Data Processing Agreement
Version 1.0 · Last updated: 25 September 2026
0. Framework and acceptance
0.1. This Data Processing Agreement (“DPA”) forms an integral part of the Strike.os Terms and Conditions (“Terms”) and governs the processing of personal data that Strike.os carries out on behalf of the Agency in the course of providing the service.
0.2. The DPA is entered into between the Agency — the organisation that creates the account and subscribes to the service — and Strike.os, operated by Hugo Aires Fangueiro Marques, sole trader, NIF 263 395 081, with its place of business at Av. D. António Bento Martins Júnior, n.º 319, 3.º Esq., 4480-664 Vila do Conde, Portugal.
0.3. Acceptance takes place electronically, when the account is created, through the acceptance checkbox that names the Terms, the Privacy Policy and this DPA. Strike.os records the date, the time and the version of the DPA accepted. This record counts as the conclusion of the DPA in writing for the purposes of Article 28(9) GDPR.
0.4. Each version of the DPA has its own number and date. Changes are communicated to the Agency on the platform and by email at least 15 days in advance, and the new version is accepted at the next access to the platform. An Agency that does not accept may cancel its subscription under §12.
0.5. In matters of personal data protection, in the event of conflict between this DPA and the Terms, the DPA prevails.
1. Definitions
GDPR — Regulation (EU) 2016/679. The terms “controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given to them in the GDPR.
Agency Data — the personal data that the Agency uploads to the platform, or that the platform collects on the Agency's instructions, relating to the Agency's clients, to the teams of those clients, to the content it publishes and to the audience that interacts with the pages it manages. Annex 1 describes it.
Account Data — the personal data of the people who have an account on the platform (members of the Agency's team and clients of the Agency invited to the portal), to the extent necessary to create, authenticate and protect that account. It is governed by the Privacy Policy, not by this DPA.
Connected Services — the third-party services that the Agency connects to the platform with its own accounts (Meta, Google, the Agency's certified invoicing account). §8 deals with them.
Sub-processor — a third party engaged by Strike.os that processes Agency Data on behalf of the Agency. Annex 3 lists them.
2. Parties and roles
2.1. With regard to Agency Data, the Agency is the controller and Strike.os is the processor. The Agency determines the purposes and the means; Strike.os processes the data on the Agency's instructions.
2.2. With regard to Account Data, Strike.os is the controller as regards the creation, authentication, security and access logs of the account, and the processor as regards everything those people do with Agency Data within the platform.
2.3. With regard to Connected Services, each provider is an independent controller for its own platform. Strike.os accesses those services on behalf of the Agency, with the authorisation the Agency grants it, and solely as a technological channel for transmitting the Agency's instructions.
3. Subject matter, nature, purpose and duration
3.1. The subject matter, the nature and the purpose of the processing, the categories of personal data and the categories of data subjects are set out in Annex 1.
3.2. The processing lasts for as long as the Agency has an account on the platform, including the read-only period described in §12, and ends with the deletion of Agency Data under that section.
4. The Agency's instructions
4.1. Strike.os processes Agency Data only on documented instructions from the Agency, including with regard to transfers to third countries, unless Union or Member State law requires it to process them otherwise — in which case it informs the Agency beforehand, unless that law prohibits it.
4.2. The normal use of the platform's features by the Agency and its users constitutes the documented instruction. Instructions outside the platform are given in writing to hello@strike-os.com.
4.3. Strike.os immediately informs the Agency if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
4.4. Strike.os does not process Agency Data for its own purposes.
5. Confidentiality
5.1. The persons authorised by Strike.os to process Agency Data are bound by a duty of confidentiality. As at the date of this version, administrative access to the systems is exercised by a single person, the owner of Strike.os.
6. Security
6.1. Strike.os applies the technical and organisational measures described in Annex 2, appropriate to the risk in accordance with Article 32 GDPR.
6.2. Strike.os may update the measures in Annex 2, provided that the level of protection does not decrease. The version in force is published with this DPA.
