Data Processing Agreement (DPA)
Agreement pursuant to Art. 28 GDPR between you as controller and Fade Media GmbH as processor. Version 1.0, as of 2026-08-07. Acceptance takes place in the dashboard under Settings → Privacy → Data processing agreement, where the signed version with its date is also available for download. The German version is the authoritative one in case of doubt.
§ 1 Subject matter and roles
The customer ("controller") uses PostOmnia to plan, approve, publish and analyse its own and third-party social media presences. Where personal data is processed in doing so, Fade Media GmbH ("processor") acts exclusively on the controller's documented instructions.
The controller remains responsible for the lawfulness of the processing – in particular for being permitted to process the content, contact data and social media credentials it brings into PostOmnia. Where the controller itself acts on behalf of its own clients (the typical agency case), Fade Media GmbH acts as a sub-processor.
For the customer's own contract, billing and account data, Fade Media GmbH is itself the controller; the Privacy Policy applies to that, not this agreement.
§ 2 Nature, purpose and duration
- Nature: storing, organising, retrieving, using, transmitting to the social media platforms selected by the controller, and erasing.
- Purpose: providing the contractually agreed functions – editorial planning, content creation (including AI-assisted), client approval, publishing, analytics, link-in-bio pages and team collaboration.
- Duration: for the term of the main contract. § 9 applies after termination.
§ 3 Categories of data subjects and data
- Data subjects: the controller's staff and team members; its clients and their contacts (approval portal); subscribers to link-in-bio pages; persons identifiable in uploaded content or media.
- Categories of data: master and contact data (name, email address, role); content data (post texts, images, videos, comments, approval decisions); access and connection data of the connected social media accounts (stored encrypted); usage and log data (timestamps, IP address, actions in the audit log); reach and click metrics.
Special categories of personal data under Art. 9 GDPR are not the subject of this agreement. If the controller nevertheless submits such data as content, the processor handles it like any other content data; the controller assesses admissibility.
§ 4 Instructions
The processor processes the data solely on the controller's documented instructions. This agreement, the main contract and the settings and actions performed within the service constitute instructions. Further instructions are issued in text form to info@postomnia.com.
If the processor considers an instruction unlawful, it shall notify the controller without undue delay and may suspend execution until the matter is resolved. Where Union or Member State law requires processing, the processor informs the controller beforehand unless that law prohibits it.
§ 5 Confidentiality
The processor engages only persons who are bound by confidentiality or under an appropriate statutory obligation of confidentiality, and who have been familiarised with the applicable data protection requirements before starting work.
§ 6 Technical and organisational measures
The processor implements the measures described in Annex 1 (TOM) pursuant to Art. 32 GDPR. The measures may be developed further as long as the level of protection is not reduced. Annex 1 forms part of this agreement.
§ 7 Sub-processors
The controller grants general authorisation for engaging the sub-processors listed in Annex 2 (sub-processor list). The processor imposes on each sub-processor obligations at least equivalent to those agreed here.
Changes to the list are announced at least 30 days in advance by email to the address stored in the account. Within that period the controller may object for an important data-protection-related reason; if no agreement is reached, it may terminate the main contract for cause with effect from the date the change takes effect.
§ 8 International transfers
Processing takes place within the European Union as a matter of principle. Where individual sub-processors process outside the EU, this occurs only on the basis of a mechanism under Art. 44 et seq. GDPR – in particular an adequacy decision or the EU Standard Contractual Clauses with supplementary measures. The applicable basis is stated per provider in Annex 2.
§ 9 Erasure and return
The controller can export its data at any time (Settings → Privacy → Export my data) and permanently delete workspaces or the account. After the main contract ends, the processor erases the processed data within 30 days unless a statutory retention obligation applies. Invoices and receipts are subject to retention under German tax and commercial law and are blocked rather than erased for the duration of that period. Backups are overwritten as part of the regular rotation cycle (see Annex 1).
§ 10 Assistance obligations
The processor assists the controller by appropriate means with
- requests from data subjects under Art. 15–22 GDPR – largely already covered by the export and deletion functions built into the product;
- compliance with the obligations under Art. 32–36 GDPR, in particular data protection impact assessments;
- notification of personal data breaches. The processor notifies the controller of such breaches without undue delay and no later than 48 hours after becoming aware of them, including the information required under Art. 33(3) GDPR.
§ 11 Evidence and audits
The processor makes available the information necessary to demonstrate compliance – primarily through the documentation in Annex 1 and the security overview at /sicherheit.html. Where that is not sufficient, it allows for and contributes to audits, including inspections, after reasonable prior notice, during normal business hours and without disrupting operations. The controller bears the cost of an on-site audit unless the audit reveals a breach.
§ 12 Liability and final provisions
Liability is governed by Art. 82 GDPR and the provisions of the main contract. German law applies. In the event of conflicts between this agreement and the main contract, this agreement prevails on data protection matters.
Version 1.0 · As of 2026-08-07 · Annex 1: TOM · Annex 2: Sub-processors