legal
Data processing
Processor terms for customers who control personal data in the product. Clause 7 is the one your data protection lead will want.
Written from the system, not from a template. Every statement here describes what the software actually does — the region, the sub-processors, what is collected, what is retained, what leaves the EEA. It is a description of a system rather than legal advice, and it is published rather than sent after a call. If your counsel needs redlines, or your own paper, that is a conversation and not a problem.
This agreement is between Touch Grass AB and the customer whose account uses Inkstand. It forms part of the terms of service and applies automatically wherever the service is used to process personal data. No signature is needed for it to apply; if you need a countersigned copy for your file, ask.
▸Contents — 12 clauses
Contents
1Roles#
3Confidentiality#
4Security#
5Sub-processors#
6Where processing happens#
7Transfers outside the EEA#
| Function | What is sent | Status today |
|---|---|---|
| Deck generation | The brief and the brand voice rules, to produce slide copy. | Live in the product. |
| Brand-guideline reading | The text extracted from a brand document you supply. | Live in the product. |
| Deck compliance review | The text of the deck being edited, with the voice rules. | Reachable from the editor on request. Not wired into the export gate, and every release record states that AI review did not run. |
| Claim research | The claim being checked, plus a web search of the sources you nominate. | Deployed but not reachable from the interface. When it is, the claim text will reach a search provider as well as a model. |
8Assisting you with data subject requests#
9Breach notification, impact assessments and consultation#
10Audit and information#
11Deletion and return#
12Liability, precedence and duration#
Annex IDescription of the processing
Written to be copied into your record of processing activities without editing. Where a row is short, it is short because the system is.
| Heading | Detail |
|---|---|
| Controller | The customer whose account holds the data. |
| Processor | Touch Grass AB, a private limited company (aktiebolag) registered in Sweden since 2024, registration number 559484-7435, Idunsgatan 46, 214 46 Malmö, Sweden. |
| Subject matter | Composition, rule-checking, review and export of social media content. |
| Duration | For as long as the account exists, plus the deletion window in clause 11. |
| Nature of processing | Storage, structured retrieval, rendering, rule evaluation, transmission to an AI provider where a user asks for it, and the writing of insert-only audit records. |
| Purpose | Producing and releasing brand-compliant marketing content, and evidencing what was released and on what basis. |
| Categories of data subject | Users of the account; people named or depicted in content the customer creates or uploads; external reviewers sent a review link; recipients of an invitation. |
| Categories of personal data | Email address and display name; content and images the customer supplies, which may contain any personal data the customer chooses to include; a reviewer's self-typed name, role and comments; the identity of the person who released a piece of content and what they acknowledged. |
| Special category data | None is requested and none is required. The service is not designed for it. If a customer places it in content, the customer must satisfy itself of a lawful basis under Article 9. |
| Children’s data | Not requested. The service is not directed at children. |
| Frequency | Continuous for storage; on user action for rule checking, transfer to an AI provider and export. |
Annex IITechnical and organisational measures
What is in place, drawn from the running system, and what is absent. The absences are here because a measures annex that lists only strengths is one nobody can rely on.
In place
- Tenant isolation in the database. Row-level security on every table, keyed to account membership through a single shared function, asserted on every run by more than a hundred and fifty automated checks against a real database covering reads, writes, member enumeration, unaffiliated users, audit records, role enforcement, review links and brand-scoped access.
- Encryption in transit. HTTPS throughout; HSTS with a two-year max-age, includeSubDomains and preload; TLS to the database and to storage.
- Encryption at rest, provided by the managed database and object storage platform. We do not operate our own disks and do not manage our own keys.
- No stored passwords. Sign-in is a one-time link to an email address, so there is no credential to leak or reuse.
- Private asset storage. Uploads go to a private bucket with an allow-list of types and size caps, served only through signed URLs that expire in an hour, with the path prefix as the authorisation key.
- Least privilege for our own staff, enforced by policy rather than instruction, as described in clause 3.2. Administrator status is seeded out of band.
- Insert-only audit records for every release and every generation, not editable by the account owner or by us.
- Time-bound access grants. Invitations are single-use, address-bound and expire in fourteen days. Review links carry a mandatory expiry and can be revoked.
- Response headers: nosniff, frame-ancestors denied, strict-origin-when-cross-origin referrer policy, and camera, microphone and geolocation denied.
- Server-side fetch hardening on the one feature that retrieves a URL you supply: non-HTTP schemes, private and link-local addresses, intranet names, unbounded bodies and redirect chains are refused. It does not defeat DNS rebinding, which is documented in the code as well as here.
- Secret separation. The browser bundle carries only the public key that every row-level policy applies to. The policy-bypassing key and the model-provider key exist only inside server-side functions.
- Automated testing before release: more than 800 tests on the compliance and rendering logic, plus the isolation checks above.
- A small dependency surface, treated as a control: eleven runtime packages, and two features written in-house rather than add a sub-processor.
Not in place
- No SOC 2, ISO 27001 or Cyber Essentials, and none in progress.
- No independent penetration test has been commissioned.
- No SSO, SAML, SCIM or multi-factor authentication. Sign-in is mailbox possession.
- No configurable session timeout and no forced re-authentication interval.
- No IP allow-listing or device restriction.
- No written, rehearsed incident response runbook.
- No tested restore, and therefore no published backup retention window or recovery objective.
- No published transfer impact assessment for the transfers in clause 7.
- No self-service export or erasure for a named individual; clause 8.2 assistance is manual.
Annex IIISub-processors
The current list, what each does and where each sits, is maintained on the sub-processors page, which forms annex III to this agreement. Changes are announced under clause 5.2.
Data processing agreement, version 0.3, effective 29 July 2026. Every agreement, and who you are contracting with, on the legal index.