One product, one legal page
This page contains the service terms, privacy roles, Data Processing Addendum, security summary, subprocessor list and refund terms that apply to DobroDesk. Localized routes provide localized navigation, but the agreement text below is legally controlling in English.
Business service
The Customer is the organization that owns the Workspace.
Clear data roles
CoMStudio is controller for account data and processor for support data.
Product-specific coverage
Email, widget, channels, integrations, migration, AI, API and MCP are covered.
1. Agreement and definitions
This DobroDesk Legal Pack is an agreement between CoMStudio OÜ, registry code 17167299, with its registered office at Lõõtsa tn 5, 11415 Tallinn, Estonia ("CoMStudio", "we", "us" or "our") and the organization or person that creates, buys or uses a DobroDesk Workspace ("Customer", "you" or "your"). DobroDesk is a CoMStudio product.
This page contains the complete online terms for DobroDesk, including its service terms, privacy notice, Data Processing Addendum ("DPA"), security summary and subprocessor information. An online checkout, order form or other written order accepted by CoMStudio is an "Order". This Legal Pack and each applicable Order form the "Agreement".
If documents conflict, the DPA controls for the processing of Customer Personal Data, an Order controls for the commercial details it expressly changes and this Legal Pack controls for all other matters. Mandatory law always applies where it cannot be changed by contract.
You accept the Agreement when you create a Workspace, click to accept it, place an Order or use DobroDesk. If you act for an organization, you confirm that you have authority to bind that organization. DobroDesk is intended for business use by people who are at least 18 years old.
Defined terms
- Authorized User
- An employee, contractor or other person Customer authorizes to use its Workspace.
- Connected Service
- A third-party mailbox, channel, knowledge source, customer system, migration source or application connected by Customer.
- Customer Data
- Data, content and instructions submitted to DobroDesk by or for Customer, including support messages, customer and company records, files, internal notes, knowledge, integration data, configuration and AI inputs and outputs. Account, billing and service-security data that CoMStudio processes for its own purposes is not Customer Data.
- Customer Personal Data
- Personal data contained in Customer Data that CoMStudio processes on Customer's behalf.
- End User
- A person who communicates with Customer through email, a website widget or another connected support channel.
- Workspace
- Customer's tenant in DobroDesk, including its Channels, Inboxes, Teams, Conversations, Customers, Companies and settings.
2. DobroDesk service
DobroDesk is a business customer-support service. It receives and organizes customer communications as Conversations, provides shared Inboxes and assignment tools and may provide customer context, knowledge, reporting, automation, AI assistance, public help content, APIs, webhooks and enterprise controls.
The features included in Customer's subscription are the features shown as available in the applicable Order, checkout and Workspace. Preview, beta, trial, roadmap and disabled features are not part of a paid commitment unless an Order expressly says otherwise. A preview or beta feature may change or be withdrawn and is provided without a service-level commitment.
Customer may use DobroDesk for its internal business operations and to support its own End Users. Customer may not resell DobroDesk, make it available as a standalone service to an unrelated third party or use it to build a competing service unless CoMStudio agrees in writing.
Accounts and Workspace administration
Customer is responsible for:
- providing accurate account and billing information;
- authorizing and removing Authorized Users and assigning appropriate permissions;
- protecting sign-in methods, recovery methods, API tokens, integration credentials and devices;
- all activity performed through its Workspace except activity caused by CoMStudio's breach of the Agreement; and
- promptly notifying CoMStudio at support@comstud.io of suspected unauthorized access.
CoMStudio may access a Workspace only as needed to provide requested support, maintain or secure the service, investigate abuse, comply with law or perform the Agreement. Personnel access is limited by role and confidentiality obligations.
3. Customer Data
As between the parties, Customer retains its rights in Customer Data. Customer gives CoMStudio and its subprocessors a non-exclusive, worldwide and limited right to host, copy, transmit, transform, display and otherwise process Customer Data only to provide, secure, support and maintain DobroDesk, follow Customer's documented instructions and comply with law.
