Data Processing Addendum
This addendum applies whenever Journl Ltd ("Journl", "we") processes personal data inside your books on your behalf. You, the business whose books they are, are the controller of that data; Journl is the processor. It forms part of the terms of service and meets Article 28 of the UK GDPR. Where it and the terms differ on data protection, this addendum wins.
1. Your instructions
We process your personal data only on your documented instructions: these terms, this addendum, and what you do in Journl (raising an invoice instructs us to email it; filing a return instructs us to send it to HMRC). If the law requires us to do something else, we will tell you first unless the law forbids it. If we think an instruction breaks data protection law, we will tell you.
2. Our people
Only people who need access to run or support the service have it, and each is bound to confidentiality. Operator access to a business is recorded.
3. Security
We keep the measures in Annex 2 in place and review them as risks and technology change. We will not reduce the overall protection they give.
4. Sub-processors
You authorise the sub-processors in Annex 3. Before adding or replacing one we will email account owners at least 30 days ahead; if you object on reasonable data protection grounds and we cannot resolve it, you can close your account before the change takes effect. Each sub-processor is bound by written terms giving at least the protection in this addendum, and we remain responsible to you for its work.
5. Helping you answer requests
Journl's own tools let you find, export, correct and delete the people in your books. If someone asks us directly about data in your books, we will pass the request to you within 5 working days and not answer it ourselves, except to say we have done so. We will give reasonable further help when you need it.
6. Personal data breaches
We will tell you without undue delay, and within 48 hours of becoming aware, of any personal data breach affecting your data. We will say what happened, what data and how many people are affected as far as we know, the likely consequences, and what we are doing about it, and keep you updated as we learn more. We will help you meet your own duty to report to the Information Commissioner within 72 hours and to tell the people affected.
7. Other help
We will give you the information you reasonably need for your own security measures, impact assessments and any consultation with the Information Commissioner, as far as it concerns Journl.
8. When you leave
You can export everything at any time before you close your account. After you ask us to close it, your books are kept read-only until their deletion is approved, at most 90 days after your request, and then deleted. Copies in backups are overwritten within a further 35 days and deleted file versions within 30 days. We keep nothing longer unless the law requires it.
9. Showing that we comply
We will make available the information reasonably needed to show we meet this addendum and answer reasonable written questions. Once a year, or after a breach, or when the Information Commissioner requires it, you may audit our compliance, at your own cost, on 30 days' notice, during working hours, under confidentiality, and without access to other customers' data.
10. Transfers outside the UK
Your books are stored in the United Kingdom. Personal data leaves the UK only where a sub-processor in Annex 3 says so, and only with a safeguard UK law recognises: an adequacy decision, or the UK International Data Transfer Agreement or Addendum.
11. Liability
The limits of liability in the terms of service apply to this addendum, except where the law does not allow them to.
Annex 1 — the processing
- Subject matter and purpose: providing Journl, accounting software, to you.
- Duration: while you subscribe, then until deletion as in section 8.
- Nature: storing, organising, calculating, displaying, exporting, emailing on your instruction, sending returns to HMRC on your instruction, and reading uploaded documents to suggest entries.
- People: your customers, suppliers, employees and other contacts, and people you invite to your books.
- Data: names, addresses, email addresses, phone numbers, bank details for payments, invoices and bills, bank statement lines, payroll records, and the contents of documents you upload. Journl is not designed for special category data; please do not put it in your books.
Annex 2 — security measures
- Encryption in transit (TLS) and at rest for the database, backups and files.
- Two-factor sign-in required on every account; signed-in sessions can be ended remotely.
- Each business's data separated in the database itself, not only in the application.
- HMRC access tokens encrypted again under a key held outside the database.
- An append-only audit trail of postings and changes; operator actions recorded separately.
- The database in two London data centres with 35 days of point-in-time recovery and deletion protection.
- Deleting a business requires an authorised operator, a fresh password and the business's name.
Annex 3 — sub-processors
- Amazon Web Services — hosting, database, files, backups and email sending. United Kingdom (London).
- Anthropic — reading bills and receipts you upload or forward, to suggest the supplier, dates and amounts for you to check; only the document is sent and it is not used to train models. United States, under [confirm: the UK transfer safeguard in Anthropic's data processing terms].