Data Processing Agreement

Last updated: October 1, 2026

1. Introduction

This Data Processing Agreement (DPA) forms part of, and is incorporated by reference into, the Terms of Service between Aigentifyable LLC (“ScoutSocial”, Processor) and the Customer (as defined in § 1.1 of the ToS, Controller). It applies whenever, in the course of providing the ScoutSocial platform, ScoutSocial processes Personal Data on the Customer's behalf. Where the Customer is itself a natural person using ScoutSocial for personal purposes (not on behalf of an organisation), this DPA applies only to the extent the Customer is acting as controller of third-party Personal Data (e.g. data of Connected Platform Members it is processing through ScoutSocial).

2. Definitions

  • “Personal Data” means any data relating to an identified or identifiable natural person
  • “Processing” means any operation performed on personal data
  • “Controller” means the entity that determines the purposes and means of processing
  • “Processor” means the entity that processes personal data on behalf of the Controller
  • “Sub-processor” means any third party engaged by the Processor to process personal data

“Connected Platform” means a third-party social-media service whose account the Customer has connected to ScoutSocial via OAuth (currently Facebook, Instagram, LinkedIn, X, TikTok and YouTube). “Platform Data” means any data ScoutSocial accesses, stores or processes through a Connected Platform's API — including raw API responses, derived analytics, and aggregated outputs. “Authorised Client” has the meaning given in the LinkedIn Marketing API Terms. “Tech Provider” means a third-party developer providing services on behalf of an end-user under Meta's, LinkedIn's or Google's developer programs, in which capacity ScoutSocial acts when it manages a Page, organisation or channel on the Customer's behalf.

3. Scope and Roles

3.1 Customer as Controller. With respect to (a) account data of the Customer and its workspace users, (b) content the Customer or its users create or upload in ScoutSocial, and (c) Platform Data the Customer instructs ScoutSocial to process on its behalf, the Customer is the data Controller and ScoutSocial is the data Processor, and the processing is limited to providing the service as described in the Terms of Service.

3.2 Independent controller for certain Platform Data. For Platform Data ScoutSocial receives from X under the X Controller-to-Controller Data Protection Addendum (automatically incorporated into the X Developer Agreement), ScoutSocial receives that data as an independent Controller alongside X. The Customer acknowledges this dual relationship; ScoutSocial's obligations under this DPA continue to apply to such data in addition to its obligations as independent controller.

3.3 Sub-Processor relationships. ScoutSocial's Sub-processors (§ 5) act as processors of ScoutSocial under written terms. ScoutSocial remains fully liable to the Customer for the acts and omissions of its Sub-processors as if they were its own.

4. Processing Purposes

ScoutSocial processes Personal Data for the following purposes:

  • Providing and maintaining the platform
  • Social media content management and publishing
  • AI-powered content generation and analysis
  • Analytics and performance reporting (where consented)
  • Account and subscription management
  • Security, fraud prevention and service reliability
  • Legal and regulatory compliance

4.1 EU/UK Lawful-Basis Mapping

For customers and data subjects in the EU/EEA/UK, ScoutSocial's processing activities map to the following GDPR/UK GDPR lawful bases:

  • Performance of contract (Art. 6(1)(b)): delivering the contracted ScoutSocial service.
  • Legitimate interests (Art. 6(1)(f)): platform security, abuse prevention, service reliability, and observability. ScoutSocial maintains documented legitimate-interest balancing assessments for these activities.
  • Legal obligation (Art. 6(1)(c)): mandatory compliance logging, tax records, and responses to lawful regulatory requests.
  • Consent (Art. 6(1)(a)): optional analytics cookies and optional marketing communications.

A per-activity lawful-basis mapping is set out in our Privacy Policy § 4 and the two must be read consistently. Public-interest and vital-interest lawful bases are not used for ordinary ScoutSocial service processing. Where any feature would involve processing of GDPR Article 9 special-category data, ScoutSocial will obtain explicit consent under Art. 9(2)(a) or rely on another Art. 9 condition explicitly identified before processing; ScoutSocial does not currently process Article 9 data in its standard service. Any change to this position will require an update to this DPA and prior notice to the Customer.

