apublished

Data Processing Agreement

apublished

Version 1.0 Last updated: 8 August 2026 Effective: 8 August 2026


How this document works

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and Hippolyte Surer, sole proprietor, Avenue du Delay 11, 1110 Morges, Switzerland ("apublished", "we", "us").

It applies automatically, without signature, whenever we process personal data on the Customer's behalf and the Customer is subject to the EU General Data Protection Regulation, the UK GDPR or the Swiss Federal Act on Data Protection. Accepting the Terms of Service accepts this DPA.

If your procurement process requires a signed copy, or your own DPA template, write to legal@apublished.com. We will sign this document as it stands, and we will look at a reasonable alternative, but we cannot accept terms that conflict with what the social platforms require of us.

Order of precedence. On the subject of personal data processed on the Customer's behalf, this DPA prevails over the Terms of Service and the Privacy Policy. The Standard Contractual Clauses incorporated by Section 11 prevail over this DPA where they conflict.


1. Definitions

"Data Protection Law" means, as applicable: Regulation (EU) 2016/679 (the "GDPR"); the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 together with the UK Data Protection Act 2018 (the "UK GDPR"); and the Swiss Federal Act on Data Protection of 25 September 2020 with its Ordinance (the "FADP").

"Customer Personal Data" means personal data contained in Customer Content or otherwise processed by us on the Customer's behalf through the Service.

"Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in the GDPR. Under the FADP, "Controller" corresponds to the responsible party and "Processor" to the order processor.

"SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

"UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

"Subprocessor" means a processor engaged by us to process Customer Personal Data.

Other capitalised terms have the meaning given in the Terms of Service.


2. Roles of the parties

The Customer is the Controller of Customer Personal Data. apublished is the Processor.

Where the Customer is itself a processor acting for another controller, apublished is a subprocessor, and references to the Customer's instructions include instructions passed down from that controller. The Customer confirms that it has the authority to appoint us on those terms.

apublished is an independent Controller for the account, billing, support, security and website data described in Section 3 of the Privacy Policy. This DPA does not apply to that data.


3. Subject matter and details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

The processing lasts for the term of the Terms of Service, plus the retention periods described in Section 10.


4. Instructions

We process Customer Personal Data only on the Customer's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union, Member State or Swiss law to which we are subject. In that case, we inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

The Customer's documented instructions are:

(a) the Terms of Service and this DPA; (b) the Customer's use of the Service through its interfaces, including every API call, MCP call and scheduled target, which constitutes an instruction to process the data it contains for the purpose that call describes; (c) any further written instruction the parties agree.

We will tell the Customer if, in our opinion, an instruction infringes Data Protection Law. We may suspend performance of an instruction that we reasonably believe is unlawful, or that would put our access to a platform at risk, until it is resolved.

We do not use Customer Personal Data for our own purposes. We do not use it to train machine learning models, to build profiles, for advertising, or to create any product other than the Service provided to the Customer.


5. Customer obligations and warranties

The Customer warrants that:

The Customer is responsible for the accuracy, quality and legality of Customer Personal Data and of the means by which it acquired it.


6. Confidentiality

We ensure that every person authorised to process Customer Personal Data, whether employee or contractor, is bound by an appropriate obligation of confidentiality that survives the end of their engagement, and is trained in their obligations. Access is limited to those who need it to perform the Service.


7. Security

We implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects.

We may update those measures, provided that the level of protection is not reduced. The current version of Annex II is always the one published at apublished.com/dpa.


8. Subprocessors

General authorisation. The Customer gives a general authorisation for us to engage Subprocessors, subject to this Section.

Current list. The Subprocessors engaged as at the date of this DPA are listed at apublished.com/subprocessors, with their role, the processing they perform and their location. That page is incorporated into this DPA.

Changes. We will give the Customer at least 30 days' notice before adding or replacing a Subprocessor. Notice is given by email to the account address and by updating the subprocessor page. The Customer may subscribe to change notifications from that page.

