Data Processing Addendum

Last updated: 29 September 2026

This addendum ("DPA") is part of the Terms of service between you (the "Customer") and TOTOSLOCAL ONE PRIVATE LIMITED ("Postozo"). It applies when Postozo processes personal data on the Customer's behalf, for example the personal data of the Customer's clients, team members or audience that is put into the Service.

Roles

The Customer is the controller (data fiduciary) of that personal data. Postozo is the processor and processes it only to provide the Service and on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the Service.

Types of data and people

Data: names, emails, profile details and ids, post content, comments, images and videos, and statistics from connected platforms. People: the Customer's team members, clients and the people who appear in or react to published content.

Confidentiality

Anyone at Postozo who can access the data is bound to keep it confidential.

Security

Postozo keeps appropriate security measures, including: HTTPS for all traffic; encryption of channel tokens and secrets in the database (AES-256-GCM); hashed passwords and API keys; separation of workspaces and client roles; server access limited to authorised staff; daily database backups kept for 30 days.

Subprocessors

The Customer allows Postozo to use the subprocessors listed in the Privacy policy. We will give notice of new subprocessors by updating that list, and the Customer may object by writing to support@postozo.com. We make our subprocessors follow data protection duties at least as strict as this DPA.

Transfers

Data is stored in the United States. Where the law requires, transfers are covered by suitable safeguards, such as standard contractual clauses.

Helping the Customer

Postozo will help the Customer, in a reasonable way, to answer requests from people using their rights and to meet its own legal duties about security and breaches.

Breaches

Postozo will tell the Customer without undue delay, and within 72 hours where possible, after becoming aware of a breach affecting the Customer's personal data, with the details we have.

Deleting data

When the Customer's account ends, Postozo deletes the personal data within 30 days, and from backups within a further 30 days, unless the law requires us to keep it.

Information and audits

Postozo will give the Customer the information reasonably needed to show it meets this DPA. Requests go to support@postozo.com.

Liability

Each party's liability under this DPA follows the limits in the Terms of service.

Contact
TOTOSLOCAL ONE PRIVATE LIMITED
Sky Privlion, 501, Nipania, Indore, Madhya Pradesh 452010, India
support@postozo.com
FAQ

Questions

Who is the controller of my clients' data?

You are. Postozo is the processor and acts only on your instructions.

How fast will you tell us about a breach?

Without undue delay, and within 72 hours where possible, with the details we have.

When is data deleted after an account ends?

Within 30 days, and from backups within a further 30 days, unless the law requires us to keep it.