LanternTeam learning
Privacy & data protection

GDPR
at Lantern.

A team guide to customer data, the controls we provide, and the responsibilities we share.

Internal training  ·  7 October 2026  ·  About 30 minutes

In this guide
Part 01

The GDPR basics

Understand the data, the principles and who is responsible.

GDPR overview

General Data Protection Regulation

  • GDPR sets rules for the use of personal data and protects people’s rights.
  • EU GDPR and UK GDPR are related but separate legal regimes.
  • The rules can apply to businesses outside Europe serving people there.
  • Everyone handling personal data contributes to compliance.
Further context & references

EU GDPR and UK GDPR are separate legal regimes. The applicable rules depend on the organisation, the people whose data it uses and the processing involved.

Personal data in everyday work

Personal data

  • Customer names, emails and IP addresses
  • Quiz answers linked to a person or session
  • Merchant contacts, support tickets and exports

Processing

  • Opening a submission to troubleshoot
  • Sending answers to a connected integration
  • Downloading, editing or deleting a CSV
Further context & references

Personal data can identify someone directly or through a combination of details. Viewing, storing, exporting, sharing and deleting personal data are all forms of processing.

GDPR principles in daily work

Lawful and transparent use

Primarily the merchant’s responsibility for quiz data

The merchant explains why it collects personal data, how it will use it and the lawful basis for doing so. Its privacy information should make clear how Lantern and enabled integrations fit into that processing. Lantern handles quiz data under the merchant’s documented instructions.

Purpose and minimisation

Primarily the merchant’s responsibility for quiz configuration

The merchant chooses the purpose of the quiz and collects only the data needed for that purpose. It also decides which integrations should receive the answers. Our team uses only the records needed for an authorised task and avoids unnecessary access, exports or copies.

Accuracy and retention

Lantern’s responsibility when handling the data

We support corrections and deletion under verified merchant instructions, follow the applicable retention rules and use approved procedures to remove or anonymise data. We avoid introducing errors when handling records. The merchant remains responsible for the accuracy and retention decisions it controls.

Security

Lantern’s responsibility for its processing

We protect personal data from loss, misuse and unauthorised access. This includes secure logins, restricted access, encryption and confidential handling. Each team member follows the company’s security procedures and promptly reports suspected incidents.

Further context & references

Data protection principles apply throughout the processing lifecycle. Controllers determine the purposes and lawful basis. Processors follow documented instructions and have their own security and other legal duties.

The merchant and Lantern have different roles

Merchant: controller

  • Chooses quiz questions and purposes
  • Decides what to collect and share
  • Handles notices, lawful basis and customer rights

Lantern: processor

  • Processes quiz data under instructions
  • Operates and secures the service
  • Provides controls and assistance to the merchant

App Attic Ltd also acts as a controller for its own business data.

Further context & references

A controller decides the purposes and means of processing. A processor handles personal data on the controller’s behalf. An organisation can have different roles for different processing activities.

Configuration responsibility and processor duties

The merchant decides

  • Whether each question is necessary
  • Its lawful basis and consent approach
  • Which integrations receive answers
  • Whether a data protection impact assessment is needed

Lantern’s processor duties

  • Follow authorised processing instructions
  • Maintain appropriate security and confidentiality
  • Help the merchant fulfil individuals’ rights
  • Notify the merchant of personal data breaches
  • Use authorised subprocessors under written agreements

What rights can a person exercise?

People can ask what personal data is held about them, how it is used and for a copy of that data. They can ask for incorrect data to be corrected and, where the right applies, for their data to be deleted. Other rights can include restricting processing, objecting to particular uses and receiving data in a portable format.

For quiz data, the merchant leads the response as controller. Lantern helps locate, export, correct or delete records under verified instructions. A deletion request does not automatically override a legal requirement to retain data.

What does incident response mean for Lantern?

If we become aware of a personal data breach affecting a merchant’s data, we must notify that merchant without undue delay, and no later than 72 hours after awareness, and provide the information needed to support its response. Team members report suspected incidents immediately through the internal incident route or their team lead.

What is a subprocessor agreement?

A subprocessor is a provider that handles personal data on Lantern’s behalf to help deliver the service, such as Google Cloud or Tinybird. Lantern needs the merchant’s prior specific or general written authorisation to use subprocessors.