7. Sub-processors
7.1. The Agency gives Strike.os a general authorisation to engage the Sub-processors listed in Annex 3, which is also published and maintained at strike-os.com/en/dpa.
7.2. Strike.os notifies the Agency, on the platform and by email, of any addition or replacement of a Sub-processor at least 15 days in advance, stating the name, the purpose, the location and the transfer mechanism where applicable.
7.3. The Agency may object, on reasoned grounds, within that period. If Strike.os cannot offer a reasonable technical alternative, the Agency has the right to cancel its subscription, with a pro rata refund for the period paid for and not used.
7.4. Strike.os enters into a written contract with each Sub-processor that imposes on it data protection obligations equivalent to those of this DPA, and is liable to the Agency for the performance of those obligations.
8. The Agency's Connected Services
8.1. The platform integrates third-party services — the Meta and Google pages and accounts, and the Agency's certified invoicing account — under the exclusive and direct authorisation of the Agency, given with its own accounts and revocable by it at any time.
8.2. In these integrations Strike.os acts solely as a technological channel for transmitting the Agency's instructions: it publishes, reads metrics, creates events or issues documents because the Agency asks it to, in the Agency's account. These services are not Sub-processors of Strike.os; they are governed by the terms and policies of each provider, which the Agency accepted when connecting them.
8.3. Strike.os stores the access credentials for these services encrypted at rest and uses them only for the operations the Agency instructs.
9. International transfers
9.1. The database, authentication and some older media files are hosted in the European Union (Ireland), by Supabase. The application server, which holds the remaining media files and the logs, is in the United Kingdom, a country covered by an adequacy decision of the European Commission. The backups of that server are stored by Hostinger separately from it, at a location the provider does not state (Annex 3).
9.2. Where a Sub-processor processes Agency Data outside the European Economic Area, the transfer relies on an adequacy decision of the European Commission — in particular the decision for the United Kingdom and, for certified entities, the decision on the EU-U.S. Data Privacy Framework — or on the standard contractual clauses adopted by the Commission, incorporated into the contract with that provider. Where the contracted provider is in the EEA and processing outside it is carried out by that provider's sub-processors, it is that provider that makes the transfer, on behalf of the Agency, and that must frame it within one of the mechanisms of Chapter V of the GDPR. Annex 3 states the mechanism for each one, where the provider's DPA states it, and any exceptions provided for in that DPA.
10. Assistance to the Agency
10.1. Strike.os assists the Agency, by appropriate technical and organisational measures, in fulfilling the obligation to respond to requests from data subjects (access, rectification, erasure, restriction, portability, objection), within 15 days of the Agency's request.
10.2. Strike.os assists the Agency, to the extent reasonable and within the limits of the information available to it, in complying with the obligations of security, of notification of personal data breaches and of data protection impact assessment.
10.3. If a data subject contacts Strike.os directly about Agency Data, Strike.os forwards the request to the Agency without responding to its substance.
10.4. The channel for these requests is hello@strike-os.com.
11. Personal data breach
11.1. Strike.os notifies the Agency of any personal data breach affecting Agency Data within 48 hours of becoming aware of it, to the account administrator's email address.
11.2. The notification describes, to the extent known at the time, the nature of the breach, the categories and approximate number of data subjects and of records concerned, the likely consequences and the measures taken or proposed — the content of Article 33(3) GDPR — and is updated as Strike.os learns more.
12. End of the contract, return and deletion
12.1. The contract ends upon cancellation of the subscription by the Agency, upon the end of the trial period without a subscription, upon non-payment that is not remedied, or upon termination under the Terms.
12.2. From the end of the contract, the account remains in read-only mode for 90 days. During that period the Agency may consult the data and request the full export of Agency Data, its erasure, or both.
12.3. The export is delivered in a structured, commonly used format — CSV and JSON files — together with the original media files.
12.4. The Agency may request export or erasure at any time, including while the contract is in force. In this version of the platform, export and erasure requests are carried out manually by Strike.os, within 15 days of the request.
