Data Processing Addendum
Effective date: 1 October 2026 · Version 2026-10-01
This Data Processing Addendum ("DPA") is part of the Feedloom Terms of Service (the "Terms") between Sprout LLC, 299 NW 46th St, Boca Raton, FL 33431, USA ("Sprout", "Processor") and the customer that accepts the Terms ("Customer"). It applies when Sprout processes Customer Personal Data on behalf of Customer. The Customer accepts this DPA when it accepts the Terms. No signature is needed. If the Customer wants a signed copy, it can write to facundomartin@sproutco.io.
If this DPA conflicts with the Terms, this DPA applies. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses apply.
1. Definitions
- Data Protection Laws: all laws on personal data that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws, the Brazilian LGPD (Lei 13.709/2018) and the Argentine Ley 25.326.
- Customer Personal Data: personal data that Sprout processes on behalf of Customer to provide the Service, as described in Annex I.
- Personal Data Breach: a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Subprocessor: a third party that Sprout engages to process Customer Personal Data.
- SCCs: the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0, in force from 21 March 2022, as amended).
- Other terms (controller, processor, data subject, processing, business, service provider) have the meaning given by the Data Protection Laws.
2. Roles and scope
2.1. Customer is the controller (or, under the CCPA, the "business") of Customer Personal Data. If Customer acts as a processor for its own client (for example an agency), Customer confirms that its client has authorized Customer's instructions and the use of Sprout, and Sprout is a subprocessor of Customer.
2.2. Sprout is the processor (or "service provider") of Customer Personal Data.
2.3. This DPA does not apply to personal data that Sprout processes as a controller for its own purposes, for example account, billing, security and contract records of Customer's users. The Privacy Policy covers that data.
2.4. Social networks and AI assistants are not Subprocessors. When Customer instructs Sprout to publish a post, Sprout sends it to the social network that Customer selected. That social network receives the post as a separate controller under its relationship with Customer. An AI assistant that Customer connects through MCP or the API is a service chosen and controlled by Customer.
3. Customer's responsibilities
3.1. Customer is responsible for the lawfulness of the processing, including having a legal basis and the necessary consents for personal data in its content (for example the images of people in photos), and for giving the notices that the law requires.
3.2. Customer must not use the Service to process special categories of personal data or data of children, except where Customer has assessed that this is lawful and the Service is suitable.
4. Processing on instructions
4.1. Sprout processes Customer Personal Data only on Customer's documented instructions, including for transfers to third countries, unless the law requires otherwise. In that case, Sprout tells Customer before it processes the data, unless the law forbids this.
4.2. The Terms, this DPA and Customer's use and configuration of the Service (including approvals, schedules and publication requests) are Customer's complete instructions. Additional instructions need written agreement.
4.3. Sprout tells Customer at once if, in its opinion, an instruction breaks the Data Protection Laws.
5. Confidentiality
Sprout ensures that every person authorized to process Customer Personal Data is bound by a duty of confidentiality, and accesses the data only when this is needed to provide, secure or support the Service.
6. Security
Sprout implements the technical and organizational measures in Annex II. Sprout can update these measures if the overall level of security does not decrease.
7. Subprocessors
7.1. Customer gives Sprout a general authorization to engage Subprocessors. The current Subprocessors are listed in Annex III and at feedloom.app/legal/subprocessors.
7.2. Sprout gives at least 30 days' notice before it adds or replaces a Subprocessor, by updating the subprocessor page and by email to account owners who subscribed to these notices (account owners of paid plans are subscribed by default).
7.3. Customer can object on reasonable data-protection grounds within that period by writing to facundomartin@sproutco.io. The parties then discuss the objection in good faith. If they cannot solve it, Customer can end the affected part of the Service before the change takes effect, and Sprout refunds any prepaid fees for the rest of the paid period.
7.4. Sprout imposes on each Subprocessor, by written contract, data-protection obligations that give at least the same level of protection as this DPA. Sprout remains liable to Customer for the performance of its Subprocessors' obligations.
8. Assistance
8.1. Data subject requests. Sprout helps Customer, by appropriate technical and organizational measures, to answer requests from data subjects. Customer can edit, download and delete its content in the Service. If Sprout receives a request directly, it sends it to Customer without undue delay and does not answer it, unless Customer instructs otherwise or the law requires it.
8.2. Other assistance. Taking into account the information available to it, Sprout helps Customer with its security obligations, Personal Data Breach notifications, data protection impact assessments and prior consultations (GDPR Articles 32 to 36).
9. Personal Data Breaches
9.1. Sprout notifies Customer without undue delay, and in any case within 48 hours, after it becomes aware of a Personal Data Breach that affects Customer Personal Data.
9.2. The notice includes, as far as known: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact person. Sprout gives further information as it becomes available.
