Octonity
Legal

Data Processing Agreement

The Article 28 GDPR agreement between you (the Controller) and Octonity (the Processor) when you use the Octonity Service.

Version 1.0 · Last updated: July 3, 2026

Summary

This Data Processing Agreement (“DPA”) is entered into by Octonity (“Processor”) and the customer whose workspace is registered on the Octonity Service (“Controller”). It forms part of, and supplements, the Octonity Terms of Service and takes effect on the effective date of those Terms. Terms defined in the Terms have the same meaning here unless otherwise specified.

1. Definitions

GDPR
Regulation (EU) 2016/679 (General Data Protection Regulation).
Personal Data
As defined in Article 4(1) GDPR.
Data Subject
The identified or identifiable natural person to whom Personal Data relates.
Processing
As defined in Article 4(2) GDPR — any operation performed on Personal Data.
Service
The Octonity software-as-a-service offering described in the Terms.
Subprocessor
A third party engaged by the Processor to process Personal Data on the Controller’s behalf.
Standard Contractual Clauses (SCC)
The standard contractual clauses adopted by the European Commission under Article 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914).

2. Subject matter, duration, nature, and purpose

  • Subject matter: Processing of Personal Data by the Processor on behalf of the Controller in the course of providing the Service.
  • Duration: This DPA remains in force for as long as the Processor processes Personal Data under the Terms.
  • Nature and purpose: Hosting, transmission, storage, and computation necessary to deliver the Service, including account management, content authoring and publishing, unified inbox, moderation, analytics, and marketplace transactions.
  • Categories of Data Subjects: the Controller’s Users, invited collaborators, Marketplace buyers/sellers, and any Data Subject whose data is submitted to the Service by the Controller (e.g. commenters on connected social accounts).
  • Categories of Personal Data: identification data (name, email), authentication data (password hash, 2FA tokens), account activity, content authored or scheduled, connected-channel tokens and IDs, incoming DM/comment text, billing data (via Stripe), and technical logs (IP, user agent).

3. Roles

The Controller is the controller of the Personal Data processed under the Service. The Processor processes Personal Data only on documented instructions from the Controller, which are given through the Terms, the Service configuration (e.g. Connected Channels, marketplace listing options), and this DPA.

4. Instructions and lawfulness

The Processor processes Personal Data only for the purpose of providing the Service and on documented instructions from the Controller. The Processor shall promptly notify the Controller if, in its opinion, an instruction infringes GDPR or another EU or Member State data-protection provision, and may suspend performance of the affected instruction until the Controller confirms or amends it.

5. Subprocessors

The Controller grants the Processor general authorisation to engage subprocessors, provided the Processor:

  • Maintains a current list of subprocessors at /legal/subprocessors (the “Subprocessor List”), which forms Annex II of this DPA;
  • Notifies the Controller at least 30 days in advance of any material addition or replacement of a subprocessor. The Controller may object within that period on reasonable grounds relating to the protection of Personal Data; if such an objection cannot be resolved, the Controller may terminate the affected Service without penalty.
  • Imposes on each subprocessor data-protection obligations no less onerous than those set out in this DPA and remains fully liable to the Controller for the performance of the subprocessor.

6. Security of processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, the Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256 or stronger).
  • Segregation of Personal Data by tenant, enforced at the application and database layer (multi-tenant row-level scoping + declared tenant foreign keys).
  • Encrypted storage of authentication tokens (OAuth tokens, refresh tokens) using key material managed by a dedicated data-protection stack (Microsoft Azure Data Protection).
  • Access control: MFA-protected admin access, principle of least privilege, quarterly access reviews.
  • Audit logging of security-relevant events (auth, permission grants, export, deletion) retained for 7 years.
  • Regular backup (encrypted, daily) with tested restore procedures.
  • Vulnerability management: dependency scanning, periodic penetration tests, coordinated disclosure via a documented security.txt address.
  • Business continuity and disaster recovery plans reviewed annually.

7. Confidentiality

The Processor ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

8. Data Subject rights

Taking into account the nature of the Processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the Data Subject’s rights under Chapter III GDPR. The Service exposes self-serve export (Article 20) and deletion (Article 17) functionality; the Processor supports the Controller in fulfilling other rights (rectification, restriction, objection) via a documented request path at privacy@octonity.com.

9. Personal Data breaches

The Processor notifies the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting the Controller’s data. The notification includes: (i) the nature of the breach, (ii) the categories and approximate number of Data Subjects and records concerned, (iii) the likely consequences, and (iv) the measures taken or proposed to address the breach and mitigate its adverse effects.

10. Data Protection Impact Assessment + prior consultation

The Processor provides reasonable assistance to the Controller in carrying out data-protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the Processing and the information available to the Processor.

11. International transfers

Where Personal Data is transferred outside the EU/EEA, the parties rely on: (i) an adequacy decision under Article 45 GDPR where one exists, or (ii) the Standard Contractual Clauses (Module 2 or Module 3 as applicable) incorporated by reference. The specific transfers are identified in the Subprocessor List (Annex II). Where SCC apply between the Processor and its subprocessor for a US transfer, the relevant supplementary measures are described in the Subprocessor List entry.

12. Deletion or return of Personal Data

At the choice of the Controller, the Processor deletes or returns all Personal Data to the Controller after the end of the provision of Service, and deletes existing copies unless storage is required by EU or Member State law. Standard retention: 30 days after Service termination for export, then permanent deletion, subject to the residual retention set out in the Privacy Policy (e.g. billing records for 7 years under German tax law).

13. Audit rights

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. To limit disruption to the Service, the Controller shall (i) give at least 30 days’ written notice, (ii) conduct audits during normal business hours and no more than once per calendar year (except where a Personal Data breach has occurred), and (iii) bear its own costs. The Processor may satisfy audit requests via third-party attestations (e.g. SOC 2, ISO 27001) where equivalent evidence exists.

14. Liability and precedence

This DPA is subject to the liability limitations set out in the Terms. In case of conflict between this DPA and the Terms in respect of the Processing of Personal Data, this DPA prevails.

15. Governing law

This DPA is governed by the law of the Federal Republic of Germany, subject to any mandatory conflict-of-laws rules of the country in which the Data Subject habitually resides. Exclusive place of jurisdiction is Berlin, Germany.

Annexes

Annex I — Description of processing. Set out in section 2 of this DPA.

Annex II — Subprocessor List. Available at /legal/subprocessors, updated from time to time in accordance with section 5.

Annex III — Technical and organisational measures. Set out in section 6 of this DPA. Detailed configuration evidence available on request via privacy@octonity.com.

Execution

This DPA is entered into by acceptance of the Terms of Service. Enterprise customers who require a countersigned copy for their vendor register may request a PDF version at legal@octonity.com. The hosted version at this URL remains the authoritative text.