This Data Processing Agreement ("DPA") is part of the Terms of Service (the "Terms") between Jaapi AB, company registration number 559387-9421 ("Jaapi") and the organization that holds an Account with Jaapi (the "Customer", who is "you" in the Terms). It sets out the terms under which Jaapi processes personal data on the Customer's behalf, as Article 28(3) of the General Data Protection Regulation (EU) 2016/679 ("GDPR") requires.
1. Scope and precedence
1.1 This DPA applies to all personal data Jaapi processes on the Customer's behalf in providing the Services, in every store the Customer holds with Jaapi.
1.2 On matters of data protection this DPA prevails over the Terms. A data processing agreement signed by both parties prevails over this DPA.
1.3 "Data Protection Law" means the GDPR; the UK GDPR and the Data Protection Act 2018 of the United Kingdom; the Swiss Federal Act on Data Protection ("FADP"); and, where they apply to the Customer's personal data, US state privacy laws. Terms defined in the GDPR ("personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", "supervisory authority") have the meaning the GDPR gives them, and a reference to an article of the GDPR includes the equivalent provision of the UK GDPR and the FADP where those apply, with the supervisory authority they designate. "Services" and "Account" have the meaning the Terms give them.
1.4 Where a US state privacy law applies to personal data in the Customer's store, Annex 3 applies to that data in addition to this DPA.
2. Roles
2.1 For the personal data in the Customer's store, the Customer is the controller and Jaapi is the processor. Where the Customer is itself a processor for another controller, the Customer warrants that its instructions to Jaapi are authorized by that controller.
2.2 Jaapi is the controller of the personal data it holds about the Customer as its client: the contact details of the Customer's representatives, the agreement and the invoices. That processing is described in Jaapi's privacy policy and is outside this DPA.
3. Details of the processing
Subject matter. Hosting and operating the Customer's store: user accounts, orders, their payment, production and delivery, employee credit, gift links, and support.
Duration. From the Customer's request for an Account until the personal data is deleted under section 11.
Nature and purpose. Storing and serving the store's data; authenticating users; creating user accounts from the Customer's identity provider or HR system when the Customer connects one; taking and paying for orders; passing each order to a manufacturing supplier for production and delivery; sending the store's email; keeping the store secure and working; answering support requests.
Types of personal data. Name, email address, role and department; shipping addresses, with the phone number and any customs tax identifier entered for delivery; order history; credit balance and its history; support correspondence; IP address, requested page and browser identification in request logs. Payment card details are held by Jaapi's payment processor and never reach Jaapi's systems.
Categories of data subjects. The Customer's employees and other persons the Customer gives access to its store; recipients of gifts sent from the store, including the recipients of a gift campaign, whose name and email address the Customer gives Jaapi to send the invitation; the Customer's administrators and other people who write to support on the Customer's behalf.
Special categories of data. The Services are not designed to process special categories of personal data under Article 9 GDPR, and the Customer shall not use them for that purpose.
4. Instructions
4.1 Jaapi processes personal data only on the Customer's documented instructions, unless required to do so by a law to which Jaapi or its sub-processor is subject. In that case Jaapi informs the Customer of the legal requirement before processing, unless the law prohibits it on important grounds of public interest.
4.2 The Customer's instructions are: the Terms, this DPA, the configuration the Customer sets for its store, the actions the Customer's administrators take in the store's administration tools, and the connections the Customer makes to its identity provider or HR system. Further instructions are given in writing to the contact in section 14. Jaapi carries them out within the Services, and informs the Customer under section 4.3 where an instruction cannot be carried out within the Services; section 9.3 applies to instructions that go beyond them.
4.3 Jaapi informs the Customer without delay if it considers that an instruction infringes Data Protection Law.
4.4 The Customer is responsible for the lawfulness of the processing it instructs, for the accuracy of the personal data it or its users enter, and for informing its users about the processing. Jaapi publishes its privacy policy on every store to help the Customer meet that obligation, and sends a user nothing when the Customer provisions the account, so the Customer informs its users itself.
4.5 Requests from public authorities. If Jaapi, or a sub-processor to Jaapi's knowledge, receives a legally binding request from a court, a law-enforcement agency or another public authority for the Customer's personal data, Jaapi notifies the Customer promptly unless the law prohibits it, refers the requester to the Customer where possible, uses reasonable efforts to challenge a request it considers unlawful or disproportionate, discloses no more than the request lawfully requires, and keeps a record of the request and of what was disclosed, which it makes available to the Customer on request. Where the law prohibits notifying the Customer, Jaapi uses reasonable efforts to have the prohibition lifted and informs the Customer as soon as it may.
