JourneyWise Data Processing Addendum

Incorporated by reference into the JourneyWise Commercial Terms of Service

Last Updated: [August 4, 2026]

This Data Processing Addendum (“DPA”) is incorporated into and forms part of the JourneyWise Commercial Terms of Service or other agreement between Customer and JourneyWise that references this DPA and governs Customer's use of the Services (the “Agreement”), and applies to JourneyWise's processing of Customer Data (defined below). Capitalised terms used but not otherwise defined in this DPA have the meaning set out in the Agreement. JourneyWise may amend this DPA from time to time on reasonable notice to Customer to the extent required by changes in Applicable Data Protection Laws. If there is a conflict between this DPA and the Agreement, this DPA governs.

A. Definitions

  1. A.1. “Applicable Data Protection Laws” means all applicable privacy or data protection laws and regulations relating to the processing of personal data, including UK GDPR and, where applicable, the GDPR, as amended from time to time.
  2. A.2. “Customer Personal Data” means personal data submitted through the Services by or for Customer or a Customer Affiliate, including contact records, call recordings and transcripts, and email or calendar content synced through the Services.
  3. A.3. “Customer Affiliate” means an affiliate of Customer that (a) is permitted to use the Services under the Agreement, and (b) directly or indirectly controls, is controlled by, or is under common control with Customer, meaning ownership or control of more than 50% of voting interests.
  4. A.4. “Customer Data” means all data or other information submitted through the Services by or for Customer or a Customer Affiliate.
  5. A.5. “Data Subject Request” means a request from a data subject to exercise rights under Applicable Data Protection Laws, such as rights to access, correct, or delete their personal data.
  6. A.6. “GDPR” means Regulation (EU) 2016/679.
  7. A.7. “UK GDPR” means the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended.
  8. A.8. “Security Breach” means a breach of JourneyWise's security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Customer Personal Data.
  9. A.9. “Standard Contractual Clauses” or “SCCs” means Module Two (controller to processor) or Module Three (processor to processor) of the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  10. A.10. “Subprocessor” means an entity engaged by JourneyWise to process Customer Personal Data.
  11. A.11. “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018.
  12. A.12. The terms “personal data”, “data subject”, “processing”, “controller”, and “processor” have the meanings given by Applicable Data Protection Laws or, absent any such meaning, by the UK GDPR.
  13. A.13. The terms “controller” and “processor” include “business” and “service provider” respectively, where required by Applicable Data Protection Laws.

B. Processing of Customer Data

  1. B.1. With respect to Customer Personal Data, Customer is the controller and JourneyWise is Customer's processor. Each party will comply with its respective obligations under Applicable Data Protection Laws.
  2. B.2. Unless required by applicable law, JourneyWise will only process Customer Personal Data to provide or maintain the Services, and in compliance with Customer's documented instructions, including as set out in the Agreement and this DPA.
  3. B.3. JourneyWise may use artificial intelligence and machine learning technologies provided by approved Subprocessors solely to provide the Services requested by Customer, including generating summaries, conversation intelligence, lead insights, recommendations, and other AI-powered functionality made available through the Services. JourneyWise will ensure that any Customer Personal Data processed by such providers is processed only for the purpose of providing the Services to Customer and in accordance with this DPA. JourneyWise will not permit Customer Personal Data to be used to train publicly available foundation models or artificial intelligence systems unless Customer has expressly instructed or authorised such use.
  4. B.4. Without limiting the foregoing, JourneyWise will not:
    • sell or share Customer Personal Data, as defined by Applicable Data Protection Laws;
    • retain, use, or disclose Customer Personal Data outside of the direct business relationship and for any purpose other than the business purposes specified in Part B of Schedule 1, or as otherwise permitted by Applicable Data Protection Laws; and
    • except as otherwise permitted by Applicable Data Protection Laws, combine Customer Personal Data with personal data JourneyWise receives from or on behalf of another person, or collects from its own interaction with the data subject.
  5. B.5. JourneyWise will promptly inform Customer if it determines it can no longer comply with its processing obligations under this DPA, in which case Customer may take reasonable steps under the Agreement to stop or remediate any unauthorised processing.
  6. B.6. JourneyWise will promptly inform Customer if, in its opinion, an instruction from Customer relating to the processing of Customer Personal Data violates Applicable Data Protection Law.
  7. B.7. JourneyWise will cooperate with and provide reasonable assistance to Customer for (a) Customer's performance of any data protection impact assessment relating to JourneyWise's processing, and (b) related consultation with supervisory authorities, where Customer reasonably considers this required by Applicable Data Protection Laws.
  8. B.8. JourneyWise will ensure each person it authorises to process Customer Personal Data is subject to an appropriate duty of confidentiality.

