1.Parties and conclusion of this Agreement
The processor is the Provider within the meaning of the Terms of Service:
- Name
- Onecast Paweł Zaręba
- Address
- ul. Piastowska 17, 42-256 Przymiłowice, Polska
- Tax ID (NIP)
- 9492285992
- REGON
- 545521872
- Phone
- +48786583222
- kontakt@onecast.pl
- This data processing agreement (the “Agreement”) is concluded between the Provider as processor and the Customer as controller. It is Annex 1 to the Terms of Service and an integral part of them, and it is the contract referred to in Article 28(3) GDPR.
- This Agreement is concluded in electronic form when the Basic Agreement is concluded — by ticking, when signing up for an Account, the declaration accepting the Terms of Service together with this Agreement. The Provider records the type of document, its version, language and the date of the declaration. The electronic form meets the requirement of Article 28(9) GDPR.
- A User who concluded the Basic Agreement before this Agreement was made available concludes it through the procedure for changes to the Terms of Service described in the “Changes to the Terms” section of the Terms of Service.
- This Agreement covers the Organization owned by the User who concluded it — including one created after this Agreement was concluded. A User accepting this Agreement on behalf of a business or another entity represents that they are authorised to do so; that entity is then the party to this Agreement.
- This Agreement applies to the extent the Customer is the controller of Customer Personal Data to which the GDPR applies. It does not apply to processing by a natural person in the course of a purely personal or household activity (Article 2(2)(c) GDPR).
- Where the Customer processes Customer Personal Data as a processor on behalf of another controller (e.g. an agency managing its clients’ profiles), the Customer warrants that it has that controller’s authorisation to entrust the data to the Provider and to the use of the sub-processors listed in Annex A, and that its instructions are consistent with that controller’s instructions. The Provider then acts as a sub-processor and takes instructions only from the Customer.
- In matters concerning the protection of Customer Personal Data this Agreement prevails over the Terms of Service; in all other matters the Terms of Service apply. If the parties conclude a separate, individually negotiated data processing agreement (e.g. under the Enterprise plan), it prevails over this Agreement to the extent it governs the same matters.
2.Definitions
- GDPR
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Customer
- A User who is the Owner of an Organization or, where they use Onecast on behalf of a business or another entity, that entity.
- Customer Personal Data
- Personal data the Provider processes on behalf of the Customer in connection with providing the Service in the Customer’s Organizations — to the extent described in the “Types of data and categories of data subjects” section.
- Sub-processor
- An entity engaged by the Provider to process Customer Personal Data in order to provide the Service (Article 28(2) and (4) GDPR), listed in Annex A.
- Personal data breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data (Article 4(12) GDPR).
- Platform
- An external social network to which a Channel is connected (e.g. Facebook, Instagram, Threads, TikTok, LinkedIn, YouTube, Bluesky, Mastodon).
- EEA
- The European Economic Area.
- Other terms
- Capitalised terms not defined above (including Provider, Service, User, Account, Organization, Owner, Workspace, Channel, Basic Agreement, Paid Agreement) have the meaning given to them in the Terms of Service, and the terms “controller”, “processor”, “processing” and “data subject” have the meaning given to them in the GDPR.
3.Subject matter, nature and purpose of processing
- The subject matter of this Agreement is the processing of Customer Personal Data by the Provider on behalf of the Customer in connection with providing the Service under the Terms of Service.
- Nature of processing — the Provider performs on Customer Personal Data the operations needed for the Onecast features the Customer uses:
- collection — from the Organization’s Users (content, media) and from Platforms through their APIs, based on the authorisation granted when connecting a Channel (profile data, publications, comments, statistics),
- recording, organisation and storage in the database and in file storage,
- adaptation of media — resizing, cropping, format conversion, creation of versions, variants and thumbnails,
- consultation and display to members of the Organization according to their roles,
- disclosure by transmission — publishing content and media on the Channels chosen by the Customer, replies to comments, e-mail notifications to members of the Organization,
- erasure — on the Customer’s instruction and automatically, when the retention periods described in the “Types of data and categories of data subjects” section expire and when an Organization without an active plan is deleted as described in the “Duration of processing” section.
- Purpose of processing — solely providing the Service to the Customer: creating, scheduling and publishing content on connected Channels, running the media library, presenting publications and statistics, handling comments where the feature is available and collaboration between members of the Organization — as well as maintaining, securing and diagnosing the Service and handling the Customer’s requests to the extent needed to provide it.
- The Provider does not process Customer Personal Data for its own purposes — in particular it does not use it for marketing, advertising or profiling, does not sell it, does not combine it with other customers’ data and does not use it to train artificial intelligence models.
