Data Processing Agreement

Last updated: September 15, 2026

1. Introduction and Acceptance

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between FortyTwo Eleven Consulting AB (Org.nr: 559358-1746), a company registered in Sweden that provides Outstand ("Outstand," "we," "us," or "our"), and the customer that has agreed to the Terms ("Customer," "you," or "your").

This DPA applies whenever Outstand processes personal data on your behalf in providing the Service and that processing is subject to Data Protection Laws. It takes effect automatically when you accept the Terms, and no separate signature is required. If your organization needs a countersigned copy for its records, contact support@outstand.so.

This DPA does not cover personal data for which Outstand is itself the controller, such as your account, billing and website usage data. That processing is described in our Privacy Policy.

2. Definitions

Capitalized terms not defined here have the meaning given in the Terms.

  • Data Protection Laws: the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any national laws implementing or supplementing them, in each case as applicable to the processing
  • Customer Personal Data: personal data that Outstand processes on behalf of Customer in providing the Service, as described in Annex 1
  • Controller, Processor, Data Subject, Personal Data, Processing and Supervisory Authority: have the meanings given in the GDPR
  • Subprocessor: any third party engaged by Outstand to process Customer Personal Data
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data
  • Standard Contractual Clauses (SCCs): the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914

3. Roles and Scope of Processing

For Customer Personal Data, you are the controller (or a processor acting on behalf of your own customers), and Outstand is your processor (or subprocessor). The subject matter, duration, nature and purpose of the processing, and the categories of personal data and data subjects, are set out in Annex 1.

Social media platforms that you connect to the Service, such as X, LinkedIn, Meta, TikTok, YouTube, Pinterest and Bluesky, are not Outstand's subprocessors. When you instruct us to publish content or retrieve data, we exchange that data with the platform on your behalf, and the platform processes it as an independent controller under its own terms.

4. Your Obligations

You are responsible for:

  • Having a lawful basis, and any notices and consents required by Data Protection Laws, for the personal data you submit
  • Ensuring your instructions to Outstand comply with Data Protection Laws
  • Not submitting special categories of personal data unless the processing is lawful and necessary for your use of the Service
  • Complying with the terms and policies of the social media platforms you connect

5. Outstand's Obligations

Outstand will:

  • Process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required otherwise by EU or Member State law, in which case we will inform you before processing unless that law prohibits it. Your instructions are the Terms, this DPA, and your configuration and use of the Service, including requests made through our API, dashboard and MCP server
  • Promptly inform you if, in our opinion, an instruction infringes Data Protection Laws
  • Ensure that everyone authorized to process Customer Personal Data is bound by an appropriate obligation of confidentiality
  • Implement and maintain the technical and organizational measures described in Annex 2
  • Not sell Customer Personal Data or use it for any purpose other than providing the Service

6. Subprocessors

You give Outstand general authorization to engage subprocessors. Our current subprocessors are listed in Annex 3 and in the Subprocessors section of our Privacy Policy.

  • We impose data protection obligations on each subprocessor by written contract that are no less protective than those in this DPA, and we remain responsible to you for their performance
  • We will give at least 30 days' notice before a new subprocessor starts processing Customer Personal Data, by updating the subprocessor list and emailing the account owner
  • You may object to a new subprocessor on reasonable data protection grounds by emailing support@outstand.so within that notice period. We will work with you in good faith to address the objection. If we cannot, you may terminate the affected part of the Service, and we will refund any prepaid fees for the period after termination
  • In an emergency, such as a security incident at an existing provider, we may replace a subprocessor with shorter notice

7. International Data Transfers

Our primary database, task scheduling and product analytics are hosted in the European Economic Area (EEA). Some subprocessors are based in, or may access data from, countries outside the EEA, as shown in Annex 3.

Where Customer Personal Data is transferred to a country that has not received an adequacy decision, the transfer is protected by the SCCs or another valid transfer mechanism under Data Protection Laws, such as the EU-U.S. Data Privacy Framework where the recipient is certified. Where the SCCs apply between you and Outstand, Module Two (controller to processor) or Module Three (processor to processor) is incorporated by reference, with Clause 7 (docking clause) included, Option 2 (general authorization) of Clause 9, the optional wording of Clause 11 omitted, Clauses 17 and 18 governed by the laws and courts of Sweden, and Annexes I to III completed by Annexes 1 to 3 of this DPA. For transfers subject to UK or Swiss law, the SCCs apply as amended by the UK International Data Transfer Addendum or as required by Swiss law.

8. Personal Data Breaches

Outstand will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. Notice will go to the account owner's email address and will describe, as far as the information is available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not yet available, we will provide it in phases as it becomes available. We will take reasonable steps to contain and remediate the breach.

