Addendum to the ZenFeed.eu Terms of Service
Data Processing Agreement (DPA)
Effective: July 30, 2026
This Data Processing Agreement forms an integral addendum to the ZenFeed.eu Terms of Service and takes effect automatically when you accept the Terms and create an account. It doesn't need to be separately signed. It governs how ZenFeed processes the personal data of people who comment on the Facebook Pages you connect to the Service, in line with Article 28 of the GDPR.
Controller β the organisation or individual that registers a ZenFeed account and administers one or more Facebook Pages connected to the Service ("you", "the Administrator"). Processor β Szymon Nieradka, trading as ZenFeed (NIP: PL8522145925) ("ZenFeed", "we", "us").
1 Subject matter and duration
ZenFeed processes personal data on your behalf for the scope and purpose described in Section 2 below.
This agreement runs for as long as you use the Service β from account activation until the account is closed or the Terms of Service are terminated, whichever is later.
2 Nature, purpose, and scope of processing
In short: ZenFeed processes personal data solely to provide automated comment moderation β analysing comment content for toxicity/hate speech and carrying out the action you've configured (removing or hiding a comment). Details:
Subject matter
Providing automated comment moderation for the Facebook Pages you administer
Duration
For as long as this agreement is in effect (Section 1)
Nature of processing
Automated analysis of comment content (toxicity/hate speech classification) using an AI model, followed by the action you've configured (remove or hide)
Purpose
Content moderation β detecting and removing/hiding comments that violate the rules you've set
Categories of personal data
Comment text; the commenter's public profile data available via the Facebook Graph API (ID, profile name); publication timestamp. Comment text may indirectly reveal special category data (GDPR Art. 9) if a commenter writes about it themselves
Categories of data subjects
People who comment on posts on the Facebook Pages you administer
Retention
Raw comment text is automatically deleted after 30 days. After that, only anonymised aggregate statistics are kept for dashboard reporting. Custom retention periods are available on the Pro plan.
3 Your responsibilities as Administrator
You confirm that you have a lawful basis for processing commenters' personal data in connection with moderating your Page (typically legitimate interest, GDPR Art. 6(1)(f), in maintaining order in a space you administer), and that you remain solely responsible for the lawfulness of that purpose and basis β ZenFeed does not verify it. You remain responsible for providing commenters with any Art. 13/14 GDPR information that falls on you as the Page administrator.
4 ZenFeed's obligations as Processor
- check_circle Processes personal data only on your documented instructions β in practice, the moderation settings you configure yourself (sensitivity threshold, remove/hide action, connected pages) β unless required otherwise by EU or Member State law, in which case we'll inform you of that requirement first, where the law permits.
- check_circle Ensures that anyone authorised to process personal data on our side is bound by confidentiality.
- check_circle Implements the technical and organisational measures described in Section 7 (GDPR Art. 32).
- check_circle Only uses sub-processors under the conditions set out in Section 5.
- check_circle Helps you, to the extent reasonably possible, respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection).
- check_circle Helps you meet your obligations around processing security, breach notification (GDPR Art. 33-34), and, where relevant, data protection impact assessments (Art. 35-36), taking into account the nature of the processing and the information available to us.
- check_circle Notifies you of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it.
- check_circle Deletes or returns all personal data to you once the relevant services end, and deletes existing copies, unless EU or Member State law requires us to keep it β in line with the retention policy in Section 2.
- check_circle Makes available all information reasonably necessary to demonstrate compliance with Art. 28 GDPR, and allows for audits, including inspections, on terms agreed separately (scope, form, cost, and frequency no more than once a year, unless prompted by a supervisory authority's recommendation or an actual incident).
5 Sub-processors
You give ZenFeed general authorisation to use the sub-processors listed below to provide the Service. We'll notify you of any intended changes β adding or replacing a sub-processor β with reasonable advance notice, giving you 30 days from that notice to object.
Hetzner Online GmbH
Application and database hosting, plus the automation that carries out data deletion after 30 days
EU (Germany)
Google Cloud (Vertex AI)
AI analysis of comment content (toxicity classification)
EU (europe-west4)
Every sub-processor is bound by the same data protection obligations as ZenFeed under this agreement, and ZenFeed remains fully responsible to you for their performance.
6 Transfers outside the EEA
As listed in Section 5, all processing takes place within the European Economic Area. If ZenFeed ever intends to transfer data outside the EEA, we'll notify you first and put an appropriate transfer mechanism in place (e.g. Standard Contractual Clauses) before doing so.
7 Technical and organisational measures
- check_circle Facebook access tokens are stored encrypted with AES-256-GCM (ciphertext, initialisation vector, and authentication tag stored separately).
- check_circle Hosting infrastructure (Hetzner) and the AI model (Google Vertex AI, region europe-west4) run entirely within the EU β data doesn't leave the EEA in the standard processing flow.
- check_circle Raw comment text is automatically deleted after 30 days; only anonymised aggregate data is retained beyond that.
- check_circle Access to production systems is limited to authorised personnel.
8 Liability
Each party is liable for damage caused by processing that infringes the GDPR only to the extent it hasn't complied with its own GDPR obligations, or has acted outside or against your lawful instructions, per GDPR Art. 82.
9 Final provisions
- check_circle Anything not covered by this agreement is governed by the GDPR and applicable Polish law.
- check_circle As an addendum to the Terms of Service, this document changes whenever the Terms change, following the same notice process.
- check_circle If this agreement conflicts with the Terms of Service on a data-protection matter, this agreement takes precedence.
Questions about this agreement? Write to us at
mail hello@zenfeed.eu