Data Processing Agreement

Last updated: August 24, 2026

This Data Processing Agreement (the "DPA") is entered into under Art. 28(3) GDPR between you, the customer using Laetium (the "Controller"), and Ridoco, KvK 95439609, the Netherlands, trading as Laetium (the "Processor"). It forms part of, and is incorporated into, the Terms of Service. By using the Service you accept this DPA. No signature is required. A countersigned copy is available on request, see section 12.

1. Scope and Roles

This DPA applies only to Customer Personal Data, meaning personal data that you bring into the Service or that the Service retrieves from your connected accounts on your instruction. For that data you are the Controller and Ridoco is the Processor.

This DPA does not apply to data for which Ridoco is itself the controller, such as your account details, billing records and support correspondence. That data is governed by the Privacy Policy.

Where you are yourself acting as a processor for a third party, for example an agency managing a client account, Ridoco acts as a sub-processor and this DPA applies accordingly.

2. Details of the Processing (Art. 28(3))

Subject matter. Provision of the Laetium social media management Service.

Duration. For as long as your account is active, plus the retention periods set out in section 9.

Nature and purpose. Storage, retrieval, scheduling, publication, aggregation and display of social media content and metrics on your instruction.

Categories of data subjects. Your own personnel and authorised workspace members; the holders of the social accounts you connect; people who interact with those accounts, including followers, commenters and senders of direct messages; and the account holders you track as competitors.

Types of personal data. Account handles, display names, avatars and profile URLs; OAuth access and refresh tokens; post and caption content; uploaded media; direct message content received through the social inbox; engagement, audience and demographic metrics returned by the platforms; link click records; and advertising campaign metrics where you connect an ad account.

Special categories. The Service is not designed to process special categories of personal data under Art. 9 GDPR, and you must not deliberately use it for that purpose. You acknowledge that free text fields, uploaded media and inbound direct messages may incidentally contain such data, and that you remain the Controller for it.

3. Ridoco Obligations as Processor

  • Documented instructions. Ridoco processes Customer Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by EU or Member State law. Your use of the Service, and the configuration you set in it, constitute your instructions. If Ridoco is required by law to process beyond your instructions you are told first, unless that law forbids it.
  • Unlawful instructions. Ridoco will tell you if, in its view, an instruction infringes the GDPR or other EU or Member State data protection law, and may suspend that instruction until it is confirmed or changed.
  • Confidentiality. Every person authorised to process Customer Personal Data is bound by a duty of confidentiality that survives the end of their engagement.
  • Security. Ridoco implements the technical and organisational measures described in section 7, in accordance with Art. 32 GDPR.
  • Assistance. Ridoco assists you, taking into account the nature of the processing and the information available to it, in meeting your obligations under Arts. 32 to 36 GDPR, including security, breach notification, data protection impact assessments and prior consultation.

4. Sub-processors

You give general written authorisation for Ridoco to engage sub-processors. The current sub-processors are:

Sub-processorPurposeLocation
netcup GmbH, and the Anexia group companies it relies onServer hosting, databases, backupsGermany, Austria (EU)
Cloudflare (R2)Storage of media awaiting publicationEU jurisdiction bucket, provider US-based
Google (Workspace SMTP)Transactional email deliveryEU and United States
SentryError and crash reportingEU and United States
StripeCard payments and subscription billing (controller data, listed for completeness)EU and United States
PayPalPayment where you choose PayPal instead of a card (controller data, listed for completeness)EU and United States

The social media platforms you connect are not Ridoco sub-processors. When Ridoco publishes or retrieves on your behalf it acts on your instruction, and each platform is an independent controller for what it then does with that data under its own terms.

Ridoco will give you at least 14 days notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If Ridoco cannot resolve your objection you may terminate the affected part of the Service and receive a pro rata refund of prepaid fees. Ridoco imposes data protection obligations on every sub-processor that are no less protective than those in this DPA, and remains fully liable to you for their performance.

5. International Transfers

Customer Personal Data is stored on servers in the European Union. Where a sub-processor transfers data outside the EEA, that transfer relies on the EU to US Data Privacy Framework where the sub-processor is certified under it, or on the European Commission Standard Contractual Clauses together with supplementary technical measures including encryption in transit and encryption of tokens at rest. Copies of the relevant safeguards are available on request.

6. Data Subject Requests

Taking into account the nature of the processing, Ridoco assists you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests under Chapter III GDPR. The dashboard export and deletion tools cover most requests without Ridoco involvement.

If a data subject contacts Ridoco directly about Customer Personal Data, Ridoco will not respond substantively, and will refer them to you and forward the request without undue delay.

7. Security Measures (Art. 32)

  • TLS encryption for all data in transit
  • AES-256 encryption of OAuth access and refresh tokens at rest
  • Bcrypt password hashing
  • Workspace-level logical separation, so one customer cannot reach another customer data
  • Role-based access control within workspaces, with an audit log of sensitive operations
  • Rate limiting against brute force and enumeration
  • Access to production data limited to the operator of the Service, under a confidentiality obligation
  • Encrypted, access-controlled backups held within the EU
  • Ongoing dependency and vulnerability monitoring, with patches applied as released

Ridoco may update these measures over time. The overall level of security will not be reduced below what is described here.

8. Personal Data Breach

Ridoco will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event in time for you to meet your own 72 hour obligation under Art. 33 GDPR. The notification will describe the nature of the breach, the likely consequences, the measures taken, and a contact point for further information, to the extent that information is available to Ridoco.

9. Deletion and Return

On termination of your account, or at any time on your written request, Ridoco will delete or return all Customer Personal Data at your choice, and delete existing copies, unless EU or Member State law requires further storage.

In practice: account deletion is confirmed by a link emailed to you, and that link is valid for 7 days. Opening it applies the deletion at once, in one transaction. Sessions and API keys are destroyed, workspace memberships are dropped, and the identifying fields on the account are erased. There is no recovery window afterwards and Ridoco cannot restore the account, so export first if you want to keep anything. OAuth tokens are deleted immediately on disconnection or account deletion. Residual copies in encrypted backups are overwritten on the normal backup rotation and in any event within 35 days. Billing records are retained for 7 years as Netherlands tax law requires, and those are controller data, not Customer Personal Data.

10. Audit and Information Rights

Ridoco will make available to you all information necessary to demonstrate compliance with Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance Ridoco will respond to a reasonable written information request within 30 days. If that does not satisfy your obligations, you may carry out an on-site or remote audit no more than once in any 12 month period, on 30 days notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own audit costs and those of Ridoco, unless the audit uncovers a material breach of this DPA by Ridoco. Ridoco may satisfy an audit request by providing a current third-party certification or report where one covers the scope in question. Additional audits may be carried out where a supervisory authority requires them or following a personal data breach affecting your data.

11. Term, Liability and Law

This DPA takes effect when you first use the Service and continues for as long as Ridoco processes Customer Personal Data for you.

Each party is liable for its own compliance with the GDPR. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by applicable data protection law. Nothing in this DPA limits a data subject rights under Art. 82 GDPR.

Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails. This DPA is governed by the law of the Netherlands, and the courts of the Netherlands have jurisdiction.

12. Contact

Ridoco, trading as Laetium
De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands
KvK 95439609 · BTW NL005153257B49
Email: privacylaetium@doombringerz.com

For a countersigned copy of this DPA, email the address above with your legal entity name and registered address.