Skip to content
Postpilot
Back to home

Data Processing Addendum

When you process personal data of your audience through Postpilot, we act as your processor under Art. 28 GDPR. This page summarises the Auftragsverarbeitungsvertrag (AVV); a signed PDF is available on request.

Last updated · 16 September 2026

Subject and duration

Postpilot processes the personal data you submit (post content, comments, DMs) for the duration of your subscription, solely to deliver the contracted services.

Nature and purpose

Scheduling, publishing, analytics, inbox replies, AI-assisted caption drafting. No further processing.

Sub-processors

NVIDIA Corporation (AI text generation via the NIM API, USA, Standard Contractual Clauses), Stripe Payments Europe Ltd. (payment processing, Dublin, Ireland), Functional Software Inc. d/b/a Sentry (error monitoring, EU data centre), Hetzner Online GmbH (hosting, Germany). No US-based marketing or analytics sub-processors.

Security

Encryption in transit (TLS 1.3) and at rest (AES-256). Quarterly security review. Personnel signed to confidentiality. Incident response process with 72-hour breach notification.

Audits

On request and with reasonable notice, you may audit Postpilot's compliance with this DPA at your own cost, no more than once per year.

Deletion on termination

On contract end, your personal data is deleted within 30 days unless legal retention obligations require otherwise. Confirmation provided on request.

Request signed DPA PDF