Customer is responsible for the accuracy, legality and quality of Customer Data and for having the rights, notices, permissions and lawful basis needed to collect it and instruct CoMStudio to process it. Customer must not submit payment-card security codes, account passwords, private cryptographic keys or regulated health, biometric or similar high-risk data unless CoMStudio has expressly agreed in writing that DobroDesk supports that use.
CoMStudio does not sell Customer Data or use it for third-party advertising. CoMStudio may create and use aggregated statistics that do not identify Customer, an Authorized User or an End User to operate, secure, plan and improve DobroDesk. CoMStudio will not attempt to re-identify that information.
Service ownership and confidentiality
CoMStudio and its licensors own DobroDesk, its documentation, service designs and underlying technology. The Agreement gives Customer a limited right to use the service and does not transfer ownership. CoMStudio may use voluntary feedback without restriction, but will not identify Customer publicly as the source without permission.
Each party may receive non-public information that a reasonable person would understand to be confidential. The receiving party will use it only to perform the Agreement, protect it with reasonable care and disclose it only to personnel, advisers and providers who need it and are bound to protect it. These duties do not apply to information independently developed, lawfully received without restriction or publicly available without breach. A legally required disclosure may be made after prior notice where law permits.
Exports, retention and deletion
Customer may use the available export controls to retrieve Customer Data. The standard service keeps Conversations online for the period shown in the Workspace, currently 120 days, before they become eligible for private archiving. Archiving is not deletion. Enterprise controls may allow an approved online-retention period from 30 to 3,650 days. Legal holds, security investigations, backup cycles and legal obligations may delay deletion.
Following termination or a verified deletion request, CoMStudio will return or delete Customer Personal Data in accordance with the available export and deletion process, unless Customer requests continued lawful retention or applicable law or a legal hold requires retention. Customer should complete any required export before deleting a Workspace or ending access.
4. Channels, integrations, migrations and developer access
Customer may connect supported email services, website widgets, messaging channels, knowledge sources, commerce or customer systems, migration sources and developer clients. The current connectable catalog and required permissions are shown in DobroDesk before authorization. Customer chooses each Connected Service and directs the exchange of Customer Data with it.
Customer is responsible for:
- having authority over each connected account, mailbox, domain, website, page, store, workspace, server and data source;
- complying with the Connected Service's terms, messaging rules, response windows and consent requirements;
- requesting only the permissions and data needed for its support workflow;
- checking imported data and mappings before relying on them; and
- disconnecting a service when Customer no longer has authority or no longer needs the connection.
A Connected Service is controlled by its provider. CoMStudio does not guarantee that a provider will approve, maintain or continue an integration and is not responsible for a provider's systems, terms or processing after data is sent to that provider at Customer's direction. CoMStudio may change, pause or discontinue an integration if the provider changes its interface or terms or if continued use creates a security, legal or operational risk. Where practical, CoMStudio will provide notice and an export or transition path.
Historical imports do not become billable merely because they were imported. A later customer message that continues an imported Conversation may create an accepted Conversation. Migration credentials are deleted when Customer explicitly finishes or disconnects the migration flow, subject to bounded retry and security records.
Customer may use published APIs, SDKs, webhooks and MCP access only within documented scopes and limits. Customer is responsible for its applications, callback endpoints, token custody, webhook verification and any actions performed by its authorized clients. Customer must not bypass rate limits, probe non-public interfaces or use developer access to obtain another customer's data.
5. AI features
DobroDesk may use hosted open-model infrastructure for classification, language detection and translation, summaries, knowledge retrieval, quality review, drafts and optional automated replies. Customer messages, approved evidence, embeddings, prompts and outputs are not used to train shared or third-party AI models.
Customer-visible AI drafts require human approval by default. Customer may enable a supported automated-reply mode for selected Channels or Inboxes. DobroDesk keeps legal, billing, account deletion, privacy, abuse, security and clearly angry-customer matters under human control and routes requests to a person when its safety or evidence rules require it.