4.Types of data and categories of data subjects
Customer Personal Data comprises personal data in the following categories — to the extent the Customer uses the relevant feature:
| Category | Types of data | Data subjects | Retention in Onecast |
|---|---|---|---|
| Post content and media | Text of the post and of the first comment, Platform-specific settings (e.g. title, description), photos and videos with their versions, variants and thumbnails — and any personal data the Customer includes in them (e.g. image, name, tag, mention). | People shown, named or tagged in the Customer’s content and media, e.g. its employees, collaborators, customers, event participants. | Until deleted by the Customer. A deleted post disappears from the post list immediately, and its technical record remains until the Workspace, Organization, Account or Channel history is deleted. Deleted media is erased from file storage in the background. |
| Publications | ID, link, text or description, thumbnail and publication date — for posts published through Onecast and for publications imported from the Platform at the Customer’s request. | As for post content and media. | Imported publications — until the Channel is disconnected. Publications created by Onecast — until the Channel history, Workspace, Organization or Account is deleted. Data retrieved from YouTube — at most 30 days after it was last retrieved, unless refreshed. |
| Comments and replies | Comment text, the author’s display name, handle, avatar and ID, like count, and replies published by members of the Organization — for Platforms for which Onecast offers the comments feature. | Authors of comments under the Customer’s publications — users of the Platforms. | 30 days after the comment was added on the Platform; earlier if the Channel is disconnected or access to it is permanently lost. When a comment is deleted on the Platform, its text and author data are deleted immediately and a technical marker without that data after 72 hours. |
| Channel profile data | Name, handle, avatar and account ID of the connected profile. | Natural persons whose profiles the Customer connects as Channels (e.g. the Customer itself, its employees, creators working with the Customer). | Until the Workspace, Organization or Account is deleted — also after the Channel is disconnected, except for YouTube Channels. When a Channel is disconnected with its history deleted, the avatar is deleted and the name and handle remain as the Channel’s label. YouTube Channel: once it is disconnected, its name, handle, avatar and account ID are deleted without undue delay, and the local Onecast history remains without data identifying the Channel; when authorised access to the channel temporarily cannot be confirmed, this data is kept at most for the period allowed by YouTube’s policies — currently 30 days — needed to reconnect or refresh it, and then deleted. YouTube channel avatar — at most 30 days after it was last retrieved, unless refreshed. |
| Statistics | Aggregate engagement counts for publications (e.g. likes, comments, views, reach) and the Channel’s follower count — with no data about individual audience members. | People whose profiles are connected as Channels — to the extent the statistics of their profile are personal data. | Until the Channel history, Workspace, Organization or Account is deleted. YouTube statistics — as long as authorised access to the channel is confirmed at least once every 30 days. |
| Other data in the Workspace | Personal data that members of the Organization put in other Workspace items (e.g. names of tags and media collections) and in the name, description, icon and logo of the Organization or a Workspace, and the attribution of content to the member of the Organization who created it. | Members of the Customer’s Organization and other people designated by the Customer. | Until the item is deleted or changed, or the Workspace, Organization or Account is deleted. |
- Category
- Post content and media
- Types of data
- Text of the post and of the first comment, Platform-specific settings (e.g. title, description), photos and videos with their versions, variants and thumbnails — and any personal data the Customer includes in them (e.g. image, name, tag, mention).
- Data subjects
- People shown, named or tagged in the Customer’s content and media, e.g. its employees, collaborators, customers, event participants.
- Retention in Onecast
- Until deleted by the Customer. A deleted post disappears from the post list immediately, and its technical record remains until the Workspace, Organization, Account or Channel history is deleted. Deleted media is erased from file storage in the background.
- Category
- Publications
- Types of data
- ID, link, text or description, thumbnail and publication date — for posts published through Onecast and for publications imported from the Platform at the Customer’s request.
- Data subjects
- As for post content and media.
- Retention in Onecast
- Imported publications — until the Channel is disconnected. Publications created by Onecast — until the Channel history, Workspace, Organization or Account is deleted. Data retrieved from YouTube — at most 30 days after it was last retrieved, unless refreshed.
- Category
- Comments and replies
- Types of data
- Comment text, the author’s display name, handle, avatar and ID, like count, and replies published by members of the Organization — for Platforms for which Onecast offers the comments feature.
- Data subjects
- Authors of comments under the Customer’s publications — users of the Platforms.
- Retention in Onecast
- 30 days after the comment was added on the Platform; earlier if the Channel is disconnected or access to it is permanently lost. When a comment is deleted on the Platform, its text and author data are deleted immediately and a technical marker without that data after 72 hours.
- Category
- Channel profile data
- Types of data
- Name, handle, avatar and account ID of the connected profile.
- Data subjects
- Natural persons whose profiles the Customer connects as Channels (e.g. the Customer itself, its employees, creators working with the Customer).
- Retention in Onecast
- Until the Workspace, Organization or Account is deleted — also after the Channel is disconnected, except for YouTube Channels. When a Channel is disconnected with its history deleted, the avatar is deleted and the name and handle remain as the Channel’s label. YouTube Channel: once it is disconnected, its name, handle, avatar and account ID are deleted without undue delay, and the local Onecast history remains without data identifying the Channel; when authorised access to the channel temporarily cannot be confirmed, this data is kept at most for the period allowed by YouTube’s policies — currently 30 days — needed to reconnect or refresh it, and then deleted. YouTube channel avatar — at most 30 days after it was last retrieved, unless refreshed.
