Jotholm

Jotholm Privacy Policy

Last updated: 18 July 2026
Effective: 21 June 2026

1. Who we are (the data controller)

Jotholm ("Jotholm", "we", "us") is a subscription software-as-a-service collaborative whiteboard. This policy explains what personal data we process, why, on what lawful basis, how long we keep it, and the rights you have over it.

The data controller is:

2. What personal data we collect

We practise data minimisation (GDPR Art. 5(1)(c)): we collect only what each purpose requires.

2.1 Account data

When you create an account we store:

2.2 Workspace and board content

Jotholm is a whiteboard. Content you and your collaborators create (stickers, frames, text blocks, uploaded images, board layout, and your per-user board viewport) is stored per workspace, along with the identifier and timestamp of the member who created or last changed each element. A full mutation history ("ops log") is retained for collaboration, undo, and recovery (retention in §5).

2.3 Session and device data

When you sign in we create session records containing a hashed session token, timestamps, and a device label derived from your browser's User-Agent string (truncated). Session cookies are described in the Cookie Policy.

2.4 Billing data

If you subscribe to a paid plan, billing is handled by Stripe (see §7 and the Subprocessors list). We store a Stripe customer identifier against your account and a Stripe subscription identifier, status, and renewal date against the relevant workspace. We do not store your card number or full payment details; those are handled directly by Stripe.

2.5 Email-flow data

For email verification and magic sign-in links we temporarily store hashed, expiring tokens tied to your email address.

2.6 What we do not collect

2.7 Authentication-security event data

To help our operator diagnose login failures and detect attacks on your account (for example, bursts of failed sign-ins), we keep a bounded record of authentication outcomes inside your own workspace database. Each record contains only:

There is no password, token, cookie, or free-text field, and no raw email or name. This store is retention-bounded (newest 20 records per identifier, a 30-day maximum age, and a hard 10,000-record cap per workspace; see §5), self-expiring, lives only inside your own per-workspace database (no cross-tenant store), and is readable only through our restricted, audited operator back-office (§8). It is not used for analytics, profiling, marketing, or any automated decision-making.

3. Why we process it, and our lawful basis

Every processing activity maps to a GDPR Art. 6 lawful basis:

PurposeData usedLawful basis (Art. 6)
Create and operate your account; provide the whiteboard serviceAccount, workspace/board content, sessionContract (Art. 6(1)(b))
Authenticate you and keep your account secureCredentials, session, device labelContract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f), security)
Rate-limiting and abuse/fraud preventionTransient IP addressLegitimate interests (Art. 6(1)(f))
Diagnose login failures and detect account-security attacks (authentication-security events, §2.7)Pseudonymised (HMAC) login identifier, source IP, login outcomeLegitimate interests (Art. 6(1)(f), security)
Process subscription payments and renewalsEmail, Stripe identifiers, plan statusContract (Art. 6(1)(b))
Send service/transactional emails (verification, sign-in, account notices)EmailContract (Art. 6(1)(b))
Maintain product analytics to improve the serviceAggregated, non-identifying event countsLegitimate interests (Art. 6(1)(f))
Comply with legal/accounting/tax obligationsBilling recordsLegal obligation (Art. 6(1)(c))

We do not currently rely on consent (Art. 6(1)(a)) for any of the above, because we do not run non-essential cookies or marketing. There is no marketing-email programme at launch; we send only transactional/service email (account, billing, security, and policy-change notices). If a marketing-email programme is introduced later, it will require a separate, freely-given opt-in and an update to this section.

Purpose limitation (Art. 5(1)(b)): we use personal data only for the purposes listed above and disclosed at collection.

4. Who we share it with (subprocessors & recipients)

We do not sell personal data. We share it only with vendors that process data on our behalf under contract. The complete, current list, with each vendor's purpose and location, is maintained in the Jotholm Subprocessors list. In summary, personal data may be processed by our payment processor (Stripe), our transactional email provider, our hosting/infrastructure provider, and, only if you choose "Sign in with Google", Google as the identity provider.

We may also disclose data where legally required (e.g. valid legal process), which we will assess against applicable law before complying.

