GDPR & Data Protection
This page supplements the Poscally Privacy Policy and explains how Poscally approaches GDPR and related European privacy laws.
1. Who This Applies To
This page is particularly relevant to users in:
- European Economic Area
- United Kingdom
- Switzerland
- Other jurisdictions providing similar privacy rights
2. Data Controller
For personal information collected directly through Poscally, 23Labs generally acts as the data controller.
When Poscally processes information on behalf of a business or agency customer, that customer may act as the controller and Poscally may act as a processor.
3. Privacy by Design
Poscally aims to avoid collecting personal information that is unnecessary for providing the Service. Information is primarily processed to:
- Maintain and secure accounts
- Connect social media platforms
- Schedule and publish content
- Retrieve authorised social data
- Provide analytics
- Process subscriptions
- Provide support
- Improve the Service
4. Legal Bases
Performance of a Contract
Used where processing is necessary to provide Poscally — for example, account creation, social media connection, scheduling, publishing and workspace functionality.
Legitimate Interests
May apply to security, fraud prevention, service improvement, analytics, troubleshooting and customer support.
Consent
May apply to optional cookies, marketing communications, optional integrations and optional data processing activities. Users may withdraw consent where applicable.
Legal Obligation
Information may be processed where required by law, regulation or lawful legal process.
5. GDPR Rights
Where GDPR applies, users may have:
Right of Access
Request confirmation of whether Poscally processes personal information and obtain a copy.
Right to Rectification
Request correction of inaccurate information.
Right to Erasure
Request deletion of personal information where applicable.
Right to Restriction
Request temporary restriction of certain processing.
Right to Data Portability
Request certain information in a structured, commonly used machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing.
Right to Withdraw Consent
Withdraw consent where consent is the legal basis.
Right to Lodge a Complaint
Users may contact the relevant data protection authority in their country.
6. Exercising GDPR Rights
Requests should be sent to privacy@poscally.com.
Poscally may verify identity before processing a request. Requests will be handled within timeframes required by applicable law.
8. Account Deletion
Users may request deletion of their Poscally account. Some information may be retained where legally or operationally required for:
- Tax and accounting
- Fraud prevention
- Security
- Legal obligations
- Disputes
Published social media content may remain on connected social platforms. See Data Deletion.
9. International Transfers
Poscally may use providers located outside the EEA, UK or Switzerland. Where required, lawful transfer protections may include:
- Standard Contractual Clauses
- Adequacy decisions
- Other approved legal transfer mechanisms
10. Subprocessors
Current key service providers include:
- Vercel
- Supabase
- Stripe
- CookieYes
- Google Analytics
- Meta
A dedicated Subprocessors page may be added as Poscally's infrastructure expands.
11. Data Processing Agreements
Business or agency customers requiring a Data Processing Agreement should contact privacy@poscally.com.
13. Contact
Poscally
A product of 23Labs
Victoria, Australia
Related: Privacy Policy, Cookie Policy, Data Deletion.
7. Social Media Data
When a user connects a social network, Poscally processes information according to the permissions approved by the user. Users may disconnect integrations through Poscally or revoke access directly through the relevant social network.