GDPR Article 28 compliant · Version 1.0 · Effective 29 March 2026
Complete the form at the bottom of this page. We will email a countersigned PDF DPA within 2 business days. This DPA is suitable for GDPR, UK GDPR, and Indian DPDP Act compliance. No legal negotiation required for standard terms — enterprise custom DPAs available on request.
Request Signed DPA → Email legal@postlister.comIn this Agreement: "Controller" means the organisation whose employees use EngageLive; "Processor" means EngageLive / postlister.com; "Personal Data" means any information relating to an identified or identifiable person; "Processing" has the meaning given in GDPR Article 4(2); "GDPR" means Regulation (EU) 2016/679.
The Processor provides a real-time audience engagement platform that allows the Controller's employees (hosts) to run interactive sessions with participants. Processing occurs as follows:
| Data Element | Subjects | Purpose | Retention |
|---|---|---|---|
| Host account data (email, name, organisation) | Host/Controller staff | Authentication, plan management, session logging, purchase receipts, organisation features | Stored on Processor's encrypted MySQL server (Hostinger EU). Retained for lifetime of account. Deleted within 30 days of account deletion request. |
| Session activity data (poll responses, quiz answers, Q&A submissions) | Session participants | Real-time display to host and participants during session; post-session analytics for host | Flows through Firebase Realtime Database for real-time delivery during session. Aggregated results archived on Processor's encrypted MySQL server per plan retention schedule (30 days Free; 180 days Starter; unlimited Pro/Business). Individual response data minimised — only aggregates stored long-term. Firebase real-time copy deleted at session end. |
| Participant names and emails (optional, if enabled by host) | Session participants | Identify participants on leaderboard/responses; enable host follow-up if host enables email collection | Participant names associated with responses retained on Processor's encrypted server per plan retention schedule (same as response data above). Participant emails, if collected by host, are included in host's exportable session data and deleted after retention period. Participants can request deletion via the host or directly at support@postlister.com. |
| Purchase records | Employees of the Controller who purchase plans | Verify active plan, apply participant limit increase | Retained for 13 months from purchase date for accounting purposes, then deleted. |
The Processor shall process Personal Data only on documented instructions from the Controller. The Controller's use of EngageLive constitutes its instructions to process data as described in Section 2. The Controller warrants that its instructions comply with applicable law.
Personal Data processed through EngageLive may be transferred to the following locations:
| Data Type | Location | Transfer Mechanism |
|---|---|---|
| Session real-time messages (Firebase) | Google Firebase — asia-southeast1 (Singapore) | Google Cloud Standard Contractual Clauses; Firebase Data Processing Terms |
| Purchase records | Hostinger servers (EU — Lithuania) | GDPR Art. 3 — data processed within EU/EEA |
| Payment data | PayPal (USA/Luxembourg); PayU (India) | PayPal Standard Contractual Clauses; PayU DPDP compliance |
| Sub-processor | Purpose | Location | Privacy Policy |
|---|---|---|---|
| Google LLC (Firebase) | Real-time database for session messaging | Singapore (asia-southeast1) | policies.google.com/privacy |
| Hostinger International Ltd | Web hosting and file storage | Lithuania, EU | hostinger.com/privacy-policy |
| PayPal Holdings Inc | Payment processing (optional) | USA / Luxembourg | paypal.com |
| PayU Payments Pvt Ltd | Payment processing — India (optional) | India | payu.in |
| Cloudflare Inc | CDN, DDoS protection, SSL termination | USA (with EU servers) | cloudflare.com |
The Processor will notify the Controller of any intended changes to this list with at least 14 days' notice by email, giving the Controller the opportunity to object.
This Agreement remains in force for as long as the Controller's employees use EngageLive. Either party may terminate by providing 30 days' written notice. On termination, the Processor shall delete all Personal Data within 30 days.
This Agreement is governed by the laws of India, with GDPR Article 28 obligations interpreted in accordance with EU law. For Controllers in the EU/EEA/UK, EU/UK GDPR takes precedence over conflicting provisions of Indian law in respect of data protection obligations only.
Where Personal Data of EU/UK data subjects is transferred outside the EEA/UK, the parties agree to be bound by the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor) as published on 4 June 2021 (EU SCCs), which are incorporated into this Agreement by reference.
Email us directly at legal@postlister.com with the following details and we will send a countersigned PDF DPA within 2 business days:
We respond to all DPA requests within 2 business days. For urgent requests or custom enterprise DPAs, contact legal@postlister.com directly with "URGENT DPA" in the subject line. We do not share your details with any third party.