Lantern must put a written agreement in place with each subprocessor, requiring equivalent data protection obligations for the work it performs. These include limits on data use, confidentiality, security and assistance with relevant privacy obligations. Where the merchant gives general authorisation, planned provider changes require notice and an opportunity to object.

Lantern remains responsible to the merchant for its subprocessors’ processing obligations. The team must use approved providers and escalate requests to introduce a new tool or share data with a new provider.

Further context & references

Processors assist controllers with individual rights and notify them of personal data breaches without undue delay. Engaging a subprocessor requires prior specific or general written authorisation and a written contract imposing equivalent data protection obligations.

Sensitive data needs additional protection

Sensitive personal data such as health information, religious or philosophical beliefs, and information about a person’s sex life or sexual orientation receives additional protection under GDPR. These categories are known as special category data.

Misuse or disclosure can create particular risks to people, including discrimination. That is why GDPR requires additional justification and safeguards for processing this information.

The merchant is responsible for identifying an Article 6 lawful basis and a separate Article 9 condition for the special category data it chooses to collect and use through its quiz.

Marketing consent alone does not establish permission to process special category data. Lantern’s team should understand the additional sensitivity and continue to apply our confidentiality, security and processing obligations.

Further context & references

Special category data requires an Article 6 lawful basis and a separate Article 9 condition. Health information, religious or philosophical beliefs, sex life and sexual orientation fall within these protected categories.

Part 02

Processing agreements

Know what a DPA does and how to handle document requests.

What a DPA means

A Data Processing Agreement sets binding rules for how a processor handles data for a controller.

  • It defines the processing and the parties’ responsibilities.
  • It covers confidentiality, security and subprocessors.
  • It covers assistance, incidents, deletion or return, and audit information.
Further context & references

Article 28 requires binding processing terms covering the scope of processing and the parties’ obligations. These include instructions, confidentiality, security, subprocessors, assistance, deletion or return and audit information.

DPA questions in customer support

  • Confirm the legal entity: App Attic Ltd, operator of the Lantern Shopify app.
  • Use approved Lantern documents and check the domain and version.
  • Escalate requests for a DPA, signature or contractual commitment.
  • Never confirm that lantern.ai/lantern-dpa applies to our app.
Further context & references

A processing agreement may take electronic form. A separately countersigned PDF is not the only possible arrangement, but the applicable terms must legally bind the parties and meet Article 28 requirements.

Part 03

Lantern’s controls & data lifecycle

Explain hosting, sharing, retention and customer choices accurately.

Hosting, analytics and international access

  • Google Cloud: quiz responses in the Netherlands and Belgium.
  • Tinybird: response storage for advanced analytics in the EU.
  • Merchants can disable advanced analytics and answer storage outside Google Cloud inside the app.
  • Authorised access can include the UK, EU, Philippines and other approved locations.

International access needs safeguards

  • Personnel follow contractual confidentiality and data protection obligations.
  • Training and authenticated access help protect day-to-day handling.
  • Storing answers in the EU and allowing someone to access them from another country are separate parts of the data flow. Overseas access can also require legal safeguards.
  • Before granting access to an overseas provider or contractor, Lantern must check the recipient, the country and the safeguards required for that arrangement.
  • Standard Contractual Clauses can provide contractual safeguards where appropriate. The EU–US Data Privacy Framework applies to eligible transfers to certified US recipients.
Further context & references

The location of storage and the location of access can differ. Whether overseas access is a restricted transfer depends on the legal entities and arrangement involved. Employees within the same entity and separate contractors may be treated differently. EU and UK transfers can require different contractual safeguards.

Lantern’s security measures

  • Encryption protects data in transit and at rest.
  • Access controls and authentication restrict who can use systems.
  • Activity logging and security reviews support monitoring.
  • Confidentiality obligations and training govern personnel handling.
  • Lantern does not hold SOC 2 or ISO 27001 certification.

Sensitive Data Controls

01

Normal

Lantern stores the answer and sends it to connected integrations as usual.

02

Don't share

The answer stays in Lantern, including Submissions, analytics and CSV exports. Integrations do not receive it.

03

Don't store

Lantern uses the answer for the current quiz session, then deletes it when results are generated. Integrations do not receive it.

Try an example

A health-related quiz answer

What changes when the merchant changes this question’s setting?

Sensitive data setting
Normal

Lantern retains the answer and sends it to enabled integrations, such as Klaviyo.

Illustrative example. Opt-in details follow separate rules. Publish a changed quiz setting for it to take effect.