- Category
- Statistics
- Types of data
- Aggregate engagement counts for publications (e.g. likes, comments, views, reach) and the Channel’s follower count — with no data about individual audience members.
- Data subjects
- People whose profiles are connected as Channels — to the extent the statistics of their profile are personal data.
- Retention in Onecast
- Until the Channel history, Workspace, Organization or Account is deleted. YouTube statistics — as long as authorised access to the channel is confirmed at least once every 30 days.
- Category
- Other data in the Workspace
- Types of data
- Personal data that members of the Organization put in other Workspace items (e.g. names of tags and media collections) and in the name, description, icon and logo of the Organization or a Workspace, and the attribution of content to the member of the Organization who created it.
- Data subjects
- Members of the Customer’s Organization and other people designated by the Customer.
- Retention in Onecast
- Until the item is deleted or changed, or the Workspace, Organization or Account is deleted.
Special categories of data (Article 9 GDPR) and data relating to criminal convictions and offences (Article 10 GDPR): the Service is not designed for the systematic processing of such data. The Customer should not use Onecast for such processing without an appropriate legal basis and without assessing whether the Service and the measures described in Annex B are appropriate for it. If such data is included in Customer Personal Data (e.g. incidentally in the text of a post or in a media item), it remains Customer Personal Data — all provisions of this Agreement and the security measures described in Annex B apply to it.
Processing is continuous for the duration of this Agreement.
5.Duration of processing
- This Agreement remains in force for as long as the Basic Agreement. The Customer Personal Data of an Organization is processed until that Organization is deleted — by its Owner, together with the Owner’s Account, or automatically as set out in clause 2.
- The end of a Paid Agreement does not end this Agreement: the Organization continues in the read-only mode described in the Terms of Service. An Organization that has no active plan (a Paid Agreement, a trial or a plan granted by the Provider) is deleted by the Provider together with its Customer Personal Data 90 days after its last plan ended — after notice sent to the Owner by e-mail at least 30 days in advance, in accordance with the Terms of Service. An active plan obtained before that period ends keeps the Organization and its data. An Account that does not belong to any Organization, and is deleted for that reason after 30 days, holds no Customer Personal Data.
- The Provider’s obligations regarding Customer Personal Data, in particular confidentiality and security, continue after this Agreement ends — until the Customer Personal Data is deleted in accordance with the “Deletion or return of data” section.
6.Rights and obligations of the Customer
- The Customer determines the purposes and means of processing Customer Personal Data — in particular what content it creates and publishes, which Channels it connects, whom it replies to, whom it invites to the Organization and when it deletes data — and is responsible for the lawfulness of that processing.
- In particular, the Customer ensures that it:
- has a legal basis for processing Customer Personal Data and for entrusting it to the Provider and, where required, consent to the dissemination of the image of people shown in media,
- has fulfilled its information obligations towards data subjects, including the authors of comments under its publications,
- is entitled to the Channels it connects and to publish content on them,
- gives members of the Organization roles appropriate to their tasks and promptly removes access from people who should no longer have it,
- does not put personal data into Onecast beyond what is needed for the purposes for which it uses the Service.
- In particular, the Customer has the right to:
- give the Provider instructions regarding the processing of Customer Personal Data — as set out in the “Processing on documented instructions” section,
- receive the information needed to demonstrate GDPR compliance and to carry out audits — as set out in the “Information and audits” section,
- object to a change of sub-processor — as set out in the “Sub-processors” section,
- request deletion or return of Customer Personal Data — as set out in the “Deletion or return of data” section.
- The Customer promptly informs the Provider of circumstances that require the Provider to act regarding Customer Personal Data — in particular requests from data subjects and proceedings by authorities.
7.Processing on documented instructions
- The Provider processes Customer Personal Data only on documented instructions from the Customer — including with regard to transfers to a third country or an international organisation — unless required to do so by Union or Member State law. In that case it informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Article 28(3)(a) GDPR).
- The Customer’s documented instructions are:
- this Agreement and the Terms of Service, including the description of the Service’s features,
- actions taken in Onecast by Users in the Customer’s Organizations within their roles — e.g. creating, scheduling, publishing or deleting a post, uploading or deleting media, connecting or disconnecting a Channel, importing publication history, replying to a comment, deleting a Workspace or Organization,
- instructions sent by e-mail to kontakt@onecast.pl from the e-mail address of the Owner of the Organization concerned.
- The Customer is responsible for the actions of the Users to whom it has given access to its Organizations and Workspaces — the Provider treats their actions within their roles as the Customer’s instructions.