Objection. The Customer may object to a new Subprocessor on reasonable data protection grounds by writing to legal@apublished.com within the notice period, stating the grounds. We will work in good faith to address the objection, which may include offering a reasonable alternative or a configuration that avoids the Subprocessor. If we cannot, the Customer may terminate the affected part of the Service by written notice, and we will refund any prepaid fees for the period after termination. Termination on this ground is the Customer's exclusive remedy.

Flow-down and responsibility. Each Subprocessor is engaged under a written contract imposing data protection obligations that are no less protective than those in this DPA, appropriate to the processing it performs. We remain fully liable to the Customer for the performance of each Subprocessor's obligations.

Emergency changes. Where a Subprocessor must be replaced urgently for security, availability or legal reasons, we may do so immediately and will notify the Customer as soon as possible with an explanation.


9. Data subject rights, assistance and breach notification

Requests received by us. If a data subject contacts us directly with a request concerning Customer Personal Data, we will not respond to the substance ourselves. We will tell them to contact the Customer, and forward the request to the Customer without undue delay, unless the Customer has instructed otherwise or the law requires otherwise.

Assistance. Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR and the equivalent provisions of the UK GDPR and the FADP. The Service's own API allows the Customer to retrieve, correct and delete Customer Personal Data directly, and that is the primary means of assistance.

Further assistance. We will assist the Customer, taking into account the nature of processing and the information available to us, in complying with its obligations under Articles 32 to 36 GDPR: security of processing, breach notification to the authority and to data subjects, data protection impact assessments, and prior consultation.

Personal Data Breach. We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known at the time and supplemented as more becomes known:

We will not notify a supervisory authority or a data subject about a breach affecting Customer Personal Data on the Customer's behalf unless the Customer asks us to in writing or the law requires us to.

Cost. Assistance is provided at no charge where it is proportionate to the Service. Where a request requires significant engineering effort beyond the Service's own capabilities, we may charge our reasonable costs, agreed with the Customer in advance.


10. Deletion and return

On termination of the Terms of Service, and at the Customer's choice, we will delete or return Customer Personal Data.

In practice:

We will certify deletion in writing on request.


11. International transfers

The Customer authorises us to transfer Customer Personal Data outside Switzerland, the EEA and the United Kingdom as necessary to provide the Service, including to the Subprocessors listed at apublished.com/subprocessors and to the social platforms the Customer instructs us to publish to.

Where a transfer requires a safeguard under Chapter V GDPR, the equivalent UK provisions or Article 16 FADP, the following apply, in this order:

(a) Adequacy. Where the European Commission, the UK Secretary of State or the Swiss Federal Council has recognised the destination as providing adequate protection, we rely on that recognition. This covers transfers between Switzerland and the EEA, and transfers to a recipient certified under the EU-US and Swiss-US Data Privacy Framework for the data covered by that certification.

(b) EU Standard Contractual Clauses. Otherwise, the SCCs are incorporated into this DPA by reference and are deemed executed by the parties, as follows:

(c) Swiss amendments. Where the FADP governs the transfer, the SCCs apply with the amendments recognised by the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP; the competent supervisory authority is the FDPIC; "Member State" is read so as not to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence; and the clauses protect the data of legal entities until the FADP no longer does.

(d) UK. Where the UK GDPR governs the transfer, the UK Addendum is incorporated and completed as follows: Table 1 is populated with the parties' details in Annex I; Table 2 selects the Module and options above; Table 3 refers to Annexes I and II of this DPA; in Table 4, neither party may end the Addendum when the Approved Addendum changes.

(e) Transfer assessment. We have assessed the laws of the destinations to which we transfer, and we apply supplementary measures where our assessment indicates they are needed, including encryption in transit and at rest with keys we control. We will provide our assessment to the Customer on reasonable request, subject to confidentiality.

Government access requests. If we receive a legally binding request from a public authority for Customer Personal Data, we will notify the Customer, unless prohibited by law, in which case we will use reasonable efforts to obtain a waiver of the prohibition and will document our efforts. We will challenge requests that we consider unlawful, and we will disclose only the minimum the request compels.


