Legal
Terms and Privacy
These Terms of Service, Privacy Policy, and Data Processing Agreement set out the terms governing access to and use of the PromioAgent service, including the respective rights and obligations of PromioAgent and its customers in relation to service use, data protection, and data processing. Last updated: 8 May 2026.
Part A - Terms of Service
1. Introduction and Scope
These Terms of Service, together with the Privacy Policy and Data Processing Agreement set out below, constitute the agreement governing the provision and use of the PromioAgent service operated by PromioAgent, obrt za trgovinu, promidžbu i ostale usluge, vl. Diego Stanić, with registered address at Trg Drage Iblera 10, Zagreb, Croatia, OIB: 52504314980 (“PromioAgent”).
PromioAgent provides a software-as-a-service platform that helps business customers upload business images, configure preferences, generate AI-assisted captions, schedule posts, receive approval emails, and publish content to connected Instagram and Facebook accounts. The service is intended for business use only.
By accessing or using the service, the Customer agrees to be bound by this Agreement. If the Customer does not agree to this Agreement, the Customer must not access or use the service.
The Customer must provide accurate account and billing information, keep login credentials secure, and is responsible for all activity under its account. If the Customer connects Instagram, Facebook, or other social media accounts, the Customer represents that it has the authority to manage and publish content for those accounts, pages, or profiles, including any required Business or Creator account permissions.
2. Nature of the Service
The service is designed and operated primarily for the processing of business-related data. PromioAgent does not require the submission of personal data for the core functionality of the service and does not actively seek to collect personal data through Customer content.
The Customer may, at its discretion, upload, submit, generate, or otherwise make available content that includes personal data, including names, images, social media identifiers, or other information relating to identifiable individuals. PromioAgent does not determine the content, nature, or lawfulness of such data and processes it only in accordance with the Customer’s documented instructions, except where otherwise required by applicable law.
The Customer acknowledges that any personal data processed through Customer content is introduced by the Customer and remains under the Customer’s control and responsibility.
3. Customer Responsibilities, Content and Acceptable Use
The Customer is solely responsible for all content uploaded, submitted, generated, scheduled, or published through the service. This responsibility includes ensuring that such content, and any personal data contained in it, is processed lawfully, fairly, and transparently in accordance with all applicable privacy, data protection, electronic communications, consumer protection, marketing, and platform laws, including the GDPR where applicable.
The Customer shall ensure that it has an appropriate legal basis, permission, consent, authorisation, or other lawful ground required under applicable privacy and data protection laws for any personal data processed through the service. The Customer shall also ensure that all required privacy notices, disclosures, and information have been provided to relevant individuals. PromioAgent is not responsible for monitoring, reviewing, or verifying the legality of Customer content.
The Customer retains all rights, title, and interest in and to images, instructions, captions, business content, and other content uploaded, input, generated, or published through the service. The Customer grants PromioAgent a limited, non-exclusive, worldwide, royalty-free licence to host, store, process, generate, modify, transmit, display, schedule, and publish Customer content solely for the purpose of providing and improving the service in accordance with the Customer’s settings and instructions.
The Customer represents and warrants that it has all rights, permissions, consents, and authorisations necessary to upload, process, generate, schedule, and publish Customer content, including rights relating to individuals, images, brands, trade marks, locations, products, music, or other protected material appearing in such content.
The Customer shall not use the service to create, upload, schedule, or publish unlawful, misleading, harmful, infringing, discriminatory, spam, abusive, or platform-violating content. PromioAgent may suspend or restrict access to the service where use of the service creates legal, security, platform, operational, or abuse risk.
AI-assisted outputs may be inaccurate, incomplete, unsuitable, or inappropriate for a particular use. PromioAgent does not guarantee that such outputs are unique, accurate, or free of third-party rights, and similar or identical outputs may be generated for other users. Dashboard controls and approval email functionality are provided to support Customer review, editing, cancellation, or approval of content. The Customer remains responsible for reviewing, verifying, and determining the suitability, legality, accuracy, and compliance of all generated or published content.
Where the Customer uses the service to publish or transmit content to third-party platforms, including social media platforms, such platforms may acquire rights to use that content in accordance with their own terms and policies. PromioAgent does not claim ownership of Customer content and is not responsible for any use of Customer content by third-party platforms.
