Ignix Data Processing Addendum

Last updated: June 24, 2026

This Data Processing Addendum ("DPA") forms part of the Ignix Terms of Service (the "Agreement") between Dreaming Solutions LLC ("Ignix", "we", "us") and the customer agreeing to it ("Customer", "you"). It applies where, and to the extent that, Ignix processes Customer Personal Data on your behalf in connection with your use of the Service. Capitalized terms not defined here have the meaning given in the Agreement.

If there is a conflict between this DPA and the rest of the Agreement regarding the processing of Customer Personal Data, this DPA controls.

1. Definitions

"Data Protection Laws" means the privacy and data-protection laws that apply to a party's processing of Customer Personal Data, including, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and U.S. state privacy laws.

"Customer Personal Data" means personal data within Customer Content that Ignix processes on your behalf.

"Controller", "Processor", "Data Subject", "Personal Data", and "Processing" have the meanings given in the applicable Data Protection Laws. "Subprocessor" means a third party engaged by Ignix to process Customer Personal Data.

2. Roles of the parties

For Customer Personal Data, you are the Controller (or a Processor acting for another controller) and Ignix is the Processor. You determine the purposes and means of processing; Ignix processes Customer Personal Data only as described in this DPA and on your documented instructions.

You are responsible for the lawfulness of the data you put into the Service, for having a valid legal basis, and for providing any required notices and obtaining any required consents from Data Subjects.

3. Scope of processing

The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.

4. Ignix's obligations

Ignix will:

  1. Process on instructions. Process Customer Personal Data only to provide and support the Service and on your documented instructions (including those given through the Service), unless required by law to do otherwise, in which case it will inform you where legally permitted.
  2. Confidentiality. Ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
  3. Security. Implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Annex B.
  4. Assist you. Taking into account the nature of the processing, provide reasonable assistance to help you respond to Data Subject requests and to meet your obligations regarding security, breach notification, data protection impact assessments, and consultation with authorities.
  5. Breach notification. Notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your notification obligations.
  6. Deletion or return. On termination of the Service, and at your choice, delete or return Customer Personal Data, except where retention is required by law. Routine deletion follows the retention practices described in our Privacy Policy.
  7. Records and audits. Make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice, no more than once per year unless required by a regulator or following a breach, and subject to confidentiality and to not unreasonably disrupting our operations.

5. Subprocessors

You authorize Ignix to engage Subprocessors to process Customer Personal Data. Our current Subprocessors are listed on our Subprocessor List. We will:

  • Impose on each Subprocessor data-protection obligations consistent with this DPA; and
  • Remain responsible for each Subprocessor's performance.

We will give you notice (for example, by updating the Subprocessor List or by email) before adding or replacing a Subprocessor. If you have a reasonable, data-protection-based objection to a new Subprocessor, you may notify us within the notice period; we will work with you in good faith to address it, and if we cannot, you may terminate the affected part of the Service.

6. International transfers

Where Ignix transfers Customer Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism recognized under Data Protection Laws, such as the EU Standard Contractual Clauses (and the UK Addendum and Swiss equivalents), which are incorporated into this DPA by reference and completed using the details in the Annexes.

7. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

8. Term

This DPA takes effect when you accept the Agreement and continues for as long as Ignix processes Customer Personal Data on your behalf.

Annex A — Details of processing

Subject matter: Ignix's provision of the Service to you.

Duration: For the term of the Agreement and until deletion or return of Customer Personal Data as described in this DPA.

Nature and purpose: Hosting, storing, transmitting, and otherwise processing Customer Content to provide social media scheduling and publishing, DM and comment automation, a unified inbox, analytics, and AI Features, across the social networks you connect.

Types of Personal Data: Depending on how you use the Service, this may include identifiers and contact details, social-media handles and profile information, the content of posts, comments, and direct messages, message metadata, audience and engagement data, and any other personal data you choose to include in Customer Content.

Categories of Data Subjects: Your Authorized Users, and the individuals whose information appears in Customer Content — such as your social-media audience, followers, and people who message or interact with the accounts you manage.

Annex B — Security measures

Ignix maintains technical and organizational measures appropriate to the risk, including:

  • Access controls limiting access to Customer Personal Data to authorized personnel on a need-to-know basis, with authentication and the principle of least privilege.
  • Encryption of data in transit and, where appropriate, at rest.
  • Network and infrastructure security, including measures to protect against unauthorized access, with primary hosting in the European Union.
  • Logging and monitoring to help detect and respond to security events.
  • Confidentiality obligations for personnel.
  • Procedures to identify, respond to, and remediate security incidents, and to restore availability of data.
  • Ongoing review of these measures, which may be updated provided the level of protection is not materially reduced.

Contact

For DPA requests or questions: [email protected].