Effective March 15, 2026 (last updated August 4, 2026)
1. Information We Collect
a. Information You Provide
We may collect personal information that you voluntarily provide when you:
- Register for an account.
- Use our Services.
- Contact our support team.
Examples of such information include:
- Name and contact details (e.g., email address, phone number).
- Billing and payment information.
- Data uploaded to the Services (“User Data”).
b. Automatically Collected Information
When you use our Services, we may collect information automatically, such as:
- Device information (e.g., IP address, browser type).
- Usage data (e.g., pages visited, time spent on the Services).
- Cookies and similar technologies (see Section 7).
c. Third-Party Information
We may receive information about you from third-party services if you link or integrate those services with our platform.
d. Messages Archived on Managed Devices
Where an organization deploys our enterprise messaging-archival application to its corporate-managed Android devices, we collect, on that organization’s behalf, the SMS, MMS, and RCS messages stored on those devices - including message content, attachments, participants, and timestamps. This collection is described in Section 5 (Compliance Archiving of Messages on Managed Devices).
2. How We Use Your Information
Except for archived messages described in Section 5, which are used only as described in Section 5(c), we use the information we collect for the following purposes:
- To provide, maintain, and improve our Services.
- To authenticate your account and ensure secure access.
- To communicate with you, including sending updates, notifications, and support messages.
- To process payments and manage subscriptions.
- To comply with legal and regulatory obligations.
- To analyze usage trends and enhance user experience.
3. Sharing and Disclosure of Information
We do not sell your personal information. However, we may share your information in the following circumstances:
a. With Service Providers
We may share information with third-party vendors who assist us in operating the Services, such as payment processors, cloud hosting providers, and customer support tools.
b. As Required by Law
We may disclose your information to comply with legal obligations, such as responding to subpoenas, court orders, or government requests.
c. In Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.
d. With Your Consent
We may share your information for other purposes if you provide explicit consent.
e. Mobile Phone Numbers and SMS Consent
No mobile information, including mobile phone numbers and text messaging opt-in or consent data, will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors that support delivery of the Services - such as messaging providers and aggregators (e.g., Twilio) and customer support tools, solely as needed to deliver the SMS and other Services you have requested - is permitted. All other categories of information sharing described in this Policy exclude text messaging originator opt-in data and consent, which will not be shared with any third parties.
4. SMS and Text Message Communications
If you provide your mobile phone number and opt in to receive text messages from us, the following terms apply:
- Purpose. We use SMS solely to deliver the Services you have requested, including account verification, security alerts, transactional notifications, and customer support replies. We do not send marketing or promotional SMS.
- Message Frequency. Message frequency is minimal and varies based on your use of the Services. We only send messages as required to deliver the Services.
- Message and Data Rates. Message and data rates may apply. Check with your mobile carrier for details about your plan.
- Opt-Out. You can opt out of SMS at any time by replying STOP to any message you receive from us. After you opt out, you will receive a single confirmation message and we will not send you further SMS unless you opt in again.
- Help. For help, reply HELP to any message or contact us at support@commacompliance.com.
- Carriers. Mobile carriers are not liable for delayed or undelivered messages.
5. Compliance Archiving of Messages on Managed Devices
Comma Compliance provides an enterprise messaging-archival application (the “Comma Compliance Messages Archiver” for Android) that organizations deploy to their corporate-managed (fully-managed, device-owner) Android devices to meet regulatory, legal-hold, and internal-policy obligations to retain employees’ business communications. This Section describes how that application collects and handles message data. It applies only to devices an organization has enrolled and configured for archiving; it does not apply to personal devices or to visitors to our websites.
a. Enterprise-Administered
The application operates only after an organization’s administrator has enabled message archiving for the organization and the device has been connected to that organization - either through administrator-delivered managed configuration or through the employee’s own authenticated sign-in to the organization. The organization that deploys the application controls the resulting archive; Comma Compliance processes the data on that organization’s behalf as its service provider.
b. What We Collect
On a managed device, the application reads and archives the SMS, MMS, and RCS messages that the device’s default messaging app has received and stored, including:
- Message content - text bodies and attachment files (such as images, video, voice messages, and contact cards).
- Participants - sender and recipient phone numbers and, where available, associated contact names.
- Metadata - timestamps, read receipts, reactions, edits, and delivery status.
The application reads only messages the device’s default messaging app has already received and stored. It does not intercept, weaken, or bypass any messaging app’s transport encryption, and it does not capture messages from third-party messengers (such as WhatsApp, Signal, or Telegram), which do not flow through the device’s standard messaging storage.
c. How We Use It
Archived messages are transmitted only to the organization’s designated compliance archive and are used solely to provide the archival Service the organization has requested. This data is not used for advertising, is never sold, and is not shared with anyone other than the organization that administers the archive and the subprocessors that operate the Service on our behalf (for example, cloud hosting).
d. Transparency and Consent
Archiving is never covert. While archiving is active, the device displays a persistent, non-dismissible notification stating that messages are being archived for compliance and naming the organization. Before any message access is requested, the application shows a plain-language screen explaining what is captured, that the organization administers the archive, and that messages are encrypted on the device before they are sent. Each organization is responsible for providing any notice to, and obtaining any required consent or other authorization from, the individuals whose messages are archived, as required by the laws that apply to it.
