Data Processing Agreement

Last updated August 1, 2026 - Version 1.1

When you store details about your clients in wallticker - in particular the name, email address, or phone number of a contact person - you decide what is stored and why, and we store it on your behalf. In data-protection terms you are the controller of that information and we are your processor. This agreement sets out the terms required by Article 28 GDPR. It applies automatically to every account and forms part of the Terms of Service; you do not need to sign anything separately.

1. Parties and Scope

This agreement is between you, the account holder, and Luwall AB, org. nr 559359-5993, Sweden ("we", "us"), the operator of wallticker.

It governs only the personal data you enter about other people. That is currently the optional contact person on a client record, and any personal detail you choose to type into a free-text field such as an entry description or note.

It does not govern your own account data - your email address, your time entries, your absence records. For that data we are the controller, not your processor, and the Privacy Policy applies instead.

2. Our Respective Roles

You are the controller. You decide whose details to record, which fields to fill in, and how long to keep them. You are responsible for having a lawful basis to record another person's details, and for telling them you have done so if they are entitled to know.

We are the processor. We store that data, keep it available to you, and delete it when you tell us to. We do not decide what it is for and we do not use it for our own purposes.

No other wallticker account can read your data. There are no shared workspaces, no teams, and no administrator who can see your records.

3. Subject Matter, Duration, Nature and Purpose

Subject matter: storage and display of the client and contact details you enter, so that you can attribute your recorded time to the right client and produce reports and exports.

Nature of processing: storing, organising, retrieving, displaying, exporting, and deleting. We do not analyse this data, profile anyone, or make automated decisions with it.

Duration: for as long as you keep the record and your account exists. Processing ends when you delete the record or when your account is erased.

4. Categories of Data and Data Subjects

Data subjects: the contact people at your clients, and any individual you happen to name in a free-text field.

Categories of personal data: name, email address, telephone number, and business address, together with the organisation they are associated with.

No special categories. The client and contact fields must not be used to record health data, religious or political views, trade-union membership, or any other special category of data under Article 9 GDPR. There is deliberately no free-text notes field on a client record. If you enter such data anyway, you do so outside the intended use of the Service and remain responsible for it.

5. Processing on Your Instructions

We process this data only on your documented instructions. Your use of the Service - what you create, edit, export, and delete - constitutes those instructions, together with this agreement and the Terms of Service.

We will process it otherwise only where required by European Union or Swedish law. If that happens we will tell you first, unless the law forbids us from doing so.

If we believe an instruction of yours would breach data-protection law, we will tell you.

6. Confidentiality

Everyone we authorise to access personal data is bound by an obligation of confidentiality. Access is limited to those who need it to operate or support the Service, and we do not grant routine access to account contents.

7. Security Measures

We apply the technical and organisational measures required by Article 32 GDPR. In particular:

  • Database-level isolation. Every record is bound to one account, and the database itself rejects any attempt to read or write another account's data. This does not depend on application code being free of bugs.
  • Encryption in transit for all traffic, and encryption at rest for stored data.
  • Authentication handled by a specialist provider, with leaked-password protection and email confirmation.
  • Least privilege. Credentials that can bypass record-level isolation are restricted to server-side use and are never exposed to the browser.

8. Sub-Processors

You give us general authorisation to engage the sub-processors below, each under a written contract imposing the same obligations set out here:

  • Supabase - database and authentication. Data is stored in the European Union.
  • Vercel - application hosting and content delivery.
  • Brevo - transactional email.
  • Stripe - payment processing, for paid plans only.

We will give you notice before adding or replacing a sub-processor, through the Service or by email. If you object on reasonable data-protection grounds, you may stop using the Service and delete your account; we do not charge for the unused part of a prepaid period in that case.

Google and GitHub act as sign-in providers, and Google additionally as a calendar source if you connect one. Those relationships concern your own account data rather than your clients' data, and are described in the Privacy Policy.

9. International Transfers

Your data is stored in the European Union. Some sub-processors are established in the United States and may process data there while delivering their service. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, supported by encryption in transit and at rest.

10. Helping You Answer Data Subject Requests

If one of your clients' contacts asks you for their data, asks you to correct it, or asks you to delete it, you can act on that request yourself: every field is editable and deletable in the Service, and the account export includes your client records in a structured, machine-readable file.

Where you cannot resolve a request with those tools, we will assist you, taking into account the nature of the processing and the information available to us.

If such a person contacts us directly, we will not answer on your behalf. We will refer them to you, since you are the controller.

11. Personal Data Breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and will provide the information you reasonably need in order to meet your own notification duties under Articles 33 and 34 GDPR. We will also assist you, where relevant, with data protection impact assessments and prior consultation under Articles 35 and 36.

12. Deletion and Return

You can delete any client record at any time, and you can export your data at any time as a single structured file.

When you delete your account, all of it is erased from the Service after the 30-day grace period described in the Privacy Policy, including your client records. Nothing is retained afterwards except (a) the short-lived technical residues in our sub-processors’ backups and logs listed under “What remains afterwards” in the Privacy Policy, which are never used for any purpose, and (b) where European Union or Swedish law requires it, in which case we keep only what the law requires, for the period it requires.

13. Information and Audits

On reasonable request we will make available the information necessary to demonstrate that we meet the obligations in this agreement, and will contribute to audits or inspections conducted by you or an auditor you appoint. We may satisfy this by providing our own documentation and that of our sub-processors where it addresses the request. Audits are limited to once a year unless a supervisory authority requires otherwise or a breach has occurred.

14. Changes, Liability and Governing Law

This agreement forms part of the Terms of Service. If we change it materially, we will ask you to accept the change before you continue using the Service, in the same way as for a material change to the Terms.

Liability under this agreement is governed by the limitations in the Terms of Service, except where the GDPR provides otherwise and those provisions cannot be limited by contract.

Swedish law governs this agreement. The supervisory authority is the Swedish Authority for Privacy Protection (IMY).