4. Intellectual Property and Use of the Service
All intellectual property rights in and to the PromioAgent service, including its software, source code, object code, algorithms, architecture, user interface, design, workflows, models, databases, trade secrets, and underlying technology, are and shall remain the exclusive property of PromioAgent or its licensors. Nothing in this Agreement transfers or assigns any such rights to the Customer.
Subject to this Agreement, the Customer is granted a limited, non-exclusive, non-transferable, and non-sublicensable right to access and use the service solely for its internal business purposes.
The Customer shall not, and shall not permit any third party to, reverse engineer, decompile, disassemble, copy, modify, adapt, create derivative works from, scrape, benchmark, extract data, models, workflows, or other proprietary elements from, or otherwise attempt to derive the source code, underlying ideas, algorithms, structure, or organisation of the service, except to the extent expressly permitted by this Agreement or applicable law. The Customer shall not use the service to develop, train, or improve any competing product or service or circumvent any technical or contractual restrictions imposed by the service.
The Customer acknowledges that the service contains confidential information and trade secrets, including algorithms, AI-related configurations, prompt structures, workflows, and system logic. The Customer shall not access, use, disclose, or exploit such information except as strictly necessary for permitted use of the service and shall take reasonable measures to prevent unauthorised access to or misuse of the service.
If the Customer provides suggestions, ideas, feedback, or recommendations regarding the service, PromioAgent may use, disclose, reproduce, modify, and otherwise exploit such feedback without restriction or obligation to the Customer.
5. Subscription, Billing, Invoices and Taxes
PromioAgent may offer paid subscription plans, including a free trial where stated during checkout. Unless otherwise stated, a valid payment method may be required to start a trial. After the trial period, the subscription renews at the displayed price and billing interval unless cancelled before the end of the trial or applicable renewal date.
Billing, payment processing, subscription management, and customer portal functionality may be provided by Stripe or another payment service provider. The Customer may manage billing and cancellation through the available customer portal or other method provided by PromioAgent. Refunds, if any, are provided only as required by applicable law or as expressly stated at checkout.
PromioAgent, obrt za trgovinu, promidžbu i ostale usluge, vl. Diego Stanić is currently not in the Croatian VAT system. Prices, taxes, and charges are displayed according to the checkout configuration and applicable tax rules. The Customer is responsible for providing complete and accurate billing information. Where Croatian B2B e-invoicing, fiscalisation, or other invoicing requirements apply, PromioAgent may issue compliant invoices through a Croatian accounting or e-invoice provider in addition to payment records generated by the payment service provider.
6. Liability and Disclaimer
The service is provided on an “as is” and “as available” basis, to the maximum extent permitted by applicable law. PromioAgent does not warrant that the service, integrations, schedules, AI outputs, approval emails, or publishing actions will be uninterrupted, error-free, complete, accurate, or free from security vulnerabilities.
To the maximum extent permitted by applicable law, PromioAgent shall not be liable for the legality, accuracy, completeness, or compliance of Customer content, including any personal data included in such content. The Customer remains solely responsible for ensuring that its use of the service complies with applicable laws, third-party rights, and platform terms.
To the maximum extent permitted by applicable law, PromioAgent’s aggregate liability arising out of or in connection with the service shall be limited to the amounts paid by the Customer for the service during a reasonable period preceding the event giving rise to the claim, except to the extent such limitation is prohibited by applicable law.
7. Changes to these Terms
PromioAgent may update this Agreement from time to time as the service evolves or as required for legal, operational, or security reasons. Material changes shall be communicated through the service, by email, or on the website where appropriate. Continued use of the service after the effective date of an updated Agreement constitutes acceptance of the updated terms.
Part B - Privacy Policy
4. Roles of the Parties under Data Protection Law
To the extent personal data is processed in Customer content or otherwise on behalf of the Customer through the service, the Customer determines the purposes and means of such processing and is responsible for complying with applicable privacy and data protection laws. PromioAgent processes such personal data only on behalf of the Customer and in accordance with the Customer’s documented instructions, except where applicable law requires otherwise.
PromioAgent acts independently for limited processing activities necessary to operate, administer, secure, and improve the service, including account administration, authentication, subscription management, billing support, service communications, and security-related processing, when personal data is processed for those purposes.
5. Categories of Data Processed
In its capacity as controller, PromioAgent may process account and service administration data, including email address, authentication data, business name, business type, custom business type, business profile information, subscription status, support communications, customer identifiers, subscription identifiers, payment status information, approval email settings, user interface language preferences, and other account or service preferences selected by the Customer. Payment card data is processed by the relevant payment service provider and is not stored by PromioAgent.
