castiva
← Back to home

Data Processing Addendum

Last updated: August 28, 2026

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Servicebetween Goptimise ("Castiva", "we") and the agency or business using the Service ("Customer"). It applies where the Customer, in using the Service, has us process personal data on its behalf — for example the social account data, audience statistics, media and content of the Customer's own clients.

For that data, the Customer is the controller (or a processor acting for its own clients) and Castiva is the processorunder Art. 28 GDPR. For the account data of the Customer's users (login, profile, billing), Castiva is an independent controller as described in the Privacy Policy.

2. Subject matter and instructions

We process Customer data only to provide, secure and improve the Service as described in the Terms, and only on the Customer's documented instructions — given through the Service itself (connecting channels, composing and publishing posts, requesting AI generations, inviting team members) or in writing. We will inform the Customer if, in our view, an instruction infringes data-protection law.

Categories of data typically processed: social account identifiers and statistics, published content and media, boost/advertising spend figures, team member names and email addresses. Duration: for the term of the subscription, plus the deletion window below.

3. Confidentiality and security

Persons authorised to process the data are bound by confidentiality. We implement appropriate technical and organisational measures, including: encryption of OAuth tokens and provider keys at rest (AES-256-GCM), TLS in transit, salted password hashing, role-based access with per-client scoping, tenant isolation on every query, audit logging of administrative actions, rate limiting, and defined retention periods with automated deletion sweeps.

4. Sub-processors

The Customer authorises the sub-processors we use to run the Service:

  • Hetzner Online GmbH (Germany) — hosting and databases;
  • Stripe — payments and metered billing;
  • Resend — transactional email;
  • Anthropic, Google, OpenAI, fal.ai, WaveSpeed, ElevenLabs — AI generations, only when and to the extent the Customer requests them;
  • Meta, TikTok, Google (YouTube) — the social platforms the Customer connects, which act on their own terms.

We will notify the Customer of intended sub-processor changes (for example by updating this page and announcing material changes in the Service), giving the Customer the opportunity to object on reasonable data-protection grounds. Each sub-processor is bound by data-protection obligations no less protective than this DPA.

5. International transfers

Primary hosting is in the EU. Where a sub-processor processes data outside the EU/EEA (for example US-based AI providers), transfers rely on an adequacy decision or the EU Standard Contractual Clauses, as implemented in that sub-processor's data-processing terms.

6. Assistance, deletion and audits

Taking into account the nature of the processing, we assist the Customer with data-subject requests (the Service provides self-serve deletion and export where possible), with security-incident notifications — we will inform the Customer without undue delay after becoming aware of a personal data breach affecting their data — and with data-protection impact assessments where required.

On termination, the Customer can delete its agency and all associated data directly in the Service (Settings → Agency → Delete this agency); we delete remaining personal data within 30 days, except where retention is required by law. We make available the information reasonably necessary to demonstrate compliance with this DPA and allow audits as required by Art. 28(3)(h) GDPR, normally satisfied by documentation, with on-site audits at most once a year on 30 days' notice, at the Customer's cost.

7. Contact

Data-protection questions and notices: [email protected].