9.3. A notice is not an admission of fault or liability.
10. Deletion and return
10.1. During the term, Customer can download its images and delete its content in the Service.
10.2. When Customer deletes content, Sprout deletes it from its database and its storage provider; stored files are removed by an automatic cleanup after deletion is confirmed by the provider.
10.3. When Customer deletes its account or the Terms end, Sprout deletes Customer Personal Data within 30 days, and asks its publishing provider to remove the connections to Customer's social accounts, unless the law requires Sprout to keep the data. For 30 days after the end of the Terms, Customer can ask Sprout for a copy of its data. Copies in backups are deleted when the backup cycle overwrites them, and are protected until then. Posts that Customer already published remain on the social networks; Customer can delete them there.
11. Audits
11.1. Sprout makes available to Customer the information necessary to demonstrate compliance with this DPA and GDPR Article 28.
11.2. Customer can audit Sprout's compliance once a year, or more often if a supervisory authority requires it or after a Personal Data Breach. Customer must give 30 days' written notice, use an auditor that is bound by confidentiality and not a competitor of Sprout, avoid disruption, and pay its own costs. Sprout can first answer a written questionnaire or provide reports of its providers, if they are sufficient.
12. International transfers
12.1. Sprout is in the United States and processes Customer Personal Data in the United States and in the other locations in Annex III.
12.2. EEA. For transfers of Customer Personal Data from the EEA to Sprout, the SCCs are incorporated into this DPA by reference: Module 2 (controller to processor) where Customer is a controller, and Module 3 (processor to processor) where Customer is a processor. The parties make these choices: Clause 7 (docking clause) applies; Clause 9(a) Option 2 (general written authorization) with the notice period in section 7.2; the option in Clause 11(a) does not apply; Clause 13: the supervisory authority determined under Clause 13(a); Clause 17 Option 1: the law of Ireland; Clause 18(b): the courts of Ireland. Annex I and Annex II of this DPA complete Annexes I and II of the SCCs, and Annex III of this DPA completes Annex III of the SCCs.
12.3. United Kingdom. For transfers from the UK, the UK Addendum is incorporated by reference. Table 1: the parties' details are in Annex I. Table 2: the SCCs as incorporated in section 12.2. Table 3: Annexes I to III of this DPA. Table 4: both parties may end the UK Addendum as allowed by its Section 19.
12.4. Switzerland. For transfers from Switzerland, the SCCs apply with these changes: the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to the GDPR include the Swiss FADP; and the term "member state" does not exclude data subjects in Switzerland from suing in their place of habitual residence.
12.5. Brazil and Argentina. Where the LGPD or Ley 25.326 requires a specific transfer mechanism, the parties agree to the standard contractual clauses approved by the ANPD (Resolução CD/ANPD 19/2024) or by the Argentine authority (Disposición 60-E/2016), as applicable, which are incorporated by reference, with the details of the Annexes to this DPA.
12.6. If Sprout certifies under the EU–US Data Privacy Framework (or its UK or Swiss parts), Sprout can rely on that certification instead, and tells Customer.
13. US state privacy laws (CCPA and others)
13.1. Sprout is Customer's service provider (and processor) and processes Customer Personal Data only for the business purposes in Annex I.
13.2. Sprout does not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it for any purpose other than the business purposes in Annex I, including for any commercial purpose other than providing the Service; (c) retain, use or disclose it outside the direct business relationship between Sprout and Customer; or (d) combine it with personal data that Sprout receives from or on behalf of another person, or collects from its own interaction with the consumer, except as the CCPA allows for service providers.
13.3. Sprout does not use Customer Personal Data to train AI models.
13.4. Sprout complies with the CCPA and gives the same level of protection that the CCPA requires of Customer. Sprout tells Customer if it can no longer meet its obligations. Customer can take reasonable steps to stop and fix unauthorized use, including by the audit in section 11. Sprout certifies that it understands and will comply with the restrictions in this section.
14. Liability
The liability of each party under this DPA is subject to the limitations in the Terms, except where the Data Protection Laws or the SCCs do not allow such a limitation towards data subjects.
15. Term
This DPA applies as long as Sprout processes Customer Personal Data. Sections 10 and 12 continue after the end of the Terms until Sprout has deleted all Customer Personal Data.
Annex I — Description of the processing
A. Parties
- Data exporter: Customer, as identified in its account. Contact: the account owner's email. Role: controller (or processor for its client). Activities: use of the Feedloom Service.
- Data importer: Sprout LLC, 299 NW 46th St, Boca Raton, FL 33431, USA. Contact: facundomartin@sproutco.io. Role: processor (or subprocessor). Activities: providing the Feedloom Service.
