Commolyn Terms of Service and Data Processing Addendum

Last updated: 2026-09-28

Part A — Terms of Service

1. Who provides the service and who these Terms cover

Commolyn is provided by Ilya Tsipelshteyn, a VAT-registered sole proprietor (Osek Murshe) in Israel ("Commolyn", "we", or "us"). Contact us at [email protected].

These Terms govern use of a Commolyn account, event page, and Telegram bot operated from Israel; they do not cover a separately operated Russian service. They take effect for a user when the user accepts them after being shown a link to this document. Sections addressed to an "Organizer" apply when a person creates or administers a community. An Organizer may be an individual or an organization; a person accepting on an organization's behalf confirms that they are authorized to bind it. The Data Processing Addendum ("DPA") in Part B forms part of these Terms when an Organizer accepts them for its community.

An event's own rules and any privacy information supplied by its Organizer are separate from these Terms. Commolyn's Privacy Policy explains how we handle personal data.

2. Accounts and authorized use

You must provide accurate account information, keep access credentials secure, and tell us promptly if you suspect unauthorized access. You are responsible for actions taken through your account unless they result from our breach of these Terms or applicable law. Use only the permissions granted to your account and community role.

You must be at least 18 years old to create an account and must have the legal capacity or authority needed to accept these Terms. A person under 18 may take part only when registered by a parent or legal guardian acting on their behalf. We do not independently verify that relationship. A person who adds another adult as a companion must have a legitimate reason and authority to provide that person's details and should make relevant privacy information available to them.

Do not use Commolyn to break the law, impersonate another person, send unsolicited messages, interfere with the service, or upload material that violates others' rights. Do not attempt to obtain information about members of another community without authorization.

3. Communities and events

Commolyn supplies software for managing communities and events. The Organizer, not Commolyn, runs each community and event, decides event content, participation requirements and rules, and is responsible for arrangements made with participants. Commolyn does not organize an event merely by displaying its page or processing registrations.

An Organizer is responsible for the accuracy and legality of community and event content, for selecting team members and their access, and for communications it sends or directs the service to send. The Organizer must provide any participant notices and obtain any permissions required for its own activities, including publication of photos or event details. A participant should review the Organizer's event information and rules before registering.

Where an event requires agreement to its rules, that agreement must be requested separately and clearly before registration. Commolyn's Terms and Privacy Policy do not replace the event's rules or the Organizer's own privacy information. An Organizer must not present acceptance of event rules as consent to unrelated data processing.

4. Community questions and personal data

The Organizer decides which membership-profile and event-registration questions to ask and why. It must limit questions to what is needed for the community or event, explain its purposes and legal basis to participants, handle requests concerning those answers, and keep access limited to authorized team members. The Organizer must not ask for health information, other special categories of personal data under the GDPR, including information revealing religious or political beliefs, or highly sensitive information under Israeli privacy law, including financial, salary, location, and personality-assessment data and data subject to a statutory confidentiality obligation, in field labels, descriptions, required answers, or free-text prompts. If such information is supplied unexpectedly, the Organizer must not use it and must arrange its removal, with our assistance where needed.

An Organizer that registers or invites someone else must have an appropriate basis to provide that person's data and must give them the relevant information. It must ensure that any person registering a child is the child's parent or legal guardian. The Organizer remains responsible for the activities it carries out with data after exporting it or sharing it outside Commolyn.

The Organizer is responsible for its purposes and legal basis for community and event data. Commolyn processes that data on the Organizer's documented instructions under Part B. Commolyn separately determines how account, security, and support data is used, as explained in the Privacy Policy.

5. Content and third-party services

You keep your rights in material you submit. You grant Commolyn a limited permission to host, copy, display, transmit, and process that material only to operate the service, follow the applicable Organizer's instructions, and meet legal obligations. You must have the rights needed to submit and share it. Public event pages and content posted to shared channels may be seen or forwarded by others.

Google provides sign-in. Telegram provides the messaging environment for the bot and community chats. Those services have their own terms and privacy rules. An Organizer that uses Telegram to communicate with participants is responsible for informing them that those communications pass through Telegram. Commolyn's Privacy Policy also applies to information received by our bot.

6. Service changes, suspension, and deletion

We may maintain, change, or discontinue features and may suspend access where reasonably necessary for security, unlawful use, or a material breach of these Terms. Where practicable, we will give notice and an opportunity to resolve the issue. We may remove content that violates these Terms or the law, taking account of the affected user's rights.

