Data Processing Agreement
This Data Processing Agreement ("DPA") is part of the Terms of Service between you, the customer who owns a Postfjord workspace ("you", the controller), and Yogakollektivet Sverige AB, org. nr 556858-0699, Sweden ("Postfjord", "we", the processor). It applies whenever we process personal data on your behalf while providing Postfjord, and it meets the requirements of article 28 of the EU General Data Protection Regulation (GDPR). If this DPA and the Terms of Service differ on data protection, this DPA applies. A signed copy is available on request from hello [at] postfjord.com.
1. Scope and roles
You are the controller for personal data about your contacts that you, your team or your automations handle in Postfjord, as described in Annex 1. We process that data only as your processor. Data about you and your team as our customers, and the shared email suppression list, are processed by us as controller and are covered by our Privacy Policy.
2. Your instructions
We process the data only on your documented instructions. Your instructions are these terms, the settings you choose and the actions you and your team take in Postfjord, including automations and API calls. We also process data when EU or Swedish law requires it, and then tell you first unless the law forbids it. If we believe an instruction breaks data protection law, we tell you.
3. Your responsibilities
You are responsible for having a lawful basis for the data and for sending messages and emails to your contacts, for informing your contacts about the processing, for the content of your instructions, and for handling your contacts' requests. You must not use custom fields or automations to collect special categories of personal data (such as health data) unless you have a lawful basis and appropriate safeguards.
4. Confidentiality and security
Everyone at Postfjord who can access the data is bound by confidentiality. We take the technical and organisational measures in Annex 2 and keep them appropriate to the risk. We may improve them over time but will not lower the overall level of protection.
5. Sub-processors
You give us general authorisation to use the sub-processors listed in Annex 3. We tell you at least 30 days before we add or replace a sub-processor that will process your data, by email to the workspace owner or in the app, and we update Annex 3. If you have a reasonable data protection objection, tell us within that period; if we cannot resolve it, you may stop using the affected feature or end your subscription without penalty. We bind every sub-processor to data protection obligations that are at least as protective as this DPA and remain responsible for its work.
6. Transfers outside the EU and EEA
We transfer data outside the EU and EEA only to a sub-processor listed in Annex 3 and only with a valid safeguard: an EU adequacy decision, such as the EU-US Data Privacy Framework for certified companies, or the EU standard contractual clauses. Data you choose to send to services you connect yourself (for example Mailchimp or your own AI provider) is transferred on your instruction and under your own agreement with that provider.
7. Helping you
Taking into account the nature of the processing, we help you:
- answer requests from your contacts to access, correct, delete, restrict, object to or port their data, mainly through the tools in the app, and otherwise on request;
- meet your obligations on security, personal data breaches, data protection impact assessments and prior consultation with a supervisory authority, with the information we have.
If a contact sends a request about your data directly to us, we forward it to you and do not answer it ourselves unless you ask us to.
8. Personal data breaches
We notify you without undue delay, and where possible within 48 hours, after we become aware of a personal data breach affecting your data. We tell you what we know about its nature, the data and people affected, the likely consequences and the measures taken or proposed, and we add information as it becomes available.
9. Deletion and return
You can export your contacts at any time and delete a workspace in the app. When a workspace is deleted, or when your agreement ends and the workspace is deleted, we delete your data from our live database without undue delay. Database backups and restore points are kept for 7 days, so the data is gone from them within 7 days. Short-lived copies in logs and in our providers' systems are deleted on their normal schedules (for example email delivery events after 30 days and technical logs after about 30 days). We keep data longer only where EU or Swedish law requires it.
10. Information and audits
We make available the information needed to show that we meet this DPA. If that is not enough, you may audit our compliance once a year, with at least 30 days' notice, during business hours, at your own cost, through an independent auditor bound by confidentiality, and without access to other customers' data. For our sub-processors we may rely on their own certifications and audit reports.
11. Term, liability and law
This DPA applies for as long as we process personal data on your behalf. The limits of liability in the Terms of Service apply, except where data protection law does not allow them. Swedish law applies, and disputes are handled as set out in the Terms of Service.
Annex 1: Details of the processing
| Subject matter and purpose | Providing Postfjord to you: an inbox for messages and comments, contacts, automations and AI replies, email to your contacts, and related analytics, integrations and exports. |
|---|---|
| Nature of the processing | Receiving, storing, organising, displaying, searching, analysing, sending and deleting data; automated processing by rules you set and by AI features you choose. |
| Data subjects | People who send direct messages to or comment on your connected Instagram and Facebook accounts; contacts you or your automations add; recipients of your emails; people who confirm or unsubscribe from your emails. |
| Categories of personal data | Platform identifiers, names and usernames; email addresses and phone numbers; content of messages and comments, including links to attachments; birthdays, tags and other fields you define; conversation status, assignment and opt-out records; link clicks; email consent and unsubscribe records; email delivery, bounce and complaint events; when available, email opens and clicks. |
| Special categories | Not intended. Messages that people choose to send may contain them. |
| Duration | For as long as you use Postfjord, then deleted as described in section 9. |
Annex 2: Technical and organisational measures
- Data stored in the EU (Google Cloud, Belgium) and email sent from the EU (Amazon SES, Stockholm).
- Encryption in transit (TLS) and at rest by our cloud providers; access tokens and integration keys additionally encrypted by us with AES-256-GCM; API keys stored only as hashes.
- Access to workspace data enforced by server-side security rules according to the roles the workspace owner sets; administrative access limited to named Postfjord staff and used only for support, security, abuse handling and legal obligations.
- Incoming webhooks from Meta and Amazon are accepted only with a valid signature; email confirm and unsubscribe links use signed tokens.
- Data minimisation: profile lookups used for automations are not stored, and the email suppression list stores only hashes.
- Rate limits and abuse checks on public endpoints and sending.
- Automatic deletion of automation logs and email delivery events after 30 days.
- Daily database backups and point-in-time recovery, each kept for 7 days.
- Separation of customer data by workspace.
Annex 3: Sub-processors
| Sub-processor | Processing | Location |
|---|---|---|
| Google Cloud and Firebase | Hosting, database, file storage and functions for all features, and checking links in your emails against Google Web Risk before they are sent | EU (Belgium) |
| Amazon Web Services (Amazon SES) | Sending your emails and returning delivery, bounce and complaint events | EU (Stockholm, Sweden) |
| Anthropic | AI replies and AI drafts that use conversation content, when your workspace uses Postfjord's AI rather than its own provider | USA (EU standard contractual clauses) |
| Oderland | Notification emails to your team that can contain a contact's name, a message excerpt or a collected email address | Sweden |
| Cloudflare | Delivering your landing pages and link in bio pages on postfjord.page, including the signup forms on them, so a visitor's request and what they type in a form pass through it | Global (EU-US Data Privacy Framework and EU standard contractual clauses) |
Meta is not our sub-processor: it runs the platforms your contacts use and is an independent controller. Services you connect yourself, such as Mailchimp or your own AI provider, act under your own agreement with them.