Skip to content

Data Processing Addendum

Last updated: 2026-09-16. Effective automatically when you use the service — no signature needed.

1. How this applies

This Data Processing Addendum ("DPA") is part of the Terms of Service. It takes effect automatically the moment you use Chartosaurus to connect a data source, for every customer, with no signature and no email exchange. You do not have to ask us for it and we do not have to countersign it.

It governs personal data contained in the data sources you connect. Where it conflicts with the Terms of Service on that subject, this page wins.

If your legal team needs a signed copy on paper, email support@chartosaurus.com and we will sign one. That is a formality — the terms are the same either way.

2. Roles: who is controller, who is processor

Two different sets of data are in play here, and they have different answers. This is the part reviewers check first.

The data you connect — the schema and row values of a Notion database, or a CSV you upload. You decide what it contains and why it exists. You are the controller; we are your processor. This DPA covers that data and only that data.

Your own account data — your email address, your hashed password, your session records, your subscription record with our payment processor. We decide what we hold and why, because running the service requires it. For that data we are the controller, and the Privacy Policy, not this DPA, is the document that governs it.

One consequence worth stating: a data subject request about your account data comes to us. A data subject request about the contents of your connected database goes to you — see section 8.

3. What we process, for how long, and why

Subject matter — the personal data contained in the data sources you connect to Chartosaurus.

Duration — for as long as the connection exists on your account. It ends when you delete the connection or delete your account, subject to section 10.

Nature and purpose — we read your database's property names and types, and the row values needed to draw a chart. We aggregate, sort and group those values and render them as a chart, then serve that chart in the app and at any embed URL you publish. That is the entire purpose. We do not use your data for anything else, we never sell it, we never share it with another customer, and we do not use it to train machine-learning models.

For Notion, row values are fetched on demand and held in a short-lived server cache that expires on its own timer — between 30 and 300 seconds depending on your plan. They are not written to our database. For a CSV you upload there is no upstream to re-fetch from, so the parsed contents are stored in full until you delete the connection or the account.

Categories of data subjects — whoever appears in the database you connect. We cannot know who that is. Depending on what you built, they may be your employees, your customers, your survey respondents, or nobody at all.

Categories of personal data — likewise determined by you, not by us. Whatever sits in the columns you chart. We impose no schema and inspect nothing beyond what is needed to render the chart. If you connect a database containing special category data under GDPR Article 9, that is your decision and your legal basis; the product applies no additional safeguards for it.

4. Our obligations as processor

Documented instructions — we process the connected data only on your instructions. Your use of the product is the instruction: connecting a database instructs us to read it, building a chart instructs us to render it, publishing an embed instructs us to serve it. We will not process it for any other purpose. If a law compels us to process it otherwise, we will tell you before doing so unless that law forbids the notice.

Confidentiality — access to production systems is limited to the one person who operates Chartosaurus, who is bound to confidentiality by these terms. There is no wider team, no contractor, and no shared credential.

Security — we apply the measures in section 6.

Sub-processors — none is added without the notice in section 5.

Assistance — we assist you with data subject requests (section 8), with breach notification (section 7), and with data protection impact assessments, to the extent the information is ours to give.

Deletion or return — on termination, as described in section 10. Export is self-service and available at any time from Settings.

5. Sub-processors

You authorise us to use the sub-processors listed on the Sub-processors page. That list is complete; none is added silently.

Before a new sub-processor starts processing your connected data, we will update that page and email you at least 30 days beforehand.

If you object to a new sub-processor on reasonable data protection grounds, tell us within those 30 days. We will try to find a workaround. If there is none, you may terminate the affected subscription and we will refund the unused portion of the current period.

We remain responsible to you for what our sub-processors do with your data, and we impose data protection terms on them no less protective than these.

6. Security measures

Data source credentials — Notion tokens are encrypted with AES-256-GCM before being written to the database, using a 256-bit key that lives only in the server environment, never in the database and never in the source tree. Each value gets a fresh random 96-bit IV, and the cipher is authenticated, so tampered ciphertext fails to decrypt rather than decrypting to something wrong. Tokens are decrypted in memory only for the duration of an API call; they are never sent to the browser, never written to logs, and excluded from your data export.

Transport — the application is served over HTTPS.

Authentication — accounts use email and password, with the password stored only as a hash. Sessions are held as tokens, and each session record keeps the IP address and browser user-agent that created it so a suspicious sign-in can be spotted. Every session on an account is destroyed when its password is reset. Password reset links expire in one hour and work once.

Rate limiting — sign-up, sign-in, password change, password reset and embed requests are rate limited through Upstash Redis.

Error monitoring — Sentry runs with "send default PII" switched off, and every outbound event passes through a scrubber that redacts embed tokens, share tokens and password reset tokens from URLs, error messages, breadcrumbs and span data.

Audit logging — security-relevant actions such as password changes, password resets and account deletion are written to an audit log with the acting user's ID and a timestamp.

Access — hosting and the PostgreSQL database run on a VPS we manage. One person has administrative access to it.

