Skip to main content

Data Processing Addendum

Our GDPR Article 28 processor terms.

Effective: August 3, 2026Last updated: August 3, 2026

This Addendum forms part of the Terms of Service between Postlyo (“Processor”) and the customer (“Controller”). It applies where we process personal data on the customer’s behalf.

Where this Addendum conflicts with the Terms of Service in relation to the processing of personal data, this Addendum prevails.

Customers requiring a countersigned copy — as many enterprise and EU procurement processes do — should contact legal@postlyo.com.

1. Definitions

Data Protection Law means all laws applicable to the processing under this Addendum, including the EU General Data Protection Regulation (2016/679) (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss FADP, India’s Digital Personal Data Protection Act 2023, and US state privacy laws including the CCPA as amended.

Customer Personal Data means personal data contained in Customer Content or otherwise processed by us on the customer’s behalf. Controller, Processor, Data Subject, Processing, Personal Data Breach and Supervisory Authority have the meanings given in the GDPR. SCCs means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.

2. Roles

  1. Customer is the Controller of Customer Personal Data, including personal data of visitors to the customer’s Sites. We are the Processor.
  2. We are the Controller in respect of the customer’s own account, billing and usage data — governed by our Privacy Policy, not this Addendum.
  3. Where the customer is itself a processor for a third party, we are a sub-processor, and the customer warrants it has authority to appoint one on these terms.
  4. Neither party sells personal data, and neither shares it for cross-context behavioural advertising, as those terms are defined under the CCPA.

3. Scope of processing (Annex I)

FieldDetail
Subject matterProvision of the Postlyo hosted publishing service
DurationThe term of the Terms of Service, plus the retention periods in the Data Retention Policy
Nature and purposeHosting, storing, transmitting, rendering and delivering Customer Content and Sites; collecting and storing submissions made through Sites; providing dashboards, support and related functionality
Categories of data subjectCustomer's team members and authorised users; visitors, readers and commenters on Customer's Sites; individuals who submit contact forms; individuals identified in published content
Categories of personal dataIdentifiers (name, username, email); account and profile information; content submitted by data subjects including comments and enquiry messages; technical data including IP address, device and browser information; usage and interaction data
Special category dataNot intended or expected. Customer must not submit it without first notifying us and agreeing appropriate safeguards
Children's dataNot intended — see section 5.6
FrequencyContinuous, for the duration of the Terms

4. Our obligations

We will:

  1. Process only on documented instructions from the customer. The Terms, this Addendum, and the customer’s use of the Service’s features together constitute those instructions. We will process on another basis only where required by law, and will inform the customer beforehand unless the law prohibits it.
  2. Inform the customer if, in our opinion, an instruction infringes Data Protection Law.
  3. Ensure personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
  4. Implement appropriate technical and organisational measures under GDPR Article 32, as described in section 13.
  5. Engage sub-processors only as permitted by section 7.
  6. Assist the customer with data subject requests, per section 8.
  7. Assist the customer with data protection impact assessments and prior consultations, taking into account the nature of processing and the information available to us.
  8. Notify the customer of Personal Data Breaches per section 9.
  9. Delete or return Customer Personal Data at the end of the Terms, per section 10.
  10. Make available the information necessary to demonstrate compliance with Article 28 and allow audits, per section 11.

5. Customer's obligations

The customer:

  1. Is responsible for the lawfulness of the personal data it provides and the instructions it gives, and warrants it has a valid legal basis for the processing.
  2. Must provide any required notices to data subjects — including publishing an accurate privacy policy on each Site it operates.
  3. Must obtain any required consents — including, critically, consent for non-essential cookies and tracking before any analytics or advertising integration is activated for visitors in jurisdictions that require it. See our Cookie Policy.
  4. Is responsible for responding to its own data subjects' requests, complaints and enquiries.
  5. Must configure the Service appropriately, including access controls, team member permissions, and retention settings.
  6. Must not use the Service to process children's personal data where doing so triggers obligations we have not agreed to support, and must not enable behavioural advertising on Sites directed at children.
  7. Must not submit special category data without prior agreement.
  8. Must keep instructions lawful.

6. International transfers

  1. Customer Personal Data may be transferred to and processed in the countries identified in our sub-processor list.
  2. Where a transfer from the EEA is subject to Chapter V of the GDPR, the SCCs are incorporated by reference, with Module Two (controller to processor) applying where the customer is a controller and Module Three (processor to processor) where the customer is a processor; the customer as data exporter and us as data importer; Clause 7 (docking) applicable; Clause 9 Option 2 (general written authorisation) with the notice period in section 7.2; Clause 11 optional redress clause not applicable; Clauses 17 and 18(b) governed by the law and courts of [EU member state — to be completed by the website owner]; and Annexes I and II populated by sections 3 and 13 of this Addendum.
  3. For UK transfers, the International Data Transfer Addendum (Version B1.0) applies to the SCCs.
  4. For Swiss transfers, the SCCs apply with references to the GDPR read as references to the FADP.
  5. We will conduct transfer impact assessments where required and will notify the customer if we become unable to comply with the SCCs.

