Leap
Legal

Data Processing Agreement

How Leap processes personal data on your behalf: roles, security, sub-processors and international transfers. Incorporated into the Terms of Service, no signature required.

Effective 17 August 2026Last updated 17 August 2026Version 1.0

1. Scope, roles and how this DPA applies

This Data Processing Agreement (“DPA”) applies where Tide Venture Studio Ltd (“Leap”, “we”, “us”), a company registered in England and Wales, processes personal data on your behalf in providing the Service.

How it takes effect

This DPA is incorporated into the Terms of Service. It applies automatically from the moment you accept the Terms, you do not need to sign or request it. If you require a countersigned copy for your records, contact privacy@leap-social.com; for Enterprise customers a countersigned version can be annexed to your order form.

Roles

  • You are the controller of the personal data contained in your Customer Content and in the data retrieved from your Connected Accounts, including your audiences, followers, commenters and the people who message your accounts. Where you are yourself a processor for another party (for example an agency acting for a client), you act as that party's processor and Leap acts as sub-processor.
  • Leap is the processor of that data.
  • Leap is a separate controller of the account, billing, security and usage data described in our Privacy Policy. That processing is governed by the Privacy Policy, not by this DPA.

Precedence

In the event of conflict, this DPA prevails over the Terms of Service in relation to the processing of Customer Personal Data. Where the Standard Contractual Clauses apply (section 8), they prevail over this DPA to the extent of any conflict.

2. Definitions

  • Data Protection Law: the UK GDPR and Data Protection Act 2018; the EU GDPR (Regulation (EU) 2016/679); and any other data protection or privacy law applicable to the processing.
  • Customer Personal Data: personal data contained in Customer Content and Connected Account data, processed by Leap on your behalf under the Agreement.
  • SCCs: the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, as completed in section 8.
  • UK Addendum: the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
  • Sub-processor: a processor engaged by Leap to process Customer Personal Data.
  • Controller, processor, personal data, processing, data subject and personal data breach have the meanings given in Data Protection Law.

Capitalised terms not defined here have the meanings given in the Terms of Service.

3. Processing of Customer Personal Data

3.1 Documented instructions. Leap will process Customer Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law, in which case we will inform you before processing, unless the law prohibits that on important grounds of public interest.

3.2 What counts as your instructions. Your instructions comprise: the Agreement (including this DPA); your and your Authorized Users' configuration and use of the Service, including which social accounts you connect, what you publish, what you schedule, and which features you enable (including AI features and automated sending); and any further written instructions you give that we agree to.

3.3 AI processing is part of the Service. You acknowledge that Leap is an AI-powered platform and that AI processing of Customer Content is an inherent part of the Service. By using the Service you instruct us to process Customer Personal Data using AI, including transmission to our AI sub-processor as described in Annex III and section 8. Features that send messages automatically without your review are off by default and take effect only when you enable them.

3.4 Unlawful instructions. We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may suspend the affected processing until the instruction is withdrawn, amended or confirmed.

3.5 Details. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex I.

4. Your obligations as controller

4.1 You warrant that you have, and will maintain throughout the term, a valid lawful basis for the processing you instruct, and that you have given all notices and obtained all consents required by Data Protection Law, including in respect of people who are not your customers, such as members of the public who comment on or send messages to your Connected Accounts.

4.2 You are responsible for the accuracy, quality and legality of Customer Personal Data and of the means by which you acquired it.

4.3 You will not instruct processing of special category data (Article 9) or criminal offence data (Article 10) through the Service unless you have a lawful basis and have told us in advance in writing. The Service is not designed for such data and Annex II describes measures calibrated accordingly.

4.4 You will inform the individuals whose data you process through the Service, as required by Articles 13 and 14, including that their data may be processed using AI and transferred as described in section 8.

4.5 You will not use the Service to process personal data of anyone under 18, other than as incidentally contained in public engagement with your Connected Accounts.

