Data Processing Agreement (DPA)
Personal Data Processing Agreement
1. Definitions
- Controller: the Customer using the jimble.dev platform
- Processor: JIMBLE LABS, publisher of jimble.dev
- Personal data: any information relating to an identified or identifiable natural person processed via the platform
- GDPR: Regulation (EU) 2016/679 of 27 April 2016
2. Purpose and term
This agreement sets out the conditions under which the Processor undertakes to process personal data on behalf of the Controller in connection with the use of the jimble.dev platform. It enters into force upon acceptance of these terms and remains in force for the entire duration of use of the service.
3. Nature and purpose of the processing
- Nature of the operations: hosting, storage, processing and analysis of data via AI workflows
- Purpose: provision of the jimble.dev service (execution of event-driven workflows, AI API calls, management of logs and results)
- Duration of the processing: for the entire duration of the subscription and for one year after termination
4. Types of data and categories of data subjects
Categories of data subjects: the Customer's end users, contacts or employees
Types of data: data determined by the Customer within its workflows (e.g. names, emails, message contents, application logs, etc.). The Processor does not determine the purposes or the means of the processing.
5. Obligations of the Processor
The Processor undertakes to:
- Process the data only on documented instructions from the Controller
- Ensure the confidentiality of the data (trained personnel subject to confidentiality obligations)
- Implement appropriate technical and organisational measures (see the Security section)
- Not engage any Sub-processor without the prior written authorisation of the Controller (list available on this page)
- Assist the Controller in complying with the rights of data subjects (access, rectification, erasure, etc.)
- Notify any personal data breach within 72 hours
- Make available all information necessary to demonstrate compliance with its obligations and allow for audits
6. Technical and organisational measures
The Processor applies the security measures described in our Security Policy, in particular:
- Encryption of data in transit (TLS) and at rest (AES-256)
- Role-based access control (RBAC)
- Access logging and monitoring
- Regular encrypted backups
- Vulnerability management and security updates
7. Sub-processors
The Controller authorises the Processor to engage the Sub-processors listed on this page. Any change to this list will be notified to the Controller with 12 days' prior notice, allowing the Controller to object to the change.
8. International transfers
The data is hosted in the EU and is not transferred outside the EU.
9. Audit and compliance
The Controller may, upon written request and with reasonable prior notice, audit the Processor's compliance or appoint an independent auditor to do so. The Processor makes the necessary documentation available (ISO 27001 and SOC 2 certifications, penetration test reports, etc.).
10. Breach notification
In the event of a personal data breach, the Processor notifies the Controller within 72 hours with the following information: nature of the breach, categories and approximate number of data subjects concerned, measures taken or proposed.
11. Return and deletion of data
At the end of the contract, the Processor deletes or returns all personal data, at the Controller's choice, unless there is a legal obligation to retain it. Deletion takes place within one year.
12. Governing law
This agreement is governed by French law and the GDPR.
Last updated: 7 July 2026