5. Sub-Processors

ScoutSocial engages the sub-processors listed at scoutsocial.ai/legal/sub-processors, which is the authoritative current list and is updated whenever sub-processors are added, replaced or removed. Each sub-processor is engaged under a written processor agreement that imposes data-protection obligations no less protective than those in this DPA. For sub-processors processing Personal Data outside the EEA, the relevant SCCs (Module Two, controller-to-processor) and the UK IDTA are incorporated by reference into this DPA. ScoutSocial's contracts with OpenAI and Anthropic prohibit those providers from training their models on Customer Personal Data, content, prompts or outputs. ScoutSocial will give the Customer at least 14 days' prior written notice of any sub-processor addition, replacement or change. The Customer may object to the change on reasonable data-protection grounds; if the objection cannot be resolved, the Customer may terminate the affected service for convenience.

6. Data Security

ScoutSocial implements appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include encryption of data in transit (TLS 1.2+) and at rest, role-based access controls, encrypted storage of OAuth access and refresh tokens, regular security assessments, vulnerability management, and documented incident-response procedures. ScoutSocial does not collect or store Connected Platform login credentials directly — only OAuth tokens granted through the platform's authorisation flow. The full description of measures is published at scoutsocial.ai/legal/security and aligns with widely recognised frameworks (ISO/IEC 27001, NIST CSF, SOC 2 principles); to the extent required by a specific Connected Platform's developer terms, ScoutSocial implements that platform's prescribed Technical and Organisational Measures (TOMs) for incoming Platform Data.

Tenant isolation. All Customer Personal Data and Platform Data is logically isolated by organisation; ScoutSocial does not permit access to one organisation's data by another, and every data-access path is scoped to the organisation that owns the data.

Emergency platform kill switch. ScoutSocial maintains a per-platform kill switch that allows it to immediately halt all outbound API calls to a Connected Platform in response to a compliance or security event; when a platform is disabled, requests are blocked before any data is transmitted.

7. Data Subject Rights

ScoutSocial will assist the Customer (taking into account the nature of the processing and the information available to ScoutSocial) in responding to data-subject requests for access, rectification, erasure, portability, restriction and objection, including by providing a self-service data export in Settings → Workspace & Preferences → Privacy & Cookies. Where a Connected Platform forwards a data-subject request relating to a Customer account to ScoutSocial (notably Meta and LinkedIn — see § 7.1 below), ScoutSocial will notify the Customer within 24 hours. For platform-side data, ScoutSocial routes data subjects to the platform's own rights channel (TikTok webform, Google account permissions, LinkedIn Help, Meta Help, X privacy form) — see Privacy Policy § 9. Standard response SLA: ScoutSocial will fulfil verified data-subject requests within one calendar month (extendable to three months for complex requests, with notification).

DPIAs and prior consultations (Art. 28(3)(f)). Taking into account the nature of the processing and the information available to it, ScoutSocial will provide reasonable assistance to the Customer with data-protection impact assessments and with prior consultations of supervisory authorities under GDPR Articles 35–36.

7.1 Tech Provider obligations

Where ScoutSocial acts as a Tech Provider for the Customer under Meta's Platform Terms or LinkedIn's API Terms, ScoutSocial undertakes to:

  • (a) process Platform Data only at the direction of the specific Customer;
  • (b) maintain strict per-Customer data segregation, with no cross-tenant access;
  • (c) for LinkedIn, maintain a list of all Customer organisations producible to LinkedIn on its request;
  • (d) promptly terminate the Customer's access to the affected platform's data on the platform's request, in the platform's stated timeframe;
  • (e) notify the affected Customer within 24 hours of any data-subject request the platform forwards to ScoutSocial concerning the Customer's accounts.

YouTube Authorised Data is confined within each Customer's workspace and is exposed only to users the authorising individual has approved.

8. Data Breach Notification

ScoutSocial will notify the Controller of any Personal Data breach without undue delay and no later than 72 hours after becoming aware. Notification will include:

  • Nature of the breach
  • Categories and number of data subjects affected
  • Likely consequences
  • Measures taken to address the breach

Where the breach involves Platform Data from a Connected Platform, ScoutSocial will additionally notify the Connected Platform within its required timeframe and through its required channel — including, for LinkedIn, written notification to security@linkedin.com within 24 hours of discovery, and for Meta, submission via the Meta incident form. ScoutSocial will coordinate with the Customer before any public statement to honour platform-specific public-statement embargoes (e.g. LinkedIn requires prior written permission).

