Last updated: September 15, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between FortyTwo Eleven Consulting AB (Org.nr: 559358-1746), a company registered in Sweden that provides Outstand ("Outstand," "we," "us," or "our"), and the customer that has agreed to the Terms ("Customer," "you," or "your").
This DPA applies whenever Outstand processes personal data on your behalf in providing the Service and that processing is subject to Data Protection Laws. It takes effect automatically when you accept the Terms, and no separate signature is required. If your organization needs a countersigned copy for its records, contact support@outstand.so.
This DPA does not cover personal data for which Outstand is itself the controller, such as your account, billing and website usage data. That processing is described in our Privacy Policy.
Capitalized terms not defined here have the meaning given in the Terms.
For Customer Personal Data, you are the controller (or a processor acting on behalf of your own customers), and Outstand is your processor (or subprocessor). The subject matter, duration, nature and purpose of the processing, and the categories of personal data and data subjects, are set out in Annex 1.
Social media platforms that you connect to the Service, such as X, LinkedIn, Meta, TikTok, YouTube, Pinterest and Bluesky, are not Outstand's subprocessors. When you instruct us to publish content or retrieve data, we exchange that data with the platform on your behalf, and the platform processes it as an independent controller under its own terms.
You are responsible for:
Outstand will:
You give Outstand general authorization to engage subprocessors. Our current subprocessors are listed in Annex 3 and in the Subprocessors section of our Privacy Policy.
Our primary database, task scheduling and product analytics are hosted in the European Economic Area (EEA). Some subprocessors are based in, or may access data from, countries outside the EEA, as shown in Annex 3.
Where Customer Personal Data is transferred to a country that has not received an adequacy decision, the transfer is protected by the SCCs or another valid transfer mechanism under Data Protection Laws, such as the EU-U.S. Data Privacy Framework where the recipient is certified. Where the SCCs apply between you and Outstand, Module Two (controller to processor) or Module Three (processor to processor) is incorporated by reference, with Clause 7 (docking clause) included, Option 2 (general authorization) of Clause 9, the optional wording of Clause 11 omitted, Clauses 17 and 18 governed by the laws and courts of Sweden, and Annexes I to III completed by Annexes 1 to 3 of this DPA. For transfers subject to UK or Swiss law, the SCCs apply as amended by the UK International Data Transfer Addendum or as required by Swiss law.
Outstand will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. Notice will go to the account owner's email address and will describe, as far as the information is available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where information is not yet available, we will provide it in phases as it becomes available. We will take reasonable steps to contain and remediate the breach.
Taking into account the nature of the processing, Outstand will:
On request, Outstand will make available the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including written answers to security questionnaires. If that information is not sufficient, or a supervisory authority requires it, you may audit our compliance, either yourself or through an independent auditor bound by confidentiality, no more than once a year, on at least 30 days' written notice, during normal business hours, and at your own cost. Audits must not unreasonably disrupt our operations or compromise the security or confidentiality of other customers' data.
You can export or delete Customer Personal Data through the API at any time during the term. Within 90 days after your account is closed, Outstand will delete Customer Personal Data from its production systems, unless EU or Member State law requires us to retain it. Residual copies in backups are deleted as those backups expire in the normal course and remain protected by this DPA until then.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent permitted by Data Protection Laws. Nothing in this DPA limits either party's liability to data subjects under the SCCs or Data Protection Laws.
This DPA remains in effect for as long as Outstand processes Customer Personal Data. If there is a conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms. This DPA is governed by the laws of Sweden, and disputes are subject to the jurisdiction set out in the Terms, except where the SCCs or Data Protection Laws require otherwise.
We may update this DPA to reflect changes in Data Protection Laws or the Service. Material changes will be notified in line with the Terms and will not reduce the overall level of protection for Customer Personal Data.
As of September 15, 2026, Outstand uses the following subprocessors:
| Subprocessor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Cloudflare | Application hosting, edge network and security, media storage, queues and operational logs | All Service data in transit, uploaded media files, application logs | Global edge network; company based in the United States |
| PlanetScale | Primary database | Account and organization data, connected social account data including access tokens, posts and schedules, usage records | Frankfurt, Germany (AWS eu-central-1) |
| Google Cloud | Scheduled publishing tasks and webhook delivery (Cloud Tasks) | Post and message payloads queued for publishing, webhook event payloads | St. Ghislain, Belgium (europe-west1) |
| Stripe | Payments, subscriptions and invoicing | Billing contact name and email, payment method details, invoices, usage quantities | United States and European Union |
| Loops | Transactional and account emails | Name, email address, organization name, email content | United States |
| PostHog | Product analytics and feature flags | User and organization identifiers, email address, IP address, device information, product usage events | Frankfurt, Germany (PostHog EU Cloud) |
For questions about this DPA, to object to a subprocessor, or to request a countersigned copy, contact us at:
Company: FortyTwo Eleven Consulting AB (Org.nr: 559358-1746)
Email: support@outstand.so
Website: outstand.so