Data Processing Addendum
Last updated: May 24, 2026
Table of contents
1. Scope and Relationship to Terms
This Data Processing Addendum ("DPA") forms part of the Terms of Service, order form, subscription agreement, or other written agreement between Joby CRM LLC ("Joby") and the customer using the Service ("Customer").
This DPA applies when Joby processes Customer Data that includes personal data, personal information, or similar regulated information on Customer's behalf. If this DPA conflicts with the Terms, this DPA controls only for data processing obligations.
2. Roles of the Parties
For Customer Data, Customer is generally the controller, business, or equivalent decision maker, and Joby is generally the processor, service provider, or equivalent service provider.
Customer determines the purposes and means of processing Customer Data, including what data is entered into Joby, which users are invited, which features are enabled, how long data is retained, and how data is used for Customer's business.
Joby processes Customer Data only to provide, secure, support, maintain, and improve the Service, comply with Customer's documented instructions, comply with law, and perform obligations under the agreement.
3. Processing Details
Subject matter: cloud CRM, communications, scheduling, dispatch, estimates, invoicing, payments, AI, reporting, time tracking, and workforce location features.
Duration: the subscription term plus any post-termination export, backup, deletion, or legal retention period described in the agreement and Data Retention Policy.
Nature and purpose: hosting, storage, retrieval, display, transmission, analysis, transcription, AI-assisted generation, authentication, authorization, logging, support, billing, security, and product operations needed to provide the Service.
Categories of data subjects may include Customer's employees, contractors, subcontractors, authorized users, leads, prospects, customers, vendors, account contacts, and other people whose information Customer submits to the Service.
Categories of Customer Data may include names, email addresses, phone numbers, addresses, job details, notes, estimates, invoices, messages, call metadata, call recordings, transcriptions, payment metadata, files, photos, time entries, GPS proof, live location route points, device/app metadata, and audit logs.
4. Customer Obligations
Customer is responsible for:
- Providing lawful instructions to Joby
- Having all rights, notices, and consents needed to collect and process Customer Data
- Maintaining its own privacy notices, employee/contractor notices, customer notices, and consent records
- Responding to privacy requests from data subjects where Customer is the controller/business
- Configuring permissions, retention, exports, integrations, and deletion settings appropriately
- Using the Service in compliance with applicable privacy, employment, communications, consumer protection, and recordkeeping laws
5. Joby Obligations
Joby will:
- Process Customer Data only on Customer's documented instructions, unless required by law
- Ensure personnel authorized to process Customer Data are subject to confidentiality obligations
- Maintain reasonable administrative, technical, and organizational security measures
- Assist Customer with data subject requests, security incidents, and privacy assessments where required and reasonably possible
- Make available information reasonably necessary to demonstrate compliance with this DPA
- Delete or return Customer Data after termination according to the agreement, Data Retention Policy, backup cycles, and legal retention requirements
6. Security Measures
Joby's security program includes reasonable measures such as:
- TLS encryption in transit
- Provider-supported encryption at rest
- Role-based access controls and organization-level data separation
- Authentication and authorization controls
- Logging and monitoring for security and operations
- Restricted administrative access to production systems
- Backup and recovery processes
- Vendor review for key subprocessors
- Incident response procedures
Customer is responsible for its own user access reviews, endpoint security, passwords, device controls, exported data, and internal policies.
7. Subprocessors
Customer gives Joby general authorization to use subprocessors needed to provide the Service. Joby's current subprocessor list is published at /subprocessors.
Joby will impose written obligations on subprocessors that are materially similar to the data protection obligations in this DPA. Joby remains responsible for subprocessors' performance of their data processing obligations to the extent required by applicable law.
Joby will provide notice of material subprocessor changes by updating the subprocessor page and, where reasonable, emailing the primary account contact or customers who requested subprocessor notices.
8. International Transfers
Joby is based in the United States and primarily processes data in the United States. Where Customer Data is transferred from the EEA, United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the parties will use legally recognized transfer mechanisms where required.
For EEA transfers, the parties incorporate the European Commission Standard Contractual Clauses as applicable. For UK transfers, the parties incorporate the UK International Data Transfer Addendum or other valid transfer mechanism as applicable.
Customer may request the applicable transfer annexes by emailing legal@joby.io.
9. CCPA/CPRA Service Provider Terms
For Customer Data subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act, Joby acts as a service provider/contractor for Customer.
Joby will not sell or share Customer Data for cross-context behavioral advertising. Joby will not retain, use, or disclose Customer Data outside the direct business relationship with Customer except as permitted by law, the agreement, and Customer's instructions.
Joby may process Customer Data to provide the Service, secure the Service, detect incidents, prevent fraud or illegal activity, debug, repair errors, perform analytics and internal improvements permitted for service providers, comply with law, and meet contractual obligations.
10. Data Subject Requests
If Joby receives a privacy request relating to Customer Data, Joby may direct the requester to Customer unless applicable law requires otherwise. Customer is responsible for responding to requests where Customer is the controller/business.
Joby will provide reasonable assistance using available product tools and support channels. Assistance requiring engineering, custom exports, legal review, or exceptional effort may be subject to reasonable fees where permitted by law and contract.
11. Security Incidents
Joby will notify Customer without undue delay after confirming a security incident affecting Customer Data in Joby's systems, where required by law or agreement.
Notice may include, to the extent known and legally permitted, the nature of the incident, affected data categories, likely consequences, remediation steps, and recommended customer actions. Customer is responsible for any notices to its own users, employees, customers, regulators, or other parties unless law assigns that obligation to Joby.
12. Audits and Compliance Information
Upon reasonable request, Joby will provide available security and compliance information such as a security overview, subprocessor list, data retention information, and responses to reasonable security questionnaires.
On-site audits are not available for standard plans. Enterprise customers may request additional review rights in a signed order form or enterprise agreement. Audits must not compromise Joby's systems, security, confidentiality obligations, or other customers' data.
13. Return and Deletion
Customer may export Customer Data using available product tools or request reasonable support. After termination, Joby generally provides a limited export period before deleting Customer Data from active systems.
Deletion from backups, provider logs, and disaster recovery systems occurs through ordinary backup rotation and retention cycles. Joby may retain limited records where required for legal, tax, security, fraud prevention, billing, dispute, or compliance purposes.
14. Contact and Signature Requests
To request a countersigned DPA, email legal@joby.io with:
- Customer legal entity name
- Billing account email
- Signatory name/title
- Whether GDPR, UK GDPR, CCPA, or another law is the driver
- Any required vendor portal link or deadline
Joby CRM LLC
1180 South Beverly Drive
Los Angeles, CA 90035
United States
