Legal
Data Processing Agreement
This Data Processing Agreement (the "DPA") sets out how Andre Blunt Kft ("Joblobos", "we", "us", "our") processes personal data on behalf of a tenant ("you", the "Tenant" or "Customer") when you use the Joblobos platform. It gives effect to Article 28(3) of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"). For the End Customer and business records you enter into Joblobos, you are the controller and we are your processor; this DPA governs that processing.
This DPA is published at joblobos.com/legal/dpa and is incorporated into and forms part of our Terms of Service. By subscribing to or using the service, you accept it. No separate signature is required. Where you and we have signed a negotiated data processing agreement, that signed agreement controls for any point on which it conflicts with this DPA. Last updated: 2026-07-11.
1. Roles and Scope
This DPA applies where we process personal data on your behalf as your processor, in the course of providing the Joblobos platform to you under the Terms of Service. For that data you are the controller and we are the processor within the meaning of the GDPR.
This DPA does not apply to personal data for which we are the controller in our own right, such as your account and administrator details, our billing relationship with you, website-visitor data, and the telemetry we collect to run and secure the service. Our own controller processing is described in our Privacy Policy.
In this DPA, "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given to them in the GDPR. "Customer Personal Data" means the personal data within the Tenant Data (as defined in the Terms of Service) that we process on your behalf under the Terms of Service.
As controller, you determine the purposes and means of processing Customer Personal Data. You are responsible for establishing and maintaining a lawful basis under Article 6 and, where relevant, Article 9; for the accuracy, quality, and legality of the Customer Personal Data and of your instructions to us; for having the right to provide that data to us for processing; and for responding to data subjects as the controller. Your rights include giving and varying documented instructions under Section 4, objecting to sub-processors under Section 7, receiving the assistance in Sections 8 and 9, auditing under Section 12, and having Customer Personal Data returned or deleted under Section 11.
2. Subject-Matter, Duration, Nature and Purpose of Processing
Subject-matter. The processing under this DPA is our processing of Customer Personal Data to provide the Joblobos platform to you, a multi-tenant application for running the commercial side of a trade business.
Duration. We process Customer Personal Data for as long as you have an account and use the service, and afterward only for the limited period needed to return or delete it as set out in this DPA and the Terms of Service.
Nature and purpose. The nature of the processing is hosting, storage, organization, retrieval, transmission, display, and deletion of Customer Personal Data, together with the messaging and optional AI processing involved in the features you enable, carried out by automated means through the platform and its sub-processors. The purpose is limited to providing, securing, maintaining, and supporting the service on your documented instructions, and complying with law.
3. Categories of Data Subjects and Personal Data
Categories of data subjects. Your End Customers and leads (the individuals whose details you or your website visitors enter into Joblobos), and the individuals named within your business records.
Categories of personal data. Identification and contact details such as name, email address, postal or site address, and phone number; the content of messages exchanged with an End Customer, including SMS, WhatsApp, and lead-capture chat content; and business-record data such as quotes, orders, invoices, recorded payments, notes, and system or design details that relate to an identifiable individual.
You control what personal data you enter into the service. You must not enter special categories of personal data (Article 9) or criminal-offence data (Article 10) unless you and we have agreed appropriate additional measures in writing.
4. Processing on Documented Instructions
We process Customer Personal Data only on your documented instructions, including as to any transfer to a third country or an international organization, unless we are required to process by Union or Hungarian law to which we are subject; in that case we inform you of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
Your documented instructions are made up of the Terms of Service, this DPA, and your use and configuration of the service through its features and settings. Additional or different instructions must be agreed in writing and may be subject to a change in fees where they require work beyond the standard operation of the service.
We immediately inform you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. We are not obliged to carry out an instruction we reasonably believe to be unlawful.
5. Confidentiality
We ensure that the persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. We limit access to Customer Personal Data to personnel who need it to provide, secure, or support the service, on a least-privilege basis.