12.5. Once the read-only period has ended, Strike.os permanently deletes Agency Data, except what Union or Member State law requires it to retain. Backups expire within their own window, of up to 21 days, after which the deleted data no longer exists in them either.
12.6. Erased data from Connected Services (Meta pages, Google calendars, documents in the Agency's invoicing account) continues to exist in those services; the Agency manages it there.
13. Audit
13.1. Strike.os makes available to the Agency the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, in the first instance by written response to a questionnaire.
13.2. The Agency, or an auditor mandated by it and bound by confidentiality, may carry out an audit once a year — or after a personal data breach, or where required by a supervisory authority — with at least 30 days' prior notice, at an agreed time, without disrupting the operation of the service, and bearing the costs of the audit.
13.3. With regard to Sub-processors, Strike.os makes available the independent audit reports and certifications they publish (for example, SOC 2), which the Agency accepts in place of a direct audit of those providers.
14. Obligations and warranties of the Agency
14.1. The Agency warrants that it has a lawful legal basis for all personal data it uploads to the platform or that the platform collects on the Agency's instructions — including content containing third-party data and the data coming from the Meta and Google accounts it connects — and that it complies with its duties to inform data subjects.
14.2. The Agency undertakes not to upload to the platform special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10).
14.3. The Agency is responsible for the lawfulness of the instructions it gives and for the user accounts it creates or invites.
15. Liability
15.1. Each party is liable for damage caused by processing that infringes the GDPR in accordance with Article 82.
15.2. As between the parties, the limitations and exclusions of liability in the Terms apply, including the carve-out for wilful misconduct or gross negligence, without prejudice to any contrary provision of the GDPR and of mandatory law.
16. Final provisions
16.1. This DPA is governed by Portuguese law. The competent court is the one established in the Terms.
16.2. If any clause is invalid, the remaining clauses remain in force, and the invalid clause is replaced by the one that comes closest to its purpose within the law.
16.3. Contact for all data protection matters: hello@strike-os.com.
Annex 1 — Details of the processing
Subject matter. The provision of the Strike.os platform to the Agency: client management, planning and publishing of social media content, approvals by clients, team calendar, performance reports and financial records.
Nature and operations. Collection (by upload by the Agency or by reading the accounts it connects), storage, organisation, structuring, consultation, generation of text from the data (captions, plans, reports), transmission to Connected Services on the Agency's instructions (publishing, reading metrics, calendar events, issuing documents), sending of emails on behalf of the Agency, export and erasure.
Purpose. Exclusively the performance of the operations necessary to manage the Agency's business, in accordance with the instructions given through normal use of the platform.
Duration. The term of the contract, plus the read-only period of 90 days and the backup window (§12).
Categories of personal data.
— Identification and contact data of the Agency's clients and of the teams of those clients: name, email, phone, role.
— Billing data of the Agency's clients: NIF, billing address, documents issued, payments and costs recorded — where the client is a natural person or a sole trader, this is personal data.
— Content uploaded or created on the platform that may contain personal data of third parties: texts, captions, images, videos, comments.
— Approvals in the portal: who approved or rejected what, when, and the comments left.
— Calendar events: titles, dates, participants.
— Identifiers, access credentials (encrypted) and metrics of the pages and accounts the Agency connects (Meta, Google), including comments and interactions from the audience.
— AI-generated text from the data above, at the Agency's request.
Categories of data subjects.
— Clients, current and prospective, of the Agency, and the people who represent them.
— People invited by the Agency to the approvals portal.
— Members of the Agency's team, as authors of content and of calendar events.
— The audience that interacts with the social media pages managed by the Agency.
Special categories. They are neither requested nor expected. The Agency undertakes not to upload them (§14.2).
Annex 2 — Technical and organisational measures
In force as at the date of this version. Nothing here is a promise: it is what exists.
Isolation per Agency. Every row in the database belongs to an Agency and access is enforced in the database itself (row-level security policies on all tables), not only in the application.
Encryption in transit. All communication with the platform and between the platform and the providers takes place over HTTPS/TLS.
