Data Processing Agreement
The contractual data-processing terms that apply when JobCue processes tenant-controlled personal data.
JobCue Data Processing Agreement
Last updated: 22 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between a customer organisation using JobCue and EasyMediaUK, operating the JobCue service.
It applies where JobCue processes Personal Data on behalf of a customer in connection with the provision of the JobCue service.
1. Parties
This DPA is between:
The Processor
EasyMediaUK, trading through and operating the JobCue service
24 Mercer Road
Haydock
St Helens
WA11 0SS
United Kingdom
Email: hello@jobcue.co.uk
referred to in this DPA as “JobCue”, “we”, “us”, “our” or the “Processor”;
and
The Controller
The organisation that has subscribed to, registered for or otherwise entered into an agreement to use JobCue,
referred to in this DPA as the “Customer” or the “Controller”.
Together, JobCue and the Customer are referred to as the “Parties”.
2. Purpose and status of this DPA
This DPA governs JobCue’s processing of Personal Data on behalf of the Customer.
It supplements the JobCue subscription terms, order, registration agreement or other agreement governing the Customer’s use of JobCue.
Where there is a conflict between this DPA and another contractual provision concerning the processing of Personal Data on behalf of the Customer, this DPA will take precedence to the extent of that conflict.
This DPA is intended to satisfy the requirements applying to contracts between controllers and processors under the UK GDPR and other applicable UK data-protection law.
3. Definitions
For the purposes of this DPA:
“Applicable Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and any other applicable UK legislation governing the processing of Personal Data, as amended or replaced from time to time.
“Controller” has the meaning given under Applicable Data Protection Law and, for the purposes of this DPA, generally means the Customer.
“Customer Data” means information entered into, uploaded to, generated within or otherwise processed through the Customer’s JobCue workspace.
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
“Personal Data” means personal data as defined by Applicable Data Protection Law.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Personal Data.
“Processing”, “process” and “processed” have the meanings given under Applicable Data Protection Law.
“Processor” means JobCue where it processes Personal Data on behalf of the Customer.
“Sub-processor” means another organisation engaged by JobCue to process Personal Data on behalf of the Customer in connection with the JobCue service.
“UK GDPR” means the retained UK version of the General Data Protection Regulation as amended from time to time.
4. Roles of the Parties
The Customer is normally the Controller of Personal Data that it chooses to enter into or process through its JobCue workspace.
JobCue acts as the Processor where it processes that Personal Data on behalf of the Customer.
The Customer determines:
- what Personal Data it enters into JobCue;
- the purposes for which the Personal Data is processed;
- which individuals’ information is recorded;
- which JobCue Users are authorised to access the information;
- which modules and features are used;
- how long Customer-controlled records are retained, subject to the functionality and contractual arrangements of the service.
JobCue determines how the technical JobCue service is operated in order to provide the service to the Customer, while processing Customer Personal Data only in accordance with the Customer’s documented instructions except where otherwise required by law.
Nothing in this DPA prevents JobCue from acting as an independent Controller for Personal Data that JobCue processes for its own legitimate business purposes, such as:
- account administration;
- billing;
- subscription management;
- security;
- fraud prevention;
- legal compliance;
- direct communications with the Customer;
- operation of the JobCue website.
Such processing is governed by the JobCue Privacy Policy and applicable law.
5. Customer responsibilities
The Customer is responsible for ensuring that its use of JobCue complies with Applicable Data Protection Law.
The Customer warrants that:
- it has an appropriate lawful basis for the Personal Data it enters into JobCue;
- it has provided any required privacy information to relevant Data Subjects;
- its instructions to JobCue comply with Applicable Data Protection Law;
- it will not instruct JobCue to process Personal Data unlawfully;
- it will only give Users access to Personal Data where such access is appropriate;
- it will manage User accounts, roles and permissions appropriately;
- information entered into JobCue is adequate, relevant and limited to what is reasonably required for the Customer’s purposes;
- where special-category or particularly sensitive Personal Data is processed, the Customer has determined that such processing is lawful and appropriate.
The Customer remains responsible for responding to Data Subjects in relation to its own processing activities, with reasonable assistance from JobCue where required under this DPA.
6. Processing instructions
JobCue will process Personal Data only on documented instructions from the Customer unless JobCue is required to process the Personal Data by applicable UK law.