6. Security of Processing (Article 32)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to individuals, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. A summary of our current measures is set out in Annex B.
We keep our measures under review and may update them as the service and the threat landscape develop, provided the level of protection is not materially reduced.
7. Sub-Processors
You give us general authorization to engage sub-processors to process Customer Personal Data in order to provide the service. Our current sub-processors are listed in Annex A, which mirrors the sub-processor list in our Privacy Policy.
Where we engage a sub-processor, we impose on it, by contract, data protection obligations that are in substance no less protective than those in this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures under Article 28. We remain liable to you for the performance of each sub-processor's obligations.
We maintain the list of sub-processors in Annex A. When we intend to add or replace a sub-processor, we give you reasonable prior notice, for example by updating Annex A and the Privacy Policy and, where you have asked to be told, by notifying you. You may object to a proposed change on reasonable data protection grounds within the notice period. If you do, we will work with you in good faith to address the objection; if we cannot, you may, as your sole remedy, terminate the affected part of the service and stop using the feature that requires the sub-processor.
8. Assistance with Data-Subject Requests
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR, including access, rectification, erasure, restriction, portability, and objection.
Much of this assistance is built into the service: you can view, edit, export, and delete the End Customer and business records in your workspace directly. If we receive a request from one of your End Customers or another data subject that relates to Customer Personal Data, we do not respond directly except to acknowledge and redirect them to you as the controller, and we tell you without undue delay.
9. Assistance with Security, Breach, and Impact Assessments (Articles 32 to 36)
Taking into account the nature of processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR. This covers security of processing, notification of a personal data breach to the supervisory authority and to affected data subjects, data protection impact assessments, and prior consultation with the supervisory authority.
Our assistance is proportionate to the information we hold as processor and may be subject to reasonable fees where it goes beyond the standard operation of the service.
10. Personal Data Breach
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take.
Where we do not have all of this information at once, we provide it in phases as it becomes available. As your processor, we do not notify the supervisory authority or the affected data subjects on our own account for breaches of Customer Personal Data; you, as the controller, are responsible for any such notification, and we support you in making it.
11. Deletion or Return of Personal Data
On termination of the service, and at your choice, we delete or return all Customer Personal Data to you and delete existing copies, unless Union or Hungarian law requires us to keep the data.
In practice, you may export your Customer Personal Data through the service's export functionality during the export window described in the Terms of Service. After that window we delete or de-identify Customer Personal Data in the ordinary course, subject to copies held in routine backups that age out on our normal cycle and to any records we are required by law to retain. Backup copies are isolated from active processing and are deleted as the backups expire.
12. Audits and Information
We make available to you the information necessary to demonstrate compliance with the obligations in Article 28 and this DPA, and we allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
To keep audits proportionate and to protect the security and confidentiality of our other tenants, audits are conducted on reasonable prior notice, no more than once a year unless a supervisory authority requires otherwise or we have had a material breach, during business hours, subject to confidentiality, and in a way that does not give access to other tenants' data. We may satisfy an audit request by providing our current security documentation and third-party reports where these reasonably address your request. Each party bears its own costs, and you cover our reasonable costs for any audit that goes beyond the provision of standard documentation.
13. International Transfers
We aim to keep Customer Personal Data within the European Union, and our primary database, authentication, and file storage are hosted in an EU region. Some sub-processors listed in Annex A process limited data outside the European Economic Area, in particular Twilio and Anthropic in the United States.
Where a transfer of Customer Personal Data to a third country takes place, we rely on an appropriate safeguard recognized under the GDPR, in most cases the European Commission's Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework, together with supplementary measures where needed. The transfer mechanism is described in Annex B. The specific safeguard depends on the provider and its current certification status; we will provide the mechanism relied upon for a named provider on request at legal@joblobos.com.
14. Liability, Precedence, and Governing Law
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Where the Standard Contractual Clauses apply to a transfer, and only in respect of that transfer and its data subjects, the liability and redress terms of those clauses apply as written and are not limited by this paragraph.
