Data processing agreement

Data processing terms for customer content

This DPA applies automatically when a business customer uses Postiva to process personal data on its behalf.

Last updated 11 August 2026

1. Scope and roles

This DPA forms part of the Terms of Service between the customer and Webdevamin, trading as Postiva. It applies when Postiva processes personal data contained in customer content on the customer's documented instructions.

The customer is controller and Postiva is processor for that data. Each party remains independently responsible for personal data it processes for its own account, such as business contact, billing, security, or legal records.

2. Processing details

  • Subject matter: hosting, extracting, generating, rendering, organising, sharing, and delivering customer content through Postiva.
  • Duration: for the service term and the deletion or recovery periods described in the Privacy Policy.
  • Nature and purpose: content repurposing, team collaboration, client review, storage, support, security, and customer-requested output generation.
  • Data subjects: customer users, staff, clients, prospects, website authors, content subjects, and other people represented in submitted material.
  • Data types: names, contact details, online identifiers, professional details, source text, images, audio, video, comments, and any other data the customer chooses to submit.
The service is not intended for special-category data, criminal-offence data, children's data, or high-risk identity and financial records. Customers must not submit such data unless they have first confirmed that the use is lawful and appropriate.

3. Customer instructions

Postiva processes customer personal data only to provide the service, follow product settings and support requests, comply with this DPA, or meet applicable law. The customer instructs Postiva through its use of features, account configuration, and written support requests.

Postiva will inform the customer if an instruction appears to violate applicable data protection law, unless law prohibits that notice. The customer is responsible for lawful collection, notices, legal bases, data accuracy, and responding to data subjects.

4. Confidentiality and security

People authorised to process customer data are bound by confidentiality. Postiva maintains measures appropriate to the service risk, including encrypted transport, access controls, private object storage, password hashing, team-level authorisation, audit-relevant application records, CSRF protection, throttling, and optional multi-factor authentication.

The customer must secure accounts, restrict team access, manage API tokens, review public approval links and marketplace publication, and avoid unnecessary personal data.

5. Subprocessors

The customer gives general authorisation for Postiva to use subprocessors needed to provide the service. Current core subprocessors include:

Legal entityService and dataProcessing countriesTransfer mechanism
OpenAI Ireland Ltd.AI text, image, style and speech processing: prompts, selected source material, references and outputIreland and affiliate or subprocessor locations, including the United StatesEEA contract; EU SCCs and supplementary measures for restricted onward transfers
Hetzner Online GmbHApplication server and database infrastructureSelected EU datacentre and EU supportNo Chapter V transfer for EU-only configuration
Ploi, Dutch Chamber of Commerce 94117233Server management and deployment metadataEuropean UnionNo Chapter V transfer for EU processing
Cloudflare, Inc.Network security, delivery and private R2 object storageGlobal network, including the EEA and United StatesEU-US Data Privacy Framework where applicable, otherwise EU SCCs and supplementary measures
Amazon Web Services EMEA SARLSES transactional email content and delivery metadataIreland region, with limited global support or subprocessor accessEEA processing where applicable; AWS DPA safeguards and EU SCCs for restricted transfers

Postiva remains responsible for subprocessor obligations to the extent required by Article 28 GDPR. New or replacement subprocessors will be announced through this page or the service at least 30 days before access to customer personal data. A customer with a reasonable data-protection objection should contact [email protected] during that notice period. Postiva will assess the documented objection and try a reasonable alternative. If no workable alternative exists, the customer may stop the affected processing and terminate that use.

6. International transfers

When personal data is transferred outside the European Economic Area without an adequacy decision, Postiva will use the EU Standard Contractual Clauses or another lawful transfer mechanism and take supplementary measures where appropriate. The customer authorises Postiva to enter those safeguards on its behalf where needed for subprocessing.

7. Assistance

Taking account of the processing and information available, Postiva will reasonably assist the customer with data subject requests, security obligations, breach notifications, impact assessments, and prior consultation. If a data subject contacts Postiva about customer-controlled data, the request will be referred to the customer unless Postiva is legally required to respond.

8. Personal data breaches

Postiva will notify the customer without undue delay after becoming aware of a personal data breach affecting customer-controlled data. Available information about the nature; affected data-subject and record categories and approximate numbers; contact point; likely consequences; and measures taken or proposed to contain and mitigate the breach will be supplied as it becomes known. Information can be supplied in phases when it is not available at once. Notification does not admit fault or liability.

Dedicated incident contact: [email protected], with “Security incident” in the subject.

9. Return and deletion

Customers can delete projects and assets through the service. When an account is closed, recoverable personal-team data is retained for up to 30 days and then purged, subject to limited backups, legal obligations, disputes, and billing records. Shared-team data remains under the control of that team's owner.

On written request at the end of the service, Postiva will delete or return customer personal data where technically available, unless Union or Member State law requires retention.

10. Information and audits

Postiva will provide information reasonably necessary to demonstrate Article 28 compliance. Audits should first use current documentation and written questions. If those are insufficient, the customer may request a proportionate audit with reasonable notice, during business hours, under confidentiality, and without compromising other customers or system security. The customer bears audit costs unless the audit identifies a material breach by Postiva.

11. Order and governing law

If this DPA conflicts with the Terms on personal-data processing, this DPA controls. The governing law and dispute provisions in the Terms apply. The current EU Standard Contractual Clauses control over inconsistent commercial terms where they apply.

Annex 1. Technical and organisational measures

  • Access and identity: named accounts, password hashing, role and team checks, optional passkeys and two-factor authentication, and password confirmation for sensitive settings.
  • Tenant separation: application-level authorisation scopes customer and team records. Private downloads use authorisation and time-limited signed links.
  • Transmission and files: encrypted HTTPS transport in production and non-public object storage for customer assets.
  • Availability: infrastructure monitoring, provider backups, job retries, and recovery procedures appropriate to the service.
  • Operations: dependency patching, restricted production access, logging, abuse throttling, incident handling, and scheduled retention cleanup.
  • Deletion: project deletion, account recovery followed by purge, expiring exports and review links, and deletion processes that account for backup rotation and legal holds.
  • Testing: automated authorisation, isolation, validation, retention, and public-link tests, with security review proportionate to material changes.

Annex 2. Standard clauses

The controller-to-processor clauses in Commission Implementing Decision (EU) 2021/915 are incorporated only where the parties expressly select and execute them. They do not by themselves legalise an international transfer. For an actual restricted transfer, the applicable module of Decision (EU) 2021/914, its annexes, and the relevant transfer assessment must be completed separately.