Effective date: April 11, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Controller” or “Customer”) and OpenPost (“Processor”) and governs the processing of personal data that you entrust to us through your use of the OpenPost platform.
This DPA is designed to satisfy the requirements of Article 28 of the General Data Protection Regulation (GDPR) and equivalent provisions in other applicable data protection legislation.
You are the data controller. You decide what content to create, which platforms to publish to, and what data to store in OpenPost. We are the data processor. We process your data solely to provide the OpenPost service as described in our Terms of Service.
The categories of Personal Data processed may include: names, email addresses, social media usernames and profile information, content authored by you, media files you upload, and analytics data from connected platforms.
Data subjects may include: your employees, team members, contractors, and the audiences of your social media accounts (to the extent that engagement data contains identifiable information).
As your data processor, OpenPost will:
We use the following sub-processors to deliver the OpenPost service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting, authentication | United States |
| Cloudflare | Media file storage (R2), CDN | Global |
| Vercel | Application hosting | United States |
| Stripe | Payment processing | United States |
We will notify you before adding or replacing a sub-processor, giving you the opportunity to object. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.
If we become aware of a personal data breach that affects data we process on your behalf, we will:
Where Personal Data is transferred outside the EEA, we ensure that appropriate safeguards are in place. These may include Standard Contractual Clauses (SCCs) adopted by the European Commission, adequacy decisions, or other transfer mechanisms recognized under GDPR.
This DPA remains in effect for the duration of your OpenPost subscription. Upon termination, we will delete your Personal Data in accordance with the timelines described in our Privacy Policy (within 30 days, with backup purges within 90 days).
For questions about this DPA or to exercise rights under it, contact: