Effective date: April 18, 2026
This Data Processing Agreement ("DPA") is entered into between PostEngine AI Solutions ("Processor", "we", "us") and the customer who has accepted the PostEngine Terms of Service ("Controller", "you"). This DPA supplements and forms part of the Terms of Service.
This DPA governs the processing of personal data by the Processor on behalf of the Controller in connection with the PostEngine platform. Processing will continue for the duration of the service agreement and will cease upon account termination, subject to applicable data retention obligations.
The Processor processes personal data solely to provide the PostEngine service, which includes:
Data subjects include:
The following categories of personal data are processed:
The Processor engages the following sub-processors to provide the service. The Controller consents to the use of these sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Cloud infrastructure, compute, managed database, and object storage | New York City, United States |
| Cloudflare, Inc. | Edge network for the application domain: DNS, TLS termination, and DDoS and bot protection. All traffic to the platform passes through it in transit | United States |
| OpenAI, Inc. | AI-assisted content generation, draft review and scoring, image safety checks, indexing of past content, and image generation on the older image path (real-time processing, no training on customer data) | United States |
| Anthropic, PBC | AI-assisted content generation, rewriting and repurposing — the second provider for the same requests as OpenAI, and the one used when the other fails (real-time processing, no training on customer data) | United States |
| Google LLC | AI image generation and editing for post visuals through the Gemini API, and reading a draft to write the brief for its image | United States |
| Unsplash | Stock photo search; receives English keywords derived from a draft and the identifier of a photo used, not the draft itself | Canada |
| Sentry (Functional Software, Inc.) | Application error tracking and performance monitoring | United States |
| Resend | Transactional email delivery: publishing-failure notices, team invitations and auto-publish notices | United States |
| LinkedIn Corporation (Microsoft) | Social media platform — user profile data and content publishing via API (user-consented) | United States |
| Polar Software, Inc. | Merchant of record for paid plans: payment processing, subscription billing, sales-tax/VAT calculation and invoicing (card and billing details are collected and held by Polar, not by us) | United States |
We will notify the Controller at least 14 days before engaging a new sub-processor. The Controller may object in writing within that period.
The Processor implements the following technical and organizational measures to protect personal data:
The Processor will assist the Controller in fulfilling data subject rights requests, including:
Requests should be directed to [email protected] and will be acknowledged within 72 hours and fulfilled within 30 days.
In the event of a personal data breach, the Processor will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification will include:
Upon termination of the service agreement, the Processor will:
Data required by law to be retained (such as financial transaction records) will be kept for the legally mandated period and then securely deleted.
This DPA is governed by the same laws that govern the Terms of Service. In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.
For questions about this Data Processing Agreement or data protection matters, contact us at [email protected].
See also: Privacy Policy · Terms of Service · Support Center