Last updated: September 13, 2026
This Data Processing Agreement ("DPA") is part of the Terms of Service between Remoteen, operating Depost AI ("Depost AI", "we", "us"), and the customer who accepts those Terms ("Customer", "you"). It applies whenever we process personal data on your behalf, which is the case when you use Depost AI to manage content for clients, or when the content in your workspace contains personal data about people other than you.
It applies automatically to every business customer; no signature is needed. If you need a countersigned copy for your records or for a client, email support@depost.ai and we will send one.
"Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "GDPR" means Regulation (EU) 2016/679 and, where it applies, the UK GDPR. "Customer Data" means the personal data you or your users put into the Service, or that the Service collects from a LinkedIn account you connect, and that we process for you. "Sub-processor" means a third party we use to process Customer Data.
For Customer Data, you are the controller (or a processor acting for your own client) and we are your processor. For the account data of the people who sign in to Depost AI, we are an independent controller, as described in our Privacy Policy; that data is outside this DPA.
You are responsible for having a lawful basis for the Customer Data you put into the Service, for the instructions you give us, and for having the permission of any client whose content you manage.
The details of the processing are set out in Annex 1. In short: we process Customer Data to provide Depost AI to you, for as long as you have an account, and we do not process it for any other purpose.
We process Customer Data only on your documented instructions. Your instructions are the Terms, this DPA, and your use of the Service, including what you and your team ask the Service to do and any request you make through the MCP connector. If we believe an instruction breaks the law, we will tell you before acting on it. We will not process Customer Data for our own purposes, and we will not use it to train AI models.
Everyone at Depost AI who can access Customer Data is bound by a confidentiality obligation and has access only to the extent needed to provide the Service and support you.
We keep in place the technical and organisational measures described in Annex 2, and we review them as the Service and the threats to it change. We may update those measures, but not in a way that reduces the overall level of protection.
You authorise us to use the sub-processors listed in section 7 of our Privacy Policy, which is Annex 3 of this DPA. Each of them is bound by written terms that protect Customer Data at least as well as this DPA does, and we remain responsible to you for their work.
Before we add or replace a sub-processor that will process Customer Data, we will update that list and email account holders at least 30 days in advance. If you have a reasonable data protection objection, tell us within those 30 days. We will try to resolve it; if we cannot, you may terminate the affected part of the Service by written notice before the change takes effect.
Depost AI is hosted in the United States, and we are based in Pakistan. Where Customer Data is transferred out of the EEA or the UK to a country without an adequacy decision, the transfer is covered by the EU Standard Contractual Clauses (module 2, controller to processor, or module 3, processor to processor, as applicable) and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference, and by the EU-US and UK-US Data Privacy Framework where a sub-processor is certified under it. The details in Annex 1 and the measures in Annex 2 serve as the annexes to those clauses. For the purposes of the Clauses only, the governing law and courts are those of Ireland; everything else in this DPA is governed by the Terms.
If a data subject contacts us directly about Customer Data, we will pass the request to you promptly and will not respond on our own unless the law requires it. We will help you respond to data subject requests, carry out data protection impact assessments, and consult with a supervisory authority, to the extent the request concerns our processing and you cannot do it yourself with the tools in the Service. Where that help needs significant effort, we may charge our reasonable costs, and we will tell you before we start.
If we become aware of a personal data breach affecting Customer Data, we will tell you without undue delay, and in any case within 72 hours of becoming aware of it. The notice will describe what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and what we have done or propose to do about it. We will update you as we learn more, and we will cooperate with your own notifications to authorities and data subjects.
You can delete Customer Data at any time through the Service, brand by brand or workspace by workspace. When you delete a brand, a workspace, or your account, the Customer Data in it is deleted from our live systems straight away. Encrypted backups that still contain it expire within 30 days and are used only to restore the Service after a failure, never to bring deleted data back. We instruct our sub-processors to delete their copies; where a provider keeps a transient copy for abuse monitoring under its own terms, it is deleted within 30 days. Before you delete, you can ask us for an export of your content in a machine-readable format, which we provide within 30 days. We keep Customer Data after termination only where the law requires it, and then only for as long as it requires.
On request, and no more than once in any 12 months, we will give you the information you reasonably need to confirm that we meet this DPA, by answering a written security questionnaire and sharing relevant documentation. If that is not enough for a specific, well-founded reason, or after a personal data breach, or where a supervisory authority requires it, you may audit us, or have an independent auditor bound by confidentiality do so, on at least 30 days' notice, during business hours, in a way that does not disrupt the Service, and at your cost. Findings are confidential.
We do not use Customer Data to train, fine-tune or evaluate AI models, ours or anyone else's, and our AI sub-processors are engaged on terms that prohibit them from doing so. Customer Data is never shown to other customers or used to improve output for them.
This DPA lasts as long as we process Customer Data for you. Liability under it is governed by the limitation of liability in the Terms; the rights of data subjects under Article 82 GDPR are not affected. If this DPA conflicts with the Terms on a data protection matter, this DPA wins; if it conflicts with the Standard Contractual Clauses, the clauses win. It is governed by the same law as the Terms. We may update this DPA when the law or the Service changes, and will tell account holders before a material change takes effect.
| Subject matter | Providing Depost AI: drafting, analysing, scheduling and publishing LinkedIn content, and keeping the memory and analytics that support it |
|---|---|
| Duration | For as long as you have an account; deleted from live systems on the deletion of a brand, a workspace or the account, and from backups within 30 days |
| Nature and purpose | Storing, organising, analysing and generating content from Customer Data, and transmitting it to LinkedIn and to the AI client you connect, on your instruction |
| Categories of data subjects | Your team members and invited users; the people whose LinkedIn accounts you connect; people who appear in your content, such as those who comment on or react to posts; and people named in the documents and knowledge you add |
| Categories of personal data | Names, LinkedIn profile details and identifiers, post and comment text, engagement and performance data, images, and any personal data in the content and documents you provide |
| Special categories | None intended. You agree not to put special category data into the Service |
| Frequency | Continuous, for the duration of the account |
The current list is section 7 of our Privacy Policy, with the purpose, country and privacy terms of each. It is dated, and it is updated before any change takes effect.