Teamful favicon
Effective date: February 3rd, 2026

Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement (“Agreement”) between Teamful ApS (“Teamful,” “Processor,” “we,” “us”) and the customer entity (“Customer,” “Controller,” “you”) governing use of the Teamful platform and services (“Service”).
 
This DPA applies where Teamful processes Personal Data on behalf of the Customer in the course of providing the Service and is intended to ensure compliance with applicable data protection laws, including Regulation (EU) 2016/679 (“GDPR”).
 
 
1. Definitions
 
Capitalized terms not defined in this DPA have the meaning given in the Agreement or GDPR.
 
For the purposes of this DPA:
• “Personal Data” means any information relating to an identified or identifiable natural person processed under this Agreement.
• “Processing” has the meaning set out in Article 4(2) GDPR.
• “Data Subject” means the individual to whom Personal Data relates.
• “Sub-processor” means a third party engaged by Teamful to process Personal Data on behalf of the Customer.
 
 
2. Roles of the Parties
 
The parties acknowledge that, for the purposes of GDPR:
• The Customer acts as Controller of Personal Data.
• Teamful acts as Processor, processing Personal Data solely on documented instructions from the Customer.
 
Nothing in this DPA shall be interpreted as making Teamful a Controller of Customer Personal Data.
 
 
3. Scope and Purpose of Processing
 
Teamful processes Personal Data solely for the purpose of providing, maintaining, securing, and improving the Service, including:
• Account management and authentication
• Campaign planning, collaboration, approvals, and reporting
• Integrations with third-party platforms at Customer instruction
• Customer support and technical operations
 
Processing is limited to what is necessary to deliver the Service as described in the Agreement.
 
 
4. Categories of Data Subjects and Personal Data
 
Processing may involve the following categories of Data Subjects:
• Customer employees and internal users
• External collaborators, creators, freelancers, and agencies
• Brand representatives and client users
 
Personal Data processed may include, depending on use of the Service:
• Identification data (name, username, profile image)
• Contact information (email address)
• Account and authentication data
• Campaign, content, and workflow metadata
• Social media account identifiers and performance data retrieved via APIs
• Communications and approvals within the platform
 
Teamful does not intentionally process special categories of Personal Data unless explicitly provided by the Customer.
 
 
5. Processing Instructions
 
Teamful shall process Personal Data only in accordance with documented instructions from the Customer, including those set out in the Agreement and this DPA, unless required to do otherwise by applicable law.
 
If Teamful believes an instruction violates applicable data protection law, Teamful shall inform the Customer without undue delay.
 
 
6. Confidentiality
 
Teamful ensures that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory, and receive training relevant to data protection and information security.
 
 
7. Security Measures
 
Teamful implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
 
Such measures include, but are not limited to:
•Logical access controls and role-based permissions
•Encryption in transit and at rest where appropriate
•Monitoring, logging, and incident detection mechanisms
•Secure development and infrastructure practices
 
Teamful regularly reviews and updates its security controls to reflect industry standards and risk assessments.
 
 
8. Sub-processors
 
The Customer authorizes Teamful to engage Sub-processors to support delivery of the Service, including infrastructure providers, payment processors, analytics services, and customer support tools.
 
Teamful ensures that all Sub-processors are bound by written agreements imposing data protection obligations no less protective than those set out in this DPA.
 
Teamful remains fully responsible for the performance of its Sub-processors with respect to data protection obligations.
 
A current list of Sub-processors may be made available upon request or via the Teamful website.
 
 
9. International Data Transfers
 
Where Personal Data is transferred outside the European Economic Area, Teamful ensures that such transfers are subject to appropriate safeguards, including Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms.
 
 
10. Assistance with Data Subject Rights
 
Taking into account the nature of processing, Teamful shall provide reasonable assistance to the Customer to enable compliance with Data Subject rights under GDPR, including access, rectification, erasure, restriction, and portability.
 
Teamful shall not respond directly to Data Subject requests unless instructed by the Customer or required by law.
 
 
11. Personal Data Breach Notification
 
Teamful shall notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer data.
 
Such notification shall include, to the extent reasonably available, information necessary for the Customer to meet its obligations under GDPR Articles 33 and 34.
 
 
12. Data Retention and Deletion
 
Upon termination or expiration of the Agreement, Teamful shall, at the Customer’s choice, delete or return all Personal Data, unless retention is required by applicable law.
 
Deletion shall occur within a commercially reasonable timeframe consistent with backup and recovery procedures.
 
 
13. Audits and Compliance
 
Upon reasonable prior notice, the Customer may request information necessary to demonstrate Teamful’s compliance with this DPA.
 
Where required, Teamful may satisfy audit requests through third-party certifications, summaries of audit reports, or other appropriate documentation, unless otherwise required by law.
 
 
14. Liability
 
Liability arising from this DPA shall be subject to the limitations and exclusions set out in the Agreement, except where prohibited by applicable law.
 
 
15. Governing Law
 
This DPA is governed by the laws specified in the Agreement. Where required by GDPR, disputes relating to this DPA shall be subject to the jurisdiction of courts competent under applicable data protection law.
 
 
16. Order of Precedence
 
In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.
 