9. Assistance

Taking into account the nature of the processing, Outstand will:

  • Assist you with appropriate technical and organizational measures in responding to requests from data subjects exercising their rights. Most requests can be handled directly through the API, for example by deleting posts, media or connected accounts. If we receive a request directly, we will forward it to you and not respond ourselves unless you authorize us to
  • Provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service
  • Notify you of any legally binding request from a public authority for Customer Personal Data, unless the law prohibits it, and challenge requests we reasonably consider unlawful

10. Audits

On request, Outstand will make available the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including written answers to security questionnaires. If that information is not sufficient, or a supervisory authority requires it, you may audit our compliance, either yourself or through an independent auditor bound by confidentiality, no more than once a year, on at least 30 days' written notice, during normal business hours, and at your own cost. Audits must not unreasonably disrupt our operations or compromise the security or confidentiality of other customers' data.

11. Deletion and Return

You can export or delete Customer Personal Data through the API at any time during the term. Within 90 days after your account is closed, Outstand will delete Customer Personal Data from its production systems, unless EU or Member State law requires us to retain it. Residual copies in backups are deleted as those backups expire in the normal course and remain protected by this DPA until then.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent permitted by Data Protection Laws. Nothing in this DPA limits either party's liability to data subjects under the SCCs or Data Protection Laws.

13. Term, Precedence and Governing Law

This DPA remains in effect for as long as Outstand processes Customer Personal Data. If there is a conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms. This DPA is governed by the laws of Sweden, and disputes are subject to the jurisdiction set out in the Terms, except where the SCCs or Data Protection Laws require otherwise.

We may update this DPA to reflect changes in Data Protection Laws or the Service. Material changes will be notified in line with the Terms and will not reduce the overall level of protection for Customer Personal Data.

Annex 1: Details of Processing

  • Data exporter: the Customer, as identified in its Outstand account
  • Data importer: FortyTwo Eleven Consulting AB (Org.nr: 559358-1746), Sweden, providing Outstand. Contact: support@outstand.so
  • Subject matter: provision of the Outstand unified social media API, dashboard and MCP server
  • Duration: the term of the Terms, plus the deletion period in section 11
  • Frequency: continuous
  • Nature of processing: collection, storage, organization, retrieval, transmission to and from connected social media platforms, scheduling, and deletion
  • Purpose: publishing and scheduling content, managing connected social accounts, retrieving analytics, comments and messages, and delivering webhooks, each as instructed by the Customer
  • Categories of data subjects: the Customer's users and team members; owners and managers of connected social media accounts; the Customer's own end users where the Customer connects their accounts; individuals who appear in content; and individuals who interact with connected accounts, for example by commenting or sending messages
  • Categories of personal data: connected account identifiers (usernames, display names, profile images and platform IDs); OAuth access and refresh tokens; post content, including text, images and video, and its metadata; comments, replies and direct messages retrieved from connected platforms; engagement analytics; and API request metadata, such as IP addresses and timestamps
  • Special categories of data: none intended. Content submitted by the Customer may incidentally contain them, and the Customer is responsible for the lawfulness of that processing

Annex 2: Technical and Organizational Security Measures

  • Encryption in transit: all traffic to the API, dashboard and MCP server is encrypted with TLS
  • Encryption at rest: the database and media storage are encrypted at rest by our infrastructure providers
  • Customer access control: dashboard sign-in supports two-factor authentication and passkeys, and API access uses revocable API keys scoped to an organization
  • Tenant isolation: Customer Personal Data is scoped to the owning organization, and requests are authorized against that organization
  • Credential protection: access tokens for connected social accounts are stored securely and excluded from API responses unless the account owner explicitly requests them
  • Internal access control: access to production systems is limited to authorized personnel who need it, on a least-privilege basis
  • Availability: the Service runs on managed infrastructure with automated database backups
  • Monitoring and incident response: operational logging and monitoring, and a documented process for handling and notifying Personal Data Breaches
  • Vendor management: subprocessors are selected for their security practices and bound by written data protection terms

Annex 3: Subprocessors

As of September 15, 2026, Outstand uses the following subprocessors:

SubprocessorPurposePersonal data processedLocation
CloudflareApplication hosting, edge network and security, media storage, queues and operational logsAll Service data in transit, uploaded media files, application logsGlobal edge network; company based in the United States
PlanetScalePrimary databaseAccount and organization data, connected social account data including access tokens, posts and schedules, usage recordsFrankfurt, Germany (AWS eu-central-1)
Google CloudScheduled publishing tasks and webhook delivery (Cloud Tasks)Post and message payloads queued for publishing, webhook event payloadsSt. Ghislain, Belgium (europe-west1)
StripePayments, subscriptions and invoicingBilling contact name and email, payment method details, invoices, usage quantitiesUnited States and European Union
LoopsTransactional and account emailsName, email address, organization name, email contentUnited States
PostHogProduct analytics and feature flagsUser and organization identifiers, email address, IP address, device information, product usage eventsFrankfurt, Germany (PostHog EU Cloud)

Contact

For questions about this DPA, to object to a subprocessor, or to request a countersigned copy, contact us at:

Company: FortyTwo Eleven Consulting AB (Org.nr: 559358-1746)

Email: support@outstand.so

Website: outstand.so