5. Confidentiality and personnel

Leap will ensure that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, are subject to appropriate access controls on a least-privilege basis, and receive appropriate data protection and security training. Access by Leap personnel to Customer Personal Data is limited to what is necessary to provide, secure and support the Service, and administrative actions are recorded in an append-only audit log (Annex II).

6. Security

Leap will implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as required by Article 32.

Those measures are described in Annex II. We may update them provided that the level of security is not materially reduced.

7. Sub-processors

7.1 General authorization. You give Leap general written authorization to engage sub-processors to process Customer Personal Data. The sub-processors engaged at the date of this DPA are listed in Annex III.

7.2 Notice of changes. We will give you at least 30 days' notice before adding or replacing a sub-processor, by updating the sub-processor page and notifying customers who have subscribed to notifications there. You should subscribe to that list: it is how we give notice.

7.3 Objection. You may object to a new sub-processor on reasonable data protection grounds by writing to privacy@leap-social.com within the notice period, explaining your grounds. We will work with you in good faith to address the objection. If we cannot do so within a reasonable period, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid Fees for the unused period. That is your sole remedy.

7.4 Flow-down and liability. We will impose on each sub-processor data protection obligations no less protective than those in this DPA, by written contract. Leap remains fully liable to you for the performance of each sub-processor's obligations.

7.5 Emergency changes. Where a sub-processor change is required urgently to address a security, availability or legal risk, we may make it with shorter notice and will tell you as soon as reasonably practicable.

8. International transfers

8.1 Where processing takes place. Leap's own infrastructure, application servers, database, cache, object storage and backups, is located in the European Union (Frankfurt, Germany). Annex III records the location of each sub-processor.

8.2 Transfers outside the UK/EEA. Where Customer Personal Data is transferred outside the UK or EEA to a country without an adequacy decision, that transfer is made under:

  • the EU Standard Contractual Clauses, Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated into this DPA by reference and deemed executed between the parties; and
  • the UK International Data Transfer Addendum, where the UK GDPR applies.

8.3 Completing the SCCs. For the purposes of the SCCs: the data exporter is you; the data importer is Leap; Clause 7 (docking) applies; under Clause 9 option 2 (general written authorization) applies with the notice period in section 7.2; under Clause 11 the optional independent dispute resolution body does not apply; under Clause 17 the governing law is the law of Ireland (or, where the UK Addendum applies, England and Wales); under Clause 18 the forum is the courts of Ireland (or England and Wales as applicable). Annex I to this DPA serves as Annexes I.A, I.B and I.C, Annex II as Annex II, and Annex III as the list of sub-processors.

8.4 AI processing in the United States. You acknowledge that AI features involve a transfer of Customer Personal Data to the United States (Annex III), made under the SCCs and UK Addendum, and that this is inherent in the Service. We have carried out a transfer risk assessment and consider the safeguards appropriate to the content involved; a summary is available on request.

8.5 Publishing to social platforms. When you publish content, schedule posts, reply or retrieve analytics, data is exchanged with the social platform you have connected. That exchange is made on your instruction, to a platform you have selected and with which you have your own direct relationship and terms. Leap acts as a conduit for that instruction. Those platforms are independent controllers in respect of the data they hold, and you are responsible for the lawfulness of that transfer and for your relationship with each platform.

9. Assistance with data subject rights

9.1 Self-service. The Service provides functionality that allows you to access, correct and delete Customer Personal Data yourself, including a self-serve account deletion and erasure flow. In most cases you can respond to a data subject request without our involvement.

9.2 Our assistance. Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.

9.3 Requests received by us. If we receive a request from a data subject relating to Customer Personal Data, we will not respond to it directly except to confirm that the request should be directed to you, and we will forward it to you without undue delay.

9.4 Cost. Assistance under 9.2 is provided at no charge unless the request is manifestly unfounded or excessive, or requires significant engineering effort beyond the Service's functionality, in which case we may charge our reasonable costs, notified to you in advance.

10. Personal data breach

10.1 Notification. We will notify you of a personal data breach affecting Customer Personal Data without undue delay and in any event within 72 hours of becoming aware of it.

