Legal

Data Processing Addendum

Last updated: June 18, 2026

How we handle your data when you use AICMOHQ. Written in plain English.

1. Who we are

This Data Processing Addendum ("DPA") is part of your agreement with AICMOHQ, operated by [Legal entity name] ("we", "us"). It governs how we handle your personal data when you use the service.

Under data protection law (GDPR, UK GDPR), you are the data controller and we are the data processor. We only process your data to deliver AICMOHQ — nothing else.

2. What this covers

This DPA applies for as long as you use AICMOHQ, plus any period needed to return or delete your data afterward.

AICMOHQ helps you research, create, schedule, and publish marketing content across connected platforms. We process personal data only to run the features you enable.

3. What we process

We process the minimum data needed to deliver the service:

  • Account information: name, email, authentication identifiers
  • Platform tokens: OAuth access and refresh tokens for connected platforms (Twitter/X, LinkedIn, Reddit, etc.)
  • Content: posts, prompts, and AI-generated content you create or approve
  • Usage data: credit usage, feature interactions
  • Billing data: payment identifiers managed by Dodo Payments
  • Technical data: IP address, device information

4. Subprocessors

We use these subprocessors to deliver AICMOHQ. Each is bound by data-protection terms at least as protective as this DPA:

  • Supabase — database, authentication, and storage
  • OpenAI — AI content generation and analysis
  • Dodo Payments — billing and subscription management (Merchant of Record)
  • Resend — transactional and promotional email delivery
  • Google — OAuth, Google Analytics 4, and Google Sheets sync (where enabled)
  • Vercel — hosting and infrastructure
  • Exa AI — web search and opportunity discovery for the Scout agent
  • PostHog — product analytics and usage tracking

5. Adding new subprocessors

We'll notify you before adding any new subprocessor. You can object on legitimate data-protection grounds. If we can't resolve your concern, you may terminate the affected part of the service.

6. What we commit to

We will:

  • Process your data only on your instructions (this DPA and your use of the service)
  • Keep our team bound by confidentiality obligations
  • Use encryption in transit, scoped access tokens, and row-level access controls
  • Help you respond to data-subject requests where reasonable
  • Notify you promptly if we become aware of a data breach affecting your data
  • Provide information to demonstrate our compliance

7. International transfers

Your data may be processed in countries where our subprocessors operate. Where a transfer crosses a border that requires extra safeguards, we use Standard Contractual Clauses and additional technical measures.

8. Deleting your data

When our agreement ends, you choose: we return your data or delete it. You can disconnect any platform at any time — this immediately revokes stored tokens for that platform. Deletion may take a reasonable period to clear active systems and backups. We retain data only where law requires it.

9. Audit rights

You can audit our compliance. We'll provide the information you need and cooperate with reasonable audits. Audits require advance notice, confidentiality agreements, and limits on frequency to protect other customers' data.

10. Governing law

This DPA is governed by the laws of [jurisdiction]. It supplements our Terms of Service and Privacy Policy. If there's a conflict about how we process personal data, this DPA wins.

Questions? Email us at hello@aicmohq.com.

Questions about this addendum? Email hello@aicmohq.com or visit our contact page. See also our Privacy Policy and Terms of Service.