Skip to content
Inkstand

legal

Data processing

Processor terms for customers who control personal data in the product. Clause 7 is the one your data protection lead will want.

Version 0.3Effective 29 July 202612 min readTouch Grass AB

Written from the system, not from a template. Every statement here describes what the software actually does — the region, the sub-processors, what is collected, what is retained, what leaves the EEA. It is a description of a system rather than legal advice, and it is published rather than sent after a call. If your counsel needs redlines, or your own paper, that is a conversation and not a problem.

This agreement is between Touch Grass AB and the customer whose account uses Inkstand. It forms part of the terms of service and applies automatically wherever the service is used to process personal data. No signature is needed for it to apply; if you need a countersigned copy for your file, ask.

Contents — 12 clauses

1Roles#

1.1Where you use Inkstand to process personal data — a name in a testimonial, a client contact in a brief, a colleague's face in an uploaded photograph — you are the controller and we are the processor.
1.2We process that data only on your documented instructions. Your instructions are the configuration of your account and its workspaces, and the actions your people take in the product, plus anything else we agree in writing. This agreement is itself a documented instruction.
1.3If an instruction appears to us to breach data protection law, we will tell you and may decline to act on it until it is resolved. If we are required by EU or Swedish law to process for another reason, we will tell you first unless that law forbids it.
1.4We are the controller, not your processor, for the account data described in clause 2 of the privacy notice. That data is outside this agreement.

2What is processed#

The subject matter, duration, nature and purpose of the processing, the categories of personal data and the categories of data subjects are set out in annex I. It is written to be transferred into your Article 30 record without rewriting.

3Confidentiality#

3.1Everyone we authorise to process personal data is bound by an obligation of confidentiality that survives their engagement ending.
3.2Access is limited by database policy rather than by internal instruction. A platform administrator can read account names, membership, workspace names, invitations and governance records, and cannot read carousels, projects, uploaded assets or templates, because no policy grants it. Administrator status cannot be granted from inside the product.

4Security#

4.1We implement the technical and organisational measures set out in annex II, having regard to the state of the art, the cost of implementation, and the risk to data subjects.
4.2Annex II names what is absent as well as what is present. We hold no certification and have commissioned no independent audit or penetration test, and we do not claim otherwise anywhere. Measures may change, but not so as to materially reduce protection.

5Sub-processors#

5.1You give a general authorisation for us to engage the sub-processors published on the sub-processors page, which is annex III to this agreement.
5.2We will announce an addition or replacement at least 30 days before it begins processing, by email to account owners. You may object on reasonable data protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected part of the service without penalty.
5.3Each sub-processor is engaged under terms imposing obligations no less protective than these, and we remain fully liable to you for their performance.

6Where processing happens#

6.1The database, authentication and file storage are in the European Union — Stockholm. There is one region and no option to select another. Personal data at rest does not leave the EEA.
6.2Both parties to this agreement in the ordinary case are established in the EEA — you wherever you are established, and us in Sweden — so the only transfer question is the one in clause 7.

7Transfers outside the EEA#

7.1Four functions transfer content outside the EEA and they are the only ones that do. Each is triggered by a deliberate user action; none runs on a schedule, on save, or on export.
FunctionWhat is sentStatus today
Deck generationThe brief and the brand voice rules, to produce slide copy.Live in the product.
Brand-guideline readingThe text extracted from a brand document you supply.Live in the product.
Deck compliance reviewThe text of the deck being edited, with the voice rules.Reachable from the editor on request. Not wired into the export gate, and every release record states that AI review did not run.
Claim researchThe claim being checked, plus a web search of the sources you nominate.Deployed but not reachable from the interface. When it is, the claim text will reach a search provider as well as a model.
7.2Transfers are made through a routing service which forwards to a model provider. The specific model is recorded against each generation and each release, so "which model saw this content" is answerable for a named piece of work rather than in general.
7.3The basis for those transfers is the standard contractual clauses adopted by the European Commission, as incorporated in each sub-processor's own data processing terms, together with their supplementary measures. We rely on those clauses rather than entering into our own with each model provider, and we have not carried out and published a transfer impact assessment of our own. If your assessment requires one, say so before you enable these features — that is a real gap, not a formality.
7.4Retention by the model provider is governed by that provider's terms and by our account configuration, currently Not by default. Routing can be restricted to providers that do not retain the payload, and that restriction is requested per call rather than set on the account — but it rules out the fastest providers for a given model and costs roughly forty per cent in latency, so it is an entitlement for accounts that need the guarantee rather than something applied to everyone. Where it is not requested, content sent for generation is handled under the routing provider’s own terms.. We do not use your content to train models and neither we nor a sub-processor is permitted to under those terms.
7.5You can run the whole product without any transfer. The rule engine that performs deterministic checking runs in the browser, the editor and export are local, and the governance record is written in-region. Do not use the four features above for content containing personal data you cannot lawfully transfer.

