Legal

Data Processing Agreement

Last updated 19 July 2026

Legal Notice

This Data Processing Agreement sets out how OS Informatics Limited processes personal data on a customer's behalf as part of providing the Ji4 service, and forms part of the Ji4 Terms of service.

About this DPA

This Data Processing Agreement ("DPA") forms part of the agreement between OS Informatics Limited, trading as Ji4 ("Processor", "Ji4") and the Customer identified in the applicable Order ("Controller", "Customer") under the Ji4 Terms of Service (the "Agreement"). It applies where Ji4 processes personal data on the Customer's behalf in providing the Service. Capitalised terms not defined here have the meaning given in the Agreement. "GDPR" means Regulation (EU) 2016/679; "Data Protection Law" means the GDPR, the Irish Data Protection Act 2018, and other applicable privacy law.

1. Roles and scope

1.1 For Customer Data containing personal data, the Customer is the controller (or a processor acting for another controller) and Ji4 is the processor. The subject matter, duration, nature, purpose, categories of data and data subjects are set out in Annex A.

1.2 Ji4 acts as an independent controller only for the limited processing described in the Ji4 Privacy Policy (account, billing, security and service administration data), which is outside this DPA.

1.3 Where the Customer is itself a processor, the Customer warrants that its instructions to Ji4 are authorised by the relevant controller, and Ji4 is engaged as its subprocessor.

Read the Ji4 Privacy Policy

2. Processing on instructions

2.1 Ji4 will process personal data only on the Customer's documented instructions, including regarding transfers, unless required to do otherwise by EU or Member State law, in which case Ji4 will inform the Customer before processing unless that law prohibits it on important grounds of public interest.

2.2 The Agreement, this DPA, and the Customer's use and configuration of the Service (including connecting integrations and enabling features) constitute the Customer's complete documented instructions. Additional instructions require agreement in writing.

2.3 Ji4 will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Ji4 is not obliged to perform a legal review of instructions.

3. Confidentiality

Ji4 ensures that persons authorised to process the personal data are bound by confidentiality obligations, contractual or statutory, and access personal data only as needed to provide the Service.

4. Security

4.1 Ji4 implements and maintains the technical and organisational measures described in Annex C, taking into account the state of the art, costs, and the nature, scope, context and purposes of processing and risks to data subjects, as required by Article 32 GDPR.

4.2 Ji4 may update the measures provided the updates do not materially reduce the overall level of protection during a Subscription Term.

4.3 The Customer is responsible for its own security obligations, including Authorised User management, credential protection, configuration choices, and the security of exported data.

5. Subprocessors

5.1 The Customer grants general written authorisation for Ji4 to engage the subprocessors listed in Annex B.

5.2 Ji4 will provide at least 30 days' notice of any intended addition or replacement of a subprocessor, by email to the account owner or through the Service, giving the Customer the opportunity to object on reasonable data protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected Service and receive a pro rata refund of prepaid fees for the unused period. Continued use after the notice period constitutes acceptance.

5.3 Ji4 will impose data protection obligations on each subprocessor that are materially no less protective than this DPA, and remains liable to the Customer for the subprocessor's performance.

6. Data subject rights

Taking into account the nature of the processing, Ji4 will assist the Customer through appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data subject requests under Chapter III GDPR. If a data subject contacts Ji4 directly regarding Customer Data, Ji4 will, where the requester is identifiable as relating to the Customer, promptly redirect them to the Customer and notify the Customer, and will not respond substantively except on the Customer's instruction or where legally required.

7. Assistance

Taking into account the nature of processing and the information available to it, Ji4 will provide reasonable assistance to the Customer with: security of processing (Article 32), personal data breach notification (Articles 33 and 34), data protection impact assessments (Article 35), and prior consultation (Article 36). Assistance materially exceeding the standard functionality of the Service may be subject to reasonable fees disclosed in advance, except where the need for assistance arises from Ji4's breach of this DPA.

8. Personal data breach

8.1 Ji4 will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data.

8.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.

8.3 Ji4 will take reasonable steps to contain and remediate the breach and will cooperate with the Customer's reasonable requests. Ji4's notification is not an admission of fault.

9. International transfers

9.1 Ji4 processes Customer Data primarily in [PRIMARY PROCESSING REGION]. Transfers outside the EEA occur only to subprocessors listed in Annex B and only with a valid transfer mechanism: an adequacy decision (including the EU-US Data Privacy Framework for certified recipients), the Standard Contractual Clauses adopted by the European Commission (Module 2 or Module 3 as applicable), or another valid mechanism, together with supplementary measures where required.

9.2 Where the SCCs apply between the Customer and Ji4, they are incorporated by reference with the Customer as data exporter and Ji4 as data importer, Annexes A to C of this DPA serving as their appendices, the option under Clause 9(a) being general authorisation with the notice period in Section 5.2, Irish law governing under Clause 17, and Irish courts under Clause 18.

