Data Processing Agreement
How Postly processes personal data on your behalf, in compliance with global privacy regulations.
1. Scope & roles
This Data Processing Agreement (DPA) forms part of the Postly Terms of Service. Postly acts as the data processor and you (the customer) act as the data controller for personal data processed through the service.
2. Processing of data
Postly processes personal data only on your documented instructions and as needed to provide the service — including scheduling, publishing, and analytics across connected platforms.
3. Security measures
We implement appropriate technical and organizational measures: encryption in transit and at rest, access controls, audit logging, and least-privilege principles. Media is auto-deleted after publishing and messages after one week.
4. Sub-processors
We use vetted sub-processors (hosting, database, email delivery) under equivalent data-protection obligations. A current list is available on request, and we notify you of material changes.
5. Data subject rights
We assist you in responding to data-subject requests (access, correction, deletion) and support your compliance with GDPR, CCPA and similar regulations.
6. Contact
For DPA requests or a signed copy, contact info@joinpostly.com.