8Assisting you with data subject requests#

8.1If a data subject contacts us about data we process for you, we will not respond to the substance ourselves. We will tell you without undue delay and let you answer.
8.2We will assist you with access, rectification, erasure, restriction, portability and objection, by appropriate technical and organisational measures, so far as is possible. That assistance is manual today. There is no self-service flow that locates and exports or erases the data of a named individual across an account. The data is straightforward to find because everything is keyed to a workspace, and the work is done by hand.
8.3Assistance is at no charge for a reasonable volume of requests.

9Breach notification, impact assessments and consultation#

9.1We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, with the nature of the breach, the categories and approximate numbers involved, the likely consequences, and the measures taken. Where we cannot give all of it at once we will give it in stages rather than delay the first notification.
9.2There is no written incident response runbook. The statutory obligation stands regardless, and describing a rehearsed process that has not been rehearsed would be the precise failure this product exists to catch.
9.3We will provide reasonable assistance with a data protection impact assessment and with prior consultation of a supervisory authority, so far as the information is ours to give.

10Audit and information#

10.1We will make available the information needed to demonstrate compliance with this agreement. Most of it is published in advance on the security page, including a questionnaire answered before it is sent.
10.2You may audit once in any twelve-month period, and additionally after a personal data breach affecting you, on thirty days' notice, at your cost, under confidentiality, and without disrupting the service or reaching another customer's data. A questionnaire and a call will normally do it.
10.3You may commission a penetration test against a test account with our written agreement on scope and timing. We would rather have the report than not.

11Deletion and return#

11.1You can export your own data at any time without asking us: artwork as PNG and PDF, the governance record as JSON. Nothing is held in a format only we can read.
11.2On termination we will, at your choice, delete or return the personal data we process for you, and delete existing copies, within ninety days — subject to clause 11.3 and to backups, which expire on the platform's own cycle and are not selectively editable.
11.3The exception, stated plainly. Export and generation records are insert-only in the database and cannot be edited or deleted by anyone, including us. They hold the identity of the person who released something, the wording they acknowledged, a fingerprint of the content, the rule snapshot and the findings, which can quote short fragments of the content checked. They are deleted when the workspace they belong to is deleted. If your retention policy cannot accommodate a record that the audited party cannot erase, raise it before you start, because it is a property of the schema and not a setting.

12Liability, precedence and duration#

12.1This agreement applies from the first use of the service and continues while we process personal data for you.
12.2Where this agreement and the terms of service conflict on a data protection matter, this agreement wins. Everything else, including the limitation of liability in clause 16 of the terms, applies to this agreement as well and is not increased by it.
12.3Where the UK GDPR applies to your processing, references here to the GDPR are read as the UK GDPR and references to a supervisory authority as the Information Commissioner. We have not appointed an Article 27 representative in the UK.

Annex IDescription of the processing

Written to be copied into your record of processing activities without editing. Where a row is short, it is short because the system is.

