Before you sign this: this is a standard-form template, not a substitute for your own legal counsel's review. If your organization requires specific clauses (a particular sub-processor list format, region-locked hosting, a named Data Protection Officer, breach-notice windows tighter than 72 hours, etc.), have your lawyer mark this up before either party signs. Request a countersigned copy at support@droppost.ai.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified at signup ("Customer," "Controller") and Nameless Investments, Inc., operating as DropPost ("DropPost," "Processor"), governing DropPost's processing of personal data on Customer's behalf in connection with the DropPost service (the "Service").
1. Definitions
"Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in the EU General Data Protection Regulation (GDPR) and, where applicable, equivalent US state privacy laws (e.g., the CCPA/CPRA). "Customer Personal Data" means Personal Data submitted to or processed by the Service on Customer's behalf, as described in Section 2.
2. Subject Matter, Nature, and Purpose of Processing
DropPost processes Customer Personal Data solely to provide the Service: connecting to Customer's Dropbox account and social media accounts, analyzing media Customer uploads, generating captions, and publishing that content to the social accounts Customer connects. Processing is automated (file analysis, AI captioning, publishing) and continues for the duration of Customer's subscription.
3. Categories of Data Subjects and Personal Data
The Personal Data DropPost processes under this DPA is limited to:
- Customer's own account data - business name, contact email, and login credentials of the individual(s) Customer authorizes to use the Service.
- Connected-platform metadata - the display name and platform-assigned account identifier of each social media account and Dropbox account Customer connects (not the underlying platform account holder's broader personal data).
- Content Customer chooses to upload - photos, videos, and any personal data incidentally contained within them (e.g., a person's likeness in a photo Customer posts). DropPost does not analyze this content for any purpose beyond generating a caption and does not use it to identify or profile any individual.
DropPost does not knowingly process special categories of data (health, biometric, etc.) and Customer agrees not to submit such data through the Service.
4. Processor Obligations
DropPost shall:
- process Customer Personal Data only on documented instructions from Customer (including this DPA and Customer's configuration of the Service), unless required otherwise by law;
- ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations;
- implement the technical and organizational security measures described in Section 7;
- assist Customer, at Customer's reasonable request, in responding to Data Subject rights requests and in Customer's own compliance obligations under applicable law (Sections 8-9);
- make available to Customer the information reasonably necessary to demonstrate compliance with this DPA.
5. Sub-processors
Customer authorizes DropPost to engage the following categories of sub-processors, each bound by data protection terms materially no less protective than this DPA:
- Infrastructure hosting - Liquid Web (application server hosting).
- AI captioning - OpenAI, when Customer selects cloud-based captioning in Settings (Customer may instead select locally-processed captioning, which does not use this sub-processor).
- Payment processing - Stripe, Inc. (billing and card data; DropPost never stores card numbers itself).
- Transactional email - Google Workspace (account, billing, and failure-notification email delivery).
DropPost will provide at least 14 days' notice (via email to Customer's account contact) before adding or replacing a sub-processor materially affecting the processing of Customer Personal Data, during which Customer may object on reasonable data-protection grounds.
6. International Data Transfers
DropPost's infrastructure is hosted in the United States. Where Customer Personal Data originates in the European Economic Area, United Kingdom, or Switzerland, the parties agree that the Standard Contractual Clauses (Module 2: Controller to Processor), as adopted by the European Commission, are incorporated into this DPA by reference and apply to such transfers.
7. Security Measures
DropPost maintains technical and organizational measures appropriate to the risk, including: encryption of connected-platform access tokens at rest; encrypted transport (TLS) for all Service traffic; access to production systems restricted to authorized personnel; and regular review of the publishing pipeline for the class of reliability issue that could affect data integrity (e.g., duplicate or failed publishes).
8. Data Subject Rights
DropPost will assist Customer in fulfilling its obligation to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, objection) under applicable law, to the extent Customer cannot independently fulfill such a request through the Service's own self-serve tools (Settings' data export, and account deletion as described at droppost.ai/data-deletion.html).
9. Personal Data Breach Notification
DropPost will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data, providing the information reasonably available at the time and reasonable cooperation in Customer's own breach-notification obligations.
10. Audit Rights
DropPost will make available to Customer, on reasonable written request no more than once per 12-month period, information reasonably necessary to demonstrate compliance with this DPA. DropPost may satisfy this through a written response, documentation, or (for an on-site or third-party audit, at Customer's expense) a mutually scheduled review.
11. Return or Deletion of Data
On termination of the Service, Customer may export its data at any time before termination via Settings, or request deletion as described at droppost.ai/data-deletion.html. Following a verified deletion request, DropPost deletes Customer Personal Data within the timeframe stated on that page, except billing records DropPost is required to retain for tax or legal purposes.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the underlying agreement between the parties (DropPost's Terms of Service).
13. Term
This DPA takes effect on the date Customer's underlying agreement with DropPost takes effect and remains in effect for as long as DropPost processes Customer Personal Data under that agreement.
Questions
Email support@droppost.ai with questions about this DPA or to request a countersigned copy.
