Last updated: 27 July 2026
Roles and instructions
The customer determines why and how personal data is placed in its workspace and is normally the controller. CompanyMateHQ processes that data only to provide, secure, support, and improve the contracted service, and on the customer's documented instructions.
The customer is responsible for ensuring it has a lawful basis, notices, and permissions for the data it supplies and for configuring agents and integrations appropriately.
Subject matter and categories
Processing covers the provision of a tenant-scoped AI business workspace. It may include user identity and contact information, business and operational information, documents and assets uploaded by the customer, work records, and data supplied through customer-authorised integrations. The duration is the term of the customer's use of the service, plus any agreed deletion or backup period.
Confidentiality and security
Access is limited through email-based, one-time-code authentication, tenant-scoped authorisation, role permissions, and audit records. Integration credentials are kept server-side. CompanyMateHQ is designed so that agents do not make external commitments, payments, filings, publishing actions, or irreversible company changes without explicit owner approval.
No security control removes every risk. Customers should protect their email account, invite only trusted people, connect only appropriate business accounts, and promptly revoke access that is no longer needed.
Subprocessors and transfers
The service may rely on infrastructure, email, authentication, storage, AI, and integration providers to deliver the customer's configured features. A production agreement should list the active subprocessors, their processing locations, and the applicable transfer mechanism before customer data is placed in service.
Assistance, incidents, and audits
CompanyMateHQ will reasonably assist a customer with data-subject requests, security incident information, and compliance questions to the extent required by applicable law and the customer agreement. Any formal audit rights, response times, and incident-notification arrangements should be agreed in the signed data-processing agreement.
Return or deletion
At the end of the service, the customer can request return or deletion of tenant data, subject to legal obligations and standard backup cycles. The exact process and timeframe should be set out in the customer's written agreement.