B. Description of the processing
| Item | Description |
|---|---|
| Categories of data subjects | (1) Persons who appear in or are named in Customer's content (photos, posts, sources), for example Customer's staff, customers or clients. (2) Owners and managers of the social accounts that Customer connects. (3) Customer's clients and other reviewers who receive approval links. |
| Categories of personal data | (1) Content: images and photos, names, text, quotes, links and other data in brand kits, sources, prompts, planner conversations, posts and renders. (2) Connected-account data: account and profile IDs, names, handles, profile pictures, connection status, publication results. Access tokens are held by the publishing provider (Annex III), not in Sprout's database. (3) Reviewer data: names and email addresses of reviewers, approval decisions and timestamps. |
| Special categories | None intended. |
| Frequency | Continuous, while the Service is used. |
| Nature of the processing | Collection (including crawling of sources that Customer connects), storage, analysis with AI, rendering, display, transmission to the publishing provider and to the social networks selected by Customer, download and deletion. |
| Purpose (business purpose) | To provide the Service to Customer: plan, create, render, review, schedule and publish posts; manage connected accounts; secure the Service. |
| Retention | Until Customer deletes the content or its account, then deletion within 30 days (section 10). AI requests are not stored by Sprout beyond the resulting proposal; the AI provider's retention is in Annex III. |
| Subprocessor transfers | As listed in Annex III, for the same purposes and durations. |
C. Competent supervisory authority: as determined by Clause 13 of the SCCs.
Annex II — Technical and organizational security measures
- Encryption in transit: HTTPS/TLS for all public endpoints, HSTS in production. Media at our storage provider is encrypted at rest by the provider.
- Private media storage: stored objects are private, scoped per organization and served only through short-lived signed links (5 minutes) after an access check; uploads are type-checked by content (no SVG) and size-limited; integrity is checked with SHA-256 digests.
- Access control: deny-by-default authorization for every action; strict tenant isolation in the database layer with automated isolation tests; roles inside each organization; administrator access limited to named staff, with a reason, a visible banner and an audit record for impersonation.
- Authentication: single-use sign-in links that expire in 15 minutes, bcrypt password hashes with a 12-character minimum, rate limits, session list with revoke, re-authentication for sensitive changes, signed and encrypted session cookies.
- AI safeguards: AI output cannot select an organization, approve a batch or trigger publication; publication uses only approved revisions; per-organization AI budgets and limits.
- Audit: append-only audit log during its retention period. The database rejects changes and ordinary deletions; a controlled retention job deletes entries after 24 months unless a legal or security hold applies.
- Network and infrastructure: application and database on a private network; the database port is not exposed to the internet; Cloudflare network protection; signed and verified webhooks.
- Application security: content security policy with per-request nonces, CSRF protection, secure headers, input validation; automated dependency audits and static security analysis in every release.
- Secrets: credentials kept only in the deployment environment, never in source code; social-account access tokens are not stored in Sprout's database.
- Resilience: regular database backups; monitoring of health endpoints.
- Personnel: confidentiality duties; access only when needed.
- Incident response: documented process to assess, contain and notify Personal Data Breaches (section 9).
- Deletion: deletion of content and stored files after Customer's deletion or account closure (section 10).
Annex III — Subprocessors (as of 1 October 2026)
| Subprocessor | Service | Data | Location | Transfer safeguard | Status |
|---|---|---|---|---|---|
| DigitalOcean, LLC | Hosting of application, database and local media storage | All Customer Personal Data | USA (New York, NYC3) | Onward-transfer contract (SCCs Clause 8.8); DPF where certified | Active |
| Cloudflare, Inc. | DNS, network and security; Browser Run (rendering of images in a remote browser); R2 object storage for media | Content in transit and in rendering; stored images and photos | Global network; company in USA | Onward-transfer contract (SCCs Clause 8.8); DPF where certified | Network and rendering: active. R2 storage: not active on 1 October 2026; covered by this notice |
| ZERNIO SOFTWARE SL (Zernio) | Connection of social accounts and publishing of posts; holds access tokens for connected accounts | Connected-account data, access tokens, posts and media to publish | Spain (provider); international subprocessors as described in its Trust Center | Onward-transfer contract (SCCs Clause 8.8) | Active when Customer connects an account |
| Postmark (ActiveCampaign, LLC) | Transactional email (for example approval-link and reconnect notices) | Email addresses, names, message content | USA | Onward-transfer contract (SCCs Clause 8.8); DPF where certified | Active |
| OpenAI, L.L.C. | AI planning and text generation in the Feedloom planner | Sources, brand data, prompts and posts sent with each request; requests sent with storage turned off; not used for training under OpenAI's API terms | USA | Onward-transfer contract (SCCs Clause 8.8); DPF where certified | Not active on 1 October 2026; covered by this notice |
Stripe processes payment data of Customer's own account as a separate service; it does not process Customer Personal Data under this DPA. Social networks and AI assistants connected by Customer are not Subprocessors (section 2.4).