Data Processing Addendum
Last updated: 4 October 2026
This agreement governs personal information PageJoy processes on a business customer's instructions. It covers shared Business workspace records, saved client details and any separately approved plugin processing described in its completed schedules.
1. Parties, acceptance and priority
The provider is PageJoy. The customer is the business or person identified by the authorised Owner when the Business workspace is created, at the address supplied by that customer in its order or written instructions, with contact the workspace Owner email unless the customer provides a different authorised privacy contact.
This Addendum forms part of the agreement for the underlying PageJoy software service. The authorised Owner accepts it when creating the Business workspace, and it takes effect for that customer on the recorded acceptance date. A public web page alone is not evidence that a customer agreed to it.
For processing covered by it, this Addendum takes priority over inconsistent service terms. Mandatory law and a binding approved international transfer instrument take priority over it to the extent required by that law or instrument. Payment merchant arrangements do not change the processor duties accepted here.
2. Scope and roles
Customer Personal Data means personal information included in the completed processing schedule that we process on the customer's instructions. Controller and processor have the meanings given by applicable data protection law. The customer is the controller, or a processor authorised by its controller to appoint us. We are its processor or subprocessor for Customer Personal Data.
Shared Business workspace personal data includes the business details, clients, items, Templates documents, document approvals, membership permissions and workspace activity entries within Schedule 1. The business customer controls this information and appoints the Owner and authorised members to act for it. An Owner or member does not become the controller of every shared record merely by having a personal account or administering the workspace.
This Addendum does not cover information we independently control for account administration, free-use counting, billing, our own service security, legal compliance or support purposes, as described in the Privacy Notice. Workspace access and activity data processed for the business customer's shared work remain Customer Personal Data. Any separate independently controlled use of membership, activity or support information must be identified, justified and disclosed in that notice; this exclusion does not permit an undisclosed secondary use of Customer Personal Data. The Addendum does not change the separate roles of Stripe, Google, Apple, OpenAI, Anthropic, Supabase Auth, Cloudflare Turnstile or the chosen email sender. Their actual controller, processor or subprocessor roles must be recorded for the relevant operation in the Service Providers page and Schedule 3; naming a provider does not authorise it to receive Customer Personal Data.
Website PDF and Photo work is processed on each person's device and is not shared through the Business workspace or uploaded to us by those tools. Free users' invoice details remain in their browser. These files and details are outside our server processing schedule. A separately agreed server-processing operation must be included in Schedule 1 with its recipients and deletion controls. Temporary server copies for that agreed operation are deleted immediately after returning the result. Claude files are chosen only in our own panel, processed on the device and returned as a browser download. Our tools never read files uploaded to the Claude chat, its history, memory or conversation summaries. A customer instruction cannot override that boundary. Saved Templates records are separate from temporary file copies and follow their workspace retention rules.
Article 28 UK GDPR and EU GDPR requires a binding controller and processor agreement. ICO contract guidance.
3. The customer's duties and rights
The customer decides the purpose of its processing and must have a lawful basis for collecting and using Customer Personal Data. It must provide required notices, obtain required consent, honour individual rights and give lawful instructions. It must use the service within the agreed data categories and take reasonable care over its access credentials and exports.
The customer may instruct us, seek the assistance described here, review compliance, object to subprocessor changes through section 7 and choose return or deletion under section 10. It must tell us promptly about a relevant data incident or unlawful instruction it discovers. If the customer is a processor, it must pass relevant notices and information to its controller.
The customer is responsible for deciding which people may join its Business workspace and the lawful purposes for which they may use shared records. The Owner can approve documents, remove members and change roles. The customer must tell members what information is shared, which actions are logged and how to exercise rights. Our agreed Owner, Member and Viewer permissions are Owners manage billing, members, business details, approvals, exports, deletion and all shared records. Members create and edit shared records, submit documents and send only when approvals permit. Viewers read, download and export without editing or approving. Owners see all workspace activity; Viewers see document activity only. Roles never grant another person access to local PDF or Photo files. The current member limit is 2; how that limit counts each role is two people in total, including the Owner and every Member or Viewer.
We do not decide the customer's lawful basis or replace its duty to assess whether the service is suitable for its data.
4. Instructions and permitted purposes
We process Customer Personal Data only on documented customer instructions, including instructions about overseas transfers. Instructions comprise the completed schedules, this Addendum and lawful operations the customer's authorised users request within that scope. Additional instructions go to support@pagejoy.app and must be recorded.
