// JobsBook.app

Data Processing Addendum

Effective: 27 July 2026 · Version 2026-07-27

This Data Processing Addendum ("DPA") supplements the JobsBook.app Terms of Service. It reflects the parties' obligations under Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679) where you upload personal data of your own customers into JobsBook.app. By accepting the Terms you accept this DPA. An executed copy is available on request from info@yourdataapp.com.

1. Definitions

Capitalised terms not defined here have the meaning given in the GDPR:

  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meaning in Article 4 GDPR.
  • "Customer" means the tenant / subscriber to the Service.
  • "Provider" means YourDataApp Ltd.
  • "Customer Personal Data" means Personal Data uploaded to or generated by the Service under the Customer's account.
  • "Sub-processor" means a third party engaged by the Provider to process Customer Personal Data.

2. Roles

The parties acknowledge that in respect of Customer Personal Data uploaded into the Service (e.g. customer records, staff records, bookings, invoices), the Customer is the Controller and the Provider is the Processor. Where the Provider processes Personal Data of the Customer's own account holder for its own purposes (billing, account administration, security), the Provider is an independent Controller and its processing is described in the Privacy Policy.

3. Subject-matter, duration and nature of processing

  • Subject-matter: provision of the JobsBook.app Service (bookings, staff dispatch, invoicing, customer records).
  • Duration: for as long as the Customer's subscription is active, plus the retention periods set out in the Privacy Policy.
  • Nature and purpose: hosting, storing, transmitting, displaying and generating personal-data-containing artefacts required to deliver the Service.
  • Categories of Data Subjects: Customer's own employees / staff, Customer's clients / consumers, Customer's account users.
  • Categories of Personal Data: identification data (name, contact details), professional data (job role, staff PIN), commercial data (invoices, bookings), technical data (IP address truncated, session tokens), address / geolocation data.

4. Provider obligations

The Provider shall:

  • process Customer Personal Data only on documented instructions from the Customer, including transfers, unless required by EU or Member State law;
  • ensure that persons authorised to process Personal Data have committed themselves to confidentiality;
  • implement the technical and organisational security measures described in Annex II (below);
  • assist the Customer, taking into account the nature of processing, in responding to Data Subject rights requests, and in complying with Articles 32–36 GDPR;
  • notify the Customer without undue delay after becoming aware of a Personal Data Breach;
  • at the Customer's choice, delete or return all Personal Data at end of provision, and delete existing copies unless retention is required by law;
  • make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR and allow for audits, including inspections, conducted by the Customer or a mandated auditor (subject to reasonable confidentiality and scheduling arrangements).

5. Sub-processors

The Customer grants a general written authorisation to the Provider to engage Sub-processors, subject to (a) written contractual terms flowing down GDPR-equivalent obligations, (b) the Provider remaining fully liable to the Customer for the Sub-processor's acts and omissions, and (c) the Provider giving the Customer at least 30 days' prior written notice (by email or in-app) of any intended addition or replacement of a Sub-processor. The Customer may object on reasonable data-protection grounds; in that case the parties will discuss the matter in good faith and, failing resolution, the Customer may terminate the affected part of the Service.

The current list of Sub-processors is published in the Privacy Policy, Section 4.

6. International transfers

Where the Provider transfers Customer Personal Data outside the EEA, the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) — Decision (EU) 2021/914 — as incorporated by reference into this DPA, Module 2 or Module 3 as applicable. The Provider will maintain supplementary technical measures (encryption in transit, minimum-necessary payloads) commensurate with the risk identified in the transfer impact assessment.

7. Data Subject rights

Taking into account the nature of the processing, the Provider shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights (Articles 12–23 GDPR). The Customer can perform most access, export, rectification and erasure operations self-serve via the Service.

8. Personal Data Breach

The Provider will notify the Customer without undue delay — and, where feasible, within 72 hours — after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it.

9. Deletion and return at end of processing

On termination of the Service, the Provider will make Customer Personal Data available for export for at least 30 days (via Settings → Privacy & data → Export my data) after which it will be permanently deleted, except for invoice / ledger records which will be anonymised and retained for the 7-year period required by Irish Revenue.

10. Liability and governing law

The liability and governing law provisions of the main Terms of Service apply to this DPA. In case of conflict between this DPA and the Terms, this DPA prevails with respect to the subject-matter of Article 28 GDPR.

11. Annex I — Description of processing

  • Data exporter: the Customer (Controller).
  • Data importer: YourDataApp Ltd (Processor).
  • Frequency of transfer: continuous.
  • Retention: as described in the Privacy Policy, Section 6.
  • Purpose: to deliver the JobsBook.app Service to the Customer.

12. Annex II — Technical and organisational measures

The Provider maintains the following minimum measures:

  • TLS 1.2+ encryption in transit; HSTS enforced on production.
  • Encryption at rest for the primary database (AES-256).
  • Bcrypt password & PIN hashing (cost ≥ 12).
  • Multi-tenant isolation enforced at the database driver level.
  • Short-lived (24 h) JWT-based sessions with server-side revocation on credential change.
  • Principle of least privilege for production access; MFA enforced for on-call engineers.
  • Continuous dependency scanning and prompt patching of critical CVEs.
  • Encrypted rolling backups (30-day retention).
  • Written incident-response process with named responder rotations.
Terms·Privacy·Cookies·DPA·Imprint·Contact·
© 2026 YourDataApp Ltd · Dublin, Ireland · info@yourdataapp.com