Legal

Data Processing Agreement (DPA)

This Data Processing Agreement applies where PostMint processes personal data on behalf of a business customer (the controller) and forms part of the Terms of Service. It is drafted to meet Article 28 GDPR.

Last reviewed: [TO BE COMPLETED]

1. Subject matter and duration

PostMint processes personal data on the customer's behalf in order to provide the PostMint service. Processing lasts for as long as the customer's account exists, plus any short period needed to complete deletion or to comply with a legal obligation.

2. Nature and purpose of processing

Hosting, storing, organising, generating, adapting, transmitting, scheduling, publishing to platforms selected by the customer, supporting the customer and securing the service.

3. Categories of personal data

  • Account and contact details of the customer's users.
  • Business information the customer enters, including Brand Profile content.
  • Content, captions, prompts, uploaded photos and publishing history, which may contain personal data such as images of identifiable people or names in captions.
  • Social account identifiers and access tokens for the platforms the customer connects.
  • Technical and log data generated by use of the service.

4. Categories of data subjects

  • The customer's own staff and account users.
  • The customer's clients, guests or audience where they appear in submitted or generated content.
  • People who interact with the customer's published content.

5. Processing on documented instructions

PostMint processes personal data only on the customer's documented instructions, which include the Terms of Service, this DPA, the settings the customer chooses and the actions the customer takes in the product. PostMint will inform the customer if, in its opinion, an instruction infringes data protection law, and will not use the customer's personal data for its own unrelated purposes.

6. Confidentiality

PostMint ensures that persons authorised to process the customer's personal data are bound by confidentiality and process it only as needed to perform their role.

7. Technical and organisational measures

PostMint implements appropriate technical and organisational measures having regard to the state of the art, the costs of implementation and the risks involved. The measures currently in place are described on the Trust & Security page.

Confirm before publishing. Attach or restate your final security measures here (Annex II style) once verified. Do not claim measures that are not implemented.

8. Subprocessors

The customer gives general authorisation for PostMint to engage subprocessors for hosting, payment processing, email delivery, AI generation and similar functions. PostMint imposes data protection obligations on each subprocessor that are no less protective than this DPA, remains responsible for their performance, and will inform the customer of intended changes so the customer can object.

9. Subprocessor list

  • Hosting / infrastructure: [TO BE COMPLETED] — role: running the application and database — location: [TO BE COMPLETED]
  • Payment processing: [TO BE COMPLETED] — role: subscription payments and invoices — location: [TO BE COMPLETED]
  • Email delivery: [TO BE COMPLETED] — role: account, trial and support email — location: [TO BE COMPLETED]
  • AI content generation: [TO BE COMPLETED] — role: generating text, analysing selected photos, generating visuals — location: [TO BE COMPLETED]
  • Analytics: [TO BE COMPLETED] — role: website usage statistics (consent-based) — location: [TO BE COMPLETED]

Confirm before publishing. Complete this list with the actual provider names, roles and processing locations before launch. Keep it versioned so customers can see changes.

10. International transfers

Where a subprocessor processes personal data outside the EEA, PostMint puts an appropriate GDPR transfer mechanism in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any supplementary measures required.

11. Assisting with data subject requests

PostMint provides the customer with the functionality and, where needed, reasonable assistance to respond to requests for access, rectification, erasure, restriction, portability and objection. If a data subject contacts PostMint directly about the customer's data, PostMint refers them to the customer.

12. Personal data breaches

PostMint notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's personal data, provides the information reasonably available to support the customer's own notification duties, and takes reasonable steps to mitigate the breach.

13. DPIAs and prior consultation

On request, and taking into account the nature of processing and the information available to it, PostMint provides reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority.

14. Deletion or return after termination

On termination the customer may export their data from the product. After termination, PostMint deletes the customer's personal data from live systems, except to the extent storage is required by law. Backups are removed on their normal cycle.

Confirm before publishing. State the concrete deletion and backup-cycle timelines once your infrastructure is final.

15. Audits and information rights

PostMint makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and allows for audits, including inspections, by the customer or an independent auditor mandated by the customer, subject to reasonable notice, confidentiality, and protection of other customers' data and of PostMint's security.

16. Order of precedence

If this DPA conflicts with the Terms of Service in relation to processing personal data on the customer's behalf, this DPA prevails.

Contact

To request a signed copy of this DPA, contact mint@postmint.nl.

Review and updates

We may update this document when the service, the law or our providers change. The version on this page is always the current one. Where a change materially affects you, we will inform you by email or in the app.

Confirm before publishing. Legal review pending: have this document checked by a qualified Dutch/EU adviser before launch, and set the 'last reviewed' date in /app/frontend/src/data/legal.js.

PostMint · postmint.nl · mint@postmint.nl · Registered in the Netherlands · KVK 42148900