GDPR Article 28 processor terms · Version 1.0 · Last updated 29 August 2026
This DPA forms part of the agreement (the “Agreement”) between the customer (the “Controller”) and Jelect (the “Processor”) for the customer’s use of the Jelect service (the “Service”). It governs the processing of personal data carried out by the Processor on behalf of the Controller and is intended to satisfy Article 28 of Regulation (EU) 2016/679 (the “GDPR”).
Processor: Jelect, a service operated by [legal entity name — to be added], registered in the Netherlands under Chamber of Commerce (KvK) number [KvK number — to be added], VAT/BTW [VAT number — to be added], registered address [business address — to be added]. Contact: privacy@jelect.io.
Controller: the customer entity identified in the Agreement or order form.
For the personal data processed under the Service, the Controller determines the purposes and means of processing and the Processor processes that data solely on the Controller’s documented instructions, as set out in this DPA and the Agreement. The Processor does not sell personal data and does not use it for its own purposes, for advertising, or to train models.
The Processor shall:
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
The Controller provides general authorisation for the Processor to engage the subprocessors listed at jelect.io/subprocessors. The Processor will inform the Controller of any intended addition or replacement of a subprocessor that processes personal data, giving the Controller the opportunity to object on reasonable data-protection grounds. Where a subprocessor is engaged, the Processor imposes data-protection obligations equivalent to those in this DPA and remains liable for the subprocessor’s performance.
The Processor primarily hosts and processes personal data within the European Union (see Annex III). Where any transfer of personal data to a third country takes place, it will be carried out only on a lawful transfer mechanism under Chapter V of the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with any supplementary measures required.
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and shall provide the information reasonably required for the Controller to meet its own notification obligations under Articles 33 and 34 of the GDPR.
On termination or expiry of the Service, and at the Controller’s choice, the Processor will return the Controller’s personal data or delete it, and delete existing copies, within a reasonable period, unless retention is required by applicable law. Backup copies are deleted in the ordinary course of the Processor’s backup cycle.
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, on reasonable prior notice, no more than once per year (save where required by a supervisory authority), and subject to confidentiality. The Processor may satisfy audit requests by providing relevant documentation of its security measures.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on the effective date of the Agreement and continues for as long as the Processor processes personal data on the Controller’s behalf.
This DPA is governed by the laws of the Netherlands and, where applicable, the GDPR, consistent with the governing-law terms of the Agreement.
| Subject matter | Provision of the Jelect account-scoring and prospecting Service. |
|---|---|
| Duration | For the term of the Agreement and until return or deletion of personal data under Section 7. |
| Nature and purpose | Collection, organisation, storage, enrichment, scoring and display of business-contact and company data so the Controller can identify, prioritise and manage target accounts and existing customers. |
| Categories of data subjects | The Controller’s existing customers and business contacts, and individuals associated with prospective target companies (typically employees acting in a professional capacity). |
| Types of personal data | Business contact details such as name, job title, employer, business email address, business telephone number, and public professional profile links; account/relationship data uploaded by the Controller (e.g. CRM records). Jelect does not require or intend to process special categories of personal data. |
The Processor maintains measures appropriate to the risk, including tenant isolation enforced at the database layer, encryption in transit, access controls and least-privilege administration, secrets kept out of source control, hashing of API keys at rest, audit logging of sensitive operations, and separated production access. A fuller description is published at jelect.io/security and is incorporated here by reference.
The current list of subprocessors, their purpose and processing region is maintained at jelect.io/subprocessors. At the date of this version, the primary infrastructure subprocessors are Supabase (managed database, authentication and storage; EU) and Vercel (application and API hosting; EU / global edge).