10.2 Content of notification. So far as the information is available to us, we will describe the nature of the breach including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases without undue delay.

10.3 Cooperation. We will cooperate with you and take reasonable steps as directed by you to assist in the investigation, mitigation and remediation of the breach, and to assist you in meeting your own obligations to notify supervisory authorities and data subjects.

10.4 No admission. Our notification is not an acknowledgement of fault or liability.

10.5 Your obligation. You are responsible for determining whether the breach must be notified to a supervisory authority or to data subjects, and for making that notification. You will not name Leap in any public notification without our prior consent, not to be unreasonably withheld.

11. Assistance with DPIAs and consultation

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and with any prior consultation with a supervisory authority, as required by Articles 35 and 36. Annex II and the Privacy Policy are intended to give you most of the information you will need. Where assistance requires significant effort we may charge our reasonable costs, notified in advance.

12. Deletion and return of data

12.1 On termination or expiry of the Agreement, we will, at your choice, delete or return Customer Personal Data, and delete existing copies, unless Data Protection Law or other applicable law requires us to retain it.

12.2 Export window. We will make Customer Content available for export for 30 days after termination. If you have not exported it and have not asked us to return it within that period, we will delete it.

12.3 Deletion timescale. Deletion will be completed within 90 days of the end of the export window, subject to 12.4.

12.4 Permitted retention. We may retain Customer Personal Data where required by law, including invoices and transaction records required for tax and accounting purposes, and in routine backups until those backups expire on their normal cycle. Data retained under this clause remains subject to sections 5, 6 and 8, and will not be processed for any other purpose.

13. Audit and information rights

13.1 Information. We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 and with this DPA. In the first instance this means Annex II, the Privacy Policy, the sub-processor list, and our responses to a written security questionnaire: which we will complete within 30 days of request, no more than once in any 12-month period unless there has been a personal data breach affecting you or a supervisory authority requires otherwise.

13.2 Third-party reports. Where we hold a third-party audit report or certification (for example SOC 2 or ISO 27001), we will provide it on request under confidentiality, and it will be accepted as satisfying 13.1.

13.3 On-site audits. Where the information under 13.1 and 13.2 is not sufficient to demonstrate compliance, you may audit, or mandate an independent auditor to audit, our processing, subject to: 30 days' prior written notice; no more than once in any 12-month period (except following a personal data breach affecting you or where a supervisory authority requires it); conduct during normal business hours, without unreasonably disrupting our business; the auditor being bound by confidentiality and not being a competitor of Leap; scope limited to systems and records relevant to Customer Personal Data and excluding other customers' data, our commercially sensitive information and third-party confidential information; and your bearing your own and our reasonable costs.

13.4 Nothing in this section limits a supervisory authority's own powers.

14. Agencies and client accounts

14.1 Agencies. Where you use the Service as an agency to manage social media on behalf of your clients, you act as processor for each client and Leap acts as sub-processor. You warrant that you are authorized by each client to engage Leap as a sub-processor on the terms of this DPA and to give the instructions you give.

14.2 Flow-down. You may rely on and flow down the terms of this DPA to your clients as part of your own processing agreement with them, provided you do not represent them as terms agreed directly between Leap and your client, and provided you do not grant your clients rights against Leap that exceed those in this DPA.

14.3 Client accounts. Personal data in a client account is Customer Personal Data. You are responsible for the access you grant your staff to client accounts and for ensuring your arrangements with each client permit the processing.

14.4 Direct requests. If a client of yours contacts us directly regarding data in a client account, we will refer them to you.

15. Liability, term and general

15.1 Liability. Each party's liability under this DPA is subject to the exclusions and limitations in the Terms of Service, to the extent permitted by Data Protection Law. Nothing in this DPA limits either party's liability to a data subject or a supervisory authority.

15.2 Term. This DPA takes effect when you accept the Terms and continues until Leap ceases to process Customer Personal Data, after which sections 5, 6, 8, 12 and 15 survive.

15.3 Changes. We may update this DPA where required to reflect changes in Data Protection Law, in the Service, or in our sub-processors, provided the change does not reduce the protection afforded to Customer Personal Data.