C. Subprocessors

  1. C.1. Customer grants JourneyWise general authorisation to engage the Subprocessors listed in Schedule 4, and any additional Subprocessors in accordance with Section C.3.
  2. C.2. JourneyWise will (a) enter into a contractual agreement with each Subprocessor imposing data protection obligations substantially as protective as JourneyWise's obligations under this DPA, to the extent applicable to the nature of the services provided, and (b) remain liable to Customer for each Subprocessor's acts and omissions related to this DPA to the extent JourneyWise is liable for its own, consistent with the limitation of liability in the Agreement.
  3. C.3. If JourneyWise wishes to appoint an additional Subprocessor: (a) JourneyWise will give Customer reasonable notice before granting the Subprocessor access to Customer Personal Data; and (b) Customer may object, on reasonable data privacy or security grounds, by written notice within 15 days of that notice, or is deemed to consent. If Customer objects, the parties will work together in good faith to find a mutually acceptable resolution.

D. Data Subject Requests

  1. D.1. JourneyWise will forward to Customer promptly any Data Subject Request it receives relating to Customer Personal Data, and may advise the data subject to submit their request directly to Customer.
  2. D.2. JourneyWise will, taking into account the nature of the processing, provide Customer with reasonable and timely assistance to fulfil its obligations under Applicable Data Protection Laws to respond to Data Subject Requests.

E. Security

  1. E.1. JourneyWise will comply with the data security obligations of Applicable Data Protection Laws, and will implement and maintain reasonable and appropriate technical and organisational measures designed to protect Customer Data appropriate to the risk of the processing, as summarised in Schedule 2. JourneyWise may update these measures over time, provided any update does not materially reduce the overall security of the Services.
  2. E.2. The parties agree that the measures in Schedule 2 provide an appropriate level of security for the Customer Data, accounting for the risks presented by the processing described in the Agreement and this DPA.
  3. E.3. JourneyWise maintains commercially reasonable business continuity and disaster recovery procedures designed to minimise disruption to the Services and restore the availability of Customer Data following a service interruption or other operational incident. Such procedures may be reviewed and updated periodically to reflect changes in JourneyWise's infrastructure and operational requirements.

F. Compliance and Audits

  1. F.1. Upon Customer's written request, and subject to the confidentiality obligations in the Agreement, JourneyWise will provide Customer with reasonably available information necessary to demonstrate compliance with this DPA.
  2. F.2. Upon Customer's written request, JourneyWise will permit Customer, at Customer's expense, to audit JourneyWise's applicable controls and compliance with this DPA (an “Audit”), provided the Audit is (a) conducted by Customer or a third-party auditor that has signed an appropriate confidentiality agreement with JourneyWise, (b) subject to mutually agreed scope, timing, and confidentiality controls, and (c) not conducted less than 12 months after a prior similar Audit, unless there are indications of non-compliance or it is required by a supervisory authority.
  3. F.3. Customer will pay any reasonably incurred costs of an Audit that is not (a) required by Applicable Data Protection Laws or (b) in response to a Security Breach.
  4. F.4. Customer may use the results of an Audit only to meet its own regulatory audit requirements or to confirm compliance with this DPA.

G. Security Breaches

  1. G.1. JourneyWise will notify Customer in writing without undue delay, and in any event within forty-eight (48) hours after confirming a Security Breach involving Customer Personal Data, and will reasonably cooperate with Customer's investigation. Notification of, or response to, a Security Breach does not constitute an admission of fault or liability by JourneyWise.
  2. G.2. Upon becoming aware of a Security Breach, JourneyWise will (a) investigate it, and (b) provide timely information on its nature, including, where reasonably possible, the categories and approximate number of data subjects and Customer Personal Data records concerned, the likely consequences, and the measures taken or proposed to address it, including mitigation of adverse effects.

H. Deletion and Return

  1. H.1. Within 30 days of termination or expiration of the Agreement, JourneyWise will:
    • if requested by Customer within that period, return a copy of all Customer Data in its control or possession, or provide self-service export functionality allowing Customer to do the same; and
    • delete all copies of Customer Data (including Customer Personal Data) processed by JourneyWise or any Subprocessor, except to the extent (i) Applicable Data Protection Laws or other legal or regulatory requirements require retention, (ii) retention is necessary to resolve a dispute between the parties, or (iii) retention is necessary to combat harmful use of the Services.
  2. H.2. Notwithstanding Section H.1, Customer Data contained within encrypted backup systems may remain until such backups are overwritten or securely deleted in accordance with JourneyWise's standard backup retention and disaster recovery procedures. During any such retention period, JourneyWise will continue to protect Customer Data in accordance with this DPA and will not restore or otherwise process such backup data except where required for disaster recovery, legal compliance, or system integrity.

