Legal
Privacy Policy
This interim policy explains how Cominent handles personal information while the service is in private pilot.
Effective August 9, 2026 · Last updated August 9, 2026 · Version 0.2 (interim)
01
Information we process
- Account and organization information supplied by users or administrators.
- Business content submitted to a workspace, including documents, messages, tasks, agreements, and related metadata.
- Integration data that an authorized organization chooses to connect.
- Security, device, diagnostic, and usage information needed to operate and protect the service.
02
How information reaches Cominent
Information may be provided directly by you, supplied by your organization or another authorized workspace participant, generated through your use of the service, or retrieved from a third-party platform that an authorized administrator connects. If you provide information about another person, you are responsible for having an appropriate basis to do so.
03
Our privacy role
For customer workspace content, the subscribing organization generally determines why and how information is processed and acts as controller or business; Cominent generally processes that content as its processor or service provider. Cominent may act as controller for account administration, billing, security, fraud prevention, service communications, and compliance records. The exact allocation of responsibilities must be confirmed in an executed customer agreement or data processing addendum.
04
Categories and sources
- Identifiers and professional information, such as name, work email, employer, role, and account identifiers.
- Commercial and relationship records, including counterparties, agreements, commitments, invoices, projects, approvals, and correspondence.
- Internet, device, and security activity, including IP address, user agent, timestamps, session events, request identifiers, and integration health.
- Inference and AI output derived from authorized business content, including summaries, proposed risks, dates, classifications, and action candidates.
- Content obtained from administrators, workspace participants, counterparties, connected providers, and the user’s interaction with Cominent.
05
How we use information
- Provide, secure, maintain, and improve Cominent.
- Authenticate users, enforce permissions, and maintain audit records.
- Process organization content to provide requested automation and AI-assisted features.
- Communicate about service, security, support, and policy changes.
06
Legal bases and organizational instructions
Depending on location and context, processing may be based on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required. For customer-controlled workspace content, Cominent generally acts on the instructions of the organization that controls the workspace.
07
AI processing
AI features may process authorized workspace content to produce summaries, suggestions, classifications, and operational records. AI output may be incomplete or incorrect and must be reviewed by an authorized person before material action is taken. Cominent does not intentionally use one customer’s private workspace content to benefit another customer.
08
Connected services
When an organization connects services such as email, calendars, collaboration tools, document storage, task systems, or electronic-signature platforms, Cominent processes only the data authorized through that connection and subject to available provider permissions. Removing a connection stops future collection but may not automatically delete records already imported into a workspace.
09
Sharing and service providers
Information may be shared with infrastructure, security, communications, and AI service providers only as needed to operate the service, subject to appropriate contractual and technical controls. We may also disclose information when legally required or to protect rights, safety, and service integrity.
10
Subprocessor categories
A provider should receive only the information necessary for its function. A production subprocessor register, processing locations, and change-notification process must be completed before general availability.
- Cloud hosting, managed databases, object storage, content delivery, and network protection.
- Authentication, email delivery, customer support, error monitoring, logging, and incident response.
- Payment processing and subscription administration.
- AI model and processing providers selected for enabled features.
- Customer-authorized services such as Microsoft, Google, Slack, GitHub, Notion, Atlassian, Linear, DocuSign, and Adobe.
11
Sale, sharing, and advertising
Cominent does not intend to sell personal information or use private workspace content for cross-context behavioural advertising. If future practices create a legal “sale” or “sharing” obligation, this policy and required opt-out mechanisms must be updated before that processing begins.
12
International processing
Cominent and its service providers may process information in countries other than the country where it was collected. Where required, appropriate contractual or other safeguards should be used for international transfers. Enterprise data-location commitments must be stated in an executed customer agreement.
13
Retention and deletion
We retain information for as long as needed to provide and secure the service, follow organization instructions, meet legal obligations, resolve disputes, and enforce agreements. Retention may vary by record type, workspace settings, backup cycle, legal hold, and connected provider. Deleted information may remain temporarily in protected backups before routine expiration.
14
Your privacy rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of personal information. Requests may need to be directed to the organization controlling the workspace. We may verify identity and retain information when legally permitted or required.
15
Canadian and international privacy requests
Cominent intends to apply accountability, purpose limitation, consent or other lawful authority, access, accuracy, safeguards, openness, and retention principles appropriate to applicable Canadian privacy law. Individuals in the EEA, United Kingdom, California, and other jurisdictions may have additional rights. This statement does not concede that every law applies to every processing activity. Requests will be assessed under the law and contractual role that actually applies.
16
Automated decision-making
Cominent is designed to present AI output as assistance and proposed business information, not as an autonomous final decision. Organizations must require human review for legally or similarly significant decisions. Contact the workspace controller if you believe an automated process materially affected you.
17
Security and breach response
We use administrative, technical, and organizational safeguards designed to protect information. No system can guarantee absolute security. If we confirm a security incident affecting protected customer information, notification and cooperation obligations will follow applicable law and any executed customer agreement.
18
Children and sensitive information
Cominent is a business service and is not directed to children. Users should not submit regulated, highly sensitive, or special-category information unless their organization has approved that use and appropriate legal, contractual, and security controls are in place.
19
Policy changes and contact
We may update this policy as the pilot and service evolve. Material changes will be communicated through the service or an appropriate organizational contact. Questions and requests should be sent through your designated Cominent pilot or privacy contact until a formal privacy address is published.