The Customer instructs JobCue to process Personal Data as necessary to:
- provide the JobCue service;
- host and maintain the Customer’s workspace;
- make Customer Data available to authorised Users;
- provide enabled modules and functionality;
- support authentication and access control;
- carry out Customer-configured workflows and automations;
- provide backup, security and service-recovery functionality;
- provide customer support;
- perform maintenance and troubleshooting;
- facilitate authorised integrations and external storage connections;
- delete, export or otherwise manage Customer Data in accordance with the Customer’s use of the service and contractual instructions.
The Customer’s use and configuration of JobCue, including its use of features, modules, permissions, workflow rules and integrations, constitutes documented instructions for these purposes.
Additional instructions may be provided in writing, including by email or support request, provided that they are consistent with the Customer’s agreement with JobCue.
If JobCue believes that an instruction infringes Applicable Data Protection Law, JobCue will inform the Customer without undue delay unless prohibited from doing so by law.
7. Details of the processing
The details required in relation to the processing are set out in Schedule 1 to this DPA.
8. Confidentiality
JobCue will ensure that persons authorised to process Customer Personal Data:
- are subject to an appropriate duty of confidentiality;
- are given access only where reasonably necessary for their role;
- are made aware of the confidential nature of Customer Data;
- process Personal Data only in accordance with authorised instructions.
Access to Customer Data by JobCue personnel will be limited to circumstances where such access is reasonably necessary for purposes such as:
- customer support;
- system maintenance;
- troubleshooting;
- security;
- investigation of an incident;
- compliance with legal obligations.
9. Security of processing
JobCue will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful:
- destruction;
- loss;
- alteration;
- unauthorised disclosure;
- unauthorised access.
Measures may include, where appropriate:
- authenticated User accounts;
- role-based access controls;
- organisation and tenant separation;
- secure password storage;
- authentication controls;
- email verification and multi-factor authentication mechanisms;
- encrypted network connections;
- secure session management;
- logging and audit trails;
- application-level access controls;
- server and infrastructure security controls;
- backups and recovery processes;
- security monitoring;
- vulnerability remediation and software maintenance;
- limiting administrative access according to operational need.
JobCue will review its security measures periodically and may update them as technology, risk and the JobCue service evolve.
Nothing in this DPA requires JobCue to disclose information where doing so would itself materially compromise the security of JobCue, another customer or the service.
10. Customer security responsibilities
The Customer acknowledges that security is a shared responsibility.
The Customer is responsible for:
- maintaining the confidentiality of its User credentials;
- ensuring User accounts are assigned only to authorised individuals;
- promptly disabling access for Users who no longer require it;
- assigning appropriate roles and permissions;
- protecting devices used to access JobCue;
- ensuring its own network and connected systems are appropriately secured;
- configuring external storage and integrations securely;
- ensuring Users do not share authentication credentials;
- notifying JobCue promptly if it suspects unauthorised access to its account.
JobCue is not responsible for a Personal Data Breach caused solely by the Customer’s failure to appropriately manage its own Users, credentials, devices, integrations or external systems.
11. Sub-processors
The Customer gives JobCue general authorisation to engage Sub-processors where reasonably necessary to provide and operate the JobCue service.
JobCue will ensure that any Sub-processor processing Customer Personal Data on JobCue’s behalf is subject to a written agreement imposing data-protection obligations that provide an appropriate level of protection for that Personal Data.
JobCue remains responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law.
Sub-processors may provide services including:
- hosting;
- cloud infrastructure;
- backups;
- email delivery;
- payment-related infrastructure;
- storage;
- security;
- monitoring;
- technical service delivery.
JobCue may maintain a current list of material Sub-processors on its website or make such information available to Customers on request.
12. Changes to Sub-processors
Where JobCue introduces or replaces a material Sub-processor that will process Customer Personal Data, JobCue will take reasonable steps to make information about the change available to affected Customers.
Where required by Applicable Data Protection Law, the Customer may raise a reasonable data-protection objection to the proposed Sub-processor.
The Parties will work in good faith to attempt to resolve a valid objection.
If a reasonable solution cannot be reached and the Sub-processor is necessary for continued delivery of the JobCue service, either Party may exercise any applicable termination rights under the main agreement.
A Customer may not object to a Sub-processor solely for general commercial reasons unrelated to data protection.
13. Third-party services selected by the Customer
JobCue may allow Customers to connect services that they independently select, such as:
- Microsoft 365;
- OneDrive;
- SharePoint;
- Dropbox;
- other supported third-party services.
Where the Customer chooses and authorises such a service, the Customer instructs JobCue to communicate with that service as necessary to provide the requested integration.
The third-party provider may have its own direct relationship with the Customer and may act as a Controller, Processor or separate Processor depending on the circumstances.
