JUMP AI Technologies Data Processing Addendum

Version: 1.4
Effective Date: 1 July 2026
Last Updated: 1 July 2026
DPA URL: https://jumpdiscovery.com/terms-and-conditions/dpa

This Data Processing Addendum, including its annexes and any documents incorporated by reference (the “DPA”), forms part of the agreement between JUMP AI Technologies SL, a company incorporated under the laws of Spain, with registered office at Calle Fuenterrabia 9, Oficina 6, 28014 Madrid, Spain, and Spanish tax identification number B87597944 (“Jump”, “we”, “us” or “our”) and the customer identified in the applicable order form, statement of work, software license and service order, master services agreement, online terms, or other written agreement referencing Jump’s terms and conditions (“Customer”, “you” or “your”).

This DPA applies where Jump Processes Personal Data on behalf of Customer in connection with the provision of Jump’s products and services, including, as applicable, Jump Insights (analytics), Jump Recommender (personalisation engine), Jump Search (enterprise search), Jump Propensity Engine (prediction and churn analytics), Jump Pulse (marketing intelligence), Datanauta (agentic data platform), Conversational AI assistant, and any other products or services described in the applicable Agreement or Order Form (collectively, the “Services”).

This DPA is modular. It applies only to the Services actually purchased, ordered, enabled, configured, or used by Customer under the Agreement. References in this DPA or its Annexes to a particular Jump product, feature, processing activity, data category, AI functionality, or Sub-processor shall not mean that such product, feature, processing activity, data category, AI functionality, or Sub-processor is used for every Customer.

1. Relationship with the Agreement

1.1 Incorporation. This DPA is incorporated into and forms part of the Agreement where the Agreement, Jump’s online Terms and Conditions, an Order Form, a Statement of Work, or any other applicable contractual document refers to or incorporates this DPA by reference. Customer’s use of the Services constitutes acceptance of this DPA to the extent Jump Processes Personal Data on behalf of Customer.

1.2 Order of precedence. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail solely with respect to the Processing of Customer Personal Data. In all other respects, the Agreement shall continue to apply.

1.3 No expansion of Services. This DPA does not grant Customer any additional right to use any Jump product or service not purchased under the applicable Agreement or Order Form.

1.4 Versioning. Jump may update this DPA from time to time to reflect changes in applicable law, regulatory guidance, security practices, Sub-processors, products, or operational requirements. Jump will not materially reduce the level of protection for Customer Personal Data during the term of the Agreement. Material changes will be notified in accordance with Section 20.

1.5 Legacy agreements. Where an existing Agreement does not incorporate Jump’s online Terms and Conditions, this DPA shall apply only if incorporated by a signed addendum, written amendment, PDF DPA, order form, statement of work, or other written agreement between the parties. For such legacy Agreements, Jump may provide this DPA in PDF format for Customer review, signature, or written acceptance.

2. Definitions

For the purposes of this DPA:

“Agreement” means the applicable agreement, order form, statement of work, software license and service order, online terms, or other contractual document governing Customer’s use of the Services.

“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including, where applicable, Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), the Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantee, the UK GDPR, and any laws implementing, supplementing, replacing, or amending the foregoing.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process”, “Processing”, “Sub-processor”, and “Supervisory Authority” shall have the meanings given to them under the GDPR or Applicable Data Protection Laws.

“Customer Data” means all data, content, files, events, records, metadata, logs, identifiers, queries, prompts, outputs, configurations, or other information submitted to, uploaded to, transmitted to, or otherwise made available to Jump by or on behalf of Customer in connection with the Services.

“Customer Personal Data” means Personal Data contained in Customer Data that Jump Processes on behalf of Customer as Processor.

“Documentation” means Jump’s then-current technical, product, security, legal, support, and user documentation applicable to the Services, including documentation made available through Jump’s websites, portals, legal pages, security pages, or customer communications.

“Restricted Transfer” means a transfer of Customer Personal Data from the European Economic Area or the United Kingdom to a country or recipient that is not recognised as providing an adequate level of data protection under Applicable Data Protection Laws.

“Services” means the products and services provided by Jump to Customer under the Agreement, including any professional services, implementation services, support services, APIs, dashboards, data processing pipelines, models, analytics, recommendation, search, prediction, marketing intelligence and campaign support, and AI-enabled services.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended, replaced, or supplemented from time to time.

3. Roles of the Parties

3.1 Customer as Controller. As between the parties, Customer is the Controller of Customer Personal Data, unless Customer acts as Processor on behalf of a third-party Controller, in which case Customer represents and warrants that it has all necessary authority and instructions from such Controller to appoint Jump as Sub-processor.

3.2 Jump as Processor. Jump shall Process Customer Personal Data as Processor on behalf of Customer and only in accordance with Customer’s documented instructions, as further described in this DPA.

3.3 Documented instructions. Customer’s documented instructions include:

  1. the Agreement;
  2. this DPA;
  3. the applicable Order Form or Statement of Work;
  4. Customer’s configuration and use of the Services;
  5. instructions submitted through authorised support channels; and
  6. any other written instructions agreed by the parties.

3.4 Customer responsibility for instructions. Customer is responsible for ensuring that its instructions to Jump comply with Applicable Data Protection Laws. Customer shall not instruct Jump to Process Customer Personal Data in a manner that would violate Applicable Data Protection Laws.

3.5 Unlawful instructions. If Jump reasonably believes that an instruction from Customer infringes Applicable Data Protection Laws, Jump shall inform Customer without undue delay, unless prohibited by applicable law.

3.6 Jump as independent Controller. This DPA applies where Jump Processes Customer Personal Data as Processor on behalf of Customer. It does not apply to Personal Data that Jump Processes as an independent Controller for its own limited business purposes, such as managing customer accounts and contacts, billing, finance, contract administration, legal compliance, fraud prevention, security monitoring, and business communications. For clarity, this Section does not permit Jump to use Customer Personal Data processed on Customer’s behalf for purposes unrelated to the Services. Such independent-controller Processing is governed by Jump’s applicable privacy notice, not this DPA.

4. Scope, Nature, and Purpose of Processing

4.1 Scope. Jump shall Process Customer Personal Data only to provide, maintain, secure, support, operate, and improve the Services, only to the extent necessary to provide the contracted Services in accordance with the Agreement and Customer’s documented instructions.

4.2 Subject matter. The subject matter of the Processing is the provision of cloud software, data analytics, video intelligence, recommendation, search, prediction, marketing intelligence and campaign support, AI-enabled services, and related professional services by Jump to Customer.

4.3 Duration. Jump shall Process Customer Personal Data for the duration of the Agreement, unless otherwise required by applicable law, the Agreement, this DPA, or Customer’s written instructions.

