Data Processing Agreement
Version 2026-06-30 · Effective 2026-06-30
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between JobMistr s.r.o. ("JobMistr", the "Processor") and the customer accepting the Terms (the "Customer", the "Controller"). It applies whenever the Customer uses the JobMistr service (the "Service") to process personal data of the Customer's own data subjects ("Customer Personal Data"), and implements Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). It is accepted together with the Terms when the account is created; no signature is required, and a countersigned copy is available on request to legal@jobmistr.com.
1. Roles
For Customer Personal Data, the Customer is the controller and JobMistr is the processor. (For personal data of the Customer themselves — account, billing, and usage data — JobMistr is the controller; see the Privacy Policy.)
2. Subject matter, duration, nature and purpose
- Subject matter and nature — hosting, storage, display, transmission, organisation, backup, export, and deletion of Customer Personal Data as part of operating the Service (business management, invoicing, quotes, contracts, calendar and bookings, messaging, accounting and tax outputs, marketplace features).
- Purpose — providing the Service to the Customer under the Terms. JobMistr does not process Customer Personal Data for its own purposes.
- Duration — the term of the Terms, plus the deletion and recovery windows described in section 10.
3. Categories of data subjects and personal data
- Data subjects — the Customer's clients and prospective clients, their contact persons, suppliers, team members and staff, and other persons whose data the Customer enters into the Service.
- Categories of data — identification and contact data (names, emails, phone numbers, addresses), business identifiers (IČO, DIČ), billing and payment metadata, documents and their contents (invoices, quotes, contracts), signature images and signing metadata, calendar and booking data, message content, photographs, notes, and location data related to jobs.
- Special categories (Art. 9) — the Service is not designed for special-category data and the Customer agrees not to submit it (see Terms, section 4).
4. Processor obligations
JobMistr shall:
- process Customer Personal Data only on the Customer's documented instructions (the Terms, this DPA, and the Customer's use of the Service's controls constitute those instructions), including with regard to transfers to third countries, unless required to do otherwise by EU or member-state law — in which case JobMistr will inform the Customer of that legal requirement before processing, unless the law prohibits it;
- inform the Customer immediately if, in its opinion, an instruction infringes the GDPR or other data-protection law;
- ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations;
- implement the technical and organisational measures described in section 5;
- assist the Customer, taking into account the nature of the processing, in responding to data-subject requests (section 7) and in complying with Articles 32 to 36 GDPR (security, breach notification, data-protection impact assessments);
- delete or return Customer Personal Data at the end of the provision of services (section 10); and
- make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits (section 11).
5. Security (technical and organisational measures)
JobMistr implements the measures described on the Security page, which forms the annex of technical and organisational measures to this DPA. They include encryption in transit (TLS 1.3), field-level AES-256-GCM encryption at rest for sensitive personal data, role-based access control with tenant isolation, audit logging of sensitive operations, and tested backup and recovery procedures. The measures may be updated over time provided the overall level of protection is not reduced.
6. Sub-processors
The Customer grants JobMistr general written authorisation to engage sub-processors. The current list is published in section 4 of the Privacy Policy. JobMistr will announce material changes (additions or replacements) by email to workspace owners at least thirty (30) days before they take effect; the Customer may object on reasonable data-protection grounds before that period elapses, and if no solution is found may terminate the affected services. JobMistr imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains fully liable to the Customer for the performance of each sub-processor's obligations.
7. Data-subject requests
JobMistr will forward to the Customer without undue delay any request from a data subject of the Customer received directly by JobMistr, and will not respond on the merits except on the Customer's instruction. The Service's built-in tools (search, edit, export, delete) enable the Customer to handle access, rectification, erasure, and portability requests self-service.
8. Personal-data breaches
JobMistr will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide the information reasonably required by Article 33(3) GDPR as it becomes available, so the Customer can meet its own notification obligations.
9. International transfers
Customer Personal Data is hosted in the EU. Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V GDPR, as described in the Privacy Policy.
10. Deletion and return
The Customer may export Customer Personal Data at any time (Settings → Data & export). Upon termination of the Terms or deletion of the workspace, Customer Personal Data is retained for thirty (30) days for recovery and then deleted from active systems; backups roll off within a further thirty (30) days. Records subject to statutory retention (for example, accounting records under Czech law) are retained for the statutory period only. Upon request, JobMistr will confirm deletion in writing.
11. Audit and information rights
JobMistr will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party certifications and reports of its sub-processors. The Customer may conduct an audit (itself or through an independent auditor bound by confidentiality) no more than once per twelve (12) months, on at least thirty (30) days' written notice, during business hours, without disrupting operations, and at the Customer's own cost. Where an audit would reveal other customers' data, JobMistr may instead provide equivalent evidence.
12. Liability
The liability of each party under this DPA is subject to the exclusions and limitations of liability in the Terms. Nothing in this DPA limits either party's liability to data subjects under Article 82 GDPR.
13. Final provisions
This DPA is governed by the laws of the Czech Republic. It is published in Czech and English; in case of conflict the Czech version prevails. In case of conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails. Changes to this DPA follow the change procedure in the Terms.
14. Contact
JobMistr s.r.o.
Korunní 2569/108, Vinohrady, 101 00 Praha 10
Company ID (IČO): 29698774
Czech Republic
Data processing enquiries: privacy@jobmistr.com