1. Roles and scope
The Customer is the data controller and FLOPOST, LLC ("FloPost") is the data processor for personal data processed in connection with the Customer's use of the Service, including followers, commenters, DM recipients, and team members that the Customer manages through FloPost.
2. Processor obligations (GDPR Article 28)
- Process personal data only on documented instructions.
- Maintain confidentiality of personnel with access.
- Implement appropriate technical and organizational security measures (encryption in transit and at rest, role-based access, least privilege).
- Notify the Customer without undue delay (and in any event within 72 hours) of any confirmed personal-data breach.
- Assist the Customer in responding to data-subject requests.
3. Subprocessors
FloPost engages subprocessors as described in our privacy policy. Material changes to this list are posted on our privacy policy page at least 30 days before they take effect, and a Customer may object on reasonable documented grounds.
4. International transfers
Where personal data is transferred out of the EEA, UK, or Switzerland, FloPost relies on the European Commission's Standard Contractual Clauses (2021/914) and, where applicable, the UK International Data Transfer Addendum.
5. Return and deletion of data
The Customer can download its data at any time in the FloPost app under Settings > Download my data, and delete it at once under Settings > Delete my account; a request emailed to support@flopost.ai is carried out within 7 days. Deleted data is gone from our database and file storage, the 7-day undo copy included, within 7 days, except the few records our privacy policy lists as kept after an account is deleted.
6. How to execute
Customers on paid plans can execute this DPA by emailing support@flopost.ai; we countersign and return a PDF.
Last updated: September 26, 2026