4.4 Nature of Processing. The Processing may include collection, ingestion, receipt, recording, organisation, structuring, storage, hosting, transmission, retrieval, consultation, analysis, transformation, pseudonymisation, aggregation, enrichment, scoring, indexing, modelling, prediction, recommendation, display, export, deletion, and other Processing operations necessary to provide the Services.

4.5 Purpose of Processing. The purposes of Processing are described in Annex I and include, as applicable:

  1. providing analytics and insights;
  2. generating recommendations;
  3. enabling search and discovery;
  4. predicting churn, disengagement, propensity, or similar behavioural patterns;
  5. supporting data-driven marketing campaigns and campaign performance analysis;
  6. integrating Customer data sources;
  7. delivering dashboards, exports, reports, APIs, alerts, or data feeds;
  8. providing technical support, implementation, maintenance, and security; and
  9. providing AI-enabled features where enabled by Customer.

4.6 Modular application. The specific Processing applicable to Customer shall depend on the Services purchased, configured, enabled, and used by Customer.

5. Customer Obligations

5.1 Customer shall comply with Applicable Data Protection Laws in relation to Customer Personal Data and its use of the Services.

5.2 Customer shall be responsible for:

  1. determining the purposes and lawful bases for Processing Customer Personal Data;
  2. providing all required privacy notices to Data Subjects;
  3. obtaining all required consents or authorisations, where applicable;
  4. ensuring that Customer Personal Data is accurate, relevant, limited, and lawful;
  5. configuring the Services in accordance with privacy by design and data minimisation principles;
  6. ensuring that Customer has the right to provide Customer Personal Data to Jump for Processing;
  7. handling Data Subject requests, unless otherwise agreed; and
  8. ensuring that Customer’s use of AI-enabled Services complies with applicable law, including transparency obligations where applicable.

5.3 Customer shall not submit to the Services any special categories of Personal Data, children’s data, criminal offence data, health data, biometric data, payment card data, government identifiers, or other highly sensitive data unless:

  1. expressly agreed in the applicable Order Form or Statement of Work;
  2. technically required for the agreed Services;
  3. permitted under Applicable Data Protection Laws; and
  4. subject to appropriate safeguards agreed by the parties.

5.4 Customer shall not use the Services to make decisions producing legal or similarly significant effects concerning Data Subjects based solely on automated Processing unless Customer has ensured that such Processing is lawful and appropriate safeguards are in place.

6. Jump Obligations

6.1 Jump shall Process Customer Personal Data only in accordance with Customer’s documented instructions, unless required to do otherwise by applicable law. In such case, Jump shall inform Customer of that legal requirement before Processing, unless prohibited by law.

6.2 Jump shall ensure that persons authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations.

6.3 Jump shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as described in Annex II.

6.4 Jump shall assist Customer, taking into account the nature of the Processing and information available to Jump, with Customer’s obligations under Applicable Data Protection Laws relating to:

  1. security of Processing;
  2. Personal Data Breach notification;
  3. data protection impact assessments;
  4. prior consultation with Supervisory Authorities, where required; and
  5. Data Subject requests.

6.5 Jump shall maintain records of Processing activities as required by Applicable Data Protection Laws and make relevant information available to Customer as reasonably necessary to demonstrate compliance with this DPA.

6.6 Jump shall not sell Customer Personal Data or use Customer Personal Data for advertising, profiling, or marketing purposes unrelated to the provision of the Services.

6.7 Jump shall not use Customer Personal Data to train general-purpose AI models or third-party foundation models unless expressly authorised by Customer in writing.

7. Direct Identifiers, Email Addresses and Data Minimisation

7.1 Customer acknowledges that some Services may Process direct identifiers, including email addresses, where such data is provided, made available, or authorised by Customer and is necessary to provide the contracted Services.

7.2 Jump shall Process email addresses and other direct identifiers only in accordance with Customer’s documented instructions and only where necessary for the purposes of providing the contracted Services, such as user matching, account-level analytics, campaign segmentation support, customer-controlled activation, support, troubleshooting, reporting, or other agreed use cases.

7.3 Where email addresses or other direct identifiers are not necessary for the applicable Services, Customer and Jump should use pseudonymised, hashed, tokenised, aggregated, or otherwise minimised data instead.

7.4 Jump may recommend that Customer excludes, hashes, removes, or minimises email addresses or other direct identifiers from data pipelines where they are not required for the provision of the Services.

7.5 Customer remains responsible for determining whether email addresses or other direct identifiers are necessary, lawful, and proportionate for the Services requested by Customer.

7.6 Jump will not use email addresses or other direct identifiers to contact Customer’s end users, execute marketing campaigns, sell data, or perform direct marketing unless expressly instructed and authorised by Customer in writing.

7.7 Unless expressly agreed otherwise, Jump Pulse and similar services provide analytics, segmentation, campaign planning, and performance support. Customer remains responsible for executing campaigns through Customer-controlled tools, accounts, vendors, and communication channels.

8. Sensitive Data, Minors and Customer-Controlled Data

8.1 Jump Processes only the Customer Personal Data provided, made available, transmitted, configured, or authorised by Customer in connection with the Services.

8.2 The Services are not designed to Process special categories of Personal Data, criminal offence data, health data, biometric data, payment card data, government identifiers, or Personal Data relating to minors, unless expressly agreed in the applicable Agreement, Order Form, Statement of Work, signed addendum, or other written agreement between the parties.

8.3 Customer shall not submit such data to the Services unless:

  1. expressly agreed in writing;
  2. technically required for the agreed Services;
  3. permitted under Applicable Data Protection Laws;
  4. subject to an appropriate lawful basis and transparency notices; and
  5. subject to additional safeguards agreed by the parties where required.

8.4 Customer is solely responsible for determining which Personal Data is provided to Jump and for ensuring that such Personal Data is lawful, adequate, relevant, limited to what is necessary, and suitable for the intended use of the Services.

8.5 If Customer becomes aware that special categories of Personal Data, children’s data, criminal offence data, health data, biometric data, payment card data, government identifiers, or similarly sensitive data has been submitted to the Services without written agreement, Customer shall promptly notify Jump and cooperate with Jump to delete, isolate, minimise, or otherwise remediate such data.

9. Confidentiality

9.1 Jump shall ensure that personnel authorised to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

9.2 Jump shall limit access to Customer Personal Data to personnel, contractors, and Sub-processors who need such access to provide, support, secure, or maintain the Services.

9.3 Jump shall maintain internal access controls designed to ensure that access to Customer Personal Data is granted on a need-to-know basis.

