Data Processing Agreement
GDPR-compliant data handling, sub-processor transparency, and audit rights.
Last updated: February 3, 2026
01 Overview
This Data Processing Agreement ("DPA") forms part of the agreement between JuhJuh Ltd ("Processor") and the customer entity ("Controller") for the provision of the JuhJuh development orchestration platform.
This DPA applies where JuhJuh processes personal data on behalf of the Controller in the course of providing the platform services. It supplements the Terms of Service and Privacy Policy.
02 Definitions
| Personal Data | Any information relating to an identified or identifiable natural person processed through JuhJuh |
| Controller | The customer entity that determines the purposes and means of processing personal data |
| Processor | JuhJuh Ltd, which processes personal data on behalf of the Controller through JuhJuh |
| Sub-processor | A third party engaged by the Processor to process personal data on behalf of the Controller |
| Data Subject | The identified or identifiable natural person to whom the personal data relates |
03 Scope of processing
JuhJuh processes the following categories of personal data:
- User identity data: names, email addresses, usernames
- Access data: IP addresses, session tokens, authentication logs
- Activity data: audit trail events, ticket interactions, execution logs
- Content data: ticket descriptions, comments, and knowledge entries that may contain personal data
Processing is limited to what is necessary to provide the JuhJuh platform services as described in the Terms of Service.
04 Processor obligations
JuhJuh Ltd, as Processor, commits to:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorized to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests (access, rectification, deletion, portability)
- Assist the Controller in ensuring compliance with obligations regarding data protection impact assessments
- Delete or return all personal data upon termination of services, at the Controller's choice
- Make available all information necessary to demonstrate compliance with these obligations
05 Sub-processors
The Controller authorizes the use of the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| AI model providers | Code generation execution | Per provider region |
| Stripe | Payment processing | United States |
| Infrastructure provider | Cloud hosting, database, and caching | Per deployment region |
We will notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object within that period. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.
06 Technical and organizational security measures
JuhJuh implements the following security measures:
- Access control: Role-based access with four permission levels, IP whitelisting with CIDR precision
- Authentication: Industry-standard one-way password hashing, session-based authentication, rate limiting
- Encryption: TLS for data in transit, encryption at rest for database storage
- Audit: Full audit trail logging every action with timestamp, user, and resource context
- Isolation: AI executions run in isolated sandboxes with environment variable sanitization
- Review pipeline: Five independent safety layers between AI-generated code and production environments
07 International data transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission
- Transfer to countries with an adequacy decision from the European Commission
- Binding Corporate Rules where applicable
Enterprise customers deploying JuhJuh on-premises or in a specified region can ensure all data remains within their chosen jurisdiction.
08 Data breach notification
In the event of a personal data breach, JuhJuh Ltd will:
- Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach
- Provide details of the breach including: nature and categories of data affected, approximate number of data subjects, likely consequences, and measures taken or proposed to address the breach
- Cooperate with the Controller in investigating and remediating the breach
- Document all breaches, including facts, effects, and remedial actions taken
09 Audit rights
The Controller has the right to audit JuhJuh Ltd's compliance with this DPA. Audits may be conducted:
- Once per 12-month period under normal circumstances
- At any time following a data breach or suspected non-compliance
- By the Controller directly or by an independent auditor appointed by the Controller
JuhJuh Ltd will provide reasonable access to facilities, systems, and documentation relevant to the processing of personal data. The Controller shall provide at least 30 days' written notice for routine audits.
10 Contact
For DPA-related inquiries or to execute a signed copy:
JuhJuh Ltd — Data Protection Officer