Skip to content
SocialPostxr SocialPostxr
  • Home
  • Features
  • Pricing
  • Blog
  • Login
  • Start Free
Login Start Free

Data Processing Agreement

The Article 28 terms on which we process personal data on your behalf.

Last updated: 1 August 2026 · version 2026-08-01

1. When this applies

This agreement applies when you use SocialPostxr to process personal data about other people — your staff, your customers, or anyone identifiable from content you upload. In that situation you are the controller and ACEMAN SOFTWARE SOLUTIONS LTD is your processor.

It forms part of our Terms of Service and takes effect when you create an account. You do not need to sign anything for it to apply. If your procurement process needs a countersigned copy, email privacy@socialpostxr.com and we will provide one.

Personal data about you — your own account and billing details — is a different matter. There we are the controller, and our Privacy Notice applies instead.

2. What we process, and why

These are the particulars required by Article 28(3).

  • Subject matter: Providing the SocialPostxr service: generating, scheduling and publishing social media content on the customer's instruction.
  • Duration: For as long as the customer's subscription is active, plus the period needed for account deletion and backup expiry to complete.
  • Nature of the processing: Storage, retrieval, organisation, generation of derived content using AI models, transmission to social media platforms the customer has connected, and deletion.
  • Purpose: To deliver the service the customer has subscribed to, and no other purpose. We do not use customer personal data for our own purposes, and we do not use it to train AI models.

2.1 Types of personal data

  • Identification data: names, email addresses, account identifiers.
  • Authentication data: hashed passwords, access tokens for connected social media accounts.
  • Content data: text, images, brand material and campaign plans the customer or their end users upload or generate.
  • Usage data: activity within the customer's account.

2.2 Categories of data subject

  • The customer's own staff and any other individuals the customer authorises to use its account.
  • Individuals appearing in or identifiable from content the customer uploads.

3. Our obligations as your processor

3.1 We act only on your documented instructions

We process personal data only on your documented instructions, including on transfers out of the UK, unless we are required to do otherwise by law — in which case we will tell you before processing, unless the law forbids us from telling you.

Art. 28(3)(a)

3.2 Everyone handling your data is under a duty of confidence

Every person we authorise to process your personal data is bound by a contractual duty of confidentiality.

Art. 28(3)(b)

3.3 We keep it secure

We apply the technical and organisational measures required by Article 32: encryption in transit and at rest, access control limited to those who need it, logging of production access, and regular review of those measures.

Art. 28(3)(c)

3.4 Subprocessors are named, and you get notice of changes

We engage the subprocessors listed in our published register. You give general written authorisation for us to use them. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data protection grounds — in which case we will work with you to find a solution, and if we cannot, you may terminate the affected part of the service without penalty. Every subprocessor is bound by data protection terms no less protective than these.

Art. 28(3)(d)

3.5 We help you answer data subject requests

We will help you respond to requests from individuals exercising their rights, by appropriate technical and organisational measures, and taking into account the nature of the processing. If a request reaches us directly, we will forward it to you rather than answer it ourselves.

Art. 28(3)(e)

3.6 We help you with breaches, assessments and consultations

We will help you meet your obligations under Articles 32 to 36: keeping data secure, notifying breaches, carrying out data protection impact assessments and consulting the ICO where required. We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, with the information you need to make your own notification.

Art. 28(3)(f)

3.7 We delete or return your data when we are done

On termination, we will delete or return all personal data at your choice, and delete existing copies, unless we are legally required to keep them. Backups expire on their own schedule.

Art. 28(3)(g)

3.8 We can prove it

We will make available the information you need to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. We will tell you immediately if we think an instruction breaches data protection law.

Art. 28(3)(h)

4. Your obligations as controller

  • Make sure you have a lawful basis for the personal data you put into the service, and that the people it concerns have been told about it as Articles 13 and 14 require.
  • Give us lawful instructions. We will tell you if we think an instruction breaches data protection law, and we will not follow it.
  • Do not put special category data (Article 9) or criminal offence data (Article 10) into the service unless we have agreed it in writing beforehand — the service is not designed for it.
  • Answer requests from individuals about their rights. We will help; the duty is yours.