HeadingDetail
ControllerThe customer whose account holds the data.
ProcessorTouch Grass AB, a private limited company (aktiebolag) registered in Sweden since 2024, registration number 559484-7435, Idunsgatan 46, 214 46 Malmö, Sweden.
Subject matterComposition, rule-checking, review and export of social media content.
DurationFor as long as the account exists, plus the deletion window in clause 11.
Nature of processingStorage, structured retrieval, rendering, rule evaluation, transmission to an AI provider where a user asks for it, and the writing of insert-only audit records.
PurposeProducing and releasing brand-compliant marketing content, and evidencing what was released and on what basis.
Categories of data subjectUsers of the account; people named or depicted in content the customer creates or uploads; external reviewers sent a review link; recipients of an invitation.
Categories of personal dataEmail address and display name; content and images the customer supplies, which may contain any personal data the customer chooses to include; a reviewer's self-typed name, role and comments; the identity of the person who released a piece of content and what they acknowledged.
Special category dataNone is requested and none is required. The service is not designed for it. If a customer places it in content, the customer must satisfy itself of a lawful basis under Article 9.
Children’s dataNot requested. The service is not directed at children.
FrequencyContinuous for storage; on user action for rule checking, transfer to an AI provider and export.

Annex IITechnical and organisational measures

What is in place, drawn from the running system, and what is absent. The absences are here because a measures annex that lists only strengths is one nobody can rely on.

In place

  • Tenant isolation in the database. Row-level security on every table, keyed to account membership through a single shared function, asserted on every run by more than a hundred and fifty automated checks against a real database covering reads, writes, member enumeration, unaffiliated users, audit records, role enforcement, review links and brand-scoped access.
  • Encryption in transit. HTTPS throughout; HSTS with a two-year max-age, includeSubDomains and preload; TLS to the database and to storage.
  • Encryption at rest, provided by the managed database and object storage platform. We do not operate our own disks and do not manage our own keys.
  • No stored passwords. Sign-in is a one-time link to an email address, so there is no credential to leak or reuse.
  • Private asset storage. Uploads go to a private bucket with an allow-list of types and size caps, served only through signed URLs that expire in an hour, with the path prefix as the authorisation key.
  • Least privilege for our own staff, enforced by policy rather than instruction, as described in clause 3.2. Administrator status is seeded out of band.
  • Insert-only audit records for every release and every generation, not editable by the account owner or by us.
  • Time-bound access grants. Invitations are single-use, address-bound and expire in fourteen days. Review links carry a mandatory expiry and can be revoked.
  • Response headers: nosniff, frame-ancestors denied, strict-origin-when-cross-origin referrer policy, and camera, microphone and geolocation denied.
  • Server-side fetch hardening on the one feature that retrieves a URL you supply: non-HTTP schemes, private and link-local addresses, intranet names, unbounded bodies and redirect chains are refused. It does not defeat DNS rebinding, which is documented in the code as well as here.
  • Secret separation. The browser bundle carries only the public key that every row-level policy applies to. The policy-bypassing key and the model-provider key exist only inside server-side functions.
  • Automated testing before release: more than 800 tests on the compliance and rendering logic, plus the isolation checks above.
  • A small dependency surface, treated as a control: eleven runtime packages, and two features written in-house rather than add a sub-processor.

Not in place

  • No SOC 2, ISO 27001 or Cyber Essentials, and none in progress.
  • No independent penetration test has been commissioned.
  • No SSO, SAML, SCIM or multi-factor authentication. Sign-in is mailbox possession.
  • No configurable session timeout and no forced re-authentication interval.
  • No IP allow-listing or device restriction.
  • No written, rehearsed incident response runbook.
  • No tested restore, and therefore no published backup retention window or recovery objective.
  • No published transfer impact assessment for the transfers in clause 7.
  • No self-service export or erasure for a named individual; clause 8.2 assistance is manual.

Annex IIISub-processors

The current list, what each does and where each sits, is maintained on the sub-processors page, which forms annex III to this agreement. Changes are announced under clause 5.2.

Data processing agreement, version 0.3, effective 29 July 2026. Every agreement, and who you are contracting with, on the legal index.