Skip to main content
Last updated: October 5, 2026

Data Processing Addendum

The data protection terms that apply when Social9 processes personal data on behalf of business customers.

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Social9, Inc. ("Social9") and the customer that accepted it ("Customer"). It applies whenever Social9 processes Customer Personal Data subject to Data Protection Laws in providing the Services.

No signature needed

This DPA is incorporated into the Agreement automatically and takes effect when the Customer accepts the Terms of Service. If your organisation needs a countersigned copy for its records, email [email protected].

1. Definitions

  • Data Protection Laws means all laws on the processing of personal data that apply to a party in connection with the Agreement, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (CCPA).
  • Customer Personal Data means personal data that Social9 processes on behalf of the Customer in providing the Services.
  • Sub-processor means a third party engaged by Social9 that processes Customer Personal Data.
  • Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • SCCs means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
  • "Controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR.

2. Roles and Scope

The Customer is the controller (or a processor acting for its own clients) of Customer Personal Data, and Social9 is its processor (or sub-processor). Annex I describes the processing. Social9 is an independent controller of personal data it processes for its own business purposes, such as account administration, billing and security, as described in its Privacy Policy; this DPA does not apply to that data.

3. Customer Instructions

Social9 processes Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA and the Customer's use and configuration of the Services are the Customer's complete instructions. Social9 will tell the Customer if it believes an instruction breaks Data Protection Laws. The Customer is responsible for having a lawful basis for the processing and for the accuracy of the data it provides.

4. Social9's Obligations

  • Ensure that everyone authorised to process Customer Personal Data is bound by confidentiality.
  • Implement and maintain the technical and organisational measures in Annex II.
  • Taking into account the nature of the processing, assist the Customer, by appropriate technical and organisational measures, in responding to data subject requests. If Social9 receives a request directly, it will refer the data subject to the Customer and will not respond itself unless required by law.
  • Provide reasonable help with the Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to the Services.
  • Not sell or share Customer Personal Data, or use it for any purpose other than providing the Services, including training general-purpose AI models.

5. Sub-processors

  • The Customer gives general authorisation for Social9 to use the Sub-processors listed on our Sub-processors page.
  • Social9 will give at least 30 days' notice before adding or replacing a Sub-processor, by updating that page and notifying Customers who have subscribed to updates.
  • The Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for them.
  • Social9 imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains liable for their performance.

6. Social Media Platforms

When the Customer schedules a post to a connected social media account, Social9 transmits that content to the platform the Customer chose, at the Customer's instruction. Social media platforms such as Meta, Google, TikTok, LinkedIn, X and Pinterest act as independent controllers of the data they receive and are not Sub-processors of Social9. The Customer's relationship with each platform is governed by that platform's terms.

7. Security Incidents

  • Social9 will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a Security Incident.
  • The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed. Social9 will provide further information as it becomes available.
  • Social9 will take reasonable steps to contain, investigate and mitigate the incident.
  • Notification is not an acknowledgement of fault or liability.

8. Audits

On written request, Social9 will make available the information reasonably necessary to demonstrate compliance with this DPA, including completed security questionnaires and any available third-party audit reports, under confidentiality. If that information is not sufficient to meet a requirement of Data Protection Laws, the Customer may audit Social9 no more than once a year, on at least 30 days' notice, during business hours, at its own cost, and in a way that does not disrupt Social9's operations or compromise other customers' data.

9. International Transfers

  • EEA. For transfers of Customer Personal Data from the EEA to Social9 in a country without an adequacy decision, the SCCs are incorporated into this DPA: Module Two (controller to processor) or Module Three (processor to processor) as applicable. Clause 7 (docking) applies; in Clause 9, option 2 (general authorisation) applies with the notice period in section 5; the optional wording in Clause 11 does not apply; Clauses 17 and 18 are governed by the law and courts of Ireland. Annexes I and II of this DPA complete the corresponding annexes of the SCCs.
  • United Kingdom. For UK transfers, the International Data Transfer Addendum issued by the UK Information Commissioner applies, completed with the information in this DPA. Either party may end the Addendum as set out in its section 19.
  • Switzerland. For Swiss transfers, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
  • If the SCCs conflict with this DPA or the Agreement, the SCCs prevail.