9. International Transfers

Where Personal Data is transferred outside the European Economic Area or the United Kingdom to a country not subject to an adequacy decision, ScoutSocial relies on:

  • (a) the European Commission's Standard Contractual Clauses (Module One controller-to-controller, or Module Two controller-to-processor, as applicable), incorporated by reference into this DPA and into ScoutSocial's contracts with each non-adequate sub-processor;
  • (b) for UK Personal Data, the UK International Data Transfer Addendum (IDTA);
  • (c) supplementary technical measures, including encryption in transit and at rest, key management, and identifier redaction before transmission to AI Sub-processors.

As an additional safeguard for X-sourced Personal Data transferred to X Corp. (USA), ScoutSocial relies on X's certification under the EU-US Data Privacy Framework, the Swiss-US DPF and the UK Extension. Transfer documentation is available to the Customer on request.

9.1 Transfer from Customer to ScoutSocial (Customer→Armenia leg)

Aigentifyable LLC is established in the Republic of Armenia, which is not subject to an EU adequacy decision. Where the Customer transfers Personal Data from the EEA to ScoutSocial, that transfer is governed as follows.

EU Personal Data — EU SCCs (Module Two). The European Commission Standard Contractual Clauses, Module Two (controller-to-processor), issued under Decision 2021/914 of 4 June 2021 (EU SCCs), are incorporated into this DPA by reference and completed in Annex C. The EU SCCs constitute the Art. 46(2)(c) GDPR transfer safeguard for this leg. In the event of any conflict between this DPA and the EU SCCs, the EU SCCs prevail for the purposes of the transfer.

UK Personal Data — UK IDTA. Where the Customer transfers UK Personal Data to ScoutSocial, that transfer is governed by the UK International Data Transfer Agreement (IDTA) issued by the ICO on 21 March 2022 (as amended from time to time), incorporated into this DPA by reference and completed by the information in Annex C. The EU SCCs serve as the Approved EU SCCs for the purposes of the UK IDTA Table 4. In the event of any conflict between this DPA and the UK IDTA, the UK IDTA prevails for UK Personal Data.

Swiss Personal Data — EU SCCs with Swiss adaptations. Where the Customer transfers Personal Data of Swiss data subjects to ScoutSocial, that transfer is made pursuant to the EU SCCs (Module Two) as recognised by the FDPIC as an appropriate safeguard under nDSG Art. 16(2)(d), subject to the Swiss adaptations set out in Annex C § C.4. In the event of any conflict between this DPA and the Swiss-adapted SCCs, the adapted SCCs prevail for Swiss Personal Data.

9.2 Government Requests

ScoutSocial will not disclose Customer Personal Data to a government authority unless required by law. Where legally permitted, we will notify the Customer, attempt to redirect the requesting authority to the Customer, and disclose only the minimum information legally required.

10. Audit Rights

10.1 Customer audits. The Customer may, on reasonable prior written notice and no more than once per year (unless required by a supervisory authority or following a confirmed material breach), audit ScoutSocial's compliance with this DPA. ScoutSocial may discharge audit obligations primarily through any third-party certifications or reports it holds (such as SOC 2 or ISO/IEC 27001, if and when obtained); on-site audits are reserved for situations where third-party reports are insufficient to address a documented concern.

10.2 Platform audits. The Customer acknowledges that several Connected Platforms (notably Meta, with at least 10 business days' notice; YouTube via API Compliance Audits) may audit ScoutSocial's processing of Platform Data. ScoutSocial will cooperate with such audits, including by providing test accounts and documentation, and will inform the Customer of the outcome to the extent permitted.

11. Data Deletion

11.1 Standard deletion. On termination of the service, ScoutSocial will, at the Customer's choice, return or securely delete Customer Personal Data within 30 days of receiving the Customer's written request (which must be submitted within 30 days of the termination date), except where ScoutSocial is required by law to retain a copy. The Customer may also trigger deletion at any time via Settings → Workspace & Preferences → Privacy & Cookies → Request Data Deletion; deletion is completed within 30 days of the request unless platform-specific overrides apply. In both cases, the 30-day completion window operates as a grace period during which a pending deletion may be cancelled; once it elapses, ScoutSocial performs a permanent hard deletion (including media stored in object storage) that is irreversible.

11.2 Platform-specific deletion overrides. Where a Connected Platform requires earlier or differently scoped deletion, that requirement prevails over § 11.1:

  • LinkedIn Member Data and OAuth tokens — immediate on Member request;
  • LinkedIn Stored Marketing Data — within 10 days of Customer cessation;
  • YouTube API Data on user revocation via Google permissions — within 7 days;
  • YouTube and TikTok on API-termination — full deletion in all forms across all storage systems, with signed deletion certification provided to Google where YouTube so requires;
  • Meta API-fetched content propagating source deletion — within 90 days.

