Legal
GDPR & Data Processing Addendum
Our commitments under the GDPR, the DPA that applies to Customer Data, and the subprocessors we use to deliver the Nylon API.
Last updated September 1, 2026
Nylon is operated by a company established in the European Union, on production infrastructure located in the United States. This page sets out our GDPR position and incorporates the Data Processing Addendum (“DPA”) that forms part of our Terms of Service. It applies automatically to every customer — you do not need to sign a separate copy, although we will countersign one on request for procurement purposes.
1. Roles of the parties
For personal data relating to your own account — your name, work email, billing details and usage logs — we are the controller, and our Privacy Policy explains that processing.
For personal data contained in the social accounts you connect and the content you publish through the API (“Customer Data”), you are the controller and we are the processor. We process Customer Data only on your documented instructions, which are given through your use of the Service and any written instructions you send us. We will tell you if we believe an instruction infringes the GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter — provision of a unified social media publishing and reading API.
- Duration — the term of your subscription, plus the deletion window in section 8.
- Nature and purpose — storing OAuth credentials, transmitting content to third-party platforms on your instruction, scheduling and retrying publication, processing media, and returning platform responses and metrics to you.
- Categories of data subjects — your personnel, your end customers who connect social accounts, and individuals appearing in or interacting with the content you publish.
- Categories of personal data — account identifiers and handles, profile names and avatars, OAuth tokens, post content and media, comment and message content where you use those endpoints, and technical identifiers.
- Special categories — not requested by us and not to be submitted without a prior written agreement.
3. Our obligations as processor
- Process Customer Data only on your documented instructions, including for transfers.
- Ensure personnel authorised to process Customer Data are bound by confidentiality.
- Implement the technical and organisational measures set out in section 5.
- Engage subprocessors only under section 4.
- Assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your obligations under Articles 32 to 36 of the GDPR.
- Delete or return Customer Data at the end of the engagement, as set out in section 8.
- Make available the information necessary to demonstrate compliance and allow for audits under section 9.
4. Subprocessors
You give general authorisation for us to engage subprocessors. We impose data protection obligations on each one that are no less protective than those in this DPA, and we remain fully liable for their performance. We will give at least 30 days’ notice before adding or replacing a subprocessor; you may object on reasonable data protection grounds, and if we cannot resolve the objection you may terminate the affected part of the Service without penalty.
| Category | Purpose | Processing location |
|---|---|---|
| Cloud hosting & databases | Application, queue and database hosting | United States |
| Object storage & CDN | Storage and delivery of uploaded media | United States |
| Media transcoding | Video and image processing for platform requirements | United States |
| Transactional email | Account, billing and security notifications | United States |
| Payment processing | Subscription billing and invoicing | United States |
| Error monitoring | Application error and performance diagnostics | United States |
The named entity behind each category is available on request from support@nylon.dev. The social platforms you choose to connect are independent controllers, not our subprocessors — when you instruct us to publish to a network, that network processes the content under its own terms.
5. Security measures
We implement appropriate technical and organisational measures under Article 32 of the GDPR, including:
- Encryption of Customer Data in transit (TLS 1.2+) and at rest
- Per-tenant encryption keys for OAuth tokens and BYOK credentials
- Role-based access control with least privilege and mandatory multi-factor authentication for staff
- Segregated production, staging and development environments
- Centralised, tamper-evident audit logging of administrative access
- Automated dependency and vulnerability scanning, with a documented patching window
- Encrypted, access-controlled backups with tested restore procedures
- Documented incident response plan with defined notification timelines
- Confidentiality undertakings and security training for all personnel with access
6. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will not make public statements identifying you without your prior consent unless legally required.
7. International transfers
Customer Data is stored and processed in the United States, in the state of Virginia. Transfers of personal data from the EEA, the UK or Switzerland to the United States are therefore restricted transfers. We rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), incorporated into this DPA by reference, with the UK International Data Transfer Addendum and the Swiss amendments applied where relevant. Module Two (controller to processor) applies between you and us; Module Three applies between us and our subprocessors. Supplementary measures include encryption in transit and at rest, a transfer impact assessment available on request, and a policy of challenging unlawful government access requests.
8. Return and deletion
You can delete Customer Data at any time through the API or dashboard. On termination of your subscription, we delete or irreversibly anonymise Customer Data within 30 days, except where storage is required by Union or Member State law. Backups are purged on their normal rotation, not later than 90 days, and remain encrypted and inaccessible in the meantime.
9. Audits
On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this DPA, including our current security documentation and any third-party assessment reports we hold. Where that is insufficient for your regulator, we will cooperate with a proportionate on-site audit at your cost, subject to confidentiality and reasonable notice.
10. Data subject requests
If we receive a request from an individual relating to Customer Data, we will not respond substantively; we will refer them to you and forward the request without undue delay. Where the Service does not already let you fulfil a request yourself, we will provide reasonable assistance in doing so.
Requests concerning data for which we are the controller — your own account data — should go to support@nylon.dev, and we respond within one month.
11. Order of precedence
This DPA forms part of and is subject to the Terms of Service. In the event of a conflict between this DPA and the Terms in relation to the processing of Customer Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
12. Contact
For a countersigned DPA, our subprocessor entity list, security documentation, or any GDPR question, write to support@nylon.dev.