10. Security Measures

10.1 Jump shall implement and maintain technical and organisational measures appropriate to the nature, scope, context, and purposes of Processing and the risks to Data Subjects.

10.2 Such measures are described in Annex II and may include, as applicable:

  1. access control;
  2. authentication and authorisation;
  3. encryption in transit and at rest;
  4. logging and monitoring;
  5. network security;
  6. backup and recovery;
  7. incident response;
  8. vulnerability management;
  9. personnel security;
  10. supplier management;
  11. segregation of Customer environments or logical separation of Customer data; and
  12. secure software development practices.

10.3 Customer acknowledges that security measures may evolve over time and that Jump may update or modify its security measures, provided that such updates do not materially reduce the overall level of protection for Customer Personal Data.

11. Sub-processors

11.1 Customer grants Jump general authorisation to engage Sub-processors to Process Customer Personal Data in connection with the provision, support, security, maintenance, and operation of the Services.

11.2 Jump’s current list of Sub-processors is set out in Annex III to this DPA.

11.3 The Sub-processor list shall include, where reasonably practicable:

  1. the name of the Sub-processor;
  2. the country or region where sub-processing may take place;
  3. the description of the processing activity;
  4. the applicable data transfer mechanism, where relevant;
  5. the applicable Services or processing context; and
  6. the duration of processing.

11.4 Jump shall impose data protection obligations on Sub-processors that are substantially equivalent to those imposed on Jump under this DPA, to the extent applicable to the nature of the services provided by the Sub-processor.

11.5 Jump shall remain responsible to Customer for the performance of its Sub-processors’ obligations in relation to Customer Personal Data.

11.6 Jump shall notify Customer of new Sub-processors by updating the Sub-processor list or by other reasonable means. Customer may object to a new Sub-processor on reasonable data protection grounds within thirty (30) days of notice.

11.7 If Customer objects to a new Sub-processor, Jump shall use reasonable efforts to make available a commercially reasonable alternative or workaround. If no reasonable alternative is available, either party may terminate the affected Services to the extent they cannot reasonably be provided without the relevant Sub-processor.

12. International Transfers and Hosting Location

12.1 Jump shall not make a Restricted Transfer of Customer Personal Data unless appropriate safeguards are in place in accordance with Applicable Data Protection Laws.

12.2 Where required, the parties shall rely on the Standard Contractual Clauses. The SCCs are incorporated into this DPA by reference and shall apply as follows:

  1. Controller-to-Processor transfers. Where Customer acts as Controller and Jump acts as Processor, the Controller-to-Processor module of the SCCs shall apply. This corresponds to Module Two of the SCCs.
  2. Processor-to-Sub-processor transfers. Where Customer acts as Processor on behalf of another Controller and Jump acts as Customer’s Sub-processor, the Processor-to-Processor module of the SCCs shall apply. This corresponds to Module Three of the SCCs.
  3. Customer shall be the data exporter and Jump shall be the data importer, unless the transfer is made by Jump to a Sub-processor;
  4. Annex I to this DPA shall be deemed to describe the transfer;
  5. Annex II to this DPA shall be deemed to describe the technical and organisational measures; and
  6. the competent Supervisory Authority shall be determined in accordance with the SCCs and Applicable Data Protection Laws.

12.3 For transfers to Sub-processors, Jump shall ensure that appropriate transfer mechanisms are in place, including SCCs, adequacy decisions, the EU-US Data Privacy Framework where applicable, or other lawful transfer mechanisms.

12.4 Where required by Applicable Data Protection Laws, Jump shall conduct or support transfer impact assessments in relation to Restricted Transfers involving Customer Personal Data.

12.5 If a transfer mechanism relied upon by the parties is invalidated, amended, or replaced, the parties shall cooperate in good faith to implement an alternative lawful transfer mechanism.

12.6 Jump will use commercially reasonable efforts to configure the hosting and primary processing location of Customer Personal Data in the cloud region closest or most appropriate to the Customer’s region, taking into account the Customer’s location, the location of the relevant end users, the availability of the relevant cloud services, technical suitability, latency, security, resilience, cost, and the configuration of the contracted Services.

12.7 Unless otherwise agreed in the applicable Agreement, Order Form, Statement of Work, signed addendum, or other written agreement between the parties:

  1. for Customers established in the European Economic Area or the United Kingdom, Jump will use European or UK/EEA-compatible hosting and processing locations where available and technically suitable for the relevant Services;
  2. for Customers established in the United States, Jump may use United States hosting and processing locations;
  3. for Customers established in Latin America, Jump may use Latin American hosting and processing locations where available and technically suitable for the relevant Services. Where such regional hosting is not available or not technically suitable, Jump may use the closest or otherwise appropriate cloud region, subject to the applicable transfer mechanisms and safeguards described in this DPA;
  4. support, security, routing, monitoring, metadata processing, backup, logging, and incident response may involve access or processing from other locations where necessary to provide, secure, maintain, or support the Services; and
  5. Customer-specific hosting commitments must be expressly stated in the applicable Order Form, Statement of Work, signed addendum, or other written agreement between the parties.

13. AI-Enabled Services and Third-Party AI Processing

13.1 Some Services may include AI-enabled features, including machine learning models, recommendation models, prediction models, natural language interfaces, generative AI, large language models, vector search, embeddings, automated tagging, classification, summarisation, or conversational agents (collectively, “AI Services”).

13.2 AI Services apply only where purchased, enabled, configured, or used by Customer. The existence of this Section does not mean that every Service uses generative AI, Gemini, or LLMs.

13.3 Where AI Services Process Customer Personal Data, Jump shall Process such Customer Personal Data only to provide the applicable AI Services and in accordance with Customer’s documented instructions.

13.4 Jump may use Google Cloud services, including Gemini, to support the operation of certain AI-enabled Services, advanced analytics features, or agentic data workflows. Where Gemini or other Google Cloud AI services are used through Google Cloud services, Jump will configure and use such services in accordance with the applicable Google Cloud terms and documentation. Jump will not knowingly configure Google Cloud or Gemini services in a manner that permits Customer Personal Data to be used to train general-purpose AI models, unless Customer expressly authorises such use in writing.

13.5 Unless expressly agreed otherwise in writing:

  1. Jump does not use Customer Personal Data to train third-party general-purpose AI models;
  2. Jump does not permit third-party AI providers to use Customer Personal Data to train their general-purpose AI models;
  3. Customer Personal Data may be used to generate Customer-specific outputs, scores, recommendations, embeddings, indexes, predictions, dashboards, reports, or configurations necessary to provide the Services to Customer;
  4. Customer-specific models, indexes, embeddings, outputs, or configurations are used to provide the Services to Customer and are not used to provide personalised services to other customers; and
  5. Jump may use aggregated, anonymised, or de-identified data that does not identify Customer or Data Subjects for security, benchmarking, service improvement, statistics, and product development.