The Customer is responsible for:
- selecting the provider;
- entering into any necessary agreement with the provider;
- determining whether the provider is appropriate for its processing;
- configuring permissions and access within that provider;
- reviewing the provider’s privacy, security and international-transfer arrangements.
JobCue is not responsible for the independent processing practices of a third-party service selected and controlled by the Customer.
14. Bring Your Own Storage
Where a Customer configures supported external storage, such as Microsoft 365/OneDrive/SharePoint or Dropbox, JobCue may use that provider as the location for persistent file storage associated with the Customer’s JobCue workspace.
Where JobCue’s external-storage configuration is designed to bypass JobCue-managed persistent file storage, file payloads will be stored in the Customer-selected external provider rather than maintained as a second persistent copy within JobCue.
JobCue may retain metadata necessary to associate those files with JobCue records, including:
- file names;
- descriptions;
- provider identifiers;
- file or folder references;
- audit information;
- lifecycle status;
- archive status;
- relevant access or retrieval metadata.
Temporary technical copies may be processed where reasonably necessary to transfer, display, scan, generate or otherwise provide requested functionality, provided that such temporary processing is consistent with the service and this DPA.
15. Data Subject rights
Taking into account the nature of the processing, JobCue will provide reasonable assistance to the Customer in responding to valid requests from Data Subjects exercising rights under Applicable Data Protection Law.
These may include rights relating to:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection;
- automated decision-making where applicable.
If JobCue receives a request directly from a Data Subject that clearly relates to Personal Data controlled by a particular Customer, JobCue will normally direct the individual to the relevant Customer or notify the Customer as appropriate.
JobCue will not independently respond to the substance of a request concerning Customer-controlled Personal Data except:
- on the Customer’s documented instructions;
- where required by law;
- where necessary to explain that JobCue acts as a Processor.
The Customer remains responsible for determining whether a Data Subject request is valid and how it should be fulfilled.
16. Assistance with compliance
Taking into account the nature of the processing and information available to JobCue, JobCue will provide reasonable assistance to the Customer with its obligations concerning:
- security of processing;
- Personal Data Breaches;
- Data Protection Impact Assessments;
- consultation with the Information Commissioner’s Office or other competent supervisory authority where required;
- Data Subject rights.
Any assistance beyond the ordinary functionality and support included with JobCue may be subject to reasonable charges where it requires substantial bespoke work, unless the need for that assistance arises from JobCue’s own breach of its obligations.
17. Personal Data Breaches
JobCue will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Personal Data processed by JobCue on behalf of that Customer.
The notification will include available information reasonably necessary for the Customer to assess the incident, which may include:
- the nature of the breach;
- the categories of Personal Data affected;
- the categories or approximate number of affected Data Subjects where known;
- the likely consequences;
- measures taken or proposed to address the breach;
- measures taken to mitigate potential adverse effects;
- a point of contact for further information.
Where complete information is not immediately available, JobCue may provide information in stages as the investigation progresses.
JobCue’s notification of a Personal Data Breach does not constitute an admission of fault or liability.
The Customer remains responsible for determining whether notification must be made to:
- the Information Commissioner’s Office;
- Data Subjects;
- another regulator or authority;
unless the relevant breach relates to processing for which JobCue itself is acting as Controller.
18. Data Protection Impact Assessments
Where the Customer is required to conduct a Data Protection Impact Assessment concerning its use of JobCue, JobCue will provide reasonable information and assistance regarding the processing it performs on the Customer’s behalf.
The Customer remains responsible for determining:
- whether a DPIA is required;
- the scope of the DPIA;
- whether the processing should proceed;
- whether consultation with a supervisory authority is required.
19. International transfers
JobCue will not make a restricted international transfer of Customer Personal Data except:
- on the documented instructions of the Customer; or
- where necessary to provide the JobCue service using an authorised Sub-processor;
and where a lawful transfer mechanism is in place where required.
Depending on the transfer, safeguards may include:
- UK adequacy regulations;
- the International Data Transfer Agreement;
- the UK Addendum to recognised contractual clauses;
- another lawful safeguard or mechanism available under Applicable Data Protection Law.
Where JobCue initiates a restricted transfer to a Sub-processor, JobCue will take the steps required of it under Applicable Data Protection Law.
Where the Customer independently instructs JobCue to transfer Personal Data to a third-party service selected by the Customer, responsibility for the transfer will be allocated according to Applicable Data Protection Law and the structure of the relevant transfer.