Until deletion is complete, the data remains protected under this DPA. To cancel a pending deletion request, contact legal@scoutsocial.ai before the deletion deadline.

11.3 Agency / multi-client offboarding

Where the Customer is an agency operating multiple end-clients inside a single ScoutSocial workspace, the Customer warrants that:

  • (a) it has the authority to act as data controller (or to bind the end-client as controller) for each end-client's data;
  • (b) within its workspace, ScoutSocial-side per-client segregation is enforced through workspace, project and access-control settings the Customer configures;
  • (c) on offboarding of an individual end-client, the Customer is responsible for triggering deletion of that client's data via the in-product tools, which ScoutSocial will execute within 30 days subject to platform-specific overrides under § 11.2.

12. Term

This DPA is effective for the duration of the service agreement. Obligations regarding data protection survive termination.

13. Language

This DPA is drafted in English. Any translation is provided for convenience only; in the event of a discrepancy, the English version governs. Where applicable data-protection law requires information to be given to data subjects in a particular language, that requirement prevails over this section.

14. Contact

For DPA inquiries:

Email: legal@scoutsocial.ai

Annex A — Subject Matter and Details of Processing

A.1 Subject matterScoutSocial's provision of the social media management platform to the Customer.
A.2 DurationFor the term of the Terms of Service.
A.3 Categories of data subjectsCustomer personnel (workspace users); Customer end-clients where the Customer is an agency; end-users of Connected Platforms (followers, commenters, etc.) whose data is exposed through the platform APIs.
A.4 Categories of Personal DataIdentifiers (name, email, organisation, platform user IDs/handles); authentication credentials (OAuth access and refresh tokens); content (drafts, posts, AI prompts and outputs, media files); analytics and metrics; usage and device data; billing identifiers (full card data handled by Paddle).
A.5 Special-category dataNot processed in the standard service; AUP §3(m) restricts Customer input of Art. 9 data to cases where the Customer holds a documented lawful condition under Art. 9(2) GDPR. Where such data is processed, it falls within the categories in §A.4 above.
A.6 Processing purposesAs set out in § 4 of this DPA.
A.7 RetentionAs set out in § 11 of this DPA and the Privacy Policy retention table.

Annex B — Technical and Organisational Measures

A summary of the TOMs implemented by ScoutSocial is published at scoutsocial.ai/legal/security and is incorporated by reference into this DPA. Customers requiring an executed copy of the SCCs or a copy of TOMs in a signed appendix format may request one at legal@scoutsocial.ai.

Annex C — Standard Contractual Clauses: Completion Details

This Annex completes the EU Standard Contractual Clauses (Module Two: controller-to-processor), Decision 2021/914 of 4 June 2021, incorporated by reference in § 9.1, and the UK International Data Transfer Agreement (IDTA), incorporated by reference in § 9.1. It also records the Swiss adaptations required under nDSG Art. 16(2)(d). References to “the Clauses” in this Annex mean the EU SCCs unless the context specifies the UK IDTA.

Execution. By accepting the Terms of Service (which incorporate this DPA by reference), the Customer and Aigentifyable LLC each agree to the EU SCCs (Module Two, Decision 2021/914) and the UK IDTA as completed in this Annex C. This acceptance constitutes the signature of both parties for the purposes of Article 7 of Decision 2021/914 and Section 2 of the UK IDTA. The date of signature for both instruments is the date the Customer first accepts the Terms of Service. Customers who require a separately executed copy of the SCCs or IDTA may request one at legal@scoutsocial.ai.

C.1 — Annex I.A: List of Parties

Data exporter (the Controller):

NameThe Customer, as identified in the Order Form / ScoutSocial account registration
AddressAs set out in the Customer’s account registration or Order Form
Contact personThe Customer’s designated privacy or legal contact (or, where none is designated, the account owner)
Activities relevant to the data transferredUse of the ScoutSocial platform, including management and publishing of social media content, AI content generation, brand tracking, and analytics
Signature and dateDeemed executed on the Customer’s acceptance of the Terms of Service
RoleController

Data importer (the Processor):

NameAigentifyable LLC
AddressYerkatughayinner str. 4, House 12, 0041, Yerevan, Republic of Armenia
Contact personLegal contact: legal@scoutsocial.ai
Activities relevant to the data transferredProvision of the ScoutSocial social media management platform and related services
Signature and dateDeemed executed on ScoutSocial’s publication of this DPA
RoleProcessor

C.2 — Annex I.B: Description of Transfer

The description of the transfer — including the subject matter, duration, nature and purpose of processing, categories of data subjects, and categories of personal data — is set out in Annex A of this DPA (§§ A.1–A.7), which is incorporated by reference into this Annex I.B. Frequency of transfer: continuous (data is transferred on an ongoing basis for the duration of the Customer’s use of the ScoutSocial service).

