1. One baseline, local supplements
Our baseline covers transparency, purpose limitation, data minimization, lawful processing, security, retention, individual rights, processor oversight, international transfers, and accountable incident handling. Applicability depends on location, customer role, business thresholds, data type, audience, and processing purpose.
This framework supports readiness; it is not legal advice, a regulatory approval, or a blanket compliance certification.
2. Regional laws considered
| Region | Examples | PostBod operational response |
|---|---|---|
| European Economic Area and United Kingdom | EU GDPR, UK GDPR, ePrivacy / PECR | Controller and processor roles, legal bases, rights support, transfer mechanisms, processor terms, and prior consent for non-essential cookies. |
| United States | State privacy laws including California CCPA/CPRA and other applicable state laws | Notice, access, correction, deletion, portability, opt-out and appeal support where applicable; recognized opt-out signals for covered processing. |
| Canada | PIPEDA and applicable provincial laws | Accountability, identified purposes, meaningful consent, collection and retention limits, safeguards, access, correction, and challenge procedures. |
| Latin America | Brazil LGPD and other applicable national laws | Legal bases, transparency, data subject rights, security, processor governance, and transfer assessment. |
| Africa | Applicable laws including South Africa POPIA, Nigeria NDPA, Kenya DPA, and Zambia DPA | Lawful and minimal processing, notices, data subject rights, processor controls, security, breach assessment, and cross-border safeguards. |
| Asia-Pacific | Applicable laws including Singapore PDPA, Australia Privacy Act/APPs, New Zealand Privacy Act, Japan APPI, South Korea PIPA, and India DPDP Act | Consent or other lawful grounds, purpose notices, access and correction, security, retention, transfer and processor controls adapted to local requirements. |
| Middle East | Applicable laws including Saudi PDPL and UAE federal or free-zone regimes | Purpose and lawful-basis controls, rights handling, security, processor obligations, and transfer assessment. |
| Switzerland | Federal Act on Data Protection | Transparent and proportionate processing, security, individual rights, processor governance, and cross-border safeguards. |
3. Rights operations
PostBod provides a single intake at privacy@postbod.app for access, know, correction, deletion, restriction, objection, portability, consent withdrawal, opt-out, sensitive-data limitation, and appeal requests where available. We verify requests, identify the controller, preserve required records, and respond under the applicable deadline. See Data Deletion.
4. Cookies and electronic marketing
Non-essential analytics does not load until the user chooses it where consent is required. Rejecting optional categories is as accessible as accepting them, and preferences remain available from the footer. Customers remain responsible for lawful audiences, suppression lists, direct-marketing rules, sponsored-content disclosures, and platform advertising policies. See Cookie Policy.
5. AI, profiling, and sensitive use
PostBod is intended for content operations, not decisions that determine a person's eligibility, employment, credit, housing, healthcare, education, insurance, or legal rights. Customers must assess profiling, sensitive data, biometric data, children, political advertising, and regulated-sector content before use. Human review is required for high-impact claims and publishing decisions.
6. Customer accountability
Customers decide what workspace data to provide and what to publish. They must maintain a lawful basis, required notices and consents, records of processing where required, data minimization, retention rules, rights procedures, transfer assessment, and appropriate contracts with PostBod. Industry-specific rules can add obligations beyond general privacy law.
7. Official guidance and contact
Useful primary references include the EU GDPR, UK ICO cookie guidance, California Attorney General CCPA guidance, Canada's PIPEDA principles, Australian Privacy Principles, Singapore PDPA overview, and Brazil LGPD information. Questions: privacy@postbod.app.

