Data Processing Addendum
Last updated: September 2, 2026
This addendum is already in force between us
This Addendum is incorporated by reference into the Terms of Service and is accepted when the Customer creates an account or uses the platform. It does not need to be signed separately, although section 18 explains how to obtain a countersigned copy if the Customer’s procurement team requires one.
1. Scope, parties and acceptance
This Data Processing Addendum (the "Addendum") is entered into between the business customer using the platform (the "Controller" or the "Customer") and Jelliu Corporation, a corporation incorporated on 4 August 2026 under the laws of the State of Delaware, United States, filed with the Delaware Division of Corporations under file number 10722311, with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States, operator of jelliu.co and app.jelliu.co ("Jelliu" or the "Processor").
The Addendum forms part of the Terms of Service published at jelliu.co/terms and applies to all processing of personal data Jelliu carries out on the Customer’s behalf. In the event of conflict with the Terms on a personal data matter, this Addendum prevails.
It is entered into in compliance with California Civil Code § 1798.100 et seq. and the other US state privacy laws, and with Article 28 of Regulation (EU) 2016/679 where the Customer is subject to it.
2. Definitions
- "Customer Personal Data": the personal data the Customer uploads to the platform or that the platform generates in carrying out its instructions, including data about its end customers.
- “Processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given to them in GDPR Article 4 and, in the United States, the equivalent meaning in California Civil Code § 1798.140.
- “Data Protection Law”: the CCPA/CPRA and the other US state consumer privacy laws, the GDPR and UK GDPR where they apply, and any other law applicable to the processing covered by this Addendum.
- "Sub-processor": a third party engaged by Jelliu that processes Customer Personal Data.
- "SCCs": the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914.
3. Subject matter, nature, purpose and duration
- Subject matter: provision of the AI agent platform described in the Terms of Service.
- Nature of the processing: collection, recording, structuring, storage, transcription, analysis using language models, consultation, disclosure by transmission to sub-processors and to the tools the Customer connects, restriction and erasure.
- Purpose: running the conversations the Customer configures by phone, WhatsApp, web chat and email; generating their transcripts, summaries and analysis; syncing outcomes with the Customer’s tools; and presenting the resulting analytics.
- Duration: for the term of the service agreement, plus the deletion period set out in section 14.
- Instructions: processing is carried out only on the Customer’s documented instructions, which consist of the Terms of Service, this Addendum and the configuration the Customer applies in the platform.
4. Categories of data subjects and personal data
| Category of data subject | Categories of personal data |
|---|---|
| The Customer’s end customers and prospects contacted by an agent | Name, phone number, email address, WhatsApp identifier, call audio, transcript, message content, attachments and receipts, conversation metadata, summary, sentiment and the data fields the Customer configures for extraction |
| The Customer’s users with dashboard access | Name, email address, identity-provider identifier, role within the organisation, IP address, user agent and audit records of their actions |
| Contacts uploaded by the Customer that have not yet been contacted | Name, phone number, email address and custom fields defined by the Customer |
Special categories of data: the platform is not designed to process sensitive data within the meaning of GDPR Article 9 or California Civil Code § 1798.140(ae), and the Customer undertakes not to upload it deliberately. If the content of a conversation reveals it incidentally, the same security measures and deletion periods apply to it as to any other content. Voice audio may constitute a biometric identifier under state laws such as Illinois’ Biometric Information Privacy Act or Chapter 503 of the Texas Business and Commerce Code: Jelliu does not create voice templates and does not perform biometric identification.
5. The Customer’s obligations as controller
- Determine the purposes and means of the processing and hold a valid legal basis for every processing operation it instructs.
- Obtain the authorisations and provide the privacy notices owed to data subjects, including recording consent where applicable law requires it.
- Not upload personal data it is not entitled to process, nor instruct Jelliu to carry out processing that breaches Data Protection Law.
- Configure the retention period, contact hours and compliance settings its business and its jurisdiction require.
- Administer its own users’ access and revoke it when appropriate.
6. Jelliu’s obligations as processor
- Process Customer Personal Data only on the Customer’s documented instructions, including as to international transfers, unless required by law, in which case it will inform the Customer before processing unless the law prohibits it.
- Immediately inform the Customer if, in its opinion, an instruction breaches Data Protection Law.
- Not process Customer Personal Data for its own purposes, not sell or share it, and not use it to train, fine-tune or develop artificial-intelligence models, nor permit its sub-processors to do so.
- Implement the technical and organisational measures in section 9 and review them periodically.
- Ensure that every person authorised to process the data is bound by a duty of confidentiality and accesses only what their function requires.
- Assist the Customer as set out in sections 10, 11 and 12.
- Make available to the Customer the information necessary to demonstrate compliance with this Addendum and allow the audits described in section 13.
- Delete or return the data on termination in accordance with section 14.
