jimble.dev

Data Processing Agreement (DPA)

Personal Data Processing Agreement

1. Definitions

2. Purpose and term

This agreement sets out the conditions under which the Processor undertakes to process personal data on behalf of the Controller in connection with the use of the jimble.dev platform. It enters into force upon acceptance of these terms and remains in force for the entire duration of use of the service.

3. Nature and purpose of the processing

4. Types of data and categories of data subjects

Categories of data subjects: the Customer's end users, contacts or employees

Types of data: data determined by the Customer within its workflows (e.g. names, emails, message contents, application logs, etc.). The Processor does not determine the purposes or the means of the processing.

5. Obligations of the Processor

The Processor undertakes to:

6. Technical and organisational measures

The Processor applies the security measures described in our Security Policy, in particular:

7. Sub-processors

The Controller authorises the Processor to engage the Sub-processors listed on this page. Any change to this list will be notified to the Controller with 12 days' prior notice, allowing the Controller to object to the change.

8. International transfers

The data is hosted in the EU and is not transferred outside the EU.

9. Audit and compliance

The Controller may, upon written request and with reasonable prior notice, audit the Processor's compliance or appoint an independent auditor to do so. The Processor makes the necessary documentation available (ISO 27001 and SOC 2 certifications, penetration test reports, etc.).

10. Breach notification

In the event of a personal data breach, the Processor notifies the Controller within 72 hours with the following information: nature of the breach, categories and approximate number of data subjects concerned, measures taken or proposed.

11. Return and deletion of data

At the end of the contract, the Processor deletes or returns all personal data, at the Controller's choice, unless there is a legal obligation to retain it. Deletion takes place within one year.

12. Governing law

This agreement is governed by French law and the GDPR.

Last updated: 7 July 2026