e. Security
Messages and attachments are encrypted on the device before transmission and are sent only to the Comma Compliance archive configured for the organization, over an encrypted connection. Each device generates its own cryptographic keypairs on the device; the private keys remain on the device and never leave it, and the on-device queue of pending data is encrypted at rest.
f. Retention and Deletion
Archived messages are retained by the organization in accordance with its own retention and legal-hold policies; the organization controls retention and deletion of its archive. An administrator can revoke a device at any time, which stops further archiving from that device. Requests to access or delete archived messages should be directed to the organization that administers the archive, and Comma Compliance will assist that organization in fulfilling those requests as its service provider.
6. Data Retention
Except for archived messages, which are retained as described in Section 5(f), we retain your information for as long as necessary to provide the Services or as required by applicable laws. User Data will be deleted following account termination, subject to any legal retention obligations.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience. These technologies help us:
- Remember your preferences.
- Analyze usage trends.
- Provide a secure and personalized experience.
You can manage cookie preferences through your browser settings. However, disabling cookies may affect the functionality of our Services.
8. Security
We implement reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, loss, or misuse. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information.
- Restriction: Request restriction of processing your information.
- Portability: Request transfer of your information to another service.
- Objection: Object to processing based on legitimate interests.
To exercise your rights for information Comma Compliance controls, contact us at support@commacompliance.com. For archived messages that an organization administers, see Section 5(f).
10. International Data Transfers
a. Data Privacy Framework Participation
Comma Compliance, the trade name of Tres Comma Compliance, Inc., complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Comma Compliance has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Comma Compliance has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between the terms in this Privacy Policy and the Data Privacy Framework Principles, the Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
b. What Our Certification Covers
Our certification covers personal data we receive from the European Economic Area, the United Kingdom, and Switzerland in two distinct roles:
- As a controller, for the account, billing, support, and website information described in Sections 1(a), 1(b), and 1(c).
- As a processor acting on a customer’s behalf, for the archived messages described in Section 5 and for other User Data our customers upload to the Services.
Where we act as a processor, the organization that deploys the Services determines the purposes and means of processing. That organization remains responsible for establishing the lawful basis for the transfer and for providing notice to, and obtaining any required consent from, the individuals whose data it archives. We process that data only on the organization’s documented instructions.
c. Onward Transfers
We share personal data with third-party service providers only to deliver the Services, as described in Section 3(a). Where we transfer personal data received under the Data Privacy Framework to a third party acting as our agent, we require that agent to provide at least the same level of protection required by the DPF Principles.
Comma Compliance remains responsible and liable under the DPF Principles if a third-party agent that we engage to process such personal data on our behalf does so in a manner inconsistent with the Principles, unless we prove that we are not responsible for the event giving rise to the damage.
A current list of our subprocessors is available on request.
d. Access, Correction, and Choice
Individuals in the EEA, the United Kingdom, and Switzerland may request access to the personal data we hold about them, and may request that we correct, amend, or delete it where it is inaccurate or has been processed in violation of the DPF Principles. You may also limit the use and disclosure of your personal data. To make such a request, contact us at privacy@commacompliance.com.
For archived messages and other data we process on a customer’s behalf, direct your request to the organization that administers the archive. We will assist that organization in responding, as described in Section 5(f).
e. Dispute Resolution
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Comma Compliance commits to resolve DPF Principles-related complaints about our collection and use of your personal information. Individuals in the European Union, the United Kingdom, and Switzerland with inquiries or complaints regarding our handling of personal data received in reliance on the Data Privacy Framework should first contact us at privacy@commacompliance.com. We will respond within 45 days of receiving your complaint.
Comma Compliance has further committed to refer unresolved Data Privacy Framework complaints to JAMS, an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.
f. Regulatory Oversight
The Federal Trade Commission has jurisdiction over Comma Compliance’s compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
g. Binding Arbitration
Under certain conditions, more fully described on the Data Privacy Framework website, you may be able to invoke binding arbitration when other dispute resolution procedures have been exhausted. See https://www.dataprivacyframework.gov/ for details.
h. Disclosure to Public Authorities
We may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
i. Other International Users
If you access the Services from outside the European Economic Area, the United Kingdom, or Switzerland, your information may be transferred to and processed in the United States, and by using the Services you consent to such transfer and processing. This consent does not extend to the archived messages described in Section 5: because the individuals whose messages are archived are not necessarily users of the Services, the deploying organization is responsible for establishing the lawful basis for any cross-border transfer of those messages and for meeting its own international data-transfer obligations to those individuals. Comma Compliance acts as the organization’s processor in effecting such transfers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be effective upon posting to our website. Your continued use of the Services constitutes acceptance of the revised Privacy Policy.
12. Contact Information
If you have any questions or concerns about this Privacy Policy, please get in touch or contact us directly:
Comma Compliance
Email: support@commacompliance.com
Phone: 888-884-3318
Address: 2261 Market Street STE 22253, San Francisco, CA 94114
