01 / Roles
Controller and processor
You (the workspace customer) are the controller for personal data you and your team put into POSTHIVE. Dignified Media GmbH is the processor for that workspace content.
Dignified Media GmbH remains the controller for account, billing, security logs, and — only with consent — analytics, as described in the Privacy Policy.
Processor:
Dignified Media GmbH
Herzogstandstr. 6
83673 Bichl
Germany
Phone: +49 160 6271848
Email: lorenz@dignified.media
02 / Scope
Subject matter and instructions
The processor hosts, transcodes, transmits, backs up, and displays workspace content, and — when you use those features — sends it to subprocessors for transcription, translation, search, or assistants. Duration: the contract term plus backup expiry.
The processor processes data only on documented instructions: these Terms, this DPA, and in-product actions you take (upload, share a review link, run a transcript). Unlawful instructions may be refused.
03 / Safeguards
Security and staff
The processor applies technical and organisational measures appropriate to a media workspace: access control, encryption in transit, hashed passwords, and scoped review links. Persons authorised to process data are bound to confidentiality.
After the end of processing the processor deletes or returns customer content when you delete a workspace or account, subject to rolling backups and statutory retention (for example invoices).
04 / Others
Subprocessors and transfers
You authorise the processors listed in the Privacy Policy, including Vercel, Supabase, Backblaze, Cloudflare, Bunny.net, Stripe, Resend, AssemblyAI, OpenAI, Google, Slack, Apple, PostHog, and Google Analytics (analytics only with end-user consent). Several are outside the EEA; transfers rely on adequacy decisions or EU Standard Contractual Clauses.
New subprocessors will be listed on that page before they process customer content. You may object on reasonable data-protection grounds within 14 days. If we cannot accommodate the objection, either party may terminate the affected service.
05 / Rights
Assistance and audits
The processor will assist with data-subject requests, security incidents, and DPIAs to the extent the information is available. A personal-data breach affecting customer content will be notified without undue delay.
You may audit the processor once per year (or after a breach) on reasonable notice, or accept a current third-party report (for example SOC 2 of a subprocessor) where that is sufficient. Audits must not disrupt operations or expose other customers.
Using POSTHIVE with a paid or free workspace constitutes acceptance of this DPA. Enterprise customers who need a signed copy should email lorenz@dignified.media.