Legal · Teams
Data Processing Addendum
Draft for review. This DPA is provided for evaluation and is not an executed contract. It becomes binding only when signed by both parties as part of a Jettova for Teams agreement, and should be reviewed by your legal counsel. Terms are subject to change before execution.
This addendum describes how Jettova processes personal data on behalf of a Teams customer. It reflects controls that exist in the product today; where it uses contractual language (transfers, notification, return of data), those terms require execution to take effect.
1. Parties and roles
This Data Processing Addendum ("DPA") supplements the agreement between Jettova, Inc. ("Jettova") and the customer organization that has subscribed to Jettova for Teams ("Customer"). It applies where Jettova processes personal data on Customer's behalf in connection with the Services.
For personal data that Customer's members submit through a Teams account (rosters, trip inputs, expense data), Customer is the controller and Jettova acts as the processor, processing that data only on Customer's documented instructions. Where Jettova determines the purposes and means of processing its own account and billing data, Jettova acts as an independent controller under its Privacy Policy.
2. Categories of data and data subjects
Data subjects: Customer's authorized users (team members, organizers, and administrators) who use a Teams account.
Categories of personal data: identity and contact data (name, email, and the identifiers returned by Customer's identity provider when SSO is used); organizational data (org membership and role); trip-planning content (destinations, dates, preferences, votes, itinerary edits); and, where expense splitting is used, the structured fields extracted from receipts (merchant, total, currency, line items). Receipt images are processed and discarded, not stored. Jettova does not store payment card data.
Jettova does not intend to process special categories of personal data through the Services and instructs Customer not to submit them.
3. Purpose and duration of processing
Jettova processes the personal data described above solely to provide, maintain, secure, and support the Services for Customer — planning and coordinating trips, managing org membership and roles, facilitating team communications, and providing administrative recaps and exports.
Processing continues for the term of the agreement and for the limited period afterward described in Section 9 (return and deletion).
4. Security measures
Jettova maintains technical and organizational measures appropriate to the risk, including: deny-by-default database access with row-level security and server-mediated service-role access; encryption in transit (HTTPS/TLS) and managed encryption at rest; Supabase Auth with enterprise SSO/SAML and SCIM provisioning available for Teams; org role-based access control with audit logging; hashed API keys with usage metering; rate limiting; and error monitoring via Sentry.
A fuller description is published and kept current at /security.
5. Sub-processors
Customer authorizes Jettova to engage the sub-processors listed at /subprocessors to process personal data in support of the Services. Jettova imposes data-protection obligations on each sub-processor consistent with this DPA and remains responsible for their performance.
Jettova will make the current sub-processor list available and will use reasonable efforts to notify Customer of intended additions or replacements so Customer has an opportunity to object on reasonable data-protection grounds.
6. International transfers
Where processing involves transferring personal data across borders, the transfer will be carried out under a lawful transfer mechanism, such as the Standard Contractual Clauses (SCCs) where applicable, together with any supplementary measures reasonably required. The specific hosting region applicable to a deployment is as configured for that deployment; see /data-residency.
7. Data subject rights
Taking into account the nature of the processing, Jettova will assist Customer in responding to data subject requests. The Services already support the core mechanisms: individual users can delete their own account and data at /delete-account, and Teams owners and admins can export their organization's data from the org console. Jettova will provide reasonable additional assistance for access, correction, and deletion requests Customer cannot fulfill through the Services.
8. Personal data breach notification
Jettova will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's personal data, and will provide the information reasonably available to help Customer meet its own notification obligations, along with a description of measures taken or proposed to address the breach.
9. Return and deletion of data
On termination or expiry of the agreement, and at Customer's choice, Jettova will delete or return Customer's personal data and delete existing copies, except where retention is required by applicable law. Customer can also export data before termination and can trigger deletions through the Services as described above. Backup copies are purged on their ordinary cycle.
Referenced here: Security measures, Sub-processors, Data residency, and the Privacy Policy.
To execute a DPA for your team, contact us.