Legal

Data Processing Addendum

This addendum forms part of the Pressbotics Terms of Service for customers who need written data-processing terms. It describes what we actually do with data, in the structure Article 28 of the GDPR asks for.

Last updated 13 September 2026. Questions: info@pressbotics.com. This page describes how the Pressbotics service actually behaves; it is not legal advice and has not yet been reviewed by a lawyer.

1. Roles — and the dual role, stated plainly

Pressbotics acts in two different capacities at once, and most SaaS terms blur this. We do not.

  • Processor. For customer data — your WordPress site records, the credentials you connect, the content your agents propose and publish, and the action history that results — you are the controller and Pressbotics is the processor. We process that data only on your documented instructions, which are the instructions you and your agents issue through the product and its API.
  • Controller. For our own account, authentication, billing, security and support data — who you are, what plan you are on, sign-in and abuse signals, and the reports you file — Pressbotics is the controller and processes that data to run and secure the service. The privacy policy governs that processing.

2. Subject matter, duration, nature and purpose

Article 28(3) processing particulars
ItemDetail
Subject matterOperating a publishing rail between the customer's AI agents and the customer's WordPress sites, including an approval gate and an audit trail.
DurationFor the term of the customer's account, plus the retention periods set out in the privacy policy. Processing of a given site's credentials ends when that site is disconnected or deleted.
Nature of processingStorage, encryption, transmission to the customer's own WordPress installation, logging of outcomes, and display back to the customer. Retrieval of limited site metadata (category and tag names, recent post titles) to help agents choose correctly.
PurposeCarrying out publish, update, schedule, media and SEO actions the customer or the customer's agent requested, and giving the customer a record of what happened.
Categories of data subjectsThe customer's own personnel and account users; authors and commenters whose names appear in content the customer's agents publish; individuals mentioned in content the customer submits.
Categories of personal dataAccount identifiers (email, user id), workspace and site records, WordPress credentials (encrypted), agent key hashes, action payloads and outcomes, support messages, IP addresses and user agents in security logs.
Special category dataNone is required by the service. Pressbotics does not ask for it. If the customer publishes content containing it, that is the customer's decision and remains the customer's responsibility.

3. Subprocessors

The customer gives general written authorisation for Pressbotics to engage subprocessors. The current list, with the purpose and the categories of data each receives, is published at /subprocessors. We will update that page and notify customers who have asked to be notified before a new subprocessor begins processing customer data, giving the customer the opportunity to object. Pressbotics remains responsible to the customer for its subprocessors' performance and imposes data protection obligations on them no less protective than these.

4. Security measures — what we actually implement

The following are measures in force today, verifiable in the product. We describe them rather than gesture at "industry-standard security".

  • Credential encryption. WordPress Application Passwords and plugin connection secrets are encrypted with AES-256-GCM. The key is held only by the publishing rail; the credential is decrypted in memory for the duration of a request and is never returned to the browser, never included in an API response, and never written to a log.
  • Agent key hashing. Agent keys are stored as one-way hashes. The raw key is displayed once at creation and is not recoverable by the customer or by us.
  • Tenant isolation. Every customer-facing table enforces PostgreSQL row-level security scoped to the workspace, so one customer's query cannot read another's rows even if application code is wrong. Site-facing mutations additionally filter on the workspace identifier.
  • Staff access control and MFA. Staff tooling is behind role checks and requires TOTP multi-factor authentication. Staff cannot read customer WordPress credentials, because they are not in possession of the rail key.
  • Encrypted MFA secrets. TOTP secrets are stored encrypted at rest; recovery codes are stored hashed.
  • SSRF-guarded outbound requests. Every request the platform makes to a customer-supplied URL passes through a guard that rejects private, loopback and link-local address ranges and refuses to follow redirects into them.
  • Audit trail. Actions, approval decisions, staff operations and inbound webhook deliveries are recorded with timestamps and actor identity.
  • Transport security. All traffic to the application and the rail is TLS-encrypted.

Pressbotics is not SOC 2 audited and is not ISO 27001 certified. We hold no third-party security certification. Nothing on this page should be read as claiming one. If a certification is a hard requirement for you, tell us before you buy rather than after.

5. Confidentiality and personnel

Access to production systems is limited to personnel who need it to operate the service, under confidentiality obligations, with individual accounts and multi-factor authentication. Pressbotics is a small team; we do not pretend to have a segregated operations department.

6. Personal data breach notification

Pressbotics will notify the customer without undue delay after becoming aware of a personal data breach affecting that customer's data, and in any event in time to allow the customer to meet its own notification deadlines. The notification will describe the nature of the breach, the categories and approximate volume of data concerned, the likely consequences, and the measures taken or proposed. Notice is sent to the account email address on file. We do not withhold notice pending complete investigation.

7. Assistance with data subject rights

Taking into account the nature of the processing, Pressbotics will assist the customer in responding to requests from data subjects to exercise their rights of access, rectification, erasure, restriction, portability and objection. In practice most requests are answerable from within the product: the customer can export their workspace data as JSON and can delete the workspace and everything under it from account settings. For anything the product cannot do, write to info@pressbotics.com and we will help within a reasonable period.

Pressbotics will also assist the customer with data protection impact assessments and with prior consultation of a supervisory authority, to the extent the information is ours to provide.

8. Return and deletion on termination

At any time, and on termination, the customer may export their data as JSON from account settings. On deletion of the workspace — self-service or on written request — Pressbotics deletes the workspace record and everything scoped to it: sites and their encrypted credentials, agent keys, action and approval history, usage records, support threads and agent authorisation grants.

Content already published to the customer's own WordPress installation is not touched and remains the customer's. Records we are required to keep for financial reporting, and support issues already created in Linear, follow those providers' retention rules; the retention schedule on the privacy page sets out the detail.

9. Audit rights

Pressbotics will make available the information necessary to demonstrate compliance with these obligations and will respond in writing to a reasonable security questionnaire, no more than once per twelve months, within thirty days. Given the size of the team we do not offer on-site audits by default; where a customer's own regulator requires an inspection, we will agree a proportionate arrangement in good faith, at the customer's cost, on reasonable notice and without disrupting the service for other customers.

10. International transfers

Pressbotics and its subprocessors process data in the United States and, for edge delivery, globally. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor, and Module Three where Pressbotics onward-transfers to a subprocessor), together with the UK International Data Transfer Addendum where the UK GDPR applies. By entering into this addendum the parties incorporate those clauses by reference, with the particulars in section 2 above completing their annexes.

11. Term and precedence

This addendum takes effect when the customer begins using the service and continues for as long as Pressbotics processes customer data. Where it conflicts with the Terms of Service on the subject of data protection, this addendum prevails.

12. Signature

Accepting the Terms of Service accepts this addendum; no signature is required for it to apply. If your procurement process needs a countersigned copy, email info@pressbotics.com with your entity name, registered address and signatory, and we will return an executed version. Send bespoke DPA paper to the same address.

Last updated 13 September 2026. This page describes system behaviour as implemented; it is not legal advice and has not been reviewed by a lawyer.