Routario Data Processing Agreement
Effective date: 8 June 2026
This Data Processing Agreement (“DPA”) forms part of the Agreement between the Provider and the Customer for the use of Routario.
1. Parties and Roles
For Customer Data processed in Routario, the Customer is generally the controller and the Provider is the processor.
The Provider is JM Ventures s.r.o., Company ID 07458240, with registered office at Pod Havránkou 656/10a, Troja, 171 00 Prague 7, Czech Republic, unless another provider entity is stated in the Order Form.
For the Provider’s own website, sales, billing, customer account, support, and commercial relationship data, the Provider may act as controller. Such processing is covered by the Privacy Policy, not this DPA.
2. Subject Matter
The Provider processes personal data on behalf of the Customer to provide Routario, including hosting, storage, retrieval, AI-assisted processing, document extraction, workflow automation, CRM-like functionality, support, maintenance, security, backups, and related services.
3. Duration
Processing continues for the duration of the Agreement and any post-termination export or deletion period, unless longer retention is required by law, security, backup, accounting, or dispute-resolution obligations.
4. Nature and Purpose of Processing
Processing may include:
- collection, recording, structuring, storage, retrieval, consultation, use, transmission, alignment, combination, restriction, deletion, and destruction;
- AI-assisted extraction, summarization, classification, drafting, recommendation, and workflow support;
- logging, security monitoring, access control, backups, troubleshooting, and support.
The purpose is to provide Routario and related services to the Customer under the Agreement.
5. Categories of Data Subjects
Depending on Customer use, data subjects may include:
- Customer employees, contractors, and users;
- Customer clients, prospects, leads, suppliers, partners, and other business contacts;
- employees or representatives of third-party organizations stored in CRM or project records;
- individuals mentioned in uploaded documents, notes, emails, transcripts, or project materials;
- other individuals whose personal data is submitted by the Customer.
6. Categories of Personal Data
Depending on Customer use, personal data may include:
- names, titles, roles, employers, departments, contact details;
- CRM notes, relationship context, meeting notes, tasks, preferences, business interests;
- professional history and project involvement;
- communications, documents, attachments, metadata, and extracted information;
- login, audit, usage, device, and security data for authorized users;
- any other personal data submitted by the Customer.
Routario is not intended for special-category personal data, criminal-offence data, children’s data, or highly sensitive private information unless expressly agreed in writing.
7. Customer Instructions
The Provider will process personal data only on documented instructions from the Customer, including as set out in the Agreement, Order Form, product configuration, support requests, and Customer use of Routario.
If the Provider believes an instruction violates applicable data protection law, it will inform the Customer unless prohibited by law.
8. Customer Obligations
The Customer is responsible for:
- establishing and maintaining a valid legal basis for processing personal data;
- providing privacy notices to data subjects where required;
- ensuring the accuracy, relevance, and lawfulness of Customer Data;
- configuring access rights and user permissions;
- responding to data subject requests unless assistance from the Provider is required;
- avoiding unnecessary upload of sensitive or excessive personal data.
9. Provider Obligations
The Provider will:
- process personal data only under the Agreement and Customer instructions;
- ensure persons authorized to process personal data are bound by confidentiality obligations;
- implement appropriate technical and organizational security measures;
- assist the Customer with data subject requests where reasonably possible;
- assist with data protection impact assessments and consultations where required and reasonably possible;
- notify the Customer of personal data breaches as required below;
- delete or return personal data after termination according to the Agreement;
- make available information reasonably necessary to demonstrate compliance with this DPA.
10. Security Measures
The Provider will maintain appropriate technical and organizational measures considering the nature, scope, context, and purposes of processing and the risks to individuals.
Measures may include:
- access controls and least-privilege permissions;
- authentication and user management;
- encryption in transit;
- environment separation where appropriate;
- backups and recovery procedures;
- logging and monitoring;
- vendor and subprocessor controls;
- internal confidentiality obligations;
- vulnerability and incident handling processes.
A more detailed security appendix may be added for enterprise customers.
11. Subprocessors
The Customer authorizes the Provider to use subprocessors to provide Routario, including hosting, infrastructure, AI, email, monitoring, analytics, support, and operational services.
The current list of subprocessors is published in the Subprocessor List. The Provider will impose data protection obligations on subprocessors that are materially equivalent to this DPA.
The Provider will provide a reasonable mechanism for notifying Customers of material subprocessor changes. If the Customer has a reasonable data-protection objection to a new subprocessor, the parties will work in good faith to resolve it. If no reasonable resolution is possible, the Customer may terminate affected services according to the Agreement.
12. International Transfers
Where personal data is transferred outside the European Economic Area, the Provider will ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, Standard Contractual Clauses, or another lawful mechanism under GDPR.
The Provider may provide additional transfer information in the Subprocessor List or security documentation.
13. Personal Data Breach
The Provider will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
The notice will include available information reasonably necessary for the Customer to assess the breach, including the nature of the breach, affected data, likely consequences, measures taken or proposed, and contact point, where such information is available.
The Provider may provide information in stages as it becomes available.
14. Data Subject Requests
If the Provider receives a data subject request relating to Customer Data, it will, where reasonably identifiable as Customer Data, forward the request to the Customer or advise the data subject to contact the Customer, unless prohibited by law.
The Provider will provide reasonable assistance to the Customer in responding to data subject requests, considering the functionality of Routario and the nature of processing.
15. Audits and Compliance Information
The Provider will make available information reasonably necessary to demonstrate compliance with this DPA.
Audits must be reasonable, proportionate, subject to confidentiality, and must not compromise security, other customers’ data, or the Provider’s systems. The Provider may satisfy audit requests through documentation, questionnaires, third-party reports, or other appropriate evidence.
On-site audits require prior written agreement and may be subject to reasonable fees.
16. Deletion and Return
Upon termination or expiry of the Agreement, the Provider will return or delete Customer Data according to the Agreement and product capabilities.
Deletion from backups may occur according to normal backup rotation schedules unless earlier deletion is technically feasible and commercially reasonable.
The Provider may retain limited records where required by law, accounting, security, compliance, or dispute-resolution obligations.
17. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, unless prohibited by applicable law.
18. Governing Law
This DPA is governed by the same law and dispute-resolution provisions as the Agreement.