Jotholm GDPR Contact & Data-Subject-Request (DSR) Process
Last updated: 21 June 2026
Effective: 21 June 2026
This document explains how to exercise your data-subject rights under the GDPR/UK GDPR and how to contact Jotholm about your personal data.
1. Who to contact
- Privacy / data-protection contact: privacy@jotholm.io (general legal: legal@jotholm.io)
- Data Protection Officer: none appointed. A DPO is not required, as none of the GDPR Art. 37 mandatory triggers apply (no large-scale systematic monitoring or large-scale special-category processing; not a public authority). Privacy queries go to the contact above.
- Controller / postal address: Johan Sjölin, an individual operating as a sole trader (Swedish enskild näringsidkare) established in Sweden, at Trollhasselgatan 27, 417 11 Göteborg, Sweden.
- EU Art. 27 representative: not required, as the controller is established in the EU (Sweden).
2. What you can request (your rights)
You may exercise any of these GDPR/UK-GDPR rights:
- Access: a copy of your personal data.
- Rectification: correction of inaccurate data.
- Erasure: deletion of your data ("right to be forgotten").
- Restriction: limit how we process your data.
- Portability: your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
3. The fastest path: self-service tools
Jotholm has built self-service tooling so you can exercise the most common rights immediately, without waiting for us:
- Access & Portability → Data export. Download a structured JSON export of your account profile and every workspace you belong to (your board, full change history, member list, and an uploaded-asset manifest). Available in-product / via the account API.
- Erasure → Delete account. Permanently and synchronously delete your account and everything you solely own (workspaces, board content, uploads, sessions, tokens). Shared workspaces with other owners survive; only your membership is removed. This also cancels any active subscription. Billing records held by our payment processor (Stripe) are retained for the statutory accounting-retention period and are not deleted, because we are legally required to keep them (Swedish Bookkeeping Act). Free on every tier; never paywalled.
- Erasure (scoped) → Delete workspace. A workspace owner can delete an entire workspace (its database, uploads, and subscription).
These actions require explicit confirmation before they run.
4. For everything else: submit a DSR
For rectification of identity data, restriction, objection, or any request you cannot complete with the self-service tools, contact the privacy contact in §1. We will:
- Acknowledge your request.
- Verify your identity to ensure we don't disclose data to the wrong person.
- Action the request and confirm completion, or explain any lawful reason we cannot fully comply.
We aim to acknowledge your request within a few business days and to complete it without undue delay and in any event within one month of verifying your identity (GDPR Art. 12(3)). For complex or numerous requests we may extend this by up to two further months, and will tell you within the first month if we need to.
There is normally no fee. We may charge a reasonable fee or refuse manifestly unfounded or excessive requests, as permitted by GDPR Art. 12(5).