Data processing addendum
Last updated October 7, 2026
This addendum covers personal information we process on your behalf.
When this addendum applies
This addendum forms part of the Terms of Service between you and LILY DIA PTY LTD (ABN 72 676 064 181), trading as Maeve Social. It applies to personal information we process on your behalf through the Service ("Customer Data").
You determine the purposes of that processing and act as the controller or equivalent responsible party. We act as your processor or service provider. If you process information for a client, we act as your subprocessor and you must have authority to give us instructions.
Information we handle for our own business purposes, such as account administration, billing, and security, is covered by our Privacy Policy. Each party must comply with the privacy and data protection laws that apply to it. Mandatory law takes priority. This addendum takes priority over conflicting provisions of the Terms for processing Customer Data.
What we process
We store, organise, retrieve, analyse, transmit, publish, and delete Customer Data to provide the features you use, including content creation, collaboration, publishing, inboxes, analytics, advertising, and AI-assisted features. Processing continues for the period we provide those features and any permitted return or deletion period.
Customer Data may include names, contact details, account identifiers, profile information, media, messages, audience and campaign information, and other personal information you lawfully provide or authorise us to retrieve. It may concern your staff, contractors, clients, customers, followers, message contacts, or other people represented in your content. Its scope depends on your use of the Service.
Your instructions and responsibilities
Your use of the Service, its settings, and these Terms are your documented instructions. We will process Customer Data only on those instructions, including for transfers, unless applicable law requires otherwise. We will tell you about a legal requirement before processing where the law permits. We will not sell Customer Data or use it for our own advertising.
You must have a lawful basis, provide required notices, obtain required permissions, and give lawful instructions. If we believe an instruction infringes applicable data protection law, we will tell you and may suspend the affected processing while it is resolved. Additional instructions or services must be agreed in writing.
Confidentiality and security
We will restrict access to people who need it to provide the Service and who are bound by confidentiality obligations. We will maintain technical and organisational measures appropriate to the risks, including access controls, secure transmission, and measures to support the confidentiality, integrity, availability, and recovery of Customer Data. We will review those measures as the Service and risks change.
Service providers and overseas processing
You give general authorisation for us to use subprocessors to provide the Service, including hosting, communications, support, and AI providers. We will impose data protection obligations appropriate to their work and equivalent to the relevant obligations in this addendum. We remain responsible to you for their performance of those obligations. You can request their identities, roles, and processing locations from moc.laicoseveam@troppus.
We will give advance notice of intended additions or replacements and a reasonable opportunity to object on data protection grounds. We will work with you to resolve a reasonable objection. If it cannot be resolved, either party may end the affected service and we will refund prepaid fees for the unused portion of that service.
Processing may occur in the countries described in our Privacy Policy. We will use safeguards required by applicable law for overseas transfers. If your use requires specific transfer terms, such as EU Standard Contractual Clauses or the UK transfer addendum, contact us before that processing begins so the required terms and safeguards can be put in place. Those instruments are not incorporated by this addendum alone.
Connected networks and external services you choose may also process information independently under their own terms and privacy policies. This addendum does not govern that independent processing.
Requests and security incidents
Taking account of the processing and information available to us, we will assist you with individual rights requests, security obligations, breach notifications, and required privacy impact assessments or regulator consultations. If we receive a request about Customer Data, we will refer it to you where appropriate and respond only on your instructions or as required by law.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data. We will provide available information about its nature, likely consequences, and measures taken or proposed, with updates as we learn more, and cooperate with your response. Notification does not itself admit liability.
Return and deletion
When the affected service ends, we will, at your choice, return or delete Customer Data and delete remaining copies, unless applicable law requires retention. You can use available download and deletion controls or contact us to arrange this. Copies awaiting removal from backups will remain protected and isolated from ordinary use, and will be deleted through the applicable backup lifecycle, subject to any shorter deadline required by law or connected-network rules.
Information still controlled by another customer in a shared workspace follows that customer's instructions. Content already published to a network remains subject to that network's controls. Independent billing, security, and legal records follow the retention provisions in our Privacy Policy.
Compliance information and liability
We will make information reasonably needed to demonstrate compliance available to you and allow and contribute to audits required by applicable data protection law, including inspections by you or an auditor you appoint. We may agree reasonable arrangements for notice, confidentiality, and protection of other customers' information. These arrangements will not prevent legally required oversight.
The Terms' liability provisions apply to this addendum, subject to liabilities and rights that cannot lawfully be limited. It creates no separate or additional liability cap. Obligations concerning retained Customer Data continue until that data has been returned or deleted. Contact moc.laicoseveam@troppus with questions or requests about this addendum.