1. Parties and precedence
This Data Processing Addendum is between PostoX, Inc ('Posto') and the customer that has accepted the Posto Terms or an Order Form ('Customer'). It forms part of the agreement. If this DPA conflicts with the agreement on processing personal data, this DPA controls.
2. Definitions and roles
Controller, processor, personal data, processing, data subject, and supervisory authority have the meanings in applicable data-protection law. Customer is controller or processor for Customer Personal Data. Posto is processor or subprocessor when it processes that data solely to provide the service. Posto is an independent controller for account administration, security, fraud prevention, billing, legal compliance, and its own business records.
3. Processing instructions
Posto will process Customer Personal Data only on documented instructions in the agreement, configured campaigns or integrations, and Customer's lawful use of the service, including transfers necessary to provide it. If Posto believes an instruction violates law, it will notify Customer unless prohibited and may suspend the affected processing.
4. Customer obligations
Customer will provide lawful instructions, required notices, a valid legal basis, and any consent required for collection and disclosure to Posto. Customer will not submit prohibited or unnecessary sensitive data and will configure retention and audience use lawfully. Customer is responsible for the accuracy and legality of Customer Personal Data.
5. Confidentiality and security
Posto will ensure persons authorized to process Customer Personal Data are bound by confidentiality and will maintain appropriate technical and organizational measures. Measures include encryption in transit, access control, secret isolation, environment separation, signed requests, mobile integrity proof, replay prevention, logging, vulnerability management, backups, recovery tests, data minimization, retention automation, and incident response.
6. Subprocessors
Customer authorizes Posto to use subprocessors to provide cloud hosting, storage, email, integrity verification, payment, support, and model services. Posto will impose data-protection obligations appropriate to each subprocessor and remains responsible for their processing to the extent required by law. Posto maintains the current named list, purposes, data categories, and processing regions at /legal/subprocessors and provides advance notice of a new subprocessor where required. Customer may object on reasonable data-protection grounds before the stated effective date.
7. Data-subject requests
Taking into account the nature of processing, Posto will provide reasonable technical and organizational assistance for Customer to respond to requests for access, correction, deletion, portability, restriction, or objection. If Posto receives a request relating to Customer Personal Data, it will direct the requester to Customer unless law permits Posto to respond.
8. Security incidents
Posto will notify Customer without undue delay after confirming a breach of Customer Personal Data and will provide available information reasonably necessary for Customer's legal obligations. Notice is not an admission of fault. Customer is responsible for notifications concerning its own systems or instructions.
9. Assessments and consultation
Posto will provide information reasonably necessary for Customer's data-protection impact assessment or prior consultation regarding the service, taking into account the nature of processing and information available to Posto.
10. Return and deletion
At termination or Customer's request, Posto will return or delete Customer Personal Data within the product's documented process unless law requires retention. Posto may retain pseudonymized financial, consent, security, fraud, backup, or legal records for the applicable period and will restrict them to those purposes. Backups are deleted on the ordinary rotation schedule.
11. Audits
Posto will make current independent reports or security documentation available under confidentiality when reasonably sufficient. If legally required and those materials are insufficient, Customer may conduct one audit per year on reasonable notice, during business hours, without accessing another customer's data or disrupting the service. Customer bears its audit costs unless material noncompliance is found.
12. International transfers
Posto will use a lawful transfer mechanism where Customer Personal Data is transferred across a restricted border. If the European Commission Standard Contractual Clauses are required, the applicable controller-to-processor or processor-to-processor module is incorporated, with Customer as exporter, Posto as importer, the agreement's governing law where permitted, and the Annex information below. The UK Addendum applies for restricted UK transfers when required.
13. Annex I — processing details
- Subject matter: contextual ad delivery, campaign operation, attribution, measurement, security, fraud prevention, and customer-requested support.
- Duration: the agreement plus documented retention and deletion periods.
- Data subjects: Customer account users and end users of participating apps or advertised services.
- Data: redacted recent interaction messages; optional coarse demographic fields; app, request, integrity, impression, click, conversion, and technical metadata; account and business contact details.
- Sensitive data: not intended or permitted in ad-request context. Customer must obtain written approval before any legally sensitive category is processed.
- Frequency: continuous when Customer uses the service.
- Purpose: provide, secure, measure, and improve the contracted Posto service on Customer's instructions.
14. Annex II — safeguards
- TLS for data in transit and managed encryption for production storage and backups.
- Role-based access, least privilege, secret management, production/simulation separation, and access logging.
- Server HMAC, Apple App Attest, Google Play Integrity, signed event tokens, request hashing, idempotency, and replay controls.
- PII filtering, strict request schemas, bounded context, sensitive-context suppression, and automated retention.
- Monitoring, reconciliation, tested backup restoration, dependency review, incident response, and employee confidentiality.
15. Annex III — subprocessor categories
Posto's current subprocessor categories include cloud infrastructure and managed database/storage providers; transactional-email providers; payment and payout processors; Apple and Google app-integrity verification; and model or embedding providers used for contextual matching and campaign operation. The current named list, locations, and processing purposes are published at /legal/subprocessors.
16. Contact
Privacy and DPA notices: privacy@postoconnect.com. Legal notices: legal@postoconnect.com. Posto address: 131 Continental Drive Suite 305, Newark, DE 19702.