13.6 Where technically feasible and commercially reasonable, Jump shall apply data minimisation measures before submitting Customer Personal Data to AI Services or third-party AI providers, including pseudonymisation, filtering, truncation, redaction, aggregation, prompt minimisation, or exclusion of unnecessary fields.

13.7 Customer is responsible for determining whether its use of AI Services requires notices to Data Subjects, consent, human oversight, additional contractual controls, data protection impact assessments, AI impact assessments, or other measures under applicable law.

13.8 Jump shall provide reasonable information about AI Services to assist Customer in meeting its transparency, accountability, and documentation obligations. Such information may include, where applicable:

  1. the type of AI functionality used;
  2. the purpose of the AI Processing;
  3. whether third-party AI providers are used;
  4. whether Customer Personal Data is used for training;
  5. retention periods for prompts and outputs;
  6. security and access controls; and
  7. known material limitations of the AI Services.

13.9 Customer shall not use AI Services for high-risk, prohibited, unlawful, discriminatory, harmful, or regulated use cases unless expressly agreed in writing and unless Customer has ensured compliance with all applicable legal requirements.

13.10 Customer acknowledges that AI outputs may be probabilistic and may contain errors, inaccuracies, or incomplete information. Customer is responsible for reviewing and validating AI outputs before relying on them for decisions affecting Data Subjects.

14. Jump Pulse

14.1 Jump Pulse is a data-driven marketing intelligence and campaign support service. Unless expressly agreed otherwise in the applicable Order Form, Statement of Work, signed addendum, or other written agreement between the parties, Jump does not directly execute marketing campaigns on behalf of Customer.

14.2 For Jump Pulse, Jump may Process Customer Personal Data to support segmentation, audience analysis, campaign planning, performance measurement, recommendations, and reporting.

14.3 Customer remains responsible for executing campaigns through its own marketing tools, platforms, accounts, vendors, and communication channels.

14.4 Customer is responsible for ensuring that any marketing campaign, communication, segmentation, profiling, or audience activation complies with Applicable Data Protection Laws, ePrivacy rules, direct marketing laws, consent requirements, opt-out requirements, and any sector-specific rules applicable to Customer.

14.5 Where Customer requests Jump to integrate with Customer’s marketing platforms, such platforms may be Customer-controlled systems or Customer-selected vendors. Unless such vendors are engaged by Jump to Process Customer Personal Data on Jump’s behalf, they are not Jump Sub-processors.

15. Data Subject Requests

15.1 Customer shall be responsible for responding to requests from Data Subjects exercising their rights under Applicable Data Protection Laws.

15.2 If Jump receives a request directly from a Data Subject relating to Customer Personal Data, Jump shall, unless legally prohibited, either:

  1. direct the Data Subject to contact Customer; or
  2. notify Customer without undue delay.

15.3 Taking into account the nature of the Processing, Jump shall provide reasonable assistance to Customer through appropriate technical and organisational measures to enable Customer to respond to Data Subject requests.

15.4 Customer shall be responsible for verifying the identity of the Data Subject and determining whether and how to respond to the request.

16. Personal Data Breaches

16.1 Jump shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

16.2 Where reasonably available, Jump’s notification shall include:

  1. a description of the nature of the Personal Data Breach;
  2. the categories and approximate number of Data Subjects affected;
  3. the categories and approximate number of Personal Data records affected;
  4. the likely consequences of the Personal Data Breach;
  5. measures taken or proposed to address the Personal Data Breach; and
  6. contact details for further information.

16.3 Jump may provide such information in phases as it becomes available.

16.4 Jump’s notification of a Personal Data Breach shall not be construed as an acknowledgement of fault or liability.

16.5 Customer shall be responsible for determining whether the Personal Data Breach must be notified to a Supervisory Authority or Data Subjects, except where Applicable Data Protection Laws impose a direct obligation on Jump.

17. Data Protection Impact Assessments and Prior Consultation

17.1 Taking into account the nature of the Processing and information available to Jump, Jump shall provide reasonable assistance to Customer in relation to data protection impact assessments and prior consultations with Supervisory Authorities, where required by Applicable Data Protection Laws.

17.2 Such assistance may include providing relevant documentation, security information, product information, Sub-processor information, data flow information, and responses to reasonable privacy questionnaires.

17.3 Any assistance beyond standard documentation and reasonable support may be subject to a separate statement of work or additional fees, unless required by Applicable Data Protection Laws.

18. Audits and Demonstration of Compliance

18.1 Jump shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA.

18.2 Customer may request information from Jump regarding its Processing of Customer Personal Data, including security documentation, Sub-processor information, data flow information, and responses to reasonable privacy or security questionnaires.

18.3 Where available, Jump may provide current third-party certifications, audit reports, penetration test summaries, security whitepapers, or similar documentation under appropriate confidentiality obligations. Nothing in this Section requires Jump to maintain any specific certification unless expressly agreed in the Agreement.

18.4 Customer may conduct an audit of Jump’s compliance with this DPA only where:

  1. required by Applicable Data Protection Laws;
  2. Customer has reasonable grounds to believe that Jump is in material breach of this DPA; or
  3. a Personal Data Breach affecting Customer Personal Data has occurred and the audit is reasonably necessary.

18.5 Any audit shall be subject to the following conditions:

  1. reasonable prior written notice of at least thirty (30) days, unless a shorter period is required by law;
  2. no more than once in any twelve (12) month period, unless required by law or following a material Personal Data Breach;
  3. conducted during normal business hours;
  4. limited to systems, records, personnel, and facilities relevant to Customer Personal Data;
  5. conducted in a manner that does not unreasonably interfere with Jump’s business operations or compromise the confidentiality, security, or data of other customers;
  6. subject to appropriate confidentiality obligations; and
  7. at Customer’s cost, unless the audit reveals a material breach of this DPA by Jump.

18.6 Jump may object to any auditor that is a competitor of Jump, lacks appropriate qualifications, or does not agree to reasonable confidentiality and security requirements.

19. Return and Deletion of Customer Personal Data

19.1 Upon termination or expiry of the Agreement, Jump shall, at Customer’s choice and subject to the functionality of the Services, return or delete Customer Personal Data in accordance with this DPA and the Agreement.

19.2 Unless otherwise agreed, Customer may export Customer Data during the term of the Agreement using available export functionality or by requesting reasonable assistance from Jump.