AI output can be incomplete, inappropriate or wrong. Customer is responsible for configuring AI features for its use case, reviewing outputs where review is required and providing End Users with any notice or choice required by law. Where AI interacts directly with an End User or produces content sent without prior human review, Customer must provide any legally required disclosure that the End User is interacting with AI and must not falsely present AI-generated content as human-generated. Customer must not use AI features for prohibited practices or for decisions that create a significant legal, employment, credit, insurance, healthcare, housing or similarly high-risk effect on a person.
CoMStudio may apply technical limits, suspend an AI feature or require human review where use threatens security or service integrity, circumvents limits, violates the Agreement or could make DobroDesk a prohibited or high-risk AI system under applicable law.
6. Fees, usage and billing
Current prices, included usage, volume bands, add-ons, taxes and billing frequency are shown before purchase in the Order or checkout. Paddle acts as Merchant of Record for self-serve purchases and handles checkout, payment methods, invoicing, tax collection and remittance. Customer authorizes Paddle to charge the amounts confirmed at checkout and any usage charges calculated under the Order.
DobroDesk is priced by accepted support Conversations rather than Authorized User seats. An accepted Conversation is a new support Conversation accepted into agent handling, AI handling or escalation. Replies in the same Conversation do not create another billable Conversation. Rejected spam, duplicate provider deliveries, bounces, quarantine-only messages, historical imports, internal notes and empty or abandoned widget sessions are not billable Conversations.
The base subscription currently includes 300 accepted Conversations per monthly billing period. Additional usage is charged according to the progressive rates shown on the pricing page and confirmed in the billing interface. A started usage package covers up to the stated number of additional accepted Conversations. Closed-period usage may be added to the next renewal invoice.
AI assistance, normal integrations and Authorized Users are included unless an Order clearly identifies a separate charge. Public Help Center sites and Enterprise controls may be separate recurring add-ons. Ending an add-on does not automatically end the base Workspace subscription.
Customer must review usage and billing information and report a good-faith billing dispute promptly. CoMStudio may suspend paid features after repeated failed payment attempts, while keeping a limited billing-resolution path where practical. Fees are exclusive of taxes unless checkout states otherwise.
7. Cancellation and refunds
Customer may cancel a subscription through the available billing controls. Cancellation prevents the next renewal and normally takes effect at the end of the current paid period unless the billing interface or an Order states otherwise. Customer remains responsible for undisputed fees incurred before cancellation.
Customer may request a full refund of a DobroDesk base subscription or recurring add-on within 14 days after its purchase or renewal, regardless of product usage. Contact support@comstud.io and identify the Workspace and transaction. This contractual refund does not limit any mandatory statutory right. Paddle may process the approved refund as Merchant of Record. Usage corrections, duplicate charges and other billing disputes are reviewed separately against the accepted-Conversation ledger and payment record.
8. Acceptable use
Customer and Authorized Users must not use DobroDesk to:
- break applicable law, sanctions, export controls or third-party rights;
- send unsolicited bulk messages, phishing, malware, abusive content or unlawful surveillance;
- impersonate another person or misrepresent the source or status of a communication;
- collect or disclose personal data without the required authority, notice or lawful basis;
- circumvent access controls, usage limits, response windows, provider policies or safety measures;
- scan, attack, overload or interfere with DobroDesk or another service;
- reverse engineer non-public parts of the service except where applicable law expressly allows it; or
- use AI output as verified professional advice or as the sole basis for a high-risk decision about a person.
CoMStudio may investigate suspected violations and may limit or suspend affected access when reasonably necessary to protect End Users, other customers, providers or the service. Where the risk allows, CoMStudio will notify Customer and give it an opportunity to correct the issue. Immediate action may be taken for security threats, unlawful activity, sanctions or material harm.
9. Term, suspension and termination
The Agreement starts when Customer first accepts it and continues while Customer has an active Workspace, subscription or Order. Each paid subscription renews for the period shown at checkout until cancelled.
Either party may terminate for a material breach that the other party does not cure within 30 days after written notice. CoMStudio may suspend access sooner where reasonably necessary for a security incident, unlawful use, sanctions, risk to the service or overdue payment. CoMStudio will limit a suspension to the affected account, feature or activity where practical.
