GDPR Compliance
Last updated: January 1, 2026
PostMind AI is committed to compliance with the General Data Protection Regulation (GDPR) and UK GDPR for users in the European Economic Area and United Kingdom. This page summarizes your rights and our obligations. Full details are in our Privacy Policy.
Data controller
Legal bases for processing
- Contract (Art. 6(1)(b)): Account management, publishing, billing, and support.
- Legitimate interests (Art. 6(1)(f)): Security, fraud prevention, product improvement.
- Consent (Art. 6(1)(a)): Marketing emails and non-essential cookies.
- Legal obligation (Art. 6(1)(c)): Tax and financial record retention.
Your rights under GDPR
- Right of access — Request a copy of your personal data.
- Right to rectification — Correct inaccurate data in Settings or via request.
- Right to erasure — Delete your account under Settings → Account → Delete Account.
- Right to restriction — Limit processing in certain circumstances.
- Right to data portability — Export JSON via Settings → Download Your Data.
- Right to object — Object to processing based on legitimate interests.
- Rights related to automated decision-making — We do not make solely automated decisions with legal effect.
To exercise any right, email support@postmindai.pro. We respond within 30 days.
International transfers
Data may be processed in the United States. We use Standard Contractual Clauses (SCCs) with subprocessors and, where applicable, participate in recognized transfer frameworks. See Section 9 of our Privacy Policy.
Subprocessors
A current list of subprocessors (AWS, Stripe, OpenAI, Anthropic, Resend, etc.) is available in Section 3 of our Privacy Policy. Enterprise customers may request a Data Processing Agreement (DPA) at legal@postmind.ai.
Supervisory authority
You have the right to lodge a complaint with your local data protection authority. EU authorities are listed at edpb.europa.eu. UK residents may contact the ICO at ico.org.uk.
