Interlinked · Legal

Interlinked - The Cube

Data Processing Agreement

The Article 28 contract between a gallery and the operator. The gallery is the controller. The operator is the processor. This is owed by us to you.

Version 2026-09-11.1 In force from 2026-09-11 Operator see below

Not reviewed by a lawyer This document was drafted by the engineering team from the actual behaviour of this software. It has not been reviewed by a lawyer. It must be reviewed by a qualified Romanian lawyer before this product is sold to a paying customer. docs/LEGAL.md lists the specific points that review has to settle.

How to accept this

This agreement applies automatically to every account and forms part of the Terms of Service. Opening an account, or continuing to use one after the version below takes effect, is acceptance of it. A customer who needs a signed counterpart, or its own paper, should write to stoiana00@gmail.com.

1. The roles, stated plainly

You, the gallery, are the controller. You decide which collectors receive a viewing room and why. You decide what is hung in it, whether marks and inquiries are switched on, how long the link lives and how many times it can be opened. You decide what to do with the viewing record afterwards. Those are the decisions Article 4(7) means by determining the purposes and means of the processing.

Solaas Tech S.R.L. is the processor. We supply the software and hold the data on your documented instruction. We do not choose your recipients, we do not decide what the measurement is used for, and we do not use it for any purpose of our own.

There is a short list on which we act as controller rather than processor, and it is deliberately separate from everything above: your staff's own user accounts and sign-in sessions, the security and integrity of the service, and the record of data-rights requests we are required to keep. That processing is described in the Privacy Notice and is not governed by this agreement.

2. Our obligations as processor (Article 28(3))

  1. Only on your instruction. We process personal data only on your documented instructions, including on transfers, unless a law we are subject to requires otherwise, in which case we tell you before processing unless that law forbids it. Using the software as it is documented is an instruction.
  2. Confidentiality. Everyone we authorise to process the data is bound to confidentiality.
  3. Security. We apply the measures in Annex II, which are the measures actually implemented in the software and not an aspiration.
  4. Sub-processors. You give general authorisation for the sub-processors in Annex III. We tell you at least 30 days before adding or replacing one, and you may object; if we cannot resolve an objection, you may terminate for the affected part of the service without penalty.
  5. Helping you answer data subjects. The software already does most of this: an export produces a collector's real rows, and an erasure destroys their viewing record. Where a collector comes to us directly, we execute what we hold the levers for and refer the rest to you, because it is yours to decide. See clause 4.
  6. Helping you with Articles 32 to 36. We assist with security, breach notification and any data protection impact assessment, taking account of what we can see, which is the infrastructure rather than your reasons for contacting a person.
  7. Deletion or return at the end. On termination you may export for 30 days; after that we delete your workspace and everything in it, unless a law requires us to keep something, in which case we say what and why.
  8. Proof. We make available the information needed to demonstrate compliance with this clause and allow audits, on reasonable notice, no more than once a year unless an authority or an incident requires otherwise.

3. Your obligations as controller

4. When a collector comes to us directly

A collector can ask us for their data or for erasure through our own form, and we verify the address before anything happens. What we then do is split along the same line as the roles:

5. Breach

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more. The 72-hour notification to the supervisory authority under Article 33 is yours to make, as controller; we give you what you need to make it.

6. Transfers

Data is stored in the European Union. A sub-processor in Annex III that is established outside it processes on the basis of the European Commission's standard contractual clauses together with any additional measures the transfer requires. The exact instrument for each is listed in docs/LEGAL.md as a point for legal review before this agreement is used with a paying customer.

Annex I, the processing

Subject matter and duration

Providing the private viewing-room service described in the Terms, for as long as the account is open, plus the export window and the retention periods in Annex IV.

Nature and purpose

Storing a gallery's inventory and contacts; delivering time-limited viewing-room links; recording and aggregating what a collector does inside a room; carrying enquiries and the conversations that follow.

Categories of data subject

Categories of personal data

CategoryFields
Who the gallery sent a room to Name · Email address · Company, city, country · Opt-in timestamp · CRM counters
The link itself Room token · Expiry, maximum opens, opens used, revocation
Each visit Visit start, last activity, end · Consent moment · Which text was consented to · Browser user agent · Hashed IP address
What the person looked at, the measurement Event type · Which artwork · Dwell, in milliseconds · Timestamp · Marks
What the person wrote Inquiry text · Thread and messages · Inquiry status
The follow-up draft, when a gallerist asks for one What was sent · What was removed first · The draft
Data-rights requests Request kind and status · Address it was made from · Verification token hash · Timestamps and outcome

No special categories. Nothing in this product asks for or is designed to hold data under Article 9 or Article 10. A collector could type anything into a free text enquiry, and the gallery should not invite them to.

