Legal

Data Processing Addendum

Effective date: July 13, 2026

Last updated: July 13, 2026

This Data Processing Addendum ("DPA") supplements the Terms & Conditions between JenFryTalks LLC, a Maryland limited liability company ("Processor") and the organization customer ("Controller") when the Controller uses the Service to process personal data of its members, employees, or athletes ("Data Subjects").

1. Roles

For personal data processed on behalf of the Controller, the Controller is the "controller" and JenFryTalks LLC is the "processor" (or equivalent role) under GDPR, UK GDPR, and CCPA/CPRA. For personal data we process for our own purposes (e.g., billing, product improvement), we act as an independent controller.

2. Subject matter and duration

Subject matter: processing of Data Subject personal data as necessary to provide the Service. Duration: the term of the Controller's subscription plus the retention period in our Data Policy.

3. Nature and purpose of processing

Delivering the assessment, generating scores, producing team/organization reports, storing account and usage data, and providing support.

4. Categories of Data Subjects and personal data

Data Subjects: the Controller's members, employees, or athletes. Personal data: name, email, organization/team, role, assessment responses and scores, usage metadata.

5. Processor obligations

  • Process personal data only on documented instructions from the Controller, including the instructions embodied in the Service.
  • Ensure personnel authorized to process personal data are bound by confidentiality.
  • Implement appropriate technical and organizational measures — see our Security Overview and the summary in Annex II below.
  • Assist the Controller in responding to Data Subject requests and in meeting security, breach-notification, DPIA, and consultation obligations.
  • Notify the Controller without undue delay after becoming aware of a personal-data breach.
  • Delete or return personal data at the end of the engagement, subject to legal retention requirements.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits at the Controller's expense, no more than once per year unless required by regulators.

6. Subprocessors

The Controller provides general authorization for the subprocessors listed at Subprocessors. We will provide at least 30 days' prior notice of new subprocessors and give the Controller a reasonable opportunity to object.

7. International transfers

Where personal data of EU/UK Data Subjects is transferred outside the EEA/UK, the parties incorporate the applicable Standard Contractual Clauses (EU 2021/914) and, for UK transfers, the UK IDTA or Addendum, with JenFryTalks LLC acting as data importer. The Controller acts as data exporter.

8. CCPA

JenFryTalks LLC acts as a "service provider" as defined by the CCPA/CPRA. We will not sell or share personal data, and will not retain, use, or disclose personal data for any purpose other than performing the Service.

9. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms & Conditions.

Annex I — Details of processing

As described in Sections 3–4.

Annex II — Security measures

  • TLS 1.2+ in transit; AES-256 at rest.
  • Role-based access controls; MFA for administrative access.
  • Database row-level security policies scoping access to the correct tenant/user.
  • Automated backups; documented incident response process.
  • Vendor management program covering subprocessors.

Signing this DPA

Organization customers who need a counter-signed DPA can email info@jenfrytalks.com with their legal entity name, address, and signatory.

Contact us

JenFryTalks LLC
Baltimore, Maryland, USA
info@jenfrytalks.com

This document is a plain-English template drafted by the product team. It is not legal advice. Please have qualified counsel review it before relying on it for regulated use (schools, EU/UK customers, enterprise contracts, or disputes).