Data Processing Agreement
Last updated 10 September 2026
This is the agreement that covers personal data we handle on your behalf — the client accounts you manage, the people in your team, and anyone who appears in the content you publish. It is what your own clients and your legal team will ask for, and it is required by Article 28 of the GDPR whenever one business processes personal data for another.
It applies automatically. Using xpost as a business customer puts it in force between you and Digital Abstracts SL; it forms part of our Terms of Service. There is nothing to request, sign, or wait for. If your procurement process needs a countersigned PDF of this exact text, email privacy@xpost.to and we will send one back within two working days.
Where this agreement uses terms from the GDPR — controller, processor, personal data, processing — they carry their GDPR meaning. “GDPR” includes the UK GDPR as it applies in the United Kingdom. Where this agreement and the Terms of Service disagree about personal data we process on your behalf, this agreement wins.
1. Who is who
You are the controller. You decide whose accounts get connected, what gets published, who is in your team, and what your guardrails allow. We are the processor. We act on your instructions and do not decide what happens to that data.
If you are yourself a processor — you run these accounts for clients who are the real controllers — then we are your sub-processor, and this agreement is what you can rely on when you sign your own DPA with them.
Some data we hold in our own right, as controller: your account and login, your billing records, and our server logs. That is not covered here — see the Privacy Policy.
2. What we process, and on whose instructions
The subject matter, duration, nature, purpose, data types, and data subjects are set out in Annex A.
Your use of the product is our instruction. Connecting an account, scheduling a post, setting a guardrail, issuing an API key — each is a documented instruction to process the data involved. Beyond that we process personal data only to provide the service, to keep it secure and working, and where the law requires it. If a law forces us to process it some other way, we will tell you before we do unless that law forbids it.
If we think an instruction breaks data protection law, we will say so rather than quietly carry it out.
3. Confidentiality
Access to your data is limited to the people who need it to run the service or to answer your support requests. They are bound by confidentiality obligations that survive their involvement, and they reach production only through named individual accounts.
4. Security
We keep the technical and organisational measures listed in Annex B. We may change them as the product and the threats change, but never to a materially lower standard of protection.
5. Sub-processors
You give us general authorisation to use the sub-processors in Annex C, and any we add under this section. Each is bound by written terms no weaker than these, and we stay responsible to you for what they do as if we had done it ourselves.
Before a new sub-processor starts processing your data we update Annex C and email the owner of every affected project at least 30 days beforehand. If you object on reasonable data-protection grounds within those 30 days, tell us: we will look for a way to give you the service without it, and if there isn’t one you may cancel the affected part of the service and we refund the unused part of what you have paid.
The social platforms themselves — X, Bluesky, LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, Pinterest — are not our sub-processors. When you tell us to publish to one, we transmit your content to it and it processes that content as an independent controller under its own terms with you.
6. Where the data goes
Your database records and your media are stored in the European Union (Frankfurt), and so are our backups. Some sub-processors in Annex C are United States companies and may process data outside the EEA.
Where a transfer needs a safeguard, we rely on the European Commission’s Standard Contractual Clauses or another mechanism approved under Chapter V of the GDPR. Where those Clauses apply, they are incorporated into this agreement — Module Two where you are a controller, Module Three where you are a processor — with Annexes A, B and C below serving as their annexes, Spain law as the governing law, and the courts of Barcelona as the forum. For UK data, the UK International Data Transfer Addendum applies to those same Clauses.
7. Requests from the people whose data it is
Most of what a data subject can ask for, you can do yourself and immediately: export a project’s data, correct it, disconnect an account, or delete the project outright.
If someone comes to us directly about data we hold for you, we do not answer for you. We will pass the request on within five working days and let you handle it as the controller, unless the law requires otherwise. Where the built-in tools are not enough to answer a request, we will help — at no charge, unless the effort is genuinely disproportionate, in which case we will say so before doing it.
We will also help you with data protection impact assessments and prior consultations with a supervisory authority, so far as the information is ours to give.
8. If something goes wrong
If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay and in any case within 48 hours of becoming aware, by email to the project owner and to any security contact you have given us.
We will tell you what happened, which categories of data and roughly how many records are involved, what the likely consequences are, what we have done about it, and who to talk to for more. We will not sit on a partial picture until it is complete — you get the first account fast and updates as we learn more, because your own 72-hour clock starts when ours does.
Notifying your supervisory authority or the affected people is your decision as controller. We give you what you need to make it and to act on it; we do not make it for you.
9. Proving it
Ask and we will give you what you need to show your own auditors that we are doing this properly: our security documentation, the current sub-processor list, our answers to your security questionnaire, and a written response to specific questions. Once a year as a matter of course, and additionally after any incident that affected you or when your regulator requires it.
Where Article 28(3)(h) gives you the right to an on-site audit, we will accommodate one on 30 days’ notice, in working hours, on a scope agreed in advance, under confidentiality, and without disrupting other customers. You bear the cost, unless the audit finds material non-compliance on our side — then we do.
10. Getting it back, and getting rid of it
- Any time: export your data from the dashboard.
- Deleting a project deletes its posts, media, delivery records, metrics, guardrails, audit log, and connected-account credentials — and revokes those credentials with our aggregator too, not just in our database.
- When this agreement ends — you close your account, or we do — we keep your data for 30 days so you can still export it, then delete it. Ask and we will delete it sooner instead.
- Backups are encrypted and expire on a rolling schedule. Deleted records can survive in them until they age out; they are never restored into the live service except to recover from a failure.
- What the law makes us keep — invoices and tax records — we keep, and nothing else.