- If, in the Provider’s opinion, an instruction infringes the GDPR or other data protection provisions, the Provider immediately informs the Customer (Article 28(3), second subparagraph, GDPR) and may suspend carrying it out until the Customer confirms or changes it.
- The Provider may refuse an instruction that would require changing the Service’s features or goes beyond its scope, stating the reason. The Customer may then stop using the Service and request deletion or return of Customer Personal Data.
8.Obligations of the Provider
In addition to the obligations set out in the other sections, the Provider:
- processes Customer Personal Data only to the extent and for the purpose described in this Agreement,
- maintains a record of all categories of processing activities carried out on behalf of controllers (Article 30(2) GDPR),
- cooperates with the supervisory authority in the performance of its tasks (Article 31 GDPR),
- promptly informs the Customer of requests from public authorities concerning Customer Personal Data and of inspections and proceedings of the supervisory authority concerning its processing, unless the law prohibits such information — and discloses Customer Personal Data to authorities only where required by law, to the extent required,
- promptly informs the Customer if it can no longer meet its obligations under this Agreement.
9.Confidentiality
- The Provider allows only persons it has authorised, and who need access to provide, maintain or secure the Service or to handle the Customer’s requests, to process Customer Personal Data — to the extent needed for those tasks.
- Each such person has committed to keeping Customer Personal Data and the ways it is secured confidential or is under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR). This obligation continues after their cooperation with the Provider ends.
- The Provider’s staff access Organization data only through a separate operations panel, with separate accounts, mandatory two-factor authentication and an activity log — see Annex B.
10.Security of processing
- Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, the Provider implements technical and organisational measures ensuring a level of security appropriate to that risk (Article 28(3)(c) and Article 32 GDPR). The measures applied are described in Annex B.
- The Provider may change the measures described in Annex B as the Service and technology evolve, provided that the change does not lower the overall level of security of Customer Personal Data.
- The Customer declares that it has read the measures described in Annex B and — given the type of data it intends to process in Onecast — considers them appropriate. The Customer and its Users are responsible for the security of Account access on their side (passwords, devices, assigning roles).
11.Sub-processors
- The Customer gives the Provider general written authorisation to engage sub-processors (Article 28(2) GDPR). By concluding this Agreement, the Customer accepts the sub-processors listed in Annex A.
- The Provider entrusts a sub-processor only with the Customer Personal Data, and only to the extent, needed for that sub-processor’s service — under a data processing agreement meeting the requirements of Article 28(3) and (4) GDPR (including the provider’s standard data processing agreement) that provides sufficient guarantees to implement appropriate technical and organisational measures.
- The Provider remains liable to the Customer for the performance of a sub-processor’s data protection obligations as for its own acts (Article 28(4), second sentence, GDPR).
- The Provider gives notice of any intended addition or replacement of a sub-processor at least 30 days before the change — by e-mail to the Owner of each Organization and by updating Annex A on this page — stating the entity’s name, the scope of its service, the location of processing and the basis for any transfer of data outside the EEA.
- The Customer may raise a reasoned objection to the change, based on data protection grounds, within 14 days of receiving the notice, by writing to kontakt@onecast.pl. The parties will seek a solution in good faith. If they do not find one, before the change takes effect the Customer may stop using the Service for the Organization concerned (by deleting it or the Account, or by requesting its deletion by e-mail) and terminate that Organization’s Paid Agreement by e-mail with effect from the day before the change — the Provider then refunds a proportionate part of the price for the unused, prepaid period.
- If a change is urgently needed for the security of Customer Personal Data, the continuity of the Service or because the current provider stops providing its service, the Provider may make it with shorter notice, informing the Customer promptly and giving reasons. The Customer then has the rights described in the previous clause, counted from the day it receives the notice.
- The Platforms on which the Customer publishes through Onecast and from which Onecast retrieves Channel data are not sub-processors: they process data as independent controllers, under agreements and terms the Customer has concluded with them, and Customer Personal Data is transmitted to them on the Customer’s instructions. Nor are providers that process only data for which the Provider is the controller sub-processors — e.g. the payment provider Stripe or Cloudflare Turnstile (see Annex A).
12.Assistance with data subject rights
- Taking into account the nature of processing, the Provider assists the Customer, by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests for exercising the data subject’s rights laid down in Chapter III GDPR (Article 28(3)(e) GDPR).
- The Customer can fulfil most such requests itself in Onecast:
- access and rectification — by viewing and editing posts, media and other Workspace items,
- erasure — by deleting a post, media item, Workspace or Organization, disconnecting a Channel (with the option to delete its history) or deleting a comment on the Platform, which also deletes its text and author data in Onecast,
- restriction of processing — by deleting a scheduled publication or disconnecting a Channel.
- Where the tools available in Onecast are not enough — e.g. when the technical record of a post deleted from the post list, a single comment or a given person’s data across many items must be permanently deleted — the Provider carries out the Customer’s instruction, sent in accordance with the “Processing on documented instructions” section, without undue delay and no later than 14 days after receiving it.
