This Data Processing Agreement (“DPA”) forms part of the Terms of Service between [Company Legal Name] (“Processor,” “we”) and the customer (“Controller,” “you”) and applies where we process personal data on your behalf under data protection laws including the EU/UK GDPR.
1. Roles
For personal data you submit through the Service, you act as the Controller and we act as the Processor. You are responsible for the lawfulness of the data you provide and instruct us to process.
2. Scope and instructions
We process personal data only to provide the Service and on your documented instructions (including as set out in the Terms and this DPA), unless required otherwise by law, in which case we will tell you unless prohibited.
3. Nature of the processing
| Subject matter | Providing social media scheduling and publishing |
|---|---|
| Duration | For the term of your account, plus deletion periods in our Privacy Policy |
| Categories of data subjects | You, your team members, and the audiences of the content you publish |
| Categories of personal data | Names, emails, account identifiers, connected-account handles and tokens, post content, usage logs |
4. Confidentiality
We ensure that personnel authorized to process personal data are bound by confidentiality obligations.
5. Security
We implement appropriate technical and organizational measures, including encryption of connected-account credentials at rest, hashed passwords, encryption in transit (HTTPS), and access controls that isolate each member’s data. See our Security page.
6. Sub-processors
You authorize us to engage the sub-processors below to provide the Service. We remain responsible for their performance and will impose data protection terms on them. We will give you notice of new sub-processors so you may object on reasonable grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| [Hosting provider] | Application and database hosting | [Region] |
| Google LLC | “Continue with Google” authentication | [Region] |
| Groq, Inc. | AI draft generation | [Region] |
| [Email/SMTP provider] | Transactional email | [Region] |
Note: the social networks you connect (Bluesky, Mastodon, Meta, LinkedIn) receive the content you choose to publish as independent controllers of what you send them.
7. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate measures to respond to requests from data subjects to exercise their rights. Many actions (edit, delete, disconnect) can be performed directly in the dashboard.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.
9. International transfers
Where personal data is transferred outside the EEA/UK, we rely on an appropriate transfer mechanism such as the Standard Contractual Clauses, which are incorporated by reference where applicable.
10. Deletion and return
On termination, we will delete or return personal data in accordance with our Privacy Policy, except where retention is required by law.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits as required by applicable law, subject to reasonable confidentiality and scheduling.
12. Contact
For DPA matters, contact [privacy@your-domain.com].