Legal

Privacy Policy

Last updated: 22 March 2026  ·  Effective: 22 March 2026

1. Introduction

This Privacy Policy explains how dijitul (“we”, “us”, “our”), the company behind postd.uk, collects, uses, stores, and protects your personal data when you use our Service at https://postd.uk.

We are committed to handling your personal data responsibly and in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For the purposes of UK GDPR, dijitul is the data controller.

Company: dijitul

Registered in: England and Wales

Address: Mansfield, Nottinghamshire, England

Email: hello@postd.uk

2. Data We Collect

We collect the following categories of personal and business data when you use the Service:

Account and Identity Data

Your full name, email address, business name, business description, and billing address.

Payment Data

Billing name and address. Payment card details are collected and processed directly by Stripe. We do not store full card numbers or CVV codes on our systems.

Social Media Access Tokens

When you connect a social media account (Facebook, X, LinkedIn, or Google Business Profile), we receive and store an access token issued by that platform. This token allows us to publish content to your account on your behalf.

Usage and Service Data

How you use the Service, including features accessed, content scheduled, and actions taken. Log data including IP address, browser type, pages visited, and timestamps.

Communications Data

Messages you send us via email or through any support channels.

We do not knowingly collect data from children under 18. If you believe a child has provided us with personal data, please contact us at hello@postd.uk and we will delete it promptly.

3. How We Use Your Data

We use your personal data only for the purposes set out below and only where we have a lawful basis for doing so under UK GDPR.

PurposeLawful Basis
Creating and managing your accountPerformance of a contract
Delivering the Service (scheduling and posting content)Performance of a contract
Processing subscription paymentsPerformance of a contract
Generating AI-assisted content suggestionsPerformance of a contract
Sending service notifications and updatesPerformance of a contract / Legitimate interests
Improving and developing the ServiceLegitimate interests
Complying with legal obligationsLegal obligation
Marketing communications (where opted in)Consent

4. Social Media Access Tokens

Access tokens are stored securely using industry-standard encryption, on servers located in the United Kingdom and/or the European Union. They are used solely for the purpose of publishing content to your social media accounts as directed by you through the Service.

We do not share, sell, or transfer your access tokens to any third party, except where necessary to make authorised API calls to the relevant platform on your behalf. Tokens are deleted from our systems when you disconnect a social media account or delete your account.

5. AI Content Generation (Anthropic and OpenAI)

The Service uses Anthropic's Claude API to write post text, and OpenAI's API to create optional post images. To write posts, we send Anthropic your business details, public text from your website and your public Google reviews. To create images, we send OpenAI a short description of the image.

We do not send your name, email address, billing details, social media tokens, or any other personal data to Anthropic or OpenAI.

Under their current commercial API terms, neither provider uses data sent through the API to train their models. Please refer to Anthropic's Privacy Policy and OpenAI's Privacy Policy for further information.

6. Cookies

We use cookies and similar tracking technologies to enable the Service to function correctly and to improve your experience.

Strictly Necessary Cookies

Essential for the Service to operate, including session cookies that keep you logged in. These do not require your consent.

Analytics Cookies (Google Analytics)

We use Google Analytics to collect anonymised information about how visitors use the Service. IP anonymisation is enabled. You can opt out at any time by installing the Google Analytics Opt-out Browser Add-on.

Preference Cookies

These remember your settings and choices to provide a more personalised experience.

7. Third-Party Data Sharing

We do not sell, rent, or trade your personal data to any third party. We share your data only with the following service providers, and only to the extent necessary for them to provide their services to us:

Third PartyPurposeLocation
StripePayment processingUSA (Data Privacy Framework)
AnthropicAI post writingUSA (Standard Contractual Clauses)
OpenAIAI image generationUSA (Standard Contractual Clauses)
Google AnalyticsService usage analyticsUSA (Data Privacy Framework)
Meta, X, LinkedIn, GooglePublishing content on your behalfVarious
Hosting / InfrastructureData storage and service deliveryUK/EU

8. International Data Transfers

Some of our third-party service providers are based in the United States. Transfers of your personal data to these providers are conducted using appropriate UK GDPR safeguards, including the UK International Data Transfer Agreement (IDTA) and Standard Contractual Clauses.

Your core account data, social media access tokens, and posted content data are stored on servers located within the United Kingdom and/or the European Union.

9. Data Retention

Data CategoryRetention Period
Account data (name, email, business info)Duration of account, plus 2 years after closure
Social media access tokensDeleted upon account deletion or disconnection
Billing and transaction records7 years (UK tax and accounting law)
Usage and log data12 months from collection
Support and communications2 years from last correspondence

10. Your Rights Under UK GDPR

Under UK GDPR, you have the following rights in relation to your personal data:

Right of Access

Request a copy of the personal data we hold about you. We will respond within 30 days.

Right to Rectification

Request that we correct any inaccurate or incomplete personal data.

Right to Erasure

Request that we delete your personal data, subject to any legal obligations to retain it.

Right to Restrict Processing

Request that we restrict processing of your data in certain circumstances.

Right to Data Portability

Receive your personal data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests, or to direct marketing at any time.

Right to Withdraw Consent

Where consent is the basis for processing, withdraw it at any time.

To exercise any of these rights, contact us at hello@postd.uk.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk — 0303 123 1113.

11. Data Security

We implement appropriate technical and organisational measures to protect your data, including TLS encryption of data in transit, encryption of sensitive data at rest (including social media tokens), strict access controls, and secure data storage within UK/EU regions.

In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify you and the ICO as required by UK GDPR.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or via a prominent notice within the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.

13. Contact Us

Email: hello@postd.uk

Website: https://postd.uk

Post: dijitul, Mansfield, Nottinghamshire, England

We aim to respond to all enquiries within 5 working days.