7. Confidentiality of personnel
Jelliu ensures that the persons authorised to process Customer Personal Data have committed themselves to confidentiality under contractual obligations that survive the end of their engagement, or are under a statutory duty of confidentiality.
Jelliu personnel access to a specific customer’s conversation content is limited to what is necessary to handle a support request, investigate an incident or comply with a legal obligation, and is recorded in the tamper-evident audit log described in section 9.
8. Sub-processors: authorisation, notice of change and objection
The Customer grants Jelliu a general authorisation to engage sub-processors. Jelliu does not publish the identity of its sub-processors; the current list, with each one’s purpose, data categories and location, is provided to any Customer who requests it in writing at the address in section 19.
Jelliu will impose on every sub-processor, by contract, data protection obligations no less demanding than those in this Addendum, and remains liable to the Customer for a sub-processor’s failure to meet its data protection obligations as if the failure were its own.
- Notice of change: Jelliu will give at least thirty (30) days’ notice of the addition or replacement of a sub-processor, by email to the account administrator and by notice in the application. The Customer may subscribe to change notifications by writing to the address in section 19.
- Right to object: the Customer may object on reasonable, data-protection-related grounds within those thirty (30) days, setting them out in writing.
- Consequence of an objection: the parties will seek an alternative in good faith. If Jelliu cannot offer one within thirty (30) days, the Customer may terminate the affected part of the service, or the whole contract where the impact is material, with a pro-rata refund of amounts paid and unused, and without penalty.
9. Technical and organisational measures (Annex II)
Jelliu applies the following measures, which constitute Annex II for the purposes of the SCCs. They are written to be verifiable, not to impress.
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS on all web and API traffic, with HSTS set to 12 months, includeSubDomains and preload. Database connections validate a pinned certificate authority; the cache and queue store rejects any connection that is not TLS or private-network |
| Encryption at rest | AES-256-GCM envelope encryption with a per-record key derived via scrypt from a unique 16-byte salt. Additional authenticated data binds every ciphertext to its tenant, so one tenant’s ciphertext cannot be decrypted in another tenant’s context. Applied to transcripts, summaries, integration credentials, flagged content, identity certificates and post-call evidence |
| Data deliberately left unencrypted | The phone number is stored in the clear because it must remain queryable and indexable. This is documented here rather than described as "everything is encrypted" |
| Tenant isolation | PostgreSQL row-level security with USING and WITH CHECK policies on the tenant identifier, set per transaction with SET LOCAL from the request context and validated as a UUID before it is applied |
| Tamper-evident audit log | Every audit event is chained with HMAC-SHA256 over the canonical row and the previous row’s hash, serialised per tenant with an advisory lock. A verifier walks the chain and detects an altered or deleted row |
| Webhook authenticity | Inbound webhooks are signature-verified before processing. Outbound webhooks to the Customer are signed with a dedicated key and carry replay protection |
| Access control | Federated authentication through an identity provider, per-organisation sessions and role-based permissions within each workspace |
| Browser hardening | Content Security Policy with a per-request nonce, third-party framing denied, a permissions policy restricting camera and geolocation, and a restricted referrer policy |
| Logging and traceability | Every administrative action and every access to personal data is logged with actor, tenant, resource and timestamp |
| Continuity | Backups managed by the database provider with point-in-time recovery |
What we do not claim
Jelliu does not hold a SOC 2, ISO 27001 or HIPAA certification today, and does not run periodic third-party penetration tests. We would rather say so than imply otherwise: a security claim we cannot substantiate is itself a legal risk. The measures described above are the ones actually implemented and verifiable.
10. Assistance with data subject requests
The platform lets the Customer access, export, rectify and delete a data subject’s data directly from the dashboard, without depending on Jelliu. That is the preferred and fastest route.
Where a request cannot be handled with those functions, Jelliu will provide reasonable assistance within ten (10) business days of the Customer’s request, at no additional cost, including deletion of the conversation in the voice provider’s infrastructure.
If a data subject sends a request directly to Jelliu about data processed on a Customer’s behalf, Jelliu will not act on it itself: it will pass it to the Customer without undue delay, tell the data subject the identity of the controller, and confirm this in writing.
11. Personal data breach notification
Jelliu will notify the Customer of any personal data breach affecting Customer Personal Data without undue delay and in any event within forty-eight (48) hours of becoming aware of it. The deadline is set below the seventy-two (72) hours in Article 33 GDPR so that the Customer has effective time to meet its own notification obligation.
The notification will include the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a point of contact. Where not all information is available, it will be provided in phases rather than delaying the first communication.
Jelliu will cooperate with the Customer in the investigation and in notifying authorities and data subjects, and will not notify the Customer’s data subjects without the Customer’s instruction unless legally required to do so.
12. Impact assessments and prior consultation
Jelliu will provide reasonable assistance to the Customer in carrying out data protection impact assessments and in prior consultations with the supervisory authority, to the extent the necessary information is held by Jelliu and cannot be obtained by the Customer itself.
