kombine.work

Data processingarticle 28 terms

Data processing agreement

Last updated: 27 September 2026

Roles

This agreement applies where Kombine processes personal data on behalf of a customer. The customer is the controller. UAB KONTRATEK, company code 308113992, is the processor. It forms part of the terms of service and needs no separate signature, although we will counter-sign a copy on request.

What is processed, and why

Subject matter: providing the Kombine platform. Duration: the term of the subscription, plus the deletion windows below. Nature and purpose: hosting, collecting, organising, storing and presenting security and compliance records so the customer can operate and evidence its controls.

Categories of data subject: the customer's employees and contractors who use the platform or appear in its records, and third parties named in incidents, service requests or supplier records.

Types of personal data: identity and contact details, account and authentication data, role and permission data, device and network identifiers including IP addresses and hostnames, activity and audit records, and any personal data the customer's people write into free text fields or attach as evidence.

Our instructions

We process personal data only on the customer's documented instructions. The configuration of the workspace, including which integrations are enabled and what they collect, is part of those instructions.

If an instruction appears to us to breach data protection law, we will say so rather than carry it out silently. If the law requires us to process data for another reason, we will tell the customer first unless the law forbids it.

Confidentiality

Everyone who can reach customer data is bound by confidentiality obligations that survive their engagement. Access is limited to the people who need it to run and support the service, and it is logged.

Security measures

Encryption of data in transit and at rest, with sensitive values such as integration credentials encrypted individually at the column level.

Strict separation between workspaces, enforced on every query rather than by convention, with automated tests that fail the build if an endpoint forgets it.

Multi factor authentication available for all accounts and mandatory for our own staff. The administration console additionally sits behind a separate identity gate. Origin servers accept traffic only through Cloudflare, and customers may restrict their workspace to named IP ranges.

Full request logging with at least 90 days online and two years in encrypted archives, an in product audit trail of changes, nightly backups across three tracks with tested restores, continuous error monitoring and a daily automated health check of the production system.

Sub-processors

The customer gives general authorisation for the sub-processors listed below. We stay responsible for what they do.

Before adding or replacing one we will give at least 30 days notice by email to workspace administrators. A customer who objects on reasonable data protection grounds within that period may terminate the affected part of the service without penalty.

Helping with data subject requests

The platform lets a customer find, correct, export and delete records itself, which covers most requests without our involvement.

Where it does not, we help. If a request reaches us directly about data in a customer workspace, we do not answer it ourselves. We pass it to the customer without undue delay.

If there is a breach

We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with what we know at the time: what happened, which categories and roughly how many records are involved, the likely consequences and what we are doing about it. We follow up as we learn more.

The purpose is to let the customer meet its own deadlines, including the 72 hour notification under the GDPR and any incident reporting it owes under NIS2.

Impact assessments

We give reasonable help with data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available to us.

Deletion and return

A full export is available in the app throughout the subscription, so return of data does not depend on us.

After termination we keep the workspace for 30 days so an export is still possible, then delete it. Copies in backups expire on their own cycle after that, and we do not restore deleted workspaces from backup.

Audits and information

We make available the information needed to demonstrate compliance with these obligations, including this page, our security documentation and summaries of independent testing.

Where that is not enough, a customer may audit us, or appoint an auditor who is not a competitor, on reasonable notice, during working hours, no more than once a year unless an incident justifies more, and subject to confidentiality.

International transfers

Processing takes place in the European Economic Area. Where a sub-processor processes personal data outside it, transfers rely on the European Commission standard contractual clauses together with any additional measures required.

Sub-processors

Sub-processorWhat it doesWhere
Amazon Web ServicesHosting, storage, database and backups. Inbound email receiving.Stockholm, Sweden. Ireland for inbound email.
CloudflareDNS, content delivery, web application firewall, access control for administrative interfaces, email routing.Global edge network, EU and other regions.
ResendSending and receiving product email, including notifications and ticket intake.European Union and United States.
StripeSubscription billing and payment processing. Card details never reach Kombine.European Union and United States.
SentryApplication error monitoring. Receives diagnostic data about failures, which can include identifiers.European Union and United States.
WorkOSSign-in for accounts on kombine.work. Holds the name and email address of anyone who creates one. The platform itself does not use it and workspace records never reach it.United States.

Current as of the date above. Changes are announced to workspace administrators at least 30 days in advance.

Only if you switch it on

The AI assistant is off by default. A workspace that enables it chooses and configures its own model provider, and we process nothing through a provider the customer has not configured.