Standard UK/EU Data Processing Addendum (version 1.0)

Last updated 28 February 2026

This version is the standard DPA incorporated into the Terms of Service where it applies. A countersigned copy is available on request at support@socialfetch.dev.

Download the versioned plain-text copy or print this page and choose “Save as PDF”.

1. Parties, status, and scope

This Data Processing Addendum (“DPA”) is between Social Freak Ltd, company number 14659411, of Unit 82A, James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, United Kingdom (“Social Fetch”), and the customer that has accepted the Social Fetch Terms of Service (“Customer”). It forms part of the Terms and applies where Social Fetch processes Customer Personal Data as a processor in providing the Services.

For Customer Personal Data in customer-instructed API requests, target parameters, retrieved results, and related hosted media, Customer is the controller (or a processor acting for another controller) and Social Fetch is Customer’s processor (or subprocessor). Social Fetch is an independent controller for account administration, billing, fraud and abuse prevention, service security, legal compliance, and management of the direct customer relationship. This DPA does not govern that independent-controller processing, which is addressed by the Privacy Policy.

If Customer acts as a processor, Customer confirms that its instructions and appointment of Social Fetch as subprocessor are authorised by the relevant controller, and references to “controller” duties in this DPA apply to Customer as appropriate.

2. Definitions and interpretation

“Applicable Data Protection Law” means the UK GDPR, Data Protection Act 2018, EU GDPR, and other data-protection law applicable to the processing. “Customer Personal Data” means personal data processed by Social Fetch on Customer’s behalf through the Services. “Personal Data Breach” means a personal data breach affecting Customer Personal Data. “Data Subject”, “personal data”, “personal data breach”, “processing”, “processor”, and “supervisory authority” have the meanings given by Applicable Data Protection Law.

Capitalised terms not defined here have the meaning in the Terms. References to written instructions include Customer’s configuration and lawful use of the Services, this DPA, the Terms, and documented support instructions accepted by Social Fetch.

3. Customer instructions and responsibilities

Social Fetch will process Customer Personal Data only on Customer’s documented instructions, including to provide, secure, support, and maintain the reliability of the Services, unless UK law, Union law, or the law of an applicable EU Member State requires other processing. If that law permits, Social Fetch will inform Customer before the legally required processing.

Social Fetch will immediately inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Social Fetch may suspend the affected processing while the parties address the instruction.

Customer determines whether and how to use the Services and is responsible for the lawfulness, fairness, transparency, purpose limitation, data minimisation, notices, permissions, and legal basis for its collection and use of public-platform data. Customer will not intentionally submit or target sensitive or special-category data unless expressly agreed in writing with appropriate safeguards; Customer acknowledges that requested public results may incidentally contain such data.

4. Confidentiality and personnel

Social Fetch will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality, receive access only as operationally necessary, and are informed of relevant security and data-protection responsibilities.

5. Security

Taking account of the state of the art, implementation cost, and the nature, scope, context and purposes of processing and risks to individuals, Social Fetch will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Current measures are described in Schedule 2 and the Security page.

Customer is responsible for securely configuring and using the Services, protecting its credentials, limiting the personal data it submits, and downloading outputs it needs to retain. No system is completely secure; the measures are commitments to risk-appropriate safeguards, not a warranty that incidents cannot occur.

6. Subprocessors

Customer gives Social Fetch general written authorisation to engage subprocessors as reasonably necessary to provide, secure, and support the Services. The public Service Provider Register identifies certain material providers for transparency but is not exhaustive and is not the source or limit of this authorisation.

We intend to give customers at least 30 days’ advance notice of a new subprocessor that will process customer personal data where practicable. We may make an urgent change sooner where reasonably necessary for security, service continuity, or legal compliance, and will give notice without undue delay. Customers may raise a reasonable, documented data-protection objection at support@socialfetch.dev during the notice period.

If Customer objects on reasonable data-protection grounds, the parties will work in good faith on a commercially reasonable solution. If no solution is reasonably available, Social Fetch may stop the affected feature or Customer may terminate the affected Services before the new provider begins processing; Customer’s sole remedy for the unresolved objection is termination and a pro-rata refund of prepaid fees for the terminated, unused period, excluding consumed credits.

Social Fetch will impose by written contract on each subprocessor the same data-protection obligations applicable to that subprocessor’s processing under this DPA, including sufficient guarantees to implement appropriate technical and organisational measures. Social Fetch remains fully liable to Customer for each subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law.

