Solution

A scheduler built for GDPR, run from Germany

BestPost is run by Livebox Studios in Oldenburg, Germany. The data processing agreement applies from day one, the servers sit in Germany, and your video files stay in the EU region of the storage provider. This is documented compliance work, not a certificate or a seal.

14 days free, no credit card.

bestpost.app/planer
0:58
summer-reel.mov
MOV4K60 fps1.2 GB
BNo double compression
Compressed once: only by the platform itself
Your file goes out untouched

BestPost is a social media scheduler run by Livebox Studios in Oldenburg, Germany. The Article 28 data processing agreement applies from your first day, servers run at netcup in Germany, and your video files are stored in the EU region of Cloudflare R2. Billing is in euros and you can cancel online without logging in.

German company, German law

The provider is Livebox Studios, owner Jeff Immega, based in Oldenburg, Germany. German law applies and the contract languages are German and English.

DPA without an email thread

The full data processing agreement is published on the site and becomes part of your contract through the terms as soon as you use BestPost commercially. A signed copy is available on request as a PDF.

Storage locations named openly

Servers operated by netcup GmbH (registered in Karlsruhe), processed in Germany, media files in the EU region of Cloudflare R2, AI features at OpenAI Ireland and only when you start them yourself. Each processor is listed with address and place of processing.

Where is my data actually stored?

BestPost runs on servers operated by netcup GmbH, a German provider, with Germany as the place of processing. netcup itself uses three subprocessors, all inside the European Economic Area: two Anexia entities in Klagenfurt, Austria, and one in Karlsruhe. Nothing in that chain leaves the EEA.

Your videos and images live in Cloudflare R2 object storage. BestPost uses the EU jurisdiction through the eu.r2.cloudflarestorage.com endpoint, so the files are stored in data centres inside the European Union. The honest part: Cloudflare, Inc. is a US company based in San Francisco. Its data processing agreement states adherence to the EU-US Data Privacy Framework, and if that certification lapses, the European Commission standard contractual clauses under implementing decision (EU) 2021/914 apply instead.

AI features run through OpenAI Ireland Ltd. in Dublin, and only when you trigger them. If you never start a transcription, a content analysis or a caption draft, nothing goes to the AI processor at all. Where an OpenAI group company outside the EEA processes data, that transfer runs on standard contractual clauses, and the contract with OpenAI does not allow your content to be used for model training.

Payments run through Stripe Payments Europe, Ltd. in Dublin together with Stripe, Inc. in the United States. Full card details are collected by Stripe only and never touch BestPost servers. For payment processing Stripe acts as its own controller, so it is not a subprocessor under the DPA.

  • netcup GmbH, registered in Karlsruhe: servers and outbound email, processed in Germany
  • Cloudflare, Inc., San Francisco: media files, stored in the EU region, DPF plus standard contractual clauses
  • OpenAI Ireland Ltd., Dublin: transcription, content analysis, caption drafts, only on active use
  • Stripe Payments Europe, Ltd., Dublin: payment processing, acting as its own controller

What does the BestPost DPA actually cover?

The BestPost data processing agreement is published in full and you do not have to request it. Once you use BestPost commercially and process personal data of other people, it becomes part of your contract through the terms, so it is in force from day one. If your records need a signed copy, you email info@bestpost.app with the subject DPA and your company name and address, and you get the contract back as a PDF.

It covers what an audit asks for: subject matter and duration, types of data, categories of data subjects, processing on documented instructions only, confidentiality, the full subprocessor list with addresses and places of processing, the technical and organisational measures under Article 32, support with data subject requests, and deletion or return of data. Personal data breaches are reported to you within 48 hours of BestPost becoming aware, which leaves you the rest of your own 72-hour window under Article 33.

Retention is specific rather than vague. Video files are deleted once the post has gone live on every platform you selected, and at the latest 14 days after the final post status. Image and carousel files deliberately have no automatic deadline: they stay until you delete them or delete your account, and the same applies to scheduled posts. Drafts are removed 14 days after they were created, and transcripts, subtitle files and AI analyses 90 days after the related media file is deleted. After the processing services end, deletion happens within 30 days at the latest, and immediately if you delete your account in the app. Backups roll over on a cycle, so a deleted item can survive in a backup for up to 30 days.

For access and portability requests you do not need to write to anyone. Settings include a self-service export that downloads your data as a JSON file: account data, platform connections, uploaded content, scheduled posts, publishing results, AI usage and billing records.

Who is this built for, and who is it not built for?

European tools that lead with data protection tend to sell to companies, agencies and public bodies. They ship approval workflows, social inboxes, monitoring and client reporting, and they price accordingly. BestPost goes the other way and serves the solo creator and the self-employed person who publishes 100 videos and more in a single run across Instagram, TikTok, YouTube, Facebook and X.

That means naming the gaps. BestPost has no approval workflow, no social inbox and no analytics reporting for clients. The smallest unit for separation, export and deletion is the account, not an individual brand inside it. If you need to hand over or delete one client, the DPA recommends running a separate account for that client.

BestPost holds no ISO 27001 certificate of its own. What the DPA does provide is a pass-through of the independent certifications held by the processors in use and where they can be verified publicly, plus evidence of Article 28 compliance on request, free of charge, usually within two weeks and as a completed audit questionnaire if you prefer.

On the commercial side, billing is in euros with tax included in the displayed price, business customers can enter a VAT ID at checkout, and reverse charge applies for businesses elsewhere in the EU. Cancellation works without logging in through a public cancellation form, through the customer portal in your account, or by email, as required by section 312k of the German Civil Code.

How it works

1

Read the legal texts first

The privacy policy, terms and data processing agreement are public, with no account and no contact form in the way. You can see the processor list and the places of processing before you sign up.

2

Sign up and the DPA is live

Use BestPost commercially and the DPA is part of your contract from day one through the terms. Nothing to request, nothing to wait for.

3

Ask for a signed copy if needed

If your records need a countersigned document, email info@bestpost.app with the subject DPA plus your company name and address, and the contract comes back as a PDF.

Common questions

Is there a GDPR-compliant social media scheduler?

Yes. BestPost is run by a German company, hosts on servers in Germany, stores media files in the EU region, publishes its Article 28 data processing agreement, names every subprocessor with address and place of processing, and sets binding retention periods. Note the wording: this is documented compliance work, not a certificate or a seal. Under GDPR you remain the controller for your commercial use and BestPost acts as your processor.

Do I need a DPA with my social media tool?

You need one as soon as you post commercially and the content involves personal data of other people, for example anyone visible or audible in your videos, or client channels you manage. Purely private use of your own content does not require it. With BestPost the agreement applies automatically through the terms, so there is nothing to sign before you start, and a countersigned PDF is available on request.

Where are my videos stored?

In Cloudflare R2 object storage, using the EU jurisdiction endpoint eu.r2.cloudflarestorage.com, which keeps the files in data centres inside the European Union. Cloudflare, Inc. is a US company, and the transfer rests on the EU-US Data Privacy Framework with standard contractual clauses as the fallback. A file only reaches a third country when you publish it to a platform based there or when you use an AI feature.

Is there a European alternative to US schedulers?

Yes, and BestPost is one built for creators rather than agencies. You get a German provider, EU storage, a DPA included, billing in euros, contract languages German and English, and online cancellation. What you do not get is an approval workflow, a social inbox or client reporting, so if your team needs those, a larger European suite fits better than BestPost.

Try it with your own videos

Upload your next batch and see how much time is left over. 14 days free, no credit card.

Start for free