Skip to content
SocialMint
FeaturesDemoPricingFAQLog inStart free

Data Processing Agreement

Version 2026-09-09 · Postial

1. Parties and scope

This agreement is between the customer identified by the Postial workspace and its subscription records (Customer) and productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG, Reichenbergerstr. 2, 94036 Passau, Germany (Postial). The workspace owner accepts for the Customer and confirms authority to do so. This agreement forms part of the service contract and governs personal data handled on the Customer’s behalf. It prevails over conflicting service terms on that subject.

The Customer is the controller, or acts as processor for its own clients and has their authority to appoint Postial as a further processor. Customer determines the lawful basis, content, recipients and permitted use. Postial processes that data solely to supply the instructed service. Postial separately controls account administration and billing data as described in the Privacy Policy.

2. Instructions and confidentiality

Customer instructs Postial through workspace settings, uploads, schedules, approval requests, connected networks and documented support requests. Postial will use personal data only on those instructions, including instructions concerning international transfers, unless applicable EU or Member State law requires otherwise. It will notify Customer before legally required processing unless the law prohibits that notice. Postial will promptly inform Customer if an instruction appears to breach data protection law and may pause the affected processing while the parties resolve it.

Access is restricted to people who need it to operate or support the service and who are bound by confidentiality duties. Those duties continue after their work ends. Customer is responsible for its users and for keeping approval links private.

3. Security and assistance

Postial implements the measures in Annex 2 and maintains protection appropriate to the processing risks under Article 32 GDPR. It will not materially reduce those protections during the contract. Customer should use appropriate account protection and restrict workspace and channel permissions.

Postial will assist Customer with access, correction, deletion, restriction, portability and objection requests using the tools and information available to it. Requests received directly from data subjects concerning Customer data will be referred to Customer rather than answered independently, except where legally required.

Postial will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer data, through the account contact or an agreed support channel. Available details will describe the incident, affected data and people, likely consequences, remedial steps and a contact for follow-up; missing details will follow as they become available. Postial will assist with security assessments, breach notifications, data protection impact assessments and regulator consultations, taking account of the service and information available.

4. Further processors and transfers

Customer gives general authorisation to the providers listed in Annex 3 where they process Customer data on Postial’s behalf. Postial will give at least 30 days’ advance notice of a proposed addition or replacement through the account contact or a workspace notice. Customer may object within that period on reasonable data protection grounds. The parties will seek a workable alternative; if none exists, Customer may end the affected service before the change applies without a penalty for that termination.

Postial will bind further processors to equivalent data protection obligations for their part of the service and remains responsible for their performance of those obligations. Transfers outside the EEA require an applicable adequacy decision or appropriate safeguards, such as the EU standard contractual clauses and necessary supplementary measures. Information on the applicable safeguards is available through the privacy contact. Merely connecting a provider is not a waiver of these requirements.

Some recipients act independently rather than as further processors. In particular, payment providers and social networks may determine their own purposes under their terms. Customer instructs disclosures to the networks and alert destinations it connects and remains responsible for its own relationship with those recipients.

5. Information, audits and termination

Postial will provide information reasonably necessary to demonstrate compliance with this agreement and Article 28 GDPR. It will allow and contribute to audits, including inspections by Customer or an independent auditor it appoints. The parties will coordinate reasonable notice, confidentiality and safeguards for other customers; urgent incidents or competent authority requirements must not be delayed by those arrangements.

On termination, Customer may request return of its content and associated personal data in a commonly readable format or their deletion. Postial will act on that choice and delete remaining copies unless EU or Member State law requires retention. Customer can make the request through the privacy contact. Any retained data remains protected, is isolated from ordinary use and is deleted when the retention obligation ends. Copies already published to third-party networks are controlled by those networks and the connected account; Postial assists with available deletion instructions but cannot promise erasure of public copies held by others.

Annex 1 — Processing details

Subject and duration: operation of the Customer’s Postial workspaces for the service term and the period needed to return or delete data as instructed.

Nature and purpose: receiving, storing, organising, displaying and editing social content; gathering client decisions; scheduling and transmitting posts to connected networks; managing workspace access; recording publication status, retries and notifications; providing support and deleting content.

Data categories: user names and contact details, brand and network identifiers, channel credentials, post text and images including image descriptions, links, schedules, approval names and comments, decision timestamps and hashed request identifiers, publishing history and operational metadata. Customer must not use the service to process special-category or criminal-offence data without a separate written agreement covering appropriate safeguards.

Data subjects: Customer staff and contractors, client reviewers and contacts, social account holders and people depicted or mentioned in Customer content.

Annex 2 — Technical and organisational measures

  • Hosting: application services run on the Sandy infrastructure with Hetzner in Germany. Provider physical access controls protect the hosting facilities.
  • Access separation: authenticated sessions, workspace membership checks, owner/editor roles, scoped API keys and resource ownership checks restrict application access.
  • Credentials and transport: HTTPS protects public service traffic. Connected-channel credentials and webhook signing credentials are encrypted with AES-256-GCM; API keys are stored as hashes. Administrative secrets are kept outside the source repository.
  • Safe publication: database transactions, row locks, bounded retries, history and uncertain-result review reduce accidental duplicate or unauthorised publication.
  • Application controls: request validation, rate limits, DNS-checked outbound requests and restricted redirects reduce abuse. Logs avoid credential values and remote response bodies.
  • Operations: access is limited to authorised operators. Changes are versioned and checked with automated tests. Incidents and data requests are handled through the privacy contact. No independent security certification or particular recovery-time guarantee is represented by this annex.

Annex 3 — Providers and recipients

  • Hetzner: infrastructure hosting in Germany; stores and processes application data as hosting provider.
  • Stripe: subscription administration, payment and invoice processing; receives billing/account identifiers, not scheduled post content as part of normal billing. Its role also includes independent controller obligations for payments, fraud prevention and legal compliance.
  • Google: only when Customer users choose Google sign-in; exchanges identity and authentication information. Google’s own account services are also governed by its terms.
  • Connected social networks: only those selected by Customer (currently Bluesky, the selected Mastodon instance and Telegram); receive the content and account instructions sent to them. X, Threads, LinkedIn and Instagram/Facebook are in preparation and receive no posts until enabled and connected. Network operators may process published content globally as independent controllers.
  • Customer-selected alert destinations: Slack, Discord or a Mattermost operator, only when configured; receive event notices and links, without the body of scheduled posts. Their independent terms and Customer’s configuration govern access in the destination.

Contact for instructions, incidents, audit information and data requests: info@productivity-boost.com.

The accepted version and acceptance time are available in workspace legal settings. This agreement can be saved using your browser’s Print / Save as PDF command.

SocialMint

Social scheduling and client approvals for agencies.

Made in Passau, Germany

FeaturesInteractive demoPricingRoadmapHelp centerAPI docs
ImpressumPrivacy PolicyTerms of ServiceData Processing AgreementContact
CompareHootsuite alternative for agenciesPostiz alternative

© 2026 productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG