1. Roles
You (the customer) are the data controller of the personal data you enter into the platform (e.g. names and contacts of your clients, any personal data in the content, the data of the social accounts you connect).
appost.io (Francesco Checchia, sole proprietorship under Italian law) is the processor under Art. 28 GDPR. It processes your data only to provide you the service, on documented instructions (these terms + DPA).
2. Subject matter
- Categories of data subjects: you, your team members, your clients (if you are an agency), the recipients of the posts you publish.
- Types of personal data: account data, professional contacts, editorial content, data from the connected social platforms (encrypted tokens, Page/account identifiers, imported recent content, metrics), audit log.
- Processing operations: hosting, AI processing, scheduling, publishing, analytics, audit, backup.
- Duration: while the contract is active; on closure, a 7-day grace period and then deletion (see section 8).
3. Processing locations and transfers
The platform infrastructure consists of servers operated by the controller in Germany (European Union): the database, file and content storage, queues and cache reside in the European Union. Encrypted offsite backups are kept on Backblaze B2 (USA), encrypted on the controller's side, so the provider cannot access the data in clear. Transactional emails are sent through a self-hosted mail server in the EU.
For AI generation and brand-profile enrichment, some data (the content you submit for processing and the public content read at your request) is transmitted to providers located in third countries, in particular the United States. Such transfers are covered by the EU Standard Contractual Clauses (SCC) 2021/914. Content is transmitted solely to produce the requested result and for the service's purposes (see section 5).
4. Technical and organizational security measures
Encryption
- TLS in transit.
- AES-256 at rest (database, storage, backups).
- Social platform OAuth tokens encrypted separately with AES-256-GCM, never returned by the app's interfaces.
- Passwords protected with bcrypt (cost factor 12); no plaintext passwords.
Access and isolation
- Per-customer (tenant) data isolation enforced at the database level (Row-Level Security).
- Immutable audit log of relevant operations.
- Staff access to customer data on a least-privilege basis, only when needed for support.
Resilience
- Encrypted backups, stored offsite and rotated periodically.
- Database replica within the EU perimeter.
5. Authorized sub-processors
Declared by category; an up-to-date named list is available on request to dpo@appost.io. Advance notice for new categories, with a right to object and to terminate if a sub-processor is not acceptable.
- AI model providers (USA, third country) — text generation, content embeddings, image generation and moderation, routed through an AI model gateway. Transfer safeguard: EU SCC 2021/914 + data minimization.
- Web search and reading providers (USA and other third countries) — market research and reading of the brand's website to enrich the editorial profile, on your action. Transfer safeguard: EU SCC 2021/914.
- CDN, DNS and perimeter protection (global network with an EU point of presence) — content delivery, anti-abuse and DDoS protection, DNS. Transfer safeguard: EU SCC 2021/914.
- Encrypted offsite backup (USA, third country) — storage of encrypted backup copies outside the primary cluster. Transfer safeguard: EU SCC + controller-side encryption (the provider cannot access the data in clear).
Transactional email: a self-hosted mail server in the European Union, operated by the controller — not an external sub-processor.
Payments: during the preview no payment provider is active. When we introduce subscriptions, the payment provider will be added as a processor (with relevant safeguards) and listed here.
The platforms you publish to (Meta, LinkedIn, WordPress) are not sub-processors: they are destinations you choose, on your own accounts.
6. Data breach
In the event of a personal data breach posing a risk to your data, we notify you without undue delay and in any case within 72 hours of discovery (Art. 33 GDPR). The notice includes: the nature of the breach, the data affected, the measures taken, and the DPO contact.
7. Audit & inspection
You have a right to audit (Art. 28(3)(h) GDPR), by appointment and in ways that do not compromise operations or the security of other customers. On request, we provide documentation on the technical and organizational measures in place.
8. Data deletion at the end of the contract
- 7-day grace period from account closure, during which you can regain access.
- Permanent deletion of working data at the end of the grace period.
- Encrypted backups overwritten on the rotation cycle.
- Anonymized billing skeleton kept for 10 years (Art. 2220 of the Italian Civil Code) once payments exist — stripped of name, email and direct identifiers.
- Social platform data: Meta's data-deletion request (https://api.appost.io/oauth/meta/data-deletion) deletes connections, imported historical posts, and social-derived voice examples with their vector representations. Details in the privacy policy.
9. Full document
This is the summary. The full, signable DPA is available on request; for plans involving third-party personal data it is an integral part of the service contract.