On termination, Customer's right to use DobroDesk ends and outstanding fees become due. Sections that by their nature should survive, including ownership, confidentiality, payment, liability, dispute and data-protection obligations, remain effective. Customer Data is handled as described in the Customer Data section and DPA.
10. Warranties, indemnity and liability
CoMStudio will provide paid DobroDesk services with reasonable skill and care and will use commercially reasonable measures to protect the service. Except for this express commitment and any non-excludable warranty, DobroDesk is provided "as is" and "as available". CoMStudio does not promise uninterrupted operation, a particular business result or the continued availability of a Connected Service. A service-level agreement applies only if an Order expressly includes one.
Customer will defend and indemnify CoMStudio against a third-party claim to the extent it results from Customer Data, Customer's unlawful communications, Customer's Connected Services or Customer's material breach of the Agreement. CoMStudio must give prompt notice, reasonable cooperation and control of the defense to Customer, and Customer may not settle a claim in a way that admits fault or imposes obligations on CoMStudio without written consent.
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, punitive or consequential damages or for loss of profits, revenue, goodwill or anticipated savings. CoMStudio's total aggregate liability arising from DobroDesk is limited to the greater of EUR 500 or the fees paid for DobroDesk during the six months before the event giving rise to the claim.
These exclusions and limits do not apply to fraud, wilful misconduct, death or personal injury caused by negligence or liability that applicable law does not allow a party to exclude or limit. The limitations apply across all legal theories and together form one aggregate cap.
11. Privacy and data roles
This section explains how CoMStudio handles personal data in connection with DobroDesk. CoMStudio has two different roles and the role depends on why the data is processed.
- CoMStudio as controller: CoMStudio determines why and how it processes website visitor data, account and Authorized User details, business contacts, billing metadata, direct support requests, service-security data and its own legal records.
- CoMStudio as processor: Customer determines why Customer Personal Data in support Conversations, customer records, files, knowledge and Connected Services is processed. CoMStudio processes that data on Customer's documented instructions under the DPA below.
If you communicate with a company that uses DobroDesk, that company is normally the controller of your support Conversation. Contact that company first to exercise rights concerning the Conversation. CoMStudio will assist the company as required by the DPA and law.
Personal data CoMStudio controls
CoMStudio may collect the following controller data:
- name, business email, account identifiers, organization, role, locale, time zone and authentication events;
- Workspace subscription, billing contact, Paddle customer and transaction identifiers, invoice status, tax status and refunds;
- service usage, device, browser, IP address, request, security, fraud-prevention and diagnostic records;
- communications sent directly to CoMStudio, including sales, support, privacy and security requests; and
- cookie or similar essential session data and aggregate, cookieless website analytics.
CoMStudio uses this data to:
- create and administer accounts and perform the Agreement;
- authenticate users, secure DobroDesk, prevent abuse and investigate incidents;
- provide support and service communications;
- administer subscriptions, invoices, taxes, refunds and financial records;
- understand aggregate service performance and improve reliability; and
- comply with legal obligations and establish, exercise or defend legal claims.
The applicable legal bases are performance of a contract, steps requested before entering a contract, CoMStudio's legitimate interests in operating and securing its business, compliance with legal obligations and consent where law requires consent. CoMStudio does not sell personal data or share it for cross-context behavioural advertising.
Recipients and controller-data retention
Controller data may be disclosed to infrastructure and security providers, Paddle as Merchant of Record, professional advisers, authorities where legally required and a successor in a corporate transaction subject to appropriate safeguards. CoMStudio keeps account and business-contact data while the relationship is active and as needed afterwards for support, security, disputes and legal obligations. Transaction, invoice and tax records are kept for the period required by applicable accounting and tax law. Security records are kept only as long as reasonably necessary for the relevant risk and investigation.
Privacy rights
Depending on applicable law, a person may request access, correction, deletion, restriction, portability or objection, withdraw consent or appeal a denied request. A person may also complain to a competent data-protection authority. Requests concerning data CoMStudio controls may be sent to support@comstud.io. CoMStudio may verify identity and authority before acting.