12. Audit

We will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and the equivalent provisions of the UK GDPR and the FADP, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

To keep this workable for a small provider:


13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except that nothing in this DPA or the Terms limits either party's liability to a data subject under Data Protection Law, or under Clause 12 of the SCCs, or any liability that cannot be limited under Swiss law, including liability for unlawful intent or gross negligence under Article 100 of the Swiss Code of Obligations.


14. General

This DPA takes effect on the effective date of the Terms of Service and ends when all Customer Personal Data has been deleted or returned under Section 10.

We may update this DPA where necessary to reflect a change in Data Protection Law, a decision of a competent authority, a change in the SCCs, or a change to our Subprocessors or measures that does not reduce protection. Material changes are notified as described in Section 22 of the Terms of Service.

Except as stated in Section 11, this DPA is governed by Swiss law, and the courts of Morges, Canton of Vaud, Switzerland have exclusive jurisdiction.

If any provision is held invalid, the rest remains in force.



Annex I

A. List of parties

Data exporter (Controller)

NameThe Customer, as identified in its apublished account
AddressAs given in the Customer's account billing details
ContactThe account owner's email address, and any privacy contact the Customer has configured
Activities relevant to the transferUse of the apublished Service to schedule and publish content to social media platforms
RoleController (or processor, where the Customer acts for another controller)
Signature and dateDeemed executed on acceptance of the Terms of Service

Data importer (Processor)

NameHippolyte Surer, sole proprietor, trading as apublished
AddressAvenue du Delay 11, 1110 Morges, Switzerland
Contactprivacy@apublished.com
Activities relevant to the transferProvision of the apublished publishing, scheduling and delivery Service
RoleProcessor
Signature and dateDeemed executed on acceptance of the Terms of Service

B. Description of transfer

Categories of data subjects

Categories of personal data

Sensitive data

None is intended, requested or expected. The Service is not designed to process special categories of personal data under Article 9 GDPR, data on criminal convictions under Article 10 GDPR, or sensitive personal data under the FADP. The Customer must not submit such data without a prior written agreement on additional safeguards.

If such data is nonetheless present in Customer Content, the restrictions applied are those in Annex II, in particular encryption at rest, tenant isolation enforced at the database level, strict access limitation and audit logging.

Frequency of transfer

Continuous, for the duration of the Terms of Service.

Nature of the processing

Collection, recording, organisation, structuring, storage, adaptation and alteration for platform-specific formatting, retrieval, consultation, use, transmission to the platforms the Customer selects, restriction, erasure and destruction.

Purpose of the processing

To provide the Service: to accept content, validate it against platform constraints, hold it until a scheduled time, publish it to the channels the Customer has connected, record the outcome, deliver webhooks, and support the Customer.

Retention period

As set out in Section 10 of this DPA and Section 9 of the Privacy Policy.

Transfers to subprocessors

Subject matter, nature, and duration as stated for each Subprocessor at apublished.com/subprocessors.

C. Competent supervisory authority

Where the SCCs apply under the GDPR, the competent supervisory authority is the authority of the EU Member State in which the Customer's Article 27 representative is established, or, where the Customer is established in the EEA, the authority of that Member State.

Where the FADP applies, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.

Where the UK GDPR applies, the competent authority is the Information Commissioner's Office, United Kingdom.


Annex II

Technical and organisational measures

The measures below are those in place as at the date of this DPA. They may be improved but not reduced.

1. Pseudonymisation and encryption

2. Confidentiality

3. Integrity

4. Availability and resilience

5. Testing and evaluation

6. Subprocessor governance

7. Incident response

8. Data minimisation and deletion


Annex III

Subprocessors

The current list, with the role, processing activity and location of each Subprocessor, is maintained at apublished.com/subprocessors and forms part of this DPA. A snapshot as at the date of this document is reproduced in that page's own version history.