Data Processing Agreement

Last updated: June 2026 Version 10.0

This Data Processing Agreement forms part of the agreement under which Content Swarm Limited provides the Content Swarm service to a customer. It applies where Content Swarm processes personal data on the customer’s behalf.

The customer is the Controller. Content Swarm Limited is the Processor.

This DPA is incorporated into the Content Swarm Terms and Conditions and is accepted when a customer creates an account or signs an order form. A countersigned copy is available on request from support@contentswarm.io.

1. Definitions and applicable law

Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Process and Supervisory Authority have the meanings given in applicable data protection law.

Applicable data protection law means the UK GDPR, the Data Protection Act 2018, and where relevant the EU GDPR and member state law.

Customer Personal Data means personal data that Content Swarm processes on the customer’s behalf under the agreement.

2. Scope and instructions

Content Swarm will process Customer Personal Data only to provide the LinkedIn engagement and content coordination service, including the web application, Chrome extension, AI features, support and security functions described in the agreement, and only on the customer’s documented instructions.

This DPA, the agreement, and the customer’s use of the service constitute the customer’s documented instructions. This includes the transmission of customer supplied content to our AI provider as described in Annex 1.

If law requires Content Swarm to process Customer Personal Data other than on the customer’s instructions, Content Swarm will inform the customer before processing unless the law prohibits that notice.

Content Swarm will promptly inform the customer if, in its opinion, an instruction infringes applicable data protection law.

3. Content Swarm as controller

Content Swarm acts as an independent controller, not as a processor, for a limited set of processing carried out for its own business purposes. This includes account administration and billing, service security and abuse prevention, aggregated product analytics, and meeting its own legal obligations.

That processing is described in the Content Swarm Privacy Policy.

4. Confidentiality

Content Swarm will ensure that people authorised to process Customer Personal Data are bound by appropriate confidentiality obligations, and receive access only where needed for their role.

5. Security

Content Swarm will implement and maintain the technical and organisational measures set out in Annex 2, taking account of the state of the art, the nature, scope, context and purpose of processing, and the risks to Data Subjects, as required by Article 32 of the UK GDPR and EU GDPR.

Content Swarm may update these measures, provided the level of security is not materially reduced.

6. Subprocessors

The customer gives general authorisation for Content Swarm to appoint the subprocessors listed at contentswarm.io/subprocessors.

Content Swarm will give the customer at least 30 days’ notice, by email to subscribed customers and by updating that page, before a new or replacement subprocessor begins processing Customer Personal Data.

The customer may object on reasonable data protection grounds within that 30 day period. The parties will work in good faith to resolve the objection. If it cannot be resolved, the customer may terminate the affected part of the service without penalty and receive a pro rata refund of prepaid fees.

Content Swarm will impose data protection terms on each subprocessor that are no less protective than this DPA, and remains fully liable for each subprocessor’s performance of its data protection obligations.

7. Data Subject requests

Taking account of the nature of processing, Content Swarm will provide reasonable technical and organisational assistance to help the customer respond to Data Subject rights requests.

If Content Swarm receives a request relating to Customer Personal Data directly, it will not respond to it substantively, and will direct the requester to the customer, unless the customer has authorised it to respond.

8. Compliance assistance

Content Swarm will provide reasonable assistance to the customer with security of processing, breach notification, data protection impact assessments and prior consultation with a Supervisory Authority, taking account of the nature of processing and the information available to Content Swarm.

9. Personal Data Breaches

Content Swarm will notify the customer without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed.

Content Swarm will take reasonable steps to contain, investigate and remediate the breach, and will provide the further information the customer reasonably needs to meet its own notification obligations.

10. International transfers

The Content Swarm application, API and database are hosted on Amazon Web Services in the US East (Ohio) region. Customer Personal Data is therefore processed outside the United Kingdom and European Economic Area in the ordinary course of the service.

Where a restricted transfer occurs, the parties incorporate the European Commission Standard Contractual Clauses, Module Two (controller to processor), as completed in Annex 3. For UK restricted transfers, the UK International Data Transfer Addendum applies as completed in Annex 3.

The Standard Contractual Clauses and the UK Addendum prevail over any conflicting term in this DPA.

Transfer safeguards for each subprocessor are set out at contentswarm.io/subprocessors.

11. Audit and information

Content Swarm will make available the information reasonably necessary to demonstrate compliance with this DPA.

On at least 30 days’ written notice, and no more than once in any 12 month period, the customer or an independent auditor appointed by it may audit Content Swarm’s compliance. Additional audits may be carried out following a material Personal Data Breach or where a Supervisory Authority requires one.

Audits will take place during business hours, must not unreasonably disrupt Content Swarm’s business, must protect the confidentiality and security of other customers, are subject to confidentiality obligations, and will where possible first make use of available reports and written responses. The customer bears the cost of any on site audit.

12. Return and deletion

On termination or expiry of the agreement, Content Swarm will, at the customer’s choice, return or delete Customer Personal Data and existing copies, unless applicable law requires retention.

Unless the customer instructs otherwise:

  • Customer Personal Data remains available for export on request for 30 days after termination
  • Production data is deleted after that export window
  • Backup copies are put beyond ordinary use and deleted as the backup cycle expires
  • Written confirmation of what has been deleted is provided on request

Content Swarm may retain Customer Personal Data where applicable law requires it, and may retain limited records for security, audit and the establishment or defence of legal claims. Any data retained is protected in accordance with this DPA and deleted once the retention purpose has been met.

Content published to LinkedIn at the customer’s direction resides on LinkedIn’s platform and is outside Content Swarm’s control. Its removal is a matter for the customer and LinkedIn.

Full detail is at contentswarm.io/retention.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement.

