Legal
Privacy Policy
Last updated: 22 March 2026 · Effective: 22 March 2026
1. Introduction
This Privacy Policy explains how dijitul (“we”, “us”, “our”), the company behind postd.uk, collects, uses, stores, and protects your personal data when you use our Service at https://postd.uk.
We are committed to handling your personal data responsibly and in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For the purposes of UK GDPR, dijitul is the data controller.
Company: dijitul
Registered in: England and Wales
Address: Mansfield, Nottinghamshire, England
Email: hello@postd.uk
2. Data We Collect
We collect the following categories of personal and business data when you use the Service:
Account and Identity Data
Your full name, email address, business name, business description, and billing address.
Payment Data
Billing name and address. Payment card details are collected and processed directly by Stripe. We do not store full card numbers or CVV codes on our systems.
Social Media Access Tokens
When you connect a social media account (Facebook, X, LinkedIn, or Google Business Profile), we receive and store an access token issued by that platform. This token allows us to publish content to your account on your behalf.
Usage and Service Data
How you use the Service, including features accessed, content scheduled, and actions taken. Log data including IP address, browser type, pages visited, and timestamps.
Communications Data
Messages you send us via email or through any support channels.
We do not knowingly collect data from children under 18. If you believe a child has provided us with personal data, please contact us at hello@postd.uk and we will delete it promptly.
3. How We Use Your Data
We use your personal data only for the purposes set out below and only where we have a lawful basis for doing so under UK GDPR.
| Purpose | Lawful Basis |
|---|---|
| Creating and managing your account | Performance of a contract |
| Delivering the Service (scheduling and posting content) | Performance of a contract |
| Processing subscription payments | Performance of a contract |
| Generating AI-assisted content suggestions | Performance of a contract |
| Sending service notifications and updates | Performance of a contract / Legitimate interests |
| Improving and developing the Service | Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Marketing communications (where opted in) | Consent |
4. Social Media Access Tokens
Access tokens are stored securely using industry-standard encryption, on servers located in the United Kingdom and/or the European Union. They are used solely for the purpose of publishing content to your social media accounts as directed by you through the Service.
We do not share, sell, or transfer your access tokens to any third party, except where necessary to make authorised API calls to the relevant platform on your behalf. Tokens are deleted from our systems when you disconnect a social media account or delete your account.
5. AI Content Generation (Anthropic and OpenAI)
The Service uses Anthropic's Claude API to write post text, and OpenAI's API to create optional post images. To write posts, we send Anthropic your business details, public text from your website and your public Google reviews. To create images, we send OpenAI a short description of the image.
We do not send your name, email address, billing details, social media tokens, or any other personal data to Anthropic or OpenAI.
Under their current commercial API terms, neither provider uses data sent through the API to train their models. Please refer to Anthropic's Privacy Policy and OpenAI's Privacy Policy for further information.
6. Cookies
We use cookies and similar tracking technologies to enable the Service to function correctly and to improve your experience.
Strictly Necessary Cookies
Essential for the Service to operate, including session cookies that keep you logged in. These do not require your consent.
Analytics Cookies (Google Analytics)
We use Google Analytics to collect anonymised information about how visitors use the Service. IP anonymisation is enabled. You can opt out at any time by installing the Google Analytics Opt-out Browser Add-on.
Preference Cookies
These remember your settings and choices to provide a more personalised experience.
7. Third-Party Data Sharing
We do not sell, rent, or trade your personal data to any third party. We share your data only with the following service providers, and only to the extent necessary for them to provide their services to us:
| Third Party | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA (Data Privacy Framework) |
| Anthropic | AI post writing | USA (Standard Contractual Clauses) |
| OpenAI | AI image generation | USA (Standard Contractual Clauses) |
| Google Analytics | Service usage analytics | USA (Data Privacy Framework) |
| Meta, X, LinkedIn, Google | Publishing content on your behalf | Various |
| Hosting / Infrastructure | Data storage and service delivery | UK/EU |
8. International Data Transfers
Some of our third-party service providers are based in the United States. Transfers of your personal data to these providers are conducted using appropriate UK GDPR safeguards, including the UK International Data Transfer Agreement (IDTA) and Standard Contractual Clauses.
Your core account data, social media access tokens, and posted content data are stored on servers located within the United Kingdom and/or the European Union.
9. Data Retention
| Data Category | Retention Period |
|---|---|
| Account data (name, email, business info) | Duration of account, plus 2 years after closure |
| Social media access tokens | Deleted upon account deletion or disconnection |
| Billing and transaction records | 7 years (UK tax and accounting law) |
| Usage and log data | 12 months from collection |
| Support and communications | 2 years from last correspondence |
10. Your Rights Under UK GDPR
Under UK GDPR, you have the following rights in relation to your personal data:
Right of Access
Request a copy of the personal data we hold about you. We will respond within 30 days.
Right to Rectification
Request that we correct any inaccurate or incomplete personal data.
Right to Erasure
Request that we delete your personal data, subject to any legal obligations to retain it.
Right to Restrict Processing
Request that we restrict processing of your data in certain circumstances.
Right to Data Portability
Receive your personal data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests, or to direct marketing at any time.
Right to Withdraw Consent
Where consent is the basis for processing, withdraw it at any time.
To exercise any of these rights, contact us at hello@postd.uk.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk — 0303 123 1113.
11. Data Security
We implement appropriate technical and organisational measures to protect your data, including TLS encryption of data in transit, encryption of sensitive data at rest (including social media tokens), strict access controls, and secure data storage within UK/EU regions.
In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify you and the ICO as required by UK GDPR.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or via a prominent notice within the Service at least 14 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
13. Contact Us
We aim to respond to all enquiries within 5 working days.