you create an account, complete a form, request or receive services, connect an integration, make a payment, contact us, or provide documents or content.
- From Business Customers and other users, including when they authorise us to provide services involving you or submit your information as a representative, owner, director, employee, contractor, or other associated person.
- Automatically, through cookies, pixels, web beacons, logs, and similar technologies when you use the Website or platform.
- From connected services and partners, such as Google, Microsoft, payment providers, accounting or ecommerce platforms, identity-verification providers, and other integrations you or a Business Customer enable.
- From public and official sources, including company registers, tax authorities, government agencies, sanctions lists, and other legally available sources.
5. How We Use Personal Data and Our Lawful Bases
The lawful bases below apply when EU or UK data-protection law requires us to identify a lawful basis and Commenda acts as a controller. When Commenda acts as a processor, the relevant Business Customer determines the purposes and lawful bases for that processing.
Operate the Website and platform
- Personal data: Device, usage, online identifiers, account and authentication data.
- Lawful basis: Legitimate interests in operating and maintaining our services; performance of a contract where necessary.
Create and administer accounts
- Personal data: Identity, contact, account, authentication, and preference data.
- Lawful basis: Performance of a contract; legitimate interests in account administration and customer service.
Provide incorporation, entity management, tax, accounting, compliance, and related services
- Personal data: Identity, contact, business, professional, service, compliance, connected-account, and user-content data.
- Lawful basis: Performance of a contract; compliance with legal obligations; legitimate interests in delivering, documenting, and improving requested services.
Submit filings, registrations, tax information, or other documents to authorities and authorised third parties
- Personal data: Identity, business, professional, service, compliance, and government-identifier data.
- Lawful basis: Performance of a contract; compliance with legal obligations; legitimate interests in completing and documenting requested services.
Enable optional integrations and connected services
- Personal data: Account, authentication, connected-account, and user-content data.
- Lawful basis: Performance of a contract; consent where required; legitimate interests in providing user-requested functionality.
Process payments and manage billing
- Personal data: Identity, contact, transaction, and billing data.
- Lawful basis: Performance of a contract; compliance with tax, accounting, and other legal obligations; legitimate interests in payment administration and fraud prevention.
Respond to enquiries, provide support, and manage our relationship with you
- Personal data: Identity, contact, account, communications, and support data.
- Lawful basis: Performance of a contract; legitimate interests in customer support and relationship management.
Secure our systems, prevent fraud and misuse, troubleshoot, and enforce our terms
- Personal data: Identity, account, authentication, device, usage, online-identifier, transaction, and communications data.
- Lawful basis: Legitimate interests in protecting Commenda, our customers, users, and systems; compliance with legal obligations.
Analyse and improve the Website, platform, and services
- Personal data: Device, usage, online-identifier, preference, support, and feedback data.
- Lawful basis: Consent where required for non-essential technologies; legitimate interests in service measurement and improvement where those interests are not overridden by individual rights.
Send service communications and information about relevant products, services, or events
- Personal data: Identity, contact, account, business, professional, marketing, and preference data.
- Lawful basis: Performance of a contract for service messages; consent where required; legitimate interests in permitted business-to-business marketing.
Comply with law, respond to lawful requests, establish or defend legal claims, and protect rights and safety
- Personal data: Any relevant category.
- Lawful basis: Compliance with legal obligations; legitimate interests in protecting rights, safety, and legal interests.
Evaluate or complete a corporate transaction
- Personal data: Identity, contact, business, professional, account, transaction, and service data.
- Lawful basis: Legitimate interests in evaluating and completing the transaction; compliance with legal obligations.
Where we rely on legitimate interests, we assess whether the processing is necessary and whether our interests are overridden by your rights and freedoms. You may request information about the relevant assessment by contacting us, subject to appropriate protection of confidential and privileged information.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
6. Cookies and Similar Technologies
We and our authorised providers use cookies, pixels, web beacons, local storage, and similar technologies for the following purposes:
- Provide essential Website and platform functions.
- Maintain sessions, preferences, and security.
- Understand usage and performance.
- Improve our services.
- Measure communications and, where applicable, marketing campaigns.
