Record of Processing Activities

Last updated: March 28, 2026

This document describes the processing activities carried out by ScoutSocial as both Controller (for our own data) and Processor (on behalf of our customers), in accordance with Article 30 of the GDPR.

Processing Activities

PurposeData CategoriesData SubjectsRecipientsRetentionLegal Basis
Account managementName, email, organization infoRegistered usersClerk (auth)Duration of account + 30 daysContract
Social media publishingSocial account credentials, post content, mediaUsers, social audiencesSocial platforms (LinkedIn, X, etc.)Duration of accountContract
AI content generationUser prompts, content draftsUsersOpenAI, AnthropicNot retained by providers beyond processingContract / Legitimate interest
Analytics and insightsUsage data, engagement metrics, performance dataUsersGoogle Analytics (with consent)24 months (aggregated)Legitimate interest / Consent
Billing and subscriptionsPayment method, billing addressAccount ownersPaddle (merchant of record)Duration of account + tax retention periodContract / Legal obligation
Customer supportSupport tickets, communicationUsersInternal team24 monthsLegitimate interest
Security and fraud preventionIP addresses, access logs, audit trailsUsersInternal, AWS12 monthsLegitimate interest / Legal obligation
Email communicationsEmail address, preferencesUsersInternalUntil unsubscribedConsent (marketing) / Contract (transactional)

Technical and Organizational Measures

  • Encryption at rest and in transit (TLS 1.2+)
  • Role-based access controls
  • Encrypted storage of OAuth tokens and API keys
  • Regular security assessments
  • Employee access controls and training
  • Incident response procedures
  • Data backup and disaster recovery

Data Protection Officer

For inquiries about these processing activities: info@scoutsocial.ai

© 2026 ScoutSocial. All rights reserved.

Home