Data Processing Addendum
dpa-v1.0This Data Processing Addendum forms a binding part of the SMAT Terms when the customer is a controller and SMAT processes personal data on that customer’s documented instructions.
1.Parties, effect and scope
This Data Processing Addendum forms a binding part of the SMAT Terms when the customer is a controller and SMAT processes personal data on that customer’s documented instructions. It takes effect with the applicable service contract; no separate signature is required unless mandatory law or an agreed order requires one. SMAT is the processor for that processing. The customer remains controller and is responsible for lawful instructions, notices, legal bases and data-subject requests.
The subject is operation of the SMAT account and requested content, assistant, storage, scheduling and publishing functions for the contract term. Processing may include collection, organization, storage, retrieval, generation, transmission, restriction and deletion of account identifiers, brand information, instructions, communications, media, social-platform identifiers and content about persons chosen by the customer. Data subjects may include customer staff, contacts, audiences and people depicted or mentioned in submitted material.
2.Instructions and confidentiality
SMAT processes customer personal data only on documented instructions in the contract, account configuration and authenticated actions, including approved transfers, unless Union or Member State law requires otherwise. If legally permitted, SMAT informs the customer before mandatory processing. SMAT promptly flags an instruction it believes infringes applicable data-protection law.
People authorized to process customer personal data are bound by confidentiality and receive access only as needed for their role. The customer must not submit special-category, criminal-offence or other high-risk data unless SMAT has expressly agreed appropriate scope and safeguards in writing.
3.Security measures
SMAT maintains measures proportionate to the current service risk, including tenant-scoped authorization, protected secrets, session and request controls, transport encryption, logging, controlled provider gateways, backups where configured, incident handling, data export and registered erasure paths. Measures are reviewed as the service changes.
The customer is responsible for account permissions, strong credentials, connected-platform access, lawful content selection and prompt removal of access that is no longer required. No measure guarantees absolute security.
4.Sub-processors
The customer gives general authorization only for a provider and product function whose row in the current Privacy Notice explicitly identifies a processor or sub-processor role supported by a retained contractual receipt. A row marked “unverified — dependent production flow blocked” is not authorized by this clause and the dependent flow must remain blocked. SMAT will provide reasonable advance notice of a material new evidenced sub-processor where required, allowing the customer to object on substantiated data-protection grounds. SMAT remains responsible for imposing applicable processor obligations on an engaged sub-processor.
This Addendum does not infer a controller, processor or sub-processor role from an integration and does not claim that a particular provider DPA, Data Privacy Framework certification or Standard Contractual Clauses have been signed or verified.
5.Assistance and personal-data breaches
Taking account of the nature of processing and information available, SMAT assists the customer with data-subject requests, security, breach notifications, impact assessments and prior consultation duties. Assistance beyond standard product functions may be charged where permitted and agreed.
SMAT notifies the customer without undue delay after becoming aware of a personal-data breach affecting customer data and provides available information about its nature, likely consequences, affected data and subjects, mitigation and contact point. Early notices may be supplemented as investigation continues. Notification is not an admission of fault.
6.Return, deletion and audit information
At the customer’s choice and subject to mandatory retention, SMAT deletes or returns customer personal data after the service ends and deletes remaining copies through the applicable lifecycle. Data isolated for legal retention is not used for other purposes. Account export and erasure functions provide the standard operational path.
SMAT makes information reasonably necessary to demonstrate Article 28 compliance available to the customer. Audits must protect other customers, security and confidentiality, use existing independent evidence first, give reasonable notice and avoid unreasonable disruption. Each party bears its own ordinary costs unless a material breach by SMAT is established.
7.Transfers, precedence and contact
SMAT makes a restricted transfer only where a valid mechanism and required safeguards have been verified for the active provider flow. If the parties must enter additional transfer clauses, they will do so before the dependent processing is activated.
This Addendum prevails over conflicting service terms on processor obligations. Mandatory data-protection law prevails over both. Undefined terms have the GDPR meaning. Privacy and processor questions go to [email protected].