5. Subprocessors

You give general written authorisation for us to engage the subprocessors listed below and on our subprocessors page. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data protection grounds.

One entry in the table is listed for completeness rather than as a subprocessor you are authorising: Google LLC (Google Fonts). It receives an IP address directly from an app user's own device when the app loads fonts. That transfer does not pass through us, involves no customer data we hold, and rests on no contract — so it is not something we engage on your behalf, and nothing in this agreement should be read as saying it is. It appears in the register because your users are entitled to know it happens.

Authorised subprocessors, plus recipients listed for completeness.
ProviderPurposeData processedLawful basisRetentionLocation & safeguard
Salesforce, Inc.HerokuApplication hostingEverything the backend processes in transit: account identifiers, email addresses, brand descriptions, uploaded images, post textContract — Art. 6(1)(b)Ephemeral; logs held only in a rolling bufferEUUK→EEA, none required
Supabase, Inc.Database, object storage, authentication, realtimeThe whole user record: identifiers, email, names, brand profiles, uploaded and generated images and video, post content, schedules, credit ledgerContract — Art. 6(1)(b)Controlled by us for live rowsUnited Kingdom (London, eu-west-2)UK/EEA — none required (data at rest is in the UK)
Cloudflare, Inc.Hosting this site; CDN, TLS, WAF and bot management in front of the APISite visitors: IP address, user agent, request URL, bot-management cookieContract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f)Our interest: Keeping the site and the API available and protected from attack, bots and abuse.Bot cookie 30 minutesGlobal edge, nearest locationUK Addendum
Google Ireland LimitedFirebase HostingHosting the web applicationApp visitors: IP address, user agent, requested pathContract — Art. 6(1)(b)—europe-west1, global CDN edgeUK→EEA none required for the backend; UK Addendum for edge
Google LLCGoogle FontsFont delivery for the SocialPostxr app (web and mobile) — not this website. The app loads font stylesheets from fonts.googleapis.com and font files from fonts.gstatic.com. This website serves every font from our own servers and sends nothing to Google.Your device's IP address and technical request data (user agent, which font files were requested), sent directly from your device to Google whenever the app loads fonts. That is every app session, because the app's text engine also loads its fallback fonts from Google — not only when you choose a font in the font picker. No account identifier is sent, and Google states these requests are not linked to a Google account or used for profiling.Contract — Art. 6(1)(b)Google-controlled; per Google's Fonts privacy statement, requests are logged in aggregateUnited States / globalNecessary for the font feature the user operates, disclosed at signup (UK GDPR Art. 49(1)(b)); no contractual safeguard exists for this service
OpenAIGenerating post copy, art direction, campaign strategy, image description and image generationBrand names and descriptions, tone and visual-identity text, target-audience descriptions, campaign briefs, questionnaire answers, uploaded and generated images sent for analysis, the website address given for brand extraction. No account email is sent.Contract — Art. 6(1)(b)Not used for training. Abuse-monitoring logs up to 30 daysUnited StatesUK Addendum
Ayrshare LLCPublishing to the user's connected social accounts and retrieving analyticsPost text, hashtags, media, scheduled times; connected social account authorisations; returned analytics, comments and messagesContract — Art. 6(1)(b)Life of the account; deletion acknowledged within five business daysUnited StatesUK Addendum
StripeSubscription billing and checkoutEmail address, Stripe customer identifier, account identifier in checkout metadata. Card details go directly to Stripe and never reach us.Contract — Art. 6(1)(b)Regulatory retention periodsUnited States / United KingdomUK Addendum
Microsoft Ireland Operations LimitedSending transactional and support emailRecipient email address, and the subject and body of transactional support email — whatever the user typed into the support formLegitimate interests — Art. 6(1)(f)Our interest: Replying to you when you contact us for support. We cannot answer a support request without sending you an email.Controlled by our mailbox settingsEuropean UnionUK/EEA — none required
Functional Software, Inc.SentryError monitoring and service reliabilityException type, message and stack trace; a pseudonymous account identifier. Request bodies, cookies and authentication headers are not sent.Legitimate interests — Art. 6(1)(f)Our interest: Being told when the service breaks, with enough detail to fix it, rather than waiting for someone to report it.90 daysEU — GermanyUK→EEA none required; UK Addendum for onward US processing
Grafana LabsPerformance monitoringPerformance traces of outbound requests: method, URL, status, timing. URLs contain a pseudonymous account identifier. No request or response bodies.Legitimate interests — Art. 6(1)(f)Our interest: Knowing which parts of the service are slow, so we can keep it usable.30 daysUnited KingdomNone required
Google Ireland LimitedGoogle AnalyticsWebsite and product analyticsVisitors who accept analytics cookies: IP address, device and browser data, pages viewed, analytics identifier. Nothing is sent before consentConsent — Art. 6(1)(a)Event-level data: 2 months; user-level data: 14 months (GA4 property 523407750)United States / globalUK Addendum
Google LLCGoogle Tag ManagerDelivery mechanism for analyticsDelivers the analytics script to consenting visitors; receives IP address and user agent as a consequenceConsent — Art. 6(1)(a)Not a storage endpointUnited States / globalUK Addendum
Kloudend, Inc.ipapi.coDetecting country and currency to set up the accountThe user's IP address at signup, if they consent to automatic location detectionConsent — Art. 6(1)(a)Server log files, period not publishedUnited StatesUK Addendum