20. Location of processing
Customer Personal Data may be processed in the United Kingdom and, where required to provide the service, in other jurisdictions used by authorised Sub-processors or Customer-selected integrations.
JobCue will apply the international-transfer requirements described in this DPA where Applicable Data Protection Law requires them.
21. Records and accountability
JobCue will maintain records concerning processing carried out on behalf of Customers where required by Applicable Data Protection Law.
JobCue will make available to the Customer information reasonably necessary to demonstrate JobCue’s compliance with its processor obligations under Applicable Data Protection Law.
22. Audits
The Customer may request information reasonably necessary to verify JobCue’s compliance with this DPA.
Where reasonably sufficient, compliance may be demonstrated through:
- written security information;
- policies;
- technical documentation;
- responses to reasonable security or privacy questionnaires;
- independent reports or certifications if and when available;
- other appropriate compliance information.
Where these measures are insufficient and Applicable Data Protection Law requires further verification, the Customer may request an audit.
Any audit must:
- be reasonable and proportionate;
- relate specifically to Personal Data processed for that Customer;
- normally take place during business hours;
- be subject to reasonable advance written notice;
- avoid unreasonable disruption to JobCue;
- preserve the security and confidentiality of other JobCue customers;
- be conducted by the Customer or an appropriately qualified independent auditor subject to confidentiality obligations.
The Customer will bear its own audit costs and any reasonable costs incurred by JobCue in supporting an extensive or bespoke audit, unless the audit identifies a material breach by JobCue of this DPA.
Nothing in this section requires JobCue to provide:
- access to another customer’s data;
- access that would compromise platform security;
- confidential information unrelated to the Customer’s processing;
- source code or credentials;
- unrestricted physical or system access.
23. Government and legal requests
If JobCue receives a legally binding request from a public authority requiring disclosure of Customer Personal Data, JobCue will, where legally permitted:
- notify the Customer;
- limit disclosure to what is legally required;
- reasonably cooperate with lawful efforts by the Customer to challenge or limit the request.
JobCue will not voluntarily disclose Customer Personal Data to public authorities except where legally permitted and reasonably necessary.
24. Return and deletion of Personal Data
On termination or expiry of the Customer’s JobCue service, JobCue will, at the Customer’s choice and subject to the available functionality and main agreement:
- provide a reasonable means for the Customer to retrieve or export Customer Data where applicable;
- return relevant Personal Data where technically appropriate; or
- delete Personal Data processed on the Customer’s behalf.
JobCue may retain information where required by applicable law.
Deletion from live systems does not necessarily result in immediate deletion from backups.
Personal Data may remain within encrypted or otherwise protected backups until those backups are deleted or overwritten through the normal backup lifecycle.
JobCue will not restore deleted Customer Data from backups except where reasonably necessary for service recovery, disaster recovery, security or legal purposes.
If restored, Personal Data scheduled for deletion will remain subject to the applicable deletion requirements.
25. Data export and account closure
The Customer is responsible for exporting any information it wishes to retain before the end of any applicable post-termination access or export period.
JobCue may provide export tools or reasonable assistance appropriate to the service.
Bespoke migration, transformation or extraction work beyond standard export functionality may be subject to separate charges.
26. Customer-selected retention and archiving
Where JobCue provides functionality allowing a Customer to configure:
- retention periods;
- archiving;
- deletion;
- storage destinations;
- document lifecycle rules;
the Customer is responsible for choosing settings appropriate to its legal and operational requirements.
JobCue’s provision of configurable retention functionality does not constitute legal advice about how long the Customer should retain particular Personal Data.
27. Special-category and high-risk Personal Data
JobCue is designed as a general business operations platform rather than a specialist system for processing special-category or highly sensitive Personal Data.
The Customer must assess whether JobCue is appropriate before using it for information including, where applicable:
- health information;
- biometric or genetic data;
- information revealing racial or ethnic origin;
- religious or philosophical beliefs;
- trade-union membership;
- information concerning sex life or sexual orientation;
- criminal-offence data;
- other unusually sensitive information.
Where the Customer chooses to process such information, the Customer is responsible for identifying an appropriate lawful basis and any additional legal condition required.
Nothing in this section authorises processing that would otherwise breach Applicable Data Protection Law.
28. Automated workflows
JobCue allows Customers to configure workflow automations that may perform actions based on information or events within the Customer’s workspace.
The Customer is responsible for determining:
- which automations it enables;
- the rules and triggers it configures;
- whether an automated action is appropriate for its business process;
- whether any automated processing has legal or similarly significant effects on an individual.
