Controller and processor roles
For customer workspace data, the customer typically acts as controller and Commandix acts as processor according to the customer agreement and DPA. For website visitors, demo inquiries, security contacts, and direct communications, Commandix may act as controller for the data needed to respond, secure the site, and operate the business.
A signed customer agreement, order form, or DPA controls where it differs from this public overview.
Review the DPA overview and Subprocessors for processing terms and vendor transparency.
Personal data categories
Commandix may process account identifiers, names, email addresses, company information, roles, team membership, authentication metadata, task ownership, project assignments, goal ownership, comments or descriptions entered by users, sales contacts entered by customers, logs, device data, IP address, cookie consent records, and support or privacy request content.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, role, workspace, authentication status. | Create and secure accounts, manage access, and support users. |
| Execution data | Goals, projects, tasks, owners, teams, constraints, comments, and workflow history. | Provide the Commandix application and operating views. |
| Sales data | Deals, contacts, companies, pipeline stages, tasks, and expected close dates entered by the customer. | Support revenue execution workflows chosen by the customer. |
| Security data | IP address, user agent, auth events, rate-limit events, logs, cookie consent events. | Protect the service, investigate abuse, and maintain audit evidence. |
Lawful basis
For customer workspace data, processing is generally performed on customer instructions under the applicable agreement. For direct business contacts, Commandix may rely on legitimate interests, contract necessity, consent where required, or legal obligations depending on context.
Data subject rights
Individuals may request access, rectification, erasure, restriction, portability, objection, or consent withdrawal. If the request relates to a customer workspace, Commandix may need to route the request to the customer controller unless the agreement permits direct action.
Use the privacy request form or email privacy@commandix.io.
Subprocessors
Commandix publishes subprocessor information for hosting, identity, email, bot protection, certificates, security tooling, and optional integrations. See Subprocessors.
Retention and deletion
Retention depends on the data type, customer agreement, legal obligations, security needs, and operational requirements. Customer data deletion or return at termination is handled under the customer agreement and DPA.
International transfers
Where personal data is transferred internationally, Commandix expects to use contractual, organizational, and technical safeguards appropriate to the processing context and vendor location.
Cookies and consent
The public site stores cookie consent preferences and the app uses essential authentication and CSRF cookies. See the Cookie Policy.