C.3 — Annex I.C: Competent Supervisory Authority

EU/EEA Customers: The competent supervisory authority is the data protection authority of the EU Member State in which the Customer (data exporter) is established. Where the Customer is not established in an EU Member State but processes Personal Data of EU/EEA data subjects in circumstances falling within GDPR Art. 3, the competent supervisory authority is determined by the GDPR’s competence rules (Art. 77 GDPR) applicable to the Customer.

UK Customers: The competent supervisory authority is the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.

Note: Where a Customer operates in multiple EU Member States and has a main establishment in one of them, the supervisory authority of that main establishment is the lead supervisory authority for this transfer.

C.4 — Swiss Adaptations (nDSG Art. 16(2)(d))

Where the Customer transfers Personal Data of Swiss data subjects to ScoutSocial, the EU SCCs (Module Two) apply with the following adaptations, as recognised by the FDPIC:

  • (a) References to “Regulation (EU) 2016/679” or “GDPR” are to be understood as references to the Swiss Federal Act on Data Protection (nDSG) for the purposes of Swiss data subject transfers.
  • (b) References to “EU Member State” are to be understood as including the Swiss Confederation where relevant to the data subjects or data exporter concerned.
  • (c) The competent supervisory authority for Swiss data subjects is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern.
  • (d) References to “data subjects” include Swiss residents in respect of whom the nDSG applies.
  • (e) These adaptations apply only to the extent necessary to render the EU SCCs applicable under nDSG Art. 16(2)(d); in all other respects the EU SCCs apply in their original form.

C.5 — Annex II: Technical and Organisational Measures

The technical and organisational measures applicable to this transfer are those set out in Annex B of this DPA and at scoutsocial.ai/legal/security, incorporated by reference into this Annex II. Key measures relevant to the transfer include: TLS 1.2+ encryption in transit; AES-256 encryption at rest (AWS-managed keys); role-based access controls; server-side PII redaction before AI sub-processor transmission; OAuth token encryption; tenant isolation; and documented incident-response procedures.

C.6 — Annex III: List of Sub-Processors

The authoritative list of sub-processors authorised by the data exporter to process Personal Data under the EU SCCs is published at scoutsocial.ai/legal/sub-processors and is updated in accordance with § 5 of this DPA (14-day prior notice of changes). The list at that URL forms Annex III to the EU SCCs and is incorporated by reference.

C.7 — Clause 17: Governing Law (EU SCCs)

The Parties agree that the EU SCCs are governed by the law of the Republic of Ireland. This choice applies to the EU SCCs only and does not affect the governing law of this DPA or the Terms of Service as a whole.

Basis: Ireland is a Member State whose law allows for third-party beneficiary rights (as required by Clause 17 of the EU SCCs), provides English-language proceedings, and is subject to the jurisdiction of the CJEU.

C.8 — Clause 18: Choice of Courts (EU SCCs)

Any dispute arising from the EU SCCs shall be resolved by the courts of the Republic of Ireland, without prejudice to the rights of data subjects to bring claims before the supervisory authority or courts of their Member State of habitual residence under Clause 18(c) of the EU SCCs.

C.9 — UK IDTA: Completion Details

For the purposes of the UK International Data Transfer Agreement (IDTA):

Table 1 — PartiesAs set out in § C.1 above
Table 2 — Selected SCCs, modules and selected clausesEU SCCs Module Two (controller-to-processor), Decision 2021/914, as completed in this Annex C
Table 3 — Appendix InformationAnnex I.A: § C.1; Annex I.B / I.C: §§ C.2–C.3; Annex II TOMs: § C.5; Annex III sub-processors: § C.6
Table 4 — Ending the IDTAEither Party may end the IDTA in the event it cannot continue to comply with it (standard IDTA Table 4 election)

Governing law of the UK IDTA: English law. Jurisdiction: courts of England and Wales.

© 2026 ScoutSocial. All rights reserved.

Home