Version 28.08.26
Effective date 28 August, 2026
1. Purpose, parties and language
2. Roles
3. Scope of the processing
4. Instructions
5. The Controller’s obligations
6. Confidentiality
7. Technical and organisational security measures
8. Sub-processors
9. Transfers to third countries
10. Assistance
11. Personal data breaches
12. Audit
13. Remuneration for extraordinary assistance
14. Storage and erasure
15. Liability
16. Entry into force and amendments
This data processing agreement (the “Agreement”) is entered into pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”) and constitutes an addendum to the agreement on the provision of services entered into between the parties, including JED ApS’ Terms of Service as in force from time to time (the “Main Agreement”).
In the event of any inconsistency between the Main Agreement and this Data Processing Agreement, this Data Processing Agreement shall prevail to the extent the inconsistency concerns the processing of personal data or the parties’ obligations under applicable data protection legislation.
The Agreement governs the Processor’s processing of personal data on behalf of the Controller in connection with the provision, operation and support of:
a) the JEDWare platform, cf. Service Schedule A, and
b) Telephony and IT Services, including hosted 3CX telephony, cf. Service Schedule B
The scope of the processing depends on which of the Processor’s services the Controller has purchased.
The parties agree that amendments to applicable data protection legislation which directly affect the parties’ rights or obligations under this Agreement shall automatically be deemed incorporated into the Agreement from the time such amendments enter into force.
1.1 Processor
JED ApS
Bogensevej 90, DK-5270 Odense N
Denmark
VAT Number (CVR): DK35653821
Website: www.jed-ware.com
1.2 Language
This Data Processing Agreement has been prepared in Danish.
The Processor makes an English translation available for the convenience of customers. In the event of any inconsistency between the two language versions, the Danish version shall prevail.
The Controller (the “Customer”) determines the purposes and means of the processing of personal data, including which personal data are processed, why they are processed and for how long they are stored.
JED ApS (the “Processor”) processes personal data solely on behalf of and on documented instructions from the Controller and acts in that connection as processor within the meaning of Article 4(8) GDPR.
JED ApS may not process personal data for its own purposes and acquires no independent rights in the personal data processed on behalf of the Controller.
The Controller is responsible for ensuring that a valid legal basis exists for the processing of personal data, including any requirements as to information to data subjects, consent, retention periods and other obligations under applicable data protection legislation.
If the Controller activates 3CX’s cloud-based transcription or AI features, the Processor may use 3CX as a sub-processor to the extent 3CX processes personal data on the Processor’s behalf. If these features are not used, or if the processing takes place exclusively locally, 3CX is regarded solely as a software supplier.
To the extent the Processor is required by law to record or retain information, such processing does not take place on behalf of the Controller. The Processor is an independent controller in respect of such processing, and the processing is not covered by this Agreement.
The Processor collects usage statistics from the JEDWare Platform as part of the provision of the Services, cf. § 3.2. The Processor is entitled to use aggregated and anonymised results thereof for the operation, troubleshooting, security and further development of the Services, provided that such results cannot be attributed to the Controller or to any data subject.
The Processor processes personal data for the purpose of providing, operating, supporting and securing the Services in accordance with the Controller’s documented instructions, this Agreement and the Main Agreement.
For all Services, the processing comprises the creation and administration of user accounts, access management, authentication, troubleshooting and technical support, as well as activity and usage logs generated through the use of the Services.
The processing comprises the collection, aggregation, processing and presentation of data from the Controller’s telephony, communications and other business systems for the purposes of dashboards, wallboards, reports, real-time and historical statistics, notifications, integrations and API access.
The processing includes call metadata such as time, duration, direction, queue and agent status, and the telephone numbers of the parties involved, to the extent such information is transferred to the platform from the Controller’s systems.
The processing further comprises the collection of usage statistics for the purposes of operation, troubleshooting, security and further development of the platform. The statistics record which pages and features are used, together with technical information such as browser, operating system, screen size and language.