15.4 Governing law. Except where the SCCs provide otherwise (8.3), this DPA is governed by the law of England and Wales.

15.5 Contact. privacy@leap-social.com · Tide Venture Studio Ltd, London.

Annex I: Details of processing

This Annex serves as Annexes I.A, I.B and I.C to the SCCs.

A. List of parties

Data exporter (controller): the Leap customer identified in the account, whose contact details are those held in the account. Activities relevant to the transfer: use of the Leap platform to manage social media accounts and, where enabled, the Wizards marketplace.

Data importer (processor): Tide Venture Studio Ltd, London, privacy@leap-social.com. Activities relevant to the transfer: provision of the Leap social media management platform.

B. Description of transfer

Categories of data subjects

  • The customer's Authorized Users (employees, contractors, team members)
  • The customer's clients and their personnel, where the customer is an agency
  • Members of the public who interact with the customer's Connected Accounts: followers, commenters, people who send messages or mentions
  • People depicted in or identified by content the customer uploads or publishes
  • Wizards Experts and Clients, and their personnel, where the marketplace is used

Categories of personal data

  • Identity and contact data: names, usernames and handles, email addresses, profile images
  • Account and organization data: roles, permissions, workspace and client-account membership
  • Content: posts, captions, images, video, campaign material, brand-voice settings, documents, and any personal data the customer chooses to include in them
  • Connected Account data: account identifiers, profile information, published content and metadata
  • Engagement data: comments, mentions, replies and, where the customer enables it, direct messages on Connected Accounts
  • Analytics data: follower counts, reach, impressions, likes, comments, shares, clicks, video views, and audience aggregates provided by the platforms
  • Marketplace data: profiles, listings, offers, bookings, messages between Experts and Clients

Special categories of data: none intended. The Service is not designed for special category data and customers are contractually required not to instruct such processing without prior written notice (4.3). Where such data appears incidentally in public engagement content, the measures in Annex II apply.

Frequency of transfer: continuous, for the duration of the Agreement.

Nature and purpose of processing: hosting, storage, organization, retrieval, structuring, analysis, AI-assisted drafting and analysis, transmission to social platforms at the customer's instruction, and deletion, in each case to provide the Service described in the Terms.

Duration of processing: for the term of the Agreement, plus the export and deletion periods in section 12.

Sub-processors: see Annex III. Subject matter, nature and duration as stated there.

C. Competent supervisory authority

Where the EU GDPR applies via the SCCs, the competent supervisory authority is that of the EU/EEA member state in which the data exporter is established or, where the exporter is not established in the EEA, the authority of the member state in which its Article 27 representative is established. Where the UK GDPR applies, the competent authority is the Information Commissioner's Office.

Annex II: Technical and organizational measures

The following measures are implemented by Leap. They may be updated provided the level of security is not materially reduced.

Tenant isolation

  • Database-enforced isolation using PostgreSQL Row-Level Security. Policies key on a per-transaction session setting (app.current_org) so that rows outside the active tenant are neither readable nor writable.
  • The application connects at runtime as a non-superuser, non-owner database role that cannot bypass RLS. Schema migrations run as a separate owner role.
  • Tenant context is set within the transaction using parameterized values, so it cannot leak across pooled connections.
  • RLS is enforced today on the core-domain and content schemas. The social, entitlements and billing schemas rely on application-layer tenant scoping plus the non-privileged database role, with database-level RLS a tracked follow-up.

Encryption

  • In transit: TLS for all external connections; HTTPS enforced; secure cookies in production.
  • At rest: encryption at rest provided by the managed database and storage services.
  • Field-level encryption: social platform OAuth access and refresh tokens are encrypted with AES-256-GCM using a 12-byte random IV per encryption and an authenticated tag, with the key held only in the environment. Tokens are never returned to clients.