14. Order of precedence and notices

If this DPA conflicts with the agreement in relation to the processing of Customer Personal Data, this DPA prevails. The Standard Contractual Clauses and UK Addendum prevail over both.

Notices under this DPA should be sent to support@contentswarm.io and to the customer contact named in the agreement.

Annex 1: Details of processing

Subject matter. Provision of the Content Swarm LinkedIn engagement and content coordination service, including the web application, Chrome extension, AI features, support and security.

Duration. The term of the customer agreement, plus the deletion period described in clause 12.

Nature and purpose. Collection, access, storage, organisation, structuring, use, generation, retrieval, transmission, analysis, support, security monitoring, export and deletion of data in order to provide the service the customer has directed.

Categories of Data Subject

  • Customer users, staff, contractors, administrators and invited team members
  • LinkedIn users whose public post or profile data the customer chooses to process
  • Customer prospects, contacts and content audiences, where included by the customer
  • Individuals who contact support or who appear in customer supplied content

Categories of Personal Data

  • Names, email addresses, account IDs, team membership and role information
  • LinkedIn identifiers, profile and account data, OAuth tokens and granted permissions
  • Post URLs and text, drafts, generated content, comments, shares, reactions and performance metrics
  • Usage events, logs, IP address, device, browser, session and support information

Special category and criminal offence data. These are not required for the service and must not be submitted unless the parties agree suitable instructions and safeguards in writing.

Frequency of transfer. Continuous, for the duration of the agreement.

Processing location. Amazon Web Services, US East (Ohio). Subprocessor locations are listed at contentswarm.io/subprocessors.

Annex 2: Technical and organisational measures

The measures described below are those Content Swarm has in place.

Authentication and access control

Content Swarm does not store user passwords. Authentication is delegated to LinkedIn, so identity verification, password policy and any multi factor authentication configured on the user’s LinkedIn account apply at sign in.

Application sessions use Secure and HttpOnly cookies with a maximum seven day lifetime. Cross site request forgery protection is enforced on state changing requests, with a restricted list of trusted origins that includes only Content Swarm domains, LinkedIn and the published Chrome extension identifier.

Production infrastructure access is restricted to named individuals on a least privilege basis.

Encryption

All Content Swarm service endpoints are served over HTTPS. Traffic between the browser, the Chrome extension and the API is encrypted in transit.

Application and network security

Debug mode is disabled in production. Permitted request origins and hosts are restricted to a defined list. Application level exception handling captures and reports errors without exposing internal detail to end users. The service runs on Amazon Web Services infrastructure, benefiting from AWS physical, environmental and network security controls.

Logging and monitoring

The application writes structured logs for its own components. Errors are captured, monitored and alerted through a third party error tracking service. An internal event record captures significant account and team changes, including additions and removals of team members.

Backups

Automated database backups are taken and retained by Amazon RDS in line with the configured backup retention period, and expire automatically.

Personnel

People with access to Customer Personal Data are bound by confidentiality obligations in their employment or contractor agreements, and receive access only where their role requires it.

Subprocessor management

All subprocessors are bound by data protection terms no less protective than this DPA. The current list is maintained at contentswarm.io/subprocessors, with 30 days’ notice of any change and a right to object.

Incident response

Content Swarm operates a process for detecting, containing, investigating and reporting security incidents, including notification to affected customers within the timeframe set out in clause 9.

Certification

Content Swarm does not currently hold an external security certification such as ISO 27001 or SOC 2, and no representation is made to that effect.

Annex 3: Standard Contractual Clauses and UK Addendum

Where a restricted transfer of Customer Personal Data takes place, the parties incorporate the following.

EU Standard Contractual Clauses

The European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA and completed as follows:

Data Processing Agreement table
ClauseSelection
Clause 7, docking clauseIncluded
Clause 9, subprocessorsOption 2, general written authorisation, with a notice period of 30 days as set out in clause 6 of this DPA
Clause 11, independent dispute resolutionNot included
Clause 17, governing lawThe law of Ireland
Clause 18(b), forum and jurisdictionThe courts of Ireland
Competent supervisory authorityThe supervisory authority of the EU member state in which the customer is established, or where the customer is not established in the EU, the Irish Data Protection Commission
  • Annex I.A, parties. Data exporter: the customer, acting as controller. Data importer: Content Swarm Limited, acting as processor, 727-729 High Road, London, England, N12 0BP, contact support@contentswarm.io.
  • Annex I.B, description of transfer. As set out in Annex 1 of this DPA.
  • Annex I.C, competent supervisory authority. As stated in the table above.
  • Annex II, technical and organisational measures. As set out in Annex 2 of this DPA.
  • Annex III, subprocessors. As published at contentswarm.io/subprocessors and updated in accordance with clause 6.

UK International Data Transfer Addendum

For transfers subject to UK data protection law, the parties incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, completed as follows:

Data Processing Agreement table
TableEntry
Table 1, partiesExporter: the customer. Importer: Content Swarm Limited. Details and contacts as in Annex I.A above. Start date: the effective date of the agreement
Table 2, selected SCCsThe EU Standard Contractual Clauses as incorporated and completed above, Module Two
Table 3, appendix informationAnnex 1A and 1B as in Annex I above. Annex II as in Annex 2 of this DPA. Annex III as published at contentswarm.io/subprocessors
Table 4, ending the AddendumNeither party may end the Addendum when the Approved Addendum changes

Where a conflict arises, the Standard Contractual Clauses and the UK Addendum prevail over the remainder of this DPA.

A countersigned copy of this DPA, including this annex, is available on request from support@contentswarm.io.

Content Swarm Limited, 727-729 High Road, London N12 0BP, United Kingdom. Contact support@contentswarm.io.