Usage statistics are collected using Umami, an open-source analytics platform hosted by the Processor on its own servers. No cookies or browser storage are used, and the statistics are therefore not subject to cookie consent. No user profile is created. Users are distinguished by an anonymised identifier that is recalculated daily and that can neither be followed across days nor attributed to a named user account. The IP address is processed momentarily in order to derive the identifier and a location at country level, and is not stored.
Name, username, email address, entered content, screen or session recordings and stored IP addresses are not collected.
The statistics are aggregated and do not identify individuals. The processing forms part of the provision of the Services and is carried out on the Controller’s instructions. The Processor is entitled to use aggregated and anonymised results thereof for the further development of the platform, cf. § 2.
Where the Controller has purchased hosted 3CX telephony from the Processor, the processing further comprises operation of the telephone system, call handling, call recording, transcription of calls, voicemail, replication, backup, monitoring and technical support.
The processing may comprise personal data relating to:
· The Controller’s employees
· The Controller’s customers
· Suppliers and business partners
· Users of the JEDWare Platform, including administrators
· Other persons taking part in telephone conversations
The processing may comprise:
· Name, telephone number and email address
· Internal extension numbers and IP addresses
· Call metadata
· Call recordings and transcriptions
· AI-generated summaries and analyses, where such features are used
· User account and login information
· Activity and usage logs in the platform
· Statistical and report data derived from the above
The processing comprises collection, storage, organisation, making available, transcription, replication and erasure.
The Processor may not use the information for its own purposes.
The Processor may process personal data only on documented instructions from the Controller, unless the processing is required under EU law or Danish law.
The Controller’s documented instructions consist of the Main Agreement, this Data Processing Agreement and any subsequent written instructions from the Controller.
The Controller is responsible for determining the purposes of the processing, including whether telephone conversations are recorded, whether transcription is activated, which persons are given access to the information, and for how long the information is stored within the framework set out in §14.
If the Processor considers that an instruction infringes applicable data protection legislation, the Processor shall immediately inform the Controller.
The Controller is responsible for ensuring that:
• a valid legal basis for the processing exists
• data subjects receive the necessary information
• any consent is obtained where required
• call recordings and transcription are used lawfully
• instructions to the Processor are lawful
The Processor ensures that employees with access to personal data:
• are subject to a duty of confidentiality
• have access only on a need-to-know basis
• receive appropriate instruction on the processing of personal data
The duty of confidentiality continues to apply after termination of employment.
The Processor has implemented appropriate technical and organisational security measures, having regard to:
• The nature of the processing
• The scope of the processing
• The risks to the rights of data subjects
• The state of the art
• Encrypted connections (TLS)
• Role-based access control
• Strong passwords and multi-factor authentication where possible
• Firewall protection
• Ongoing security updates
• Antivirus or EDR protection
• Logging of administrator activity
• Restricted access to servers
• Recovery procedures
• Internal procedures for security incidents
• Hosting with a cloud provider within the EU/EEA
• Encryption of data at rest
• Segregation of customer data within the platform
• Logging of access and administrator actions
• Backup of platform data
• Copy of 3CX to a separate replication server
• Backup of 3CX
• Backup of virtual servers
The Processor reviews the security measures on an ongoing basis and adapts them as necessary, having regard to the state of the art and the risk landscape.
JED ApS may use the following sub-processors to carry out specific processing activities on behalf of the Controller.
Sub-processor | Service schedule | Purpose | Location |
3CX Ltd. | B | Cloud-based transcription and AI features | EEA and any third countries in accordance with the GDPR |
OVHcloud | B | Replication server and backup | Poland |
Google Cloud | A | Hosting of the JEDWare platform | Belgium |
The Processor ensures that all sub-processors are subject to data protection obligations at least equivalent to those set out in this Data Processing Agreement and applicable data protection legislation.
The Processor is liable to the Controller for the processing carried out by sub-processors to the same extent as if the processing had been carried out by the Processor itself.
By entering into the Main Agreement, the Controller gives general authorisation for the Processor’s use and replacement of sub-processors. The Controller will be notified with reasonable notice of any material changes.
As a general rule, the Processor does not transfer personal data outside the EU/EEA.
