This Data Processing Agreement (the “DPA”) is between Johco LLC (“Johco”) and the customer identified in the applicable order form, subscription record, or other agreement for the Services (“Customer”). The Customer’s legal name, address, and notice contact may be supplied in that order form or agreement. This DPA supplements the agreement governing Customer’s use of the Services (the “Main Agreement”).
1. Definitions
- Applicable Data Protection Law
- Any privacy or data-protection law that applies to Johco’s processing of Customer Personal Data under the Main Agreement.
- Customer Data
- Data submitted to or generated for Customer through the Services. Customer Data includes Customer Personal Data.
- Customer Personal Data
- Personal data, personal information, or a comparable regulated category contained in Customer Data that Johco processes on Customer’s behalf.
- Security Incident
- A confirmed breach of Johco-managed security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Unsuccessful attempts, scans, and events that do not compromise Customer Personal Data are not Security Incidents.
- Services
- The Johco Excel add-in, application, APIs, account services, and related support identified in the Main Agreement.
- Subprocessor
- A third party engaged by Johco to process Customer Personal Data on Johco’s behalf in providing the Services.
“Controller,” “processor,” “business,” “service provider,” “contractor,” “personal data,” “personal information,” “processing,” and “data subject” have the meanings assigned by the Applicable Data Protection Law.
2. Scope and roles
2.1. This DPA applies only to Johco’s processing of Customer Personal Data on Customer’s behalf in connection with the Services. It does not govern data for which Johco independently determines the purposes and means of processing, which is addressed by Johco’s Privacy Policy.
2.2. Customer is the controller and Johco is the processor of Customer Personal Data. If Customer is itself a processor for another controller, Johco acts as Customer’s subprocessor. Each party will comply with the obligations that Applicable Data Protection Law assigns to its role.
2.3. The subject matter, duration, nature, purposes, data types, and data-subject categories for the processing are described in Appendix A and may be narrowed in an Order Form. Customer retains control over the Customer Data it submits and the product settings it selects.
3. Instructions and use limits
3.1. Johco will process Customer Personal Data only to provide, secure, maintain, and support the Services in accordance with the Main Agreement, this DPA, Customer’s documented use of product controls, and other documented instructions that Johco agrees to follow. Johco will inform Customer if it reasonably believes an instruction violates Applicable Data Protection Law, unless the law prohibits notice.
3.2. If law requires Johco to process Customer Personal Data contrary to Customer’s instructions, Johco will notify Customer before doing so unless the law prohibits notice.
3.3. AI-assisted language parsing is optional. Johco will send request content to an AI model provider only when the relevant provider is enabled for the Services and Customer or an authorized user selects an AI-assisted route. In local-only mode, Johco will not send workbook, project, or request content to an AI model provider. Local-only mode does not disable separate account, identity, billing, consent-management, security, or support processing.
3.4. Johco will not authorize an AI provider to use Customer Personal Data to train the provider’s generally available models unless Customer gives separate written instructions for that use. Johco will not use Customer Personal Data to develop a generally available Johco model unless Customer separately agrees in writing.
4. Customer responsibilities
4.1. Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing all required notices, obtaining all required permissions, and issuing lawful instructions to Johco.
4.2. Customer will limit access to authorized users, protect its credentials, configure the Services appropriately, and not submit regulated sensitive data unless the Main Agreement or an Order Form expressly permits that data and the parties have agreed on appropriate safeguards. The Services are not represented in this draft as designed for protected health information, payment-card data entered into prompts, government identifiers, biometric identifiers, or other specially regulated data.
4.3. Customer will use reasonable efforts to avoid including personal data in free-form prompts, workbooks, uploads, or support materials when that data is not needed for the requested output.
5. U.S. privacy-law terms
To the extent an Applicable Data Protection Law treats Johco as a service provider, contractor, or processor, Johco will:
- process Customer Personal Data only for the limited and specified business purposes in Appendix A and the Main Agreement;
- not sell or share Customer Personal Data, as those terms are defined by the applicable law;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than those specified, except as permitted by law;
- not combine Customer Personal Data with personal information received from another person or collected through Johco’s independent interaction with a data subject, except as permitted by law;
- provide the same level of privacy protection required of a service provider, contractor, or processor under the applicable law;
- notify Customer if Johco determines it can no longer meet these obligations; and
- permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized processing, subject to the safeguards in Section 12.
6. Confidentiality
Johco will restrict access to Customer Personal Data to personnel and contractors who need access to perform the Services. Johco will require those persons to protect the data under confidentiality obligations that continue after their engagement ends.
7. Security
7.1. Taking account of the nature of the processing, available technology, implementation cost, and risks to individuals, Johco will maintain reasonable technical and organizational measures designed to protect the confidentiality, integrity, and availability of Customer Personal Data. The current measures are described in Appendix B.
7.2. Johco may update those measures as technology and the Services change, provided an update does not materially reduce the overall protection of Customer Personal Data during the subscription term.