In its capacity as processor, PromioAgent may process Customer content and related service data, including uploaded images, original file names, storage paths, image URLs, text, generated captions, rewritten captions, scheduling information, post preferences, chat instructions, publishing instructions, publishing logs, cancellation tokens, brand memory, avoid rules, and other content or information submitted, generated, or configured by the Customer through the service.
PromioAgent may also process technical and integration data necessary to enable the service, including authentication cookies, session data, social media account identifiers, OAuth codes, access tokens, connected account information, device and connection data, system logs, publishing status information, error logs, and data required for security, troubleshooting, maintenance, token refresh, and service operation.
6. Service Architecture and Processing Flow
The service is provided through a browser-based application and supporting cloud infrastructure. PromioAgent processes technical data necessary to operate and secure the website and service.
When a Customer creates or uses an account, PromioAgent and its service providers process authentication data, account profile data, service preferences, uploaded content, scheduled posts, generated captions, connected social media channel information, billing status, and related service records as necessary to provide the service.
Where the Customer uses AI-assisted generation, third-party integrations, payment functionality, approval emails, location or weather-based features, or automated publishing, PromioAgent may share the data necessary to provide those features with the relevant service providers or platforms.
7. Legal Bases for Processing
Where PromioAgent acts as controller, it processes personal data where necessary for the performance of a contract, compliance with legal obligations, and the pursuit of legitimate interests, including operating, securing, maintaining, and improving the service.
Where PromioAgent processes personal data on behalf of the Customer, it does so pursuant to this Agreement, including the Customer’s documented instructions. The Customer is responsible for identifying, documenting, and maintaining an appropriate legal basis, permission, consent, authorisation, or other lawful ground required for the underlying processing of personal data submitted to or processed through the service under applicable privacy and data protection laws.
8. Third-Party Services and Independent Controllers
The service may rely on third-party providers for hosting, application infrastructure, authentication, database and storage services, artificial intelligence functionality, email delivery, payment processing, analytics, customer support, location search, weather or event context, scheduled automation, and social media integrations. Such providers may include Vercel, Supabase, OpenAI, Stripe, Resend, Google Places, Open-Meteo, Meta, Facebook, Instagram, and other service providers used to operate or improve the service.
Payment processing is provided by Stripe or another applicable payment service provider, which acts as an independent controller in relation to payment data processed through its services. Such processing is governed by the payment provider’s own terms and privacy documentation.
Where the Customer connects or publishes content to third-party social media platforms, including Facebook or Instagram, those platforms act as independent controllers for processing carried out on their respective services. Content published to such platforms is subject to the applicable platform terms, policies, and privacy documentation.
PromioAgent does not control, and is not responsible for, the processing activities, terms, privacy practices, availability, outages, rejected posts, account restrictions, API decisions, or changes made by independent third-party services or platforms.
9. International Data Transfers
PromioAgent and its service providers may process personal data in jurisdictions other than the country or region in which the Customer or individuals are located. Where personal data is transferred internationally, PromioAgent shall implement appropriate safeguards or rely on lawful transfer mechanisms required by applicable privacy and data protection laws, including standard contractual clauses or equivalent mechanisms where applicable.
10. Data Retention and Account Deletion
PromioAgent retains personal data only for as long as necessary to provide the service, administer the Customer account, comply with legal obligations, resolve disputes, enforce agreements, and maintain appropriate business records. Customer content is retained for the duration of the Customer’s active use of the service, unless deleted earlier by the Customer.
Upon termination of the service or deletion of the Customer account, PromioAgent shall delete or anonymise personal data within a reasonable period, unless retention is required by applicable law or is reasonably necessary for the establishment, exercise, or defence of legal claims.
If the Customer deletes its account, PromioAgent shall take reasonable steps to delete the relevant user account, profile records, scheduled posts, image metadata, chat messages, service instructions, and uploaded images from the applicable systems, subject to technical limitations, backup retention, legal obligations, and any retention necessary for the establishment, exercise, or defence of legal claims. Where an active subscription exists, PromioAgent may attempt to cancel or update the related subscription status through the applicable payment provider.
11. Data Subject Rights
Where PromioAgent processes personal data for its own purposes, individuals may exercise rights available to them under applicable privacy and data protection laws, which may include rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent, or appeal, by contacting PromioAgent using the contact details set out in this Agreement.
