LEGAL · DPA

Data Processing Addendum

The GDPR Article 28 terms on which we process personal data on behalf of enterprise and team customers.

This document is provided in good faith and is not legal advice.

Effective date: 7 June 2026

This Data Processing Addendum (the “DPA”) forms part of the agreement between Juste Tools LTD, a company registered in England and Wales (“Juste Tools”, “Clavio”, “Processor”), and the customer organisation that subscribes to the Clavio service (the “Customer” or “Controller”), and governs the processing of personal data that Clavio carries out on the Customer's behalf. It is designed to satisfy the requirements of Article 28 of the UK GDPR and the EU GDPR. Where this DPA conflicts with the rest of the agreement on the subject of data protection, this DPA prevails.

We sign this DPA per customer. To put it in place, email office@justetools.co.uk with your company name, jurisdiction, and signatory and we will return a copy pre-filled for signature. We also accept a Customer's own DPA for countersignature where its terms are materially equivalent.

1. Definitions

Terms such as controller, processor, sub-processor, data subject, personal data, processing, and personal data breachhave the meanings given in the UK GDPR and the EU GDPR. “Data Protection Laws” means the UK GDPR, the EU GDPR (Regulation 2016/679), the UK Data Protection Act 2018, and any other applicable data-protection or privacy laws.

2. Roles & scope

For personal data processed under the agreement, the Customer is the controller and Clavio is the processor (or, where the Customer is itself a processor for its end users, Clavio is a sub-processor). Clavio processes personal data only to provide and support the Service. The subject-matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A below.

3. Processor obligations (Article 28)

Clavio shall:

  • Documented instructions — process personal data only on the Customer's documented instructions (including those in the agreement and this DPA), unless required to do otherwise by law, in which case Clavio will, where lawful, inform the Customer first.
  • Confidentiality — ensure that persons authorised to process the personal data are bound by an appropriate duty of confidentiality.
  • Security — implement the technical and organisational measures described in §6 and Annex B (Article 32).
  • Sub-processors — engage sub-processors only in accordance with §5.
  • Assistance with data-subject rights — taking into account the nature of the processing, assist the Customer by appropriate measures to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection).
  • Assistance with compliance — assist the Customer in ensuring compliance with Articles 32–36 (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the information available to Clavio.
  • Deletion or return — at the Customer's choice, delete or return all personal data after the end of the provision of services, and delete existing copies unless storage is required by law (see §8).
  • Audits — make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality and security arrangements.

4. Personal data breach

Clavio shall notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and shall provide the information reasonably available to it to help the Customer meet its own notification obligations to supervisory authorities and data subjects under Articles 33 and 34.

5. Sub-processors

The Customer provides general authorisationfor Clavio to engage sub-processors to provide the Service. Clavio's current sub-processors are listed in our Privacy Policy and are set out below. Clavio will impose data-protection obligations on each sub-processor that are materially equivalent to those in this DPA, and remains responsible for its sub-processors' performance. Clavio will inform the Customer of intended changes to its sub-processors and give the Customer the opportunity to object on reasonable data-protection grounds.

  • Anthropic — AI polishing of transcribed text; processes transcripts and dictation content.
  • OpenAI (Whisper) — speech-to-text transcription; processes voice recordings.
  • Groq — may provide speech-to-text transcription when configured; processes voice recordings and related inference data under the applicable account data controls.
  • Lemon Squeezy — payment processing and subscription billing as Merchant of Record; processes account & identity data (name, email), billing and payment information, and country for tax.
  • Apple — sign-in and identity verification; processes account & identity data.
  • Google — sign-in and identity verification; processes account & identity data.
  • Railway — application hosting and database infrastructure; may process all categories described in Annex A.
  • GitLab — software delivery and operational tooling; processes diagnostics and operational data.

6. Security measures (Article 32)

Clavio maintains appropriate technical and organisational measures to protect personal data, including: encryption of data in transit (TLS); storage of only hashed authentication tokens rather than passwords; access controls on a need-to-know basis; use of reputable infrastructure providers; and operational practices designed to ensure the ongoing confidentiality, integrity, availability, and resilience of the Service. A summary of these measures is set out in Annex B.

7. International transfers

Where processing under this DPA involves a transfer of personal data outside the UK or the EEA to a country without an adequacy decision, the parties agree that such transfers are made subject to appropriate safeguards under Article 46 — namely the European Commission's Standard Contractual Clauses (EU 2021/914) and, for UK transfers, the UK International Data Transfer Agreement / UK Addendum, which are hereby incorporated by reference and completed with the details in the Annexes. We sign these clauses without negotiation as standard.

8. Duration, deletion & return

This DPA applies for as long as Clavio processes personal data on the Customer's behalf. On termination or expiry of the Service, and at the Customer's choice, Clavio will delete or return the Customer's personal data and delete existing copies, subject to short backup-rotation windows and any retention required by law.

9. Annex A — Details of processing

  • Subject-matter & nature: provision of an AI voice-dictation service — capturing, transmitting, transcribing, and polishing dictation, and account and subscription management.
  • Purpose: to deliver the Service to the Customer and its authorised users.
  • Duration: for the term of the agreement, plus any limited wind-down period under §8.
  • Categories of data subjects: the Customer's authorised users (for example employees or team members).
  • Types of personal data: account & identity data (user identifier, name, email — including Apple private-relay addresses); voice recordings and transcripts; subscription, billing, and payment information (handled by our Merchant of Record, Lemon Squeezy), including country for tax; usage, diagnostics, and device/OS data.
  • Special-category data: voice recordings, processed transiently to produce transcripts; not used to train AI models.

10. Annex B — Security measures (summary)

  • Encryption of personal data in transit (TLS).
  • Authentication via signed-in identity providers; storage of only hashed tokens, not passwords.
  • Role- and need-to-know-based access controls to systems and data.
  • Use of reputable, security-reviewed infrastructure and AI sub-processors under data-protection terms.
  • Logging and monitoring to detect and respond to security events, and a process to notify the Customer of personal data breaches.
  • Measures designed to restore availability and access to personal data in a timely manner after an incident.

11. Contact

To request, sign, or ask questions about this DPA, contact office@justetools.co.uk.