Skip to content
sendgecko

Data Processing Agreement

The data processing terms that apply when SendGecko processes personal data for you as a processor. Includes the EU Standard Contractual Clauses.

Last updated

This Data Processing Agreement (“DPA”) is part of the Terms of Service between PINTECH DOO Skopje (“SendGecko”, the “Processor”) and the customer who accepted them (the “Customer”, the “Controller”). It applies automatically, with no signature, whenever SendGecko processes personal data for the Customer in providing the Service.

Definitions and roles

“Data Protection Law” means the laws that apply to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, the Swiss FADP, the data protection law of North Macedonia, and US state privacy laws such as the California Consumer Privacy Act. “Personal Data”, “process”, “controller”, “processor” and “data subject” have the meaning the law gives them.

For personal data that is part of Customer Content (the posts, media, Resources, team member details, and similar data the Customer puts into SendGecko), the Customer is the controller and SendGecko is the processor. For the data SendGecko uses for its own purposes (accounts, billing, security, product improvement), SendGecko is an independent controller, as the Privacy Policy explains.

Instructions

SendGecko will process Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, and the Customer's use and settings of the Service (for example scheduling a post, connecting a channel, or choosing an AI model), unless the law requires otherwise, in which case SendGecko will tell the Customer first where it may.

If SendGecko thinks an instruction breaks Data Protection Law, it will tell the Customer and may pause the processing concerned.

Confidentiality

People at SendGecko who can access Personal Data are bound by confidentiality, get access only when they need it for their work.

Security

SendGecko applies the technical and organisational measures in Annex B, which are described in more detail on the Security page, and keeps them appropriate to the risk. We may update them if the level of protection doesn't go down.

Subprocessors

  • The Customer gives general authorisation for SendGecko to use the subprocessors listed on Subprocessors. AI providers are used only when the Customer or its users choose their models.
  • SendGecko will update that page and notify the workspace owner by email at least 30 days before a new subprocessor starts processing Customer Personal Data.
  • The Customer may object on reasonable data protection grounds within that time. We'll try to find a solution (for example by not using the new subprocessor for the Customer). If we can't, the Customer may end the affected Service and we'll refund the unused prepaid period for it.
  • SendGecko has a written agreement with each subprocessor that imposes data protection duties at least as protective as this DPA, and remains responsible for them.

Helping with data subject requests

Taking into account the nature of the processing, SendGecko will help the Customer answer requests from people exercising their rights (access, correction, deletion, restriction, portability, objection), mainly through the tools in the Service. If a person contacts SendGecko about Customer Personal Data, we'll point them to the Customer and won't answer on the Customer's behalf unless the law requires it.

Personal data breaches

SendGecko will notify the Customer without undue delay, and where possible within 72 hours, after becoming aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. The notice will describe what happened, the likely effect and what we're doing, and we'll keep the Customer updated and help it meet its own duties to notify.

Impact assessments and authorities

SendGecko will give reasonable help with data protection impact assessments and prior consultations with authorities that relate to the processing under this DPA.

Return and deletion

During the term, the Customer can export and delete Customer Content. After the Terms end, the Customer has 30 days to export its data. SendGecko then deletes Customer Personal Data as described in the retention table, except where the law requires it to be kept. Copies in encrypted backups are deleted when those backups expire (within 30 days) and aren't used for anything else.

Information and audits

SendGecko will give the Customer the information needed to show we follow this DPA, usually through answers to a security questionnaire and the documents on our Security page. If that isn't enough, or a supervisory authority requires it, the Customer may audit us once a year (or after a breach), with 30 days' written notice, during business hours, under confidentiality, without disturbing other customers, and at the Customer's own cost.

International transfers

SendGecko hosts Customer Personal Data in Germany and its team works from North Macedonia. If Customer Personal Data subject to the GDPR is transferred to SendGecko in a country without an adequacy decision, the parties agree that:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA, with the Customer as “data exporter” and SendGecko as “data importer”; Clause 7 (docking) applies; in Clause 9 Option 2 (general authorisation, 30 days) applies; in Clause 11 the optional wording doesn't apply; in Clause 17 the law of Germany applies; in Clause 18 the courts of Germany have jurisdiction; and the supervisory authority in Annex I.C is the one responsible for the data exporter;
  • for transfers from SendGecko to its subprocessors, SendGecko uses the Standard Contractual Clauses (Module Three) or another valid transfer mechanism, such as the EU–US Data Privacy Framework;
  • for transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses applies; for transfers subject to the Swiss FADP, the Clauses apply with references to the GDPR read as references to the FADP.

Annexes A, B and C of this DPA complete Annexes I, II and III of the Clauses. If the Clauses and this DPA conflict, the Clauses prevail.

US state privacy laws

Where US state privacy laws apply, SendGecko acts as the Customer's “service provider” or “processor”. It won't sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, or combine it with other data, except as the law allows.

Liability and order of precedence

Each party's liability under this DPA is subject to the limits in the Terms, except where the law or the Standard Contractual Clauses say otherwise. If documents conflict, the order is: the Standard Contractual Clauses, this DPA, then the Terms. This DPA lasts as long as SendGecko processes Customer Personal Data.

Annex A: details of the processing

Details of the processing
ItemDescription
Controller / exporterThe Customer, as identified by the workspace owner's account.
Processor / importerPINTECH DOO Skopje, Skopje, North Macedonia. Contact: contact@sendgecko.io.
Subject matter and purposeProviding the SendGecko Service: storing, adapting, scheduling and publishing content to the networks the Customer connects; showing analytics; AI-assisted writing when the Customer uses it; support.
DurationWhile the Customer uses the Service, plus the return and deletion period in section 9.
Nature of processingHosting, storage, transmission to the connected networks and chosen AI providers, formatting, resizing, retrieval, deletion.
Categories of data subjectsThe Customer's team members and invited guests; people who appear in or are mentioned in Customer Content; the Customer's audience, to the limited extent that aggregate counts or names appear in content.
Types of personal dataNames, email addresses, profile pictures, usernames and IDs on networks; any personal data in posts, captions, images, videos and Resources; connection credentials (encrypted); usage and log data.
Special categoriesNone intended. The Customer must not upload sensitive data unless necessary and lawful.
FrequencyContinuous, for as long as the Customer uses the Service.

Annex B: security measures

  • Encryption. TLS in transit. Access tokens, refresh tokens, app passwords, webhook URLs and AI provider keys are encrypted at rest with AES-256-GCM using versioned keys that can be rotated. Backups are encrypted.
  • Access control. Every query and action is scoped to a workspace and checked against the user's role. Passwordless sign-in (passkeys, email codes, Google), session management, and rate limiting and bot protection on sign-in.
  • Least privilege. We ask each network only for the permissions we need. Staff access to production data is limited, logged and based on need.
  • Secure processing. Webhook signatures are verified. Web addresses supplied by users are fetched only through a safeguarded fetcher that blocks private networks. Uploads are type-checked, and location data is removed from images.
  • Logging and monitoring. Audit log for sensitive actions, error monitoring with secrets redacted, and alerts for failures.
  • Resilience. Daily encrypted backups kept for 30 days, with regular restore tests.
  • Organisation. Confidentiality duties, an incident response process, and dependency and vulnerability management.

Annex C: subprocessors

The current list, with each subprocessor's purpose, data and location, is on sendgecko.io/subprocessors.