Data Processing Terms
Last updated: 28 July 2026
These are binding terms, not a summary. They form the data processing agreement required by Article 28(3) of the UK GDPR between you (the controller) and Larssoni (the processor), and they are incorporated into the Terms of Service. You do not need to sign anything separately — accepting the Terms of Service accepts these. If your organisation needs a countersigned copy on its own paper, email support@larssoni.com and we will sign yours.
Parties. You, the Larssoni account holder (“Controller”). Oscar Wiren, trading as Larssoni (sole trader), 1 Potters Road, London SW6 2WQ, United Kingdom (“Processor”, “we”, “us”).
1. What we process, and why
| Subject matter | Hosting, displaying and refreshing the artifacts you publish through Larssoni |
| Duration | For as long as your account is active, plus the retention periods in §8 |
| Nature and purpose | Storing your content; serving it to the audience you choose; reading a data source you connect and substituting values into your artifact on the schedule you set; producing analytics for you |
| Types of personal data | Whatever personal data you choose to include in an artifact or a connected data source; the email addresses of people you invite to view a gated artifact; your own account data |
| Categories of data subjects | Your personnel and clients, whoever you share an artifact with, and any individual whose data appears in a source you connect |
| Special category data | Larssoni is not designed for special category or criminal offence data. If you intend to process it here, tell us first — we may need to agree additional measures, and some of the transfer mechanisms in §7 treat it differently |
2. Our obligations as processor — Article 28(3)
(a) Only on your instructions. We process personal data only on your documented instructions, including as to international transfers, unless UK law requires otherwise — in which case we will tell you before processing, unless the law forbids us from telling you. Your instructions are: these terms, the Terms of Service, and what you do in the product (choosing a gate, connecting a source, setting a schedule). If we ever determine the purpose and means of processing ourselves, we become a controller for that processing and say so. We do, and disclose in our Privacy Policy, act as an independent controller for one narrow thing: the email address a gated viewer enters to obtain access. We are not acting on your instructions there, and you are never shown that address.
(b) Confidentiality. Everyone we authorise to process personal data is bound by a duty of confidentiality. Larssoni has no employees; the operator is personally bound by this obligation, and any future personnel or contractor will be bound in writing before access is granted.
(c) Security. We implement appropriate technical and organisational measures under Article 32. The measures actually in place are listed at §4 and described publicly at larssoni.com/security.
(d) Sub-processors. We engage sub-processors only under §6.
(e) Data subject rights. Taking into account the nature of the processing, we assist you in responding to requests under Chapter III (access, rectification, erasure, restriction, portability, objection). In practice: your content is exportable in full at any time and deletable by you directly, which will satisfy most requests without our involvement. Where it does not, email support@larssoni.com and we will help.
(f) Assistance with Articles 32–36. We assist you with security, breach notification (§5), data protection impact assessments and any prior consultation with the ICO, taking into account the nature of the processing and the information available to us.
(g) Deletion or return. On termination, and at your choice, we delete or return all personal data and delete existing copies, unless UK law requires us to keep it. Deletion follows §8. Data in routine backups is put beyond use immediately and erased on the next backup cycle.
(h) Audit and information. We make available all information necessary to demonstrate compliance with this Article, and allow for and contribute to audits, on the terms in §9.
3. Your obligations as controller
You warrant that you have a lawful basis for the personal data you put into Larssoni, that you have given any notices and obtained any consents your own processing requires, and that your instructions to us will not put us in breach of data protection law. You are responsible for the content of your artifacts, and for deciding who may view them.
4. Security measures (Article 32)
- Isolation. Artifacts are served from content domains separate from the application domain, which never carry a login cookie. Free-tier public content is served from a third, separate domain so it cannot affect the reputation of business content.
- Sandboxing. Every served artifact runs under a strict Content-Security-Policy: no outbound network calls, no form submission, no framing by third parties, and scripts limited to a short allowlist of common library CDNs. A hosted page cannot exfiltrate data or submit a form.
- Encryption. Data-source credentials are encrypted at rest with AES-GCM and never logged. All traffic is served over TLS.
- Access tokens. Sign-in sessions, magic-link tokens, viewer access codes and API keys are all stored hashed, never in plain form.
- Minimisation in the AI setup step. The one AI call sends your artifact’s markup, your data source’s column names and synthetic example rows we generate ourselves. Real data values are never sent. Refreshes after setup involve no AI provider at all.
- Audit logging. An append-only, hash-chained log records changes to your workspace and artifacts, supporting tamper detection.
- Testing. The isolation and sandbox controls are verified by an automated security battery on every release and checked against the live edge.