Encryption at rest of credentials. Access tokens for Connected Services are stored encrypted with AES-256-GCM, with the key outside the database.
Authentication. Password with minimum requirements; two-factor authentication available for all accounts; sessions with expiry; invitations with explicit acceptance.
Administrative access. A single person with administrative access to the systems. Service keys only on the server, never in the browser.
Hosting. Database and authentication on AWS eu-west-1 (Ireland), operated by Supabase, which also stores some older media files; application server, the remaining media files and the logs in a Hostinger data centre in the United Kingdom (Manchester).
Backups. Automatic daily database backups by Supabase, with a retention window of 7 days; weekly backups of the application server by Hostinger, stored separately from the server, of which the two most recent are kept (the older one up to about two weeks old).
Logging and monitoring. Access and error logs on the server; service health checks; logging of payment and billing events.
Analytics without a trace on the device. Product analytics on the Agency's users writes neither cookies nor local storage and masks all text.
Development. Changes to the software only through review and controlled integration, with automated tests that verify, among other things, the isolation between Agencies.
Deletion. Documented process for export and erasure requests (§12), with a monthly check of accounts that have been read-only for more than 90 days.
Annex 3 — Sub-processors
List in force as at the date of this version. Also published at strike-os.com/en/dpa, with the history of changes.
Supabase. Entity: Supabase Pte. Ltd. (Singapore). Purpose: Database and authentication; some older media files, uploaded between February and July 2026. Location of processing: AWS eu-west-1, Ireland; remote access by the provider's staff from outside the EEA, for support and monitoring; the media files stored in Supabase pass through the provider's CDN, cached on servers around the world. Transfer mechanism: Data hosted in the EU; standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3), incorporated into the provider's DPA, for the transfer to Supabase Pte. Ltd. (Singapore) and access by its staff from outside the EEA (support and monitoring).
Hostinger. Entity: Hostinger International Ltd. (Cyprus). Purpose: Application server, media files, logs and server backups. Location of processing: United Kingdom (Manchester); backups are stored by the provider separately from the server, at a location it does not state. Transfer mechanism: Adequacy decision of the European Commission for the United Kingdom (Implementing Decision (EU) 2021/1772, as amended by Implementing Decision (EU) 2025/2574, valid until 27/12/2031); for anything the provider transfers to countries without an adequacy decision, the standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3) provided for in its DPA, except where the transfer relies on another ground permitted by that DPA, such as necessity for the provision of the service or the customer's consent.
Anthropic. Entity: Anthropic Ireland, Limited (Ireland). Purpose: Text generation through the API, at the Agency's request — captions, plans and reports. Location of processing: USA and other countries outside the EEA, through the provider's sub-processors. Transfer mechanism: Strike.os contracts with an entity in the EEA, so there is no international transfer between them; processing outside the EEA is carried out by the provider's sub-processors, with whom it undertakes to conclude contracts imposing data protection obligations substantially as protective as those of its DPA, to the extent applicable to the services each provides (clause C.2); the provider's DPA does not state the Chapter V GDPR mechanism it uses for those transfers. It also incorporates, to the extent required, the standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3) and does not mention the EU-U.S. Data Privacy Framework. The data is not used to train models, under the commercial terms of the API.
Resend. Entity: Plus Five Five, Inc. (USA), trading as Resend. Purpose: Sending emails on behalf of the Agency: invitations, approvals, notices. Location of processing: USA. Transfer mechanism: EU-U.S. Data Privacy Framework (certified entity) and standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3), incorporated into the provider's DPA.
Not Sub-processors (and therefore not on this list): Meta and Google, which are the Agency's Connected Services (§8); the Agency's certified invoicing account (InvoiceXpress), which is contracted directly by the Agency (§8); and the providers that Strike.os uses for Account Data and for its own business — Stripe (subscription billing), InvoiceXpress (invoicing by Strike.os to the Agency) and PostHog (product analytics) — which are listed in the Privacy Policy.
Version history
1.0 — 25 September 2026 — first published version.