Legal
Data Processing Addendum
When you use Herd CMS to publish on behalf of your own organisation or your clients, you are the controller of that content and we process it for you. This addendum sets out the terms of that arrangement — Article 28 of the GDPR for customers in Europe, and the service provider terms US state privacy laws require.
Last updated 27 July 2026
This addendum applies automatically to every customer — you do not need to sign anything. If your procurement process needs a countersigned copy, or your own paper instead, email info@getherd.io.
1. Parties and scope
This addendum is between you (the “Customer”, acting as controller) and Herd LLC, a Delaware limited liability company (“we”, acting as processor), and forms part of the Terms of Service. It applies to personal data we process on your behalf through Herd CMS (“Customer Personal Data”).
It does not apply to data for which we are ourselves the controller — your account details, our activity log, and technical log data. Those are covered by the Privacy Policy.
“GDPR” means Regulation (EU) 2016/679 and, as it forms part of UK law, the UK GDPR. “Data Protection Law” means the GDPR where it applies, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), other US state comprehensive privacy laws, and any other data protection law applicable to the processing. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the GDPR; where the CCPA applies, the Customer is a business and we are a service provider.
If this addendum conflicts with the Terms of Service on the subject of personal data, this addendum wins.
2. Roles and responsibilities
You determine the purposes and means of processing Customer Personal Data. You are responsible for having a lawful basis for it, for the accuracy and legality of the data you put into the Service, for giving data subjects the notices Data Protection Law requires, and for obtaining any consent needed for the content you publish. You confirm your instructions to us will not put us in breach of Data Protection Law.
We process Customer Personal Data only as your processor, on the terms below. The subject matter, duration, nature, purpose, data types and categories of data subject are described in Annex I.
3. Processing on your instructions
We will process Customer Personal Data only on your documented instructions, including as to international transfers, unless a law we are subject to requires otherwise — in which case we will tell you before processing, unless that law forbids it on important grounds of public interest.
Your use of the Service in accordance with the Terms of Service, together with this addendum and any configuration you set in the product, constitutes your documented instructions. If we consider an instruction to infringe Data Protection Law, we will tell you without undue delay and may suspend the affected processing until it is resolved. Additional instructions outside the Service’s normal functionality are subject to written agreement, and we may charge a reasonable fee for them.
We will not sell Customer Personal Data, use it for our own marketing, share it for cross-context behavioural advertising, or use it to train machine learning models.
US state privacy laws
Where the CCPA or an equivalent US state law applies, we act as a service provider (or processor, as that law names it) and we certify that we:
- do not sell or share Customer Personal Data, as those terms are defined in the CCPA;
- retain, use and disclose it only for the specific purpose of providing the Service under the Terms of Service, and not for any other commercial purpose;
- do not combine it with personal information received from another source, except as the CCPA permits a service provider to do;
- comply with the obligations the CCPA places on service providers; and
- will tell you if we determine we can no longer meet those obligations, and will stop the affected processing.
You may take reasonable and appropriate steps to confirm we use Customer Personal Data consistently with your obligations, and to stop and remediate any unauthorised use.
4. Confidentiality of personnel
We limit access to Customer Personal Data to personnel who need it to provide the Service or to comply with the law. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement, and receives appropriate training on their data protection responsibilities.
5. Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. The measures in force are described in Annex II. We may update them, provided the level of security is not reduced.
6. Sub-processors
You give us general written authorisation to engage sub-processors. The current list is published at /subprocessors and is incorporated here by reference.
- We will give you at least 30 days’ notice by email before a new sub-processor begins processing Customer Personal Data.
- You may object within that period on reasonable data protection grounds. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty for the remainder of the term.
- Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than this addendum. We remain fully liable to you for a sub-processor’s performance of its obligations.
7. International transfers
We are established in the United States. Where Customer Personal Data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we ensure an appropriate transfer mechanism is in place — an adequacy decision or certification where one covers the transfer, or otherwise the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, together with the UK International Data Transfer Addendum for UK transfers and the Swiss amendments for Swiss transfers, plus any supplementary measures the transfer requires. Those clauses are incorporated into this addendum by reference where needed, with Annexes I and II below completing them.
8. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. The Service’s own functionality lets you access, correct, export and delete Customer Personal Data directly.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively — we will forward the request to you without undue delay and tell the data subject we have done so.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 48 hours of becoming aware of it. The notification will describe, so far as we know at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. We will supply further detail as it becomes available.
We will assist you in meeting your own obligations under Articles 33 and 34 GDPR. Notifying you is not an admission of fault or liability.
10. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, under Articles 35 and 36 GDPR.
11. Return and deletion
On termination of the Service, you have 30 days to export Customer Personal Data using the Service’s export functionality. After that period we will delete it, and will instruct our sub-processors to do the same, unless Data Protection Law or another law we are subject to requires us to keep it — in which case we will keep it only for as long as, and for the purpose that, the law requires, and it stays protected by this addendum. Backups are overwritten on their normal rotation cycle. We will confirm deletion in writing if you ask.
12. Information and audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice: we will first answer a reasonable security questionnaire and provide the documentation we hold. If that is genuinely insufficient, you may conduct an audit no more than once in any twelve months (or after a personal data breach affecting your data), on 30 days’ written notice, during business hours, without unreasonably disrupting the Service, subject to confidentiality, and at your cost. Nothing here requires us to disclose another customer’s data or information that would compromise our security.
13. Liability
Each party’s liability under this addendum is subject to the limitations and exclusions in the Terms of Service, except to the extent Data Protection Law does not permit that. Nothing in this addendum limits a data subject’s rights under Data Protection Law.
14. Term
This addendum takes effect when you begin using the Service and continues until we no longer process Customer Personal Data. Clauses that by their nature should survive, do.
Annex I — Details of processing
| Subject matter | Provision of Herd CMS: scheduling, managing and publishing social content on the Customer’s behalf. |
| Duration | The term of the Terms of Service, plus the deletion period in clause 11. |
| Nature and purpose | Hosting, storage, organisation, retrieval, adaptation for technical purposes, transmission to LinkedIn at the Customer’s instruction, and erasure — all to operate the Service. |
| Types of personal data | Identification and contact data of the Customer’s users (name, email, role, organisation membership); LinkedIn connection data (member ID, display name, profile picture URL, encrypted access and refresh tokens); any personal data the Customer chooses to include in content, captions and uploaded images or video; activity records attributing actions to users. |
| Categories of data subject | The Customer’s personnel and authorised users; the Customer’s own clients’ personnel where they are given access; individuals appearing in or identified by content the Customer publishes. |
| Special category data | Not requested and not required. The Service is not designed for it, and the Customer should not put it into content. |
| Frequency | Continuous, for the duration of the Service. |
| Retention | As set out in the Privacy Policy retention schedule; activity records for 24 months. |
| Sub-processors | As listed at /subprocessors, for the purposes and durations stated there. |
Annex II — Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption in transit | All traffic served over HTTPS/TLS. |
| Encryption at rest | LinkedIn access and refresh tokens encrypted with AES-256-GCM. Tokens are never displayed after connecting and never sent to the browser. Storage-level encryption at rest is provided by our hosting and database providers. |
| Credentials | Passwords stored only as bcrypt hashes, never in plain text. |
| Access control | Authentication required for all non-public functionality. Authorisation scoped per organisation and per role — members of one organisation cannot access another’s content, media or connections. |
| Least privilege | Administrative access to production systems limited to personnel who need it, each bound by written confidentiality. |
| Third-party permissions | LinkedIn authorisation requested at the minimum scope needed to publish; no read access to feeds, connections or messages. |
| Accountability | Activity log recording scheduling, publishing and connection events with timestamp and actor. |
| Resilience | Managed, redundant hosting and database infrastructure with provider-managed backup and restore. |
| Data minimisation | No analytics, advertising or third-party tracking. One strictly necessary session cookie. |
| Deletion | Disconnecting a LinkedIn account deletes the stored tokens. Content deleted per the published retention schedule. |
Annex III — Contact
Data protection contact for Herd LLC: info@getherd.io, TODO — registered business address, United States. We have not appointed a Data Protection Officer, as we are not required to. The Customer’s contact for the purposes of this addendum is the administrative contact on its account.