Data Processing Agreement
Last updated: 30 September 2026
This Data Processing Agreement (DPA) forms part of the Terms of Service (together with this DPA, the Agreement) between Postmind AI Ltd (we, us, the Processor) and the Customer (you, the Controller). It applies whenever we process Customer Personal Data on your behalf in providing PostMind Studio (the Service). It is accepted when you accept the Terms of Service; no separate signature is needed. Capitalised words not defined here have the meaning given in the Terms of Service.
1. Definitions
1.1 Data Protection Laws means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, and, where they apply to the processing, the EU General Data Protection Regulation 2016/679 (EU GDPR) and the laws of EU member states implementing or supplementing it, each as amended or replaced.
1.2 Customer Personal Data means personal data contained in Customer Content that we process on your behalf in providing the Service, as described in Annex 1.
1.3 Sub-processor means a third party we engage to process Customer Personal Data.
1.4 Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
1.5 Restricted Transfer means a transfer of Customer Personal Data to a country outside the UK (or, where the EU GDPR applies, outside the EEA) that is not covered by an adequacy decision or regulations.
1.6 controller, processor, data subject, personal data, processing and supervisory authority have the meanings given in the Data Protection Laws; for the UK, the supervisory authority is the Information Commissioner's Office (ICO).
2. Roles and scope
2.1 You are the controller, and we are the processor, of Customer Personal Data. Where you act as a processor for your own client (for example as an agency), you confirm that your client has authorised you to instruct us, and we are your sub-processor.
2.2 Personal data we process as a controller, such as account, billing, security and usage data about you and your Authorised Users, is covered by our Privacy Policy, not by this DPA.
2.3 The subject matter, duration, nature and purpose of the processing, and the types of personal data and data subjects, are set out in Annex 1.
3. Your responsibilities
3.1 You are responsible for the lawfulness of the processing you instruct, including having a lawful basis, giving data subjects the information they are entitled to, and obtaining any consents needed. In particular, where you use voice cloning or include an identifiable person's image or likeness, you are responsible for obtaining that person's explicit, informed and documented consent before uploading their voice samples, consent recording or image.
3.2 You will not instruct us to process special category data or criminal offence data except as strictly necessary for your lawful use of the Service (for example the voice samples and consent recording for a voice clone), and you will not include personal data of children in Inputs without a lawful basis and appropriate safeguards.
4. Our obligations as processor
4.1 Instructions. We will process Customer Personal Data only on your documented instructions, unless the law requires otherwise, in which case we will tell you before processing unless the law prohibits it. The Agreement, your configuration of the Service and the actions your Authorised Users take in it are your complete instructions. We will tell you promptly if we believe an instruction infringes Data Protection Laws.
4.2 Confidentiality. We will ensure that everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality and accesses it only as needed to provide, support or secure the Service or to comply with the law.
4.3 Security. We will implement and maintain the technical and organisational measures described in Annex 2, which are designed to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR. We may update those measures provided the overall level of protection is not reduced.
4.4 No other use. We will not sell Customer Personal Data, use it for our own purposes, or use it to train AI models.
5. Sub-processors
5.1 General authorisation. You give us general written authorisation to engage Sub-processors. Our current Sub-processors are listed on our Sub-processors page, which you have reviewed and approve.
5.2 Changes. We will tell you of any intended addition or replacement of a Sub-processor at least 30 days in advance by updating the Sub-processors page and notifying your Organisation's owners by email or in the Service. In an emergency (for example to keep the Service running when a provider fails) the notice may be shorter, and we will give it as soon as we can.
5.3 Objection. You may object to a new Sub-processor on reasonable data protection grounds by writing to support@postmindai.pro within the notice period. We will discuss your concerns in good faith and, where possible, offer a way to avoid the new Sub-processor processing your Customer Personal Data. If we cannot, you may end the affected part of the Agreement by notice before the change takes effect, and we will refund any prepaid Fees for the period after termination.
5.4 Flow-down. We will impose on each Sub-processor, by written contract, data protection obligations that offer at least the same level of protection as this DPA, and we remain liable to you for its performance of those obligations.