People in the European Economic Area may complain to the Estonian Data Protection Inspectorate or their local supervisory authority. California and other US residents may exercise applicable access, correction and deletion rights and may request confirmation that CoMStudio does not sell or share their personal information for targeted advertising. CoMStudio will not discriminate against a person for exercising a privacy right.
Children and End User notices
DobroDesk accounts are not intended for people under 18. Customer decides whether and how its own support service may be used by minors and is responsible for any parental notice or consent required for End User data. Customer must provide End Users with a clear privacy notice that identifies Customer, explains its use of DobroDesk and Connected Services and describes any AI or automated interaction where law requires that disclosure.
The DobroDesk widget uses essential session and security technology to start and resume a support Conversation. Customer is responsible for including this processing in its notice and for obtaining consent where local law requires consent for storage or access on an End User's device.
12. Data Processing Addendum
This DPA applies whenever CoMStudio processes Customer Personal Data as Customer's processor or service provider. It forms part of the Agreement without requiring a separate signature. "Data Protection Law" means privacy and data-protection law applicable to the processing, including the GDPR, UK GDPR and applicable US state privacy law. GDPR terms such as controller, processor, personal data, data subject and processing have their GDPR meanings.
12.1 Instructions and compliance
Customer appoints CoMStudio to process Customer Personal Data to provide, secure, support and maintain DobroDesk, follow settings and actions initiated by Customer and Authorized Users, support Connected Services selected by Customer, comply with the Agreement and follow other documented instructions agreed by the parties. CoMStudio will not process Customer Personal Data for another purpose unless required by law. Where legally permitted, CoMStudio will notify Customer before processing required by law.
Customer is responsible for ensuring that its instructions and use of DobroDesk comply with Data Protection Law and that it has a lawful basis, required notices and rights to provide Customer Personal Data. CoMStudio will inform Customer if it reasonably believes an instruction violates Data Protection Law and may pause the affected processing while the parties resolve the issue.
12.2 Confidentiality and personnel
CoMStudio will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate security and privacy guidance and access the data only as necessary for their responsibilities.
12.3 Security
CoMStudio will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. The current measures are summarized in the Security measures section below. Customer is responsible for configuring available access, retention, integration and security controls for its risk and use case.
12.4 Security incidents
CoMStudio will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data. The notice will include information reasonably available to CoMStudio about the nature of the incident, affected data, likely consequences and mitigation. CoMStudio's notice is not an admission of fault. Customer is responsible for notices to data subjects or authorities unless law assigns that duty to CoMStudio.
12.5 Data-subject requests and regulatory assistance
Taking into account the nature of processing, CoMStudio will provide reasonable assistance through available product controls and support so Customer can respond to data-subject requests. If CoMStudio receives a request concerning Customer Personal Data directly, it will direct the requester to Customer where practical and will not substantively respond on Customer's behalf unless Customer instructs it or law requires it.
CoMStudio will provide reasonable information needed for Customer's data-protection impact assessments, prior consultations and breach obligations, taking into account the nature of processing and information available to CoMStudio.
12.6 Audits
CoMStudio will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Customer should first use current security documentation, product information and independent assurance that CoMStudio makes available. If that is not sufficient, Customer may request one reasonable audit in a 12-month period, or an additional audit following a confirmed breach or regulator request. Audits must protect other customers, security and confidentiality, occur during normal business hours and avoid unreasonable disruption. Customer bears its audit costs unless the audit identifies CoMStudio's material breach of this DPA.
12.7 Return and deletion
At Customer's choice and subject to available export controls, CoMStudio will return or delete Customer Personal Data after the end of the services and delete remaining copies when they are no longer required for backup integrity, security, legal hold or applicable law. Until deletion, this DPA continues to apply. CoMStudio may retain de-identified information that cannot reasonably identify Customer or a data subject.
12.8 Liability and order of precedence
The Agreement's liability limitations apply to this DPA in aggregate with all other claims under the Agreement. This DPA controls if it conflicts with another part of the Agreement on the protection or processing of Customer Personal Data.
