A draft, not yet in force. It still needs XONIK's registered name, registered address, contact address, governing law and date they take effect. Until then this describes accurately what the software does, and it is not a document anybody should rely on.

Data processing addendum

In force from [not yet in force]

This applies where you are a controller of personal data and we process it for you — which for an agency using Dispatch on behalf of its clients is the normal case. It forms part of the terms between [registered name] and you, and takes precedence over them on anything about personal data.

Roles

You are the controller. We are the processor. Where you are yourself a processor for your own client, we are the sub-processor and this addendum flows down: the same obligations apply to us that apply to you.

Scope

Subject matterPublishing content to LinkedIn on your instruction, and reporting on it
DurationThe life of the account, plus 30 days for export
Nature and purposeStorage, scheduling, publication, retrieval of engagement figures, and record-keeping of approvals
Categories of personYour staff and your clients' staff who use the panel; members of the public who comment on a published post
Categories of dataNames, business email addresses, roles, authored content, approval records with network addresses, LinkedIn access tokens, and for commenters a name, headline and picture for 24 hours
Special categoriesNone. Do not put any into a post.

Your instructions

The panel and these terms are your documented instructions. We process only on them, and we will tell you if we believe an instruction breaks data protection law rather than carrying it out quietly.

Our obligations

Measures actually in place

Written as what the software does, not as what a certificate says. The current list, and everything not held, is on the security page.

Sub-processors

Hosting, mail, and LinkedIn for the publishing itself. Each is named, with its region, on the security page, which is generated from the running system rather than maintained separately. We will give 30 days' notice before adding one, and you may object on reasonable data protection grounds; if we cannot resolve it, you may end the account and we will refund the unused part of the period.

Transfers

Where personal data leaves the region named on the security page, the transfer relies on the standard contractual clauses or on an adequacy decision, whichever applies to that provider.

Liability

The limits in the terms apply to this addendum as well, except where the law does not permit them.

Ending

This addendum lasts as long as we process personal data for you. On termination you may export everything for 30 days, after which we delete it. You can erase it yourself at any time and it happens immediately.