19.3 Following termination or expiry of the Agreement, Jump shall securely delete, destroy, or return Customer Personal Data in its possession or control in accordance with the retention periods set out in Annex I, unless retention is required by applicable law or necessary for backup, security, fraud prevention, dispute resolution, accounting, compliance, or legitimate archival purposes.

19.4 Customer Personal Data stored in backups shall be protected in accordance with this DPA and deleted in accordance with Jump’s backup lifecycle.

19.5 Where Jump is legally required to retain Customer Personal Data, Jump shall continue to protect such data in accordance with this DPA and shall not further Process it except as required by applicable law.

19.6 Jump may retain anonymised, aggregated, or de-identified data that does not identify Customer or Data Subjects, provided that such data is not Personal Data under Applicable Data Protection Laws.

20. Changes to this DPA, Sub-processors, and Legal Pages

20.1 Jump may update this DPA, the Sub-processor list, the Technical and Organisational Measures, and other legal or security documentation from time to time.

20.2 Jump shall not materially reduce the overall level of protection for Customer Personal Data during the term of the Agreement.

20.3 Material updates may be notified by email, account notification, publication on Jump’s legal page, update to the applicable URL, or other reasonable means.

20.4 Customer is responsible for ensuring that its legal, privacy, or security contact details are kept up to date.

21. Liability

21.1 The liability of each party under this DPA shall be subject to the exclusions, limitations, and liability caps set out in the Agreement.

21.2 Nothing in this DPA shall limit liability where such limitation is prohibited by applicable law.

21.3 This DPA does not create any additional indemnity, uncapped liability, service credit, warranty, or remedy unless expressly stated in the Agreement.

22. Term and Termination

22.1 This DPA shall remain in effect for as long as Jump Processes Customer Personal Data on behalf of Customer.

22.2 Termination or expiry of the Agreement shall not affect any obligation under this DPA that is intended to survive, including confidentiality, deletion, security, and international transfer obligations.

23. Governing Law and Jurisdiction

23.1 This DPA shall be governed by the law governing the Agreement.

23.2 If the Agreement does not specify a governing law, this DPA shall be governed by the laws of Spain.

23.3 If the Agreement does not specify jurisdiction, the courts of Madrid, Spain, shall have exclusive jurisdiction, without prejudice to any rights of Data Subjects or Supervisory Authorities under Applicable Data Protection Laws.

Annex I - Details of Processing

This Annex describes the Processing of Customer Personal Data by Jump. The specific Processing applicable to Customer depends on the Services purchased, enabled, configured, and used by Customer. Customer-specific processing details, if any, may be set out in the applicable Order Form, Statement of Work, signed addendum, or other written agreement between the parties.

A. Subject Matter

Provision of Jump’s cloud software, data platform, analytics, recommendation, search, prediction, marketing intelligence and campaign support, AI-enabled services, support, implementation, and related services.

B. Duration

For the term of the Agreement and thereafter only as necessary for deletion, return, legal compliance, backup lifecycle, dispute resolution, accounting, or security purposes.

C. Categories of Data Subjects

Depending on the Services used, Customer Personal Data may relate to:

  1. Customer’s end users, subscribers, viewers, registered users, visitors, prospects, or consumers.
  2. Customer’s employees, contractors, administrators, business users, marketing users, data users, support users, and authorised users.
  3. Users of Customer’s websites, applications, platforms, video services, digital properties, or communication channels.
  4. Individuals included in Customer datasets provided to Jump.
  5. Individuals interacting with AI-enabled services, chatbots, search interfaces, recommendation interfaces, or other digital interfaces configured by Customer.
  6. Other individuals whose Personal Data is included in Customer Data.

D. Categories of Customer Personal Data

Depending on the Services used and the Customer Data made available to Jump, Customer Personal Data may include:

  1. User identifiers: user ID, subscriber ID, customer ID, account ID, pseudonymous ID, hashed ID, app instance ID, profile ID, derived profile ID, reporting user ID, device ID, advertising ID, cookie ID, session ID, or similar identifiers.
  2. Contact details: email address, phone number, push token, notification token, communication preferences, language preference, or similar contact or communication identifiers, where provided by Customer or required for the applicable Services.
  3. Account and subscription data: subscription status, subscription package, plan, billing status, subscription period, start date, cancellation date, renewal status, payment status, lifecycle stage, trial status, registration status, and account events.
  4. Usage and behavioural data: page views, screen views, clicks, searches, watch events, playback events, completion rates, engagement events, feature usage, navigation events, session duration, timestamps, and user activity records.
  5. Content interaction data: content viewed, content searched, content recommended, content clicked, catalogue metadata, watch history, favourites, likes, ratings, preferences, recommendations shown, recommendation interactions, and content performance metrics.
  6. Device and technical data: IP address, user agent, browser, device type, device brand, operating system, platform, app version, network data, logs, error events, diagnostic information, and regional or location attribution data.
  7. Marketing and campaign data: audience segments, campaign membership, campaign performance, marketing source, medium, campaign identifiers, ad interaction data, email engagement data, push notification events, conversion events, win-back lists, and similar campaign-related data.
  8. Prediction and scoring data: propensity scores, churn scores, engagement scores, retention scores, recommendation scores, segmentation outputs, model outputs, confidence scores, cluster assignments, churn influencers, and related predictive analytics outputs.
  9. Search data: search queries, filters, search results displayed, result interactions, ranking signals, click-through data, and search performance data.
  10. AI input and output data: prompts, questions, instructions, context provided by Customer, retrieved content, AI-generated responses, summaries, classifications, embeddings, vector representations, metadata, and feedback signals.
  11. Customer configuration data: dashboard settings, roles, permissions, business rules, taxonomy, mapping tables, integration settings, data models, schemas, and transformation logic.
  12. Support and implementation data: tickets, logs, sample files, screenshots, communications, technical documentation, issue descriptions, and diagnostic datasets.
  13. Other Customer-controlled data: any other Personal Data submitted, transmitted, configured, authorised, or otherwise made available by Customer to the Services.

E. Special Categories of Data

Jump’s Services are not designed to Process special categories of Personal Data unless expressly agreed in writing.

Customer shall not submit special categories of Personal Data, children’s data, criminal offence data, health data, biometric data, payment card data, government identifiers, or similarly sensitive data unless expressly agreed in the applicable Order Form, Statement of Work, or other written agreement.

F. Purposes of Processing by Product or Service

The following list is modular. It applies only to the Services purchased, enabled, configured, or used by Customer.

Jump Insights

Main Processing Purposes: analytics, dashboards, business intelligence, audience and content analysis, reporting, KPI tracking.

Typical Data Processed: user IDs, usage events, content events, device data, subscription data, engagement data, aggregated metrics, email where provided and necessary.

