Data processing addendumData Processing Addendum

Effective date: July 26, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer", "Controller") and JAGODANA LLC, operating Imejis.io ("Imejis", "Processor"). It applies where Imejis processes Personal Data on Customer's behalf. If you require a countersigned copy, contact support@imejis.io.

1 definitions1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings in the GDPR. "Applicable Data Protection Law" means the GDPR, UK GDPR, and applicable US state privacy laws (including the CCPA/CPRA), as relevant to the Processing.

2 roles and scope2. Roles and scope

For Personal Data that Customer submits to the Service, Customer is the Controller and Imejis is the Processor. Imejis may also engage Sub-processors (Section 8). This DPA applies to Processing of Personal Data by Imejis on Customer's behalf.

3 processing instructions3. Processing instructions

Imejis will Process Personal Data only on Customer's documented instructions, including as set out in the Terms and this DPA, unless required by law (in which case Imejis will inform Customer unless legally prohibited). Customer instructs Imejis to Process Personal Data to provide, secure, and support the Service. Customer is responsible for the lawfulness of the Personal Data it submits.

4 confidentiality4. Confidentiality

Imejis ensures that personnel authorized to Process Personal Data are bound by confidentiality obligations.

5 security5. Security

Imejis implements appropriate technical and organizational measures to protect Personal Data, as summarized in our Security overview and Annex II. Measures include encryption in transit, access controls, and OAuth-based authentication.

6 data subject requests6. Data subject requests

Taking into account the nature of the Processing, Imejis will assist Customer, by appropriate technical and organizational measures and insofar as possible, to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Law. If Imejis receives such a request directly, it will forward it to Customer.

7 personal data breaches7. Personal data breaches

Imejis will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.

8 sub processors8. Sub-processors

Customer provides general authorization for Imejis to engage Sub-processors to Process Personal Data. Our current Sub-processors are listed at /sub-processors. Imejis will impose data-protection obligations on Sub-processors substantially similar to those in this DPA and remains responsible for their performance. Imejis will give Customer notice of intended changes to Sub-processors and a reasonable opportunity to object on legitimate data-protection grounds.

9 international transfers9. International transfers

Where Processing involves transfer of Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses (and the UK Addendum, where relevant) are incorporated by reference and apply to such transfers.

10 deletion and return10. Deletion and return

Upon termination of the Service and expiry of any retention required by law, Imejis will delete or return Customer's Personal Data as described in the Privacy Policy, and delete existing copies unless retention is required by law.

11 audits11. Audits

Imejis will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, will allow for audits limited to Customer's Personal Data, conducted in a manner that does not disrupt the Service.

12 us state privacy law12. US state privacy law

To the extent the CCPA/CPRA applies, Imejis acts as a "service provider" and will not sell or share Personal Data, nor retain, use, or disclose it for any purpose other than providing the Service or as permitted by law.

13 liability13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.


Annex i details of processingAnnex I — Details of processing

  • Subject matter: provision of the Imejis Service (design, storage, and rendering of images) to Customer.
  • Duration: the term of the Terms of Service plus any legally required retention.
  • Nature and purpose: hosting, storing, transmitting, and rendering Customer Content, account management, billing, support, and security.
  • Categories of Data Subjects: Customer's authorized users and any individuals whose Personal Data Customer includes in Customer Content.
  • Categories of Personal Data: account and contact data (e.g. name, email), usage and log data, and any Personal Data Customer chooses to submit as Customer Content. Customer should not submit special-category data unless separately agreed.

Annex ii security measuresAnnex II — Security measures

Encryption of data in transit (HTTPS/TLS); access controls and least-privilege administration; OAuth 2.0 authentication with short-lived tokens and revocable API keys; logical isolation of Customer Content; use of reputable cloud providers with their own certifications; monitoring and backups. See /security.

Annex iii sub processorsAnnex III — Sub-processors

As listed and maintained at /sub-processors.