Where PromioAgent processes personal data on behalf of the Customer, requests from individuals relating to Customer content should be directed to the Customer. PromioAgent shall provide reasonable assistance to the Customer, taking into account the nature of the processing, the information available to PromioAgent, and the requirements of applicable privacy and data protection laws.
Part C - Data Processing Agreement
12. Security
PromioAgent shall implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, as further described in Annex 2 – Technical and Organisational Measures. The Customer acknowledges that no service or transmission method can be guaranteed to be completely secure.
13. Processor Obligations
This Section applies to the extent PromioAgent processes personal data on behalf of the Customer under applicable privacy and data protection laws.
PromioAgent shall process personal data only on documented instructions from the Customer, unless required to do so by applicable law. PromioAgent shall ensure that persons authorised to process personal data are subject to appropriate confidentiality obligations.
PromioAgent shall implement appropriate technical and organisational measures to protect personal data and shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer.
PromioAgent may engage subprocessors to support the provision of the service, provided that such subprocessors are subject to data protection obligations that are substantially equivalent to those set out in this Agreement. PromioAgent shall remain responsible for the performance of its subprocessors to the extent required by applicable law.
Taking into account the nature of the processing and the information available to PromioAgent, PromioAgent shall provide reasonable assistance to the Customer in fulfilling obligations relating to individual rights, security of processing, personal data breach notifications, privacy or data protection impact assessments, and consultations or communications with supervisory, regulatory, or governmental authorities where required by applicable law.
Upon termination of the service, PromioAgent shall, at the Customer’s choice where feasible, delete or return personal data processed on behalf of the Customer, unless retention is required by applicable law.
PromioAgent shall make available information reasonably necessary to demonstrate compliance with this Section and shall allow for and contribute to audits or inspections where required by applicable privacy and data protection laws, subject to reasonable confidentiality, security, and operational limitations.
14. Contact
Questions relating to this Agreement or the processing of personal data may be directed to PromioAgent at: promio.business@gmail.com.
Annex 1 - Third Party Service Providers
This Annex identifies the third-party service providers that PromioAgent may use to support the provision, operation, security, maintenance, and improvement of the service. To the extent such providers process personal data on behalf of PromioAgent in connection with the service, they are considered subprocessors for the purposes of this Agreement. Where a provider acts as an independent controller, this is indicated below.
Vercel - Hosting, deployment, application infrastructure, serverless functions, and scheduled jobs. Categories of data processed: technical request data, device and connection data, application logs, and service operation data. Role / notes: subprocessor for hosting and infrastructure services.
Supabase - Authentication, database, storage, session management, and email confirmation functionality. Categories of data processed: account data, authentication data, profile data, service preferences, uploaded images, image metadata, scheduled posts, tokens, and related service records. Role / notes: subprocessor for authentication, database, and storage services.
OpenAI - AI-assisted content generation, caption generation, rewriting, and related language-processing functionality. Categories of data processed: customer-selected context, business type, tone, language, location, brand memory, avoid rules, uploaded images or image references where applicable, existing posts, captions, and scheduling instructions. Role / notes: subprocessor for AI functionality, to the extent personal data is included in submitted prompts or generated content.
Stripe - Payment processing, checkout, billing portal, subscription management, and payment status notifications. Categories of data processed: billing identifiers, subscription identifiers, payment status, customer identifiers, transaction-related metadata, and payment information. Role / notes: generally acts as an independent controller for payment data and may also process limited service-related data as a provider.
Resend - Transactional and approval email delivery. Categories of data processed: email address, caption preview, image preview or reference, scheduled time, cancellation link or token, and email delivery metadata. Role / notes: subprocessor for email delivery services.
Google Places - Location search and place lookup functionality. Categories of data processed: location search queries and related location results selected or used by the Customer. Role / notes: provider of location search functionality; may act under its own terms and privacy documentation.
Open-Meteo - Weather-aware content context. Categories of data processed: location-related weather query data and weather response data used to support content generation. Role / notes: provider of weather data functionality.
Meta / Facebook / Instagram - Social media authentication, connected account management, token exchange, token refresh, and publication of content to connected channels. Categories of data processed: OAuth codes, access tokens, connected account information, page or profile identifiers, captions, image URLs or files, publishing status, error messages, and scheduled publishing information. Role / notes: independent controllers for processing on their own platforms; may also receive data necessary to enable Customer-directed publishing integrations.
