Legal

Data Processing Addendum

This DPA governs how we process personal data on behalf of Buddy customers, in line with applicable data protection law.

Effective June 12, 2026Plaxonic IT Services13 Sections

01Scope & Roles

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", "Controller") and Plaxonic IT Services ("we", "Processor") for use of Buddy. It applies where we process personal data on the Customer's behalf. Where terms conflict, this DPA governs the processing of personal data.

The Customer is the controller of personal data it submits to the Platform; we act as processor, and any of our sub-processors act as sub-processors.

02Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person submitted to the Platform by the Customer.
  • Controller / Processor / Sub-processor: Have the meanings given under applicable data protection law, including the GDPR.
  • Data Subject: The individual to whom personal data relates.
  • Applicable Data Protection Law: All laws governing the processing of personal data, including the GDPR, UK GDPR, and CCPA/CPRA where relevant.

03Details of Processing

  • Subject Matter: Provision of the Buddy AI social media content platform.
  • Duration: For the term of the agreement, plus any retention period required to fulfil the Service or by law.
  • Nature & Purpose: Hosting, storing, and processing content and account data to generate, schedule, and publish social media content.
  • Categories of Data: Account identifiers, brand and organization data, content and prompts, usage data, and limited billing metadata.
  • Data Subjects: The Customer's authorized users and, where applicable, individuals referenced in content the Customer submits.

04Customer Instructions

We process personal data only on the documented instructions of the Customer, including as set out in the agreement and this DPA, unless required to do otherwise by law. If we believe an instruction violates applicable data protection law, we will inform the Customer.

05Confidentiality

We ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations and receive suitable data protection training. Access is limited to those who need it to deliver the Service.

06Security Measures

We implement appropriate technical and organizational measures to protect personal data, taking into account the state of the art and the risks involved. These include:

  • Encryption of data in transit (HTTPS/TLS).
  • Secure authentication and role-based access controls.
  • Network protections, logging, and monitoring.
  • Regular review of access rights and security practices.

07Sub-processors

The Customer authorizes us to engage sub-processors to deliver the Service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Current sub-processors include:

  • Stripe: Payment processing.
  • Cloud Hosting Provider: Infrastructure, storage, and content delivery.
  • AI Providers (e.g. Groq, Google Gemini): AI content and image generation from the minimum data necessary.

We will give the Customer notice of intended changes to sub-processors, allowing the Customer to reasonably object.

08Data Subject Requests

Taking into account the nature of the processing, we provide tools and reasonable assistance to help the Customer respond to data subject requests to exercise their rights of access, correction, deletion, restriction, portability, and objection.

09Personal Data Breach

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide information reasonably available to help the Customer meet its notification obligations.

10International Transfers

Where personal data is transferred across borders, we rely on lawful transfer mechanisms, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required.

11Return & Deletion of Data

On termination of the Service, and at the Customer's choice, we will delete or return the personal data we process on the Customer's behalf, unless retention is required by law. Deletion is performed within a reasonable timeframe.

12Audits

We make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, will support audits mandated by applicable data protection law.

13Contact

For DPA requests or to execute a signed copy, contact Plaxonic IT Services at support@superbuddy.io.

Still have questions?

Reach the Plaxonic team directly at support@superbuddy.io.

← Back to homeBuddy is a product of Plaxonic IT Services © 2026. All rights reserved.