Last updated September 1, 2025
This Data Processing Agreement (“DPA”) forms part of the Terms of Use (or other similarly titled written or electronic agreement addressing the same subject matter) (“Agreement”) between Customer (as defined in the Agreement) and “Joist AI” under which the Processor provides the Controller with the software and services (the “Services”). The Controller and the Processor are individually referred to as a “Party” and collectively as the “Parties”.
The Parties seek to implement this DPA to comply with the requirements of EU GDPR (defined hereunder) in relation to Processor’s processing of Personal Data (as defined under the EU GDPR) as part of its obligations under the Agreement.
This DPA shall apply to Processor’s processing of Personal Data, provided by the Controller as part of Processor’s obligations under the Agreement.
Except as modified below, the terms of the Agreement shall remain in full force and effect.
Terms not otherwise defined herein shall have the meaning given to them in the EU GDPR or the Agreement. The following terms shall have the corresponding meanings assigned to them below:
1.1 "Data Transfer" means a transfer of the Personal Data from the Controller to the Processor, or between two establishments of the Processor, or with a Sub-processor by the Processor.
1.2 “EU GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
1.3 “Standard Contractual Clauses” means the contractual clauses attached hereto as Schedule 1 pursuant to the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021 on Standard Contractual Clauses for the transfer of Personal Data to processors established in third countries which do not ensure an adequate level of data protection.
1.4 “Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
1.5 “Processor” means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
1.6 “Sub-processor” means a processor/ sub-contractor appointed by the Processor for the provision of all or parts of the Services and Processes the Personal Data as provided by the Controller.
A. LIST OF PARTIES
Data exporter(s):
Name : Customer (As set forth in the relevant Order Form).
Address: As set forth in the relevant Order Form.
Contact person’s name, position, and contact details: As set forth in the relevant Order Form.
Activities relevant to the data transferred under these Clauses: Recipient of the Services provided by Joist in accordance with the Agreement (as defined in Recital A of this DPA).
Signature and date: Signature and date are set out in this DPA.
Role Controller/ Processor): Controller
Data importer(s):
Name: Joist AI (As set forth at the beginning of this DPA)
Address: Joist Technologies, Inc. 8910 University Center Lane, Suite 400, San Diego, CA 92122.
Contact person’s name, position, and contact details: Rohan Jawali, CEO, Joist Technologies Inc.
Activities relevant to the data transferred under these Clauses: Provision of the Services to the Customer in accordance with the Agreement.
Signature and date: Signature and date are set out in this DPA.
Role (controller/processor): Processor.
B. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred
Customer’s Authorized Users (as defined in the Agreement) of the Services.
Categories of personal data transferredName, Title, Role, Education/Qualifications/Past Experience/Career Summaries/Bios, Business contact details, Image, Gender Identification (i.e. pronouns), Language, Related person, Related URL, User ID, Username, hourly rates.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
No sensitive data collected.
The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis).
Continuous basis
Nature of the processing
Extracting the person’s information from past proposal documents and indexing and organization purposes, enabling fast and efficient retrieval.
Purpose(s) of the data transfer and further processing
The purpose of the transfer is to facilitate the performance of the Services more fully described in the Agreement pursuant to executed Order Forms.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
Personal data will be retained only for as long as is necessary to fulfil the purposes for which it was collected or in accordance with applicable data protection legislation.
For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing
The subject matter, nature, and duration of the Processing more fully described in the Agreement, Addendum, and accompanying order forms.
TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organisational security measures implemented by Joist AI as the data processor/data importer to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, and the risks for the rights and freedoms of natural persons.
SECURITY
Security Management System
Personnel Security
Access Controls
Data Center and Network Security
Data Centers
Networks and Transmission.
Data Storage, Isolation, Authentication, and Destruction.
Joist AI stores data in a multi-tenant environment on AWS RDS servers. Data, the Services database and file system architecture are replicated between multiple availability zones on AWS. Joist logically isolates the data of different customers. A central authentication system is used across all Services to increase uniform security of data. Joist ensures secure disposal of Client Data through the use of a series of data destruction processes.
LIST OF SUB-PROCESSORS
Please refer to https://trust.joist.ai/ for Joist AI’s list of sub-processors.