10. Return and Deletion

The Customer can export its content and delete Customer Personal Data at any time using the Services. When the Agreement ends, Social9 will delete Customer Personal Data within 30 days, and from backups within a further 35 days, unless the law requires it to be kept. On request, Social9 will confirm deletion in writing.

11. California (CCPA)

To the extent the CCPA applies, Social9 is a service provider. Social9 will not sell or share Customer Personal Data; retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than the business purposes in the Agreement; or combine it with personal information from other sources except as the CCPA permits. Social9 will comply with the CCPA, give the same level of protection it requires, and tell the Customer if it can no longer meet its obligations. The Customer may take reasonable steps to stop and remediate unauthorised use.

12. General

  • Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws or the SCCs do not allow it.
  • If this DPA conflicts with the Agreement, this DPA prevails on data protection matters.
  • This DPA lasts as long as Social9 processes Customer Personal Data.
  • Social9 may update this DPA to reflect changes in law or the Services; an update will not materially reduce the protection given to Customer Personal Data.

Annex I: Description of Processing

Data exporterThe Customer (controller, or processor on behalf of its own clients)
Data importerSocial9, Inc. (processor, or sub-processor)
Data subjectsCustomer's authorised users; people whose personal data appears in content, media or messages the Customer creates, schedules or publishes; Customer's clients and their staff, where the Customer is an agency
Categories of personal dataNames, email addresses, job titles and workspace roles of users; social media account identifiers, names, handles and profile pictures; personal data contained in posts, captions, images and videos; usage and log data
Special categoriesNone intended. The Customer should not use the Services to process special category data unless agreed in writing
FrequencyContinuous, for as long as the Customer uses the Services
Nature and purposeHosting, storing, generating with AI, scheduling and publishing social media content to the accounts the Customer connects, and providing related analytics and support
Duration and retentionFor the term of the Agreement, then deleted within 30 days, as set out in section 10
Competent supervisory authorityThe authority determined under Clause 13 of the SCCs

Annex II: Technical and Organisational Measures

Social9 maintains the measures set out in its Information Security Policy, including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256), with application-layer encryption of social platform tokens
  • Role-based, least-privilege access with single sign-on and multi-factor authentication for administrative access, and quarterly access reviews
  • Logical separation of each customer's data, and separate production and development environments
  • Web application firewall, DDoS protection, rate limiting and network isolation of databases
  • Peer-reviewed code changes, dependency vulnerability monitoring and secrets management
  • Centralised logging and alerting, and a documented incident response plan
  • Encrypted daily backups with tested restoration
  • Vendor security review and data protection terms for all Sub-processors
  • Confidentiality agreements and annual security training for all personnel

Annex III: Sub-processors

The current list is maintained on our Sub-processors page. At the date of this DPA it is:

  • Amazon Web Services, Inc.: Cloud hosting, databases, file storage and backups (United States)
  • Cloudflare, Inc.: Content delivery, media delivery, DNS, DDoS protection and web application firewall (United States and global edge network)
  • Anthropic, PBC: AI content generation (Claude models) (United States)
  • OpenAI, L.L.C.: AI content generation (United States)
  • Google LLC: AI content generation (Gemini models) and website analytics (Google Analytics) (United States)
  • OpenRouter, Inc.: Routing AI generation requests to model providers (United States)
  • Stripe, Inc.: Payment processing and subscription billing (United States)
  • Mailazy: Transactional email delivery (United States)
  • SSOJet: Sign-in, social login and enterprise single sign-on (SAML, OIDC) (United States)