Data Processing Agreement
Effective: April 16, 2026 · CommTrail, LLC · Sheridan, Wyoming
1. Parties
This Data Processing Agreement (“DPA”) is entered into between CommTrail, LLC, a Wyoming limited liability company (“Processor”), and the organization that has created an account on Meeting Signup (“Controller”).
This DPA is incorporated by reference into and forms part of the CommTrail Terms of Service. By using the Service, the Controller agrees to the terms of this DPA.
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person submitted through the Service.
- Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- Data Subject: The individual whose Personal Data is being processed (e.g., a meeting attendee who signs up to speak).
- Sub-processor: Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
3. Categories of Personal Data Processed
CommTrail processes the following categories of Personal Data on behalf of the Controller:
- Full name of meeting attendees
- Email address (when provided voluntarily by the attendee)
- Topic or subject of intended public comment
- Organization represented (when provided)
- Physical address (when provided)
- Accessibility accommodation type and notes (when requested by the attendee)
- Confirmation codes and signup timestamps
- IP addresses (retained transiently for rate limiting; not stored long-term)
- Staff user account information (name, email, role) for Controller’s employees
4. Purpose and Legal Basis of Processing
CommTrail processes Personal Data solely for the purpose of providing the Meeting Signup service to the Controller — specifically, managing speaker sign-up lists for public meetings. CommTrail does not process Personal Data for its own commercial purposes, does not sell Personal Data, and does not use attendee data for advertising or profiling.
The Controller is responsible for ensuring it has a lawful basis for collecting and processing Personal Data submitted through the Service (e.g., public interest, consent, or legitimate interest in managing public meeting participation).
5. Controller Obligations
The Controller agrees to:
- Comply with all applicable data protection laws in its use of the Service
- Provide any required notices to Data Subjects regarding the collection and use of their Personal Data
- Not instruct CommTrail to process Personal Data in a manner that would violate applicable law
- Respond to Data Subject requests regarding their Personal Data
6. Processor Obligations
CommTrail agrees to:
- Process Personal Data only on documented instructions from the Controller (i.e., as necessary to provide the Service)
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see Section 7)
- Assist the Controller in responding to Data Subject requests within five (5) business days of written request
- Not engage Sub-processors without informing the Controller (see Section 9)
- Delete or return all Personal Data upon termination of the Service (see Section 10)
7. Security Measures
CommTrail implements the following technical and organizational measures to protect Personal Data:
- Encryption in transit: All data transmitted between users and the Service is encrypted using TLS 1.2 or higher
- Encryption at rest: Data stored in the Supabase database is encrypted at rest using AES-256
- Access controls: Role-based access control limits staff access; service role credentials are restricted to server-side use only
- Authentication: Staff accounts are protected by email/password authentication with optional multi-factor authentication
- Data isolation: Row-Level Security (RLS) policies in the database ensure each organization can only access its own data
- Audit logging: All mutations to meeting and attendee data are logged with actor identity and timestamp
8. Breach Notification
In the event CommTrail becomes aware of a confirmed security breach involving Personal Data, CommTrail will notify the Controller without undue delay and within seventy-two (72) hours of becoming aware of the breach. Notification will be provided to the Account Administrator email address on file and will include: a description of the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.
9. Sub-processors
CommTrail uses the following Sub-processors to deliver the Service:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Microsoft Azure | Application hosting, email delivery (Azure Communication Services) | United States |
| Supabase, Inc. | Database, authentication, file storage | United States (AWS US East) |
| Stripe, Inc. | Payment processing (billing data only; no attendee data) | United States |
| Sentry, Inc. | Error monitoring and performance tracking | United States |
CommTrail will inform the Controller of any intended changes to this Sub-processor list by updating this page at least 14 days before the change takes effect. Controllers who object to a new Sub-processor may terminate their account within that 14-day period.
10. Data Retention and Deletion
CommTrail retains Personal Data for as long as the Controller’s account is active. Upon account closure or termination of the Service:
- The Controller may export all data via the CSV export feature before account closure
- All Personal Data will be deleted from active systems within thirty (30) days of account closure
- Backup copies may persist for up to an additional sixty (60) days before being purged from backup rotation
- CommTrail will confirm deletion in writing upon written request
11. Data Transfers
All Personal Data processed by CommTrail is stored and processed within the United States. CommTrail does not transfer Personal Data to countries outside the United States.
12. Governing Law
This DPA is governed by the laws of the State of Wyoming, United States, without regard to conflict of law principles.
13. Contact
For questions about this DPA, data subject requests, or to request a countersigned copy, contact: legal@commtrail.com
CommTrail, LLC · Sheridan, Wyoming 82801