You may stop using Commolyn and close your account at any time by contacting [email protected]. We may close an account for the reasons that allow suspension under this section. Closing an account does not end obligations that arose before closure. Account data is then handled as described in the Privacy Policy.

An Organizer may request deletion of its community or end its use of the service. Community and event data is kept in the active system for up to 30 days after community deletion for recovery, then deleted or anonymized, subject to applicable law and the backup rotation described in the Privacy Policy and Part B. Individual deletion requests are handled under the Privacy Policy and, for Organizer-controlled data, Part B. We will provide a reasonable opportunity to obtain community data before final deletion where feasible and lawful.

Any paid plan, price, or payment obligation requires separate terms shown and accepted before a charge is made. Event fees or other arrangements between an Organizer and participants are their responsibility unless we expressly offer a payment feature under separate terms.

7. Responsibility and disputes

Unless you accept separate paid terms, Commolyn is provided free of charge on an "as is" and "as available" basis. We do not promise that it will be uninterrupted, error-free, or suitable for a particular purpose. We do not organize events and are not responsible for their outcome or the conduct of Organizers or participants.

To the extent the law permits, we disclaim implied warranties and conditions and are not responsible for content, communications, or data supplied by Organizers, participants, or other users, or for the availability, acts, or omissions of third-party services such as Google, Telegram, or Cloudflare. You are responsible for keeping your own copies of information you need, using any exports available in the service.

To the extent the law permits, Commolyn is not liable for losses caused by interruptions, errors, or unavailability of the free service, or for indirect or consequential losses, including loss of profits, revenue, business, or goodwill. To the extent the law permits, Commolyn's total liability arising out of or relating to free use of the service in any twelve-month period is limited to USD 100. Any liability terms for a paid service will be stated in the separate terms accepted before payment.

Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud, wilful misconduct, or any other liability that cannot legally be excluded or limited, or removes mandatory consumer or data-protection rights.

An Organizer will indemnify Commolyn against third-party claims and reasonable costs directly caused by the Organizer's events, content, breach of sections 3 or 4, or unlawful collection or use of personal data, except to the extent caused by Commolyn's own acts or omissions. Commolyn will notify the Organizer promptly of such a claim and allow it to take part in the defence.

These Terms are governed by the law of Israel, without removing any mandatory protections that apply to you under the law of your place of residence. The courts of Israel have jurisdiction, subject to any mandatory right to bring a claim elsewhere. Contact [email protected] first if you want to raise a concern; this does not restrict your right to seek a legal remedy.

We may update these Terms. We will give reasonable advance notice of material changes where practicable and obtain renewed acceptance where law requires it. The date above identifies this version.

8. General

  • Commolyn's rights. Commolyn and its licensors own the service, its software, design, and brand. These Terms give you a limited, non-exclusive, non-transferable right to use the service under these Terms and do not transfer any intellectual property to you. Do not copy, modify, reverse engineer, or resell the service except where the law allows it.
  • Feedback. If you send us suggestions or feedback, we may use them without any obligation to you.
  • Events beyond our control. We are not responsible for delay or failure caused by events beyond our reasonable control, including outages of internet, hosting, or messaging providers, natural events, war, or government action.
  • Assignment. You may not transfer your rights or obligations under these Terms without our consent. We may transfer them to a successor of the Commolyn business if your rights under these Terms and applicable law are not reduced; we will notify you of such a transfer.
  • Severability. If a court finds any part of these Terms invalid or unenforceable, that part is limited or removed to the minimum extent necessary and the rest of these Terms remains in effect.
  • No waiver. A failure or delay in enforcing any provision is not a waiver of it.
  • Entire agreement. These Terms, including Part B and the documents they reference, are the entire agreement about the service and replace earlier understandings about it. Separate terms for paid plans or features apply in addition once accepted.
  • Relationship. The parties are independent. These Terms create no partnership, agency, or employment relationship and give no rights to third parties except as stated in them.
  • Notices. We may send notices to the email address or messaging channel associated with your account or show them in the service. Send notices to us at [email protected].
  • Language. These Terms are written in English. If we provide a translation, the English version prevails to the extent the law permits.
  • Survival. Provisions that by their nature should continue after these Terms end survive, including sections 5, 7, and 8, and Part B for as long as Commolyn holds Organizer Data.

