This addendum ("DPA") is part of the Terms of service between you (the "Customer") and TOTOSLOCAL ONE PRIVATE LIMITED ("Postozo"). It applies when Postozo processes personal data on the Customer's behalf, for example the personal data of the Customer's clients, team members or audience that is put into the Service.
Roles
The Customer is the controller (data fiduciary) of that personal data. Postozo is the processor and processes it only to provide the Service and on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the Service.
Types of data and people
Data: names, emails, profile details and ids, post content, comments, images and videos, and statistics from connected platforms. People: the Customer's team members, clients and the people who appear in or react to published content.
Confidentiality
Anyone at Postozo who can access the data is bound to keep it confidential.
Security
Postozo keeps appropriate security measures, including: HTTPS for all traffic; encryption of channel tokens and secrets in the database (AES-256-GCM); hashed passwords and API keys; separation of workspaces and client roles; server access limited to authorised staff; daily database backups kept for 30 days.
Subprocessors
The Customer allows Postozo to use the subprocessors listed in the Privacy policy. We will give notice of new subprocessors by updating that list, and the Customer may object by writing to support@postozo.com. We make our subprocessors follow data protection duties at least as strict as this DPA.
Transfers
Data is stored in the United States. Where the law requires, transfers are covered by suitable safeguards, such as standard contractual clauses.
Helping the Customer
Postozo will help the Customer, in a reasonable way, to answer requests from people using their rights and to meet its own legal duties about security and breaches.
Breaches
Postozo will tell the Customer without undue delay, and within 72 hours where possible, after becoming aware of a breach affecting the Customer's personal data, with the details we have.
Deleting data
When the Customer's account ends, Postozo deletes the personal data within 30 days, and from backups within a further 30 days, unless the law requires us to keep it.
Information and audits
Postozo will give the Customer the information reasonably needed to show it meets this DPA. Requests go to support@postozo.com.
Liability
Each party's liability under this DPA follows the limits in the Terms of service.
TOTOSLOCAL ONE PRIVATE LIMITED
Sky Privlion, 501, Nipania, Indore, Madhya Pradesh 452010, India
support@postozo.com