Data Processing Agreement

Last updated 7 October 2026.

1. About this agreement

This data processing agreement is between Luminous Emporium Ltd, a company registered in England and Wales with registered office at 124-128 City Road, London, United Kingdom, EC1V 2NX and company number 16201976, which operates scatterpost ("we", "us"), and the business that holds the scatterpost account ("you"). It forms part of our terms of service and applies on every plan, including the Free plan, with no separate signature needed. It sets out the terms required by Article 28(3) of the UK GDPR for the personal data we process for you. Words such as controller, processor, personal data, processing and personal data breach have the meanings given in the UK GDPR. If this agreement conflicts with the terms on the processing of customer personal data, this agreement wins.

2. Roles

"Customer content" means the articles, drafts, media, channel data and report text you or your agents put into scatterpost, and any personal data in them ("customer personal data"). For customer personal data you are the controller and we are your processor. For the account, billing, usage and security data we hold about you and your team members, we are the controller, as set out in our privacy policy, and this agreement does not apply to that data.

You are responsible for having a lawful basis for the customer personal data you put into scatterpost, for giving any notices it needs, and for making sure your instructions to us comply with data protection law.

3. Details of the processing

Subject matter: providing scatterpost to you under the terms. Duration: for as long as your workspace exists, and after that until the customer personal data is deleted under section 12. Nature and purpose: storing and hosting customer content; drafting, formatting and adapting it for each platform, including AI-assisted generation where you ask for it; scheduling it; publishing it to your own website and the other platforms you connect; reading back links and performance figures for what was published; exporting it; and deleting it.

Types of personal data: any personal data you include in customer content, such as names, usernames, job titles, contact details, quotes, photographs and video of people; the names and identifiers of the accounts, Pages and sites you connect as channels; and any personal data in report text. Short-link click figures are counts only and hold no information about the person who clicked. You should not put special category data or criminal offence data into scatterpost unless you have a lawful basis for publishing it.

Categories of data subjects: your staff, authors and contributors; people named, quoted or pictured in your content; the people who own or manage the channels you connect; and anyone else whose personal data you choose to include.

4. Instructions

We process customer personal data only on your documented instructions, including on transfers outside the UK. Your instructions are the terms, this agreement, and the actions you or your agents take through the dashboard, the MCP server and the API, such as creating, scheduling, publishing, exporting or deleting content, and, where a connected platform tells us that its user has removed scatterpost or asked for deletion, deleting that connection and the data we hold for it as described in our privacy policy. The only exception is where UK law requires us to process it otherwise; in that case we will tell you before we do, unless that law forbids it. We will tell you if we believe an instruction infringes data protection law.

5. Confidentiality

Everyone we authorise to process customer personal data is bound by a duty of confidentiality, by contract or by law, and may access it only as needed to provide the service, give support, investigate problems or prevent abuse.

6. Security

We take the technical and organisational measures required by Article 32 of the UK GDPR. In summary: platform access tokens and webhook secrets are encrypted at rest with AES-256-GCM; every workspace's data is separated in the database by row-level security tied to workspace membership, and every API request is checked against the workspace it names before any row is read or changed; workspace members have owner, editor or viewer roles; API keys are stored only as hashes and can be revoked; access tokens, credentials and API keys are never returned by a tool or included in an export; error reports have credentials, tokens, sign-in link codes and email addresses removed, and carry no user, cookie or header data, before they are sent to our error-tracking provider; staff access to workspace data through our internal admin console needs a second sign-in factor, never shows credentials or tokens, and is recorded in an internal audit log; and access to our hosting and database providers' consoles is limited to authorised staff. We review these measures as the service changes.

7. Subprocessors

You give us general authorisation to use the subprocessors listed on our subprocessors page. We put each subprocessor under written data protection terms that give at least the protection of this agreement, and we remain responsible to you for their performance of those obligations.

Before we add or replace a subprocessor, we will update the subprocessors page and email the workspace owner at least 30 days in advance. You may object on reasonable data protection grounds by emailing hello@scatterpost.io within that period. We will discuss your objection in good faith, and if we cannot resolve it before the change takes effect, you may end the terms and this agreement with immediate effect by deleting your workspace, and we will refund any fees you have paid in advance for the unused part of your billing period.

8. International transfers

Our database, authentication and image storage are hosted by Supabase in London. Video files are stored with Vercel, in its London region, and Vercel also hosts the application, so customer content is processed on Vercel's infrastructure, including in the USA. Where a subprocessor processes customer personal data outside the UK, the transfer relies on UK adequacy regulations (for example, for the EEA), on the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner, or on the UK Extension to the EU-US Data Privacy Framework with the Standard Contractual Clauses, as named against each subprocessor on the subprocessors page.

9. Destination platforms

The platforms you connect and publish to, such as Dev.to, Hashnode, LinkedIn, Bluesky, Mastodon, X, Meta (Facebook and Instagram) and TikTok, are not our subprocessors. When you instruct us to publish, we send them the content you choose, and each receives and handles it as an independent controller under its own terms and privacy policy, including any transfer outside the UK. Content published to a platform stays there until you delete it on that platform. Your own website receives content under your control, not ours.

10. Assistance

Taking into account the nature of the processing, we will help you respond to requests from data subjects to exercise their rights. Most requests can be met directly in the dashboard, where you can edit and delete content, disconnect channels, export your workspace and delete it. If a data subject contacts us directly about customer personal data, we will pass the request to you and will not respond to it ourselves unless you ask us to. We will also give you the information we reasonably can to help with your security obligations, data protection impact assessments and any prior consultation with the Information Commissioner's Office.

11. Personal data breaches

We will notify the workspace owner by email without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting customer personal data. We will give you what you need to meet your own notification duties as it becomes available: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, its likely consequences, and the measures taken or proposed. We will take reasonable steps to contain the breach and reduce its effects.

12. Return and deletion

At any time, the workspace owner can export the workspace from workspace settings as one JSON file holding its articles, publications, channels (without credentials), short links with their click counts, members and audit log, with a download link for each media file that is valid for one hour. This is how customer personal data is returned to you; please export before you delete.

When the workspace owner deletes the workspace, we cancel any subscription and delete the workspace's media files, content, channels and their tokens, and the rest of its data from our database. We keep only a short deletion record (the workspace id and slug, who deleted it and when) and the billing records tax law requires. If these terms end without the workspace being deleted, we will delete it within 30 days, as set out in the terms, unless UK law requires us to keep some of it. Deleted data can remain in our database provider's routine backups for up to 7 days, until those backups expire. Content already published to a destination platform is not affected and stays there until you delete it on that platform.

13. Audits and information

We will make available the information reasonably needed to show that we meet Article 28 of the UK GDPR, by answering your written questions about our processing. If those answers are not enough, or a regulator requires it, you or an independent auditor bound by confidentiality may audit our compliance with this agreement, on at least 30 days' written notice, no more than once in any 12 months unless following a personal data breach or where a regulator requires it, during normal business hours and in a way that does not disrupt the service or give access to other customers' data. You bear your own costs of any audit.

14. Liability

Each party's liability arising out of or in connection with this agreement is subject to the limitations and exclusions of liability in section 7 of the terms, which apply to this agreement and the terms taken together. Nothing in this agreement limits any liability that cannot be limited by law, or any right a data subject has directly under the UK GDPR.

15. Changes, duration and governing law

This agreement lasts for as long as we process customer personal data for you. We may update it to reflect changes in the law or the service, and will give notice of any material change through the dashboard or by email; a change will not reduce the protection it gives customer personal data. It is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it.

16. Contact

Questions about this agreement can be sent to hello@scatterpost.io.