Access control and authentication

  • Role-based access control with an enforced role hierarchy; no privilege escalation to or above one's own rank.
  • Session security: short-lived HS256 access tokens with pinned algorithm, issuer and audience; refresh tokens stored only as SHA-256 hashes, with rotation and reuse detection: a replayed token revokes all of that user's sessions.
  • OAuth hardening: single-use state with fetch-and-delete consumption, PKCE (S256), cryptographic verification of OIDC id_tokens against provider JWKS, nonce binding, and an open-redirect allow-list.
  • Account-takeover protection: automatic account linking requires a provider-asserted verified email.
  • Platform administration is a separate deployable in a separate authorization realm, outside organization membership, with a bootstrap allow-list and superadmin controls.

Logging, monitoring and detection

  • Append-only audit log of administrative actions, capturing actor, action, target, metadata, IP and timestamp. Never updated or deleted.
  • Security event feed recording security-relevant events by severity, unauthorized access attempts, refresh-token reuse, tenant spoofing attempts, rate-limit abuse, brute force, probing and privilege changes, with IP blocking.
  • Production error monitoring across all services.
  • Health checks and an automated watchdog that opens and resolves incidents.

Application security

  • Containers run as a non-root user.
  • Security headers, locked CORS, request body size limits, and rate limiting.
  • Input validation across the API with a typed error hierarchy.
  • SSRF guards on server-side fetches of user-supplied URLs; mitigation of XSS in user-provided media and content rendering.
  • Idempotent publishing and webhook handling to prevent duplicate actions.
  • Expand-and-contract migration discipline; no destructive change in a single deploy.

Secrets management

  • Secrets held in environment variable groups, never committed to source control, validated at boot, and rotated on a schedule.
  • Credentialed connection strings passed via the environment, never on the command line.

Development and supply chain

  • Continuous integration running typecheck, tests, build, dependency audit and secret scanning on every change.
  • Manual, gated production deploys behind environment protection.
  • Separate development, staging and production environments with separate databases and secrets.

Resilience and recovery

  • Managed database backups with documented backup and restore procedures and a runbook.
  • Queue configuration that does not evict jobs; private-network-only cache.

Data subject rights support

  • Erasure across all module schemas, available both as a self-serve account deletion flow and as an operator-run action from the admin console, audited like any other administrative action.

Personnel

  • Access on a least-privilege basis, limited to what is necessary to provide, secure and support the Service.
  • Confidentiality obligations for all personnel with access to Customer Personal Data.
  • Administrative access to customer accounts through an audited impersonation mechanism.

Annex III: Sub-processors

Sub-processorRoleProcessingLocationTransfer mechanism
Render Services, Inc.Hosting, managed PostgreSQL, managed RedisHosting of the application and storage of all Customer Personal DataEU, FrankfurtData remains in the EU
Object storage providerMedia object storageStorage of images, video and other assetsEUData remains in the EU
Anthropic, PBCAI provider (Claude)AI-assisted drafting, analysis and reply generation on content submitted to an AI featureUnited StatesSCCs + UK Addendum. Anthropic does not use inputs or outputs to train its models
StripePayments, tax, invoicing, marketplace payoutsBilling contact and transaction dataEU / USSCCs + UK Addendum where applicable
BrevoTransactional and notification emailRecipient email address and message contentEU, FranceData remains in the EU
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsApplication error data, which may incidentally contain personal data in stack traces and request contextUnited StatesSCCs + UK Addendum
Google LLCWebsite analytics (Google Analytics)Website usage data. Applies to Leap's own website and app, not to Customer ContentUnited StatesSCCs via Google Ads Data Processing Terms

Identity providers. Where an Authorized User signs in using Google, Microsoft, Apple, Facebook, LinkedIn or X, that provider processes authentication data as an independent controller under its own terms, not as Leap's sub-processor.

Social platforms. Facebook and Instagram (Meta), LinkedIn, X, TikTok, YouTube, Pinterest and Telegram are independent controllers in respect of data they hold. Leap transmits to and retrieves from them on the customer's instruction (8.5); they are not Leap's sub-processors.

Cookies

We use essential cookies to run Leap, and optional ones to understand how the site is used. You choose. Cookie preferences