11. What we will never do with it
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use your content, your clients’ content, or your metrics to train machine-learning models — ours or anyone else’s. That includes the optional AI features: the model provider in Annex C processes what you send on our instruction, for that one request, and does not train on it. This is a contractual commitment, not a current preference.
12. Liability, law, and changes
Liability under this agreement is subject to the limits in the Terms of Service. This agreement is governed by the law of Spain together with applicable EU law, and the courts of Barcelona have jurisdiction.
We may update this agreement to keep it accurate and lawful. We update the date at the top, and for any change that materially affects your rights we email you at least 30 days beforehand. Sub-processor changes follow section 5.
Annex A — the processing, in detail
- Subject matter — providing the xpost service described in the Terms of Service.
- Duration — for as long as your account exists, plus the deletion window in section 10.
- Nature and purpose — storing and scheduling the content you create, applying your guardrails and approval rules, transmitting it to the platforms you connected, recording what happened to each delivery, reporting back the engagement counts on posts we published for you, and reading what is already on each connected profile so you can see a new post in its real context.
- Frequency — continuous, for as long as the service is in use.
Types of personal data:
- the email address, hashed password or sign-in identifier, and activity of the people in your workspace;
- for each connected social account: the handle, the platform’s internal ID, the profile picture, and the credential that lets us post — an access and refresh token, or for Bluesky the app password created there — all encrypted at rest;
- the content you upload or publish — captions, images, video, alt text — which may itself contain personal data about anyone you choose to include in it;
- engagement counts for the posts we published for you, and a copy of the posts already on each connected profile, so the Feed can show what is really on that account;
- the audit log: who, or which AI agent under which key, did what and when;
- ordinary technical data in server logs — IP addresses, browser user agents, timestamps.
Categories of data subject: the people in your team and the agents they issue keys to; the holders of the social accounts you connect, including your clients; and any person identifiable from the content you publish.
Special category data is not needed to run this service and you should not put it into your content. If you do, that is your decision as controller and you are responsible for having a lawful basis for it.
Annex B — how it is protected
- Encryption. Everything travels over HTTPS. Platform tokens, API keys, and other secrets are encrypted at rest with AES-256-GCM under a key held outside the database. Passwords are stored only as salted hashes and are never readable, by us or anyone else.
- Separation. Every project’s data is isolated from every other at the query level, and that isolation is covered by automated tests that run on every change — it is a thing we prove, not a thing we intend.
- Least privilege. API keys are scoped: a key can be read-only, or allowed to write but not to approve. An AI agent posting through the API lands in your approval queue by default and cannot publish around it.
- Access control. Production systems are reached through named individual accounts with two-factor authentication where the provider supports it, and access is removed when it is no longer needed.
- Accountability. Every project keeps an audit log of the actions taken in it, including everything done with an agent key.
- Backups. The database is dumped every six hours and the media mirrored daily, both encrypted and stored off-platform in the EU, in a bucket the running system’s own credentials cannot delete from. Each backup proves it can be decrypted with the key we hold — so a backup that could not be restored fails loudly instead of waiting to be discovered.
- Monitoring. An external uptime monitor watches a health endpoint that fails when scheduled posts stop going out, and a separate one watches the backups. Error reports have credentials stripped out of URLs before they leave our systems.
- Resilience. Each delivery to each account is independent, retried on failure, and its outcome recorded, so a problem with one platform cannot silently take another down with it.
- Change control. A typed codebase with an automated test suite, a staging environment with its own database and its own file storage, and production releases promoted by hand and reversible in one command.
- Deletion. Deleting a project removes its data from the live system and revokes its connected-account credentials at the source as well as here.
Annex C — sub-processors
The current list, as of 10 September 2026. Changes follow section 5 — 30 days’ notice by email before a new one starts.
- Vercel Inc. (United States) — hosting, the network in front of the site, and media storage. Functions and media are served from Frankfurt.
- Neon Inc. (United States) — the Postgres database. Stored in Frankfurt (eu-central-1).
- Amazon Web Services (United States) — encrypted database and media backups, stored in Frankfurt (eu-central-1).
- Bundle sp. z o.o. (Poland) — the publishing aggregator for LinkedIn, Instagram, Facebook, TikTok, YouTube, Threads, and Pinterest. It receives the content of posts to those platforms and holds the authorisation for accounts connected through it. Operates from the EEA.
- Stripe (Stripe Payments Europe, Ltd., Ireland; Stripe, Inc., United States) — subscriptions and payments. Card details go directly to Stripe and never reach our servers.
- Resend (United States) — transactional email: sign-in and password reset, approval requests, delivery alerts, and the daily round-up.
- Cloudflare, Inc. (United States) — DNS for xpost.to and routing for inbound mail to our published addresses.
- Functional Software, Inc. (Sentry) (United States) — error monitoring. Credentials that appear in URLs are redacted before anything is sent.
- Anthropic PBC (United States) — the optional AI features only: writing and tailoring captions, suggesting alt text, and the classifier behind the banned-topics guardrail. It sees the text or image involved in that one request, and only where AI features are switched on for your workspace. It does not train on it.
Separately, and not as a sub-processor we appointed: if you connect an AI assistant to xpost, everything you ask that assistant for is returned through it, so its operator receives that data on your instruction — OpenAI, L.L.C. for ChatGPT, Anthropic PBC for Claude, and correspondingly for any other MCP client you choose. You add and remove those connections yourself, under whatever terms you have with that operator.
Contact
privacy@xpost.to — for this agreement, a signed copy of it, security questionnaires, and data requests. A person answers.
Digital Abstracts SL
Alaba 60, 2-2, 08005 Barcelona
Spain