Shifter Shifter
Why Shifter?FeaturesPricingFAQsContact Us Add to Slack
Why Shifter?FeaturesPricingFAQsContact Us Add to Slack

Data Protection Addendum

Version 2.1 | Last Updated Date: June 21st 2022

This Data Protection Addendum (the "Addendum") applies to the processing of Personal Data by JangaApps, LLC ("JangaApps") including, without limitation, Personal Data relating to data subjects located in the European Economic Area, Switzerland or the United Kingdom ("EU Personal Data") and consumers located in California ("CA Personal Data"). This Addendum supplements the online Terms of Use or other signed agreement entered into between you ("Customer") and JangaApps for the provision of JangaApps's products and services (the "Services") to Customer (the "Agreement") and is incorporated into the Agreement. In the event of a conflict between this Addendum and any other terms in the Agreement, the terms of this Addendum will govern.

"Data Controller", "Data Processor", "subprocessor", "Supervisory Authority", "data subject" and "process" have the meanings given in the relevant Data Protection Requirements. "Consumer", "business", "sale", and "service provider" shall have the meaning given in the CCPA. "Personal Data" means (a) the personal data that Customer provides to JangaApps for the provision of the Services and (b) any other information that Customer provides to JangaApps for the provision of the Services that constitutes "personal information" under the CCPA.

As between the parties, with regard to EU Personal Data, Customer is a Data Controller and JangaApps may be either a Data Processor or a subprocessor. As between the parties, with regard to CA Personal Data, Customer is a business and JangaApps is a service provider.

1. Nature of Data Processing

The subject matter of the data processing, including the processing operations carried out by JangaApps on behalf of Customer and Customer's data processing instructions for JangaApps, will be described in the Agreement, this Addendum, and each statement of work, order form, or equivalent document where Customer orders Services from JangaApps.

Categories of data subjects: Individuals who may use JangaApps's Services as provided to Customer under the Agreement.

Types of Personal Data processed: Personal Data provided by Customer to JangaApps in connection with the Agreement, including name, surname, email address, other profile information, and content of messages sent by data subjects in connection with the Services under the Agreement.

2. Compliance with Laws

The parties shall each comply with their respective obligations under all applicable laws, regulations, and other legal requirements relating to privacy, data security, consumer protection, marketing, and communications ("Privacy Laws"), including the California Consumer Privacy Act of 2018 ("CCPA"). With regard to EU Personal Data, the parties will comply with the EU Data Protection Directive 95/46/EC, the General Data Protection Regulation ("GDPR"), and any subordinate legislation (collectively, with Privacy Laws, the "Data Protection Requirements").

3. Customer Obligations

Customer shall:

  • Provide instruction to JangaApps and determine the purposes and general means of JangaApps's processing of Personal Data on behalf of Customer;
  • Comply with its personal data protection, data security and other obligations prescribed by Data Protection Requirements for Data Controllers;
  • Establish and maintain a procedure for the exercise of the rights of data subjects;
  • As required, provide notice and obtain consent from data subjects;
  • Establish a legal basis for JangaApps's processing of Personal Data;
  • Process only data that have been lawfully and validly collected;
  • Ensure compliance with this Addendum by its personnel.

By entering into this Addendum, Customer instructs JangaApps to process Customer Personal Data only in accordance with applicable law: (a) to provide the Services; (b) as authorized by the Agreement; and (c) as further documented in written instructions given by Customer and acknowledged by JangaApps.

4. JangaApps Obligations

JangaApps, in its capacity as a Data Processor or subprocessor, shall:

  • Process Personal Data solely for the purposes of providing the Services as described in the Agreement;
  • Not sell any CA Personal Data or retain, use or disclose CA Personal Data outside of the direct business relationship;
  • Inform Customer immediately if an instruction violates applicable Data Protection Requirements;
  • Adopt and maintain appropriate security measures ("Security Measures");
  • Grant access to Personal Data only to personnel who need such access;
  • Remain responsible for subprocessors' acts and omissions with regard to data protection;
  • Enter into contractual arrangements with subprocessors requiring substantially similar data protection compliance.

JangaApps shall inform Customer without delay if JangaApps becomes aware of any legally binding request for disclosure of Personal Data by a law enforcement authority, or any notice, inquiry or investigation by a Supervisory Authority.

JangaApps agrees to notify Customer of any Personal Data Breach without undue delay and in any event within 72 hours of becoming aware of it.

JangaApps shall reasonably assist Customer regarding:

  • Any requests from data subjects in respect of access, rectification, erasure, restriction, portability, blocking or deletion of Personal Data;
  • The investigation of Personal Data Breaches and notification to Supervisory Authorities and data subjects;
  • The preparation of data protection impact assessments.

5. Audit; Certification

Customer may audit JangaApps's compliance with this Addendum up to once per year. JangaApps will cooperate with the audit by providing the information and assistance reasonably necessary. The audit must be conducted during regular business hours, subject to an agreed upon audit plan.

6. Data Transfers

JangaApps is located in the United States and may store and process Personal Data in the United States or anywhere JangaApps or its Subprocessors maintains facilities. Transfers of EU Personal Data are governed by the Standard Contractual Clauses for the transfer of EU Personal Data to processors established in third countries (European Commission Decision 2010/87/EU).

The parties agree that:

  • Customer will act as the data exporter and JangaApps will act as the data importer;
  • The categories of data subjects, data, and processing operations shall be as set out in Section 1;
  • The technical and organizational measures shall be the Security Measures;
  • Customer's authorizations constitute prior written consent to subcontracting;
  • Certification of deletion shall be provided upon Customer's request.

7. Analytics

Customer acknowledges that JangaApps may create and derive anonymized and/or aggregated data from processing under the Agreement and use such data for its lawful business purposes.

8. Term

This Addendum shall remain in effect as long as JangaApps carries out Personal Data processing operations on behalf of Customer or until the termination of the Agreement.

9. Data Return and Deletion

Upon expiration or termination of the Agreement, JangaApps shall securely destroy all Personal Data and, at the request of Customer, certify that it has taken such measures, unless applicable laws prevent JangaApps from doing so.

10. Liability

The total combined liability of either party towards the other party under or in connection with this Addendum and the Standard Contractual Clauses combined will be limited to the liability limitations agreed to by the parties in the Agreement.

Attachment 1: Security Measures

JangaApps may update the Security Measures from time to time, provided the updated measures do not decrease the overall protection of Personal Data. Security measures include:

  • Organizational management and staff responsible for information security program development, implementation and maintenance;
  • Audit and risk assessment procedures for periodic review and assessment of risks;
  • Data security controls including logical segregation, role-based access, monitoring, and industry standard encryption;
  • Logical access controls to manage electronic access based on authority levels and job functions;
  • Password controls to manage and control password strength, expiration and usage;
  • System audit or event logging and related monitoring procedures;
  • Change management procedures and tracking mechanisms;
  • Incident management procedures for investigation, response, and mitigation;
  • Disaster recovery procedures to maintain service and recover from emergencies.
Shifter Shifter
By JangaApps

Manage on-call rotations directly in Slack. Always know who is responsible for incoming events, bugs and questions.

Company
HomeFeaturesPricingFAQsContact
Use Cases
Engineering TeamsDevOps & SRECustomer SupportSales Teams
Legal
Privacy PolicyTerms of ServiceData Protection
Copyright 2026 @JangaApps. All Rights Reserved.