What we do not have, stated plainly so you do not have to assume: no SOC 2 report, no ISO 27001 certification, no external penetration test, no 24/7 on-call rotation, and no formal incident response team. Chartosaurus is one person. If your procurement process requires any of those, this product will not pass it, and we would rather you found that out here than three weeks into a review.

7. Personal data breach

If we become aware of a personal data breach affecting the data you connected, we will notify you without undue delay and in any case within 72 hours of becoming aware of it. We commit to that window. The clock starts when we become aware, not when the breach happened.

The notification will describe what we know at the time: what happened, which categories and roughly how many records are involved, what the likely consequences are, and what we are doing about it. If we do not yet have the full picture we will send what we have and follow up, rather than wait.

Notifying your supervisory authority and, where required, the affected data subjects is the controller's duty, so it is yours. We will give you what you need to do it.

We do not have a 24/7 on-call rotation. In practice that means detection depends on error monitoring and on our own checks, not on someone watching a screen at 3am. Factor that into your own risk assessment.

8. Data subject requests

If someone contacts us with an access, correction, deletion, objection or portability request about data inside a database you connected, we will not answer it ourselves. We are not the controller for that data and we have no way to verify the person's identity against your records. We will forward the request to you promptly and tell the requester we have done so.

We will then assist you in answering it, using appropriate technical and organisational measures, as far as the information is ours to reach. In most cases the answer is in your Notion workspace or your spreadsheet, not on our servers.

Requests about your own account data — your email address, your sessions, your billing record — are ours to answer. Send those to support@chartosaurus.com.

9. International transfers

Where the data sits: our server, and the PostgreSQL database and cache files on it, are in a Contabo data centre in Germany. So the connected data you send us is at rest inside the EEA, and it stays there. We state that plainly because it is a better position than a page like this usually describes, and a reviewer should not have to email to find it out.

Where a border is nevertheless crossed: Chartosaurus is operated from Indonesia, and Indonesia has no EU adequacy decision. The one person who administers that server reaches it remotely from Indonesia, and under the GDPR remote access to EEA-hosted data is itself a transfer. It needs a safeguard even though the disk never leaves Germany. The location of the hardware narrows this question; it does not answer it.

Our other sub-processors are a separate matter — payments, transactional email, error monitoring and rate limiting each process in their own jurisdiction, which we do not choose. Each is named on the Sub-processors page. Those are onward transfers in the ordinary sense, and nothing about the database being in Germany changes them.

Here is what we actually have, rather than what a template would claim. Where a sub-processor publishes Standard Contractual Clauses in its data processing terms, those clauses apply to our use of it and we rely on them; that covers the onward transfers. For the transfer from you to us, we will enter into the EU Standard Contractual Clauses on request — email support@chartosaurus.com and we will sign the controller-to-processor module. We have not performed a formal transfer impact assessment, and we will not claim we have.

10. Deletion and return

You can export at any time: Settings → Export downloads a JSON file with your account record, your connections as names and metadata, and all your charts. Credentials are never included in an export.

On account deletion — Settings → Delete account — the user record is deleted and, by database cascade, your sessions, your password hash, every connection with its encrypted tokens and any stored CSV rows, every chart, every dashboard and every subscription record go with it. It is immediate and there is no undo, so export first.

Two things survive, for the reasons set out in section 10 of the Privacy Policy: security audit log rows, which hold a user ID and an action rather than your email or your content; and payment and tax records held by our payment processor under its own retention schedule. Our stored copies of that processor's webhook events are no longer among them — each is filed with the customer ID it belongs to and deleted with the account, and any that outlives an account is deleted 90 days after receipt.

Cached Notion rows are not deleted so much as abandoned — each entry expires on its own timer, at most five minutes, and nothing refreshes it once the account is gone.

Backups of the database are taken by us, on our own schedule, and are deleted 30 days after they are written — the same 30-day window stated in section 10 of the Privacy Policy, and the window the backup script enforces by deleting anything older on each run. A deleted record can therefore persist inside a backup for up to 30 days after deletion, and no longer. Backups are encrypted, and are restored only to recover from a disaster, never to retrieve an individual deleted account.

Deleting a Notion connection here deletes our stored copy of its token. It does not revoke the token at Notion's end — do that in Notion → Settings → Connections.

11. Audits

We will make available the information needed to demonstrate compliance with this DPA, and we answer security questionnaires. Send yours to support@chartosaurus.com; a straightforward one comes back within a week.

We cannot host an on-site audit and we cannot accommodate an auditor you send. There is no office to visit and no team to interview — the honest answer is that a one-person operation does not have the capacity, and we would rather say so than agree to a clause we could not honour. If your policy makes an on-site audit right non-negotiable, we are not the right supplier.

There is no third-party audit report to hand you either, because there has not been one. See section 6.

12. Contact

Anything about this DPA — a signed copy, a questionnaire, a sub-processor objection, a transfer question — goes to support@chartosaurus.com. One person reads that inbox and answers within two business days.

Suspected vulnerabilities go through the same route — see Security for what to include and how disclosure is handled.