12.9 US state privacy requirements
To the extent a US state privacy law applies to Customer Personal Data, CoMStudio acts as Customer's service provider or contractor. CoMStudio will not sell or share Customer Personal Data, retain, use or disclose it outside the business purposes specified in the Agreement or combine it with personal data received from another person except as the applicable law permits. CoMStudio will notify Customer if it determines it can no longer meet these obligations. Customer may take reasonable and appropriate steps to verify and require remediation of CoMStudio's use of Customer Personal Data, subject to the audit protections in this DPA.
12.10 Other privacy laws
References to GDPR concepts do not limit this DPA to Europe. Where the LGPD, PIPEDA or another applicable privacy law imposes equivalent controller, processor, operator or service-provider duties, the parties will apply this DPA consistently with those duties and mandatory local law. CoMStudio will provide reasonable cooperation for a legally required regional addendum.
Processing details
| Subject matter | Providing and securing the DobroDesk customer-support service selected and configured by Customer. |
|---|---|
| Duration | The Agreement term and the limited return, deletion, backup or legally required retention period afterwards. |
| Data subjects | End Users, prospects, customers, Customer personnel, Authorized Users, contractors and people represented in Connected Services. |
| Data categories | Identity and contact data, support messages, files, message and delivery metadata, customer and company records, internal notes, knowledge, integration records, technical identifiers, audit events, AI inputs and outputs and usage-meter records. |
| Processing operations | Collection, receipt, organization, storage, retrieval, search, transmission, display, classification, translation, summarization, generation, review, export, archiving, restriction and deletion as directed through DobroDesk. |
| Sensitive data | DobroDesk is not designed for payment-card security data, passwords or regulated health or biometric systems. Sensitive data may nevertheless appear in free-text support content at Customer's direction. Customer must apply an appropriate lawful basis and safeguards and must not use DobroDesk for a regulated use that CoMStudio has not agreed to support in writing. |
13. Security measures
CoMStudio's current technical and organizational measures for DobroDesk include:
- encrypted network transport and managed encryption for stored service data;
- Workspace and object-level tenant separation with authorization checked at service boundaries;
- role-based access, least-privilege administration and separate controls for sensitive actions;
- protected credential storage and no display of stored provider secrets after initial entry;
- signed webhook verification, replay protection, idempotency and bounded input validation;
- private storage for messages, files, raw email, exports, invoices and audit artifacts;
- logging, audit events, monitoring, abuse controls and incident-response procedures;
- backup, archive-integrity and recovery processes proportionate to the service tier; and
- secure development review, dependency maintenance and production change controls.
Security measures may evolve as technology and risk change, provided CoMStudio does not materially reduce the overall protection of Customer Personal Data during a paid subscription without an appropriate replacement measure.
14. Subprocessors and connected services
Customer gives CoMStudio general authorization to use the subprocessors below. CoMStudio will impose written data-protection and security obligations appropriate to their processing and remains responsible for their performance of those obligations to the extent required by Data Protection Law.
| Provider | Purpose | Applies when | Processing locations |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, storage, network delivery, security, email delivery and AI processing for DobroDesk. | Core service | European Union, United States and global network locations used to deliver and secure the service. |
| Google Cloud | Event delivery for Gmail and Google Workspace mailbox synchronization. | Only when Customer connects Gmail or Google Workspace | United States and other Google processing locations under the applicable Google Cloud terms. |
CoMStudio will provide at least 20 days' prior notice before a new subprocessor begins materially different processing of Customer Personal Data. Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on a reasonable alternative. If none is available, Customer may stop the affected optional feature or terminate the affected service and receive a refund of prepaid fees for its unused period.
Customer-directed Connected Services
Google and Microsoft identity and mailboxes, Notion, Atlassian Confluence, HubSpot, Shopify, Meta services including WhatsApp, Facebook and Instagram, Telegram, Slack, Discord, Freshdesk, Intercom and Zendesk are Connected Services that Customer chooses and directs. Their providers process data under Customer's account and their own terms. They are not general DobroDesk subprocessors merely because Customer enables an integration. Data sent to a Connected Service at Customer's direction is then subject to that provider's privacy and retention practices.
