Legal

Data Processing Addendum (DPA)

This Data Processing Addendum (“DPA”) outlines Hexa’s obligations when processing personal data on behalf of its customers under applicable data protection laws, including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

Last updated

1. Scope and Applicability

This DPA applies where jemmic processes personal data on behalf of the Customer in the course of providing its Services. It supplements the Terms of Service and forms part of the agreement between jemmic and the Customer.

2. Roles and Responsibilities

  • Customer is the data controller.

  • jemmic is the data processor (as defined under GDPR Article 4).

  • Both parties shall comply with their respective obligations under applicable data protection laws.

3. Types of Personal Data

Hexa may process the following categories of personal data:

  • Name

  • Email address

  • Company information

  • IP addresses

  • Audio recordings or transcripts (if call recording/transcript features are used)

  • Usage logs and activity metadata

  • CRM and calendar data (if integrated)

Hexa does not knowingly process special categories of personal data (e.g. racial or ethnic origin, political opinions, health data).

4. Purpose of Processing

jemmic processes personal data solely for the purpose of:

  • Providing and improving the Services

  • Enabling AI-powered features (e.g., summaries, forecasting, follow-ups)

  • Ensuring account and billing management

  • Monitoring system performance and security

Hexa does not process customer data for advertising or model training without explicit consent.

5. Subprocessors

jemmic uses vetted subprocessors to help provide the Services (e.g., AWS, Stripe, analytics tools). A full list is available at [jemmic.com/legal/subprocessors].

All subprocessors are bound by contractual terms equivalent to this DPA.

Customers may subscribe to change notifications or object (reasonably) to new subprocessors.

6. Data Transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, Hexa ensures adequate protection through:

  • Standard Contractual Clauses (SCCs)

  • Data Privacy Framework (DPF) (where applicable)

  • Additional security controls

7. Security Measures

jemmic implements appropriate technical and organizational security measures, including:

  • Data encryption in transit and at rest

  • Access controls and user authentication

  • Network monitoring and intrusion detection

  • Regular vulnerability scanning and audits

  • Employee confidentiality agreements and training

8. Data Subject Rights

jemmic will assist the Customer in responding to data subject requests related to:

  • Access

  • Correction

  • Erasure

  • Portability

  • Restriction or objection to processing

jemmic will promptly notify the Customer of any such requests.

9. Breach Notification

In the event of a personal data breach, jemmic shall:

  • Notify the Customer without undue delay

  • Provide relevant details of the incident

  • Assist in any investigation or regulatory communication

10. Data Deletion and Return

Upon termination or expiration of the Agreement, jemmic will:

  • Delete Customer data within 30 days (unless legally required to retain it)

  • Provide confirmation of deletion upon written request

  • Allow for secure export of Customer data prior to deletion

11. Audits and Certifications

jemmic will:

  • Make available relevant information to demonstrate compliance (e.g., security documentation, audit logs)

  • Allow audits by Customer or third-party auditors with reasonable notice

  • Maintain compliance with data protection certifications or frameworks (as applicable)

12. Governing Law

This DPA is governed by the same jurisdiction as the main agreement, unless otherwise required by applicable law.

13. Contact

For all data protection inquiries:

📧 Email: contact@jemmic.com

Jump to

Share policy

Related Legal documents

Explore other important policies

Need more info? Here’s where to find the rest of the fine print.

AI Disclosure

How our AI features process data.

Acceptable Use Policy (AUP)

What you can and can’t do with Hexa.

Cookie Policy

What cookies we use and why.

Privacy Policy

How we collect and use your data.

Terms of Service

The rules for using Hexa.

Start Now

Discover how Jemmic can
boost your business

Book a meeting to try SecuChat and find out how it can transform your use cases.

  • Trusted by 80+ institutions

  • FINMA/FDPA/GDPR standards

  • More than 1 million users

Start Now

Discover how Jemmic can boost your business

Book a meeting to try SecuChat and find out how it can transform your use cases.

  • Trusted by 80+ institutions

  • FINMA/FDPA/GDPR standards

  • More than 1 million users

Start Now

Discover how Jemmic can
boost your business

Book a meeting to try SecuChat and find out how it can transform your use cases.

  • Trusted by 80+ institutions

  • FINMA/FDPA/GDPR standards

  • More than 1 million users