5.5 Connected Platforms and your own providers. TikTok, Meta, Google (including YouTube), X, LinkedIn and any other Connected Platform receive content because you instruct us to publish it to your accounts. They act as independent controllers under their own terms, not as our Sub-processors. The same applies to any Third-Party Provider account you connect with your own credentials ("bring your own credentials"): that provider processes data under your contract with it.
6. Assistance
6.1 Data subject requests. Taking into account the nature of the processing, we will help you, by appropriate technical and organisational measures, to respond to requests from data subjects to exercise their rights. The Service lets you find, export, correct and delete Customer Content yourself. If we receive a request directly that relates to Customer Personal Data, we will pass it to you without undue delay and will not respond ourselves except to direct the person to you, unless the law requires otherwise.
6.2 Other assistance. Taking into account the information available to us, we will give you reasonable help with your obligations on security, Security Incident notification, data protection impact assessments and prior consultation with supervisory authorities. We may charge reasonable costs for help that goes beyond what is available in the Service or in our standard documentation.
7. Security Incidents
7.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting your Customer Personal Data.
7.2 The notice will describe, as far as known, the nature of the Security Incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not available at first, we will provide it in phases as it becomes available.
7.3 We will take reasonable steps to contain and investigate the Security Incident and to reduce its effects, and will cooperate with you. Our notification is not an admission of fault or liability.
7.4 We will send notices to your Organisation's owners by email. You are responsible for keeping those details up to date.
8. Deletion and return
8.1 During the Agreement you can export and delete Customer Content in the Service at any time.
8.2 When the Agreement ends, you can export Customer Content during the read-only period described in clause 15 of the Terms of Service. After that period, or after you delete your Organisation, we will delete Customer Personal Data from our live systems within 30 days, and it will expire from our encrypted backups within a further 30 days, unless the law requires us to keep it. This deletion is your instruction to us under Article 28(3)(g) of the UK GDPR.
8.3 We may keep records that we need as a controller (for example audit and billing records) as described in our Privacy Policy.
9. Records, information and audits
9.1 We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR and this DPA.
9.2 You agree to use that information first, including our written answers to reasonable security questionnaires and any third-party certifications or reports we or our Sub-processors hold. If that information is not enough to demonstrate compliance, or a supervisory authority requires it, you may carry out an audit, or have an independent auditor bound by confidentiality carry one out, on at least 30 days' written notice, no more than once in any 12 months (except after a Security Incident or at a regulator's request), during business hours and in a way that does not disrupt the Service or breach our duties to other customers. You will bear the costs of the audit.
9.3 Audits of Sub-processors take place through the rights we have under our contracts with them and the reports they publish.
10. International transfers
10.1 We host the Service and its database in the European Union (Finland). Files in Customer Content and encrypted database backups are stored in Cloudflare R2, whose global infrastructure may keep them outside the UK and EEA. Other Sub-processors process Customer Personal Data outside the UK and EEA, mainly in the United States. Locations are set out on the Sub-processors page.
10.2 We will only make a Restricted Transfer, or allow a Sub-processor to make one, where it is protected by a transfer mechanism recognised by Data Protection Laws, such as the UK Extension to the EU–US Data Privacy Framework or the EU–US Data Privacy Framework for certified recipients, or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement, together with any supplementary measures needed after a transfer risk assessment.
10.3 To the extent that you, as a controller in the EEA, transfer Customer Personal Data to us in the UK, the transfer is covered by the European Commission's adequacy decision for the United Kingdom.
11. Liability and precedence
11.1 Each party's liability under or in connection with this DPA is subject to the limits and exclusions in clause 17 of the Terms of Service, to the extent the law allows. Nothing in this DPA limits a data subject's rights against either party under Data Protection Laws.
11.2 If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
11.3 We may update this DPA to reflect changes in Data Protection Laws or in our processing, provided the update does not reduce the overall protection given to Customer Personal Data. We will give notice of material changes as described in the Terms of Service.