AI features and connected integrations

AI content generation

Lantern’s AI functionality generates quiz content using the merchant’s product catalogue and the instructions the merchant provides.

Customer quiz responses and contact details are not sent to AI providers, including OpenAI or Anthropic. Lantern does not supply these data to those providers for model training.

Data shared through connected tools

Merchants can enable data flows to email and SMS marketing platforms, Shopify Flow, Shopify customer metafields, automation tools, custom webhooks and other supported integrations.

The merchant chooses which connections to enable and how to use the data in each destination. Enabling a connection instructs Lantern to send the relevant data, subject to the quiz’s Sensitive Data settings.

Each destination handles the data under the merchant’s agreement and the terms applicable to that service. The merchant is responsible for ensuring its collection and use of the data, including marketing or automated workflows, has the required legal basis.

Don’t share and Don’t store prevent the affected question’s answer from flowing to connected integrations. Information collected on the Opt-in page, such as contact details and marketing consent, follows separate rules and can still sync.

Once data has reached another tool, Lantern’s deletion process does not automatically remove that copy. The merchant must manage those records in the destination service.

Retention and uninstall

  • While installed: Lantern retains submissions, except answers set to Don’t store.
  • After uninstall: Shopify normally sends a redaction request after about 48 hours.
  • Lantern removes identifiers, withdraws submissions from access and reporting, and deletes uploaded files.
  • Lantern retains anonymised submissions for up to 36 months after uninstallation.

Anonymised data must no longer allow a person to be identified.

Further context & references

Removing names or email addresses does not automatically make data anonymous. Effective anonymisation requires that people can no longer be identified by means reasonably likely to be used, including through remaining details or links to other data.

Part 04

Our everyday responsibilities

Protect customer information in every support and operational task.

Confidentiality in everyday work

  • Use customer information only for authorised work.
  • Access the minimum records needed for the task.
  • Share internally only with people who need the information.
  • Follow your signed confidentiality terms and current privacy policies.
  • Follow offboarding instructions for access, devices and retained copies.
Further context & references

Article 28 requires authorised personnel to commit to confidentiality or be subject to an appropriate statutory duty. Access should remain limited to the work a person is authorised to perform.

Accounts, passwords and devices

Safe access

  • Keep logins individual and never share credentials
  • Use unique passwords and approved storage
  • Enable multi-factor authentication where available
  • Lock and update your work device

Information to protect

  • Passwords and one-time codes
  • API keys, tokens and session links
  • Merchant account access details
  • Customer records visible on screen
Further context & references

GDPR requires appropriate security measures. Individual access, secure password handling and multi-factor authentication help reduce the risk of unauthorised access.

Support tickets, screenshots and exports

  • Use test data whenever it can reproduce the issue.
  • Crop or redact names, emails and sensitive answers in screenshots.
  • Check the store, recipient and attachment before sharing.
  • Do not offer to export customer data onto your local device.
  • If a customer explicitly requests an export, verify their authority and use the approved process. Avoid local downloads and use approved storage and delivery methods.
  • If you produce a customer-data CSV for an authorised request, delete your working copy as soon as the task is complete. Remove local downloads and temporary copies using the approved deletion procedure.
Further context & references

Data security covers everyday handling as well as technical systems. Limiting copies and access reduces the risk of accidental disclosure or loss.

Part 05

Incidents & customer conversations

Escalate quickly and explain our responsibilities clearly.

Suspected breaches need immediate escalation

Wrong recipient. Exposed export. Lost device. Suspicious login.

  • Report immediately through the internal incident route or your team lead.
  • Preserve evidence and record what happened and when.
  • Contain the issue only within your authority and follow the incident lead.
  • Lantern notifies affected merchants without undue delay, and no later than 72 hours after becoming aware of a personal data breach affecting their data.

The 72-hour limit is an outer deadline. Team members must report suspected incidents immediately.

Further context & references

Processors must notify controllers of personal data breaches without undue delay. Separately, controllers assess regulator notification, generally within 72 hours of awareness where the relevant risk threshold is met. High-risk breaches may also require notification to affected individuals.

A helpful customer response

Lantern provides tools to control storage and sharing. You decide how to configure the quiz and establish the lawful basis for your use.
  • Explain the relevant control and its limits.
  • Use current approved facts, including that Lantern has no SOC 2 or ISO 27001 certification.
  • Escalate legal commitments and evidence requests to the authorised owner.