Skip to content
SocialPostxr SocialPostxr
  • Home
  • Features
  • Pricing
  • Blog
  • Login
  • Start Free
Login Start Free

Subprocessors

The providers that process personal data on our behalf, what each one does and where they do it.

Last updated: 1 August 2026 · version 2026-08-01

1. What this page is

To run SocialPostxr, ACEMAN SOFTWARE SOLUTIONS LTD uses third-party providers for hosting, storage, publishing, payments, email, monitoring and AI generation. Where those providers handle personal data on our behalf, they are our processors, and because you are our customer they are your subprocessors.

This page is the authoritative list. Our Data Processing Agreement incorporates it by reference, so it is a contractual document, not just a courtesy.

A provider is listed here when personal data actually reaches it — not merely because we hold an account with them. We would rather this list be exactly right than merely long.

2. The register

Providers and other recipients of personal data, for Aceman Software Solutions Ltd.
ProviderPurposeData processedLawful basisRetentionLocation & safeguard
Salesforce, Inc.HerokuApplication hostingEverything the backend processes in transit: account identifiers, email addresses, brand descriptions, uploaded images, post textContract — Art. 6(1)(b)Ephemeral; logs held only in a rolling bufferEUUK→EEA, none required
Supabase, Inc.Database, object storage, authentication, realtimeThe whole user record: identifiers, email, names, brand profiles, uploaded and generated images and video, post content, schedules, credit ledgerContract — Art. 6(1)(b)Controlled by us for live rowsUnited Kingdom (London, eu-west-2)UK/EEA — none required (data at rest is in the UK)
Cloudflare, Inc.Hosting this site; CDN, TLS, WAF and bot management in front of the APISite visitors: IP address, user agent, request URL, bot-management cookieContract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f)Our interest: Keeping the site and the API available and protected from attack, bots and abuse.Bot cookie 30 minutesGlobal edge, nearest locationUK Addendum
Google Ireland LimitedFirebase HostingHosting the web applicationApp visitors: IP address, user agent, requested pathContract — Art. 6(1)(b)—europe-west1, global CDN edgeUK→EEA none required for the backend; UK Addendum for edge
Google LLCGoogle FontsFont delivery for the SocialPostxr app (web and mobile) — not this website. The app loads font stylesheets from fonts.googleapis.com and font files from fonts.gstatic.com. This website serves every font from our own servers and sends nothing to Google.Your device's IP address and technical request data (user agent, which font files were requested), sent directly from your device to Google whenever the app loads fonts. That is every app session, because the app's text engine also loads its fallback fonts from Google — not only when you choose a font in the font picker. No account identifier is sent, and Google states these requests are not linked to a Google account or used for profiling.Contract — Art. 6(1)(b)Google-controlled; per Google's Fonts privacy statement, requests are logged in aggregateUnited States / globalNecessary for the font feature the user operates, disclosed at signup (UK GDPR Art. 49(1)(b)); no contractual safeguard exists for this service
OpenAIGenerating post copy, art direction, campaign strategy, image description and image generationBrand names and descriptions, tone and visual-identity text, target-audience descriptions, campaign briefs, questionnaire answers, uploaded and generated images sent for analysis, the website address given for brand extraction. No account email is sent.Contract — Art. 6(1)(b)Not used for training. Abuse-monitoring logs up to 30 daysUnited StatesUK Addendum
Ayrshare LLCPublishing to the user's connected social accounts and retrieving analyticsPost text, hashtags, media, scheduled times; connected social account authorisations; returned analytics, comments and messagesContract — Art. 6(1)(b)Life of the account; deletion acknowledged within five business daysUnited StatesUK Addendum
StripeSubscription billing and checkoutEmail address, Stripe customer identifier, account identifier in checkout metadata. Card details go directly to Stripe and never reach us.Contract — Art. 6(1)(b)Regulatory retention periodsUnited States / United KingdomUK Addendum
Microsoft Ireland Operations LimitedSending transactional and support emailRecipient email address, and the subject and body of transactional support email — whatever the user typed into the support formLegitimate interests — Art. 6(1)(f)Our interest: Replying to you when you contact us for support. We cannot answer a support request without sending you an email.Controlled by our mailbox settingsEuropean UnionUK/EEA — none required
Functional Software, Inc.SentryError monitoring and service reliabilityException type, message and stack trace; a pseudonymous account identifier. Request bodies, cookies and authentication headers are not sent.Legitimate interests — Art. 6(1)(f)Our interest: Being told when the service breaks, with enough detail to fix it, rather than waiting for someone to report it.90 daysEU — GermanyUK→EEA none required; UK Addendum for onward US processing
Grafana LabsPerformance monitoringPerformance traces of outbound requests: method, URL, status, timing. URLs contain a pseudonymous account identifier. No request or response bodies.Legitimate interests — Art. 6(1)(f)Our interest: Knowing which parts of the service are slow, so we can keep it usable.30 daysUnited KingdomNone required
Google Ireland LimitedGoogle AnalyticsWebsite and product analyticsVisitors who accept analytics cookies: IP address, device and browser data, pages viewed, analytics identifier. Nothing is sent before consentConsent — Art. 6(1)(a)Event-level data: 2 months; user-level data: 14 months (GA4 property 523407750)United States / globalUK Addendum
Google LLCGoogle Tag ManagerDelivery mechanism for analyticsDelivers the analytics script to consenting visitors; receives IP address and user agent as a consequenceConsent — Art. 6(1)(a)Not a storage endpointUnited States / globalUK Addendum
Kloudend, Inc.ipapi.coDetecting country and currency to set up the accountThe user's IP address at signup, if they consent to automatic location detectionConsent — Art. 6(1)(a)Server log files, period not publishedUnited StatesUK Addendum