5. Confidentiality
5.1 Jaapi ensures that every person authorized to process the personal data is bound by a confidentiality obligation, under an agreement or a statutory duty, and has acknowledged Jaapi's information security policies.
5.2 Jaapi grants access to the personal data only to the extent necessary for a person to perform their work under the Terms.
6. Security
6.1 Jaapi implements the technical and organizational measures in Annex 1 to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of data subjects, as Article 32 GDPR requires.
6.2 Jaapi's information security management system is certified to ISO/IEC 27001:2022. The certificate is published on the trust center at trust.jaapi.com; Jaapi's policies and the current state of its controls are available to the Customer's administrators on the trust pages of its store.
6.3 Jaapi may update the measures in Annex 1 as long as the level of security does not fall below the level they provide.
7. Sub-processors
7.1 The Customer gives Jaapi general authorization to engage sub-processors for the processing described in section 3. The sub-processors engaged at the date of this DPA are those marked as such in the vendor register at trust.jaapi.com/vendors, with each one's location and the data it holds.
7.2 Jaapi informs the Customer of any intended addition or replacement of a sub-processor at least 30 days before the new sub-processor processes personal data, by the notice to the Customer's administrators that section 14 describes. The Customer may object within that period on reasonable data protection grounds. If the parties cannot resolve the objection within 30 days of its receipt, the Customer may terminate the Services for the affected store, and Jaapi refunds the fees paid in advance for the period after the termination.
7.3 Jaapi imposes on every sub-processor in the vendor register, by a written agreement, data protection obligations that provide the same level of protection as this DPA, and is liable to the Customer for the sub-processor's performance of those obligations as for its own, within section 13.1. Manufacturing suppliers are engaged under section 7.4.
7.4 Manufacturing suppliers. Orders are produced and delivered by a curated network of approved on-demand manufacturing suppliers, each engaged for the orders it produces. The Customer authorizes Jaapi to pass to the supplier producing an order the recipient's name, shipping address, email address and phone number, any customs tax identifier entered for delivery, and the product details of the order, and authorizes the supplier to pass the name, address and contact details to its carrier for delivery. Every supplier is bound by order terms that limit its use of the data to producing and delivering the order. Suppliers whose systems accept orders automatically are additionally under data processing agreements with the obligations of section 7.3; the remaining suppliers are small local producers that take orders manually and are bound by the order terms alone, which impose no other obligation of this DPA on them. The Customer may at any time instruct Jaapi to restrict its store to suppliers under data processing agreements. Supplier identities are commercially confidential; Jaapi discloses the current list, and which suppliers are under data processing agreements, to the Customer on request.
8. International transfers
8.1 Each store has one home region. The Customer's store data is stored and processed in the European Union unless the Customer's agreement or order places its store in the United States. Backups for every store are stored in the European Union. Store data is hosted in its home region; a supplier's shipment notices and reads by Jaapi's support staff may briefly be processed in the other region.
8.2 Where personal data is transferred to a country outside the European Economic Area, the United Kingdom or Switzerland that has not been recognized as providing adequate protection, because the Customer's store is placed in the United States, because a sub-processor in the vendor register is established in such a country, or because an order is produced by a supplier there under a data processing agreement, the transfer is made under the European Commission's standard contractual clauses or an adequacy decision. Where the UK GDPR applies to the data, the transfer is made under the standard contractual clauses with the UK International Data Transfer Addendum issued by the Information Commissioner's Office, or under a UK adequacy regulation; where the FADP applies, the standard contractual clauses apply with the amendments the Swiss Federal Data Protection and Information Commissioner requires. An order produced by a supplier bound by order terms alone is sent to that supplier in the recipient's own country so that it can be delivered; the Customer excludes such suppliers by the restriction in section 7.4.
9. Assistance to the Customer
9.1 Data subject rights. The store's administration tools let the Customer view and correct its users' personal data, export the list of its users, and close a user's account, which reclaims the account's unspent credit to the Customer, so that it can answer most requests from data subjects itself. On the Customer's instruction Jaapi erases the personal data that remains after an account is closed: the account's identity and profile, the recipient details on gifts the person sent, its sessions and any queued email. Three things remain, and the Customer tells the data subject so: the order records section 11.3 retains; the entries in the audit trail of Annex 1, which record the credit and security history of the store and cannot be edited or deleted, so past entries keep the email address they were written with (Article 17(3)(b) and (e) GDPR); and support correspondence, which stays with its ticket until the Customer asks Jaapi to remove it. Jaapi assists with any other request the tools do not cover. If a data subject sends a request about the Customer's store to Jaapi, Jaapi passes it to the Customer without undue delay and does not answer it on the Customer's behalf unless instructed to.
