Data Processing Addendum
Last updated 28 September 2026
1. This addendum and when it applies
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between JaniSync and the customer organization that accepted them (“Customer”). It applies wherever JaniSync processes personal data on Customer’s behalf in providing the service. If there is a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA governs. No signature is required: accepting the Terms of Service accepts this DPA, and Customer may request a countersigned copy at support@janisync.com.
2. Roles of the parties
For personal data about Customer’s own employees — cleaner profiles, timesheets, clock-in and clock-out location, pay rates — Customer is the controller (or, under CCPA/CPRA, the business) and JaniSync is the processor (the service provider). JaniSync processes that data only on Customer’s documented instructions, which are the Terms of Service, this DPA, and Customer’s configuration and use of the product. JaniSync is an independent controller only for the limited account data it needs to run its own business: who the account owners are, billing records, and support correspondence. JaniSync does not sell personal data, does not share it for cross-context behavioural advertising, and retains no right to use Customer’s personal data for its own purposes.
3. What is processed, and about whom
Subject matter and duration: provision of the JaniSync workforce-management service, for as long as Customer maintains an account, plus the retention periods in Section 8. Nature and purpose: hosting, storage, transmission, computation of payroll totals and bid prices, and delivery of account notifications. Categories of data subjects: Customer’s owners and administrators, and Customer’s cleaning employees. Categories of personal data: name and email for owners; name, pay rate, a hashed PIN and, where Customer enters one, a mobile phone number for cleaners; building and site addresses entered by Customer; shift timestamps; and device GPS coordinates captured only at the moment of clock-in and clock-out. No special-category data is requested by the product, and Customer must not submit any.
4. JaniSync’s obligations as processor
JaniSync will: process personal data only on Customer’s documented instructions, including for international transfers, unless required otherwise by law (in which case it will inform Customer first unless that law forbids it); ensure that personnel authorised to process personal data are bound by confidentiality; implement the security measures in Section 6; respect the sub-processor conditions in Section 7; assist Customer in responding to data-subject requests as described in Section 9; assist Customer with security, breach notification and impact assessments, taking into account the nature of the processing and the information available to it; and delete or return personal data as described in Section 8. JaniSync will notify Customer if, in its opinion, an instruction infringes applicable data-protection law.
5. Customer’s obligations as controller
Customer is responsible for the lawfulness of the personal data it submits and the instructions it gives, including having an appropriate legal basis and giving its own employees whatever notice its jurisdiction requires before their first shift. This is not boilerplate for this product in particular: JaniSync records employee location, and Section 4 of the Terms of Service allocates the Bring Your Own Device policy, notice, and consent obligations to Customer as the employer. JaniSync provides the tooling — a location-use disclosure shown before a cleaner’s first clock-in, with the acknowledgement recorded as a timestamp — but the employment relationship, and the duty owed inside it, is Customer’s.
6. Security measures
JaniSync maintains technical and organisational measures appropriate to the risk, including: encryption of all traffic in transit; storage of owner passwords and employee PINs as one-way cryptographic hashes, never in reversible form; tenant isolation enforced on every request, so that one organization’s data is not reachable from another’s session; brute-force controls on both the owner login and the cleaner PIN surface; least-privilege infrastructure access with no standing database credentials held by staff; automated dependency and static-analysis scanning in the build pipeline; and nightly encrypted backups held off-host. Measures may be updated over time provided the level of security is not materially reduced.
7. Sub-processors
Customer gives general authorisation for JaniSync to engage the sub-processors listed below. Each is bound by a written agreement imposing data-protection obligations no less protective than this DPA. JaniSync remains liable to Customer for its sub-processors’ performance. JaniSync will give notice before adding or replacing a sub-processor, and Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, Customer may terminate the affected part of the service.