Part B — Data Processing Addendum for Organizers

1. Scope and roles

This DPA applies when the Organizer determines the purposes and means of processing personal data submitted to its community or events ("Organizer Data") and Commolyn processes that data to provide the service. The Organizer is the controller and Commolyn is the processor for that processing. The Organizer is responsible for identifying its legal basis, providing required notices, responding to participants, and ensuring its instructions are lawful. This allocation does not remove either party's direct obligations under applicable law.

Commolyn is an independent controller for account administration, authentication, service security, and support data that it determines how to use. The Privacy Policy describes those activities. Where an Organizer is itself acting as a processor for another controller, it confirms it is authorized to give Commolyn the instructions and permissions in this DPA.

This DPA applies for as long as Commolyn processes Organizer Data on the Organizer's behalf. If this DPA conflicts with Part A about that processing, this DPA controls. Applicable privacy law controls over either part. The limitations of liability for free use in Part A section 7 apply to this DPA to the extent the law permits; separate paid terms will govern liability for paid use.

2. Processing details and instructions

The subject matter, duration, nature, purposes, data subjects, and categories of Organizer Data are set out in Annex 1. The Organizer instructs Commolyn to receive, store, organize, display to authorized community users, send through enabled integrations, back up, export, and delete Organizer Data as needed to provide the service and as configured by the Organizer. Actions taken by authorized administrators in the service and written requests from the Organizer are documented instructions, subject to this DPA.

Commolyn will process Organizer Data only on documented instructions, including for transfers outside the EU where applicable, unless a law binding on Commolyn requires otherwise. Where legally allowed, we will inform the Organizer before processing required by law. We will promptly inform the Organizer if, in our opinion, an instruction violates applicable data-protection law, and may suspend the affected processing while the issue is resolved.

The Organizer authorizes processing and access in the locations in Annex 1 and the subprocessors in Annex 2. It authorizes transmission through Telegram only when it enables or uses a Telegram feature; Telegram's own processing is governed by its terms and privacy policy, and Telegram is not listed as a Commolyn subprocessor under this DPA. Google sign-in is an account function operated by Commolyn as an independent controller and is outside the Organizer Data processing described here.

3. Confidentiality and security

Within Commolyn, only its owner has operational access to production Organizer Data and is bound by the confidentiality and use restrictions in this DPA. Before granting production access to any additional Commolyn personnel, we will require a written commitment to confidentiality, use only for the agreed purposes, and compliance with the applicable security measures. We implement appropriate technical and organizational measures, including access controls, encryption in transit, encrypted database backups, separate community authorization, restricted audit records of access attempts to protected personal data and relevant security events, and backup restoration procedures. Audit records identify the actor, time, access target and type, and whether access was allowed or denied, without copying the accessed personal data. The measures will be reviewed as risks and technology change. The Organizer controls which of its team members can access its data, including other organizers and core members, and is responsible for their use of that access. Authorized infrastructure subprocessors are described in Annex 2.

4. Subprocessors and transfers

The Organizer gives general written authorization for the subprocessors listed in Annex 2. Commolyn will impose data-protection obligations on each subprocessor that are appropriate to the work it performs and remain responsible to the Organizer for the subprocessor's performance under this DPA.

Before adding or replacing a subprocessor that will process Organizer Data, we will give the Organizer notice and a reasonable opportunity to object on data-protection grounds. If the parties cannot resolve an objection, the Organizer may stop using the affected feature or end the affected service before the change takes effect. We will not use a new subprocessor for Organizer Data until the applicable notice and objection process has been completed.

Where EU data-transfer rules apply, Commolyn will use an adequacy decision or another valid transfer mechanism for any transfer that requires one. Storage in an EU jurisdiction does not rule out access from Israel or processing by an integration in another country; Annex 1 and the Privacy Policy describe the known locations and services.

5. Assistance, incidents, and audits

Taking account of the nature of the service and information available to us, we will reasonably assist the Organizer with access, correction, deletion, restriction, and other data-subject requests concerning Organizer Data. If a participant contacts us directly about Organizer Data, we may direct them to the Organizer and will assist the Organizer in responding. The Organizer remains responsible for its response and deadlines.

We will notify the Organizer without undue delay after becoming aware of a personal-data breach affecting Organizer Data, provide the information reasonably available to us, and provide updates as we learn more. We will reasonably assist the Organizer with its security, breach-notification, and impact-assessment obligations under applicable law.