On reasonable request, Social Fetch will provide additional information reasonably necessary for Customer’s data-protection diligence where legally permitted and subject to applicable confidentiality and contractual restrictions.

7. International transfers

Social Fetch is established in the United Kingdom. Transfers of personal data from the EEA to Social Fetch in the UK may rely on the European Commission’s UK adequacy decision while it remains in force (currently renewed through 27 December 2031).

EEA-to-UK adequacy does not cover every onward transfer. For an onward transfer restricted by EU GDPR, Social Fetch will use the lawful EU mechanism applicable to that transfer, which may include an adequacy decision or the European Commission standard contractual clauses. For a transfer restricted by UK GDPR, Social Fetch will use the lawful UK mechanism applicable to that transfer, which may include UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum. Supplementary measures will be used where required. Customer may request information about the mechanism applicable to its processing, where legally permitted and subject to applicable confidentiality and contractual restrictions; this DPA does not assert that one mechanism applies to every provider or service configuration.

If a transfer mechanism used for Customer Personal Data becomes invalid, the parties will cooperate in good faith to implement a valid replacement. Where legally required and not otherwise covered, the parties will enter the then-current approved transfer terms.

8. Data-subject requests

Taking account of the nature of processing, Social Fetch will provide reasonable assistance through appropriate technical and organisational measures for Customer to respond to requests to exercise data-subject rights. If Social Fetch receives a request relating to Customer Personal Data, it will, where legally permitted, direct the requester to Customer and not respond substantively except on Customer’s documented instruction or as required by law.

Customer should use available self-service controls first. Additional assistance that requires material bespoke work may be charged at reasonable rates agreed in advance, unless the work is required because Social Fetch breached this DPA.

9. Personal data breaches

We notify affected customers without undue delay and, where feasible, within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, providing available information in phases where necessary.

Notice will include, as information becomes available: the nature of the breach; affected data and data-subject categories and approximate numbers where known; likely consequences; measures taken or proposed; and a contact point. Social Fetch may provide information in phases and will take reasonable steps to contain, investigate, mitigate, and remediate the breach.

Social Fetch’s notice or response is not an admission of fault or liability. Customer is responsible for its own regulatory and data-subject notifications. Social Fetch will reasonably assist Customer with those duties, taking account of the nature of processing and information available to Social Fetch.

10. Compliance assistance and records

Taking account of the nature of processing and information available, Social Fetch will provide reasonable assistance with Customer’s security obligations, breach notifications, data-protection impact assessments, and prior consultations with supervisory authorities under Articles 32–36 UK GDPR or EU GDPR.

Social Fetch will maintain records and information required of it as processor and will make information reasonably necessary to demonstrate compliance with this DPA available under the audit framework below.

11. Return and deletion

During the Services, Customer may retrieve API results at request time and should export data it wishes to retain. At Customer’s choice, on termination of the affected Services Social Fetch will delete or return all Customer Personal Data and delete existing copies, unless UK law, Union law, or the law of an applicable EU Member State requires retention. Social Fetch will also honour documented deletion or return requests during the Services where technically and legally practicable. Data in backups or standard deletion cycles will remain protected under this DPA, isolated from ordinary use, and deleted when the applicable cycle expires unless law requires retention.

Standard API request-log fields are retained for approximately 30 days. Under zero retention, live upstream processing still occurs but request parameters, target URLs, and response previews are not durably stored; minimal operational, billing, security, and reliability metadata remains. Hosted screenshots and similar artifacts are retained for approximately 7 days, while explicitly opted-in hosted social-media originals are retained for approximately 90 days. Legal holds, fraud evidence, and records Social Fetch processes as an independent controller may be retained as required for their separate purposes.

12. Audits

On reasonable written request no more than once in any 12-month period, Social Fetch will provide all information reasonably necessary to demonstrate compliance, such as current security documentation, relevant policies, and available independent reports or questionnaire responses. The frequency limit does not apply following a Personal Data Breach materially affecting Customer Personal Data, where Customer has reasonable documented grounds to suspect material non-compliance, or where a supervisory authority requires more frequent review.

If that information is insufficient, Customer may request a remote audit and, only where reasonably necessary, an on-site audit by Customer or an independent auditor that is not a competitor. Audits require at least 30 days’ notice where practicable, must occur during normal business hours, avoid unreasonable disruption, protect other customers’ data and Social Fetch confidential information, and be scoped to processing under this DPA.