JobCue’s ordinary workflow automation is intended to support administrative and operational processes rather than independently make legally significant decisions about individuals.
Where a Customer configures JobCue in a manner involving automated decision-making regulated by Applicable Data Protection Law, the Customer remains responsible for ensuring its use is lawful.
29. Changes to the service
JobCue may develop or modify the service over time.
Changes may include:
- new modules;
- additional integrations;
- replacement infrastructure;
- new storage options;
- changes to Sub-processors;
- improvements to security or backup processes.
Where a change materially affects the processing of Customer Personal Data, JobCue will update relevant contractual, privacy or Sub-processor information as appropriate.
30. Liability
Liability arising under or in connection with this DPA is subject to the liability provisions of the main JobCue agreement except where Applicable Data Protection Law prohibits such limitation.
Nothing in this DPA excludes or limits liability where doing so would be unlawful.
Each Party remains responsible for its own obligations under Applicable Data Protection Law.
31. Term
This DPA takes effect when the Customer begins using JobCue in circumstances where JobCue processes Personal Data on its behalf.
It continues for as long as JobCue processes such Personal Data.
Relevant provisions concerning:
- confidentiality;
- security;
- deletion;
- liability;
- audit;
- legal compliance;
will continue to apply after termination to the extent necessary to protect Personal Data or fulfil legal obligations.
32. Governing law
This DPA is governed by the same law and jurisdiction as the main agreement between JobCue and the Customer.
Where the main agreement does not specify a governing law, this DPA will be governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction, subject to any mandatory rights or jurisdiction imposed by applicable law.
33. Contact
Questions about this DPA or JobCue’s processing of Customer Personal Data should be sent to:
JobCue
Operated by EasyMediaUK
24 Mercer Road
Haydock
St Helens
WA11 0SS
United Kingdom
Email: hello@jobcue.co.uk
Schedule 1 — Details of Processing
1. Subject matter
JobCue processes Personal Data as necessary to provide a modular job, project and business operations management platform to the Customer.
This may include hosting, storing, organising, retrieving, displaying, updating, transmitting, backing up, securing and deleting Personal Data associated with the Customer’s JobCue workspace.
2. Duration
Processing will continue:
- for the duration of the Customer’s subscription or authorised use of JobCue;
- during any agreed account-closure, export or retention period;
- for such additional period as information remains in backups or must lawfully be retained.
3. Nature of processing
Processing may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- retrieval;
- consultation;
- use;
- transmission;
- making information available to authorised Users;
- association with Jobs, Projects and other business records;
- automated workflow actions;
- reporting;
- backup;
- archiving;
- restriction;
- deletion;
- destruction.
4. Purpose of processing
The purpose of processing is to provide the JobCue service and enabled functionality selected and configured by the Customer.
This may include:
- customer and CRM management;
- sales opportunity management;
- Job Management;
- Project Management;
- User Management;
- Timesheets;
- client access;
- client approvals;
- Content Map & Approvals;
- To Do management;
- resource planning;
- equipment inventory management;
- freelancer management;
- recurring services and renewal management;
- accounting and bookkeeping functionality;
- support-ticket management;
- client briefing;
- reporting;
- workflow automation;
- file and document association;
- authentication;
- audit logging;
- security;
- backup and recovery.
5. Categories of Data Subjects
Depending on the Customer’s use of JobCue, Personal Data may relate to:
- Customer employees;
- Customer Users;
- directors and owners;
- freelancers;
- contractors;
- agency workers;
- job applicants where entered by the Customer;
- existing clients;
- prospective clients;
- client contacts;
- supplier contacts;
- subcontractors;
- venue contacts;
- project stakeholders;
- support contacts;
- external collaborators;
- other individuals whose information the Customer lawfully enters into JobCue.
6. Types of Personal Data
Depending on the Customer’s configuration and use of JobCue, Personal Data may include:
Identity information
- name;
- title;
- organisation;
- role;
- User identifier.
Contact information
- email address;
- telephone number;
- business address;
- other business contact details.
Account information
- User role;
- permissions;
- account status;
- authentication and login information;
- account preferences.
Client and CRM information
- contact history;
- opportunity information;
- notes;
- communication records;
- relationship information.
Job and Project information
- project assignments;
- responsibilities;
- project notes;
- task information;
- attendance;
- availability;
- programme information;
- communications.
Workforce information
- timesheets;
- working time;
- assignments;
- availability;
- resource allocations;
- freelancer information.