 
17. Contact
 
Questions regarding this DPA or data protection practices may be directed to:
 
Teamful ApS
Copenhagen, Denmark
Email: privacy@teamful.io
Annex
Data Processing Details and Security Measures

Effective date: February 3rd, 2026

This Annex forms an integral part of the Data Processing Addendum (“DPA”) between Teamful ApS (“Teamful” or “Processor”) and the Customer (“Controller”) and describes the scope of processing activities and the technical and organizational measures implemented by Teamful in accordance with Articles 28 and 32 of the General Data Protection Regulation (“GDPR”).
 
 
1. Description of Processing Activities
 
Teamful processes Personal Data solely for the purpose of providing, operating, maintaining, and improving the Teamful platform and related services in accordance with the Agreement, the DPA, and documented instructions from the Customer.
 
Processing activities may include the collection, storage, organization, structuring, retrieval, consultation, transmission, analysis, and deletion of Personal Data submitted to or generated through use of the Service.
 
Processing is limited to what is necessary to deliver the Service and does not include independent use of Customer data for Teamful’s own commercial purposes.
 
 
2. Categories of Data Subjects
 
Depending on how the Customer uses the Service, Personal Data processed by Teamful may relate to the following categories of Data Subjects:
• Employees, contractors, and internal users of the Customer
• External collaborators, agencies, freelancers, and creators invited to campaigns or projects
• Brand representatives, client stakeholders, and approved third parties granted access by the Customer
 
 
3. Categories of Personal Data
 
The categories of Personal Data processed may include, depending on Customer configuration and usage:
 
Identification and account data, such as names, usernames, profile images, and account identifiers;
Contact data, including email addresses;
Authentication and security data, such as login credentials and access logs;
Campaign, project, deliverable, and workflow data created or uploaded within the Service;
Communications and collaboration data, including comments, approvals, messages, and attachments;
Social media account identifiers and performance metrics retrieved via third-party APIs at the Customer’s instruction;
Technical and usage data, including IP addresses, device information, timestamps, and activity logs.
 
Teamful does not intentionally process special categories of Personal Data as defined in Article 9 GDPR, nor data relating to criminal convictions under Article 10 GDPR.
 
 
4. Purpose of Processing
 
Personal Data is processed exclusively for the following purposes:
 
To provide and operate the Service in accordance with the Agreement;
To enable campaign planning, execution, collaboration, approvals, and reporting;
To support authorized integrations with third-party platforms selected by the Customer;
To provide customer support, troubleshooting, and service communications;
To maintain platform security, monitor system performance, and prevent misuse or abuse;
To comply with legal obligations applicable to Teamful.
 
 
5. Duration of Processing
 
Personal Data is processed for the duration of the Customer’s use of the Service and retained in accordance with the Agreement and applicable law.
 
Upon termination or expiration of the Agreement, Personal Data will be deleted or returned to the Customer in accordance with the DPA, subject to reasonable backup retention periods and legal retention requirements.
 
 
6. Sub-processing and Processing Locations
 
Teamful may engage Sub-processors to support delivery of the Service, including infrastructure providers, hosting services, analytics providers, payment processors, and customer support tools.
 
Processing may occur within the European Union and in other jurisdictions, including the United States.
 
Where Personal Data is transferred outside the European Economic Area, Teamful ensures appropriate safeguards are in place, including Standard Contractual Clauses or other lawful transfer mechanisms in accordance with applicable data protection law.
 
Teamful remains responsible for ensuring that Sub-processors comply with data protection obligations consistent with the DPA.
 
 
7. Technical and Organizational Security Measures
 
Teamful implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk associated with the processing of Personal Data.
 
These measures include, but are not limited to:
 
Access controls designed to ensure that only authorized personnel with a legitimate business need can access Personal Data, using role-based permissions and the principle of least privilege;
Authentication and authorization mechanisms to protect user accounts and administrative access;
Encryption of data in transit and, where appropriate, at rest;
Secure hosting infrastructure operated by reputable service providers with industry-standard security practices;
Network protections, including firewalls and monitoring systems;
Logging and monitoring of system activity to detect unauthorized access or anomalies;
Regular internal reviews of access rights and security controls;
Procedures for secure development, deployment, and maintenance of the Service.
 
Personnel with access to Personal Data are subject to confidentiality obligations and receive training relevant to data protection and information security.
 
 
8. Incident Response and Availability
 
Teamful maintains procedures designed to detect, respond to, and mitigate security incidents, including Personal Data breaches.
 
In the event of a Personal Data breach affecting Customer data, Teamful will notify the Customer without undue delay in accordance with the DPA and applicable law.
 
Backup and recovery processes are implemented to support data availability and service continuity.
 
 
9. Assistance and Compliance Support
 
Taking into account the nature of the processing, Teamful provides reasonable assistance to the Customer to support compliance with data protection obligations, including assistance with Data Subject rights requests, security inquiries, and regulatory obligations, in accordance with the Agreement and the DPA.
 
 
10. Updates to This Annex
 
Teamful may update this Annex from time to time to reflect changes in processing activities, security practices, or legal requirements. Material changes will be communicated to Customers in accordance with the Agreement.
 

Create your account