Skip to content
ChannelCockpit
ProductPricingFAQAbout usContact
EN
  • English
  • Deutsch
  • Français
  • Polski
  • Čeština
  • Norsk bokmål
  • Íslenska
  • Română
  • Dansk
  • Eesti
  • Latviešu
  • Lietuvių
  • Hrvatski
  • Nederlands
  • Svenska
  • Slovenščina
  • Ελληνικά
  • Suomi
  • Italiano
  • Español
  • Slovenčina
  • Português
  • Български
  • Magyar
  • Català
Log in (testers only)Log in Request beta accessRequest beta
ProductPricingFAQAbout usContact Log in (testers only)
EnglishDeutschFrançaisPolskiČeštinaNorsk bokmålÍslenskaRomânăDanskEestiLatviešuLietuviųHrvatskiNederlandsSvenskaSlovenščinaΕλληνικάSuomiItalianoEspañolSlovenčinaPortuguêsБългарскиMagyarCatalà
Privacy PolicyTerms of ServiceData Processing AddendumImprintData Deletion

Data Processing Addendum

Processing personal data on behalf of ChannelCockpit customers under GDPR Article 28.

Back to ChannelCockpit Contact us
On this page Parties and scopeSubject, duration and data categoriesDocumented instructionsConfidentiality and security measuresSubprocessorsProcessing outside the EEAAssistance with rights and compliancePersonal data breachesReturn and deletionEvidence, audit and final provisions

ChannelCockpit is intended for users in Germany. This translation helps you understand the German original. German original

Version: 2026-09-28

Parties and scope

This Data Processing Addendum (DPA) supplements the Terms of Service between the customer identified in the account and contract details and:

Amed Bozo · ChannelCockpit
Moritzstraße 43
65185 Wiesbaden
Germany
support@channelcockpit.app
+491773878629

It applies where ChannelCockpit processes personal data on the customer’s behalf. The customer is the controller or, where acting for its own client, a duly authorised processor. ChannelCockpit acts as processor or subprocessor accordingly. Roles follow the actual processing, not the plan or account label.

This DPA forms part of the contract and does not require an enterprise plan. ChannelCockpit may act as controller for its own account and contract administration, billing, security and legal duties, as explained in the Privacy Policy. Independent processing by social platforms or payment providers does not become processing on ChannelCockpit’s behalf through this DPA.

Subject, duration and data categories

Subject and purpose: providing selected analytics, publishing and engagement features for the platform accounts connected by the customer. Operations include retrieval, transmission, organisation, display, temporary storage, updating, export and deletion, with the technical protection and support needed for those operations.

Duration: for the instructed processing and subsequent agreed return or deletion. Data no longer needed is not retained merely until the contract ends.

Data subjects: the customer and authorised account users, people behind connected profiles, commenters, conversation participants, and people depicted or named in uploaded content.

Data categories: platform and profile IDs, names and profile images, post/video metadata and metrics, media and drafts, comments, replies and supported messages, timestamps, conversation/attachment metadata and related connection and processing records. Actual scope depends on the connections, permissions and features selected.

The service is not intended for deliberate processing of special-category data or criminal conviction data. If the customer supplies such information in content, it remains responsible for a valid legal basis, necessary safeguards and the suitability of the service; this DPA does not generally authorise those uses.

Documented instructions

ChannelCockpit processes data only on documented customer instructions, including for international transfers, unless Union or Member State law requires processing. We notify the customer before such processing unless legally prohibited. The contract, this DPA and app actions taken by an authorised customer constitute the initial instructions. Additional instructions may be sent in text form to support@channelcockpit.app.

We promptly inform the customer if we believe an instruction infringes data protection law and, where necessary, suspend the affected processing until clarified. Customer-directed data is not used for our own advertising, sale of personal data or AI model training. The customer is responsible for lawful collection, required notices and consents and its authority to issue instructions.

