---
title: "Data Processing Addendum"
description: "The data processing terms that apply when Jsonify processes personal data on a customer's behalf."
url: "https://www.jsonify.com/legal/dpa"
---

# Data Processing Addendum

Last updated: September 2026

This Data Processing Addendum ("DPA") forms part of the [Self-Serve Terms of Use](https://www.jsonify.com/legal/terms) between Trailing Comma, Inc. (d/b/a Jsonify) ("Jsonify") and the customer accepting those Terms ("Customer"). It applies whenever Jsonify processes personal data on Customer's behalf through Customer-configured pipelines ("Customer Personal Data"). It does not apply to raw fetched content Jsonify caches across pipelines, to account data, or to platform knowledge, for which Jsonify is a controller under its [Privacy Policy](https://www.jsonify.com/legal/privacy). If a signed agreement between the parties contains its own data-processing terms, that agreement governs.

## 1\. Roles and Scope

Customer is the controller (or, where Customer acts for another controller, a processor) of Customer Personal Data; Jsonify is Customer's processor (or subprocessor). Jsonify will process Customer Personal Data only on Customer's documented instructions — as given through the configuration of pipelines, the Terms, and this DPA — unless required to do otherwise by law, in which case Jsonify will inform Customer unless the law prohibits it.

## 2\. Details of Processing

*   **Subject matter and duration:** the collection, structuring, checking, and delivery of data through pipelines Customer configures, for the duration of the Terms;
*   **Nature and purpose:** automated extraction and processing of data from sources Customer confirms, and delivery of datasets to destinations Customer chooses;
*   **Categories of data:** the data present on the sources Customer confirms and in files Customer uploads as sources, which may incidentally include personal data such as names, usernames, and user-generated content;
*   **Data subjects:** individuals whose personal data appears on the confirmed sources.

## 3\. Jsonify-Specific Instructions

**Proposals.** A proposal by Jason — a suggested source, field, or schedule — is not an instruction until Customer accepts it.

**Source removal.** Jsonify may stop collecting from a source as described in the Terms; doing so is not a breach of Customer's instructions.

**Removal requests.** Customer instructs Jsonify, as a standing instruction, that Jsonify may exclude an individual's data from Customer's pipelines following a request from that individual, and will notify Customer. Customer may object within 30 days where it has a lawful basis to continue.

## 4\. Customer Obligations

Customer is responsible for the lawfulness of the processing it configures: having a valid legal basis, providing any required notices, honouring data-subject rights it controls, and not instructing collection of special categories of personal data unless strictly lawful. Customer warrants that its instructions comply with applicable data protection laws.

## 5\. Confidentiality and Personnel

Jsonify ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations.

## 6\. Security

Jsonify implements appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art and the risks of the processing, including encryption in transit, access controls, logging, and environment separation. Jsonify will assist Customer, taking into account the nature of the processing, in meeting Customer's own security, breach-notification, and data-protection-impact-assessment obligations.

## 7\. Personal Data Breaches

Jsonify will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably required for Customer to meet its own notification obligations.

## 8\. Subprocessors

Customer authorises Jsonify to engage the subprocessors listed on the [subprocessors page](https://www.jsonify.com/legal/subprocessors), which Jsonify will update before adding or replacing a subprocessor. Customer may object on reasonable data-protection grounds within 30 days of an update; if the objection cannot be resolved, Customer may terminate the affected pipelines. Jsonify imposes data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance.

## 9\. Data Subject Requests

Taking into account the nature of the processing, Jsonify will assist Customer with appropriate technical and organisational measures to respond to data-subject requests. If a data subject contacts Jsonify directly about processing under Customer's control, Jsonify will refer the request to Customer where it can identify them.

## 10\. International Transfers

Where the processing involves a transfer of personal data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, Module Two: controller to processor, or Module Three where Customer is a processor) are incorporated into this DPA by reference, with Customer as data exporter and Jsonify as data importer, completed with the details in Section 2 and the security measures in Section 5. For UK transfers, the ICO's International Data Transfer Addendum applies to the Clauses.

## 11\. CCPA and US State Laws

Where US state privacy laws such as the California Consumer Privacy Act apply, Jsonify acts as Customer's "service provider": it will not sell or share Customer Personal Data, will not retain, use, or disclose it other than to provide the Services or as permitted by law, and certifies that it understands these restrictions.

## 12\. Audit and Information

Jsonify will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party security documentation, and will respond to a written audit questionnaire no more than once per year. On-site audits are limited to where a supervisory authority requires one or following a personal data breach affecting Customer, on reasonable notice and without disrupting the Services.

## 13\. Return and Deletion

During the Terms, Customer can export its datasets through the Services. After the Terms end, Jsonify will delete Customer Personal Data within the export window described in the Terms, unless law requires longer retention, in which case it remains protected under this DPA until deleted.

## 14\. Precedence

If this DPA conflicts with the Terms, this DPA governs for the processing of Customer Personal Data. If the Standard Contractual Clauses conflict with this DPA, the Clauses govern.

## 15\. Contact

Questions about this DPA: [paul@jsonify.com](mailto:paul@jsonify.com).

[Privacy](https://www.jsonify.com/legal/privacy)[Terms](https://www.jsonify.com/legal/terms)[Acceptable use](https://www.jsonify.com/legal/acceptable-use)[DPA](https://www.jsonify.com/legal/dpa)[Subprocessors](https://www.jsonify.com/legal/subprocessors)[Legal FAQ](https://www.jsonify.com/legal/faq)[Remove my data](https://www.jsonify.com/legal/remove-my-data)[Site owners](https://www.jsonify.com/legal/site-owners)
