Data processing agreement

This version took effect on 22 August 2026.

In short: where you put other people’s personal data into this service, you decide what happens to it and we carry out your instructions. This sets out what we may do with it, how we protect it, who else can see it, what happens when you leave, and what we owe you if something goes wrong. It applies automatically to every customer; you do not have to sign anything.

1. Who this is between, and how it takes effect

This agreement is between you, the customer named on the account (the controller), and DEVIORA S.R.L., a limited liability company registered in Romania of Calea Șerban Vodă 282, Sector 4, București 040221, holding CUI 55471145 and trade register number J2026051139003, with a share capital of 500 lei (the processor, “we”).

It takes effect when you accept the terms of service, and it forms part of them. You do not need to sign or return anything. If your organisation needs a countersigned copy for its records, write to hello@crestnote.com and we will provide one.

Where this agreement and the terms of service conflict on the processing of personal data, this agreement governs. On everything else, the terms govern.

2. Which of us is which

You are the controller of the personal data you put into the service or instruct it to collect: the content you publish, the people who comment on your posts, the audience figures collected for your accounts, and the details of the team members you invite. You decide what is collected and why, and you are responsible for having a lawful basis for it.

We are the controller, separately and in our own right, of your account and billing relationship: who signed up, what plan they are on, what they were charged. That is described in the privacy policy and is not covered by this agreement.

3. What is processed, and for how long

The processing under this agreement is:

  • Subject matter and purpose: providing a social media management service, which means publishing content you schedule, reading back what the platforms report about it, collecting public figures for competitor profiles you nominate, and generating drafts you ask for.
  • Duration: for as long as your workspace exists, and afterwards only as section 9 allows.
  • Categories of data subject: your team members; people who comment on or interact with your posts; the operators of the public profiles you choose to track.
  • Categories of personal data: names, email addresses, social handles and profile pictures; the text of comments and the identity of the person who wrote them; whatever personal data you choose to include in the content you publish; platform identifiers and access tokens for the accounts you connect.
  • Special category data: none is required by the service and none should be entered into it. If you publish content revealing political opinions, religious beliefs, health, sexual orientation or trade union membership, that is your decision as controller and your lawful basis to hold.

4. We act on your instructions

We process personal data only on your documented instructions, including on transfers, unless the law requires otherwise. Your use of the service is itself an instruction: adding a competitor profile instructs us to collect its public figures, and scheduling a post instructs us to publish it.

If we believe an instruction breaks data protection law, we will tell you and may pause that processing until it is resolved. If the law requires us to process something beyond your instructions, we will tell you before doing it unless that same law forbids us from saying so.

We will not sell personal data, use it for advertising, or use one customer’s data to build, train or improve anything shown to another customer, including any benchmark or industry average, whether aggregated, anonymised or derived from it. Nothing in the service pools tenant data, and nothing will.

5. The AI features, specifically

Text and image features send the material you give them to the providers named in section 7 at the moment you use them. Under our agreements with those providers, that material is not used to train their models.

It is worth being exact about what leaves: the brief you typed, the brand description you saved, and any post or comment you asked a feature to work from. Your database, your media library and your connected account tokens are never sent to a model provider.

6. How we protect it

We keep appropriate technical and organisational measures under Article 32. The ones worth naming, because they are specific enough for you to hold us to:

  • Access tokens for connected accounts are stored as AES-256-GCM ciphertext, in a database schema the application role cannot read, under a key held outside the database. They are decrypted server-side for the duration of one call and are never sent to a browser.
  • Every table holding customer data is protected by a row-level security policy keyed to workspace membership and enforced by the database, so a query written wrongly in application code returns nothing rather than another tenant’s rows.
  • There is no database credential in any browser. Every read and write goes through a server boundary that has already resolved the caller’s identity and workspace.
  • Data is encrypted in transit, and at rest by our database and storage provider.
  • Every upstream error is passed through a single redactor before it is stored or shown, because platforms quote access tokens back inside their own error payloads.
  • Access to production systems is limited to people who need it, and each of them is individually identified.

