Data Processing Addendum
Effective date: 28 July 2026
This Data Processing Addendum ("DPA") forms part of the agreement between My Viral Vault LTD, trading as Postia ("Postia", "Processor"), and the customer entity agreeing to Postia's Terms of Service ("Customer", "Controller"), together the "Parties". It applies where Postia processes personal data on the Customer's behalf as part of providing the Postia service (the "Service").
If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the UK GDPR and, where applicable, the EU GDPR ("Data Protection Laws").
"Sub-processor" means any third party engaged by Postia to process personal data in connection with the Service.
2. Roles of the Parties
For personal data processed through the Service, the Customer is the Controller and Postia is the Processor. The Customer determines the purposes and means of processing (e.g. which Etsy listings to import, which Pinterest account to connect); Postia processes personal data only on the Customer's documented instructions, as set out in this DPA and the Terms of Service.
Where personal data appears incidentally within Customer-uploaded content (for example, a customer name inside an Etsy listing description or review screenshot), the Customer remains the Controller of that data, and warrants it has a lawful basis to share it with Postia for processing.
3. Subject Matter, Duration, Nature and Purpose of Processing
| Subject matter | Provision of the Postia Pinterest scheduling and automation Service |
| Duration | For the term of the Customer's subscription, plus any post-termination retention period described in Section 9 |
| Nature of processing | Collection, storage, import, transformation (into pin content), transmission to Pinterest, and deletion of Customer data |
| Purpose | To generate, schedule, and (upon Customer approval) publish pins to the Customer's connected Pinterest account, and to operate, secure, and support the Service |
4. Categories of Data Subjects and Personal Data
Categories of data subjects:
- The Customer's own personnel/authorised users of the account
- Individuals whose personal data may incidentally appear within Customer-uploaded Etsy/product listing data (e.g. named in a review, testimonial, or custom product text)
Categories of personal data:
- Account contact details of the Customer's authorised users (name, email)
- Pinterest account data accessed via OAuth (username, profile information, board and pin data) to the extent necessary to provide the Service
- Content of Customer-uploaded CSV/listing exports, which may incidentally include personal data as described above
Postia does not intentionally process special category data (as defined under Data Protection Laws) and the Customer agrees not to upload such data via the Service.
5. Postia's Obligations as Processor
Postia shall:
- Process personal data only on the Customer's documented instructions (including this DPA and the Terms of Service), unless required to do otherwise by law, in which case Postia will inform the Customer before processing (unless legally prohibited from doing so)
- Ensure personnel authorised to process personal data are subject to confidentiality obligations
- Implement appropriate technical and organisational security measures, including encryption in transit, access controls, and secure hosting via Postia's infrastructure providers
- Assist the Customer, insofar as reasonably possible, in responding to data subject rights requests and in meeting the Customer's obligations regarding security, breach notification, and data protection impact assessments, taking into account the nature of processing and information available to Postia
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data
- At the Customer's choice, delete or return all personal data to the Customer at the end of the provision of the Service, and delete existing copies unless applicable law requires storage (see Section 9)
- Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and confidentiality
6. Sub-processors
The Customer provides general authorisation for Postia to engage the sub-processors listed below to provide the Service. Postia will impose data protection terms on sub-processors that offer at least the same level of protection as this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Replit | Application hosting and infrastructure | United States |
| Stripe | Payment processing | Global (US-headquartered) |
| Google LLC | Website and product analytics (Google Analytics) | Global (US-headquartered) |
| ConvertKit | Transactional and marketing email delivery | United States |
| Publishing approved pins to the Customer's own connected account | Global (US-headquartered) |
Postia will give the Customer reasonable notice (e.g. via email or a notice on our website) before appointing a new sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Parties cannot resolve the objection, the Customer may terminate the affected part of the Service.
7. International Data Transfers
Where personal data is transferred outside the UK or EEA (including to sub-processors in the United States), Postia will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or the recipient's adherence to an approved certification framework.
8. Assistance with Data Subject Requests
If Postia receives a request from a data subject relating to personal data processed on the Customer's behalf, Postia will promptly forward it to the Customer and will not respond directly except to confirm receipt and redirect the requester, unless legally required to do otherwise.
9. Deletion and Retention on Termination
Upon termination or expiry of the Customer's subscription, Postia will delete Customer personal data (including Etsy listing data and Pinterest account tokens) within a reasonable period, except where retention is required by law (for example, billing records for tax purposes) or for the establishment, exercise, or defence of legal claims.
10. Liability
Each Party's liability arising under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
11. Governing Law
This DPA is governed by the same governing law as the Terms of Service (the laws of England and Wales).
12. Contact
Data protection queries relating to this DPA:
Email: support@getpostia.com