Data Processing Agreement
Last updated: June 25, 2026
This Data Processing Agreement (“DPA”) describes how Postbuddy processes personal data on behalf of customers — particularly brands and agencies — and supplements our Terms of Service. It is intended to support compliance with data-protection laws such as the GDPR and UK GDPR.
1. Roles
For personal data that you upload or process through Postbuddy in order to run your own and your clients’ social accounts, you act as the data controller and Postbuddy acts as a data processor. Where you manage multiple brands or clients (for example as an agency), you are responsible for having the necessary authority and lawful basis to process their data through Postbuddy.
2. Scope and instructions
Postbuddy processes personal data only to provide the service and in accordance with your documented instructions (which include your use of the product’s features) and applicable law. We will not use this data for our own unrelated purposes.
3. Categories of data and data subjects
- Data subjects: you, your team members, and audiences who interact with your social content.
- Personal data: account identifiers, connected social-profile details, post content and captions, comments and direct messages retrieved from connected platforms, and engagement metrics.
4. Confidentiality
We ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations.
5. Security
We implement appropriate technical and organisational measures designed to protect personal data, including encryption in transit, access controls, secure credential storage, and restricting access on a need-to-know basis. See our Privacy Policy for more on security.
6. Subprocessors
You authorise Postbuddy to engage subprocessors to help deliver the service. The categories we use are listed on our Subprocessors page. We impose data-protection obligations on subprocessors that are no less protective than those in this DPA, and we remain responsible for their performance. We will make reasonable efforts to notify customers of material changes to subprocessors on request.
7. International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised under applicable law.
8. Data subject rights
Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from data subjects to exercise their rights (such as access, rectification, erasure or portability), to the extent you cannot do so yourself through the product.
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your own notification obligations.
10. Deletion and return
On termination of your account, or on request, we will delete or return personal data processed on your behalf, subject to any retention required by law. You can delete content and disconnect accounts at any time, and request full account deletion via our Data Deletion page.
11. Audits
On reasonable written request, and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA.
12. Requesting a signed DPA
If your organisation requires a countersigned DPA, contact privacy@postbuddy.com and we will arrange one. In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.