- If a data subject’s request concerning Customer Personal Data reaches the Provider directly, the Provider does not handle it on the merits: without undue delay, and no later than within 7 days, it forwards the request to the Customer (the Owner of the relevant Organization) and tells the requester that the request has been forwarded to the controller.
- The Provider charges no additional fee for the assistance described in this section.
13.Personal data breaches
- After becoming aware of a breach of Customer Personal Data, the Provider notifies the Customer without undue delay — by e-mail to the Owner of each Organization affected (Article 33(2) GDPR).
- The notification contains — to the extent the Provider has this information at the time of notification:
- a description of the nature of the breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned,
- the contact details of the person from whom more information can be obtained,
- a description of the likely consequences of the breach,
- a description of the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
- Where it is not possible to provide the information at the same time, the Provider provides it in phases without undue delay.
- The Provider promptly takes action to contain the breach and to prevent similar breaches in the future, documents breaches (facts, effects and remedial action taken) and cooperates with the Customer in investigating them.
- Notifying the supervisory authority and communicating the breach to data subjects (Articles 33–34 GDPR) is the responsibility of the Customer as controller; the Provider assists by providing the information it has (Article 28(3)(f) GDPR). Without the Customer’s instruction the Provider does not notify data subjects, unless required by law.
- Notification of a breach is not an admission of fault or liability by the Provider.
14.Impact assessments and prior consultation
- Taking into account the nature of processing and the information available to it, the Provider assists the Customer in ensuring compliance with the obligations under Articles 32–36 GDPR, in particular with data protection impact assessments (Article 35 GDPR) and prior consultation of the supervisory authority (Article 36 GDPR) — in accordance with Article 28(3)(f) GDPR.
- This assistance consists of making available the information about processing held by the Provider — in particular the description of processing in this Agreement and in Annexes A and B — and answering the Customer’s questions about the processing of Customer Personal Data within a period agreed with the Customer, not longer than 30 days.
15.Information and audits
- The Provider makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer (Article 28(3)(h) GDPR).
- In the first instance the Provider provides information in writing: this Agreement and its annexes describe the processing, sub-processors and security measures, and the Provider answers the Customer’s questions (e.g. a security questionnaire) within a period agreed with the Customer, not longer than 30 days.
- If this information is not sufficient to demonstrate compliance, the Customer may carry out an audit, including an inspection, on the following terms:
- the Customer gives notice of the audit by e-mail at least 30 days in advance, stating its scope, date and auditor,
- the auditor is bound by confidentiality and does not carry on business competing with the Provider,
- the audit takes place on business days during working hours, for no longer than necessary, and in a way that does not disrupt the Service or compromise the confidentiality of other customers’ data or the security of the Service,
- audits take place no more than once every 12 months, unless there has been a breach of Customer Personal Data or the supervisory authority requires the audit,
- the Customer bears its own costs of a regular audit, including the auditor’s fees; if the audit reveals a material breach of this Agreement or the GDPR on the Provider’s side, the Provider remedies it at its own cost and may not rely on this provision to charge the Customer for remedying the breach.
- Audits do not cover the infrastructure of sub-processors. For that infrastructure the Provider makes available the information, reports and certifications those providers publish or provide to it.
- The Provider remedies without undue delay any shortcomings found in an audit that concern its obligations under this Agreement.
16.Transfers of data outside the EEA
- The Provider processes Customer Personal Data on a server in France (Gravelines, EU). Sub-processors may process it outside the EEA only to the extent stated in Annex A and on the basis of the mechanisms stated there: a Commission adequacy decision (Article 45 GDPR), including Implementing Decision (EU) 2023/1795 on the EU–U.S. Data Privacy Framework, or the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 (Article 46(2)(c) GDPR).
- By concluding this Agreement, the Customer instructs the transfer of Customer Personal Data to sub-processors as set out in Annex A. Any new transfer outside the EEA requires a change to Annex A under the “Sub-processors” section.
- The Customer decides to transfer data to a Platform by connecting its Channel and publishing content on it — including where that Platform processes data outside the EEA. The Provider carries out such a transfer on the Customer’s instructions.
- At the Customer’s request, the Provider identifies the safeguards applied to transfers by a sub-processor, including the data processing agreement containing the standard contractual clauses.
17.Deletion or return of data
- After the end of the provision of the Service for an Organization, the Provider — at the Customer’s choice — deletes or returns to the Customer that Organization’s Customer Personal Data and deletes all existing copies, unless Union or Member State law requires their storage (Article 28(3)(g) GDPR).
- Deleting an Organization or the Owner’s Account is an instruction to delete Customer Personal Data. Database records are deleted immediately and media files are erased from file storage in the background, usually within a few minutes; in case of technical problems the deletion is retried automatically until it succeeds. Details are on the Data deletion page.