7.1 Current sub-processors
Amazon Web Services, Inc. — cloud hosting, database and object storage; transactional and service email delivery through Amazon Simple Email Service, which processes recipient address and message content; and SMS delivery of cleaner setup messages through Amazon Simple Notification Service, which processes recipient phone number and message content; United States. Amazon Simple Notification Service is only engaged where Customer uses the SMS onboarding path. Stripe, Inc. — payment processing and subscription billing; United States. No card details reach JaniSync’s servers. Anthropic PBC — AI inference for bid-pricing and drafting assistance; United States. This sub-processor is only engaged for organizations that have AI features enabled.
7.2 AI processing, specifically
Anthropic is accessed through its commercial API. Under Anthropic’s commercial terms, Customer’s inputs and the outputs generated from them are not used to train Anthropic’s models. Anthropic does retain API inputs and outputs for up to 30 days for trust, safety and abuse-monitoring purposes, after which they are deleted. JaniSync does not hold a zero-data-retention arrangement with Anthropic, and this addendum does not claim one — if that changes, this section will say so. Independently of those contractual terms, the product limits what can be sent at all: prompts never include PINs, device tokens, raw GPS coordinates, cleaner legal names, wage rates, email addresses or payment identifiers, and cleaners are pseudonymised within a request. Every prompt is scoped to one organization, so no organization’s data conditions another’s output. Pooling anonymised bid data to improve regional benchmarks is off by default and requires the organization’s explicit opt-in, and a withdrawal of that opt-in removes its contributions on the next rebuild. No AI output is used to make an automated decision producing legal or similarly significant effects about any individual — recommendations and flags are advisory and reviewed by a human, which is both a GDPR Article 22 requirement and a product rule.
8. Retention, deletion and return
Raw location coordinates are purged 90 days after capture by an automated job, while the derived record of whether a shift was verified at the job site is retained with the timesheet. AI interaction records are purged after 180 days. On termination, Customer may export its data for 30 days, after which the account is closed. On a deletion request, JaniSync anonymises personal data belonging to Customer’s owners and employees and retains the underlying shift and payroll records, with nothing identifying attached, for the period required by wage-and-hour recordkeeping law — currently seven years. This is a deliberate limit on erasure, not an oversight: destroying the evidence that a worker was paid correctly is not a protection for that worker, and it is the “compliance with a legal obligation” exemption in GDPR Article 17(3)(b).
9. Data-subject requests
JaniSync will, taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures in fulfilling Customer’s obligation to respond to requests to access, correct, delete, restrict, object to or port personal data. Customer can action most requests itself from the dashboard; where it cannot, JaniSync provides operator tooling to export and erase an individual employee’s data. If JaniSync receives such a request directly from one of Customer’s employees, it will not respond substantively but will redirect the request to Customer, since Customer is the controller.
10. Personal data breach
JaniSync will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer’s personal data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed. JaniSync will provide reasonable cooperation for Customer to meet its own notification obligations. Notification is not an acknowledgement of fault.
11. International transfers
JaniSync operates from Ontario, Canada, and Customer Data is hosted and processed in the United States. Canada has an adequacy decision from the European Commission for data transferred to organizations subject to PIPEDA. Where personal data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to the United States, the transfer is made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where relevant, which are incorporated into this DPA by reference and completed with the details in Sections 3 and 7.1. Customer appoints JaniSync to enter into the Standard Contractual Clauses with sub-processors on its behalf where onward transfer requires it.
12. Audit
JaniSync will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a reasonable security questionnaire no more than once in any twelve-month period. Where Customer reasonably requires an on-site audit and no third-party report satisfies the requirement, the parties will agree scope, timing and cost in advance; audits must not compromise the confidentiality or security of other customers’ data, and are at Customer’s expense unless they reveal a material breach of this DPA.
13. Liability and precedence
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms of Service, and any reference there to a party’s aggregate liability means aggregate liability under the Terms of Service and this DPA together. Where the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses govern.
14. Contact
Questions about this DPA, requests for a countersigned copy, security questionnaires and breach notices can be sent to support@janisync.com.