We also maintain a fuller register internally, which includes providers that are configured in our systems but that currently receive no personal data. Only the providers that actually receive personal data are published above. We update this notice whenever that changes.

Register last verified against production: 1 August 2026.

6. International transfers

Where a recipient is outside the UK and is not covered by UK adequacy regulations, we rely on the UK International Data Transfer Agreement, or on the UK Addendum to the EU Standard Contractual Clauses where that is the instrument the recipient offers. We do not rely on the EU Standard Contractual Clauses on their own, because they are not a valid transfer mechanism for a UK exporter.

We will not transfer your personal data outside the UK without a lawful transfer mechanism in place. In practice: UK International Data Transfer Agreement (IDTA) / UK Addendum, or UK adequacy regulations where they cover the destination.

7. Security

We apply the measures required by Article 32, appropriate to the risk: encryption in transit and at rest, access limited to those who need it and logged, separation of production from development, and periodic review of these measures. We will tell you about any material change that reduces the level of protection.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event in time for you to meet your own 72-hour deadline under Article 33. Our notification will describe what happened, the categories and approximate number of records affected, the likely consequences, and what we are doing about it. Where we do not have all of that at first, we will send what we have and follow up.

Notifying the ICO and, where required, the individuals affected is your responsibility as controller. We will give you what you need to do it.

9. Audit

We will make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections by you or an auditor you appoint. We ask for 30 days' notice, no more than one audit a year unless a breach or a regulator's direction makes another necessary, and that any auditor is bound by confidentiality.

10. Deletion and return

When this agreement ends, we will delete or return all personal data processed on your behalf, at your choice, and delete existing copies — unless we are required by law to keep them, in which case we will tell you what we are keeping and why. Backups expire on their own schedule.

11. General

This agreement is governed by the laws of England and Wales. Where it conflicts with our Terms of Service on a data protection matter, this agreement wins. If the law changes so that this agreement no longer meets it, we will update it and tell you.

  • Processor: ACEMAN SOFTWARE SOLUTIONS LTD
  • Company number 12928098
  • 8 Holtdale Grove, Leeds, England, LS16 7RZ
  • Data protection contact: privacy@socialpostxr.com
SocialPostxr SocialPostxr
  • Home
  • About
  • Contact
  • Privacy
  • How we got your details
  • Terms
  • Cookies
  • Subprocessors
  • DPA

© 2026 SocialPostxr