Typical Data Subjects: end users, subscribers, viewers, Customer business users.

Jump Recommender (personalisation engine)

Main Processing Purposes: personalised or contextual content recommendations, ranking, recommendation optimisation, recommendation performance measurement.

Typical Data Processed: user IDs, content metadata, watch history, preferences, interaction data, recommendation events, model scores.

Typical Data Subjects: end users, subscribers, viewers.

Jump Search

Main Processing Purposes: search indexing, query processing, result ranking, search analytics, search performance improvement.

Typical Data Processed: search queries, user/session IDs, content metadata, click data, filters, result interactions.

Typical Data Subjects: end users, subscribers, visitors.

Jump Propensity Engine

Main Processing Purposes: churn prediction, disengagement prediction, lifecycle scoring, segmentation, propensity modelling, retention analytics.

Typical Data Processed: user IDs, subscription data, usage behaviour, engagement data, cancellation indicators, model scores, segment data, email where provided and necessary for matching or segmentation.

Typical Data Subjects: subscribers, end users, prospects.

Jump Pulse

Main Processing Purposes: data-driven marketing intelligence and campaign support, segmentation, campaign planning, performance tracking, audience activation support.

Typical Data Processed: contact details where provided, campaign segments, engagement events, email/push events, conversion events, audience lists.

Typical Data Subjects: subscribers, prospects, end users.

Datanauta

Main Processing Purposes: data integration, agentic analytics, data quality, transformation, natural language analytics, reporting, operational intelligence.

Typical Data Processed: Customer datasets, schemas, IDs, usage events, metadata, prompts and outputs where enabled.

Typical Data Subjects: individuals included in Customer datasets, Customer authorised users.

Conversational AI assistant

Main Processing Purposes: conversational interfaces, question answering, information retrieval, summarisation, AI assistance.

Typical Data Processed: prompts, questions, retrieved content, AI outputs, session metadata, user identifiers where provided.

Typical Data Subjects: website visitors, Customer users, end users.

Data integrations and onboarding

Main Processing Purposes: data ingestion, mapping, transformation, validation, quality control, implementation, source integration.

Typical Data Processed: source data provided by Customer, logs, schema, mapping files, IDs, technical metadata.

Typical Data Subjects: individuals included in Customer datasets.

Dashboards and APIs

Main Processing Purposes: display, access, export, and delivery of processed outputs to Customer.

Typical Data Processed: analytics outputs, model outputs, reports, metrics, scores, dashboards, exports.

Typical Data Subjects: Customer authorised users, end users where data is displayed.

Support and maintenance

Main Processing Purposes: troubleshooting, debugging, incident resolution, support, monitoring, service maintenance.

Typical Data Processed: support tickets, logs, screenshots, sample data, diagnostic information.

Typical Data Subjects: Customer users, end users where included in support materials.

AI-enabled features

Main Processing Purposes: conversational interfaces, summarisation, classification, tagging, natural language analytics, AI search, AI assistance.

Typical Data Processed: prompts, outputs, context, embeddings, logs, retrieved content, user/session IDs where applicable.

Typical Data Subjects: Customer users, end users, visitors interacting with AI services.

G. Specific Data Category: Direct Identifiers and Contact Details

Data category: contact details and direct identifiers.

Examples: email address, phone number, push token, notification token, user login identifier.

Used when: only where necessary to provide the contracted Services and provided, made available, or authorised by Customer.

Purpose: user matching, segmentation support, campaign analytics, customer-controlled activation, reporting, troubleshooting, support, and service delivery.

H. Frequency of Processing

Continuous, periodic, batch-based, event-based, real-time, near real-time, or ad hoc, depending on the Services and Customer configuration.

I. Retention of Customer Personal Data

Customer Personal Data is retained only for the period necessary to provide the contracted Services, unless otherwise agreed in the Agreement, configured by Customer, required by applicable law, or necessary for backup, security, support, accounting, dispute resolution, or compliance purposes.

Unless otherwise stated in the applicable Order Form, Statement of Work, signed addendum, or other written agreement between the parties, Jump applies the following standard retention periods:

  1. Production Customer Personal Data: retained for the term of the applicable Agreement or Service and deleted or returned from active production systems within thirty (30) days after termination or expiry, unless continued retention is required by applicable law or agreed in writing. Where deletion from active production systems cannot reasonably be completed within thirty (30) days due to technical or operational constraints, Jump shall complete deletion as soon as reasonably practicable and in any event within ninety (90) days.
  2. Backups: deleted or overwritten in accordance with Jump’s backup lifecycle, normally within one hundred and eighty (180) days after deletion from production systems, unless longer retention is technically required by the relevant cloud provider, backup architecture, or applicable law.
  3. Security, infrastructure and application logs: retained for up to twelve (12) months where reasonably necessary for security, troubleshooting, observability, compliance, and incident investigation.
  4. Support tickets and implementation records: retained for up to thirty-six (36) months where reasonably necessary for support history, contractual evidence, troubleshooting, auditability, or dispute resolution.
  5. AI prompts, AI outputs, embeddings, indexes, model outputs and Customer-specific configurations: retained only where necessary to provide, secure, monitor, or troubleshoot the contracted Services. Unless otherwise agreed, Customer-specific AI artefacts are deleted or deactivated from active production systems within thirty (30) days after termination or expiry of the relevant Service, subject to backup lifecycle, legal retention, and any technical or operational constraints. Where deletion or deactivation cannot reasonably be completed within thirty (30) days, Jump shall complete it as soon as reasonably practicable and in any event within ninety (90) days.
  6. Billing, accounting, legal and compliance records: retained for the statutory or legally required period applicable to Jump.

Customer-specific retention commitments must be expressly stated in the applicable Order Form, Statement of Work, signed addendum, or other written agreement between the parties.

Annex II - Technical and Organisational Measures

Jump shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data Processed on behalf of Customer against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

Such measures shall include, as applicable:

1. Access Control

Jump shall implement role-based access controls to ensure that Customer Personal Data is accessible only to authorised personnel who require such access for the provision, operation, security, maintenance, or support of the Services.

Access rights shall be granted on a need-to-know and least-privilege basis. User access shall be reviewed periodically and revoked or amended when no longer required, including upon role change or termination of employment or engagement.

Administrative access to systems Processing Customer Personal Data shall be restricted to authorised personnel only.

2. Authentication and Identity Management

Jump shall require appropriate authentication mechanisms for access to systems Processing Customer Personal Data, including strong passwords and, where available and appropriate, multi-factor authentication.

User accounts shall be personal to the authorised user and shall not be shared.

3. Encryption

Jump shall use appropriate encryption mechanisms to protect Customer Personal Data in transit and, where supported by the relevant systems and infrastructure, at rest.

