This Data Processing Agreement (“DPA”) applies when you (the “Customer”) use Skedeon to process personal data of other people. It is part of the Terms of Service between the Customer and Vertex Digital L.L.C-FZ, a limited liability company registered in the Meydan Free Zone, Dubai, United Arab Emirates, License No. 2648533.01, registered address Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates (“Vertex Digital”). It is designed to meet Article 28 of the EU and UK General Data Protection Regulation (GDPR) and similar laws. No signature is needed; if your organization needs a signed copy, write to privacy@skedeon.com.
1. Roles
- Customer = controller for “Customer Personal Data”: personal data of the Customer’s audiences and contacts that the Service processes on the Customer’s instructions.
- Vertex Digital = processor of Customer Personal Data.
- Vertex Digital is an independent controller for data about account holders (sign-in, billing relationship, support, security), as described in the Privacy Policy. Paddle is an independent controller for payment data. Meta, Google, TikTok and other platforms to which the Customer publishes are independent controllers, not our sub-processors.
2. Subject matter and details of processing
- Purpose and nature: providing the Service — storing, organizing, displaying, analysing and transmitting data to schedule and publish content, manage comments and messages, run automations (Autoreply, Flows), SmartLinks and analytics.
- Data subjects: people who interact with the Customer’s connected accounts (commenters, people who send messages, followers counted in statistics, people who click SmartLinks), contacts in Flows, people who appear in the Customer’s content, and the Customer’s team members.
- Categories of data: platform user names and IDs, profile names and pictures, message and comment content, interaction history, tags and fields set by the Customer, aggregated statistics, and content uploaded by the Customer. The Service is not designed for special categories of data, and the Customer should not use it to collect them.
- Duration: for as long as the Customer uses the Service, then deletion as described in section 9.
3. Instructions
Vertex Digital processes Customer Personal Data only on the Customer’s documented instructions, which are the Terms, this DPA and the Customer’s use and configuration of the Service, unless the law requires otherwise (in which case we inform the Customer first unless the law forbids it). We tell the Customer if we believe an instruction breaks data protection law.
4. Confidentiality
Everyone at Vertex Digital authorized to process Customer Personal Data is bound by confidentiality and accesses it only as needed to provide, support or secure the Service.
5. Security
We apply appropriate technical and organizational measures, including: encryption in transit (TLS) and of platform access tokens at rest; access restricted to authorized staff with strong authentication; separation of each workspace’s data; logging of administrative access and of actions taken through the API and AI connector; automatic deletion periods (for example inbox data older than 90 days and media after publication); backups and recovery procedures; and regular review of these measures.
6. Sub-processors
The Customer gives general authorization for the sub-processors below. We impose on each of them data protection obligations equivalent to this DPA and remain responsible for them. We announce new sub-processors on this page and by e-mail to account holders at least 15 days in advance; the Customer may object on reasonable data protection grounds, and if we cannot address the objection the Customer may cancel and receive a refund of the unused prepaid period.
- Cloudflare, Inc. — hosting of the application, content delivery, security, media storage (global network).
- Supabase, Inc. — database hosting (European Union).
- Sendinblue SAS (Brevo) — transactional e-mail to account holders (European Union).
7. International transfers
Vertex Digital is established in the United Arab Emirates. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree to the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller to processor) and, where relevant, Module 3 (processor to processor), with the UK Addendum for UK data. These clauses are incorporated by reference, with Dubai law chosen where the clauses allow and otherwise the law and courts of Ireland; this DPA provides the information for their annexes. We also rely on the transfer mechanisms of our sub-processors.
8. Assistance, breaches and audits
- Data subject requests: the Service lets the Customer find, export and delete data; we help with requests the Customer cannot handle alone, and forward requests we receive directly to the Customer.
- Personal data breaches: we notify the Customer without undue delay, and in any case within 48 hours after becoming aware of a breach affecting Customer Personal Data, with the information available and updates as we learn more.
- Other assistance: we provide reasonable information the Customer needs for data protection impact assessments and consultations with authorities.
- Audits: we make available the information needed to show compliance with this DPA. Where that is not enough, the Customer may audit once a year, with 30 days’ notice, during business hours, at its own cost and under confidentiality, or appoint an independent auditor to do so.
9. Deletion at the end
When the Customer deletes its account (Settings → Delete account), Customer Personal Data is deleted immediately from the live systems and from backups within 30 days, unless the law requires us to keep it. Before deleting, the Customer can export its data from the app.
10. General
This DPA lasts as long as we process Customer Personal Data. If it conflicts with the Terms, this DPA prevails for data protection matters; the Standard Contractual Clauses prevail over both. Liability under this DPA is subject to the limits in the Terms, except where the law does not allow it. This DPA is written in English; translations are provided for convenience, and the English version prevails in case of conflict. Contact: privacy@skedeon.com.