LazyRelay
← Back to home

Data Processing Addendum

Last updated 11 August 2026

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer," the data controller) and IPE Projects (Pty) Ltd, trading as LazyRelay, a company registered in South Africa (registration number 2021/003176/07) ("LazyRelay," the data processor). It applies whenever LazyRelay processes personal data on your behalf as part of providing the Service, and reflects our obligations under Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent UK GDPR requirements. By using LazyRelay, you and LazyRelay agree to this DPA — no separate signature is required, though a countersigned copy is available on request (email [email protected]).

Subject matter and duration

LazyRelay processes personal data on your behalf for as long as you have an active LazyRelay account, solely to provide the scheduling, publishing, and related features described in our Terms of Service.

Nature and purpose of processing

LazyRelay processes personal data to: connect to and publish content on the social media accounts you authorize; verify that published posts are genuinely live; show you comments and direct messages sent to your connected accounts; classify comments/messages that may need your attention using AI; generate caption, hashtag, and content suggestions using AI; and provide customer support, including through our AI support assistant.

Types of personal data processed

Categories of data subjects

LazyRelay's obligations as processor

LazyRelay agrees to:

Sub-processors

You give LazyRelay general authorization to engage the sub-processors below, each of which is bound by its own data protection agreement with LazyRelay incorporating GDPR Standard Contractual Clauses for any transfer outside the EU/UK:

If LazyRelay adds or replaces a sub-processor that would materially change how your personal data is handled, we'll update this page and, where appropriate, notify you directly at least 14 days in advance. You may object on reasonable data-protection grounds within that period; if we can't resolve your objection, either you or LazyRelay may terminate the affected part of the Service without penalty.

International transfers

Personal data processed under this DPA may be transferred to and processed in the United States (via Render, Anthropic, Resend, and Paddle) as well as the EU (via Supabase). Each such transfer is covered by Standard Contractual Clauses under that sub-processor's own data processing agreement, as referenced above.

Security

Social media access tokens are encrypted and stored separately from ordinary database records, accessible only through LazyRelay's own backend — never as plain text in any table. Connections between your browser, LazyRelay, and our infrastructure providers use encrypted connections. Comments and direct messages are read on demand and not persisted beyond a short classification tag. See our Privacy Policy for further detail.

Data subject rights

If someone contacts LazyRelay directly with a GDPR request about data you control (e.g. someone who commented on your connected account), we'll forward it to you rather than act on it ourselves, since you're the controller of that relationship. If you receive a request you need our help with, email [email protected].

Personal data breach notification

If LazyRelay becomes aware of a personal data breach affecting your data, we'll notify you without undue delay, with what we know at the time (nature of the breach, likely consequences, and measures taken or proposed) — promptly enough for you to meet your own regulatory notification deadlines.

Data return and deletion

When you delete your LazyRelay account, we remove your stored content and connected-account access tokens within a reasonable time, per our Data Deletion page. If you need a copy of your data returned before deletion, email [email protected].

Liability

Liability under this DPA is subject to the limitations set out in our Terms of Service. If LazyRelay materially breaches this DPA and doesn't fix it within a reasonable time after you notify us, you may terminate the affected Service at no further cost, regardless of your plan's usual cancellation terms.

Governing law

This DPA is governed by the laws of South Africa, where IPE Projects (Pty) Ltd is registered, without prejudice to any mandatory data protection rights you have under the GDPR, UK GDPR, or other law that applies to you directly.