Data Processing Addendum

How Jobotics processes personal information on behalf of its customers.

Version 1.1 · Last updated: July 2026

This Data Processing Addendum ("DPA") is entered into by and between Jobotics Inc. ("Company") and the customer identified in the applicable Order Form ("Customer") and is incorporated into the Order Form and Agreement between the parties governing Customer's use of the Services. Capitalized terms not defined herein have the meanings set forth in the Agreement.

1. Scope and Roles

This DPA applies to Company's processing of Customer Personal Information contained in Customer Content in connection with providing the Services. Customer acts as the Controller (or Business, as applicable) and remains responsible for the accuracy, quality, legality, and appropriate collection and use of Customer Personal Information. Company acts as the Processor (or Service Provider or Contractor, as applicable) when processing Personal Information on Customer's behalf. Customer authorizes Company to process Customer Personal Information as necessary to provide the Services and as otherwise permitted under the Agreement and this DPA.

2. Definitions

  • "Controller" means the entity that determines the purposes and means of the processing of Personal Information, or any equivalent term under applicable privacy laws.
  • "Processor" means the entity that processes Personal Information on behalf of a Controller and under the Controller's instructions, or any equivalent term under applicable privacy laws.

3. Processing of Personal Information

Customer instructs and authorizes Company to process Personal Information as necessary to perform the Services and for the purposes expressly described in Section 4.1 of the Agreement, including to:

  • provide, maintain, support, secure, and operate the Services;
  • enhance, analyze, and improve the Services and Company offerings;
  • use Operational Data to train and improve artificial intelligence models used to provide the Services to Company's customers generally; and
  • use Customer Content (excluding Commercial Data) for product management and program administrative purposes.

Company shall not use Commercial Data in any model made available to other customers or for cross-customer learning. Commercial Data shall be used solely to provide the Services to Customer. Company shall not disclose Customer-specific statistics or information that identifies Customer to third parties without Customer's consent.

4. State Privacy Law Requirements

To the extent Company processes Personal Information subject to applicable state privacy laws, Company shall:

  • process Personal Information only for purposes permitted under the Agreement and this DPA;
  • not sell Personal Information;
  • not share Personal Information for cross-context behavioral advertising; and
  • not retain, use, or disclose Personal Information for unrelated commercial purposes.

5. Security Measures and Security Incidents

Company shall maintain a written information security program with commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Information against unauthorized access, use, or disclosure.

Upon confirming a Security Incident involving Customer Personal Information, Company shall notify Customer without undue delay, but no later than seven (7) calendar days from the date of discovery, provide reasonably available information regarding the nature and scope of the incident, and take commercially reasonable steps to mitigate and remediate. The security measures applicable to Company's processing activities are described in Annex 1 (Security Measures) below.

6. Subprocessors

Customer authorizes Company to engage subprocessors to process Customer Personal Information in connection with providing the Services. Company's subprocessor obligations, including notice, contractual requirements, restrictions on use, and responsibility for subprocessor performance, are governed by Section 4.3 of the Agreement. Company's current list of subprocessors is available at jobotics.ai/subprocessors. Subprocessors shall maintain confidentiality and data protection obligations no less protective than those applicable to Company under the Agreement.

7. Data Subject Requests

Company shall provide reasonable assistance to Customer, considering the nature of the Services, to enable Customer to respond to requests from individuals exercising rights under applicable privacy laws. Customer is responsible for responding to Data Subject Requests. If Company receives a request directly, Company may direct the individual to Customer.

8. Return and Deletion of Customer Personal Information

Company's return, archival, and deletion obligations are governed by Section 10 of the Agreement. Following expiration or termination of the Services, Company shall provide Customer access to available Customer Content and delete Customer Content in accordance with the Agreement, subject to permitted retention of information maintained in backups or required by law.

9. Audits and Compliance Reviews

Upon reasonable request, Company shall provide Customer with available documentation demonstrating compliance with applicable security obligations. Where available, Company may satisfy audit requests by providing relevant third-party audit reports, including SOC 2 reports or similar independent assessments. Any additional audit rights shall be subject to the Agreement, reasonable notice requirements, confidentiality obligations, and limitations necessary to protect Company's systems, security, and confidential information.

10. General

This DPA is incorporated into and governed by the Agreement. In the event of conflict between this DPA and the Agreement, this DPA controls solely with respect to processing of Personal Information. The limitations of liability, confidentiality obligations, and other applicable terms of the Agreement apply to this DPA.

Annex 1 — Security Measures

Company shall maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Information against unauthorized access, use, disclosure, alteration, loss, or destruction. Company may update these measures from time to time, provided that such updates do not materially reduce the overall level of protection applicable to Customer Personal Information.

1. Access Controls

Company shall restrict access to Customer Personal Information to authorized personnel with a legitimate business need. Company shall use unique user accounts, role-based access controls, least-privilege principles, and multi-factor authentication for privileged access where supported. Access shall be reviewed periodically and removed or modified when no longer required.

2. Encryption and Data Protection

Company shall use industry-standard encryption to protect Customer Personal Information in transit over public networks and at rest within production systems, where technically applicable. Company shall maintain logical controls designed to separate Customer data from data belonging to other customers.

3. System Security

Company shall maintain reasonable secure-development, change-management, vulnerability-management, and patching practices for systems used to provide the Services. Company shall periodically conduct vulnerability scanning, security reviews, or independent security testing, as appropriate based on risk.

4. Logging and Monitoring

Company shall maintain appropriate logging and monitoring designed to identify unauthorized access, suspicious activity, and material security events. Security-relevant logs shall be protected against unauthorized access or modification and retained for a reasonable period.

5. Availability and Recovery

Company shall maintain reasonable backup, recovery, business-continuity, and disaster-recovery procedures designed to protect Customer Personal Information against accidental loss, destruction, or unavailability. Company shall periodically test restoration or recovery procedures where appropriate.

6. Personnel and Subprocessors

Personnel with access to Customer Personal Information shall be subject to confidentiality obligations and appropriate security and privacy requirements. Company shall require subprocessors that process Customer Personal Information to maintain appropriate confidentiality, security, and data-protection safeguards.

7. Security Incident Management

Company shall maintain procedures designed to identify, investigate, contain, mitigate, and remediate Security Incidents involving Customer Personal Information. Company shall notify Customer of Security Incidents in accordance with the DPA and provide reasonably available information regarding the nature and scope of the incident.

8. Security Documentation

Upon reasonable written request and subject to confidentiality and security restrictions, Company may provide available documentation regarding its security program, including relevant security policies, questionnaire responses, testing summaries, or independent audit reports, where available.

9. Secure Deletion

Company shall maintain procedures designed to securely delete or render inaccessible Customer Personal Information when required under the Agreement or DPA, subject to backup-retention cycles, technical limitations, and legal retention requirements.

Contact

Questions about this DPA or to request a countersigned copy for your organization:
Email: [email protected]