That assistance includes providing a description of the processing operations, the security measures, the data flows to sub-processors and the international transfer mechanisms.
13. Audit rights
- Jelliu will make available to the Customer, on request and once per calendar year, the documentation necessary to demonstrate compliance with this Addendum: a description of the technical and organisational measures, the data architecture, the sub-processor list and the retention policy.
- The Customer may carry out one audit per year, on thirty (30) days’ notice, during business hours, without disrupting operations, subject to a confidentiality agreement and at its own cost. It may do so itself or through an independent auditor that is not a competitor of Jelliu.
- In the event of a personal data breach affecting the Customer’s data, or an express requirement from a supervisory authority, the Customer may audit without being subject to the annual frequency limit.
- Jelliu will respond to the Customer’s reasonable security questionnaires within fifteen (15) business days.
- Jelliu does not currently hold a SOC 2 report or an ISO 27001 certification that could stand in for an audit. This is stated so that the Customer does not plan its own compliance around a document that does not exist.
14. Return and deletion on termination
On termination of the service agreement, the Customer has thirty (30) days to export Customer Personal Data from the dashboard or to ask Jelliu for an export in a structured, commonly used and machine-readable format, at no cost.
After that period, Jelliu will delete all Customer Personal Data from its active systems within the following thirty (30) days, and will instruct deletion by any sub-processor that holds it. Backups are overwritten in the ordinary rotation cycle, which does not exceed ninety (90) days, and remain encrypted and out of use throughout that period.
Jelliu may retain data the law requires it to retain, only for the statutory period and subject to the same security measures. At the Customer’s request, Jelliu will issue a written certification of deletion.
15. International transfers
- For transfers from the European Economic Area and the United Kingdom to a country without an adequacy decision, the parties hereby enter into the SCCs of Decision (EU) 2021/914, module 3 (processor to sub-processor) where Jelliu acts as the Customer’s processor, with clause 7 (docking) incorporated, option 2 of clause 9 (general sub-processor authorisation with thirty days’ notice), the clause 11 option without an independent dispute resolution body, Irish law as the law governing the SCCs and the courts of Ireland as the forum, unless the Customer is established in a Member State whose law and courts it prefers to designate.
- Annex I to the SCCs is constituted by sections 1, 3 and 4 of this Addendum; Annex II by section 9; Annex III by the current sub-processor list Jelliu provides to the Customer under section 8.
- For the United Kingdom, the ICO International Data Transfer Addendum, version B1.0, applies in addition.
- Where the Customer is established in the European Economic Area or the United Kingdom, the Standard Contractual Clauses referred to above are deemed incorporated into this Addendum. Processing takes place in the United States in every case.
- The parties do not rely exclusively on the EU-US Data Privacy Framework. The SCCs are maintained as a standalone and sufficient mechanism even where a sub-processor is certified under that framework.
16. CCPA clause: Jelliu is a service provider
With respect to personal information subject to the CCPA/CPRA, the Customer is the "business" and Jelliu is a "service provider" within the meaning of section 1798.140(ag) of the California Civil Code. Jelliu represents and warrants that it:
- Does not sell or share the personal information received from the Customer within the meaning of sections 1798.140(ad) and (ah).
- Does not retain, use or disclose it for any purpose other than performing the services described in the contract, nor for its own commercial purpose, including combining it with information received from other sources except as permitted by section 1798.140(ag)(1).
- Does not retain, use or disclose it outside the direct business relationship with the Customer.
- Complies with the CCPA obligations applicable to a service provider and provides the same level of protection the law requires.
- Will notify the Customer if it determines that it can no longer meet those obligations, whereupon the Customer may take reasonable steps to stop and remediate unauthorised use.
- Allows the Customer to verify compliance with this section through the audit rights in section 13.
17. Liability and order of precedence
Each party’s liability arising from this Addendum is governed by section 18 of the Terms of Service, including its exceptions to the cap. Nothing in this Addendum limits the rights Data Protection Law gives a data subject against either party.
In the event of conflict, the order of precedence is: first the SCCs, then this Addendum, then the Terms of Service.
18. Acceptance and signature
This Addendum is incorporated by reference into the Terms of Service and is deemed accepted and in force between the parties from the moment the Customer creates an account, accepts the Terms or begins using the platform, with no further signature required.
The person accepting the Terms on the Customer’s behalf represents that they have authority to bind it to this Addendum as well.
If the Customer’s procurement or compliance team requires a countersigned copy, it may request one at the address in section 19, stating the corporate name, tax identification number, registered address and the name and title of the signatory. Jelliu will return it signed within five (5) business days. A signed copy does not change the content of this Addendum: it documents it.
19. Contact
For matters concerning this Addendum, including requests for a countersigned copy, write to us at:
contact@jelliu.com