Commercial information
- quotes;
- rates;
- purchase-order information;
- expenses;
- invoices;
- transaction references;
- job-cost information;
- supplier information.
Support information
- support requests;
- correspondence;
- attachments;
- resolution history.
Briefing and approval information
- questionnaire responses;
- client briefs;
- feedback;
- comments;
- approval records;
- revision history.
Technical information
- IP addresses;
- login records;
- timestamps;
- audit logs;
- session information;
- security events;
- device or browser information.
Files and attachments
Personal Data contained within files, documents, images and other materials uploaded or associated with JobCue by the Customer.
7. Special-category Personal Data
JobCue does not require Customers to routinely process special-category Personal Data.
Such information may nevertheless be processed if the Customer independently enters or uploads it.
The Customer remains responsible for determining whether such processing is lawful, necessary and appropriate.
8. Frequency of processing
Processing occurs continuously or as required while the Customer and its authorised Users use the JobCue service.
9. Customer instructions
The Customer instructs JobCue to process the Personal Data described in this Schedule as required to provide the service in accordance with:
- the Customer’s subscription;
- selected modules;
- account configuration;
- workflow rules;
- User permissions;
- integrations;
- support requests;
- other documented instructions.
Schedule 2 — Security Measures
JobCue will maintain technical and organisational security measures appropriate to the nature and risk of the processing.
Measures may include:
Access control
- authenticated User access;
- organisation-specific permissions;
- role-based access;
- administrative access controls;
- restriction of access according to operational need.
Authentication
- secure credential handling;
- password hashing;
- email verification;
- multi-factor authentication mechanisms where implemented;
- session expiry and logout controls;
- password-reset controls.
Application security
- secure development practices;
- input validation;
- access-control checks;
- protection against unauthorised cross-tenant access;
- session-security controls;
- security updates and remediation.
Network security
- encrypted HTTPS/TLS connections;
- server and firewall controls;
- infrastructure monitoring where appropriate.
Logging and monitoring
- authentication logs;
- audit records;
- application and server logs;
- monitoring of suspicious or failed activity where appropriate.
Data resilience
- backup processes;
- recovery procedures;
- service-restoration processes;
- appropriate backup protection.
Personnel and confidentiality
- limited administrative access;
- confidentiality obligations;
- access according to business need.
Customer controls
JobCue provides or may provide controls allowing Customers to manage:
- Users;
- permissions;
- modules;
- connected storage;
- workflow configuration;
- account access.
Security measures may evolve as JobCue develops, provided that the overall level of protection is not materially reduced without appropriate reason.
Schedule 3 — Sub-processors and External Services
JobCue may use third-party providers to deliver elements of the service.
A current list of material Sub-processors should be maintained separately by JobCue and may be published on the JobCue website or provided to Customers on request.
The list should identify, where relevant:
- Sub-processor name;
- service provided;
- processing location;
- categories of Personal Data involved;
- applicable international-transfer mechanism where required.
Customer-selected services, including a Customer’s own Microsoft 365, OneDrive, SharePoint or Dropbox environment, are not necessarily JobCue Sub-processors where the provider has been independently selected and contracted by the Customer.
Schedule 4 — End-of-Service Processing
When a Customer’s use of JobCue ends:
- the Customer should export information it wishes to retain using available JobCue functionality;
- JobCue will cease ordinary processing of Customer Personal Data except where required for account closure or legal purposes;
- Customer Personal Data will be deleted or returned in accordance with the main agreement and available functionality;
- information contained within backups may remain until the normal backup-retention cycle removes it;
- JobCue may retain Personal Data where required by law;
- externally stored files held in Customer-controlled Microsoft, Dropbox or other environments remain subject to the Customer’s own arrangements with that provider;
- JobCue may delete retained metadata relating to externally stored files when the associated JobCue workspace is permanently removed.
Acceptance
This DPA forms part of the Customer’s agreement to use JobCue.
Where the Customer accepts the JobCue Terms, creates a JobCue subscription, continues to use the JobCue service after this DPA becomes applicable, or otherwise agrees to this DPA electronically or in writing, the Customer agrees to the terms of this DPA on behalf of the organisation it represents.
The person accepting this DPA confirms that they have authority to bind that organisation.
Processor:
EasyMediaUK, operating JobCue
24 Mercer Road
Haydock
St Helens
WA11 0SS
United Kingdom
Customer:
The organisation identified in the relevant JobCue account, subscription or order.
Effective date:
The date on which the Customer’s relevant JobCue agreement or subscription takes effect.
