What this page is
This page describes how Komunidad Global Pte. Ltd. handles the data you put into the platform, including the data belonging to your clients. It is the plain-English companion to our data processing agreement.
A signed data processing agreement is available on request from info@komunidad.co. Where the signed agreement and this page differ, the signed agreement is the one that counts.
Who is responsible for what
- You are the controller. You decide what goes into the application, why, and who may see it. If you are building for a client, they may be the controller and you their processor; that is between you and them.
- We are the processor. We hold and process that data on your instructions, to provide the service, and for nothing else.
- Our suppliers are sub-processors. They work under the same restrictions, by written contract, and are listed below.
The two commitments that matter most
We do not train AI on your data
Your data, your clients' data, your documents, your configurations and your prompts are never used to train, fine-tune or improve any AI model. Not the models in our AI Core, not a supplier's, not a general-purpose model.
The AI Core is the shared engine that runs the agents. It is shared in the same sense that the database engine is shared: it serves every tenant, and it learns from none of them. It carries no memory of your data between requests and no weights derived from it.
- AI features run against your data only to produce the answer you asked for, in your own workspace
- Where a request is served by a third-party model provider, it is sent under contractual terms that prohibit training on it and require it to be discarded after the response, with zero retention where the provider offers it
- Nothing from your workspace is used to produce output in anyone else's
- Human review of your content happens only with your explicit permission, or where you have raised a support ticket and asked us to look
If we ever want to use customer data to improve a model, we will ask first, per customer, and it will be off unless you switch it on.
Your data is not shared with other tenants
Every organisation on the platform has its own tenant. A tenant is a boundary, not a label:
- Records carry their tenant, and every query is scoped to it at the data layer, so a request cannot reach across even if the application asks it to
- Files, evidence and exports are stored under tenant-scoped paths with tenant-scoped access
- Credentials, keys and integration secrets belong to one tenant and are not reused
- AI context is assembled only from the tenant making the request
- Tenant isolation is part of the release checks, and a change to that layer gets extra review
Where you build applications for several clients, each client's application is its own tenant for the same reason.
What we process
- Account and user records: names, work emails, roles, permissions
- Whatever you put into an application: measurements, evidence, documents, locations, assessments, reports
- Operational data: logs, usage and credit records
- Support correspondence
We process it for as long as you hold the account, to provide the service, keep it secure, and meet a legal obligation.
How we protect it
The platform runs entirely on Amazon Web Services in the Asia Pacific (Singapore) region. We operate no servers of our own, and no office equipment sits in the path of customer data.
- In transit: TLS 1.2 or better everywhere, on the public edge and between internal services. HSTS is on and plain HTTP redirects
- At rest: AES-256 on databases, object storage, backups and snapshots, with keys held in AWS KMS
- Network: compute runs inside a private VPC. Databases and storage sit in private subnets with no route in from the internet, and public traffic reaches only the load balancer
- Access: least privilege, with multi-factor authentication required on every administrative account, and access to customer data logged
- Separation: production, staging and development are separate environments, and production data is never copied into the others
- Secrets: integration credentials live in a managed secret store, never in source control or configuration files. Passwords are stored only as salted hashes using a current algorithm
- Testing: changes are reviewed before release, dependencies are scanned, and the tenant isolation layer gets extra review
If you are running a vendor review and need more detail, or your own questionnaire filled in, write to info@komunidad.co.
Sub-processors
- Amazon Web Services. Hosting and storage. Asia Pacific (Singapore)
- Payment processing. Billing, card details and invoices
- Transactional email. Sign-in links, alerts and notifications
- AI inference. Serving the agents, under a no-training, zero-retention agreement
- Support ticketing. Your support conversations with us
We name each provider, and the country it processes in, in our current sub-processor list. We keep that list current rather than printing it here, because a page that has gone stale is worse than no page. Ask for it at info@komunidad.co and we will send it the same day.
We will give at least 30 days notice before adding or replacing a sub-processor. To be told when that happens, ask info@komunidad.co to put you on the notification list. You may object on reasonable data protection grounds, and if we cannot resolve it you may terminate the affected service.
International transfers
The platform runs on Amazon Web Services in the Asia Pacific (Singapore) region. We contract from Singapore and serve customers worldwide, and our teams work from Singapore and the Philippines.
Where data crosses a border we rely on the standard contractual clauses, with the UK addendum where it applies, and on the transfer obligations in Singapore's Personal Data Protection Act and the Philippine Data Privacy Act, plus the technical measures described above. We can provide the executed clauses on request.
If your own rules require the data to stay in a particular region, tell us before you build. Regional hosting is arranged case by case and is not the default.
Helping you meet your obligations
- Requests from individuals. The platform lets you find, export, correct and delete records yourself. Where you need help we will assist within 10 business days
- If someone contacts us directly about data inside your application, we will not act on it. We will forward it to you without undue delay
- Impact assessments. We will give you the information you reasonably need for a DPIA or a vendor review
If something goes wrong
If we become aware of a breach affecting your data we will tell you without undue delay and in any case within 72 hours of confirming it. The notice will say what we know, what is affected, what we are doing, and what we suggest you do. We will keep you updated as the picture changes, and we will not wait for a complete investigation before telling you.
Getting your data back, and deletion
- You can export your data at any time while the account is open, in open formats, including evidence files and the audit log
- After termination you have 30 days to export
- After that we delete customer data from live systems within 30 days, and from backups within 90 days as backups age out
- Where the law requires us to keep something, such as an invoice, we keep only that and only for as long as required
- We will confirm deletion in writing on request
Audits
You may audit our compliance once a year, or after a breach affecting you, on 30 days notice and under confidentiality. Where a current independent audit report, certification or completed security questionnaire answers the question, we will provide that instead.
Contact
Write to info@komunidad.co for anything on this page: a question, a request about your own information, a copy of the signed data processing agreement, or a security questionnaire you need filled in. It reaches the right team in both entities.
- Komunidad Global Pte. Ltd., Singapore. 1 Phillip Street, #05-01 Royal One Phillip, Singapore
- Komunidad Global Services & Operations, Philippines Inc., Philippines. G/F Uptown Eastgate Bldg., 11th Avenue, Bonifacio Global City, Taguig City, Philippines
The named contact details of our official representatives, including our data protection officer and our representatives in Singapore and the Philippines where one is required, are available on request.