PromioAgent may update this Subprocessor List from time to time to reflect changes in the service, vendors, integrations, or supporting infrastructure. Where required by applicable data protection law or contract, PromioAgent shall provide notice of material changes to subprocessors and allow the Customer to object on reasonable data protection grounds.
Annex 2 - Technical and Organisational Measures
This Annex describes the technical and organisational measures implemented or maintained by PromioAgent to protect personal data processed in connection with the service. The measures are designed to ensure a level of security appropriate to the nature, scope, context, and purposes of processing and the risks presented by the service.
1. Governance and Confidentiality
PromioAgent limits access to personal data to authorised personnel and service providers who require access for the operation, support, security, maintenance, or improvement of the service. Persons authorised to process personal data are subject to appropriate confidentiality obligations, whether by contract, professional obligation, or equivalent commitment.
2. Access Control and Authentication
The service uses authentication and session management mechanisms to control access to Customer accounts and protected service functionality. Supabase Auth is used to support account authentication and session handling. PromioAgent uses access controls intended to restrict access to account data, Customer content, uploaded images, scheduled posts, connected channel information, and other service records to authorised users and systems.
3. Session, Cookie, and OAuth Security
PromioAgent uses session cookies and temporary OAuth state cookies to support authenticated sessions and social media connection flows. OAuth state validation and token handling measures are used to reduce the risk of unauthorised connection of third-party accounts. Access tokens used for connected social media channels are processed only as necessary to enable Customer-directed publishing, token refresh, and related integration functionality.
4. Encryption and Transmission Security
PromioAgent relies on secure infrastructure providers and standard transport security measures to protect data transmitted between the browser, application, and supporting service providers. Where appropriate and supported by the relevant provider, data is protected by encryption or equivalent safeguards in storage and transmission.
5. Infrastructure and Hosting Security
The service is hosted and operated using reputable cloud and application infrastructure providers. PromioAgent relies on such providers for physical security, infrastructure availability, platform security, deployment controls, and related operational safeguards. Application components are designed to separate public pages from authenticated dashboard functionality and protected API routes.
6. Logging, Monitoring, and Error Handling
PromioAgent may maintain system logs, publishing logs, error records, and service operation records for security, troubleshooting, support, maintenance, prevention of duplicate automated publishing, and investigation of failed or unauthorised activity. Logs are retained only for as long as reasonably necessary for the relevant operational or legal purpose.
7. Automated Publishing Controls
The service includes controls intended to support reliable automated publishing, including scheduled job execution, publishing status updates, error tracking, and atomic claim logic designed to reduce the risk of duplicate publication. Where approval email functionality is enabled, Customers may receive advance notice of scheduled posts and may cancel specific posts through the applicable cancellation mechanism.
8. Data Backup, Retention, and Deletion
PromioAgent retains personal data only as described in this Agreement and uses reasonable measures to delete or anonymise personal data when it is no longer required. Upon account deletion, PromioAgent takes reasonable steps to delete relevant account records, profile data, posts, image metadata, uploaded images, chat messages, and service instructions from applicable active systems, subject to backup retention, legal obligations, and technical limitations.
9. Incident Response and Breach Notification
PromioAgent shall investigate suspected security incidents affecting the service and shall take reasonable steps to mitigate identified risks. Where PromioAgent becomes aware of a personal data breach affecting personal data processed on behalf of the Customer, PromioAgent shall notify the Customer without undue delay and provide reasonable information available to PromioAgent to assist the Customer in meeting applicable breach notification obligations.
10. Subprocessor and Vendor Management
PromioAgent selects service providers and subprocessors that are reasonably appropriate for the relevant processing activity and relies on contractual, technical, and organisational safeguards provided by those providers. Subprocessors are used only to support the provision, operation, maintenance, security, or improvement of the service, as further described in Annex 1.
11. Availability and Resilience
PromioAgent uses cloud-based infrastructure and scheduled automation to support the availability and resilience of the service. The Customer acknowledges that availability may depend on third-party providers, social media platforms, payment providers, internet connectivity, and external APIs, and that no service can be guaranteed to be uninterrupted or error-free.
12. Review and Improvement
PromioAgent may review and update its technical and organisational measures from time to time to reflect changes in the service, technology, legal requirements, risks, and operational practices. Such updates shall not materially reduce the overall level of protection for personal data processed through the service.