Postfjord
Product
postsocialPlan, write and publish to Instagram, Facebook, LinkedIn, Threads, TikTok and YouTube from one calendar, with Claude drafting in your brand voice and analytics that show what actually works. postchatOne inbox for Instagram and Facebook messages and comments, with automations that turn a comment into a conversation and always respect a STOP. postmailEmail campaigns to the contacts you already collect in Postfjord, with double opt-in, a block editor and sending from the EU, plus landing pages and a link in bio page on postfjord.page. All featuresScheduling, AI composer, inbox, DM automation, analytics, landing pages and an MCP server for ChatGPT, Claude, Gemini and other AI apps. Everything in every plan.
Solutions
For creators For small businesses For agencies For salons and beauty For gyms and studios For restaurants and cafés
Pricing Academy Blog
Sign in Get early access

Data Processing Agreement

Last updated: 28 September 2026

This Data Processing Agreement ("DPA") is part of the Terms of Service between you, the customer who owns a Postfjord workspace ("you", the controller), and Yogakollektivet Sverige AB, org. nr 556858-0699, Sweden ("Postfjord", "we", the processor). It applies whenever we process personal data on your behalf while providing Postfjord, and it meets the requirements of article 28 of the EU General Data Protection Regulation (GDPR). If this DPA and the Terms of Service differ on data protection, this DPA applies. A signed copy is available on request from hello [at] postfjord.com.

1. Scope and roles

You are the controller for personal data about your contacts that you, your team or your automations handle in Postfjord, as described in Annex 1. We process that data only as your processor. Data about you and your team as our customers, and the shared email suppression list, are processed by us as controller and are covered by our Privacy Policy.

2. Your instructions

We process the data only on your documented instructions. Your instructions are these terms, the settings you choose and the actions you and your team take in Postfjord, including automations and API calls. We also process data when EU or Swedish law requires it, and then tell you first unless the law forbids it. If we believe an instruction breaks data protection law, we tell you.

3. Your responsibilities

You are responsible for having a lawful basis for the data and for sending messages and emails to your contacts, for informing your contacts about the processing, for the content of your instructions, and for handling your contacts' requests. You must not use custom fields or automations to collect special categories of personal data (such as health data) unless you have a lawful basis and appropriate safeguards.

4. Confidentiality and security

Everyone at Postfjord who can access the data is bound by confidentiality. We take the technical and organisational measures in Annex 2 and keep them appropriate to the risk. We may improve them over time but will not lower the overall level of protection.

5. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex 3. We tell you at least 30 days before we add or replace a sub-processor that will process your data, by email to the workspace owner or in the app, and we update Annex 3. If you have a reasonable data protection objection, tell us within that period; if we cannot resolve it, you may stop using the affected feature or end your subscription without penalty. We bind every sub-processor to data protection obligations that are at least as protective as this DPA and remain responsible for its work.

6. Transfers outside the EU and EEA

We transfer data outside the EU and EEA only to a sub-processor listed in Annex 3 and only with a valid safeguard: an EU adequacy decision, such as the EU-US Data Privacy Framework for certified companies, or the EU standard contractual clauses. Data you choose to send to services you connect yourself (for example Mailchimp or your own AI provider) is transferred on your instruction and under your own agreement with that provider.

7. Helping you

Taking into account the nature of the processing, we help you:

  • answer requests from your contacts to access, correct, delete, restrict, object to or port their data, mainly through the tools in the app, and otherwise on request;
  • meet your obligations on security, personal data breaches, data protection impact assessments and prior consultation with a supervisory authority, with the information we have.

If a contact sends a request about your data directly to us, we forward it to you and do not answer it ourselves unless you ask us to.

8. Personal data breaches

We notify you without undue delay, and where possible within 48 hours, after we become aware of a personal data breach affecting your data. We tell you what we know about its nature, the data and people affected, the likely consequences and the measures taken or proposed, and we add information as it becomes available.

9. Deletion and return

You can export your contacts at any time and delete a workspace in the app. When a workspace is deleted, or when your agreement ends and the workspace is deleted, we delete your data from our live database without undue delay. Database backups and restore points are kept for 7 days, so the data is gone from them within 7 days. Short-lived copies in logs and in our providers' systems are deleted on their normal schedules (for example email delivery events after 30 days and technical logs after about 30 days). We keep data longer only where EU or Swedish law requires it.

