Documented instructions
Commandix processes customer personal data to provide, secure, maintain, support, and improve the service according to the customer agreement, DPA, and documented customer instructions.
Confidentiality
Personnel and service providers with access to customer data are expected to be bound by confidentiality obligations and access should be limited to business need.
Security measures
Security measures include access controls, tenant-aware data handling, authentication and session controls, HTTPS, CSRF protection, hardened headers, rate limiting, logging, monitoring, and edge protection. Deployment-specific controls should be validated during procurement review.
Subprocessors
Commandix may use subprocessors for hosting, infrastructure, email, identity, bot protection, certificate management, security tooling, and optional integrations. See Subprocessors.
Assistance with requests
Commandix expects to provide reasonable assistance for customer obligations related to data-subject requests, security reviews, privacy assessments, and data protection documentation, taking into account the nature of the processing.
Security incident cooperation
Commandix expects to notify affected customers of confirmed security incidents involving customer data according to the applicable agreement and to provide reasonable information for assessment and remediation.
Return and deletion
At termination, customer data return and deletion are handled according to the signed agreement, DPA, technical feasibility, backup retention, and legal requirements.
Audit and review
Audit support, security questionnaires, control evidence, and vendor review materials should be requested through the enterprise procurement path.