witness

Data processing agreement

Effective 2026-10-01 · Jobbin AB, org. no. 556893-2452

This agreement is made under Article 28 of the GDPR between the customer using witness (the controller) and Jobbin AB, org. no. 556893-2452, Stockholmsvägen 60a, 181 42 Lidingö, Sweden (the processor). It is part of the terms of service and applies from the moment the customer creates a project. Capitalised terms have the meaning the GDPR gives them.

This is our standard agreement. A customer who needs it on their own paper, or with different terms, can ask at support@witness.nu.

1. What is processed

Subject matter The contents of the controller's projects in witness.
Duration For as long as the controller has a project, and until the data is deleted under section 8.
Nature and purpose Storing, displaying, transmitting and backing up the contents of a project so that the people and agents the controller gives a link to can read and write in it.
Types of personal data Names of the people who write in a project, and whatever personal data the controller's users put into cards, comments, prose and images.
Categories of data subjects The controller's staff, contractors, testers and stakeholders, and anyone mentioned in the contents.

The processor decides nothing about what goes into a project. What is there is put there by the controller and the people it gives links to.

2. Instructions

The processor processes personal data only on the controller's documented instructions. The instructions are: provide the service as described in the terms and at /security; do what the controller does through the service, including exporting and deleting; and nothing else. The processor will tell the controller if it believes an instruction infringes the GDPR, unless the law prevents it.

The processor may process the data where Union or Member State law requires it, and will inform the controller of that requirement before processing unless the law forbids it.

3. Confidentiality

Everyone the processor authorises to process personal data is bound by confidentiality, by contract or by law. In practice that is the people who hold the service's administrative key, and they are few.

4. Security

The processor implements the technical and organisational measures in the Annex. They are chosen for the risk this data carries: a project is private to whoever holds its link, and the link is a credential of 256 random bits that is never stored in clear. The controller acknowledges that it decides who receives a link and that rotation, which the service offers, is the remedy for a link that has gone astray.

5. Sub-processors

The controller gives general authorisation to the sub-processors listed at /legal/subprocessors, which names each one, what it does and where. The processor will announce any addition or replacement on that page and by email to the account holder at least thirty days before it takes effect. The controller may object within that period; if the objection cannot be resolved, the controller may terminate the agreement and export its data under section 8.

The processor imposes on each sub-processor data protection obligations equivalent to this agreement, and remains liable to the controller for the sub-processor's performance.

6. Assistance

Taking into account the nature of the processing, the processor assists the controller with appropriate technical and organisational measures in responding to data subject requests, and — insofar as the information is available to it — in meeting the controller's obligations under Articles 32 to 36 (security, breach notification, impact assessments, prior consultation). The service's export endpoint answers most access and portability requests without involving the processor at all.

7. Personal data breaches

The processor notifies the controller without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting the controller's data, with what it knows at that point and the rest as it learns it.

8. Deletion and return

The controller can export any project at any time as a single JSON document, and delete any project at any time; deletion removes the project, its links and its images at once, and its backups within thirty days. When the agreement ends, projects remain exportable for thirty days, after which they are deleted as above. The processor keeps nothing thereafter except what Union or Member State law requires it to keep.

9. Audit

The processor makes available the information necessary to demonstrate compliance with Article 28 — this agreement, the Annex, the sub-processor list, and the security description at /security, which is generated from the same source as the service itself. The controller, or an auditor mandated by it and bound by confidentiality, may conduct an audit on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, at the controller's cost, and in a way that does not compromise other customers' data.

10. Transfers

Project data is processed in the European Union. The processor's hosting provider is a US company and processes on the basis of the EU–US Data Privacy Framework and the standard contractual clauses in the processor's agreement with it; the processor will not transfer the controller's project data outside the EU/EEA except on a valid transfer mechanism and after informing the controller through the sub-processor list.

11. Liability

Liability under this agreement follows the terms of service. Each party is liable for its own compliance with the GDPR as controller and processor respectively.

Annex — technical and organisational measures

Access to a project. A project is reached only by its two links, each a 256-bit random token, stored as a SHA-256 digest so that no clear token exists at rest. A view link cannot write to cards. A browser exchanges the token for an HttpOnly cookie scoped to that project's path, so the token is not in the URL of every request. Rotation issues a new pair and invalidates the old one immediately.

Where the data is. Every project's compute and storage is pinned to the European Union, as part of the identity of the storage object rather than as a runtime setting, so it cannot be moved by mistake. Images are stored in an EU bucket. Backups are written to an EU bucket.

Encryption. All traffic to the service is over TLS. Data at rest is encrypted by the hosting provider.

Isolation. Each project is its own storage object with its own database; there is no query that spans customers.

Browser hardening. The project page runs under a Content Security Policy that allows scripts only from the service's own origin, and renders user-written markdown through a sanitiser.

Abuse limits. Per-address budgets on link resolution, writes and event streams; a signed-in member's reads through the page and the API (images included), their writes and their event streams are budgeted per member instead. Loading the page and opening its live connection stay budgeted per address.

Backups and recovery. A nightly snapshot of every active project to an EU bucket, kept thirty days, in addition to the storage layer's point-in-time recovery. An archived project instead keeps one snapshot for as long as it stays archived, which can therefore be older than thirty days; taking it out of the archive or deleting it removes it at once.

Administrative access. The administrative interface requires a secret held by the processor's staff, compared in constant time, and is used to create, rotate, export and delete projects. Logs of requests are retained by the hosting provider for at most seven days.

Deletion. Deleting a project removes its storage object, its links and its images at once, and its backups within thirty days.