Communioo Beta
Communioo Beta Privacy Policy
Last updated: 5 August 2026
1. Overview
This Privacy Policy explains how personal data is collected, used, and stored when you use Communioo (the "Platform") during its current beta/testing phase. It is written with reference to the EU General Data Protection Regulation ("GDPR") and other applicable data protection principles, adapted to reflect that Communioo is an early-stage beta project.
2. Who is responsible for your data
Communioo is currently created and operated by Ayush Pandey, an individual, and not by any registered company, LLC, SRL/BV, or other incorporated legal entity. Depending on the type of data and processing involved (see Section 3), Ayush Pandey acts either as the data controller or as a data processor acting on the instructions of your association, pending the possible future formation of a legal entity to operate Communioo.
Contact for privacy questions or requests: ayush@communioo.com
3. Controller vs. processor roles — who decides what happens with your data
To be transparent about GDPR roles:
- Your association is generally the data controller for the personal data of its own members that it manages through the Platform (e.g., membership records, working group assignments, event attendance, campaign communications) — it decides who should have access to the Platform, what data to hold about its members, and how that data should be used for association purposes.
- The Operator (Ayush Pandey / Communioo) generally acts as a data processor with respect to that association-member data, processing it only to provide the Platform's functionality on the association's behalf and instructions. A separate data processing arrangement (broadly consistent with GDPR Article 28) governs this relationship with each participating association and is available on request.
- The Operator acts as controller for a narrower set of data needed to operate the Platform itself — e.g., account/login/security data, and aggregate technical/usage data.
- If you have questions about how a specific association is using your data, you should also contact that association directly, since they control the underlying purpose of much of the processing.
This structure does not change your rights (Section 12) — you can direct requests to the Operator, your association, or both, and they will be routed appropriately.
4. Beta status — please read this section
Communioo is currently in active beta testing with real, live members of participating associations. This Policy applies during that beta phase. Because of the beta nature of the Platform:
- Data-protection practices, infrastructure, and safeguards are still being developed and matured;
- There is no dedicated security, legal, or compliance team behind the Platform — it is maintained by one individual;
- While reasonable efforts are made to protect personal data (see Section 8), no guarantee of absolute security can be made, and the possibility of a data breach, accidental disclosure, or data loss cannot be ruled out;
- By using the Platform during this beta phase, you accept this risk (see also Section 11 and the Terms of Use).
This beta-risk acknowledgment does not, and cannot, waive or reduce any statutory obligation that applies to a data controller or processor as a matter of mandatory law (for example, the duty to notify a personal data breach to the competent supervisory authority and, where required, to affected individuals). Those statutory duties will be complied with regardless of the contractual limitations on financial liability described in Section 11.
5. What personal data is collected
Depending on how you use the Platform, the following categories of personal data may be collected and processed:
- Account and identity data: name, email address, login/authentication data (magic-link sign-in).
- Profile data: job title, company/association affiliation, membership tier, LinkedIn URL, avatar/photo, and other profile fields you choose to complete or make visible.
- Directory and visibility preferences: settings you control for what is visible to other members (e.g., directory visibility, contact visibility, avatar visibility).
- Working group and community data: working group memberships and roles, access requests, posts, comments, likes, and connections you make with other members.
- Event data: event registrations, attendance records.
- Communications data: email campaign delivery/open/engagement data (where the association you belong to sends communications through the Platform), and any support or contact-form messages you send.
- Custom fields: additional data fields your association may configure and populate about you (e.g., during data import from their existing systems).
- Usage data: basic technical data generated by using a web application (e.g., log data, session data, IP address) to the extent necessary to operate and secure the Platform.
- AI feature data: if you choose to enable AI features using your own AI provider API key, see Section 7 and the separate AI Policy for how that data is handled.
Communioo does not intentionally collect special categories of data (e.g., health, religious, or biometric data) and you should avoid submitting such data unless it is clearly necessary and relevant to your association's activities.
Competitively sensitive information. Because working groups and community features may include representatives of competing companies within the same industry, please do not share commercially sensitive competitive information (e.g., pricing, capacity, strategy) via the Platform except in compliance with applicable competition/antitrust law — see the Terms of Use, Section 9.
6. Why data is processed (purposes and legal basis)
Personal data is processed to:
- Provide, operate, and improve the Platform's core features (directory, working groups, events, community feed, messaging, etc.);
- Enable your association to manage its membership and communications;
- Send transactional emails (e.g., magic-link login, event reminders, access-request notifications) and, where applicable, campaign communications from your association;
- Maintain the security and integrity of the Platform;
- Respond to support requests and feedback during the beta.
Where GDPR applies, the legal bases relied on are generally: performance of the arrangement under which you're using the Platform as a member of your association, legitimate interests (e.g., operating and securing a beta platform, improving the product), and consent (e.g., where you affirmatively opt in to visibility settings, connect an AI feature, or receive certain communications).
7. AI features
Communioo allows members to optionally enable AI-assisted features by connecting their own personal or organizational AI provider API key (a "bring your own key" model). If you choose to do this, data you submit to those AI features is sent directly using your configured key to your chosen third-party AI provider, subject to that provider's own privacy policy and terms — not this Policy. The Operator does not supply, process data through, or have visibility into your AI provider's handling of your data, beyond what is technically necessary to route your request using the key you provided. Do not submit other members' personal data, or another company's confidential or competitively sensitive information, to an AI feature unless you are authorized to do so — see the separate AI Policy for full details and acceptable-use restrictions.