10. Information and audits

We make available the information needed to show that we meet this DPA. If that is not enough, you may audit our compliance once a year, with at least 30 days' notice, during business hours, at your own cost, through an independent auditor bound by confidentiality, and without access to other customers' data. For our sub-processors we may rely on their own certifications and audit reports.

11. Term, liability and law

This DPA applies for as long as we process personal data on your behalf. The limits of liability in the Terms of Service apply, except where data protection law does not allow them. Swedish law applies, and disputes are handled as set out in the Terms of Service.

Annex 1: Details of the processing

Subject matter and purposeProviding Postfjord to you: an inbox for messages and comments, contacts, automations and AI replies, email to your contacts, and related analytics, integrations and exports.
Nature of the processingReceiving, storing, organising, displaying, searching, analysing, sending and deleting data; automated processing by rules you set and by AI features you choose.
Data subjectsPeople who send direct messages to or comment on your connected Instagram and Facebook accounts; contacts you or your automations add; recipients of your emails; people who confirm or unsubscribe from your emails.
Categories of personal dataPlatform identifiers, names and usernames; email addresses and phone numbers; content of messages and comments, including links to attachments; birthdays, tags and other fields you define; conversation status, assignment and opt-out records; link clicks; email consent and unsubscribe records; email delivery, bounce and complaint events; when available, email opens and clicks.
Special categoriesNot intended. Messages that people choose to send may contain them.
DurationFor as long as you use Postfjord, then deleted as described in section 9.

Annex 2: Technical and organisational measures

  • Data stored in the EU (Google Cloud, Belgium) and email sent from the EU (Amazon SES, Stockholm).
  • Encryption in transit (TLS) and at rest by our cloud providers; access tokens and integration keys additionally encrypted by us with AES-256-GCM; API keys stored only as hashes.
  • Access to workspace data enforced by server-side security rules according to the roles the workspace owner sets; administrative access limited to named Postfjord staff and used only for support, security, abuse handling and legal obligations.
  • Incoming webhooks from Meta and Amazon are accepted only with a valid signature; email confirm and unsubscribe links use signed tokens.
  • Data minimisation: profile lookups used for automations are not stored, and the email suppression list stores only hashes.
  • Rate limits and abuse checks on public endpoints and sending.
  • Automatic deletion of automation logs and email delivery events after 30 days.
  • Daily database backups and point-in-time recovery, each kept for 7 days.
  • Separation of customer data by workspace.

Annex 3: Sub-processors

Sub-processorProcessingLocation
Google Cloud and FirebaseHosting, database, file storage and functions for all features, and checking links in your emails against Google Web Risk before they are sentEU (Belgium)
Amazon Web Services (Amazon SES)Sending your emails and returning delivery, bounce and complaint eventsEU (Stockholm, Sweden)
AnthropicAI replies and AI drafts that use conversation content, when your workspace uses Postfjord's AI rather than its own providerUSA (EU standard contractual clauses)
OderlandNotification emails to your team that can contain a contact's name, a message excerpt or a collected email addressSweden
CloudflareDelivering your landing pages and link in bio pages on postfjord.page, including the signup forms on them, so a visitor's request and what they type in a form pass through itGlobal (EU-US Data Privacy Framework and EU standard contractual clauses)

Meta is not our sub-processor: it runs the platforms your contacts use and is an independent controller. Services you connect yourself, such as Mailchimp or your own AI provider, act under your own agreement with them.

Postfjord

Social media scheduling, AI writing, inbox, DM automation, email and landing pages in one product. Built in Sweden.

Product

postsocial postchat postmail Dictation Landing pages and link in bio All features Pricing Product updates Download the app

Solutions

For creators For small businesses For agencies For salons and beauty For gyms and studios For restaurants and cafés ChatGPT, Claude, Gemini and MCP

Resources

Academy Help center Getting started Blog Plans and billing MCP setup Meta Muse and other agents

Compare

Linktree alternative Later alternative Buffer alternative ManyChat alternative

Company

About Contact Press Security Status Privacy Terms Data processing Data deletion
Deutsch Français Español Português (Brasil)
© 2026 Postfjord. Yogakollektivet Sverige AB, org. nr 556858-0699, Sweden. hello [at] postfjord.com · Cookie settings

May we use Google Analytics cookies to see which pages help people? Nothing is shared for advertising. Read more