- Onecast does not offer a self-service data export. A Customer who wants Customer Personal Data returned must request it by e-mail before deleting the Organization or Account — deletion is irreversible. The Provider then provides, within 30 days, a copy of the Organization’s Customer Personal Data, in particular post content and media files, in a commonly used electronic format.
- If the Basic Agreement is terminated for a reason other than the Customer’s action (e.g. by the Provider under the Terms of Service), the Provider informs the Owner by e-mail and for 30 days allows them to request the return of Customer Personal Data, and then deletes it — unless the law or a decision of an authority requires earlier deletion or preservation. Where an Organization without an active plan is deleted, the return can be requested until the notice period ends.
- Customer Personal Data may remain in database backups until they are rotated as described in Annex B. Backups are used solely to restore the Service after a failure; the Provider does not process the Customer Personal Data they contain for any other purpose and, until rotation, applies to it in full the confidentiality and security obligations under this Agreement.
- Deleting data in Onecast does not delete content already published on Platforms or data processed by Platforms — the Customer deletes it directly on the Platforms.
- At the Customer’s request, the Provider confirms the deletion of Customer Personal Data by e-mail.
18.Liability
- Towards data subjects, the parties are liable in accordance with Article 82 GDPR. The Provider is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to the Customer’s lawful instructions (Article 82(2) GDPR).
- Between the parties, liability under this Agreement is governed by the “Liability and availability” section of the Terms of Service. That section does not limit liability towards data subjects or liability under mandatory provisions of law.
19.Changes to this Agreement
- The Provider may change this Agreement for the valid reasons and through the procedure set out in the “Changes to the Terms” section of the Terms of Service — with at least 30 days’ notice, by e-mail and on this page. A Customer who does not accept the change may, before it takes effect, terminate the Basic Agreement and the Paid Agreement as described there.
- Changes to the list of sub-processors follow the “Sub-processors” section, and updates to the description of security measures that do not lower their level follow the “Security of processing” section.
- The version of this Agreement is the date of its last change, shown at the top of this page. The Provider keeps the text of every version unchanged and, at the Customer’s request, provides the version the Customer accepted.
20.Final provisions
- This Agreement is governed by Polish law. Disputes are resolved by the court having jurisdiction under the “Final provisions” section of the Terms of Service.
- This Agreement is made available free of charge on this page in a way that allows it to be obtained, reproduced and stored (e.g. by printing or saving as PDF).
- The Polish version of this Agreement is binding; the English version is a translation.
- The Customer sends matters concerning this Agreement — instructions, objections, requests to return data and audit questions — to kontakt@onecast.pl. The Provider contacts the Customer at the e-mail address of the Owner of the Organization concerned.
- If any provision of this Agreement is invalid or ineffective, the remaining provisions stay in force; the relevant provisions of the GDPR apply in its place.
21.Annex A — Sub-processors
As of the version date of this Agreement shown at the top of the page. The Provider uses the following sub-processors:
| Provider | Service | Purpose | Location | Transfer mechanism | Role |
|---|---|---|---|---|---|
| OVH Sp. z o.o., ul. Swobodna 1, 50-088 Wrocław, Poland (OVHcloud group) | Virtual private server (VPS) | Hosting the Onecast application: database, background job queues, media processing, temporary files and local database backups — all Customer Personal Data. | France (EU) — OVHcloud data centre in Gravelines. | Processing within the EEA. Remote access by OVHcloud group companies outside the EEA, where needed to provide the service — on the basis of the standard contractual clauses in the OVHcloud data processing agreement. | Sub-processor. |
| OVH Sp. z o.o., ul. Swobodna 1, 50-088 Wrocław, Poland (OVHcloud group) | Zimbra e-mail (SMTP) | Sending e-mail notifications to members of the Organization, which may contain fragments of Customer Personal Data — e.g. an excerpt of a post and the Channel name in a failed publication notice. | France — OVHcloud data centres. | Processing within the EEA. Remote access by OVHcloud group companies outside the EEA — as above. | Sub-processor. |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Cloudflare R2 — file storage | Storing post media files with their versions, variants and thumbnails (in a private bucket) and database backups, covering all Customer Personal Data stored in the database (in a separate bucket). | Cloudflare infrastructure. The Provider does not ensure storage exclusively within the EEA — data may also be processed in the USA. | Implementing Decision (EU) 2023/1795 (EU–U.S. Data Privacy Framework, in which Cloudflare, Inc. participates); additionally, the standard contractual clauses (Implementing Decision (EU) 2021/914) in the Cloudflare data processing agreement. | Sub-processor. |
- Provider
- OVH Sp. z o.o., ul. Swobodna 1, 50-088 Wrocław, Poland (OVHcloud group)
- Service
- Virtual private server (VPS)
- Purpose
- Hosting the Onecast application: database, background job queues, media processing, temporary files and local database backups — all Customer Personal Data.
- Location
- France (EU) — OVHcloud data centre in Gravelines.
- Transfer mechanism
- Processing within the EEA. Remote access by OVHcloud group companies outside the EEA, where needed to provide the service — on the basis of the standard contractual clauses in the OVHcloud data processing agreement.