9.2 Security, breaches and impact assessments. Taking into account the nature of the processing and the information available to it, Jaapi assists the Customer in meeting its obligations under Articles 32 to 36 GDPR: the security of processing, the notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments and prior consultation.
9.3 Assistance that goes beyond the tools and the documentation on the trust center, and beyond what a personal data breach requires, may be charged at Jaapi's then-current rates after notice to the Customer.
10. Personal data breach
10.1 Jaapi notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's personal data, by the breach channel section 14 describes, so that the Customer can meet its own obligations under Articles 33 and 34 GDPR.
10.2 The notification describes the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned, whether the data was encrypted, and, where known, the countries or US states the affected data subjects are in; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and the contact for further information. Where not all information is available at once, Jaapi provides it in phases without undue further delay.
10.3 Jaapi documents every personal data breach, its effects and the remedial action taken, and makes that documentation available to the Customer on request.
10.4 Jaapi cooperates with the Customer's own notifications to supervisory authorities and data subjects, and does not notify an authority or a data subject about a breach of the Customer's personal data on the Customer's behalf unless the Customer instructs it to or the law requires Jaapi to do so itself.
11. Deletion and return
11.1 When the Customer's Services end, Jaapi exports the store's data to the Customer in a standard machine-readable format on request made before the data is deleted under section 11.2.
11.2 Jaapi deletes the store's personal data, including its audit trail and support correspondence and except the records section 11.3 retains, within 30 days of the Customer's request and in any case within 90 days of the end of the Services, and confirms the deletion to the Customer. Data deleted from a database remains in encrypted backups until they expire: 30 days for daily backups and 24 months for monthly backups. Backups are restored only to recover the platform, never to bring deleted data back into service.
11.3 Jaapi retains the order records behind an invoice, with the recipient's name and address, for seven years after the end of the financial year, as the Swedish Bookkeeping Act (Bokföringslagen 1999:1078) requires, processes them only for that purpose, and deletes them in the annual purge that follows the end of that period.
12. Demonstrating compliance and audits
12.1 Jaapi makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR: its ISO/IEC 27001:2022 certificate on the trust center, and its security policies, the results of its control verifications, and summaries of its external penetration tests and internal audits to the Customer's administrators on the trust pages of its store.
12.2 Where that information is not sufficient to demonstrate compliance, the Customer, or an independent auditor mandated by the Customer and bound by confidentiality, may audit, including by inspection, Jaapi's processing of the Customer's personal data. An audit is announced at least 30 days in advance, takes place during business hours, is conducted so as not to disrupt the Services or expose other customers' data, and is limited to once in any twelve-month period unless a supervisory authority requires it or a personal data breach affecting the Customer has occurred. The Customer bears the costs of the audit. The sub-processors' own certifications and audit reports demonstrate their compliance; Jaapi does not grant physical access to their facilities.
12.3 Jaapi informs the Customer if, in its opinion, an audit request infringes Data Protection Law.
13. Liability and term
13.1 Each party's liability under this DPA is subject to the limitation of liability in the Terms, at the higher cap the Terms set for a breach of this DPA or of data protection law. The Terms' free-of-charge rule and claim-notice deadline do not apply to obligations under this DPA. A data subject's right to compensation under Article 82 GDPR is unaffected.
13.2 This DPA applies from the Customer's request for an Account, when the Terms are accepted, and remains in force for as long as Jaapi processes personal data on the Customer's behalf.
13.3 Jaapi may amend this DPA as the Terms' section "Changes and Addition" provides: a change that alters a right or an obligation is announced by the notice to the Customer's administrators that section 14 describes, takes effect on the date the notice states, at least 30 days after the notice, and the Customer may terminate before that date with a refund of the fees paid in advance for the period after the termination. A change that reduces the protection this DPA provides additionally gives the Customer the remedy of section 7.2: it may object within the notice period, and if the parties cannot resolve the objection, terminate the Services for the affected store with the same refund.
13.4 This DPA is governed by Swedish law, and disputes are settled as the Terms provide.
14. Contact
Jaapi's data protection contact is Lynn Smeria, Security Officer, lynn@jaapi.store. Jaapi has not appointed a data protection officer, as the conditions of Article 37 GDPR do not apply to it.
Jaapi's notices to the Customer under this DPA go to the Customer's administrators: a notice is shown on the platform to every administrator of each of the Customer's stores, with the change to review, until an administrator of that store acknowledges it, and the acknowledgement is recorded in the store's audit trail. A personal data breach is additionally notified by email to the administrators and to the contact email address set in the store's settings, where one is set. The Customer writes to Jaapi at the data protection contact above.