Within the completed role permissions, authorised instructions may include creating or changing shared records, approving a Templates document, granting or removing a person's membership, changing a role, requesting an export and recording or retrieving the workspace activity log. A member may only issue instructions allowed by that role; an individual account does not authorise instructions for another workspace. Customer instructions concerning a member's access are separate from that person's payment, account or privacy request.
We do not use Customer Personal Data to advertise, sell data or train AI. We do not use AI to process website files. We do not start a new purpose merely by changing a web notice.
If law requires processing beyond the instructions, we inform the customer of that legal requirement before processing, unless the law prohibits notice on important public-interest grounds. We immediately tell the customer if we consider an instruction infringes applicable UK, EU or Member State data protection law. We pause the disputed processing while the parties resolve it, except where law requires it to continue.
We tell the customer promptly if we can no longer comply with this Addendum. The parties must arrange a compliant solution or stop the affected processing.
5. Confidentiality and security
We ensure that people authorised to process Customer Personal Data are bound by confidentiality duties, whether by contract or law. Access is limited to what their authorised work requires.
We apply technical and organisational measures appropriate to the risk under Article 32 UK GDPR and EU GDPR. We assess confidentiality, integrity, availability and resilience, recovery needs and appropriate checking of the measures. The implemented measures are set out in Schedule 2. A security heading or provider claim does not replace a completed schedule. ICO security guidance.
6. Assistance and individual rights
Taking account of the nature of processing, we help the customer respond to individual rights requests using appropriate technical and organisational measures. If a person sends a request about Customer Personal Data directly to us, we promptly tell the customer and do not decide it independently unless authorised or legally required. We preserve the ability to respond within the applicable deadline.
Taking account of the processing and information available to us, we assist with security duties, breach notification, data protection impact assessments and prior consultation with a regulator under Articles 32 to 36. We provide relevant information about our processing, providers, risks and safeguards. The customer makes its own assessment and reporting decisions.
The parties may agree reasonable charges for additional assistance that goes beyond the agreed service. Charges must not delay or prevent legally required assistance or apply to correction of our own breach.
7. Subprocessors
The customer gives general written authorisation for the providers in the completed approved register in Schedule 3. We give written notice at least 30 days before adding or replacing a subprocessor, using written email to the authorised workspace Owner or nominated customer privacy contact. Notice includes its identity, role, data and locations so the customer can assess the change.
The customer may object on reasonable data protection grounds within 14 days by contacting support@pagejoy.app. We discuss the concern before the proposed provider starts the affected processing. We seek a suitable alternative or safeguards. If the concern cannot be resolved, the customer may end the affected service before that processing starts, with the agreed charge adjustment a refund of prepaid charges for the affected service period not supplied, without limiting a larger mandatory remedy. We do not treat an unresolved objection as permission to use that provider for the customer's data.
Before a subprocessor handles Customer Personal Data, we put a binding agreement in place imposing the same applicable data protection duties. We remain responsible to the customer for the subprocessor's performance of those duties. On request we provide relevant information about subprocessor commitments, with only justified redactions.
Subprocessor authorisation and equivalent obligations follow Article 28(2) and (4). EDPB controller and processor guidance.
8. Personal data breaches
We notify the customer without undue delay after becoming aware of a personal data breach involving Customer Personal Data. The initial notice includes information available at the time. We provide further information as it becomes available and do not wait for a complete investigation before notifying.
Information includes the nature of the breach, the data and people affected, approximate numbers where known, likely consequences, measures taken or proposed, and a contact for further information. We investigate, take appropriate containment and remedial steps, and provide information and assistance needed for the customer's notifications. We maintain a record of the incident.
Notice is sent to the workspace Owner email unless the customer provides a different authorised privacy contact through email to the customer-designated privacy contact or workspace Owner. Our incident contact is security@pagejoy.app, or the company registered office if email is unavailable. Any contractual notification target is without undue delay after awareness; provide available facts first and further facts as they become available, without replacing the duty to notify without undue delay.
The customer decides notifications to people and regulators unless the law places a separate duty on us. ICO breach reporting guidance.
9. Compliance information and audits
We provide information needed to show compliance with Article 28 and allow and contribute to audits, including inspections, by the customer or its appointed auditor. Relevant documentation can be reviewed first where sufficient. This does not remove the right to an inspection that is needed to assess compliance.
The parties plan routine audits with reasonable notice, confidentiality and protection of other customers' data. A breach, credible compliance concern or regulator instruction may require shorter notice or additional work. Restrictions on timing, frequency or fees must not defeat the customer's statutory rights. We cooperate with competent regulators.