- Role
- Sub-processor.
- Provider
- OVH Sp. z o.o., ul. Swobodna 1, 50-088 Wrocław, Poland (OVHcloud group)
- Service
- Zimbra e-mail (SMTP)
- Purpose
- Sending e-mail notifications to members of the Organization, which may contain fragments of Customer Personal Data — e.g. an excerpt of a post and the Channel name in a failed publication notice.
- Location
- France — OVHcloud data centres.
- Transfer mechanism
- Processing within the EEA. Remote access by OVHcloud group companies outside the EEA — as above.
- Role
- Sub-processor.
- Provider
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
- Service
- Cloudflare R2 — file storage
- Purpose
- Storing post media files with their versions, variants and thumbnails (in a private bucket) and database backups, covering all Customer Personal Data stored in the database (in a separate bucket).
- Location
- Cloudflare infrastructure. The Provider does not ensure storage exclusively within the EEA — data may also be processed in the USA.
- Transfer mechanism
- Implementing Decision (EU) 2023/1795 (EU–U.S. Data Privacy Framework, in which Cloudflare, Inc. participates); additionally, the standard contractual clauses (Implementing Decision (EU) 2021/914) in the Cloudflare data processing agreement.
- Role
- Sub-processor.
The following providers and recipients are not sub-processors of Customer Personal Data — we list them to make the distinction between roles clear:
| Provider | Service | Purpose | Location | Transfer mechanism | Role |
|---|---|---|---|---|---|
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA | Cloudflare Turnstile | Protecting the sign-in, sign-up and password reset forms against bots — based on the IP address and technical browser signals. Receives no Customer Personal Data. | Cloudflare infrastructure, including the USA. | As for Cloudflare R2. | Processor of the Provider as controller of security data; for improving bot detection — an independent controller. |
| Stripe Payments Europe, Limited (Ireland) and Stripe group companies | Payments and subscriptions | Handling payments for the Paid Agreement — billing data and payment method data. Receives no Customer Personal Data. | Ireland; possible processing in the USA. | Mechanisms applied by Stripe, including the standard contractual clauses. | Processor of the Provider for payment processing; independent controller for fraud prevention, risk management and anti-money-laundering obligations. |
| Platforms: Meta Platforms (Facebook, Instagram, Threads), TikTok, LinkedIn, Google (YouTube), Bluesky, the operator of the chosen Mastodon instance | Platform APIs | Publishing content and media, replying to comments and retrieving Channel, publication, comment and statistics data — on the Customer’s instructions. | Depending on the Platform, including outside the EEA. | According to each Platform’s rules; the Customer decides on the transfer by connecting the Channel and publishing content. | Independent controllers — recipients of data on the Customer’s instructions. |
- Provider
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
- Service
- Cloudflare Turnstile
- Purpose
- Protecting the sign-in, sign-up and password reset forms against bots — based on the IP address and technical browser signals. Receives no Customer Personal Data.
- Location
- Cloudflare infrastructure, including the USA.
- Transfer mechanism
- As for Cloudflare R2.
- Role
- Processor of the Provider as controller of security data; for improving bot detection — an independent controller.
- Provider
- Stripe Payments Europe, Limited (Ireland) and Stripe group companies
- Service
- Payments and subscriptions
- Purpose
- Handling payments for the Paid Agreement — billing data and payment method data. Receives no Customer Personal Data.
- Location
- Ireland; possible processing in the USA.
- Transfer mechanism
- Mechanisms applied by Stripe, including the standard contractual clauses.
- Role
- Processor of the Provider for payment processing; independent controller for fraud prevention, risk management and anti-money-laundering obligations.
- Provider
- Platforms: Meta Platforms (Facebook, Instagram, Threads), TikTok, LinkedIn, Google (YouTube), Bluesky, the operator of the chosen Mastodon instance
- Service
- Platform APIs
- Purpose
- Publishing content and media, replying to comments and retrieving Channel, publication, comment and statistics data — on the Customer’s instructions.
- Location
- Depending on the Platform, including outside the EEA.
- Transfer mechanism
- According to each Platform’s rules; the Customer decides on the transfer by connecting the Channel and publishing content.
- Role
- Independent controllers — recipients of data on the Customer’s instructions.
22.Annex B — Technical and organisational measures
This description reflects the Service as of the version date of this Agreement. The Provider holds no information security certification (e.g. ISO/IEC 27001, SOC 2) and does not adhere to an approved code of conduct or certification mechanism within the meaning of Articles 40–42 GDPR. Certifications held by infrastructure providers relate to their services, not to Onecast.