If there is a conflict, the order of precedence is: first, the Standard Contractual Clauses for any matter they govern; second, this DPA; third, the rest of the Terms of Service. This DPA is governed by the laws of Hungary and is subject to the governing-law and jurisdiction terms of the Terms of Service, without prejudice to any mandatory data-subject rights or supervisory-authority competence under the GDPR.
Annex A: Approved Sub-Processors
This Annex lists the sub-processors we engage to process Customer Personal Data. It mirrors the sub-processor list in our Privacy Policy, and the two are kept in sync. We give reasonable prior notice of changes as set out in Section 7.
Supabase. Purpose: database, authentication, and file storage; the primary store for account and tenant data. Location and transfer basis: hosted in an EU region.
Vercel. Purpose: application hosting and content delivery for the website and app. Location and transfer basis: may process limited data outside the EEA under an appropriate Chapter V safeguard (Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework).
Stripe. Purpose: subscription billing for Joblobos plans; processes payment details under its own terms. Location and transfer basis: may process limited data outside the EEA under an appropriate Chapter V safeguard (Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework).
Resend. Purpose: delivery of transactional email such as account, security, and notification messages. Location and transfer basis: may process limited data outside the EEA under an appropriate Chapter V safeguard (Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework).
Sentry. Purpose: error monitoring and diagnostics, which may include limited technical context attached to error events. Location and transfer basis: may process limited data outside the EEA under an appropriate Chapter V safeguard (Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework).
Twilio. Purpose: sending and delivery of WhatsApp and SMS messages between a tenant and its End Customers, processing the sender and recipient phone numbers, the message content, and delivery-status information; WhatsApp messages are additionally routed through Meta's WhatsApp Business Platform to reach the recipient. Location and transfer basis: processes data in the United States, outside the EEA; for that transfer we rely on an appropriate safeguard recognized under the GDPR, in most cases the European Commission's Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework.
Anthropic. Purpose: the optional AI features of the platform, including the lead-capture assistant, the design calculator, and estimating assistance; when a tenant or a tenant's website visitor uses one of these features, the text of that interaction, which can include a name, email, or phone number, is sent to generate a response, and under Anthropic's commercial terms the submitted content is not used to train its models. These features run only when enabled. Location and transfer basis: processes data in the United States, outside the EEA; for that transfer we rely on an appropriate safeguard recognized under the GDPR, in most cases the European Commission's Standard Contractual Clauses or, where the provider is certified, the EU-US Data Privacy Framework.
Annex B: Transfer Mechanism and Technical and Organizational Measures
Transfer mechanism. Our primary database, authentication, and file storage are hosted in an EU region, so the core of Customer Personal Data remains within the European Union. The restricted transfers that arise in practice are the onward transfers from the EEA to the United States made by certain sub-processors, in particular Twilio and Anthropic. For those onward transfers we rely on the relevant sub-processor's Chapter V safeguard: the Standard Contractual Clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, or, where the provider is certified, the EU-US Data Privacy Framework, together with supplementary measures where needed. Where you as controller require controller-to-processor Standard Contractual Clauses between you and us for our own processing, we will complete the applicable module and its operative annexes and, where you require it, execute that package with you; the current form is available on request at legal@joblobos.com.
Technical and organizational measures. The measures below summarize our current security posture and give effect to Article 32; where the SCCs apply, this summary informs their Annex II, which must be completed on formalization. Encryption of Customer Personal Data in transit. Encryption at rest provided by our infrastructure. Authentication and role-based access controls. Logical separation of each tenant's data in the multi-tenant database, enforced at the database layer. Least-privilege access for staff, limited to those who need it. Monitoring and error tracking. Regular review of our providers and sub-processors. No system is perfectly secure, so we do not guarantee absolute security; we maintain measures appropriate to the risk and keep them under review. Where the Standard Contractual Clauses apply to a transfer, the additional measures required for their Annex II are completed with that package on formalization.