Skip to content

Data Processing Agreement

Article 28 GDPR terms for customers that use Selfpost to process personal data as controllers. Effective 1 September 2026.

1. Parties and application

This DPA forms part of the Selfpost Terms between the customer as controller and Tim Hausl-Kramper, trading as THK-Media, as processor. It applies where Selfpost processes personal data on the customer's behalf, including agency and team workspaces.

If the customer is itself a processor, THK-Media acts as its subprocessor and references to controller instructions include the instructions of the relevant upstream controller.

2. Subject, duration, nature, and purpose

Processing consists of hosting, organising, adapting for technical delivery, scheduling, transmitting, publishing, retrieving status and analytics, supporting, securing, and deleting social-media content and workspace records. Processing lasts for the service term and any limited deletion or return period required by the Terms or law.

The purpose is to provide the Selfpost content workflow and connected-platform publishing functions selected and configured by the customer.

3. Data and data subjects

Data subjects may include the customer's staff, contractors, invitees, clients, social-account operators, people depicted or mentioned in uploaded content, commenters, and audience members represented in platform analytics.

Data may include identity and contact data, account and role data, social-platform identifiers, OAuth credentials, images, audio and video, captions and messages, schedules, audience and disclosure settings, publication status, analytics, support data, and technical diagnostics. The customer must not submit special-category or criminal-offence data unless expressly agreed and lawfully instructed.

4. Documented instructions

THK-Media processes data only on the customer's documented instructions, including the Terms, workspace configuration, API and interface actions, and support requests, unless Union or Member State law requires otherwise. If legally permitted, THK-Media will inform the customer before such mandatory processing.

THK-Media will promptly inform the customer if an instruction appears to infringe GDPR or other applicable data-protection law and may suspend that instruction while it is clarified.

5. Confidentiality and security

People authorised to process customer data are bound by confidentiality and receive access only as needed. THK-Media maintains measures appropriate under Article 32 GDPR, taking account of risk, implementation cost, and the state of the art.

Measures include tenant and role authorisation, encrypted provider tokens using authenticated encryption, hashed session and action tokens, private object storage and short-lived signed URLs, TLS, input validation, rate limiting, signed webhook verification, secrets separation, log redaction, audit trails, idempotent publishing, backups and recovery controls supplied by hosting providers, and procedures for access removal and deletion.

6. Subprocessors

The customer gives general authorisation for the subprocessors on the published Subprocessors page. THK-Media remains responsible for their data-protection obligations to the extent required by Article 28(4) GDPR.

THK-Media will give reasonable advance notice of a new subprocessor by email or a durable account notice. The customer may object on reasonable data-protection grounds within 14 days. The parties will seek a practical solution; if none is available, the affected service may be terminated without penalty for the unused prepaid period.

7. International transfers

THK-Media will not transfer customer personal data outside the EEA without a lawful Chapter V GDPR mechanism. Where no adequacy decision applies, the relevant European Commission Standard Contractual Clauses and necessary supplementary measures will be used.

A customer's instruction to publish to a connected platform includes an instruction to transfer the selected content to that platform. The customer remains responsible for deciding whether its use and instructions are lawful for the affected data subjects.

8. Data-subject requests and assistance

Taking account of the nature of processing, THK-Media will provide reasonable technical and organisational assistance for requests under GDPR Chapter III. If a request concerning customer-controlled data is received directly, THK-Media will forward it to the customer unless law permits or requires a direct response.

THK-Media will also reasonably assist with security, breach notification, data-protection impact assessments, and prior consultation under Articles 32 to 36, considering the information available to it.

9. Personal-data breaches

THK-Media will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled data. Available information will cover the nature of the breach, likely consequences, affected categories and approximate numbers where known, measures taken or proposed, and a contact point.

Notification is not an admission of fault. The customer remains responsible for notifications to supervisory authorities and affected persons unless the parties agree otherwise in writing.

10. Return and deletion

During the service term, available application functions allow deletion of relevant content. Export status: Signed-in users can download a machine-readable JSON export of their account, workspaces, posts, media metadata, and analytics from Account settings; requests for other formats are handled through the privacy contact. At the customer's choice and on termination, THK-Media will delete or return customer personal data and delete remaining copies, except where law requires retention. Backup status: database backups are rotated automatically; the deployment process retains the latest 14 pre-migration database dumps and older copies are overwritten.

Data already published to a social platform must be removed through that platform and is outside Selfpost's storage after transmission.

11. Information and audits

THK-Media will make information necessary to demonstrate Article 28 compliance available and allow reasonable audits by the customer or an independent auditor bound by confidentiality. Audits require reasonable advance notice, must minimise disruption, and should first use current documentation and third-party reports where sufficient.

The customer bears its audit costs unless an audit identifies a material breach by THK-Media. No audit may expose another customer's data, compromise security, or require access to provider systems beyond THK-Media's control.

12. Customer obligations and order of precedence

The customer is responsible for lawful instructions, transparency, legal bases, data accuracy, role assignment, and responding to data-subject requests. The customer must use available controls and must not provide data that is unnecessary for the service.

For processing matters, this DPA prevails over conflicting Terms. The remainder of the Terms, including lawful liability provisions, continues to apply. Austrian law and the jurisdiction provisions in the Terms govern, without restricting data subjects' or supervisory authorities' mandatory rights.