Confidentiality and security measures

We ensure people authorised to access data are bound by confidentiality or an equivalent legal duty. Access is limited to what is necessary and authorised. The operator restricts administrative access; using service providers does not replace that responsibility.

  • Access and separation: authentication, user-bound authorisation and server-side access rules; separate environments and restricted service accounts.
  • Transport and storage: encrypted transport, restricted private-media access, protected server-side storage of platform credentials and separate secret management.
  • Processing integrity: input validation, bounded retrieval, repeatable tasks protected against duplicate processing and barriers against new writes during account deletion.
  • Operation: limited error/security logging, controlled updates and tests, and monitoring and handling of technical failures. Personal content is not routinely written into diagnostic logs.
  • Deletion and minimisation: domain-specific retention limits, short-lived exports, limited message caches and central deletion/disconnection processes.

Measures reflect the nature, scope, context, purposes and risks of processing. They are updated without materially reducing the agreed protection. This is not a claim that ChannelCockpit itself holds ISO or SOC certification.

Subprocessors

The customer generally authorises the subprocessors below to the extent they actually receive customer-directed data. Support and email providers are included only where a relevant request contains such data; our own contract administration is distinct.

ProviderPurposeProcessing locationsPrivacy documents
Google Cloud EMEA Limited (Irland / Ireland); Google LLC (USA)Google Cloud and Firebase: hosting, sign-in, database, server functions, export files, logging and abuse protection. Google Workspace: support mailbox and communication.App database in Germany. Individual services, particularly Firebase Authentication, process data in the US; international support and subprocessor access are possible.Cloud / Workspace DPA · Firebase DPA · Cloud subprocessors · Workspace subprocessors
Cloudflare, Inc. (USA)Private media in R2, controlled media delivery, protection and forwarding of incoming support email through Email Routing.R2 media in the EU jurisdiction; global network, security, email and support processing, including the US.DPA · Subprocessors
Plus Five Five, Inc. (Resend, USA)Delivery of contact enquiries and transactional acknowledgements. This contact route does not send newsletters.Email delivery and processing of service, log and delivery data, including in the US.DPA · Subprocessors

We inform the customer of intended additions or replacements with reasonable advance notice, normally at least 30 days before new access. The customer may object on substantiated data protection grounds. We then seek a suitable alternative or remedy. If none is available, the customer may end the affected service before new access begins without an additional termination fee, with an appropriate refund of unused prepaid amounts. Updating only an obscure list does not replace notification.

We impose substantially equivalent data protection duties on subprocessors and remain responsible to the customer for their performance. Further subprocessors of these providers appear in the linked inventories. Social platforms chosen by the customer are not ChannelCockpit subprocessors for their own platform processing.

Processing outside the EEA

Listed providers may process data outside the EEA. We ensure the requirements of GDPR Chapter V are met, for example through an applicable adequacy decision or appropriate Standard Contractual Clauses with necessary supplementary measures. General provider authorisation does not waive these requirements. Where the customer acts as processor and needs further authorisation, it obtains it from its controller. We provide information about recipients, locations and relevant safeguards on request.

Assistance with rights and compliance

Taking the nature of processing into account, we assist the customer through appropriate technical and organisational measures with data-subject requests. Requests concerning customer-directed data are forwarded without undue delay where possible and lawful. We do not respond contrary to the customer’s instructions unless legally required.

Taking available information into account, we assist with security duties, impact assessments, prior consultation and required notifications. The customer’s controller responsibilities remain intact. Ordinary assistance under this DPA is not conditional on an additional plan. Exceptional effort is discussed in advance; mandatory assistance and deadlines cannot be frustrated by doing so.

Personal data breaches

We notify the customer without undue delay after becoming aware of a personal data breach affecting its customer-directed data. As available, the notice describes the incident, affected data and people, likely consequences, action taken or proposed and a contact point. Missing details follow without undue delay; the initial notice is not postponed until an investigation is complete. We preserve necessary evidence, contain the incident and assist with the customer’s own notification duties.