We will make information reasonably necessary to demonstrate compliance with this DPA available to the Organizer and allow audits, including inspections where legally required, on reasonable notice and subject to appropriate confidentiality and security protections. An urgent audit after a serious incident may require shorter notice. The parties will cooperate to avoid exposing another community's data.

At least once a year, we will provide each Organizer with a written summary of how we performed our security and data-processing obligations under this DPA. It will cover the reporting period, material changes to access and security measures or subprocessors, security incidents affecting Organizer Data, and the status of retention and deletion measures. We may use a standard service-wide report, supplemented where needed with information specific to the Organizer. This annual report does not replace the prompt incident notice above.

6. End of service and retention

At the Organizer's choice, Commolyn will return Organizer Data through a reasonable export or delete it when the service ends. In either case, we will delete remaining copies unless law requires retention or a restricted backup is awaiting expiry under the rotations below. The Organizer should request an export before deletion becomes final. After community deletion, Organizer Data remains in the active system for up to 30 days for recovery unless the Organizer requests earlier deletion, and is then deleted or anonymized, subject to legal exceptions. We will provide a written account of the completed deletion or return and identify restricted backup copies still awaiting expiry. We will confirm expiry of backups under our control and pass on any available confirmation from MVPS about its snapshots. Event answers and attendance records may otherwise be retained for up to five years after an event ends while the community remains active and the Organizer needs them for event history and community planning. Routine diagnostic and message-delivery logs are retained for no longer than one month; ActivityLog entries for no longer than one year. Separate, restricted access-audit and relevant security-event records are retained for at least 24 months as required by Israeli data-security rules, including after deletion of the related community or account where the law requires it.

Encrypted database backups in a separate private Cloudflare R2 bucket follow a rotation of five daily, two weekly, and two monthly copies. MVPS separately makes automated disaster-recovery snapshots of the entire VPS and overwrites older snapshots under its own rotation. MVPS states that residual backup copies after service termination typically remain for no more than 90 days, without guaranteeing that maximum. Deleted data may remain in either kind of restricted backup until the copy expires. We use backups only for recovery and will reapply applicable deletion requests after a restore before ordinary use of the restored data. These rules are also described to individuals in the Privacy Policy.

Annex 1 — Description of processing

ItemDescription
Subject matterHosting and operating the Organizer's community, event, registration, attendance, and communication functions
DurationWhile the Organizer uses the service, followed by the deletion and backup periods in section 6
Nature and purposesCollecting, recording, storing, organizing, retrieving, displaying to authorized community users, sending through enabled channels, backing up, exporting, deleting, and anonymizing data to operate the Organizer's community and events
Data subjectsOrganizers and team members acting in a community; members and participants; adults added as companions; children registered by a parent or legal guardian; people who contact the Organizer through enabled service functions
Data categoriesNames, contact details, community roles and membership, RSVP and attendance records, Organizer-defined profile and event answers, companion and dependent details, communications with the bot and through enabled notifications, and event photos or other media submitted to the service
Systems and permitted accessApplication and primary PostgreSQL database on an MVPS VPS, with MVPS disaster-recovery snapshots; Cloudflare R2 buckets for media and encrypted database backups. Commolyn's owner may access Organizer Data from Israel to operate, secure, support, and restore the service. An Organizer grants access to its own team through community roles; infrastructure providers may access data as needed to provide their services.
Planned storage and access locationsPrimary database, application, and MVPS disaster-recovery snapshots: Cyprus (EU); media and encrypted database backups: separate Cloudflare R2 buckets restricted to the EU; authorized operator access: Israel; enabled messaging integrations may process data in other locations under their own terms

The Organizer must not intentionally collect health information, other special categories of personal data under the GDPR, or highly sensitive information under Israeli privacy law through the service. If such data is submitted unexpectedly, section 4 of Part A applies.

Annex 2 — Authorized subprocessors

SubprocessorServiceData and location
MVPSVPS hosting for the application and primary database, including disaster-recovery snapshotsOrganizer Data and VPS snapshots in Cyprus, EU
CloudflareR2 object storage for media and encrypted database backupsObjects in EU-jurisdiction buckets; Cloudflare may process service metadata as described in its terms

This is the current list of providers Commolyn uses to process Organizer Data. Google sign-in and Telegram are described separately above and in the Privacy Policy because they have different roles. If another provider is added to process Organizer Data, section 4 applies.