Data Processing Agreement
1. Background and purpose
1.1 This Data Processing Agreement (“DPA”) is an annex to and forms an integral part of the Jarva Terms and Conditions or other written or electronic agreement (“Agreement”) between Jarva, CVR 45429040 (“Jarva”) and the customer that has entered into the Agreement (“Customer”) (each a “Party” and together the “Parties”), which governs the services provided by Jarva to Customer, including the Jarva platform and Jarva Tracking (the “Services”).
1.2 In the course of providing the Services to Customer pursuant to the Agreement, Jarva may process Customer Personal Data on behalf of Customer. This DPA describes the Parties’ rights and obligations with respect to the Processing of Customer Personal Data by Jarva on behalf of Customer in connection with the Services.
1.3 In the event of any conflict between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail solely with respect to the Processing of Customer Personal Data.
2. Definitions
2.1 For the purpose of this DPA, the following capitalised terms shall have the following meanings:
“Customer Personal Data” means the Personal Data that Jarva processes on behalf of Customer in connection with the Services.
“Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
“Data Protection Laws” means the GDPR and any other data protection or privacy laws applicable to the Processing of Customer Personal Data under this DPA.
“EEA” means the European Economic Area.
“GDPR” means the General Data Protection Regulation (Regulation (EU) 2016/679), as amended, replaced, or superseded from time to time, together with any applicable data protection or privacy laws implementing or supplementing it.
“Sub-processor” means another processor engaged by Jarva in the Processing of Customer Personal Data and, where applicable, any other processor engaged by such Sub-processor.
2.2 The terms “Personal Data”, “Data Subject”, “Processing”, “Controller” and “Processor” as used in this DPA have the meanings given in the GDPR.
2.3 In addition, unless expressly otherwise stated, the applicable definitions provided in the Agreement shall be applied to this DPA.
3. Processing of Personal Data
3.1 Roles of the Parties
3.1.1 For the purposes of the Processing of Customer Personal Data, Customer is the Controller and Jarva is the Processor.
3.2 Subject matter, nature and purpose
3.2.1 The subject matter, nature and purpose of the Processing is to supply and enable the Services provided by Jarva to Customer. The Processing of Customer Personal Data shall take place solely for the purposes defined herein and Jarva shall not be entitled to use the Customer Personal Data for any other purposes, unless otherwise stated in the Agreement. Customer hereby authorises Jarva to transfer Customer Personal Data to the Third-Party Platforms that Customer has connected to the Services and to anonymize Customer Personal Data.
3.3 Personal Data and Data Subjects
3.3.1 Customer may submit or make available Customer Personal Data to the Services, the extent of which is determined and controlled by Customer in its sole discretion.
3.3.2 The Customer Personal Data concerns the following categories of Data Subjects: visitors to Customer’s websites and online stores, and individuals who purchase products or services from Customer.
3.3.3 The types of Customer Personal Data typically include:
- online identifiers, such as cookie identifiers, click identifiers, IP addresses and device and browser information;
- event data, such as the actions a Data Subject takes on Customer’s websites and online stores;
- contact details, such as names, email addresses, phone numbers and addresses;
- order and transaction details, such as orders, items purchased and amounts;
- other Personal Data submitted to the Services by, or at the direction of, Customer.
3.4 Duration and termination of the Processing
3.4.1 This DPA becomes effective simultaneously with the Agreement and shall continue to be in effect until the Agreement is terminated.
3.4.2 Customer Personal Data is processed for as long as necessary to provide the Services. If any Processing by Jarva is required after termination of the Agreement, such Processing shall be conducted in accordance with the provisions of this DPA.
3.4.3 In the event of termination of the Agreement, Jarva shall delete the Customer Personal Data, or if requested by Customer in writing, return the Customer Personal Data to Customer in a commonly used format as soon as practically possible after the end of the Agreement, and such Customer Personal Data shall be deleted thereafter from the systems of Jarva, unless applicable law requires storage of the Customer Personal Data.
3.5 Instructions for Processing
3.5.1 The Customer Personal Data shall be processed in accordance with Customer’s documented instructions. This DPA, the Agreement and Customer’s use of the Services are Customer’s complete documented instructions to Jarva for the Processing of Customer Personal Data. Any additional or alternate instructions must be agreed upon separately.
3.5.2 Jarva shall not process Customer Personal Data for any other purpose or otherwise deviate from Customer’s instructions, unless required to do so by Union or Member State law to which Jarva is subject, in which case Jarva shall, to the extent legally permissible, inform Customer of that legal requirement before carrying out such Processing.
3.5.3 If Jarva considers an instruction to infringe Data Protection Laws, Jarva shall immediately inform Customer of such matter.