User access control
- sign-in with an e-mail address and a password stored only as a hash (bcrypt); optionally a passkey and two-factor authentication (TOTP) with recovery codes,
- a limit of 5 sign-in attempts and 5 two-factor authentication attempts per minute; protection of the sign-in, sign-up and password reset forms against bots (Cloudflare Turnstile),
- access to Workspaces only after the e-mail address has been verified,
- sessions expire after 2 hours of inactivity; encrypted session cookies with the HttpOnly, Secure and SameSite=Lax attributes; deleting an Account requires password confirmation.
Roles and authorisation
- separate roles in the Organization (Owner, Administrator, Member) and in the Workspace (Owner, Administrator, Member) — access to features depends on both,
- permissions are checked on the server on every request, not only in the interface,
- removing a member from an Organization, or a member leaving it, immediately ends their access to all of that Organization’s Workspaces,
- an Organization’s plan and payments are available only to its Owner.
Separation of Organizations and Workspaces
- customer data is stored in a shared database and shared file storage, with logical separation: every post, media item, Channel, publication and comment belongs to one Workspace, and every Workspace to one Organization,
- access to a Workspace’s data requires membership in it; viewing a media file in the application checks membership on every download, so removing access takes effect immediately,
- relationships in the database are protected by foreign keys that do not allow data to be left without its Workspace or Organization by bypassing the deletion procedure.
Encryption and secrets
- all communication with Onecast uses HTTPS (TLS); HTTP connections are redirected to HTTPS,
- connections to Platform APIs, the payment provider and file storage use HTTPS,
- Channel access and refresh tokens and two-factor authentication secrets are encrypted in the database with AES-256 using an application key that is not stored in the database,
- files in Cloudflare R2 storage are encrypted at rest (AES-256) by the provider,
- the application key, credentials for external services and the pseudonymisation key are kept in the server environment configuration, outside the code repository.
Private file storage
- the media bucket is private — files have no permanent public addresses,
- media are viewed in the application through an Onecast gateway that checks sign-in and Workspace membership on every request,
- Platforms retrieve files for publishing only through signed, expiring addresses valid for at most 2 hours,
- media processing (resizing, video conversion) takes place on the application server, without sending files to external processing services.
Background jobs and authorisation generation
- publishing, retrieving data from Platforms, media processing and file deletion are carried out by queue worker processes running on the application server, supervised by the system service manager (systemd) and monitored in the operations panel,
- every change to a Channel’s authorisation (connecting, reconnecting, disconnecting, confirmed loss of access) advances its authorisation generation; a job writes the result of a Platform request only if the Channel is still active and has the same generation as before the request — so a late job cannot restore data deleted when the Channel was disconnected.
Data deletion lifecycle and file deletion ledger
- deletion follows one fixed path: Channel → Workspace → Organization → Account — in database transactions, so an operation completes in full or not at all,
- disconnecting a Channel or a confirmed loss of authorisation immediately deletes its tokens, comments and publications imported from the Platform,
- daily jobs automatically delete comments after 30 days and data retrieved from YouTube that could not be refreshed within 30 days,
- file deletion ledger: every file to be erased is recorded in the database in the same transaction in which the data is deleted; a process running every 5 minutes erases the files from storage and checks that they are actually gone, and on error retries with an increasing interval (at most 24 hours) — an entry is never abandoned; a file still used by another existing item is not erased while that item exists.
Event logging and monitoring
- technical application logs and logs of communication with Platform APIs are kept for up to 14 days and are used for diagnostics and security,
- staff actions in the operations panel are recorded in an append-only activity log (who, what action, on which object, when, from which IP address) — entries cannot be edited or deleted from the panel,
- the state of worker processes, the job scheduler, backups and server resources is monitored in the operations panel.
Provider staff access
- the operations panel runs on a separate domain, with separate staff accounts, a separate session store and mandatory two-factor authentication (TOTP),
- staff permissions are granted through roles, to the extent needed to operate the Service and handle requests,
- the panel does not allow signing in to a User’s Account or acting on their behalf,
- people with access are bound by confidentiality — see the “Confidentiality” section.
Backups and recovery
- the database is backed up daily by a scheduled process on the server: a compressed database dump is written on the server with access restricted to the system administrator and uploaded to a separate Cloudflare R2 bucket, and the process checks that the backup has arrived there; no successful backup for more than 26 hours is flagged in the operations panel as a warning, and for more than 30 hours as critical,
- the same process rotates backups — on the server after 14 days and in Cloudflare R2 after 30 days; backups are used solely to restore the Service after a failure,
- the Provider does not declare a separate backup of media files stored in Cloudflare R2 or a contractually guaranteed recovery time — Onecast offers no SLA.
Organisational measures
- data minimisation: comments are retrieved only for Platforms for which the feature is enabled and kept for at most 30 days; LinkedIn comments are not retrieved; statistics are aggregate counts only,
- Onecast uses no third-party analytics, advertising or tracking cookies or tools,
- the procedures described in this Agreement: breach notification without undue delay, forwarding data subject requests within 7 days, carrying out the Customer’s instructions,
- the application code is covered by automated tests, including tests of access permissions, separation of Workspace data and data deletion paths.