Online identifiers and associated usage information may be personal data. Strictly necessary technologies operate because they are required to provide, secure, or maintain the Website and platform. Where consent is required, functional, analytics, advertising, and other non-essential technologies remain disabled unless and until you choose to enable them.
Our cookie-preference tool allows you to accept all non-essential technologies, reject them, or make choices by category. You can withdraw or change your consent at any time through the “Cookie Settings” control on our Website. Withdrawing consent does not affect the lawfulness of processing performed before withdrawal. Disabling certain technologies may affect optional functionality but will not prevent access to basic Website content.
Our Cookie Policy identifies the technologies we use, including their providers, purposes, categories, and durations.
7. Google, Microsoft, and Other Connected Services
If you choose to connect a Google, Microsoft, calendar, accounting, ecommerce, or other third-party account, we receive and use information according to the permissions presented during authorisation and the functionality you request. You can review or revoke permissions through the relevant provider's account settings or, where available, through Commenda.
Commenda's use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements.
Revoking an integration stops future access but may not automatically delete information already imported or required for legal, security, contractual, or recordkeeping purposes. You may contact us to request deletion where applicable.
8. Artificial Intelligence
Commenda may use AI-enabled tools to support service delivery, research, document review, workflow automation, customer support, security, and product improvement. Where personal data is processed using an AI-enabled tool, we apply the same purpose limitation, access controls, retention rules, security measures, contractual protections, and international-transfer requirements that apply to other processing.
Commenda does not use personal data submitted by or on behalf of Business Customers to train AI models.
We do not use solely automated decision-making that produces legal or similarly significant effects concerning you unless we provide the information and safeguards required by applicable law.
9. How We Disclose Personal Data
We may disclose personal data to the following categories of recipients. The applicable lawful basis depends on why the disclosure occurs and corresponds to the purposes described in Section 5.
- Business Customers and their authorised users: To provide and administer requested services, based on contract, legitimate interests, consent where required, or the Business Customer's documented instructions when Commenda acts as processor.
- Affiliates: To operate, administer, secure, and support our business and services, based on contract, legal obligation, or legitimate interests.
- Hosting and infrastructure providers: To host, operate, maintain, and deliver the Website, platform, and services, based on contract and our legitimate interests in providing secure and reliable services.
- Payment processors: To process payments, prevent fraud, administer billing, and maintain transaction records, based on contract, legal obligation, and legitimate interests.
- Analytics and security providers: To measure and improve service performance, protect accounts and systems, detect misuse, investigate incidents, and maintain security, based on consent where required, legal obligation, and legitimate interests.
- Professional advisers: To obtain legal, accounting, audit, banking, insurance, and other professional services, based on legal obligation and legitimate interests.
- Government and tax authorities: To complete requested filings, registrations, and services; comply with law; respond to valid legal process; and protect rights and safety, based on contract, legal obligation, and legitimate interests.
- Customer-directed integrations: To connect third-party services or disclose information as instructed or authorised by you or the relevant Business Customer, based on contract, consent where required, or documented processor instructions.
- Potential or actual parties to a merger, financing, acquisition, reorganisation, sale of assets, insolvency, or similar transaction: To evaluate, negotiate, or complete the transaction, based on legitimate interests or legal obligation.
- Other parties with your direction or consent: For the purpose disclosed when you direct or authorise the disclosure.
We may disclose aggregated or de-identified information that is not reasonably capable of identifying an individual.
10. International Transfers
Commenda is based in the United States and regularly transfers personal data from the EU, EEA, and UK to the United States and India. For the transfers covered by this Privacy Policy, Commenda does not rely on a decision that the destination provides an adequate level of data protection.
For transfers not covered by an adequacy decision, Commenda uses contractual safeguards required by applicable law, which may include:
- The European Commission's Standard Contractual Clauses.
- The UK International Data Transfer Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement.
- Another lawful transfer mechanism where applicable.
Commenda assesses the circumstances and risks of relevant transfers and implements supplementary technical, contractual, or organisational measures where required. We require recipients to protect personal data in accordance with their contracts and applicable law and to apply appropriate restrictions to onward transfers.
When Commenda acts as a processor, international transfers are also governed by the relevant data processing agreement and the Business Customer's documented instructions.
You may contact us for more information about the safeguards applicable to a transfer and, where available, a copy of the relevant contractual protections, subject to appropriate redactions.
11. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain business and transaction records, comply with legal and contractual obligations, resolve disputes, enforce agreements, and protect security and legal rights.
In determining a retention period, we consider:
- The duration of our relationship with you or the relevant Business Customer.
- The nature, amount, and sensitivity of the data.
- The purposes for which the data was collected and whether those purposes can be achieved by other means.
- Security, fraud-prevention, and incident-investigation needs.
- Applicable limitation periods and legal, tax, accounting, corporate, regulatory, and contractual requirements.
- Whether a legal hold, dispute, audit, or investigation requires preservation.
For example, we generally retain account and service records for the duration of the relationship and an appropriate period afterward; retain tax, corporate, billing, and compliance records for periods required by applicable law or contract; retain marketing data until you opt out or the data is no longer needed; and retain suppression records as necessary to honour opt-out requests. When personal data is no longer required, we delete, anonymise, or securely isolate it, subject to backup and legal-retention requirements.
12. Data Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include encryption, access controls, logging, monitoring, secure development and infrastructure practices, vendor management, incident response, and personnel training, as appropriate to the risk.
No method of transmission or storage is completely secure. You are responsible for keeping your credentials confidential and for promptly notifying us if you suspect unauthorised access to your account.
13. Your Privacy Rights
Depending on your location and the circumstances, you may have the right to:
- Access your personal data and receive information about its processing.
- Rectify inaccurate personal data and complete incomplete data.
- Erase personal data in certain circumstances.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests or a public task. You may object at any time to processing for direct marketing.
- Data portability, allowing you to receive certain data in a structured, commonly used, machine-readable format and, where technically feasible, transmit it to another controller.
- Withdraw consent at any time where processing is based on consent.
- Avoid solely automated decisions that produce legal or similarly significant effects, subject to applicable exceptions and safeguards.
- Lodge a complaint with a data-protection authority.
These rights may be subject to legal conditions, limitations, and exemptions. To exercise a right, email support@commenda.io or contact our EU or UK Representative using the details in Section 2. Please describe your request and your relationship with Commenda. We may need to verify your identity and authority before responding.
If Commenda processes your data solely on behalf of a Business Customer, please direct your request to that Business Customer. We will assist the Business Customer as required by law and contract.
You will not be discriminated against for exercising an applicable privacy right. An authorised agent may submit a request where permitted by law, subject to verification of the agent's authority.
Complaints
We encourage you to contact us first so we can try to resolve your concern. If you remain dissatisfied, you have the right to lodge a complaint with your local data-protection authority:
- UK: Information Commissioner's Office - Make a complaint
- EU/EEA: European Data Protection Board - Our members
You may also complain to the supervisory authority in the EU or EEA country where you live, where you work, or where you believe an infringement occurred.
14. Marketing Choices
You may unsubscribe from marketing emails by using the unsubscribe link in the message or contacting us. We may continue to send non-marketing messages relating to your account, services, security, legal notices, or our ongoing business relationship.
Where consent is required for marketing or non-essential tracking, you may withdraw that consent at any time. You may also object at any time to the use of your personal data for direct marketing.
15. Children
The Website and Commenda's services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data directly from children under 16 through the Website. If you believe a child has provided personal data to us without appropriate authorisation, contact us and we will take appropriate steps, including deletion where required.
Business Customers must not provide children's personal data unless it is necessary for an authorised service and they have satisfied all applicable notice, consent, and other legal requirements. In the EU, the age at which a child may independently consent to an information-society service varies by member state from 13 to 16. Under the UK GDPR, that age is 13. Our general under-16 restriction applies regardless.
16. Changes to This Privacy Policy
We keep this Privacy Policy under regular review to make sure it remains current and accurate. We may update it to reflect changes in our services, processing, legal obligations, or privacy practices. We will post the revised version on this page and update the “Last updated” date. Where required, we will provide additional notice or obtain consent.
17. Contact Us
For questions, concerns, complaints, or requests relating to this Privacy Policy or our privacy practices, contact:
Commenda Technologies, Inc. dba Commenda
111 Ellis St, 5th Floor
San Francisco, California 94102
United States
Email: support@commenda.io
Individuals in the EU or UK may also contact the appropriate representative listed in Section 2.