Required contract information and audit rights are explained in ICO Article 28 contract guidance.
10. Return and deletion
10.1. A member leaves or changes role
When membership ends, authority to access the Business workspace ends on the next server request. The personal account remains. Shared documents and activity remain with the workspace; account purge replaces authorship with a former-member identifier. Previously downloaded or cached copies cannot be recalled.
Ending membership does not itself instruct us to erase the customer's shared business details, clients, items, Templates documents or activity records. We retain or delete those records on the customer's lawful instructions and under the agreed schedule. We assist the customer with a former member's rights request under section 6. The customer must separately address copies the former member already exported or held on a device; our server cannot revoke such copies merely by removing membership. Our independently controlled account and billing records follow the Privacy Notice.
10.2. The Owner cancels and the service ends
Cancellation of renewal by the Owner leaves paid access available until the paid term ends. Cancellation is separate from an instruction to delete Customer Personal Data. During that period we continue the covered processing on the customer's lawful instructions. Access at the paid term's end, any export window, any reduced access and the handling of shared documents are paid access lasts to the displayed end date. After that the free allowance applies and existing shared records remain accessible to authorised roles for viewing and export. Cancelling renewal does not delete the workspace. Shared record retention is until the authorised customer deletes records, closes the workspace or completes an applicable account purge. Older records do not expire automatically, and cancelling renewal does not erase them and activity log retention is until the workspace is closed. Account deletion replaces the former member's identity with a minimised identifier. Older entries do not expire automatically. The customer can request export or deletion through use Export workspace data while signed in to download JSON, and save needed Templates files or browser backups. The Owner can close the Business workspace after paid access ends; contact support for a return, deletion or ownership request.
At the end of the relevant service, the customer chooses return or deletion of Customer Personal Data. Workspace data and browser backups can be downloaded as JSON, and finished Templates documents as PDF. Use Export workspace data while signed in and save any files you need. The Owner can close the Business workspace after paid access ends; the successful closure transaction removes our shared database copies. Any separately required return, provider copy or lawful retention follows the agreed customer instructions and applicable law. Contact support for a return, deletion or ownership request. We confirm completion on request.
If law requires continued storage, we identify the requirement and affected information to the customer unless notice is legally prohibited. We isolate that information from ordinary service use, protect it, use it only as legally required and delete it when the requirement ends. Backup deletion, if backups exist, follows no company-managed backup is made. Exports you download remain on your device until you remove them; account deletion cannot remove those copies and must not permit ordinary reuse.
Temporary server-processing files for an operation expressly included in Schedule 1 are deleted immediately after the result is returned. This section does not allow those files to be kept until a subscription ends. The current panel holds files in memory until you clear them or close the panel; it has no server file-processing path. Any separate server operation and its failure handling must be agreed in Schedule 1 before it is included.
10.3. A person schedules account deletion
A person schedules individual account deletion after a fresh email-code check, together with any enabled 2-step protection. The confirmed request time starts seven complete 24-hour periods in which that person can choose Keep my account in Account settings. The exact deadline is shown. At the request, other sessions and connected-chat grants are revoked. The requesting account session remains available for cancellation. Cancelling does not automatically restore revoked grants or sessions. Further product access during the window is the requesting session may use Account settings and its existing authorised product access before the deadline; other sessions and chat grants are revoked. All ordinary account access ends at the deadline.
An individual account deletion request does not instruct us to delete the business customer's entire workspace or another person's records. At account purge the former member loses workspace authority and their identity in shared records is minimised. Shared documents and activity remain until the customer deletes them or closes the workspace; older records do not expire automatically. A Business Owner must first transfer ownership with support or close the workspace, which requires the paid period to have ended and removes its shared records. Account access ends at the deletion deadline or paid end date, whichever comes first. Payment subscription cancellation through Billing or support is separate from the customer's processing instructions.
After the seven-day cancellation deadline, the account is removed on the next successful cleanup. There is no fixed maximum time until completed cleanup. Retained Customer Personal Data remains subject to the customer's lawful instructions, section 10.2 and this Addendum. Account credentials, authenticator seeds, backup-code hashes and active permissions are not part of a general shared-record retention exception. Shared documents and activity can remain until the workspace closes, with former-member identifiers minimised. Inactive hashed request-limit keys follow their separate retention rules. Personal receipts and account security records are removed at account purge. Stripe retains its separate payment records under its own legal duties, as described in the Privacy Notice. These rules do not allow Customer Personal Data to be kept for unrelated billing or security use.
