Data Processing Agreement

Data Processing Agreement

*Last updated: June 9, 2026*

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Butterknife LLC d/b/a Postmagiq ("Postmagiq", "Processor") and the customer accepting the Terms of Service ("Customer", "Controller"), and applies to the extent Postmagiq processes Personal Data subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or similar data protection laws on the Customer's behalf.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in the GDPR. "Subprocessor" means any third party engaged by Postmagiq to process Personal Data on the Customer's behalf.

2. Roles and Scope

3. Details of Processing

4. Subprocessors

The Customer provides general authorization for these Subprocessors:

| Subprocessor | Purpose | |---|---| | Google Cloud Platform | Hosting, storage, database | | Clerk | Authentication | | Stripe | Payments | | Anthropic, OpenAI, Google, Groq | AI content generation (content data only, as needed per workflow) | | Post for Me | Social publishing (LinkedIn and other connected platforms) | | PostHog | Product analytics (only with cookie consent) |

We contractually require Subprocessors to provide at least the level of protection in this DPA. AI providers are used under terms that prohibit training on Customer content. We will give at least 14 days' notice (via the Service or email) before adding or replacing a Subprocessor; the Customer may object on reasonable data-protection grounds, and if we cannot resolve the objection, the Customer may terminate the affected services.

5. Confidentiality and Security

Postmagiq ensures persons authorized to process Personal Data are bound by confidentiality, and implements appropriate technical and organizational measures, including: encryption in transit (TLS) and at rest, workspace-scoped access controls, hashed credentials, network isolation of databases, audit logging, and least-privilege access for personnel.

6. Assistance

Taking into account the nature of processing, Postmagiq will assist the Customer with: responding to Data Subject requests (the Service provides self-service export and deletion), security of processing, breach notifications, and data protection impact assessments, insofar as the information is available to Postmagiq.

7. Personal Data Breach

Postmagiq will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably required for the Customer to meet its breach-notification obligations.

8. Deletion and Return

Upon termination of the agreement, or upon account deletion initiated through the Service, Postmagiq deletes Personal Data within 30 days, except for data we must retain by law (e.g., billing records). The Customer can export its data at any time through **Settings → Privacy**.

9. International Transfers

Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor), which are incorporated by reference, with Postmagiq as data importer and the Customer as data exporter.

10. Audits

Postmagiq will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow audits by the Customer or its appointed auditor, no more than once annually, on at least 30 days' notice, during business hours, without disrupting operations, and subject to confidentiality.

11. Contact

Data protection inquiries: [privacy@postmagiq.com](mailto:privacy@postmagiq.com)