Personal data may only be transferred to countries outside the area in which the relevant data protection legislation recognises an adequate level of protection where a valid transfer basis exists, including an adequacy decision, standard contractual clauses (SCCs) or another lawful transfer mechanism.
The Processor assists the Controller with reasonable and necessary measures relating to:
• access
• rectification
• erasure
• restriction of processing
• data portability
• objections
• data protection impact assessments (DPIAs)
• dialogue with the Danish Data Protection Agency (Datatilsynet)
In the event of a personal data breach, the Processor shall notify the Controller without undue delay after becoming aware of the breach.
The notification shall as a minimum contain:
• The nature of the incident
• The information affected
• The likely consequences
• Remedial measures already taken or planned
• Contact person
The Processor assists the Controller in handling the security breach.
Notification under this provision is sent to the contact person registered with the Processor by the Controller. It is the Controller’s responsibility to ensure that the contact details are correct and up to date.
The Controller is entitled once a year to request reasonable documentation of the Processor’s compliance with this agreement, including information on technical and organisational security measures, the sub-processors used and relevant procedures for the processing of personal data.
If, in the Controller’s reasonable assessment, the documentation provided is not sufficient, the Controller may request that an audit or inspection be carried out.
An audit shall be notified in writing with at least 30 days’ notice and shall be carried out in a manner that does not unduly disrupt the Processor’s operations or compromise the security or confidentiality of other customers.
The Controller bears its own costs in connection with the audit. The Processor’s time spent in connection with audits and inspections is invoiced in accordance with §13.
The Processor provides the assistance that follows from this agreement and applicable data protection legislation.
If the Controller requests assistance, documentation, investigations, reporting, audits, attendance at meetings or other services that go beyond the Processor’s statutory or agreed obligations, the Processor is entitled to charge reasonable remuneration for this.
Notification and assistance under §11 in connection with personal data breaches are not invoiced separately, to the extent the assistance follows from the Processor’s obligations under the GDPR.
Any remuneration is governed by the Main Agreement between the parties or, if nothing else has been agreed, by the Processor’s hourly rates as in force from time to time.
Data in the JEDWare Platform is stored for as long as the subscription is active and is deleted upon termination in accordance with §14.3.
Usage statistics under §3.2 are retained for up to 12 months and are then deleted.
Unless otherwise agreed, call recordings, voicemail and transcriptions are stored for up to 90 days on the Processor’s server.
The Controller may agree a shorter or longer retention period with the Processor. A change to the retention period may give rise to separate remuneration under §13 as well as any additional storage costs.
Replication of the 3CX server is carried out to a separate replication server and is overwritten every 15 minutes. This replication server is located either with the Processor or with the sub-processor designated in §8 for replication and backup.
The Processor shall, upon request, inform the Controller which location is used for the Controller’s data.
Upon termination of the Main Agreement, the Controller may within 30 days request the return of personal data.
If the Controller does not instruct the Processor otherwise, the Processor is entitled and obliged to delete the personal data after expiry of the retention period.
Unless otherwise agreed or required by law, all personal data are deleted no later than 90 days after termination of the agreement, irrespective of any longer retention period agreed under §14.2.
Each party is responsible for compliance with its respective obligations under the GDPR.
Liability is otherwise governed by the Main Agreement between the parties.
This Data Processing Agreement enters into force at the same time as the Customer’s entry into the Main Agreement and applies for as long as the Processor processes personal data on behalf of the Controller.
By entering into the Main Agreement, the Customer simultaneously accepts this Data Processing Agreement.
The Processor may update this Data Processing Agreement where necessary as a result of changes in applicable legislation, regulatory requirements, security conditions, the functionality of the services or the Processor’s use of sub-processors.
Material changes are communicated to the Customer with reasonable notice before they enter into force.
The version of the Data Processing Agreement in force from time to time is available at www.jed-ware.com/en/data-processing-agreement, where both the Danish and the English version are available. The Danish version is the binding version, cf. §1.2.
We use cookies and similar technologies to operate and improve our website, analyse website usage, and support functionality and marketing. You can choose which categories you consent to.