We also maintain a fuller register internally, which includes providers that are configured in our systems but that currently receive no personal data. Only the providers that actually receive personal data are published above. We update this notice whenever that changes.

Register last verified against production: 1 August 2026.

3. Contracts and international transfers

Every provider we engage to process data on our behalf is under a written contract meeting Article 28 of the UK GDPR. They may act only on our documented instructions, must keep the data secure, must impose the same obligations on anyone they engage, and must delete or return the data when we stop using them.

One entry on this list is not one of those, and we would rather flag it than let the sentence above imply otherwise. Google Fonts is a free public service used by the SocialPostxr app. There is no contract to sign and Google offers no data processing agreement for it, so it is a recipient of personal data rather than a processor we have engaged. It is listed here because it receives your IP address and you are entitled to know that — not because we hold a contract with it.

For the same reason there is no transfer instrument to name. We rely on Article 49(1)(b) of the UK GDPR: the transfer is necessary to provide the font feature the user operates, and it is disclosed at signup. That is a narrower footing than the agreements covering every other row, and we are taking further advice on it.

This concerns the app only. This website serves every font from our own servers and sends nothing to Google.

Where a recipient is outside the UK and is not covered by UK adequacy regulations, we rely on the UK International Data Transfer Agreement, or on the UK Addendum to the EU Standard Contractual Clauses where that is the instrument the recipient offers. We do not rely on the EU Standard Contractual Clauses on their own, because they are not a valid transfer mechanism for a UK exporter.

In short, and for every row but the one above: UK International Data Transfer Agreement (IDTA) / UK Addendum. You can ask us for a copy of the safeguards relied on for any particular provider — email privacy@socialpostxr.com.

4. Changes to this list

We will give at least 30 days' notice before adding or replacing a subprocessor. If you object on reasonable data protection grounds, we will work with you to find a solution; if we cannot, you may terminate the affected part of the service without penalty.

To be told when this list changes, email privacy@socialpostxr.com and ask to be added to the subprocessor notification list.

5. Related documents

  • Privacy Notice — what we collect, why, and your rights.
  • Data Processing Agreement — the Article 28 terms.
  • Cookie Policy — what we store on your device.
SocialPostxr SocialPostxr
  • Home
  • About
  • Contact
  • Privacy
  • How we got your details
  • Terms
  • Cookies
  • Subprocessors
  • DPA

© 2026 SocialPostxr