Data transmitted over public networks shall be protected using industry-standard secure protocols, such as TLS or equivalent technologies.

4. Hosting and Infrastructure Security

Customer Personal Data shall be hosted and processed using reputable cloud infrastructure providers that maintain appropriate security certifications, controls, and safeguards.

Jump shall ensure that the cloud infrastructure used for the Services includes appropriate physical, environmental, network, and operational security controls.

5. Logging and Monitoring

Jump shall maintain appropriate logging and monitoring mechanisms for systems Processing Customer Personal Data, including logs relating to access, system activity, and security-relevant events, where technically feasible and appropriate.

Logs shall be used to support security monitoring, troubleshooting, incident investigation, and compliance verification.

6. Segregation and Data Minimisation

Jump shall apply appropriate logical separation of environments, systems, and datasets to prevent unauthorised access or unintended mixing of Customer Personal Data.

Jump shall Process only Customer Personal Data necessary for the provision of the Services and solely in accordance with Customer’s documented instructions and this DPA.

7. Confidentiality and Personnel Controls

Jump shall ensure that personnel authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory.

Personnel with access to Customer Personal Data shall receive appropriate information security and data protection guidance proportionate to their role and responsibilities.

8. Sub-processor Management

Jump shall perform appropriate due diligence before engaging Sub-processors that Process Customer Personal Data on behalf of Jump.

Jump shall ensure that Sub-processors are subject to written contractual obligations that provide substantially equivalent data protection and security obligations to those imposed on Jump under this DPA.

9. Vulnerability and Change Management

Jump shall apply reasonable measures to identify, assess, and remediate security vulnerabilities affecting systems used to Process Customer Personal Data.

Changes to production systems shall be managed in a controlled manner, including appropriate testing, review, and approval procedures where applicable.

10. Backup, Availability and Resilience

Jump shall implement appropriate measures designed to maintain the availability and resilience of systems Processing Customer Personal Data.

Where applicable, backups shall be maintained to support recovery of systems and data in the event of accidental loss, corruption, or unavailability.

11. Incident Response

Jump shall maintain procedures for identifying, assessing, escalating, and responding to actual or suspected Personal Data Breaches and security incidents.

Jump shall notify Customer of Personal Data Breaches in accordance with the notification obligations set out in this DPA.

12. Secure Deletion and Return of Data

Upon expiry or termination of the relevant Agreement, or upon written instruction from Customer, Jump shall return, delete, or destroy Customer Personal Data in accordance with this DPA, unless retention is required by applicable law.

Secure deletion shall be performed using reasonable and appropriate technical means, taking into account the systems and media on which Customer Personal Data is stored.

13. Business Continuity

Jump shall maintain reasonable business continuity and disaster recovery measures designed to ensure continuity of the Services and recovery from disruptive events affecting systems used to Process Customer Personal Data.

14. Review of Measures

Jump shall review and, where appropriate, update its technical and organisational measures periodically to reflect changes in technology, risk, processing activities, and applicable legal requirements, provided that such updates shall not materially reduce the overall level of security provided for Customer Personal Data.

The technical and organisational measures described above shall be interpreted taking into account the nature, scope, context and purposes of the Processing, the categories of Customer Personal Data Processed, the risks presented by the Processing, and the state of the art and cost of implementation.

Annex III - Sub-processors

This Annex sets out the current list of Sub-processors authorised by Jump to Process Customer Personal Data in connection with the provision, operation, support, maintenance, and security of Jump’s Services.

This list may be updated in accordance with Section 11 and Section 20.

1. Approved Sub-processors

Google Ireland Limited

Country / Region where sub-processing may take place: Ireland and other EEA countries.

Description of processing activity: cloud infrastructure, hosting, storage, data processing and Google Cloud services, including Gemini where applicable, used to support the operation of the Services and advanced analytics / AI-enabled features.

Transfer mechanism: adequacy decision under applicable Data Protection Laws / processing within the EEA where applicable.

Applicable Services / Context: cloud hosting, storage, processing, analytics, AI-enabled services, Jump Insights (analytics), Jump Recommender (personalisation engine), Jump Search (enterprise search), Jump Propensity Engine (prediction and churn analytics), Jump Pulse (marketing intelligence), Datanauta (agentic data platform), Conversational AI assistant, customer support, implementation, security operations, and other contracted Services where applicable.

Duration of processing: for the duration necessary to provide the contracted Services, until expiry or termination of the applicable Agreement, or until processing is no longer necessary, unless otherwise required by applicable law or agreed in writing.

Google LLC

Country / Region where sub-processing may take place: United States.

Description of processing activity: cloud infrastructure, technical support, network routing, service metadata processing and Google Cloud services, including Gemini where such processing is required to support the operation, security, maintenance, availability, and advanced analytics / AI-enabled features of the Services.

Transfer mechanism: EU-US Data Privacy Framework, UK Extension to the EU-US Data Privacy Framework, Standard Contractual Clauses where applicable, or other lawful transfer mechanism under Applicable Data Protection Laws.

Applicable Services / Context: cloud support, routing, security, metadata processing, Gemini, AI-enabled services, infrastructure support and operational support where applicable.

Duration of processing: for the duration necessary to provide the contracted Services, until expiry or termination of the applicable Agreement, or until processing is no longer necessary, unless otherwise required by applicable law or agreed in writing.

Amazon Web Services EMEA SARL / Amazon Web Services, Inc. (as applicable)

Country / Region where sub-processing may take place: European Economic Area, United States, and other AWS regions selected or required for the contracted Services.

Description of processing activity: legacy or supplementary cloud infrastructure, hosting, storage, data processing, backup, security, monitoring, and related cloud services where applicable.

Transfer mechanism: adequacy decision, Standard Contractual Clauses, Data Privacy Framework where applicable, or other lawful transfer mechanism under Applicable Data Protection Laws.

Applicable Services / Context: legacy AWS-hosted services, storage, integrations, backups, security or operational processing where applicable.

Duration of processing: for the duration necessary to provide the contracted Services, until expiry or termination of the applicable Agreement, or until processing is no longer necessary, unless otherwise required by applicable law or agreed in writing.

Slack Technologies, LLC / Salesforce group entity (as applicable)

Country / Region where sub-processing may take place: United States, European Economic Area, and other locations used by Slack/Salesforce to provide the service.

Description of processing activity: customer communications, support communications, operational coordination, incident coordination, and exchange of Customer-provided information through Slack channels or workspaces where applicable.

Transfer mechanism: Standard Contractual Clauses, Data Privacy Framework where applicable, or other lawful transfer mechanism under Applicable Data Protection Laws.