5. Personal data breaches
We notify you of a personal data breach affecting your personal data without undue delay, and in any event within 48 hours of becoming aware of it, followed by further information as it becomes available. We chose 48 hours deliberately: it leaves you meaningful runway inside your own 72-hour deadline to notify the ICO, while being a commitment a one-person operation can actually meet rather than one that sounds better and gets missed. Our notification will describe the nature of the breach, the likely consequences, and the measures taken, so far as known.
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed below.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, storage, database, edge delivery | US / global |
| Anthropic, PBC | The one-time AI setup call (markup + column names + synthetic rows only) | US |
| Stripe Payments Europe, Limited | Payment processing, as merchant of record | Ireland (EEA) |
| ActiveCampaign (Postmark) | Transactional email | US |
Changes. We will give you at least 30 days’ notice before a new sub-processor starts processing your data. You may object on reasonable data-protection grounds within 30 days of that notice. If you do, we will work with you in good faith to find an alternative; if we cannot within a reasonable period, your remedy is to terminate the affected service without penalty and receive a refund of any prepaid fees for the unexpired period. To receive notices, email support@larssoni.com and ask to be added to the sub-processor notification list.
Our liability. We remain fully liable to you for our sub-processors’ performance of these obligations, and impose equivalent data protection obligations on each.
Google is not in that table, deliberately. If a user signs in with their Google account, or authorises us to read a Google Sheet, Google acts as an independent controller — not as our sub-processor. Google holds that data already, under its own relationship with that person; it discloses a narrow slice of it to us (the openid, email, profile and spreadsheets.readonly scopes) at that person’s own instruction, given on Google’s consent screen. We do not instruct Google how to process it, and could not. Google’s own handling is governed by its Privacy Policy and the API Services User Data Policy. Once the data reaches us we process it as your processor under these terms, exactly like any other data you give us — it is simply not sub-processed to Google, because Google is the source of the disclosure, not a recipient of it.
We also keep a Google Cloud developer project, used only to hold the API credentials for those integrations. No customer data is stored or processed in it.
7. International transfers
Some of our sub-processors are in the United States. We rely on the following, and we monitor them:
- Cloudflare and ActiveCampaign (Postmark) participate in the UK Extension to the EU-US Data Privacy Framework. Transfers to a business actively certified under the UK Extension are covered by UK adequacy regulations, so they are not restricted transfers and require no additional safeguard. We check certifications remain active periodically, and if one lapses we fall back to standard clauses.
- Stripe: our contracting entity is Stripe Payments Europe, Limited, in Ireland. That is a UK-to-EEA transfer, covered by UK adequacy for the EEA — no additional safeguard needed.
- Anthropic: we rely on the EU Standard Contractual Clauses as amended by the ICO’s International Data Transfer Addendum, which Anthropic’s own data processing addendum executes automatically. We hold a transfer risk assessment (the “data protection test”) for this transfer.
Google does not appear here: for the sign-in and Sheets integrations we are not transferring personal data to Google at all — Google is disclosing it to us at the user’s instruction, as an independent controller (see §6).
If you need copies of any of this, ask.
8. Retention and deletion
| Data | Retained |
|---|---|
| Artifacts, versions and uploaded source files | Until you delete them, or 30 days after account closure |
| Google Sheet values | Never stored — read at refresh and discarded; a one-way change-detection fingerprint is kept 30 days |
| Gated viewer email addresses | Not retained. Used to check the gate and send a code, then reduced to an irreversible per-artifact hash |
| Viewer analytics hash | Erased when the artifact is deleted, or at account teardown |
| Security and change audit log | 24 months; entries linked to a payment kept 6 years to match the limitation period for contract claims |
You can export everything at any time before deletion.
9. Audit
Documentation first. On reasonable written request, no more than once in any 12-month period, we will provide a description of our technical and organisational measures, our current sub-processor list, and any third-party audit report or certification we hold, to demonstrate compliance.
Inspection if that is not enough. If that documentation is not reasonably sufficient, you may conduct one audit per 12-month period of our relevant policies and records, on at least 30 days’ written notice, during business hours, subject to reasonable confidentiality and security requirements, at your cost — unless the audit identifies a material breach of these terms, in which case we bear our own reasonable costs.
After a breach. Following a confirmed personal data breach affecting your data, you may request an audit without regard to the annual limit.
Sub-processors. We cannot submit Cloudflare, Stripe, Anthropic, Google or Postmark to a customer-initiated audit. We will pass through whatever compliance documentation those providers make available.
10. General
These terms take effect on your acceptance of the Terms of Service and continue while we process personal data for you. If any provision conflicts with the Terms of Service in respect of personal data, these terms prevail. They are governed by the law of England and Wales.
Questions, or a countersigned copy: support@larssoni.com.