11. International transfers
We transfer or permit overseas access to Customer Personal Data only on documented instructions and in compliance with applicable transfer law. Schedule 3 records destinations, onward access and the mechanism for each flow. Where a required mechanism or assessment is missing or ceases to be valid, we stop the affected transfer until a lawful solution is in place.
Schedule 4 identifies any transfer contract actually required and executed. This addendum does not attach or execute EU Standard Contractual Clauses, a UK Addendum or an International Data Transfer Agreement. Their official texts must be completed and agreed where needed. An Article 28 agreement and an international transfer safeguard serve different purposes. European Commission SCC explanation.
12. Additional United States processor terms
Where the CCPA applies to the customer and these processing services, we act as a service provider or contractor as appropriate. The limited business purposes are shared Business workspace administration, role-based access, saved invoice and Templates document hosting and retrieval, approvals and the workspace activity log, or a separately approved transient plugin operation, expressly described in Schedule 1. We do not sell or share Customer Personal Data, use it for unrelated commercial purposes, or retain, use or disclose it outside that direct business relationship except as expressly permitted by the CCPA. We do not combine it with other customers' data or our own data except as expressly permitted.
We provide the level of privacy protection required by the CCPA, assist the customer with consumer requests and applicable assessments, and give notice if we cannot meet these duties. The customer may take reasonable steps to check compliance and, on notice, stop and remedy unauthorised use. We bind relevant subcontractors to applicable obligations. We acknowledge and will comply with these restrictions.
These terms reflect CCPA Regulations section 7051. Other applicable state processor requirements are mandatory local processor duties apply where the customer and processing are covered; any required customer-specific addition must be agreed before that processing starts.
13. Other laws, liability and changes
The parties comply with other privacy laws that apply to their processing, including Canadian or Australian duties where relevant. Required additions are mandatory local processor duties apply where the customer and processing are covered; any required customer-specific addition must be agreed before that processing starts. Individual rights and regulator powers are not removed by this agreement.
The agreed allocation of contractual liability and any limits is no separate contractual monetary cap is set; responsibility follows the agreement and applicable law. No term excludes a liability or duty that cannot lawfully be excluded. The applicable law and court provisions are England and Wales, preserving mandatory local rights and any transfer instrument separate court provisions, subject to mandatory law and any transfer instrument's own provisions.
Material changes to this Addendum require the binding variation method a recorded written agreement or explicit electronic acceptance by the authorised parties, preserving the accepted version. We do not reduce agreed protection through a unilateral website update. The parties cooperate to make changes required by new law.
14. Schedule 1: processing details
| Detail | Agreed scope |
|---|---|
| Subject matter | Shared Business workspace records and paid saved invoice details for PageJoy Templates; plugin operations only if expressly included below |
| Nature | Receive, store, retrieve, organise, share within authorised roles, approve, export and delete workspace records as instructed; apply membership permissions and record the workspace activity log; approved plugin flow: receive a file, perform the requested operation, return the result and delete immediately |
| Purpose | Provide the customer's saved invoice and shared Templates work, member access, document approval and activity history, and any expressly approved file operation |
| Data types | Business details, client details, items, logos, Templates documents, approval records, workspace ID, user ID, email and role; invitation records also include intended email, role, status, token hash and expiry and workspace ID, actor ID and email, action, optional document ID and timestamp; document approvals or requested changes can hold the review comment; exact personal fields: business name, contact and address details, tax and payment details, logo, clients, saved items, document type and number, dates, line descriptions, quantities, prices, tax, currency, totals, notes, status, links, approvals and design preferences |
| People concerned | The customer's Owner, Members, Viewers, business contacts, clients and other people identified in its records and Templates documents: customer workspace users, business contacts, clients, suppliers and people the customer identifies in ordinary document fields |
| Duration and frequency | on each authorised save, retrieval, edit, approval, export or deletion while the workspace exists, until return or deletion under the customer instructions; shared records follow until the authorised customer deletes records, closes the workspace or completes an applicable account purge. Older records do not expire automatically, and cancelling renewal does not erase them, activity entries follow until the workspace is closed. Account deletion replaces the former member's identity with a minimised identifier. Older entries do not expire automatically, removal and cancellation follow section 10; transient plugin copies follow immediate deletion |
| Approved plugin operations, if any | none; server plugin processing is not included in this addendum unless the customer and company agree its scope in writing |
| Plugin data and people, if included | none; server plugin processing is not included in this addendum unless the customer and company agree its scope in writing |
| Special category, criminal, children's and other sensitive data | passwords, authentication secrets, complete card details, government identification, regulated health data, criminal-offence records and other sensitive data not required for ordinary business paperwork |
