NewOne place, every account.See how
Legal

Data Processing Agreement

Standard SaaS DPA between ManageSM (processor) and you (controller), aligned with the GDPR. Use this alongside our Terms of Service and Privacy Policy.

Last updated September 4, 2026

Draft — please review with counsel. This is our current standard DPA template. It has not been signed by us in this static form. To execute a countersigned DPA for your organisation, contact hello@managesm.com. We'll send a signed copy within 3 business days.

1. Parties

This Data Processing Agreement (“DPA”) is entered into between:

  • ManageSM (the “Processor”), operator of www.managesm.com.
  • You or your organisation (the “Controller”), being the customer that entered into the Terms of Service.

This DPA is part of, and incorporated by reference into, the Terms of Service and forms the parties' agreement in respect of personal data processed by us on your behalf under the GDPR, the UK GDPR, or comparable data protection laws.

2. Definitions

The terms “personal data”, “processing”, “controller”, “processor”, “sub-processor”, and “data subject” have the meanings given in the GDPR.

3. Subject matter and duration

  • Subject matter: processing of personal data as necessary to provide the ManageSM service.
  • Duration: for the term of your subscription plus the retention periods listed in Annex II.
  • Nature and purpose: providing the service you signed up for — storing your content, publishing to social networks on your behalf, showing engagement metrics.

4. Types of personal data and categories of data subjects

See Annex I.

5. Obligations of the Processor

We will:

  • Process personal data only on your documented instructions (which include the Terms of Service and configurations you make in the app).
  • Ensure that everyone authorised to process personal data has committed to confidentiality.
  • Implement the security measures described in Annex II.
  • Assist you in responding to data subject requests (access, deletion, portability, etc.) to the extent reasonable.
  • Notify you without undue delay of any personal data breach (target: within 72 hours of confirmed detection).
  • At your choice, return or delete all personal data when the service ends, except where retention is legally required.
  • Make available all information necessary to demonstrate compliance and allow reasonable audits (see Section 9).

6. Obligations of the Controller

You warrant that:

  • You have a valid legal basis for the processing you instruct us to perform.
  • You've provided any required notices to data subjects and obtained any required consents.
  • Your instructions to us won't violate applicable law.

7. Sub-processors

You give general authorisation for the sub-processors listed in Annex III. We'll notify you at least 30 days before adding or replacing a sub-processor by updating that annex and posting a notice on this page. You may object on reasonable grounds; if we can't resolve the objection, you may terminate the affected part of the service and receive a prorated refund of pre-paid fees.

We remain fully liable for our sub-processors' performance under this DPA.

8. International transfers

For transfers of personal data from the EEA, UK, or Switzerland to countries not recognised as providing an adequate level of protection, we rely on the Standard Contractual Clauses adopted by the European Commission (Module Two: controller to processor) and the UK International Data Transfer Addendum, as applicable. Those clauses are incorporated by reference and form part of this DPA.

9. Audits

You may audit our compliance with this DPA no more than once per 12-month period at your own expense, on 30 days' written notice, during business hours, in a manner that doesn't disrupt our operations. We can satisfy audit obligations by providing recent third-party audit reports (once available), our security documentation, and written responses to your questions.

10. Assistance

We will provide reasonable assistance in helping you meet obligations under Articles 32 to 36 GDPR (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and the information available to us.

11. Data subject requests

Most data subject rights are exercisable directly by users in the app (access, correction, deletion, export). If a data subject contacts us directly, we'll forward the request to you and not respond ourselves unless legally required.

12. Return and deletion

On termination, and at your choice: (a) we'll provide a machine-readable export of your data, or (b) we'll delete it. In either case, deletion happens within 30 days, subject to the retention required for backups (also 30 days) and legally-mandated records (e.g., tax invoices — 7 years).

13. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA excludes or limits liability that cannot be excluded or limited by law.

14. Precedence

If there's a conflict between this DPA and the Terms of Service, this DPA prevails on data-protection matters.

15. Changes

We may update this DPA where required by law or to reflect changes in the service. Material changes will be announced with 30 days' notice.


Annex I — Types of personal data and categories of data subjects

Categories of data subjects

  • Your users — the members of your workspace (workspace owners, admins, editors, reviewers).
  • Your customers, followers, and audience — insofar as their names, comments, or messages appear in content you post, in engagement data, or in your inbox.

Types of personal data

  • Names, email addresses, hashed passwords, and profile details of your workspace users.
  • OAuth access and refresh tokens for connected social accounts (encrypted at rest).
  • Handles, display names, and avatars of connected social accounts.
  • Content you draft, publish, or import (which may include personal data you choose to include).
  • Engagement data on posts you published through us (likes, comments, mentions).
  • Direct messages received on connected inboxes (once the Comments & DMs feature is live).
  • Activity records — timestamps and actor for every action in the app.

Special categories

We do not intentionally process special categories of personal data (health, religion, political opinions, biometrics, etc.). You're responsible for ensuring your content doesn't include them unless you have a lawful basis to do so.

Retention

See Section 12 above.

Annex II — Security measures

Access control

  • Role-based access per workspace.
  • Passwords hashed with bcrypt (cost factor 10).
  • Session cookies with HttpOnly, Secure, and SameSite=Lax.
  • SSH access to servers limited to named admins with key-based authentication only. Root SSH disabled.

Encryption

  • TLS 1.2 or higher for every connection to the service (Let's Encrypt certificates, auto-renewed).
  • OAuth tokens and other secrets encrypted at rest with AES-256-GCM.
  • Database connections between the application and Postgres are within a private Docker network — never exposed publicly.

Data integrity

  • Nightly database backups with 30-day retention.
  • Duplicate-detection on scheduled posts (90-day rolling window).
  • Pre-flight checks before every publish (token health, character limits, image sizes).

Operational security

  • Server operating system kept patched (Ubuntu 24.04 LTS with automatic security updates).
  • Firewall (ufw) locked to SSH (22) and HTTPS (443) only. HTTP (80) redirects to HTTPS.
  • Full activity history for auditability.

On the roadmap

  • SOC 2 Type II audit.
  • SAML SSO and SCIM provisioning.
  • Per-workspace data residency options.

Annex III — Approved sub-processors

Sub-processorPurposeLocationSince
Contabo GmbHServer infrastructure (compute, storage, network)United StatesSept 2026
Anthropic PBCAI drafting (Claude API) — only used when a customer invokes AI featuresUnited StatesSept 2026
Let's Encrypt (ISRG)TLS certificate issuanceUnited StatesSept 2026
Connected social networksPublishing posts and reading metrics on your behalf (you initiate each connection)Per each network

Stripe will be added as a sub-processor when billing launches. We'll update this annex and post 30 days' notice before that happens.

Contact

For DPA questions or to request a countersigned copy: hello@managesm.com. See also our Privacy Policy and Terms of Service.