Annex 1. Technical and organizational measures
The measures below are those Jaapi's ISO/IEC 27001:2022 certified information security management system implements. Each is described in the policy that owns it, and the technical ones are verified every quarter; the policies and the verification results are available to the Customer's administrators on the trust pages of its store.
Encryption in transit. Every connection is encrypted and authenticated: the user's browser to the store, the store to the services it calls, and Jaapi's servers to each other. The stores accept only encrypted connections and refuse protocol versions with known weaknesses.
Encryption at rest. Database backups are encrypted on the server that makes them, before they leave it, with keys held outside the storage facility. The live database volumes are not block-encrypted; each is reachable only from its own server. The platform's secrets are encrypted in the source repository. Every device with access to the platform has full-disk encryption.
Separation. Data is separated per store at the database layer, and a session is bound to one store. Each database is reachable only from its own server. Each store has one home region, as section 8.1 describes.
Access control. Access to the platform and to Jaapi's systems is granted per role on a need-to-know basis, protected by multi-factor authentication where the service offers it, reviewed at least annually, and removed when a person's role ends. Jaapi staff read customer data through the platform's viewers and a read-only query lane; there is no write channel outside the service APIs and an audited mutation lane.
Logging and audit. Requests are logged. Security-relevant actions and every change to a user's credit are written to an audit trail that the application cannot edit or delete, kept for the life of the store; its past entries keep the email address they were written with after an account is erased (section 9.1). A customer's administrators see their own store's audit trail.
Availability and recovery. Each store's database is backed up daily, backups are kept in the European Union, and a restore of the latest backup is tested every week. External monitoring watches every region and alerts the founders.
Secure development and change. Changes go through version control, automated tests and type checking before deployment, with automated review independent of the author where the change warrants it, and every deployment is an explicit, attributed action.
Vulnerability management. Dependencies are audited for published vulnerabilities on every commit, servers receive security updates, and an external party penetration tests the platform every year.
People. Everyone with access acknowledges Jaapi's security policies before they get access and every year after, and attends an annual security briefing.
Incident response. Incidents are handled under a tested incident response plan that sets whom Jaapi notifies and when; every incident is recorded with its root cause and the steps taken.
Vendor management. Every vendor in the sub-processor register is under a data processing agreement covering data location, breach notification, sub-processor disclosure and deletion at the end of the service, and receives only the data its service needs. Manufacturing suppliers are engaged under section 7.4 and receive only the data an order needs.
Annex 2. Sub-processors
The current list of sub-processors, with each one's location and the data it holds, is the vendor register at trust.jaapi.com/vendors. Manufacturing suppliers are engaged under section 7.4 and are not listed there.
Annex 3. US state privacy laws
This Annex applies to personal data in the Customer's store that is subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 and following, the "CCPA"), or to another US state privacy law with equivalent rules for processors (together, "US state privacy law"). "Personal information", "business", "service provider", "processor", "sell", "share", "business purpose" and "consumer" have the meaning the applicable law gives them. For that data, where this Annex and the body of the DPA differ, this Annex applies.
Roles. The Customer is the business or controller and Jaapi is the service provider or processor. Jaapi processes the personal information on the Customer's behalf, for the business purposes in section 3, and within the direct business relationship between the parties.
Restrictions. Jaapi does not sell or share the personal information. Jaapi does not retain, use or disclose it for any purpose other than the business purposes in section 3, for a commercial purpose of its own, or outside the direct business relationship with the Customer. Jaapi does not combine it with personal information it receives from another person or collects from its own interaction with a consumer, except as US state privacy law permits a service provider to do. Jaapi certifies that it understands these restrictions and complies with them.
Compliance. Jaapi complies with the US state privacy law that applies to it and provides the personal information the same level of privacy protection that law requires of a business. Jaapi notifies the Customer within five business days if it determines that it can no longer meet its obligations under this Annex. The Customer may take reasonable and appropriate steps to ensure that Jaapi uses the personal information as this Annex provides, including under section 12, and, on notice, to stop and remediate unauthorized use.
Consumer requests. Jaapi assists the Customer with consumer requests to know, access, correct, delete and limit as section 9.1 provides, and deletes or corrects the personal information the Customer instructs it to, subject to the retention section 11.3 requires. A request a consumer sends to Jaapi about the Customer's store is passed to the Customer under section 9.1.
Sub-processors. Every sub-processor and manufacturing supplier that receives the personal information is bound by a written contract, as section 7 describes, that limits its use of the data to the purpose Jaapi engaged it for, and Jaapi imposes the restrictions of this Annex on the sub-processors in the vendor register.