Data Processing Agreement
1. Who is who
You are the controller. Your customers' comments, messages and contact details are your data: you decide why they are processed and what happens to them.
We — Modus Altos Mikhail Kushnir, NIP 9452325283, ul. Partyzantów 8/2, 31-435 Kraków, Poland — are the processor. We act on your instructions and for no purpose of our own.
Data about you as our client — your account, your invoices, our server logs — is a different matter. There we are the controller, and that is described in the privacy policy, not here.
2. What we process for you
- Subject: running your social media accounts and producing material for them.
- Duration: for as long as your account exists.
- Types of data: names and handles of the people who interact with your accounts, the text of their comments and messages, contact details they give you, and metrics of your posts.
- Categories of people: your audience, your customers and your leads.
We do not ask for special categories of data (health, beliefs, biometrics) and the product has no place to put them. If you put them in anyway, you remain responsible for having a basis to do so.
3. Our obligations
- We process personal data only on your documented instructions. Your use of the service's features is that instruction; anything outside it we do not do.
- If the law obliges us to process data otherwise, we tell you first, unless the law forbids telling you.
- Everyone with access is bound by confidentiality.
- We keep the security measures described in §6.
- We help you answer people who exercise their rights, and we help you with impact assessments and with notifications after a breach — with what we can do given the nature of the processing.
- On termination we delete your data as described in the privacy policy, unless the law requires us to keep it.
- We make available what you need to check that we do the above, including an export of your data at any moment.
4. Your obligations
- You have a lawful basis for the data you put into the service and for the accounts you connect.
- You tell the people concerned what you do with their data.
- Your instructions to us are lawful.
- You do not put into the service data you have no right to process.
5. Sub-processors
You give general authorisation for us to use sub-processors. All of them are listed, with what they receive and where they operate, on the sub-processors page.
Before adding or replacing one, we give at least 14 days' notice on that page and by email. If you object on reasonable data protection grounds within that time, you may terminate the affected part of the service and we refund the unused period. We keep the same obligations with every sub-processor as we owe you, and we remain responsible for what they do.
6. Security measures
These are the measures actually in place, not a wish list:
- Encryption in transit for every connection.
- Access tokens for your networks encrypted at rest.
- Passwords stored as hashes; sign-in attempts rate-limited.
- Session cookie not readable by JavaScript, sent only over TLS.
- Share-link tokens stored only as hashes, revocable, with an expiry.
- Each organisation's and each brand's data stored separately; team members see only what they were given.
- Nightly backups to storage separate from the server.
- Servers in Germany (EU).
7. Transfers outside the EU
Some sub-processors operate in the United States — the page above says which. Those transfers rely on the European Commission's standard contractual clauses, or on the provider's certification under the EU-US Data Privacy Framework where it has one. You may ask us for a copy of the safeguards for any of them.
8. Breach notification
If we become aware of a personal data breach affecting your data, we notify you without undue delay and give you what you need to notify your supervisory authority — what happened, which categories and roughly how many people, the likely consequences, and what we are doing about it. We do not wait until the picture is complete: a first message with less detail is more useful to you than a complete one that is late.
9. Audits
You may ask us to demonstrate compliance with this agreement. We answer documented questions and provide what we have. An on-site audit is possible once a year with 30 days' notice, at your cost, and must not expose other clients' data.
10. Return and deletion
At any time you can export everything in your organisation as a single file (Account → Take your data). On termination, or on your request, we delete your data on the terms in the privacy policy.
11. Conflicts
If this agreement and the terms of service disagree about the processing of personal data, this agreement wins.