Privacy

This service reads your systems on your instruction. Most of what passes through it is your data about other people, so the short version is: we hold it briefly, for you, and then delete it.

Controller and roles

The operator is Nytto Labs, a Swedish sole trader operated by Fredrik Kornelind. Registered for VAT in Sweden and approved for F-tax (FA-skatt). Privacy and GDPR requests: privacy@nyttolabs.com.

For your account and billing we are the controller. For the records we read from your sources and the requests we send to your systems, you are the controller and we act as your processor, handling that data only to carry out your documented instructions — which are the sources, checks and correction actions you configure.

What we store, and for how long

DataWhyLegal basisKept for
Account email, API key hashesAuthentication, receipts, service noticesContractLife of the account
Source and action definitions, including secret header valuesTo make the requests you definedContractUntil you delete them
Divergence details (the record key and the differing values)To show you what disagreedContract (processor)Deleted 30 days after the divergence resolves
Correction requests and target responsesTo show you what was sent and what came backContract (processor)Bodies cleared after 30 days; the outcome remains
Run history and costsBilling and dispute handlingLegal obligationRuns 90 days; ledger entries as tax law requires
IP address, brieflyRate limiting unauthenticated requestsLegitimate interest in preventing abuseUp to 1 hour

We do not keep a copy of the records we read. Only the identifier and the specific values that disagreed are stored, and only while the disagreement is open.

Secrets

Secret header values are stored so that we can make your requests. They are never returned by any endpoint, never copied into a run or correction record, and injected only at the moment a request is sent. Deleting a source or action deletes them. API keys are not stored at all: we keep only a keyed hash, and the pepper for that hash lives outside the database, so a copy of the database alone yields no usable keys.

What we do not do

No advertising, no analytics or tracking cookies, no marketing email, no profiling, no sale or sharing of your data. We do not use anything read from your sources to train anything, and we do not read it except to compare it.

Sub-processors

The endpoints we read and write are the ones you nominate, which may be anywhere; that is your instruction and your responsibility as controller. Where our own sub-processors transfer data outside the EEA, that transfer relies on the European Commission’s standard contractual clauses or an adequacy decision.

Your rights

You may request access to, correction of or deletion of your personal data, object to processing, or ask for a portable copy, by writing to privacy@nyttolabs.com. We answer within one month, and you may complain to your national data protection authority. We cannot delete the billing records we are legally required to keep. Where we act as your processor, requests from the people whose data passed through us should go to you; we will help you answer them.