I. International Data Transfers

  1. I.1. JourneyWise is established in the United Kingdom. Where Customer Personal Data is transferred from the EEA or Switzerland to JourneyWise, or onward from JourneyWise to a Subprocessor located outside the UK, EEA, or Switzerland, the parties agree that, to the extent required by Applicable Data Protection Laws, the SCCs (Module Two and/or Module Three, as completed in Schedule 3) and/or the UK Addendum are incorporated by reference and deemed executed by the parties.
  2. I.2. Customer Personal Data is hosted using JourneyWise's cloud infrastructure in the region selected by JourneyWise for the provision of the Services. Customer Personal Data may be processed in other jurisdictions where reasonably necessary to provide, maintain, secure, or support the Services, provided that any such processing is carried out in accordance with Applicable Data Protection Laws and the safeguards described in this DPA.
  3. I.3. To the extent there is a conflict between this DPA, the Agreement, and the SCCs, the order of precedence is: (i) the SCCs; (ii) this DPA; (iii) the Agreement.
  4. I.4. JourneyWise will provide Customer reasonable support to enable compliance with requirements imposed on international transfers of Customer Personal Data, including information reasonably necessary for Customer to complete a transfer impact assessment.
Schedule 1 — Details of Processing and Transfers

A. List of Parties

  1. A.1. Data Exporter: Customer and/or Customer Affiliates exporting Customer Personal Data to which the GDPR or UK GDPR applies. Contact details as included in the Agreement or provided to JourneyWise on request.
  2. A.2. Data Importer: JourneyWise Ltd, 2nd Floor, College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom. Contact details as included in the Agreement or provided to Customer on request. Security and privacy enquiries may be directed to privacy@journeywise.io (or such other address as JourneyWise may notify to Customer from time to time).

B. Description of Processing

  1. B.1. Categories of data subjects: determined by Customer, typically Customer's business contacts, prospects, and customers, and Customer's own personnel using the Services.
  2. B.2. Categories of personal data: determined by Customer, typically business contact details, call recordings and transcripts, email and calendar content, and CRM pipeline data.
  3. B.3. JourneyWise uses AI service providers solely to provide features requested by Customer, including call summaries, meeting summaries, conversation intelligence, lead scoring assistance and other AI-powered functionality. JourneyWise does not permit Customer Personal Data to be used by AI providers to train publicly available foundation models except where Customer has explicitly agreed or applicable provider settings permit Customer opt-in.
  4. B.4. Special categories of personal data: none anticipated. Customer must not submit special category data to the Services.
  5. B.5. Duration and frequency of processing: continuous for the duration of the Agreement, as determined by Customer's configuration of the Services.
  6. B.6. Where JourneyWise is required by applicable law, regulation, court order, or other legally binding governmental request to disclose Customer Personal Data, JourneyWise will, unless legally prohibited from doing so, notify Customer before making such disclosure and will disclose only the minimum amount of Customer Personal Data required to comply with the applicable legal obligation.
  7. B.7. Subject matter and nature of processing: providing the Services to Customer, being a revenue execution platform combining a CRM, dialer, and conversation intelligence features, which involves collecting, storing, organising, and analysing personal data submitted by or synced through Customer's use of the Services; verifying or maintaining the quality, security, and integrity of the Services; and debugging to identify and repair errors.
  8. B.8. Purpose(s) of transfer and further processing: to provide the Services to Customer under the Agreement, and as otherwise agreed between the parties.
  9. B.9. Storage limitation: for the term of the Agreement, subject to Section H (Deletion and Return).
  10. B.10. Subprocessors: may be used by JourneyWise to assist in providing the Services (see Schedule 4).
  11. B.11. Customer is responsible for ensuring that it has all necessary rights, permissions, notices, and lawful bases required under Applicable Data Protection Laws to provide Customer Personal Data to JourneyWise for processing under the Agreement and this DPA. Customer is responsible for the accuracy, quality, and lawfulness of the Customer Personal Data it submits through the Services.

C. Competent Supervisory Authority

Where the data exporter is established in an EU Member State: the supervisory authority of that Member State. Where the data exporter falls within the territorial scope of the GDPR under Article 3(2) and has appointed a representative under Article 27(1): the supervisory authority of the Member State where the representative is established. Where no representative is required under Article 27(2): the Irish Data Protection Commission. Where the data exporter is subject to the UK GDPR: the UK Information Commissioner's Office.

Schedule 2 — Technical and Organisational Measures

A. Access Controls

  • Access to production systems and databases is limited to authorised personnel and is protected by unique credentials and multi-factor authentication (MFA).
  • Default credentials on any system are changed before use in a production capacity.
  • Access is granted on a least-privilege basis, reviewed periodically as the team grows, and revoked promptly when no longer needed.

