PostOmnia ← Back Deutsch

Data Processing Agreement (DPA)

Agreement pursuant to Art. 28 GDPR between you as controller and Fade Media GmbH as processor. Version 1.0, as of 2026-08-07. Acceptance takes place in the dashboard under Settings → Privacy → Data processing agreement, where the signed version with its date is also available for download. The German version is the authoritative one in case of doubt.

§ 1 Subject matter and roles

The customer ("controller") uses PostOmnia to plan, approve, publish and analyse its own and third-party social media presences. Where personal data is processed in doing so, Fade Media GmbH ("processor") acts exclusively on the controller's documented instructions.

The controller remains responsible for the lawfulness of the processing – in particular for being permitted to process the content, contact data and social media credentials it brings into PostOmnia. Where the controller itself acts on behalf of its own clients (the typical agency case), Fade Media GmbH acts as a sub-processor.

For the customer's own contract, billing and account data, Fade Media GmbH is itself the controller; the Privacy Policy applies to that, not this agreement.

§ 2 Nature, purpose and duration

§ 3 Categories of data subjects and data

Special categories of personal data under Art. 9 GDPR are not the subject of this agreement. If the controller nevertheless submits such data as content, the processor handles it like any other content data; the controller assesses admissibility.

§ 4 Instructions

The processor processes the data solely on the controller's documented instructions. This agreement, the main contract and the settings and actions performed within the service constitute instructions. Further instructions are issued in text form to info@postomnia.com.

If the processor considers an instruction unlawful, it shall notify the controller without undue delay and may suspend execution until the matter is resolved. Where Union or Member State law requires processing, the processor informs the controller beforehand unless that law prohibits it.

§ 5 Confidentiality

The processor engages only persons who are bound by confidentiality or under an appropriate statutory obligation of confidentiality, and who have been familiarised with the applicable data protection requirements before starting work.

§ 6 Technical and organisational measures

The processor implements the measures described in Annex 1 (TOM) pursuant to Art. 32 GDPR. The measures may be developed further as long as the level of protection is not reduced. Annex 1 forms part of this agreement.

§ 7 Sub-processors

The controller grants general authorisation for engaging the sub-processors listed in Annex 2 (sub-processor list). The processor imposes on each sub-processor obligations at least equivalent to those agreed here.

Changes to the list are announced at least 30 days in advance by email to the address stored in the account. Within that period the controller may object for an important data-protection-related reason; if no agreement is reached, it may terminate the main contract for cause with effect from the date the change takes effect.

§ 8 International transfers

Processing takes place within the European Union as a matter of principle. Where individual sub-processors process outside the EU, this occurs only on the basis of a mechanism under Art. 44 et seq. GDPR – in particular an adequacy decision or the EU Standard Contractual Clauses with supplementary measures. The applicable basis is stated per provider in Annex 2.

§ 9 Erasure and return

The controller can export its data at any time (Settings → Privacy → Export my data) and permanently delete workspaces or the account. After the main contract ends, the processor erases the processed data within 30 days unless a statutory retention obligation applies. Invoices and receipts are subject to retention under German tax and commercial law and are blocked rather than erased for the duration of that period. Backups are overwritten as part of the regular rotation cycle (see Annex 1).

§ 10 Assistance obligations

The processor assists the controller by appropriate means with

§ 11 Evidence and audits

The processor makes available the information necessary to demonstrate compliance – primarily through the documentation in Annex 1 and the security overview at /sicherheit.html. Where that is not sufficient, it allows for and contributes to audits, including inspections, after reasonable prior notice, during normal business hours and without disrupting operations. The controller bears the cost of an on-site audit unless the audit reveals a breach.

§ 12 Liability and final provisions

Liability is governed by Art. 82 GDPR and the provisions of the main contract. German law applies. In the event of conflicts between this agreement and the main contract, this agreement prevails on data protection matters.

Version 1.0 · As of 2026-08-07 · Annex 1: TOM · Annex 2: Sub-processors