12. Governing law
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except where Data Protection Laws or the applicable transfer mechanism require otherwise.
Annex 1: Details of the processing
Subject matter and purpose. Providing the Service to you: generating, editing, storing, reviewing, rendering and publishing marketing videos, images, audio and text from your Inputs; scanning your own website to learn about your business and gather its images; checking content for safety; publishing to Connected Platforms at your instruction and reading back performance data; supporting you and keeping the Service secure.
Nature of the processing. Collection, storage, organisation, structuring, adaptation, transcription, analysis, generation of derived content, transmission to Sub-processors and Connected Platforms, retrieval, disclosure by publishing at your instruction, and erasure.
Duration. For the term of the Agreement and until deletion under clause 8.
Categories of data subjects. Depending on how you use the Service: your employees, contractors and representatives who appear in or are named in content; people whose voices are cloned; your customers, clients and other people who appear in, are quoted in or are named in your Inputs or on your website; and outside reviewers you invite through share links.
Categories of personal data. Names, job titles and contact details included in content; images and video showing people; voice recordings and voice samples; consent recordings and consent statements for voice cloning; text such as scripts, captions, comments and testimonials; names and optional email addresses of outside reviewers. Performance data read back from Connected Platforms is aggregated counts (such as views, likes, comments and shares) and does not identify the people who engaged.
Special categories. Voice samples used to create a voice clone, and images of people, may be biometric data where they are processed to uniquely identify a person. You should not otherwise include special category data in Inputs.
Frequency. Continuous, for as long as you use the Service.
Annex 2: Technical and organisational security measures
- Hosting. Application servers and databases run in a data centre in Helsinki, Finland (Hetzner). Files and encrypted database backups are stored in Cloudflare R2 object storage on Cloudflare's global infrastructure, covered by Cloudflare's data processing addendum and the transfer safeguards in clause 10. Servers are protected by a network firewall and a host firewall, and only web traffic and administrative SSH are allowed in.
- Encryption in transit. All traffic to the Service uses HTTPS (TLS). Connections to Sub-processors use TLS.
- Encryption at rest. Stored files and backups are encrypted at rest by the storage provider. Connected Platform access tokens, voice profile identifiers and customer-supplied provider keys are protected with envelope encryption using a key held in AWS Key Management Service; the key never leaves AWS, and access to it is limited to the one application identity that needs it.
- Access control. Organisation roles limit what each Authorised User can see and do. Access to files uses short-lived signed links. Staff access to customer Organisations is limited to support and security purposes, time-limited and logged.
- Authentication. Passwords are stored as salted hashes and checked against known breached passwords using a privacy-preserving range query. Two-step verification is available to every user and required for our staff. Sessions expire after 14 days without use and after 30 days at most, and can be revoked. Sign-in and other sensitive endpoints are rate-limited.
- Logging and monitoring. Significant actions (such as sign-ins, membership changes, billing changes, publishing, voice consent, data exports and deletions, and staff actions) are written to an audit log. Service health is monitored and failures raise alerts. Error reporting, if enabled, excludes expected user errors.
- Application security. Input validation, origin and CSRF checks on authenticated requests, protection against server-side request forgery in website scanning, isolation of each Organisation's data in queries and storage paths, regular dependency updates and vulnerability checks, and automated tests in continuous integration.
- Content safety. Automated checks of generated and uploaded content by a specialist provider, with human review of flagged items, and a consent check before any cloned voice can be used.
- Cost and abuse controls. Per-organisation daily and monthly cost caps, rate limits and a service-wide pause switch that can stop generation quickly.
- Backups and resilience. Encrypted database backups (encrypted before they leave our server) with point-in-time recovery, and file backups, kept for up to 30 days and stored separately from the live systems, with restore procedures.
- Deletion. Automated deletion of Organisations' data after the periods in clause 8, including files in storage, with a record that deletion happened.
- People. Staff and contractors are bound by confidentiality, receive access only as needed for their role, and lose access promptly when they leave.
- Sub-processor management. Sub-processors are chosen for their security practices and bound by written data protection terms.