Data Processing Agreement (DPA)
Last updated: August 2026
Note: The German version of this document is legally binding. This English translation is provided for convenience only.
pursuant to Art. 28 GDPR, between the customer (controller) and the provider (processor). This DPA forms part of the usage agreement for Ikrames (terms and conditions) and applies to all processing of personal data that the provider carries out on behalf of the customer.
§ 1 Subject Matter and Duration
The provider processes personal data on behalf of the customer in order to provide the Ikrames services (creation, planning, publication and analysis of social media content). The duration corresponds to the term of the usage agreement.
§ 2 Nature and Purpose of the Processing
Types of data: account and profile data of the customer's team members (name, email), content and media that the customer contributes or has generated, connected social media accounts (access tokens, account identifiers), performance and interaction data of published content (including third-party comments together with their public profile information), billing and usage data.
Categories of data subjects: employees and agents of the customer, persons who interact with the customer's published content (e.g. commenters), and where applicable persons depicted in content.
Purpose: exclusively the provision of the contractually agreed services. The processing of aggregated, de-identified data for the provider's own purposes is not part of this mandate (§ 6).
§ 3 Right to Issue Instructions
The provider processes the data only on documented instructions from the customer; the customer's use of the Ikrames features constitutes such an instruction. If the provider considers an instruction to be unlawful, it shall inform the customer without undue delay and may suspend execution until the matter is clarified.
§ 4 Obligations of the Provider
The provider (a) obliges all persons involved in the processing to maintain confidentiality, (b) takes technical and organisational measures pursuant to Art. 32 GDPR (Annex 1), (c) supports the customer in responding to data subject requests and with the obligations under Art. 32–36 GDPR, (d) deletes or returns personal data after the end of the contract (§ 9), and (e) makes available to the customer the information required to demonstrate compliance (§ 10).
§ 5 Sub-processors
The customer grants general authorisation for the use of the sub-processors listed in Annex 2. The provider shall inform the customer in text form in advance of any intended changes (addition or replacement); the customer may object for good cause relating to data protection. Contracts meeting the requirements of Art. 28 GDPR are in place with every sub-processor.
§ 6 Aggregated Data for the Provider's Own Purposes
Insofar as the provider processes personal data on behalf of the customer, the provisions of this DPA apply. Separately from this, the provider is entitled to process usage and performance data in aggregated, de-identified form in order to improve and further develop its services; in this respect the provider acts as an independent controller within the meaning of Art. 4(7) GDPR. By technical measures (aggregation minimum thresholds, no records relating to individual customers in the analysis layer) the provider ensures that no conclusions about the customer, its brands or individual persons can be drawn from the aggregates.
§ 7 Data Subject Rights
If a data subject contacts the provider directly, the provider shall forward the request to the customer without undue delay. The provider supports the customer with suitable means (the platform's access, export and deletion functions) in fulfilling data subject rights.
§ 8 Notification Obligations
The provider shall notify the customer of personal data breaches affecting the mandate without undue delay after becoming aware of them, providing the information required under Art. 33(3) GDPR insofar as it is available.
§ 9 Deletion and Return
After the end of the contract, the provider deletes the personal data processed on behalf of the customer, unless a statutory retention obligation applies. Beforehand, the customer may secure its content via the platform's export functions. Aggregates already formed within the meaning of § 6 remain unaffected, as they no longer relate to identifiable persons.
§ 10 Evidence and Audits
The provider demonstrates compliance with this DPA by means of suitable documentation (including the description of measures under Annex 1, certificates and the data processing agreements of its sub-processors). Further audits take place by appointment and at the customer's expense.
§ 11 Final Provisions
In all other respects the terms and conditions apply. In the event of contradictions concerning data protection provisions, this DPA prevails. The law of the Federal Republic of Germany applies.
Annex 1 — Technical and Organisational Measures (TOMs)
- Encrypted transmission (TLS) for all connections.
- Access control: role-based permissions per workspace, row-level isolation in the database (Row Level Security), separate service credentials for system processes.
- Authentication via a specialised identity provider; access tokens of connected social accounts are not delivered to end devices in plain text.
- Logging of security-relevant events; backups by the infrastructure providers used.
- Server locations: the database and file storage are located in the European Union (Ireland); the application and the rendering service are likewise operated in the European Union (Amsterdam, Netherlands), for which the hosting service provider (Railway) uses Google Cloud Platform infrastructure. Processing of the customer's data therefore takes place in the EU. In addition, the hosting service provider processes account and usage data of the provider's own account (account, billing and usage information of the provider, not the customer's content) as an independent controller in the United States as well; that transfer takes place on the basis of the EU standard contractual clauses. Details in the „Hosting“ section of the privacy policy.
Annex 2 — Sub-processors
The same service providers are used as those named in the privacy policy under „Overview of Recipients and Processors“ — this list is generated from the same source and therefore cannot diverge from it:
- Railway — Hosting of the application and the render service (app data in transit, server logs). Operated in the EU (Amsterdam, Netherlands) since 17 August 2026, on Google Cloud Platform infrastructure. In addition, Railway processes account and usage data of our own account as an independent controller in the United States (basis: EU standard contractual clauses, Module 2, from the data processing agreement concluded on 16 August 2026). Provider: Railway Corporation, San Francisco, USA
- Supabase — Database and file storage (all user data). Project region eu-west-1 (Ireland, EU)
- Clerk — Identity and authentication (email, name, sessions)
- Stripe — Payments and invoices
- Bundle.social — Social media publishing, OAuth tokens of the connected channels. Provider: BUNDLE sp. z o.o., ul. Hoża 86/410, 00-682 Warsaw, Poland; processing within the European Economic Area
- ElevenLabs — Voice clones (voice samples)
- Anthropic — LLM processing of content texts
- OpenAI — Whisper transcription of standalone voice recordings, embeddings
- fal.ai — Image and video generation (prompts, in part brand images) and transcription of video audio tracks
- Cloudflare — DNS/proxy for ikrames.com
- PostHog — Product and reach analytics (page views, usage events) and session replays. EU hosting in Frankfurt (Germany). Anonymous reach measurement without access to your device on the basis of legitimate interest (Art. 6(1)(f) GDPR); identified analytics and session replays only with your consent (Art. 6(1)(a) GDPR). Provider: PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA. The data is hosted in the EU; where PostHog processes it in the USA beyond that, the EU Standard Contractual Clauses from PostHog's data processing agreement apply
- Resend — Delivery of system and transactional emails (recipient address, subject, message content). Provider: Plus Five Five, Inc. (trading as “Resend”), 2261 Market Street #5039, San Francisco, CA 94114, USA; basis: EU standard contractual clauses. Covers the acknowledgement for cancellation/withdrawal, the purchase confirmation for digital products, and the delivery of freebies together with the corresponding confirmation and welcome email
- Inngest — Job orchestration (event payloads containing user and content IDs and job parameters). Provider: Inngest Inc., United States; processing takes place in the USA. The EU standard contractual clauses are the envisaged basis for the transfer; the data processing agreement that makes them binding has been requested and is not yet in place
- Evomi — Proxy for source downloads in the render service — both for retrieval via yt-dlp and for direct file downloads. For encrypted targets (HTTPS) the proxy sees only the target host, the time and the amount of data transferred, not the content transmitted; for unencrypted targets (HTTP) it also sees the content. Provider: TeraShift GmbH, Switzerland; the transfer is based on the European Commission's adequacy decision for Switzerland (Decision 2000/518/EC, Art. 45 GDPR) — standard contractual clauses are not required for it