Legal
Data processing addendum
Last updated:
This addendum is being reviewed by our lawyer. If your firm needs a signed copy, write to jkuldevllc@gmail.com.
1. What this is and when it applies
This addendum is part of the Terms of service between jKulDev LLC (“we”, the processor) and the firm (“you”, the controller). It applies whenever we process personal data on your behalf — the personal data inside your firm's records (“customer personal data”) — and in particular where the EU or UK GDPR, or a law with similar rules, applies to you. It needs no signature; if you want a signed copy, write to jkuldevllc@gmail.com.
If this addendum and the Terms differ on personal data, this addendum wins. Where the EU standard contractual clauses or the UK addendum apply (section 8), they win over both.
2. Details of the processing
- Subject matter and purpose: providing Datumly to you — storing, organising, showing by role, sending notifications about, exporting and (when your people use them) making AI drafts from your records.
- Duration: for the term of the agreement, then until deletion under section 9.
- People concerned: your staff and other users you add; your clients, suppliers, subcontractors and their staff; other people named in your records (for example workers on a muster roll, people involved in an incident, meeting attendees).
- Types of data: names and contact details; roles; work records, comments and approvals; photos and files, including where photos were taken; attendance, check-in / check-out location and — where your people consent — on-duty location points; timesheets, expenses and wage figures; bills and payment details; voice notes passed for transcription (not stored); device and push tokens; audit logs.
- Special categories: none intended. Incident reports may contain health information (injuries); you decide whether to record it and must have a lawful ground for doing so.
3. Our duties as processor
We will:
- process customer personal data only on your documented instructions — these terms, your settings and your users' actions in Datumly — unless the law requires otherwise (we will tell you first unless the law forbids it), and tell you if we think an instruction breaks data-protection law;
- make sure everyone who can access it is bound to confidentiality;
- keep the security measures in Annex 2;
- use sub-processors only as section 4 allows;
- help you, as far as we reasonably can, answer requests from people exercising their rights (section 7);
- help you with security, breach notification, impact assessments and consultations with regulators (sections 5–7);
- delete or return the data at the end (section 9);
- give you the information needed to show these duties are met, and allow audits (section 10).
4. Sub-processors
You authorise the sub-processors listed in our Privacy policy (“Who we share it with”). We have a written contract with each that protects the data at least as well as this addendum, and we remain responsible for them.
We will tell you at least 30 days before adding or replacing a sub-processor, by email to your administrators or in the app. If you object on reasonable data-protection grounds, we will try to find a solution; if we cannot, you may end the affected service and receive a pro-rata refund of fees paid in advance for it.
5. Security
We keep appropriate technical and organisational measures for the risk, described in Annex 2, and may improve them over time without lowering the overall protection. You are responsible for your own settings and users — roles, two-step sign-in, location policy, API keys — and for the devices your people use.
6. Personal data breaches
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to customer personal data, we will tell you without undue delay (and aim to within 48 hours), with what we know, what we are doing, and who to contact — and keep you updated, so you can meet your own duty to notify (in the EU / UK, within 72 hours).
7. Helping with people's requests and assessments
Datumly lets you find, export, correct and delete the personal data in your records yourself, and every person can download their own data and delete their account. If a person asks us directly about your records, we will send the request to you and not answer it ourselves unless you ask us to. We will give reasonable help with data-protection impact assessments — for example for on-duty location tracking.
8. International transfers
Customer personal data is processed in Singapore and, through some sub-processors, in the United States and other countries. Where EU or UK law requires a safeguard for a transfer, the EU standard contractual clauses (Commission Decision 2021/914 — Module 2, controller to processor) and, for the UK, the International Data Transfer Addendum are incorporated into this addendum by reference, with us as the data importer, and Annexes 1–2 here completing them. We ensure equivalent safeguards with our sub-processors.
9. Deletion and return
You can export your records at any time while you use Datumly. When the agreement ends, we will, at your written choice, delete customer personal data or give you an export of it and then delete it, within 90 days of your request — except copies the law requires us to keep, which we keep confidential and use for nothing else. Backups are overwritten on their normal cycle.
10. Information and audits
We will answer reasonable questions about how we protect customer personal data and provide the information needed to show we meet this addendum. If that is not enough, or a regulator requires it, you may audit us once a year with 30 days' notice, at your cost, during working hours, by an auditor bound to confidentiality, in a way that does not reveal other customers' data.
11. Liability and order of precedence
Each side's liability under this addendum is subject to the limits in the Terms, except where the law (or the standard contractual clauses) does not allow a limit.
12. Annex 1 — the parties
- Controller / data exporter: the firm, as named in its Datumly account; contact: its administrators.
- Processor / data importer: jKulDev LLC; contact: jkuldevllc@gmail.com. Activities: providing Datumly as described in section 2.
13. Annex 2 — security measures
- Encryption in transit (TLS) everywhere; data stored with providers that encrypt at rest.
- Passwords stored as scrypt hashes; session tokens stored as hashes; secrets (authenticator keys, tax-system credentials, Apple tokens, webhook secrets) sealed with AES-256-GCM using keys kept outside the database.
- Access control enforced in the data layer for every request, by the person's roles in the firm and project; reduced, purpose-built views for clients and suppliers; nobody can grant more than they hold.
- Optional two-step sign-in for everyone, which a firm can require; rate limits on sign-in, codes and API keys.
- Audit log of approvals, money, roles, settings and support access in each firm.
- Our staff: separate console and accounts, mandatory two-step sign-in, role-based duties, every action logged; looking inside a firm only with a time-limited (≤ 2 hours), reason-stated, read-only grant shown in the firm's audit log; no impersonation or write access to firm records.
- Files reached through short-lived signed links after a permission check; uploads checked against their real type; dangerous file types refused.
- On-duty location only while checked in, with the person's consent, and deleted automatically after the firm's retention period.
- AI: content passed to providers only when a user asks for a draft; no training on it by us; audio never stored; the AI log holds no content.
- Backups and point-in-time recovery by our database provider; separate development and production environments.
14. Annex 3 — sub-processors
The current list, with what each does and where, is in our Privacy policy under “Who we share it with”.