Return and deletion

After the instructed processing ends, we return or delete personal data at the customer’s choice and delete existing copies unless law requires retention. The app provides a bounded export; necessary additional return is arranged through support@channelcockpit.app. A product export alone does not limit this duty or data-subject rights.

During use, the customer may use existing deletion and connection controls or issue additional instructions. Backups are removed through the applicable deletion cycle, protected in the meantime and not otherwise used. Independently required account, payment or legal records for which ChannelCockpit is controller follow the Privacy Policy. Original content retained by a platform is not a backup controlled by ChannelCockpit.

Evidence, audit and final provisions

We provide the information necessary to demonstrate compliance with GDPR Article 28 and allow relevant audits, including inspections by the customer or its appointed auditor. Proportionate coordination of scope, confidentiality, security and timing protects other customers and operation without restricting statutory audit or supervisory rights. Suitable existing reports may be used first but do not replace every necessary case-specific demonstration.

The instruction and privacy contact is support@channelcockpit.app. Customer contact details are those in the current account and contract records; the customer maintains a reachable privacy contact. This DPA prevails over the general terms for processing on the customer’s behalf. Mandatory privacy law and applicable Standard Contractual Clauses prevail over both.

ChannelCockpit

Publishing and analytics for YouTube, TikTok, Instagram and Facebook. Comments and messages for supported accounts. Designed and engineered in Wiesbaden, Germany.

Product

  • Features
  • Pricing
  • FAQ
  • Get started
  • Log in

Company

  • About us
  • Contact
  • Imprint

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Addendum
  • Data Deletion
  • Cancel subscription
  • Withdraw from contract
© 2026 ChannelCockpit. All rights reserved.
EnglishDeutschFrançaisPolskiČeštinaNorsk bokmålÍslenskaRomânăDanskEestiLatviešuLietuviųHrvatskiNederlandsSvenskaSlovenščinaΕλληνικάSuomiItalianoEspañolSlovenčinaPortuguêsБългарскиMagyarCatalà

Display and accessibility

Appearance
Text size
Contrast
Motion

Saved on this device only.

Diese Seite gibt es auch auf Deutsch.

Auf Deutsch ansehen

Cette page est également disponible en français.

Voir en français

Ta strona jest również dostępna po angielsku.

Wyświetl po angielsku

Tato stránka je dostupná také v angličtině.

Zobrazit anglicky

Denne siden er også tilgjengelig på norsk bokmål.

Vis på norsk bokmål

Þessi síða er einnig fáanleg á íslensku.

Skoða á íslensku

Această pagină este disponibilă și în engleză.

Vezi în engleză

Denne side findes også på dansk.

Vis på dansk

See leht on saadaval ka eesti keeles.

Vaata eesti keeles

Šī lapa pieejama arī latviešu valodā.

Skatīt latviski

Šis puslapis taip pat pasiekiamas lietuvių kalba.

Rodyti lietuviškai

Ova je stranica dostupna i na engleskom.

Prikaži na engleskom

Deze pagina is ook beschikbaar in het Nederlands.

In het Nederlands bekijken

Den här sidan finns också på svenska.

Visa på svenska

Ta stran je na voljo tudi v angleščini.

Prikaži v angleščini

Η σελίδα διατίθεται επίσης στα ελληνικά.

Προβολή στα ελληνικά

Tämä sivu on saatavilla myös suomeksi.

Näytä suomeksi

Questa pagina è disponibile anche in italiano.

Visualizza in italiano

Esta página también está disponible en inglés.

Ver en inglés

Táto stránka je dostupná aj v slovenčine.

Zobraziť po slovensky

Esta página também está disponível em português.

Ver em português

Тази страница е достъпна и на български.

Преглед на български

Ez az oldal magyarul is elérhető.

Megtekintés magyarul

Aquesta pàgina també està disponible en català.

Mostra en català