Legal

Data Processing Agreement

This Art. 28 GDPR agreement applies when you use POSTHIVE as a business to store or process personal data in a workspace — footage, comments, reviewer names, scripts, and similar customer content.

Last updated: August 2026

01 / Roles

Controller and processor

You (the workspace customer) are the controller for personal data you and your team put into POSTHIVE. Dignified Media GmbH is the processor for that workspace content.

Dignified Media GmbH remains the controller for account, billing, security logs, and — only with consent — analytics, as described in the Privacy Policy.

Processor:

Dignified Media GmbH
Herzogstandstr. 6
83673 Bichl
Germany
Phone: +49 160 6271848
Email: lorenz@dignified.media

02 / Scope

Subject matter and instructions

The processor hosts, transcodes, transmits, backs up, and displays workspace content, and — when you use those features — sends it to subprocessors for transcription, translation, search, or assistants. Duration: the contract term plus backup expiry.

The processor processes data only on documented instructions: these Terms, this DPA, and in-product actions you take (upload, share a review link, run a transcript). Unlawful instructions may be refused.

03 / Safeguards

Security and staff

The processor applies technical and organisational measures appropriate to a media workspace: access control, encryption in transit, hashed passwords, and scoped review links. Persons authorised to process data are bound to confidentiality.

After the end of processing the processor deletes or returns customer content when you delete a workspace or account, subject to rolling backups and statutory retention (for example invoices).

04 / Others

Subprocessors and transfers

You authorise the processors listed in the Privacy Policy, including Vercel, Supabase, Backblaze, Cloudflare, Bunny.net, Stripe, Resend, AssemblyAI, OpenAI, Google, Slack, Apple, PostHog, and Google Analytics (analytics only with end-user consent). Several are outside the EEA; transfers rely on adequacy decisions or EU Standard Contractual Clauses.

New subprocessors will be listed on that page before they process customer content. You may object on reasonable data-protection grounds within 14 days. If we cannot accommodate the objection, either party may terminate the affected service.

05 / Rights

Assistance and audits

The processor will assist with data-subject requests, security incidents, and DPIAs to the extent the information is available. A personal-data breach affecting customer content will be notified without undue delay.

You may audit the processor once per year (or after a breach) on reasonable notice, or accept a current third-party report (for example SOC 2 of a subprocessor) where that is sufficient. Audits must not disrupt operations or expose other customers.

Using POSTHIVE with a paid or free workspace constitutes acceptance of this DPA. Enterprise customers who need a signed copy should email lorenz@dignified.media.

Legal

Related documents

Terms of Service