Paddle is the Merchant of Record for self-serve transactions and processes payment and tax data as an independent controller under its own privacy notice. CoMStudio receives transaction identifiers, status and the billing metadata needed to provide the subscription and reconcile charges. CoMStudio does not receive full payment-card numbers or security codes.
15. International transfers
DobroDesk may process data in the European Union, the United States and global network locations needed to deliver and secure the service. Workspace data-region controls apply only where an Order and the Workspace expressly show that they are enabled. Email, Internet delivery and Connected Services can involve processing outside the selected storage region.
Where Customer Personal Data is transferred from the European Economic Area to a country without an adequacy decision, the parties enter into the European Commission's 2021 Standard Contractual Clauses. Module Two applies to controller-to-processor transfers and Module Three applies to processor-to-processor transfers. Customer is the data exporter and CoMStudio is the data importer. Acceptance of the Agreement is treated as signature of the clauses. The optional docking clause applies, Option 2 and the 20-day notice period apply under Clause 9, the optional language in Clause 11 does not apply, Estonian law governs under Clause 17 where a choice is required and the courts of Estonia are selected under Clause 18. The competent supervisory authority is determined under Clause 13.
For the annexes to the clauses, the parties and their contact details are those in the Agreement and Order, the transfer and processing details are those in the Processing details table, the security measures are those in the Security measures section and the authorized subprocessors are those in the Subprocessors table. Transfers occur continuously or as initiated through Customer's use of DobroDesk for the Agreement term and the limited deletion period afterwards.
For restricted transfers from the United Kingdom, the EU Standard Contractual Clauses are modified by and incorporate the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office. The tables of that Addendum are completed with the parties, modules, processing details, security measures and subprocessors identified in this Legal Pack and the mandatory clauses apply. For transfers from Switzerland, references in the clauses are adjusted as required by the Swiss Federal Act on Data Protection. CoMStudio will provide reasonable information about applicable transfer safeguards on request.
16. Supported territories and sanctions
DobroDesk is offered internationally but is not offered to organizations established in Russia or Belarus or to people located in Russia or Belarus when accessing or administering a Workspace. It is also unavailable where providing the service would violate applicable sanctions, export controls or a binding restriction imposed on CoMStudio or a required provider. Customer must not conceal location or identity to circumvent these restrictions.
This restriction concerns DobroDesk accounts and Authorized User access. It does not by itself require Customer to reject a lawful support message from an End User merely because that End User is travelling or located elsewhere. Customer remains responsible for its own sanctions, trade and communications compliance.
17. Changes and notices
CoMStudio may update this Legal Pack to reflect law, security, providers, pricing models or DobroDesk functionality. CoMStudio will publish the current version and effective date. Material changes will be announced by email and in the product at least 30 days before they take effect, unless a shorter period is required to address law, an urgent security risk or a provider change outside CoMStudio's control.
If Customer objects to a material change that substantially reduces its contractual rights, Customer may stop using and terminate the affected paid service before the change takes effect and request a prorated refund of prepaid fees for the unused period. Continued use after the effective date constitutes acceptance where permitted by law. CoMStudio will keep prior versions available from the Legal Center.
18. Contact, governing law and general terms
Legal, service and privacy notices to CoMStudio may be sent to support@comstud.io. CoMStudio may send notices to the Workspace Owner's current email address or through DobroDesk. Customer is responsible for keeping that address current.
The Agreement is governed by Estonian law without regard to conflict-of-law rules. The courts of Harju County, Estonia have exclusive jurisdiction, except where applicable law requires another forum. The parties will first attempt in good faith to resolve a dispute through written notice.
Neither party is liable for delay caused by events beyond its reasonable control, excluding Customer's payment obligations. Customer may not assign the Agreement without CoMStudio's written consent. CoMStudio may assign it to an affiliate or in connection with a merger, reorganization or sale of substantially all relevant assets, provided the successor assumes the Agreement. The parties are independent contractors. If a provision is unenforceable, it will be limited to the minimum extent necessary and the remaining provisions continue. A failure to enforce a provision is not a waiver.