5. How long we keep it (retention & deletion)

We keep personal data only as long as needed for the purpose, then delete it. Current retention rules in the system:

Data categoryRetentionDeletion trigger
Account, workspace membership, board contentFor the life of the account/workspaceAccount or workspace deletion (§6)
Board mutation history ("ops log")Free plan: 7 days; Paid plan: 90 days (newest ~2,000 changes always kept)Automatic daily housekeeping
Recycle bin (soft-deleted stickers/frames)14 daysAutomatic hard-delete after retention
Account ("front-door") sessions30 days (sliding)Expiry / sign-out / housekeeping
Workspace sessions365 days (sliding)Expiry / sign-out / housekeeping
Email verification / magic-link tokensShort-lived (verification ~24h; magic link ~15 min)Expiry / consumption
Authentication-security events (§2.7): pseudonymised (HMAC) identifier, source IP, login outcomeNewest 20 records per identifier, 30-day maximum age, and a 10,000-record hard cap per workspace (whichever bound is hit first)Automatic pruning on each write and on a daily housekeeping run (self-expiring)
Unverified accountsReaped after the verification window (~24h)Automatic housekeeping
Stripe webhook event records (idempotency)45 daysAutomatic housekeeping
Billing/tax records7 years after the end of the financial year (Swedish Bookkeeping Act, Bokföringslag 1999:1078)Legal obligation
Dormant free workspaces (cold-archive)Inactive ~12 months (365 days)30-day warning/grace → board content tarred off hot storage to on-premises backup storage (restorable on next access) → archived tarball pruned after a further 180 days.Automatic housekeeping

The cold-archive lifecycle is enabled in production; a dormant free workspace is warned, then archived after the grace period, then permanently removed once the 180-day tarball window elapses.

Backups: Operational backups are taken hourly as per-workspace database snapshots plus a content-addressed copy of uploaded images, written to separate backup storage held apart from the live system. They are retained on a rolling grandfather-father-son schedule: every hourly snapshot for 24 hours, one per day for 7 days, and one per week for 8 weeks, so the maximum time any copy of your data persists in a backup is approximately 8 weeks. Backups are held on access-controlled storage, encrypted at rest; the primary backup store is on-premises in Sweden (EU/EEA). See §6 for how this interacts with erasure.

6. Your rights (data-subject rights)

If you are in the EEA/UK you have the following rights under the GDPR/UK GDPR. Jotholm has built self-service tooling behind several of these:

How to exercise them, identity verification, and our response SLA are set out in the Jotholm GDPR & DSR Process. You also have the right to lodge a complaint with a supervisory authority; our lead authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY"), and you may also complain to the supervisory authority in your own country of residence.

7. International transfers

Your core workspace data is stored within the EU/EEA (see hosting, below). Some personal data is processed by subprocessors located in the United States (payments and transactional email); for those transfers we rely on an appropriate cross-border transfer mechanism (Standard Contractual Clauses and the providers' Data Processing Agreements).

In summary, the cross-border (non-EEA) data flows described above are to the US-based processors Stripe and Resend (each covered by its standard DPA incorporating SCCs, Stripe under the dual-entity arrangement below) and, for users who choose it, Google sign-in, where Google is an independent controller governed by its own DPF/SCC safeguards rather than a Jotholm processor transfer. For Stripe the contracting entity is Stripe, Inc. (US) and/or Stripe Payments Europe, Ltd. (Ireland), with Stripe's standard SCCs in place. Transfer-mechanism characterisation: Stripe: SCCs via Stripe's standard DPA (dual-entity); Resend: SCCs via Resend's standard DPA; Google sign-in: independent controller under Google's own DPF/SCC safeguards.

8. How we protect your data

The following technical and organisational measures are in place, with their limits noted:

9. Personal data breaches

In the event of a personal-data breach we will assess it and, where required, notify the competent supervisory authority (the Swedish IMY) within 72 hours of becoming aware, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights (GDPR Arts. 33–34). The breach-notification owner is the founder and controller (there is no DPO).

We maintain operational monitoring and alerting, in-app authentication rate-limiting, a bounded durable record of authentication outcomes (§2.7), and an append-only administrative audit trail to help us identify and investigate suspected security incidents. If we become aware of a personal-data breach, the assessment and notification commitments set out above apply.

10. Children

Jotholm is not directed to children. The minimum age of use is 16. We do not rely on a child-consent basis (account holders are adults; our lawful bases are contract and legitimate interests), so the Art. 8 parental-consent machinery does not apply. There is currently no automated age-gate at sign-up; by creating an account you confirm you are at least 16.

11. Cookies

We use only a small number of strictly-necessary cookies for sign-in and security; we set no advertising or analytics cookies. Full detail is in the Jotholm Cookie Policy.

12. Changes to this policy

We may update this policy; updates are notified by in-product notice, and material changes additionally by email, with reasonable advance notice before they take effect. The "Last updated" date reflects the current version.