journima
Home/Legal

Data processing agreement

Part of our terms of service, so it applies to every workspace on every plan without a signature. It sets out how Journima processes personal data on your behalf under the GDPR.

Last updated 19 September 2026

1. Parties and scope

This agreement is between the customer, meaning the organisation whose members use a Journima workspace ("you", the controller), and Journima, Prague, Czech Republic ("Journima", the processor). It forms part of the terms of service and applies from the moment a workspace is created.

It governs the personal data that you and your members put into a workspace, called workspace content in the terms. For the data we hold about you as an account holder, such as your email address and billing details, Journima is the controller and the privacy policy applies instead.

If your procurement process needs a signed copy, print this page and send it to hello@journima.com. We sign the same text; there is no second document.

2. What we process and why

  • Subject matter. Hosting, storing, displaying, exporting and, where you use them, analysing workspace content with AI features, in order to provide the service.
  • Duration. For as long as your workspace exists, plus the backup period in section 7.
  • Nature and purpose. Storage and retrieval; rendering of PDF, PNG and CSV exports; display to the people you share a map with; extraction of candidate insights from transcripts and drafting of maps when a member asks for it; a daily read of the Google Sheets ranges you connect; a daily read of the Jira issues you link, refreshed on request; and creation of an issue in your Jira site when a member asks for it.
  • Types of personal data. Whatever you choose to put in: names, roles, quotes and contact details of the people described in maps, personas and transcripts; the names and email addresses of your members and invitees; comments and audit entries recording who did what.
  • Data subjects. Your members; your customers, users, patients, citizens or employees, insofar as they appear in your content; people you interviewed.
  • Not intended. Journima is not designed for special categories of data under Article 9 GDPR, such as health records, or for data about children. Do not upload them. Pseudonymise transcripts where you can; the research hub works just as well without names.

3. Your instructions

We process workspace content only on your documented instructions. Those instructions are the terms, this agreement and the settings your admins and owners choose in the product: who is a member and in which role, whether AI features are on, which sheets and which Jira site are connected, which share links exist and when they expire. If we believe an instruction breaks the law, we tell you and may pause it.

You are responsible for the lawfulness of the content you upload, for having a legal basis to process the personal data in it, and for informing the people it describes where the law requires it.

4. Our obligations

  • Confidentiality. Everyone who works for us and may see workspace content is bound to confidentiality.
  • Security. We maintain the technical and organisational measures in Annex 2. We may improve them; we will not fall below them.
  • Access. Our staff have no day-to-day access to customer workspaces. A platform administrator can grant access to resolve a support issue, and every such grant is written to the workspace audit log.
  • Assistance. If someone exercises their rights against you, for example asks for access, correction or deletion, we help you answer within the legal deadline. Requests that reach us directly about your content are forwarded to you. We also help, as far as is reasonable, with data protection impact assessments and with a supervisory authority.
  • Breach notice. If we become aware of a personal data breach affecting your workspace content, we tell the workspace owners by email without undue delay, with what we know at the time: what happened, which data is affected, the likely consequences and what we are doing about it. We update you as we learn more.
  • Records. On request we give you the information you need to show that this agreement is met, including our sub-processor list and the security measures below.

5. Sub-processors

We use the sub-processors listed in Annex 1, and you authorise them by accepting this agreement. Each one is bound by a contract with data protection obligations at least as protective as this one, and we remain responsible to you for their work.

Before we add or replace a sub-processor for workspace content, we email workspace owners at least 30 days in advance. If you object on reasonable data protection grounds and we cannot find a solution, you may end this agreement by deleting the workspace, with the export tools available to you first.

6. International transfers

Workspace content is stored and processed in the European Union. It leaves the EU only in two cases: an AI feature sends the text a member submits to Anthropic in the United States, and a Jira connection sends requests to your own Jira site, wherever Atlassian hosts it. Those Jira requests carry what a member types when searching for an issue, the identifiers of the issues you link, and the title and description of a portfolio item when a member creates an issue from it. Where a sub-processor outside the EU processes data, the transfer relies on the European Commission's standard contractual clauses and, where the provider is certified under it, on the EU-U.S. Data Privacy Framework.

7. Return and deletion

You can export maps as PDF or PNG and the portfolio as CSV at any time, and ask us for a full workspace export in open formats. When an owner deletes a workspace, or this agreement ends, its records are deleted immediately, stored files such as images and rendered exports are cleared afterwards, and copies age out of encrypted backups within six months at the latest. We keep only what the law obliges us to keep, such as invoices.

8. Audits

On request we give you the information needed to verify that we meet this agreement: the trust center, the annexes below and answers to your security questionnaire. If that is not enough, you or an independent auditor bound to confidentiality may audit us once in any twelve months, with 30 days' notice, during working hours, at your cost, and without access to other customers' data. Where a supervisory authority requires more, we cooperate.

9. Term, liability and law

This agreement lasts as long as the terms of service apply to your workspace. Liability and governing law follow the terms. Where this agreement and the terms conflict on data protection, this agreement wins.

Annex 1: Sub-processors

ProviderWhereWhat it processes for you
Hetzner Online GmbHGermany and FinlandAll workspace content: servers, database, object storage for images and exports, backups
Anthropic, PBCUnited StatesThe text a member submits to an AI feature; not used for training
Resend, Inc.United StatesNames and email addresses of members and invitees, for transactional email
Google Ireland LimitedIrelandThe Sheets ranges you connect, and the identity of members who sign in with Google
Atlassian Pty LtdWherever your Jira Cloud site is hostedThe title and description of an issue you create from a portfolio item, and the requests that search Jira and read the issues you link; only when an admin connects Jira
Netlify, Inc.United StatesServes the product's front end; sees members' IP addresses in server logs; holds no workspace content
Functional Software, Inc. (Sentry)United StatesError reports with the failing request's path; cookies stripped, no user identifier

Providers we use only for our own account, billing and website data, such as Stripe and Cloudflare, are listed in the privacy policy.

Annex 2: Technical and organisational measures

  • Hosting. Application, database and object storage on Hetzner in Germany and Finland, inside the European Union. No tracking scripts in the product.
  • Encryption. TLS 1.2 or higher for all traffic. Database volumes and backups encrypted at rest. Passwords and share-link secrets stored as hashes, never in clear text.
  • Access control. Workspaces are invite-only, with four roles: viewer, editor, admin, owner. Sessions rest on a secure, HTTP-only cookie scoped to the API and limited to 30 days. Staff access is by audited grant only.
  • Logging. A per-workspace audit log of significant actions, with an extract available on request.
  • Backups and recovery. Nightly database dumps, kept seven daily, four weekly and six monthly, with an encrypted copy written to object storage every night. Version snapshots inside the product, the last 50 per map, restorable by you.
  • AI features. Content goes to Anthropic only when a member triggers a generation; it is not used to train models; admins can switch AI features off per workspace and we can switch them off globally.
  • Monitoring. Error monitoring strips cookies from every report and attaches no user identifier.
  • People. A small team, each bound to confidentiality, with no standing access to customer data.

Contact

Journima, Prague, Czech Republic. hello@journima.com. See also the imprint.