3.6 General obligations of the Parties
3.6.1 Customer shall have sole responsibility for: (i) the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired Customer Personal Data; and (ii) ensuring that it has established adequate lawful bases under Data Protection Laws to permit Jarva to lawfully Process Customer Personal Data as contemplated herein.
3.6.2 Each Party shall comply with all applicable Data Protection Laws in the Processing of the Personal Data and other actions under this DPA.
3.6.3 Jarva shall implement appropriate technical and organisational measures for the security of Processing as required by the Data Protection Laws and as further specified in Section 6 below.
3.6.4 Jarva shall reasonably assist Customer: (i) in ensuring the compliance with the provisions on security of the Customer Personal Data as set forth in the Data Protection Laws; (ii) by appropriate technical and organisational measures in the fulfilment of Customer’s obligation to respond to requests for exercising the Data Subject’s rights under the Data Protection Laws; (iii) in carrying out data protection impact assessments, related consultations of and other dealings with data protection authorities; and (iv) by making available to Customer all information necessary to demonstrate compliance with the obligations in this DPA and Data Protection Laws.
3.6.5 Any request directed to Jarva by a Data Subject shall be referred by Jarva to Customer without undue delay.
4. Sub-processors
4.1 Customer grants Jarva a general authorisation for Jarva’s use of Sub-processors in connection with the provision of the Services.
4.2 A list of the current Sub-processors, including their name, country, processing activities and the country or area where processing activities are carried out, is available at jarva.ai/sub-processors.
4.3 Jarva shall inform Customer of any intended changes concerning the addition or replacement of Sub-processors by updating the list at jarva.ai/sub-processors, thereby giving Customer the opportunity to object to such changes. Customer may only object to such changes based on reasonable data protection concerns.
4.4 Jarva shall enter into a written agreement with each Sub-processor containing data protection obligations not less protective than those in this DPA to the extent applicable to the nature of the services provided by such Sub-processor.
4.5 Where a Sub-processor fails to fulfil its data protection obligations, Jarva remains liable for any acts or omissions of such Sub-processor as for its own.
5. Location and transfers of data
5.1 Jarva and its Sub-processors may transfer or process Customer Personal Data outside the EEA. Jarva shall ensure that any such transfer is only made to: (i) a country deemed by the European Commission to have an adequate level of protection; (ii) entities having entered into the standard contractual clauses published by the European Commission, reference 2021/914; or (iii) recipients providing other appropriate safeguards as described in Article 46 of the GDPR. Customer gives its consent to such transfers and authorises Jarva to conclude the processor-to-processor module of those standard contractual clauses as applicable.
5.2 Upon Customer’s request, Jarva shall provide written information about the location(s) in which Customer Personal Data is processed pursuant to this DPA.
6. Security of Processing
6.1 Jarva shall implement and maintain at all times appropriate operational, administrative, physical and technical measures in accordance with common industry practice to protect the Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data transmitted, stored or otherwise processed.
6.2 Jarva shall ensure that persons authorised to process the Customer Personal Data have committed themselves to appropriate confidentiality or are under an appropriate statutory obligation of confidentiality.
6.3 Jarva shall limit access to the Customer Personal Data to personnel on a need-to-know basis.
7. Data breaches
7.1 In case of a Data Breach, Jarva shall notify Customer thereof in writing without undue delay after having become aware of it. The notification shall at least:
- describe the nature of the Data Breach, the affected Customer Personal Data, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Customer Personal Data records concerned;
- communicate the name and contact details of a contact point where more information can be obtained;
- describe the likely consequences of the Data Breach; and
- describe the measures taken or proposed to be taken by Jarva to address the Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
7.2 Where, and in so far as, it is not possible to provide the information under Section 7.1 at the same time, the information may be provided in phases without undue delay.
7.3 Upon Customer’s request, Jarva shall assist Customer with reasonable effort in documenting a Data Breach as required by Data Protection Laws and in reporting the Data Breach to the supervisory authority and to the Data Subjects.
8. Audit
8.1 Customer or an auditor mandated by Customer may, once a year at most, audit the Processing of Customer Personal Data by Jarva upon 14 working days’ prior written notice to ensure compliance with this DPA and Data Protection Laws.
8.2 The auditor mandated by Customer may not be a direct or indirect competitor of Jarva. Jarva has a right to require the mandated auditor to enter into an appropriate confidentiality agreement prior to the audit.
8.3 Jarva shall contribute to the aforementioned audits and make available all information required to complete the audits. The audits shall be performed during normal working hours and shall not unreasonably disturb the operations of Jarva.
8.4 Customer shall carry its own costs relating to the audits and shall reimburse Jarva for any reasonable costs and expenses that Jarva may incur due to any such audit. Before the commencement of any such audit, Customer and Jarva shall mutually agree upon the scope, timing, and duration of the audit.
9. Liability
9.1 Jarva’s total aggregate liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations of liability of the Agreement.
Last updated: 2026-09-19

