Data Processing Agreement

This Data Processing Agreement forms part of the agreement under which Content Swarm Limited provides the Content Swarm service to a customer. It applies where Content Swarm processes personal data on the customer's behalf. The customer is the Controller and Content Swarm Limited is the Processor.

1. Definitions and law

Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Process and Supervisory Authority have the meanings given in applicable data protection law. Applicable data protection law includes the UK GDPR, the Data Protection Act 2018, and, where relevant, the EU GDPR and member state law.

2. Scope and instructions

Content Swarm will process Customer Personal Data only to provide the LinkedIn engagement and content coordination software, Chrome extension, support, security, and related services described in the agreement, and on the customer's documented instructions. This DPA and use of the service are documented instructions.

If law requires other processing, Content Swarm will tell the customer before processing unless the law prohibits notice. Content Swarm will promptly tell the customer if, in its opinion, an instruction infringes applicable data protection law.

3. Confidentiality

Content Swarm will ensure that people authorised to process Customer Personal Data are bound by confidentiality duties and receive access only where needed for their role.

4. Security

Content Swarm will maintain appropriate technical and organisational measures taking account of the nature, scope, context, and purpose of processing and the risks to Data Subjects. Measures will address confidentiality, integrity, availability, resilience, restoration, and regular review as required by Article 32 of the UK GDPR and EU GDPR.

Current code evidence includes HTTPS service endpoints, secure and HttpOnly session cookies, CSRF controls, access controls, application logging, and error monitoring. This is not a complete security schedule.

The inspected materials do not provide a complete controls schedule covering access review, encryption at rest, key management, backups, recovery testing, vulnerability management, incident response, and staff controls.

5. Subprocessors

The customer gives general authorisation for Content Swarm to use the subprocessors on the live Subprocessor Information page. Content Swarm will impose data protection terms on each subprocessor that protect Customer Personal Data to the standard required by applicable law. Content Swarm remains responsible for a subprocessor's performance of its data protection duties.

This DPA does not set a fixed notice or objection period for new or replacement subprocessors.

6. Data Subject requests

Taking account of the nature of processing, Content Swarm will provide reasonable technical and organisational assistance so the customer can answer requests to exercise Data Subject rights. If Content Swarm receives a request relating to Customer Personal Data, it will direct the requester to the customer unless authorised to respond.

7. Compliance assistance

Content Swarm will provide reasonable assistance with security, breach notifications, data protection impact assessments, and prior consultation with a Supervisory Authority, taking account of the nature of processing and information available to Content Swarm.

8. Personal Data Breaches

Content Swarm will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. It will provide available details needed for the customer's notification duties and will take reasonable steps to contain, investigate, and remediate the breach.

9. International transfers

Content Swarm will not transfer Customer Personal Data outside the United Kingdom or European Economic Area without a lawful transfer mechanism. Where required, the parties incorporate the European Commission Standard Contractual Clauses, Module Two, for controller-to-processor transfers. For UK restricted transfers, the UK International Data Transfer Addendum to the EU clauses or the UK International Data Transfer Agreement will apply, as appropriate. The applicable clauses prevail over conflicting terms in this DPA.

Provider-specific processing locations and transfer safeguards are listed where available on the subprocessor page. Some are not documented in the inspected materials.

10. Audit and information

Content Swarm will provide information reasonably needed to demonstrate compliance with this DPA. On reasonable prior notice, it will allow one audit per year by the customer or an independent auditor, with additional audits after a material incident or where a Supervisory Authority requires one. Audits must protect other customers, security, and confidential information and should first use available reports and written evidence.

11. Return and deletion

At the end of the services, Content Swarm will, at the customer's choice, return or delete Customer Personal Data and existing copies, unless applicable law requires retention. Data in backups will be put beyond ordinary use and deleted in line with the backup cycle. The live Retention and Deletion page describes the current schedule and open operational periods.

The inspected materials do not state a fixed production deletion window, export format, backup cycle, or complete legal-retention schedule.

12. Processing details

Subject matter and duration

Processing needed to provide the Content Swarm LinkedIn engagement and content coordination service, web app, mobile apps, Chrome extension, AI features, support, and security for the term of the customer agreement and the deletion period after it ends.

Nature and purpose

Collection, access, storage, organisation, use, generation, retrieval, transmission, analysis, support, security monitoring, export, and deletion of data to provide the customer-directed service.

Data Subjects

  • Customer users, staff, contractors, administrators, and invited members.
  • LinkedIn users whose public post or profile data a customer chooses to process.
  • Customer prospects, contacts, and content audiences where included by the customer.
  • People who contact support or appear in customer-supplied content.

Types of Personal Data

  • Names, email addresses, account IDs, team membership, and role information.
  • LinkedIn identifiers, profile and account data, OAuth tokens, and granted access.
  • Post URLs and text, drafts, generated content, comments, shares, reactions, and metrics.
  • Usage events, logs, IP address, device, browser, session, and support information.

Special category and criminal offence data

These data are not required for the service and must not be submitted unless the parties agree suitable instructions and safeguards in writing.

13. Order of precedence and contact

If this DPA conflicts with the customer agreement on processing Customer Personal Data, this DPA prevails. The mandatory transfer clauses prevail over both. Notices about this DPA should be sent to support@contentswarm.io and to the customer contact in the agreement.

Content Swarm Limited, 727-729 High Road, London N12 0BP, United Kingdom. Contact support@contentswarm.io.