| Authorised customer users and instruction contacts | the current Owner, Members and Viewers within their server-enforced roles; the Owner is the default instruction contact |
| Workspace roles and current limit | Owner, Member and Viewer; permissions: Owners manage billing, members, business details, approvals, exports, deletion and all shared records. Members create and edit shared records, submit documents and send only when approvals permit. Viewers read, download and export without editing or approving. Owners see all workspace activity; Viewers see document activity only. Roles never grant another person access to local PDF or Photo files; current member limit 2, counting rule: two people in total, including the Owner and every Member or Viewer |
| Workspace storage and access locations | a computer operated by our company. Ask support for information about the location relevant to your account |
| Customer rights and duties | Sections 3, 6, 7, 9 and 10, supplemented by no additional instructions unless the customer and company record them in writing |
15. Schedule 2: technical and organisational measures
| Area | Implemented measures and verification reference |
|---|---|
| Access, authentication and least privilege | server-checked sessions, one-use email codes, optional authenticator sign-in, encrypted private account security records, server-enforced workspace roles and request limits. We do not claim an independent security certification |
| Confidentiality and staff procedures | access to customer records is restricted to authorised people who need it for their work |
| Network and data protection | server access is restricted and private account security records are encrypted with a server-held key. We do not claim an independent encryption certification |
| Account and tenant separation | workspace-scoped records, database access checks and server membership checks restrict each request to a current authorised workspace |
| Workspace roles, approval controls and membership revocation | roles are checked server-side for each shared action; removed membership is refused on the next request, Viewers cannot edit and Members cannot approve. Existing exported files cannot be recalled |
| Availability, resilience and recovery | workspace JSON export and browser backup or restore. We do not provide company-managed backups or guarantee disaster recovery or uninterrupted availability |
| Monitoring, incident response and security review | fixed-event diagnostics and manual issue review. We do not offer continuous staffed incident monitoring or claim an independent penetration-test certification |
| Data minimisation, logs and error reports | file contents, file names, signed links, codes, tokens and authenticator secrets are excluded from public diagnostics. Account security and workspace activity remain private and follow their separate retention entries |
| Plugin file handling and immediate deletion | none; server plugin processing is not included in this addendum unless the customer and company agree its scope in writing |
| Export, deletion and backup treatment | authorised JSON exports and browser backups. Closing a workspace deletes its shared database records in one transaction. Account purge removes private factors and account records after the cancellation deadline. We do not make company-managed backups |
| Provider selection and ongoing checks | provider identities and software inventories are recorded. Any provider receiving customer data must have the applicable agreement and transfer safeguards before processing starts |
The measures must be sufficiently specific for the customer to assess protection. No certification, encryption method, penetration test or backup arrangement is represented as implemented until the corresponding verified entry is completed.
16. Schedule 3: subprocessors and locations
Approved entities, functions, data, processing countries, remote-access countries and onward providers: our company-operated database and Cloudflare Workers for website and server-route hosting, with the functions, information and processing and access locations described in our Service Providers register. OpenAI and Anthropic operate separate platform services. Any additional provider must be authorised under this addendum before receiving customer data. Database storage region: a computer operated by our company. Ask support for information about the location relevant to your account. Register version and date: service version 2026-10-04, dated 4 October 2026. Applicable transfer mechanisms for each flow: customer records remain on a computer operated by our company. Any restricted provider transfer requires the applicable safeguards and assessment before it starts.
17. Schedule 4: transfer instruments, if required
Instrument and executed version: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. Parties and contact details: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. EU SCC module and optional choices: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. Annex I, including parties, processing and competent authority: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. Annex II measures: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. Annex III subprocessors where required: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. UK Addendum tables or IDTA tables: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts. Assessment and supplementary measures: not applicable to our current company-operated database. Any restricted international transfer requires a separate assessment and the applicable agreed safeguards before it starts.
18. Schedule 5: acceptance record
Customer authorised signatory or electronic acceptance record: the authorised Owner acceptance recorded in the Business workspace settings. Provider authorised signatory or acceptance record: the company offers this addendum as part of the service terms; no separate named signatory record is published. Agreed schedule version: service version 2026-10-04, dated 4 October 2026. Effective date: the Owner's acceptance when creating the Business workspace. This addendum takes effect for that customer on the recorded acceptance date.