7.3. Customer acknowledges that no network, system, or storage method is guaranteed to be completely secure. This statement does not reduce Johco’s obligations under this DPA.
8. Data-subject and compliance assistance
8.1. Taking account of the nature of the processing, Johco will provide reasonable assistance through product controls or other reasonable means so Customer can respond to requests to access, correct, delete, restrict, port, or object to processing of Customer Personal Data.
8.2. If Johco receives a request directly from a data subject concerning Customer Personal Data, Johco may direct the person to Customer and will not independently respond except as Customer instructs or law requires.
8.3. On reasonable request, Johco will provide information available to it that Customer reasonably needs for a data-protection impact assessment, regulator consultation, processing record, or security review relating specifically to the Services. Customer remains responsible for its own compliance decisions.
9. Security incidents
9.1. Johco will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notification will be sent to Customer’s administrator or designated security contact.
9.2. As information becomes reasonably available, Johco will describe the nature of the incident, affected data and data subjects, likely consequences, mitigation or remediation taken or planned, and a contact for follow-up. Johco may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the incident.
9.3. Johco’s notice or response is not an admission of fault or liability. Customer is responsible for notices it is legally required to give to individuals, regulators, or others, and Johco will provide reasonable assistance based on the nature of the processing and information available to Johco.
10. Subprocessors
10.1. Customer gives Johco general authorization to use the Subprocessors identified on the Johco Subprocessor List, but only when the applicable provider is enabled and processes Customer Personal Data for the Services. Identity and payment providers may act in different legal roles for different activities; listing a vendor does not by itself determine that vendor’s legal role.
10.2. Before a Subprocessor handles Customer Personal Data, Johco will conduct a proportionate review and enter a written agreement requiring data-protection and security obligations appropriate to the service. Johco remains responsible for the Subprocessor’s performance of the obligations Johco delegates to it, subject to the Main Agreement’s liability terms and Applicable Data Protection Law.
10.3. Johco will update the Subprocessor List and, for active customers, send notice to the current account administrator or designated DPA-notice address before a new Subprocessor receives Customer Personal Data when reasonably practicable. A customer may subscribe or update its notice address by emailing admin@johco.store. Urgent replacements needed for security, legal, or service-continuity reasons may be announced as soon as reasonably practicable.
10.4. Customer may object on reasonable, documented data-protection grounds by emailing admin@johco.store within 15 days after notice. The parties will work in good faith to address the concern. If no reasonable alternative is available, Customer may stop using the affected feature or exercise any termination right provided by the Main Agreement.
11. Return and deletion
11.1. During the subscription term, available account controls and exports will be the primary means for Customer to retrieve or delete Customer Data.
11.2. At termination or on Customer’s documented request, Johco will delete or return Customer Personal Data within a reasonable period, unless continued retention is required by law or permitted by the Main Agreement for security, fraud prevention, dispute resolution, or legal claims. Data in backups may remain until overwritten through the ordinary backup cycle; while retained, it will remain protected and will not be restored except for recovery, security, or legal purposes.
12. Information, reviews, and assessments
12.1. On reasonable written request and subject to confidentiality restrictions, Johco will provide information reasonably necessary to demonstrate its compliance with this DPA, such as a security-measures summary, relevant policies, or responses to a proportionate questionnaire. Johco does not represent that it presently holds a particular security certification or independent audit report.
12.2. If the information in Section 12.1 is not reasonably sufficient, Customer may request an assessment by Customer or an independent auditor. Unless a Security Incident, regulator, or Applicable Data Protection Law requires otherwise, an assessment will occur no more than once in a 12-month period, on reasonable advance notice, during normal business hours, and without disrupting the Services.
12.3. An assessment must protect Johco’s confidential information, other customers’ data, and system security. It may not include penetration testing, access to source code, or access to another customer’s environment without Johco’s prior written approval. Customer bears its assessment costs, and Johco may charge reasonable costs for assistance that is unusually burdensome, unless Applicable Data Protection Law prohibits the charge.
13. International transfers
13.1. Johco will not make a restricted international transfer of Customer Personal Data unless a lawful transfer mechanism or exception applies. Processing locations may depend on the enabled provider and Customer configuration and are described at the level currently known on the Subprocessor List.
13.2. If Applicable Data Protection Law requires standard contractual clauses, a United Kingdom addendum, a transfer impact assessment, or another transfer instrument, the parties will complete and enter the applicable instrument before relying on it. This draft does not by itself state that any particular international-transfer mechanism has been executed.
14. Government and legal requests
If Johco receives a binding request from a public authority for Customer Personal Data, Johco will review the request, disclose only what it reasonably determines is legally required, and notify Customer before disclosure unless prohibited by law. Where appropriate and lawful, Johco will direct the requesting authority to Customer or challenge an overbroad request.
15. Term and changes
This DPA begins on the date it is validly accepted or signed and remains in effect while Johco processes Customer Personal Data under the Main Agreement. Processing and protection obligations that by their nature continue after termination will survive. Any material amendment to an effective DPA will follow the amendment process in the Main Agreement or require the parties’ agreement; an updated online draft alone does not amend an executed DPA.