B. Encryption

  • Customer Data is encrypted in transit using TLS 1.2 or higher.
  • Customer Data at rest is encrypted using the encryption-at-rest capabilities provided by JourneyWise's database and infrastructure providers (for example, MongoDB Atlas' native encryption).

C. Data Segregation

Customer Data is logically separated by customer account such that no customer can access another customer's data without authorisation.

D. Third-Party Infrastructure

JourneyWise relies on established third-party infrastructure providers (see Schedule 4) for hosting, telephony, and email/calendar integration, each of which maintains its own security programme and certifications appropriate to the service it provides.

E. Incident Response

JourneyWise maintains a process to investigate, contain, and notify Customer of Security Breaches in accordance with Section G of this DPA.

F. Personnel

Personnel and contractors with access to Customer Data are bound by confidentiality obligations and are given access only as needed to perform their role.

G. Audit Logging

JourneyWise maintains logging of access to production systems and significant administrative activities where appropriate to support security monitoring, incident investigation, and operational integrity.

H. Vulnerability Management

JourneyWise maintains processes to identify, assess, prioritise, and remediate security vulnerabilities within its systems and supporting infrastructure.

I. Secure Software Development

JourneyWise follows secure software development practices, including peer review of production code, testing before deployment, and controlled release processes.

J. Monitoring

JourneyWise monitors its production environment to identify potential security events, operational issues, and service disruptions.

K. Patch Management

JourneyWise applies security updates and patches to systems and infrastructure within reasonable timeframes based on the nature and severity of identified risks.

L. Secret Management

Authentication credentials, encryption keys, API keys, and other sensitive secrets are stored using appropriate security controls and access restrictions.

M. Access Reviews

Access to Customer Personal Data and production systems is reviewed periodically to ensure that access remains appropriate for authorised personnel.

Schedule 3 — International Data Transfers

A. EU Standard Contractual Clauses (SCCs) and UK Transfer Mechanisms

  1. A.1. Elections for the purposes of Module Two and Module Three of the SCCs:
    • Clause 7 (Docking clause) — does not apply.
    • Clause 11 (Redress) — optional wording does not apply.
    • Clause 17 (Governing law) — Option 1 applies; the governing law is the law of Ireland.
    • Clause 18 (Choice of forum and jurisdiction) — the courts of Ireland.
    • Annex I of the SCCs: Part A of Schedule 1 (parties), Part B of Schedule 1 (description of transfer), and Part C of Schedule 1 (supervisory authority).
    • Annex II of the SCCs: Schedule 2 (technical and organisational measures).
  2. A.2. Additional elections: Clause 9 (Use of Subprocessors): Option 2 (general written authorisation) applies. JourneyWise will provide Customer with reasonable prior notice of any intended changes to its Subprocessors in accordance with Section C.3 of this DPA. The current list of authorised Subprocessors is set out in Schedule 4.
  3. A.3. JourneyWise will implement and maintain appropriate technical, organisational and contractual safeguards designed to ensure that transfers of Customer Personal Data carried out pursuant to the SCCs provide a level of protection substantially equivalent to that required under Applicable Data Protection Laws, taking into account the nature of the transfer and the applicable legal framework.
  4. A.4. Upon Customer's reasonable written request, JourneyWise will provide information reasonably necessary to assist Customer in assessing the safeguards applicable to international transfers of Customer Personal Data carried out under this DPA.

B. UK Addendum

This UK Addendum applies to any processing of Customer Personal Data subject to the UK GDPR, or to both the UK GDPR and the GDPR, where Customer Personal Data is transferred from a data exporter subject to the UK GDPR to a data importer outside the UK. For the purposes of Table 1 of Part 1 of the Approved Addendum, the parties' details are as set out in Part A of Schedule 1; for Table 2, the EU SCCs as set out in Section A above (including the Appendix Information) are the selected SCCs; and for Table 4, JourneyWise (as data importer, where applicable) may end the Approved Addendum.

C. Swiss Addendum

Where Customer Personal Data is subject to the Swiss Federal Act on Data Protection, references in the SCCs to the GDPR, EU Member States, and the competent supervisory authority are adapted to refer to Swiss law and the Federal Data Protection and Information Commissioner (FDPIC), consistent with standard Swiss Addendum practice, and the governing law and forum for such transfers is Switzerland.

Schedule 4 — Subprocessors

JourneyWise's current Subprocessors are:

  • Twilio Inc. — telephony and call/dialer infrastructure (United States).
  • MongoDB, Inc. (MongoDB Atlas) — database hosting (region as configured).
  • Microsoft Corporation — email and calendar integration via Microsoft 365/Outlook OAuth.
  • Google LLC — email and calendar integration via Google Workspace OAuth, Google Ads OAuth.
  • AI/LLM provider — OpenAI, LLC — used to generate call summaries and conversation insights.
  • Microsoft Azure — cloud infrastructure hosting.