Routario Data Processing Agreement

Effective date: 8 June 2026

This Data Processing Agreement (“DPA”) forms part of the Agreement between the Provider and the Customer for the use of Routario.

1. Parties and Roles

For Customer Data processed in Routario, the Customer is generally the controller and the Provider is the processor.

The Provider is JM Ventures s.r.o., Company ID 07458240, with registered office at Pod Havránkou 656/10a, Troja, 171 00 Prague 7, Czech Republic, unless another provider entity is stated in the Order Form.

For the Provider’s own website, sales, billing, customer account, support, and commercial relationship data, the Provider may act as controller. Such processing is covered by the Privacy Policy, not this DPA.

2. Subject Matter

The Provider processes personal data on behalf of the Customer to provide Routario, including hosting, storage, retrieval, AI-assisted processing, document extraction, workflow automation, CRM-like functionality, support, maintenance, security, backups, and related services.

3. Duration

Processing continues for the duration of the Agreement and any post-termination export or deletion period, unless longer retention is required by law, security, backup, accounting, or dispute-resolution obligations.

4. Nature and Purpose of Processing

Processing may include:

The purpose is to provide Routario and related services to the Customer under the Agreement.

5. Categories of Data Subjects

Depending on Customer use, data subjects may include:

6. Categories of Personal Data

Depending on Customer use, personal data may include:

Routario is not intended for special-category personal data, criminal-offence data, children’s data, or highly sensitive private information unless expressly agreed in writing.

7. Customer Instructions

The Provider will process personal data only on documented instructions from the Customer, including as set out in the Agreement, Order Form, product configuration, support requests, and Customer use of Routario.

If the Provider believes an instruction violates applicable data protection law, it will inform the Customer unless prohibited by law.

8. Customer Obligations

The Customer is responsible for:

9. Provider Obligations

The Provider will:

10. Security Measures

The Provider will maintain appropriate technical and organizational measures considering the nature, scope, context, and purposes of processing and the risks to individuals.

Measures may include:

A more detailed security appendix may be added for enterprise customers.

11. Subprocessors

The Customer authorizes the Provider to use subprocessors to provide Routario, including hosting, infrastructure, AI, email, monitoring, analytics, support, and operational services.

The current list of subprocessors is published in the Subprocessor List. The Provider will impose data protection obligations on subprocessors that are materially equivalent to this DPA.

The Provider will provide a reasonable mechanism for notifying Customers of material subprocessor changes. If the Customer has a reasonable data-protection objection to a new subprocessor, the parties will work in good faith to resolve it. If no reasonable resolution is possible, the Customer may terminate affected services according to the Agreement.

12. International Transfers

Where personal data is transferred outside the European Economic Area, the Provider will ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, Standard Contractual Clauses, or another lawful mechanism under GDPR.

The Provider may provide additional transfer information in the Subprocessor List or security documentation.

13. Personal Data Breach

The Provider will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.

The notice will include available information reasonably necessary for the Customer to assess the breach, including the nature of the breach, affected data, likely consequences, measures taken or proposed, and contact point, where such information is available.

The Provider may provide information in stages as it becomes available.

14. Data Subject Requests

If the Provider receives a data subject request relating to Customer Data, it will, where reasonably identifiable as Customer Data, forward the request to the Customer or advise the data subject to contact the Customer, unless prohibited by law.

The Provider will provide reasonable assistance to the Customer in responding to data subject requests, considering the functionality of Routario and the nature of processing.

15. Audits and Compliance Information

The Provider will make available information reasonably necessary to demonstrate compliance with this DPA.

Audits must be reasonable, proportionate, subject to confidentiality, and must not compromise security, other customers’ data, or the Provider’s systems. The Provider may satisfy audit requests through documentation, questionnaires, third-party reports, or other appropriate evidence.

On-site audits require prior written agreement and may be subject to reasonable fees.

16. Deletion and Return

Upon termination or expiry of the Agreement, the Provider will return or delete Customer Data according to the Agreement and product capabilities.

Deletion from backups may occur according to normal backup rotation schedules unless earlier deletion is technically feasible and commercially reasonable.

The Provider may retain limited records where required by law, accounting, security, compliance, or dispute-resolution obligations.

17. Liability

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, unless prohibited by applicable law.

18. Governing Law

This DPA is governed by the same law and dispute-resolution provisions as the Agreement.