16. Precedence and liability
16.1. If this DPA conflicts with the Main Agreement about the processing of Customer Personal Data, this DPA controls. A valid transfer addendum or mandatory contractual clause controls over this DPA to the extent of a conflict concerning the regulated transfer.
16.2. Each party’s liability arising from this DPA is subject to the exclusions and limitations of liability in the Main Agreement, except to the extent Applicable Data Protection Law or an executed mandatory transfer instrument prohibits that limitation.
17. Acceptance, signatures, and notices
17.1. Once Johco marks this DPA effective, the parties may execute it in counterparts, by electronic signature, or by an electronic acceptance process that identifies the accepting person, organization, document version, and date. An electronic copy will be treated as an original to the extent permitted by law.
17.2. A person accepting for an organization represents that the person has authority to bind that organization. The applicable Order Form or Main Agreement will identify Customer and the effective date.
17.3. Notices to Johco under this DPA must be sent to admin@johco.store. Notices to Customer will be sent to the account administrator or other contact identified in the Main Agreement.
Appendix A — Processing details
- Processor
- Johco LLC. Contact: admin@johco.store.
- Customer
- The entity identified in the applicable Order Form, subscription record, or Main Agreement.
- Subject matter
- Provision of the Johco Excel add-in, application, APIs, account services, optional language-parsing routes, and related support purchased or enabled by Customer.
- Duration and frequency
- As initiated by authorized users during the Main Agreement, plus limited retention for backups, security, support, legal obligations, and orderly deletion as described in Section 11.
- Nature of processing
- Receiving, transmitting, structuring, validating, calculating, retrieving, storing, displaying, exporting, securing, supporting, and deleting data as needed to provide the enabled Services.
- Specified purposes
- Authenticate users; administer accounts and entitlements; parse natural-language requests through the route selected by Customer; execute deterministic financial, absorption, comparison, mapping, feasibility, and related calculations; return spreadsheet or application outputs; maintain security and reliability; provide support; meter authorized usage; administer billing; and record consent preferences.
- Data subjects
- Customer’s authorized users, employees, contractors, clients, prospects, and other persons whose information Customer elects to include in workbooks, prompts, project files, support requests, property information, or transaction records.
- Personal-data categories
- Account and contact identifiers; organization and professional information; identity-provider subject identifiers; authentication, entitlement, and usage metadata; prompts and instructions; workbook, project, property, and transaction information that identifies or relates to a person; support communications; consent preferences; and billing status or payment tokens received from a payment provider. Johco should not receive complete payment-card credentials through the Services.
- Sensitive data
- Not intended under the standard Services. Customer must not submit specially regulated or sensitive data unless an Order Form expressly permits it and documents additional safeguards.
- Customer instructions
- The Main Agreement, this DPA, enabled product settings, authorized-user actions, and additional documented instructions accepted by Johco.
- Deletion
- Through available account controls and the process in Section 11, subject to legal retention and ordinary backup expiration.
Appendix B — Technical and organizational measures
The following measures describe the planned launch controls for Johco-managed systems. They are not a certification and must be verified against the production environment before this DPA is made effective.
Access and authentication
- Access to production data and administrative systems is limited according to role, operational need, and least-privilege principles.
- API credentials and application session identifiers are generated with appropriate randomness and stored as non-reversible hashes rather than plaintext where Johco controls storage.
- Administrative access is reviewed and removed when no longer required.
Transmission and separation
- Customer communications with production web and API endpoints use current, supported TLS configurations.
- Connections from Johco to configured model, identity, payment, and consent vendors use encrypted HTTPS/TLS transport.
- Authorization checks and account identifiers are used to prevent one customer from retrieving another customer’s data through ordinary product interfaces.
Data minimization and logging
- Service requests send a configured vendor only the fields reasonably needed for the selected function.
- Operational logs are designed to favor request metadata, status, timing, and error categories over prompt, workbook, project, credential, or payment content.
- Secrets and bearer credentials are excluded or redacted from routine logs where Johco controls the logging path.
- Local-only language parsing does not transmit workbook, project, or request content to an AI model provider.
Resilience and change control
- Backups appropriate to the production data store and recovery needs are maintained and access-restricted; restoration is limited to recovery, security, and legal needs.
- Material production changes are reviewed and tested in proportion to risk before release, with rollback or recovery procedures appropriate to the change.
- Dependencies and reported vulnerabilities are assessed and remediated according to severity and operational risk.
Incident handling and personnel
- Johco maintains a process to identify, triage, contain, investigate, document, and remediate suspected security events.
- Personnel with access to Customer Personal Data are subject to confidentiality obligations and receive security guidance appropriate to their responsibilities.
- Johco maintains current operational and security contacts and communicates confirmed Security Incidents as described in Section 9.
Signature page
For use only after legal review and when this DPA is marked effective. Electronic acceptance may replace these signature blocks as described in Section 17.