7. Sub-processors

  1. The customer gives general written authorisation for us to engage sub-processors.
  2. The current list is at Sub-processors. We will give at least 30 days’ notice before a new sub-processor begins processing.
  3. The customer may object on reasonable data-protection grounds within that notice period. The parties will discuss in good faith. If no resolution is reached, the customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid, unused fees.
  4. We impose on each sub-processor data protection obligations no less protective than those in this Addendum, and remain fully liable to the customer for the sub-processor’s performance.

8. Data subject rights

  1. The Service provides functionality enabling the customer to access, correct, export and delete Customer Personal Data.
  2. Where a data subject contacts us directly about data processed on a customer’s behalf, we will not respond substantively but will, where we can identify the relevant customer, forward the request and inform the data subject that we have done so.
  3. We provide reasonable assistance to help the customer respond within the statutory time limits. Assistance beyond the Service's standard functionality may be charged at our reasonable rates, on prior notice.

9. Personal data breaches

  1. We will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event in time to allow the customer to meet its own 72-hour notification obligation.
  2. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Information will be provided in phases if not all available at once.
  3. We will cooperate with the customer and take reasonable steps to mitigate.
  4. Notifying data subjects and supervisory authorities is the customer’s responsibility as controller, unless the parties agree otherwise.
  5. Our notification is not an admission of fault or liability.

10. Deletion and return

  1. On termination we will delete or return Customer Personal Data at the customer's election.
  2. The customer may export data during the window in our Data Retention Policy.
  3. After that window, we delete Customer Personal Data from live systems; residual copies in backups are deleted on the backup rotation cycle and are not accessed in the meantime.
  4. We may retain Customer Personal Data to the extent required by law — notably billing records for tax purposes — and will continue to protect it and process it only for that purpose.
  5. We will certify deletion in writing on request.

11. Audits

  1. We will make available the information reasonably necessary to demonstrate compliance with GDPR Article 28.
  2. We will first offer any available third-party audit reports, certifications, or a completed security questionnaire. The customer will accept these where they reasonably address its enquiry.
  3. Where they do not, the customer may conduct an audit, subject to: 30 days' prior written notice; no more than once in any 12-month period (unless required by a supervisory authority or following a Personal Data Breach); conduct during business hours without unreasonable disruption; a confidentiality undertaking; scope limited to Customer Personal Data and excluding other customers' data and information whose disclosure would compromise security; and the customer bearing its own costs and our reasonable costs.
  4. We will cooperate with a supervisory authority exercising its own audit powers.

12. Liability

Each party’s liability under this Addendum is subject to the limitations in Terms of Service section 16, except to the extent Data Protection Law prohibits limiting it. Nothing here limits a data subject’s rights against either party, or either party’s liability to a supervisory authority.

13. Annex II — Technical and organisational measures

AreaMeasure
EncryptionTLS for all data in transit; encryption at rest for stored data; adaptive salted hashing for account credentials; encryption of stored third-party integration credentials
PseudonymisationInternal identifiers used in place of direct identifiers where operationally feasible
ConfidentialityRole-based access control; authentication required for all non-public functionality; least-privilege internal access; logical tenant isolation enforced at the data-access layer; confidentiality obligations on personnel
IntegritySchema validation of input; sanitisation of user-generated content before rendering; parameterised database access; cryptographic verification of third-party callbacks; content revision history
Availability and resilienceManaged, redundant infrastructure; encrypted backups; availability and error monitoring with alerting
RestorationDocumented recovery procedures; regular backups per the Data Retention Policy
Testing and evaluationDependency tracking and patching; code review; vulnerability disclosure programme
Access to systemsProduction access limited to personnel who require it, and logged
TransfersSCCs and equivalent mechanisms per section 6
Sub-processor governanceAssessment and contractual flow-down per section 7
Incident managementDocumented incident response and notification procedure per section 9

Measures are described at a level appropriate for a contractual annex. Detailed configuration is withheld deliberately, as its disclosure would itself create risk. Further detail is available to customers under NDA on request.

14. Acceptance

This Addendum is incorporated into the Terms of Service and takes effect on the customer’s acceptance of those Terms. No separate signature is required.

15. Contact

PurposeContact
Data protectionprivacy@postlyo.com
Legal / countersigned copieslegal@postlyo.com
EU/UK representative (GDPR Art. 27)To be completed by the website owner.
Grievance Officer (India, DPDP Act)To be completed by the website owner.

This document is provided in English. If we publish a translation and there is a conflict, the English version governs unless local law requires otherwise.

View all legal documents