Legal changelog

Last updated 26 August 2026
Last reviewed: 26 August 2026

A dated, reverse-chronological record of changes to DSAR Desk's legal pages, pricing claims, and jurisdiction/deadline figures — what changed, and why. This exists so a business relying on our deadline guide or Terms can see exactly when a figure was corrected, not just what it currently says. See also Privacy Policy for what stays unchanged (how we handle data). These pages are reviewed on a quarterly cycle internally; this log is updated whenever that review changes something.

Scope:

This log covers legal, policy, or deadline-figure changes only — pricing corrections, jurisdiction facts, entity-name fixes, and similar. It does not cover ordinary product/design changes to the site.

2026

26 August 2026

Trust and policy page pack added; sub-processor list moved

privacy.html, security.html, dpa.html, subprocessors.html, refunds.html, contact.html, accessibility.html, service-status.html, about.html
26 August 2026

Fact/consistency audit and DPDP rewrite

26 August 2026 (same day, follow-up)

Resolved the 90-day DPDP question the first pass flagged

25 August 2026

Baseline (pre-audit)

Terms of Service and Privacy Policy last carried this date before the 26 August 2026 audit above. No changelog existed prior to this page being created.

26 August 2026 (later the same day)

Removed the free-plan hard block at the intake form

The Free plan previously declined a business's 4th data-subject request in a calendar month at the intake form, telling the requester to contact the business directly. Removed this entirely: every request is now accepted, stored and deadline-tracked regardless of plan or count — a real statutory request is the business's legal obligation whether or not they're paying us, and refusing to even track it was a risk this product cannot carry. Past 3 requests in a month, the business's notification email for that request now includes one additional line noting they're over the Free plan's count and that Pro removes it, but nothing about how the request itself is handled changes. Updated terms.html and the pricing card to describe this accurately.

terms.html, index.html, app.html, lambda/dsardesk/index.mjs
26 August 2026 (later still)

Corrected the privacy policy's self-serve deletion claim; surfaced the requester status page

The privacy policy said "DSAR Desk does not yet have... a self-serve delete my workspace button" — that button has existed in Settings for a while; the policy text was simply never updated when it shipped. Corrected it to describe what actually happens on deletion. Separately, a requester-facing status page (status.html, backed by /api/dsar-status) already existed but was never linked from anywhere a requester would actually see it — added a link to it in the request-confirmation email and on the intake form's "request submitted" screen.

privacy.html, r.html, lambda/dsardesk/index.mjs