1. Roles and scope
The Customer is the data controller and FloPost is the data processor for personal data processed in connection with the Customer's use of the Service, including followers, commenters, DM recipients, and team members that the Customer manages through FloPost.
2. Processor obligations (GDPR Article 28)
- Process personal data only on documented instructions.
- Maintain confidentiality of personnel with access.
- Implement appropriate technical and organizational security measures (encryption in transit and at rest, role-based access, least privilege).
- Notify the Customer without undue delay (and in any event within 72 hours) of any confirmed personal-data breach.
- Assist the Customer in responding to data-subject requests.
3. Subprocessors
FloPost engages subprocessors as described in our privacy policy. We notify Customers by email of material changes to this list at least 30 days in advance, and a Customer may object on reasonable documented grounds.
4. International transfers
Where personal data is transferred out of the EEA, UK, or Switzerland, FloPost relies on the European Commission's Standard Contractual Clauses (2021/914) and, where applicable, the UK International Data Transfer Addendum.
5. Return and deletion of data
On termination of the underlying Service contract, the Customer may request return or deletion of all Customer personal data within 30 days. After 90 days we delete backups containing the data unless retention is required by law.
6. How to execute
Customers on paid plans can execute this DPA by emailing admin@flopost.ai; we countersign and return a PDF.
Effective: April 2026