Data Processing Addendum

Effective September 1, 2026
This Data Processing Addendum governs Komment's processing of Customer Personal Data on a customer's behalf and forms part of the Agreement.

1. Application and definitions

This Data Processing Addendum (the “DPA”) forms part of the agreement between Komment AI Inc. (“Komment”) and the customer identified in that agreement (“Customer”) governing Customer's use of the Services (the “Agreement”). It applies when Komment Processes Customer Personal Data as a Processor to provide the Services.

This DPA becomes binding when Customer accepts or otherwise enters into an Agreement that incorporates it. A separately signed copy is not required. A separately signed data processing agreement controls to the extent it conflicts with this DPA.

Capitalized terms not defined here have the meanings in the Agreement. “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processor,” “Sale,” “Share,” and “Supervisory Authority” have the meanings given by applicable Data Protection Law or, if not defined there, the EU GDPR.

“Customer Personal Data” means Personal Data contained in Customer Content that Komment Processes on Customer's behalf. “Data Protection Law” means privacy and data-protection law applicable to that Processing, including the EU GDPR, UK GDPR, and applicable comprehensive US state privacy laws. “EU GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning given in the UK Data Protection Act 2018.

2. Roles and processing details

Customer is a Controller or a Processor acting for another Controller, and Komment is a Processor or Subprocessor, as applicable. Each party will comply with the obligations Data Protection Law assigns to it.

This DPA does not apply to Personal Data for which Komment determines the purposes and means of Processing, including information used for Komment's own account administration, billing, service security, fraud prevention, legal compliance, and direct customer relationship. Komment Processes that information as a Controller under its Privacy Policy.

Subject matter and purpose

Komment Processes Customer Personal Data to provide, secure, maintain, troubleshoot, and support the hosted Services requested and configured by Customer. This includes connecting repositories; creating temporary working copies; analyzing source code and context; routing selected content to configured model providers for inference; generating findings, reports, and Output; administering workspaces and permissions; and providing support.

Duration and nature

Processing occurs continuously or when triggered by Customer's use and instructions for the Agreement term and applicable deletion period. Processing includes collection, receipt, access, organization, storage, retrieval, copying, temporary cloning, analysis, transformation, transmission, inference, generation, display, restriction, return, and deletion.

Data Subjects

Data Subjects may include Customer's users, personnel, contractors, and workspace members; repository owners, maintainers, authors, committers, contributors, and reviewers; and individuals identified in Customer Content or Output.

Personal Data

Customer Personal Data may include names, usernames, email addresses, avatars, identifiers, roles, permissions, repository metadata, commit history, contributor information, source code, configuration, comments, documentation, prompts, dependencies, credentials, secrets, IP addresses, device and session activity, logs, support information, findings, evidence, snippets, source locations, scores, recommendations, reports, and other Output.

3. Customer responsibilities

Customer will comply with Data Protection Law; provide required notices; obtain the rights, permissions, consents, and lawful bases needed for Processing; issue lawful instructions; submit only data reasonably necessary for permitted purposes; appropriately configure access and publication controls; and respond to Data Subjects and regulators as the responsible Controller.

Customer acknowledges that repositories may contain contributor information, credentials, secrets, and other Personal Data not obvious from the repository name.

Unless expressly authorized in an Order, Customer will not intentionally submit protected health information governed by HIPAA, payment-card data subject to PCI DSS other than through Komment's designated payment provider, government identification numbers, precise geolocation, biometric identifiers used for identification, or other regulated sensitive Personal Data unnecessary for the Services. Komment will still protect such information if encountered incidentally in repository content.

4. Instructions and confidentiality

Komment will Process Customer Personal Data only on Customer's documented instructions unless law applicable to Komment requires otherwise. The Agreement, this DPA, Customer's use and configuration of the Services, and authorized support requests constitute documented instructions.

Komment will notify Customer before Processing required by law unless prohibited. If Komment reasonably believes an instruction violates Data Protection Law, it will notify Customer and may suspend the affected Processing until resolved. Additional instructions require Komment's written agreement and may be subject to reasonable fees.

Komment will ensure personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and receive access only as needed for their responsibilities.

5. Security

Komment will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures will account for the state of the art, implementation costs, nature and scope of Processing, and risks to Data Subjects.

Measures for the hosted Services include:

  • unique accounts, authentication controls, and role- and workspace-based authorization;
  • controlled administrative access for support, security, maintenance, abuse prevention, and legal compliance;
  • industry-standard transport encryption for network communications;
  • encryption of stored repository access tokens using a server-side secret;
  • secure production attributes for authentication cookies;
  • application authorization controls separating customer workspaces;
  • removal of temporary repository working copies after an ordinary scan completes or is stopped;
  • logging, monitoring, vulnerability-management, backup, continuity, and incident-response practices proportionate to the Services; and
  • confidentiality duties, need-based personnel access, provider review, and written data-protection terms for Subprocessors.

Komment may update measures as technology and risks change, provided an update does not materially decrease overall protection during the applicable subscription term. Customer remains responsible for protecting its credentials, endpoints, repository permissions, and independent backups.

6. Breaches and assistance

Komment will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include reasonably available information Customer needs for applicable notification obligations. Komment may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the breach. Notice is not an admission of fault or liability.

Taking into account the nature of Processing and information available, Komment will provide reasonable assistance with Data Subject requests, security obligations, breach notifications, data-protection impact assessments, and consultation with Supervisory Authorities.

If Komment receives a Data Subject request relating to Customer Personal Data, it will not independently fulfill it unless required by law or authorized by Customer. Komment may direct the requester to Customer and forward the request when lawful. Customer is responsible for verifying the requester and deciding how to respond.

7. Subprocessors

Customer gives Komment general written authorization to engage Subprocessors. Komment will require each Subprocessor by written agreement to protect Customer Personal Data to a standard no less protective than the obligations applicable to Komment under this DPA, to the extent relevant to its services. Komment remains responsible for its Subprocessors as required by Data Protection Law.

Before submitting Customer Personal Data, Customer may request Komment's current Subprocessor list at privacy@komment.ai. Komment will provide a mechanism to subscribe to notice before a new Subprocessor begins Processing Customer Personal Data.

Customer may object on reasonable data-protection grounds by emailing privacy@komment.ai within 15 days after notice. The parties will seek a commercially reasonable alternative. If none is available, Customer may terminate the affected Services before the new Subprocessor begins Processing and receive a refund of prepaid fees for the unused terminated period. This is Customer's sole remedy for a Subprocessor objection.

8. International transfers

Customer authorizes Komment and its Subprocessors to Process Customer Personal Data in the United States and other countries identified in Komment's current Subprocessor disclosures. Komment will use a legally recognized transfer mechanism when required.

For a restricted transfer governed by the EU GDPR, the European Commission's standard contractual clauses adopted by Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated as follows:

  • Module Two applies when Customer is a Controller and Komment is a Processor;
  • Module Three applies when Customer is a Processor and Komment is a Subprocessor;
  • Clause 7 applies;
  • in Clause 9, Option 2 applies using the notice period in Section 7;
  • the optional language in Clause 11 does not apply;
  • in Clause 17, Option 1 applies and Irish law governs;
  • under Clause 18, the courts of Ireland have jurisdiction; and
  • Section 2 supplies Annex I processing details, Section 5 supplies Annex II security measures, and the list under Section 7 supplies Annex III.

For a restricted transfer governed by the UK GDPR, the EU SCCs as completed above apply with the mandatory clauses of the UK International Data Transfer Addendum issued by the Information Commissioner's Office. For Swiss transfers, references in the EU SCCs to the EU GDPR include the Swiss Federal Act on Data Protection as applicable, references to the EU include Switzerland, and the competent authority is the applicable Swiss authority.

9. Return and deletion

During the term, Customer may access and export Customer Personal Data through available Service functionality. On termination or expiration, Komment will, at Customer's choice and subject to a request made before deletion, return or delete Customer Personal Data unless applicable law requires retention.

Komment may retain Customer Personal Data in backups, archives, security records, or legal holds until deletion through its ordinary lifecycle, provided retained information is isolated from ordinary use and remains protected. Komment may retain information aggregated or deidentified so it can no longer reasonably be linked to Customer or a Data Subject.

On request, Komment will confirm completion after the applicable deletion process concludes. This section does not require deletion of information for which Komment is an independent Controller.

10. Information and audits

Komment will make available information reasonably necessary to demonstrate compliance, including relevant independent audit reports or security documentation if and when available, subject to confidentiality and security restrictions.

If that information is insufficient, Customer may conduct an audit once in any 12-month period, and additionally after a confirmed Personal Data Breach or when required by a Supervisory Authority. Customer must provide at least 30 days' notice, use an independent qualified auditor bound by confidentiality, avoid other customers' information, and prevent unreasonable disruption.

The parties will agree on scope, timing, duration, and security controls. Customer bears its costs and reimburses Komment's reasonable costs unless the audit identifies a material breach by Komment. Komment may satisfy an onsite request with a recent independent report when permitted by law and reasonably sufficient.

11. US state privacy terms

To the extent applicable US state privacy law applies, Komment acts as Customer's processor, service provider, or contractor. Customer discloses Customer Personal Data only for the limited and specified business purposes in Section 2.

Komment will not Sell or Share Customer Personal Data; use or disclose it outside the direct business relationship or for another purpose except as permitted by law; or combine it with Personal Data from another source except as permitted by law. Komment will provide the required level of privacy protection, notify Customer if it can no longer meet an obligation, and allow reasonable steps to ensure compliant Processing and remediate unauthorized use.

Komment certifies that it understands and will comply with these restrictions.

12. Liability, precedence, and contact

Each party's liability arising from this DPA, including the EU SCCs and UK Addendum, is subject to the Agreement's exclusions and limitations to the maximum extent permitted by law. Nothing limits a Data Subject's rights under the EU SCCs or liability that cannot lawfully be limited.

If documents conflict concerning Customer Personal Data, the following order controls: the EU SCCs or UK Addendum where applicable; this DPA; an Order; and the rest of the Agreement.

Komment may update this DPA for changes in law, regulatory guidance, or the Services. Komment will provide reasonable advance notice if an update materially reduces Customer's data-protection rights during a paid subscription term.

Privacy and DPA notices must be sent to:

Komment AI Inc.
251 Little Falls Drive
Wilmington, DE 19808
privacy@komment.ai