Legal

Data Processing Agreement

Template effective: June 8, 2026 ·  GDPR Article 28 compliant

How to execute this DPA

This page contains the standard terms of our Data Processing Agreement. To execute a signed DPA for your organisation, email privacy@cloutbox.ai with subject "DPA Request" and your organisation name. We will send you a countersigned PDF within 5 business days. Enterprise customers may negotiate custom terms.

This Data Processing Agreement ("DPA") is entered into between Cloutbox Inc.("Processor") and the customer organisation identified in the applicable Order Form or subscription agreement ("Controller").

Annex 1 — Details of Processing

Subject matterProcessing of personal data of the Controller's end users in connection with the provision of the Cloutbox social media management platform.
DurationFor the term of the subscription agreement plus any post-termination period during which the Processor retains data per the Privacy Policy retention schedule.
Nature of processingStorage, retrieval, transmission, display, analysis, and deletion of personal data as instructed by the Controller through use of the Service.
Purpose of processingTo provide the Service: scheduling and publishing social media content, managing messages, delivering analytics, and enabling team collaboration on behalf of the Controller.
Types of personal dataSocial media profile identifiers, usernames, message content, post metadata, engagement metrics, and any other personal data contained in content the Controller manages through the Service.
Categories of data subjectsThe Controller's customers, followers, subscribers, and end users whose data is accessible via connected social media platform accounts managed by the Controller.

1. Processor Obligations

The Processor shall, in relation to any personal data processed in connection with the performance of its obligations under this DPA:

  • Instructions: process personal data only on documented instructions from the Controller (including as set out in the subscription agreement and the Service itself). If required by applicable law, the Processor will inform the Controller before carrying out processing contrary to instructions, unless prohibited from doing so.
  • Confidentiality: ensure that persons authorised to process personal data are subject to a binding duty of confidentiality.
  • Security: implement and maintain the technical and organisational security measures described in Annex 2 of this DPA and in the Security Policy.
  • Sub-processors: not engage any sub-processor without the Controller's general or specific written authorisation. The Controller provides general authorisation for the sub-processors listed in Annex 3. The Processor will notify the Controller of any intended changes (addition or replacement) to sub-processors at least 30 days in advance, giving the Controller the opportunity to object.
  • Data subject rights: assist the Controller in fulfilling its obligations to respond to requests for exercising data subjects' rights (access, rectification, erasure, portability, restriction, objection). The Processor will forward any requests received directly from data subjects to the Controller within 5 business days.
  • Data protection impact assessments: assist the Controller, at its cost, with conducting DPIAs and prior consultations with supervisory authorities where required by Article 35-36 GDPR.
  • Deletion / return: at the Controller's choice, delete or return all personal data to the Controller at the end of the service term, and delete existing copies, unless applicable law requires retention. The Controller's deletion request must be submitted within 30 days of termination.
  • Audit rights: make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the Controller or an independent auditor appointed by the Controller, subject to reasonable notice (at least 30 days), confidentiality obligations, and the Controller bearing audit costs.

2. Controller Obligations

  • Ensure that the transfer of personal data to the Processor is lawful, including obtaining any necessary consents from data subjects.
  • Maintain accurate records of processing activities under Article 30 GDPR.
  • Promptly notify the Processor of changes in applicable laws that may affect processing.
  • Be responsible for the accuracy and legality of personal data provided to the Processor.

3. Breach Notification

The Processor will notify the Controller without undue delay, and in any event within 24 hours of becoming aware of a personal data breach involving the Controller's data. Notification will include, to the extent available: the nature of the breach, categories and approximate number of data subjects affected, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.

The Controller is responsible for notifying the competent supervisory authority and affected data subjects as required by GDPR Articles 33-34, using the information provided by the Processor.

4. International Transfers

Where the processing involves a transfer of personal data outside the EEA, UK, or Switzerland, the parties agree that such transfers are governed by:

  • EEA to US: EU Standard Contractual Clauses (Module 2: Controller to Processor, 2021) supplemented by a Transfer Impact Assessment.
  • UK to US: UK IDTA (International Data Transfer Addendum to the EU SCCs) plus UK Transfer Risk Assessment.
  • Switzerland to US: Swiss nFADP SCCs.

The applicable SCCs and addenda are incorporated into this DPA by reference. Executed copies are available upon request at privacy@cloutbox.ai.

5. Liability

Each party's liability under this DPA shall be subject to the exclusions and caps in the Terms of Service, except where liability cannot be limited under applicable law (including GDPR). In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

Annex 2 — Technical and Organisational Security Measures

See our Security Policy for the full list. Key measures include:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls with principle of least privilege; privileged access logged and reviewed.
  • Encrypted storage of OAuth tokens.
  • Daily automated backups with 30-day retention and point-in-time recovery.
  • Annual third-party penetration testing.
  • Real-time security monitoring and incident response procedures.
  • Employee confidentiality agreements and data protection training.
  • Vulnerability management and dependency update programme.

Annex 3 — Authorised Sub-Processors

The Controller provides general authorisation for the following sub-processors:

Sub-ProcessorPurposeLocation / transfer mechanism
Supabase Inc.Database, authentication, file storageUS — SCCs
Vercel Inc.Hosting, CDN, serverless computeUS / EU — SCCs or EU region
Resend Inc.Transactional emailUS — SCCs
Inngest Inc.Background job processingUS — SCCs
Functional Software Inc. (Sentry)Error monitoringUS — SCCs
Stripe Inc.Payment processingUS / EU — SCCs or EU region

Request a Signed DPA

To receive a co-signed PDF of this DPA for your records:

privacy@cloutbox.ai

Include your organisation name and the email on your Cloutbox account. We respond within 5 business days.