1. Our commitment
PostBod applies privacy-by-design principles to account data, brand knowledge, connected accounts, AI requests, publishing, and analytics. This page explains product and contractual support; it is not a certification and does not make a customer's use automatically compliant.
2. Controller and processor roles
PostBod is generally a controller for account administration, security, billing, support, website operation, and its direct business relationships. A customer is generally the controller for personal data it submits, connects, analyzes, or publishes for its own purposes, with PostBod acting as processor under customer instructions. The facts, not labels alone, determine each role.
3. Legal bases
Where PostBod acts as controller, processing may rely on contract, steps requested before contract, legitimate interests, consent, or legal obligation. Customers must identify and document their own lawful basis for workspace content, audience data, connected social data, direct marketing, profiling, and publication.
4. Data subject rights
Eligible people may request access, correction, erasure, restriction, portability, objection, withdrawal of consent, and safeguards relating to solely automated decisions. Requests to PostBod can be sent to privacy@postbod.app. When a customer controls the data, PostBod will assist and route the request to that customer as appropriate.
5. Subprocessors and instructions
PostBod uses providers to host and operate parts of the service and maintains a Subprocessor page. Processing is limited to documented service purposes, applicable agreements, and customer instructions. Eligible customers may request a data processing agreement covering confidentiality, security, assistance, deletion, audits, and subprocessors.
6. International transfers
When personal data moves outside the EEA, UK, or Switzerland, PostBod will use an applicable adequacy decision, standard contractual clauses, the UK addendum or international data transfer agreement, or another lawful transfer mechanism. Supplementary safeguards are evaluated based on the transfer and provider.
7. Security and incidents
PostBod implements the controls described on our Security page. We maintain procedures to assess incidents and notify affected customers without undue delay when a processor notification duty applies, providing information reasonably available for the customer's regulatory assessment.
8. Customer responsibilities
Customers must provide notices, define purposes, minimize data, configure retention, manage permissions, respond to rights, assess sensitive or high-risk processing, complete impact assessments where required, and ensure content generation and social publishing have a lawful basis. Do not use PostBod for prohibited solely automated decisions with legal or similarly significant effects.
9. Requests, complaints, and contact
Contact privacy@postbod.app. You may also complain to the supervisory authority in your country or, for UK matters, the Information Commissioner's Office. We may verify identity and authority before fulfilling a request.