8. Where and how data is stored (sub-processors)
A small number of third-party service providers ("sub-processors") help run the Platform. They are described here by category and region; a current, named list of sub-processors is available to participating associations on request, as part of the data processing arrangement in Section 3.
- Database & file storage: a managed database/storage provider hosts your data on infrastructure located in the EU (Frankfurt, Germany).
- Application hosting: a cloud application-hosting provider serves and runs the Platform and processes limited technical data (including IP addresses). This provider is US-headquartered; EU regions are used where available, and any processing outside the EU/EEA is subject to appropriate transfer safeguards (see Section 14).
- Security / rate-limiting: a hosted service processes limited technical data (such as IP-derived keys) to rate-limit requests and protect the Platform. It is currently US-hosted, receives only minimal technical data under appropriate safeguards, and is a candidate for replacement with an EU-hosted equivalent.
- Malware scanning: files uploaded to the Platform are scanned for malware by a self-hosted scanner running on infrastructure located in the EU (Germany) before they are stored.
- Email delivery: a third-party email delivery provider sends transactional and campaign emails.
- Access to the underlying database and infrastructure is restricted, and reasonable technical measures (such as access controls and row-level security policies) are used to limit who can see what data. However, as noted in Section 4, no system can be guaranteed 100% secure, especially during active beta development.
- Changes to sub-processors: if the Operator engages a new sub-processor that will materially change how or where personal data is processed, reasonable efforts will be made to notify affected associations in advance.
9. Data sharing
Personal data may be visible to:
- Other members of the same association, subject to your own visibility settings (e.g., directory visibility, avatar visibility);
- Staff/administrators of your association, who use the Platform to manage membership, working groups, and events;
- Third-party service providers ("sub-processors") who process data on the Operator's behalf solely to operate the Platform, described by category in Section 8 (database/file storage, application hosting, security/rate-limiting, malware scanning, and email delivery). A current, named list is available to participating associations on request;
- Your chosen third-party AI provider, only if and when you enable AI features using your own key (see Section 7).
Personal data is not sold to third parties, and is not used for third-party advertising.
10. Data retention
During the beta, data is generally retained for as long as your account is active and your association continues to use the Platform. Because this is a beta project, data may need to be reset, migrated, exported, or deleted as the Platform evolves, is restructured, or transitions out of beta. You can request deletion of your personal data at any time (see Section 12).
11. Limitation of liability for data breach or loss
Consistent with, and subject to, the Terms of Use (in particular its Limitation of Liability and Force Majeure sections), and to the maximum extent permitted by law, the Operator's financial liability for any data breach, unauthorized access, data loss, or corruption in connection with the Platform is limited as described there. This limitation does not extend to conduct that mandatory law does not permit to be excluded (e.g., fraud, wilful misconduct, or gross negligence), and does not affect the Operator's separate statutory obligations as controller or processor (e.g., breach notification duties), which are complied with regardless of any financial liability cap.
Because Communioo has no registered company standing behind it and no dedicated security/legal team, you should assume a materially higher residual risk than you would with an established, incorporated vendor, and should weigh this when deciding what data to submit to the Platform during the beta.
12. Your rights
Depending on your location, you may have rights under GDPR or similar laws, including the right to:
- Access the personal data held about you;
- Request correction of inaccurate data;
- Request deletion of your data ("right to be forgotten");
- Object to or restrict certain processing;
- Request a copy of your data in a portable format;
- Withdraw consent where processing is based on consent (e.g., turning off AI features or adjusting visibility settings within your profile).
To exercise any of these rights, contact ayush@communioo.com and/or your association (see Section 3). Reasonable efforts will be made to respond promptly, recognizing that this is currently handled by a single individual rather than a dedicated privacy team. You may also have the right to lodge a complaint with your local data protection supervisory authority (in Belgium, the Data Protection Authority / Autorité de protection des données).
13. Children's data
Communioo is intended for use by working professionals as part of their association membership and is not directed at, or intended for use by, children. Please do not use the Platform if you are under the age of 18.
14. International transfers
Primary data storage and file/malware processing are within the EU. Some operational sub-processors — currently the application-hosting and rate-limiting providers — are US-based and may process limited technical data (such as IP addresses) outside the EU/EEA; where they do, appropriate safeguards (such as EU Standard Contractual Clauses) are relied on where required by law, and EU-hosted alternatives are preferred as the Platform matures. A current, named list of sub-processors is available to participating associations on request. If you enable AI features, your chosen AI provider may process data outside the EU/EEA depending on their own infrastructure — see their privacy terms.
15. No representations outside this Policy
Statements made in marketing materials, demos, or informal communications about the Platform's security or data-handling practices do not expand the commitments set out in this Policy. This Policy, together with the Terms of Use and AI Policy, is the entire statement of how personal data is handled on the Platform.
16. Changes to this Policy
This Policy may be updated as Communioo develops, including as it potentially transitions from an individually operated beta project to a platform operated by a registered legal entity. Material changes will be communicated by email or in-app notice where reasonably practicable.
17. Contact
For any questions, requests, or concerns about this Privacy Policy or your personal data, contact: ayush@communioo.com
See also our Privacy Policy, Terms of Use and AI Policy. Questions: ayush@communioo.com.