Applicable Services / Context: customer support, shared Slack channels with Customers, implementation communications, service operations and incident coordination where applicable.

Duration of processing: for the duration necessary to provide support, implementation, operational coordination, or the contracted Services, unless deletion is requested and technically available or retention is required by applicable law, audit, security, or dispute resolution.

The Rocket Science Group LLC d/b/a Mailchimp / Intuit group entity (as applicable)

Country / Region where sub-processing may take place: United States and other locations used by Mailchimp/Intuit to provide the service.

Description of processing activity: email communications, mailing lists, service communications, product communications, marketing operations, or campaign-related support where applicable and where Jump acts as processor or sub-processor.

Transfer mechanism: Data Privacy Framework, Standard Contractual Clauses where applicable, or other lawful transfer mechanism under Applicable Data Protection Laws.

Applicable Services / Context: mailing or campaign support, product communications, customer communications, or Jump Pulse support where applicable. Where Customer executes campaigns through its own Mailchimp account, Mailchimp is Customer’s provider and not Jump’s Sub-processor.

Duration of processing: for the duration necessary to provide the relevant communication, support, campaign-support, or contracted Services, unless deletion is requested and technically available or retention is required by applicable law, audit, security, or dispute resolution.

Supabase, Inc.

Country / Region where sub-processing may take place: United States, European Economic Area, and other cloud regions configured or used for the contracted Services.

Description of processing activity: database, authentication, storage, backend infrastructure, APIs, logging, and application services where applicable.

Transfer mechanism: Standard Contractual Clauses, Data Privacy Framework where applicable, or other lawful transfer mechanism under Applicable Data Protection Laws.

Applicable Services / Context: backend infrastructure, databases, authentication, storage, APIs, logging, customer-specific applications, pilot environments, AI-enabled services, Conversational AI assistant, Datanauta (agentic data platform), and other Jump products, services, or contracted product components where Supabase is used.

Duration of processing: for the duration necessary to provide the contracted Services, until expiry or termination of the applicable Agreement, or until processing is no longer necessary, unless otherwise required by applicable law or agreed in writing.

2. Regional Hosting Approach

Unless otherwise agreed with Customer:

  1. European Customers: primary hosting and processing will be configured in European or UK/EEA-compatible locations where available and technically suitable for the relevant Services.
  2. United States Customers: hosting and processing may be configured in United States locations.
  3. Latin America Customers: hosting and processing may be configured in Latin American locations where available and technically suitable for the relevant Services. Where such regional hosting is unavailable or unsuitable, Jump may use the closest or otherwise appropriate cloud region subject to applicable transfer mechanisms.
  4. Customers in other regions: hosting and processing may be configured in the closest or otherwise appropriate cloud region, taking into account availability, latency, resilience, security, technical suitability, and the contracted Services.
  5. Technical support, routing, security, service metadata, logging, backups, and incident response may involve processing from other locations where necessary to provide, secure, maintain, or support the Services.

3. Future Sub-processors

Jump may add new Sub-processors where necessary to provide, secure, maintain, support, or operate the Services. New Sub-processors will be notified in accordance with the DPA.

Customer may object to a new Sub-processor on reasonable data protection grounds within the period stated in the DPA.

4. Customer-Controlled Third-Party Platforms

Customer may choose to connect Jump Services to Customer-controlled third-party platforms, data sources, marketing tools, analytics tools, cloud storage, advertising accounts, CRMs, CDPs, CMSs, payment systems, notification systems, or other systems.

Unless such third-party platform is engaged by Jump to Process Customer Personal Data on Jump’s behalf, such platform is not a Jump Sub-processor. Customer is responsible for its own agreements, data protection terms, consents, lawful basis, configuration, and compliance in relation to Customer-controlled platforms.

Annex IV - AI Services Notice

This Annex applies only where Customer purchases, enables, configures, or uses AI-enabled Services.

1. AI Processing Activities

Depending on the Services used, AI Processing may include:

  1. recommendation generation;
  2. churn, disengagement, or propensity prediction;
  3. user or content clustering;
  4. content classification or tagging;
  5. semantic search or vector search;
  6. embeddings generation;
  7. natural language querying;
  8. summarisation;
  9. conversational AI;
  10. report generation;
  11. anomaly detection;
  12. assisted analytics; and
  13. other AI-enabled features described in the Agreement or Documentation.

2. Use of Customer Personal Data for Training

Unless expressly agreed otherwise in writing:

  1. Jump does not use Customer Personal Data to train third-party general-purpose AI models.
  2. Jump does not permit third-party AI providers to use Customer Personal Data to train their general-purpose AI models.
  3. Customer Personal Data may be used to generate Customer-specific outputs, scores, recommendations, embeddings, indexes, predictions, or configurations necessary to provide the Services to Customer.
  4. Customer-specific models, indexes, embeddings, or outputs are used to provide the Services to Customer and are not used to provide personalised services to other customers.

3. Customer Responsibilities for AI Services

Customer is responsible for:

  1. determining whether AI Services are appropriate for its intended use case;
  2. providing required notices to Data Subjects;
  3. ensuring a lawful basis for Processing;
  4. ensuring that AI outputs are reviewed before use in decisions affecting individuals;
  5. avoiding prohibited or high-risk uses unless expressly agreed and legally compliant;
  6. ensuring that Customer’s use of AI Services complies with Applicable Data Protection Laws, consumer protection laws, advertising laws, employment laws, sector-specific laws, and AI-specific laws where applicable; and
  7. maintaining human oversight where appropriate.

4. AI Outputs

Customer acknowledges that AI outputs may be generated through probabilistic systems and may not always be complete, accurate, current, or suitable for Customer’s intended purpose. Customer is responsible for evaluating AI outputs before relying on them.

5. Transparency

Where AI Services interact directly with Data Subjects, Customer is responsible for ensuring that Data Subjects receive appropriate transparency notices, unless Jump has expressly agreed to provide such notice on Customer’s behalf.

Annex V - Contact Details

Jump Privacy Contact

Email: privacy@jumptechnologies.ai
Address: Calle Fuenterrabia 9, Oficina 6, 28014 Madrid, Spain

Jump Data Protection Contact

Email: dpd@jumptechnologies.ai
Address: Calle Fuenterrabia 9, Oficina 6, 28014 Madrid, Spain

Jump Legal Contact

Email: legal@jumptechnologies.ai
Address: Calle Fuenterrabia 9, Oficina 6, 28014 Madrid, Spain

Customer Privacy Contact

As specified in the applicable Order Form, Agreement, or Customer account.

Customer is responsible for keeping its privacy and security contact details accurate and up to date.

Funding information