DATA PROCESSING ADDENDUM
How JibeONE handles your customers data, in writing.
GDPR-aligned processor terms with substantive Annex II security measures.
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between the customer ("Controller") and JibeAIs, LLC ("Processor", "JibeONE") and governs Processor's processing of personal data on Controller's behalf. Where the Agreement and this DPA conflict on data protection, this DPA controls.
1. Parties and recitals
The Controller determines the purposes and means of processing personal data within its JibeONE instance. The Processor provides the JibeONE platform and processes that personal data only on the Controller's documented instructions. The parties enter this DPA to comply with Article 28 of the EU General Data Protection Regulation ("GDPR") and equivalent laws.2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "Data Protection Laws" means all laws applicable to the processing, including the GDPR and the UK GDPR.3. Subject-matter and duration
The subject-matter is the provision of the JibeONE platform. Processing continues for the term of the Agreement and until deletion or return of personal data under §12.4. Nature and purpose of processing
The Processor processes personal data to host, operate, secure, and support the platform, and to provide the features the Controller enables, including optional AI features (see the AI Governance page). Processing operations include storage, retrieval, organization, transmission, and deletion.5. Types of personal data and categories of data subjects
The personal data and data-subject categories are determined by the Controller through its use of the platform, and typically include the Controller's staff, customers, and contacts, and business-contact, account, and content data those users enter. The Controller must not submit special-category data except as its own compliance program permits.6. Processor obligations (GDPR Art. 28(3))
The Processor will: (a) process personal data only on the Controller's documented instructions, including this DPA, unless required by law (in which case it will inform the Controller unless prohibited); (b) ensure personnel authorized to process personal data are bound by confidentiality; (c) implement the technical and organizational measures in Annex II; (d) engage sub-processors only under §7; (e) assist the Controller, insofar as possible, in responding to data-subject requests; (f) assist the Controller with security, breach notification, data-protection impact assessments, and prior consultation, taking into account the nature of processing and the information available; (g) delete or return personal data under §12; and (h) make available information necessary to demonstrate compliance and allow for audits under §11.7. Sub-processors
The Controller authorizes the Processor to engage the sub-processors listed on the Sub-processors page. The Processor imposes data-protection obligations on each sub-processor at least as protective as those in this DPA and remains liable for their performance. The Processor will give the Controller notice before adding or replacing a sub-processor, and the Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected service.8. Confidentiality of personnel
The Processor ensures that persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.9. Security measures (Annex II)
The Processor maintains the technical and organizational measures described in Annex II below, designed to ensure a level of security appropriate to the risk.10. Data-subject rights and breach notification
The Processor will assist the Controller, by appropriate measures, in fulfilling its obligation to respond to data-subject requests, and will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, with the information reasonably available to enable the Controller to meet its own notification obligations.11. Audit rights
The Processor makes available information reasonably necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice, no more than once per year absent a specific concern or regulatory requirement, subject to confidentiality and without disrupting the Processor's operations. The Processor may satisfy audit requests by providing third-party attestations where available.12. Deletion or return
On termination of the Agreement, the Processor will, at the Controller's choice, delete or return all Controller personal data, and delete existing copies unless retention is required by law. For on-premises and private-cloud deployments, the Controller controls its own environment and is responsible for deletion within it.13. International transfers (SCCs — Annex I)
Where the Processor transfers Controller personal data outside the EEA or UK to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), and the UK International Data Transfer Addendum where applicable, by reference as Annex A, with the module for controller-to-processor transfers applying and the docking, option, and annex selections completed in the executed order form.14. Liability and governing law
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA is governed by the laws of the State of Virginia, USA except where Data Protection Laws require otherwise.15. Signature
An executed copy is available on request via legal@jibe.one.Annex II — Technical and organizational measures
- Access control and authentication. Single credential store with bcrypt password hashing; mandatory two-factor authentication (WebAuthn passkey or time-based one-time code); deny-by-default session gating.
- Authorization. Role-based access control with no administrative bypass; row-level data filtering enforced in the database; fail-closed access decisions.
- Encryption. Encryption of personal data in transit (TLS); encryption at rest at the infrastructure layer for hosted deployments; protected vault for configuration secrets.
- Audit logging. Security-relevant actions recorded to an audit trail.
- Change and vulnerability management. Controlled release pipeline with automated dependency vulnerability scanning; coordinated vulnerability disclosure (see Security).
- Resilience. Backup tooling and monitoring for hosted deployments (see SLA).
- Sub-processor management. Due diligence and flow-down of data-protection obligations (see Sub-processors).