Annex II, security measures

Two honest gaps, recorded here rather than left for an auditor to find: the content security policy still permits inline scripts, which the build requires today and which nonces are the documented fix for; and rate limiting is held in the process rather than shared, so it multiplies if the service is ever run as more than one replica.

Annex III, sub-processors

WhoPurposeDataLocation
Cloudflare Ltd. (R2 object storage) Storage of artwork images and their derivatives Artwork image files and the object keys that name them. No collector identifiers, no signal data. EU (bucket region WEUR)
[[SMTP_PROVIDER]] (email relay) Delivery of transactional email Recipient address and display name, the subject and body of the message, which includes viewing-room invitations, inquiry notifications, password resets and data-request verification links. [[SMTP_REGION]]
[[HOSTING_PROVIDER]] (server hosting) The virtual server the application and its PostgreSQL database run on Everything in this document, at rest and in memory. [[SERVER_LOCATION]]
Apple Inc. / Google Ireland Ltd. Identity providers, only for gallery users who choose "Sign in with Apple / Google" The sign-in exchange itself. They tell us a subject id and, sometimes, a verified address; we tell them nothing about rooms, collectors or signals. United States / Ireland
Anthropic PBC (Claude API) Drafting one follow-up email, when a gallerist presses COMPOSE FOLLOW-UP What a named collector looked at, without who they are. Sent: the gallery’s public details; for the works that person actually opened, the title, artist, year, medium, dimensions and status together with their own views, minutes, zoom-ins and marks against each; their strength score, session count, total minutes and visit dates; and the text of their inquiries truncated to 400 characters, with their name, company and city replaced by placeholders. Not sent: their name, email, company or city; any price; any image; any other collector or gallery; IP addresses, user agents, session tokens or link tokens; works they never opened. The real name is put into the finished draft here, after the model has written it. Pseudonymous is not anonymous: we hold the key, so this is still personal data and still a transfer. United States. This application does not pin the inference region.
Stripe Payments Europe, Ltd. Subscription payments, invoices and the billing portal. Galleries only. The billing contact and company details a gallery types into Stripe Checkout, including the VAT identification number collected from business customers, and the card itself. Card details never touch this server: checkout and the billing portal are pages Stripe hosts. What comes back and is stored here is a customer id, a subscription id, a price key and the billing period dates. No collector data of any kind reaches Stripe. Ireland, with onward transfers under Stripe’s own terms

Annex IV, retention

WhatKept forWhat happens
Viewing measurement (dwell, zooms, views, opens) 730 days Deleted by created_at.
Marks (shortlisted works) 730 days Deleted with the visit they belong to (ON DELETE CASCADE from room_sessions), and directly by created_at.
Visits 730 days Deleted by started_at, cascading to its events and marks.
Hashed IP address and browser user agent on a visit 90 days Set to NULL in place, on visits older than 90 days.
Dead viewing-room links 365 days Token replaced with a non-resolving tombstone, one year after it expired or was revoked.
Sign-in sessions 30 days Rows past expires_at are deleted.
Password reset tokens 7 days Rows more than 7 days past expiry are deleted. Also swept on the write path by the reset endpoint itself.
Push notification devices 90 days Revoked rows deleted after 90 days; live rows not seen for 365 days deleted.
Data-rights requests 1095 days Completed or rejected rows deleted after 3 years. Unverified rows are dropped after 7 days, because an unverified request is not a request.
Collector contact records While the account is open Nothing automatic; deleted with the workspace or on request.
Inquiries, threads and messages While the account is open Nothing automatic; deleted with the workspace or on request.
Subscription and billing records While the account is open Nothing automatic; deleted with the workspace or on request.
Follow-up drafts and what was sent to the model While the account is open Nothing automatic; deleted with the workspace or on request.
Artwork images in object storage While the account is open Nothing automatic; deleted with the workspace or on request.
Database backups While the account is open Nothing automatic; deleted with the workspace or on request.