Data Processing Agreement

Last updated 10 September 2026

This is the agreement that covers personal data we handle on your behalf — the client accounts you manage, the people in your team, and anyone who appears in the content you publish. It is what your own clients and your legal team will ask for, and it is required by Article 28 of the GDPR whenever one business processes personal data for another.

It applies automatically. Using xpost as a business customer puts it in force between you and Digital Abstracts SL; it forms part of our Terms of Service. There is nothing to request, sign, or wait for. If your procurement process needs a countersigned PDF of this exact text, email privacy@xpost.to and we will send one back within two working days.

Where this agreement uses terms from the GDPR — controller, processor, personal data, processing — they carry their GDPR meaning. “GDPR” includes the UK GDPR as it applies in the United Kingdom. Where this agreement and the Terms of Service disagree about personal data we process on your behalf, this agreement wins.

1. Who is who

You are the controller. You decide whose accounts get connected, what gets published, who is in your team, and what your guardrails allow. We are the processor. We act on your instructions and do not decide what happens to that data.

If you are yourself a processor — you run these accounts for clients who are the real controllers — then we are your sub-processor, and this agreement is what you can rely on when you sign your own DPA with them.

Some data we hold in our own right, as controller: your account and login, your billing records, and our server logs. That is not covered here — see the Privacy Policy.

2. What we process, and on whose instructions

The subject matter, duration, nature, purpose, data types, and data subjects are set out in Annex A.

Your use of the product is our instruction. Connecting an account, scheduling a post, setting a guardrail, issuing an API key — each is a documented instruction to process the data involved. Beyond that we process personal data only to provide the service, to keep it secure and working, and where the law requires it. If a law forces us to process it some other way, we will tell you before we do unless that law forbids it.

If we think an instruction breaks data protection law, we will say so rather than quietly carry it out.

3. Confidentiality

Access to your data is limited to the people who need it to run the service or to answer your support requests. They are bound by confidentiality obligations that survive their involvement, and they reach production only through named individual accounts.

4. Security

We keep the technical and organisational measures listed in Annex B. We may change them as the product and the threats change, but never to a materially lower standard of protection.

5. Sub-processors

You give us general authorisation to use the sub-processors in Annex C, and any we add under this section. Each is bound by written terms no weaker than these, and we stay responsible to you for what they do as if we had done it ourselves.

Before a new sub-processor starts processing your data we update Annex C and email the owner of every affected project at least 30 days beforehand. If you object on reasonable data-protection grounds within those 30 days, tell us: we will look for a way to give you the service without it, and if there isn’t one you may cancel the affected part of the service and we refund the unused part of what you have paid.

The social platforms themselves — X, Bluesky, LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, Pinterest — are not our sub-processors. When you tell us to publish to one, we transmit your content to it and it processes that content as an independent controller under its own terms with you.

6. Where the data goes

Your database records and your media are stored in the European Union (Frankfurt), and so are our backups. Some sub-processors in Annex C are United States companies and may process data outside the EEA.

Where a transfer needs a safeguard, we rely on the European Commission’s Standard Contractual Clauses or another mechanism approved under Chapter V of the GDPR. Where those Clauses apply, they are incorporated into this agreement — Module Two where you are a controller, Module Three where you are a processor — with Annexes A, B and C below serving as their annexes, Spain law as the governing law, and the courts of Barcelona as the forum. For UK data, the UK International Data Transfer Addendum applies to those same Clauses.

7. Requests from the people whose data it is

Most of what a data subject can ask for, you can do yourself and immediately: export a project’s data, correct it, disconnect an account, or delete the project outright.

If someone comes to us directly about data we hold for you, we do not answer for you. We will pass the request on within five working days and let you handle it as the controller, unless the law requires otherwise. Where the built-in tools are not enough to answer a request, we will help — at no charge, unless the effort is genuinely disproportionate, in which case we will say so before doing it.

We will also help you with data protection impact assessments and prior consultations with a supervisory authority, so far as the information is ours to give.

8. If something goes wrong

If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay and in any case within 48 hours of becoming aware, by email to the project owner and to any security contact you have given us.

We will tell you what happened, which categories of data and roughly how many records are involved, what the likely consequences are, what we have done about it, and who to talk to for more. We will not sit on a partial picture until it is complete — you get the first account fast and updates as we learn more, because your own 72-hour clock starts when ours does.

Notifying your supervisory authority or the affected people is your decision as controller. We give you what you need to make it and to act on it; we do not make it for you.

9. Proving it

Ask and we will give you what you need to show your own auditors that we are doing this properly: our security documentation, the current sub-processor list, our answers to your security questionnaire, and a written response to specific questions. Once a year as a matter of course, and additionally after any incident that affected you or when your regulator requires it.

Where Article 28(3)(h) gives you the right to an on-site audit, we will accommodate one on 30 days’ notice, in working hours, on a scope agreed in advance, under confidentiality, and without disrupting other customers. You bear the cost, unless the audit finds material non-compliance on our side — then we do.

10. Getting it back, and getting rid of it

11. What we will never do with it

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content, your clients’ content, or your metrics to train machine-learning models — ours or anyone else’s. That includes the optional AI features: the model provider in Annex C processes what you send on our instruction, for that one request, and does not train on it. This is a contractual commitment, not a current preference.

12. Liability, law, and changes

Liability under this agreement is subject to the limits in the Terms of Service. This agreement is governed by the law of Spain together with applicable EU law, and the courts of Barcelona have jurisdiction.

We may update this agreement to keep it accurate and lawful. We update the date at the top, and for any change that materially affects your rights we email you at least 30 days beforehand. Sub-processor changes follow section 5.

Annex A — the processing, in detail

Types of personal data:

Categories of data subject: the people in your team and the agents they issue keys to; the holders of the social accounts you connect, including your clients; and any person identifiable from the content you publish.

Special category data is not needed to run this service and you should not put it into your content. If you do, that is your decision as controller and you are responsible for having a lawful basis for it.

Annex B — how it is protected

Annex C — sub-processors

The current list, as of 10 September 2026. Changes follow section 5 — 30 days’ notice by email before a new one starts.

Separately, and not as a sub-processor we appointed: if you connect an AI assistant to xpost, everything you ask that assistant for is returned through it, so its operator receives that data on your instruction — OpenAI, L.L.C. for ChatGPT, Anthropic PBC for Claude, and correspondingly for any other MCP client you choose. You add and remove those connections yourself, under whatever terms you have with that operator.

Contact

privacy@xpost.to — for this agreement, a signed copy of it, security questionnaires, and data requests. A person answers.

Digital Abstracts SL
Alaba 60, 2-2, 08005 Barcelona
Spain