Customer bears its audit costs and will reimburse Social Fetch’s reasonable costs for bespoke assistance, agreed in advance, unless the audit identifies a material breach by Social Fetch. Nothing requires disclosure of penetration-test details, credentials, source code, or information that would compromise security or another customer’s rights; Social Fetch may provide a suitable redacted or alternative form.

13. Duration, liability, and precedence

This DPA begins when Customer accepts the Terms that incorporate it or otherwise agrees to it in writing, and continues while Social Fetch processes Customer Personal Data. The limitations and exclusions of liability in the Terms apply to this DPA to the fullest extent permitted by law and, together with claims under the Terms, form one aggregate liability cap. Nothing in the Terms or this DPA limits data-subject rights, regulatory powers, or liability that cannot lawfully be limited.

If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. Applicable approved transfer terms control over this DPA only to the extent of a conflict concerning the restricted transfer they govern. The rest of the Terms remains unchanged.

14. Changes and execution

Social Fetch may update this DPA to reflect law, guidance, or the Services. It will identify the version and date and give reasonable advance notice of material changes. A change that materially reduces Customer’s data-protection rights will take effect for an existing paid term only with Customer’s express agreement or where reasonably necessary to comply with law or address an urgent security risk; an urgent change will be notified without undue delay.

The version published at /dpa when Customer accepts the Terms is incorporated into the Terms where the DPA applies, subject to updates made under the preceding paragraph. The downloadable copy at /dpa.txt contains the same versioned title, date, sections, paragraphs, and schedules as the web DPA and is provided for records and printing. Electronic acceptance of the Terms also accepts this DPA; no separate signature is required. Either party may request a countersigned copy by emailing support@socialfetch.dev. A countersigned copy records acceptance but does not amend the agreed terms unless both parties expressly agree in writing.

Schedule 1 — Processing details

Subject matter and purpose: providing, securing, supporting, metering, and troubleshooting customer-instructed Social Fetch API retrieval, transformation, AI-assisted web answering, delivery, monitoring, and optional media-hosting functions.

  • Duration: for the customer relationship and the shorter retention periods described in this DPA, subject to deletion cycles and legal retention.
  • Nature of processing: receiving instructions and target parameters; transmitting requests to upstream and infrastructure providers; retrieving, normalising, transiently caching, displaying, delivering, logging, deleting, and, where selected, hosting outputs.
  • Personal-data categories: public profile and account identifiers, handles, names, biography and profile fields, public posts and media, comments, audience and engagement data, public advertising or marketplace data, public contact or professional information, target URLs and search terms, and request/network metadata.
  • Data-subject categories: users and creators of public social or web platforms; people appearing in public posts, comments, media, advertising, marketplace, professional, or other requested public content; Customer’s end users where Customer includes their data in an instruction.
  • Frequency: on demand or on Customer-configured monitoring schedules.
  • Controller instructions: the Terms, this DPA, endpoint documentation, Customer’s API requests and settings, and documented support instructions accepted by Social Fetch.

Schedule 2 — Technical and organisational measures

Measures are risk-based and may evolve without materially reducing overall protection. Current measures include:

  • TLS for data in transit to public websites, dashboard, and API, and provider-managed encryption at rest for managed database and object storage.
  • API keys stored in hashed form and displayed in full only on creation; optional two-factor authentication; user-controlled key rotation and revocation.
  • Role- and operational-need-based production access, confidentiality duties, secrets held in environment configuration, and access review as roles change.
  • Structured request correlation using request IDs, restricted production log levels, error monitoring, provider-health monitoring, and incident investigation procedures.
  • Data minimisation through zero-retention controls, limited response previews under standard retention, defined log and media deletion periods, and analytics property filtering.
  • Managed infrastructure, queue-based retry and idempotency controls, rate/abuse controls, backups and provider resilience appropriate to the service, and change review through source control and automated testing.
  • Incident containment, evidence preservation, risk assessment, customer-notification workflow, post-incident review, and remediation tracking.

Schedule 3 — Subprocessors and transfer information

The public Service Provider Register at /subprocessors identifies certain material providers for transparency. It is non-exhaustive, does not disclose confidential supply arrangements, and is not incorporated as a complete list of subprocessors. Section 6 governs Customer’s general authorisation, change notice, objection rights, and requests for additional diligence information.

Related documents

Service Provider Register · Privacy Policy · Security