The security page describes these in the words an engineer would use, and says plainly which assurances we do not yet have.

7. Sub-processors

You give general authorisation for us to engage sub-processors. The current list is published and kept current, and as of the date at the top of this page it is Supabase, Vercel, Anthropic, OpenAI, Stripe and Resend.

Each is bound by written terms offering protection equivalent to this agreement, and we remain fully liable to you for their performance.

Before a new sub-processor begins processing, we will give you at least 30 days’ notice by email and by updating that page. If you object on reasonable data protection grounds within that period, we will either find another way to deliver that part of the service or let you end your subscription for the remainder of the term without penalty.

8. If something goes wrong

We will notify you of a personal data breach affecting your data without undue delay and in any case within 72 hours of becoming aware of it. The number is not decoration: Article 33 gives you 72 hours from the moment you become aware, and a processor who promises only “promptly” hands you a deadline you cannot meet.

The notice will describe what happened, which categories of data and roughly how many records are affected, what the likely consequences are, and what we have done about it. If we do not have all of that at first, you get what we have and the rest as it comes rather than a delayed complete report.

We will help you meet your own obligations under Articles 33 to 36, including data protection impact assessments and prior consultation, taking into account what we know and what is available to us.

9. Deletion and return

You can export your data at any time while your workspace exists. On termination, or on request, we will delete it. Deleting a workspace removes its content, media, connections, collected figures and comments, and access tokens are destroyed the moment a connection is removed rather than on a schedule.

Two things deliberately survive, and both are narrow:

  • Invoices and payment records, kept for as long as tax law requires. These are our own controller data under section 2 and are not part of the processing here.
  • The record that a deletion request was made and completed, and on what date, kept as evidence that we honoured it. For a request started from inside Facebook, that record keeps the app-scoped identifier the platform gives us for the person, indefinitely, because without it we cannot answer the status page Facebook hands them, tell a repeat request from a new one, or show anybody that the deletion happened. That identifier is scoped to this application and identifies the person nowhere else. The privacy policy describes it in full.

Backups roll off on their own cycle and are not selectively edited, which means data deleted from the live service can persist in a backup for a short period before it is overwritten. Nothing is restored from a backup into the live service to recover data you asked us to delete.

10. Helping you answer data subjects

Where somebody exercises a right against you and the data is in this service, we will help you answer, taking into account the nature of the processing. In most cases you can do it yourself from inside the product, which is faster than asking us.

If a data subject contacts us directly about data we process for you, we will not answer on your behalf. We will tell them to contact you, and tell you it happened, unless we are legally required to respond.

11. Demonstrating compliance

We will make available the information reasonably needed to show that we meet Article 28, which for a service of this size means answering your questions in writing and pointing at the published documents that describe the processing.

You may audit no more than once in a twelve-month period, on 30 days’ written notice, during business hours, at your cost, and without disrupting the service or touching another customer’s data. Where an independent report covering the same ground exists, sharing it satisfies this. There is no such report today, and the security page says so rather than implying otherwise.

12. International transfers

Everything we store ourselves is stored in the European Union. Some sub-processors are in the United States, and each is named with its location on the sub-processor page. Where personal data covered by UK or EU law is transferred out of that area, the transfer relies on the Standard Contractual Clauses or another Article 46 mechanism in that provider’s own terms, which are linked from that page.

13. Confidentiality

Everyone we authorise to process your data is bound to keep it confidential, by contract or by a statutory obligation, and that survives the end of their involvement.

14. Law, and changes to this agreement

This agreement is governed by Romanian law and by the GDPR, and the courts of Romania have jurisdiction, matching the terms of service.

We may update this agreement where the law changes or the service does. Material changes are notified by email at least 30 days before they take effect, and the date at the top of this page always says which version is in force.

Questions, and requests for a countersigned copy, go to hello@crestnote.com.