10. Deletion and return

10.1 During the Subscription Term the Customer may access and export Customer Data as described in the Agreement.

10.2 Following termination, and after the export window in the Agreement, Ji4 will delete Customer Data from active systems and, within backup retention cycles not exceeding [BACKUP RETENTION PERIOD], from backups, unless EU or Member State law requires further storage. On written request, Ji4 will confirm deletion in writing.

Read the export window in our Terms of service

11. Audit

11.1 Ji4 will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, including summaries of relevant third party audits and certifications where available.

11.2 Where the information provided is insufficient to demonstrate compliance, the Customer (or an independent auditor mandated by it, not a competitor of Ji4) may conduct an audit, no more than once per 12 months except following a personal data breach or where required by a supervisory authority, on at least 30 days' notice, during business hours, subject to confidentiality obligations, and without access to other customers' data. Each party bears its own costs.

12. Liability and precedence

Liability under this DPA is subject to the limitations and exclusions in the Agreement, including the enhanced cap. In case of conflict between this DPA and the Agreement regarding processing of personal data, this DPA prevails; where the SCCs apply and conflict with this DPA, the SCCs prevail.

Read the enhanced liability cap in our Terms of service

13. Term

This DPA applies for as long as Ji4 processes Customer Data and terminates automatically upon completed deletion under Section 10.

Annex A: Processing details

Subject matter: provision of the Ji4 customer support platform.

Duration: the Subscription Term plus the export and deletion periods.

Nature and purpose: hosting, storage, transmission, display, organisation, analysis (including AI assisted duplicate detection, summarisation and drafting), synchronisation with the Customer's Linear workspace, sending of communications to End Users, and related support and security operations.

Categories of data subjects: the Customer's End Users (its customers, users and contacts), Authorised Users, and other individuals whose data appears in support communications.

Categories of personal data: names, email addresses and contact details; support conversation content and attachments; portal activity; issue and ticket content; identifiers and technical metadata. Special category data is not intended to be processed; incidental content volunteered by End Users is processed only as part of Customer Data (see Agreement Section 8.5).

Annex B: Authorised subprocessors

SubprocessorRoleLocationTransfer mechanism
Postmark (AC PM, an ActiveCampaign company)Transactional and inbound email: outbound replies to End Users, and inbound email parsed into ticketsUnited StatesSCCs
Cloudflare, Inc.CDN, security, DNSGlobal (US)SCCs
Anthropic, PBCAI assisted issue drafting (primary provider)United StatesSCCs
OpenAI, L.L.C.AI assisted duplicate-detection embeddings; failover provider for issue draftingUnited StatesSCCs
[HOSTING PROVIDER]Application hosting and storage[LOCATION][MECHANISM]

Note: Linear is not a Ji4 subprocessor. The Customer connects its own Linear workspace as a customer-authorised integration under Section 10 of the Agreement, and Linear processes data under the Customer's direct relationship with Linear.

Transfer mechanism is listed as Standard Contractual Clauses (SCCs) for every recipient above. SCCs are a valid mechanism regardless of a provider's Data Privacy Framework status; per-provider DPF certification was not independently verified against the official government register at the time of writing, so confirm current status directly before relying on DPF for any specific provider. The payment processor is not listed here because Section 1.2 places billing and payment processing outside this DPA's scope; it is Ji4's own controller-side processing, covered by the Privacy Policy instead.

Annex C: Technical and organisational measures

This Annex describes the technical and organisational measures Ji4 applies to Customer Data.

Encryption in transit: TLS is required for all access to the Service; the passwordless authentication flow (magic links and passkeys) and the Service generally will not function without a valid HTTPS URL.

Access control and authentication: sign-in is passwordless, using single-use, time-limited magic links, rate-limited per email address, with optional WebAuthn passkeys available as a stronger authentication factor. There is no traditional password or two-factor authentication step for regular sign-in.

Tenant isolation: Customer Data is logically separated per workspace through a global application-level scope and middleware, and background jobs carry an explicit workspace identifier, so one customer's data is not reachable through another's session.

Webhook and integration security: the inbound email endpoint is protected by a shared secret, with an optional IP allowlist, and the Linear webhook is verified by signature against a signing secret.

Environment and secrets management: production configuration disables debug output, and credentials, including database, cache, email and integration secrets, are supplied through environment configuration rather than committed to source control.

Administrative access: the operational dashboard for background job processing is restricted to administrator accounts.

The following have not been confirmed against the Service's current implementation and are flagged rather than published as fact: the backup and disaster recovery mechanism and its retention period ([BACKUP RETENTION PERIOD]); encryption of data at rest; vulnerability management and patching practice; secure development and code review practice; personnel confidentiality and security awareness training; subprocessor due diligence process; and the physical security and certifications, such as ISO 27001 or SOC 2, held by [HOSTING PROVIDER]. These must be confirmed directly, not assumed, before this Annex is treated as complete.

See also the other legal documents and our security posture.

We use optional analytics cookies to understand how the Ji4 website is used and to improve it. See our cookie policy for details.