Data Processing Addendum
Version 1.1 · Effective July 26, 2026
When you run a workspace on JamCrew, you put other people's information into it. Crew members, client contacts, the people your crew list as emergency contacts. That data is yours. We hold it and process it so the product works, and nothing else. This addendum is the contract that says so in the language your legal team and your customers expect.
It is written for the way JamCrew actually works today. If something here does not match what the platform does, the platform is the truth and this page is the bug. Tell us at legal@jamcrew.io and we will fix it.
1. How you accept this, and how to get it signed
You do not need to sign anything. This addendum forms part of the Terms of Service and applies automatically to every customer whose workspace processes personal data, from the moment the workspace is created. There is no form to request and no sales call to sit through.
If your procurement process needs a countersigned copy, email legal@jamcrew.io with your entity name and address and we will sign this document as published, at the version stated above. We countersign. We do not, as a rule, negotiate a bespoke version for a single workspace, because a fleet of one-off contracts is how a small company ends up unable to honor any of them.
2. Definitions
- Customer, you, your. The company or person that agreed to the Terms of Service and operates a JamCrew workspace.
- JamCrew, we, us. Made by Jam LLC, a Georgia limited liability company, based in Gainesville, Georgia, United States, operating the JamCrew platform.
- Customer Data. Personal data that you, your admins, or your crew put into your workspace, or that the platform generates about them while you use it.
- Personal data and data subject carry the meaning given by the data protection law that applies to you. Where that law uses a different phrase, such as personal information or consumer, read it across.
- Controller is the party that decides why and how personal data gets processed. Processor is the party that processes it on the controller's instructions. A subprocessor is a vendor we use to help us do that.
- Data protection law means whichever of these applies to the processing: the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended, and the other US state privacy statutes.
3. Who is the controller and who is the processor
This is the backbone of the whole document, so it goes near the top.
- For Customer Data, you are the controller. You decide who gets invited, what gets recorded about them, how long you keep it, and what you do with it. JamCrew is your processor. We act on your instructions.
- For your own account, we are the controller. Your admin account details, billing records, support conversations, marketing site visits, and product analytics are ours to handle, and they are covered by the Privacy Policy rather than by this addendum.
- If you are yourself a processor, for example because you staff crew on behalf of another company that is the real controller, then we are your subprocessor. Module 3 of the Standard Contractual Clauses covers that case. See section 10.
- You confirm that you have a lawful basis for the data you put into your workspace, and that you gave the required notices to the people in it. The Terms already put that duty on workspace admins. This addendum does not move it.
4. Scope, duration, nature, and purpose
Subject matter and nature. We host and process Customer Data so that the JamCrew platform can do its job: storing crew profiles and skills, publishing and assigning gigs, running schedules and availability, recording check-ins and timesheets, calculating and sending pay, generating tax documents, carrying messages and notifications, searching and booking travel when your workspace uses that feature, and syncing to the accounting tools you choose to connect.
Purpose. Providing, securing, supporting, and maintaining the service for you. Nothing else. We do not sell Customer Data, we do not share it for cross-context behavioral advertising, and we do not use it to train models.
Duration. For as long as your workspace exists, plus the retention windows described in the Terms of Service, plus the short tail during which copies age out of routine backups. This addendum keeps applying to any copy of Customer Data for as long as that copy exists.
5. Categories of data subjects
- Crew members you invite, book, schedule, and pay.
- Workspace admins, producers, and anyone else you give an account to.
- Client contacts: the people at the companies you do work for.
- Emergency contacts and next of kin, named by your crew. These people never sign up, so they are worth remembering when you write your own notices.
6. Categories of personal data
This platform carries real, sensitive material. Pretending otherwise would help nobody, so here is the honest list.
- Identity and contact. Name, legal name, email address, phone number, mailing address, profile photo, home location for travel distance, preferred language.
- Work profile. Roles, skills, certifications and their expiry dates, ratings and notes, availability, bio.
- Scheduling and attendance. Gig assignments, shifts, timesheets, and GPS coordinates captured when a crew member checks in on site.
- Financial. Pay rates, timesheet totals, pay runs, payout records and Stripe Connect account identifiers, the last four digits of a bank account, the last four digits of a tax identification number, and generated 1099-NEC tax documents with total compensation.
- Travel documents. When your workspace books flights through JamCrew, the passenger record includes date of birth, gender, passport number, passport expiry, issuing country, and known traveler number. That data is sent to our flight booking provider. It is called out again on the subprocessor list because it deserves to be seen twice.
- Communications. In-app messages, email we send on your behalf, and SMS records including the body of the message.
- Uploaded documents. Whatever your workspace puts in document storage: contracts, tax forms, identification, certifications.
- Device and technical. IP address, browser and device information, push notification subscriptions, and security and diagnostic logs.
Several of these count as sensitive personal data under one law or another. Passport numbers, tax identifiers, and precise geolocation are the obvious ones. You control what goes into your workspace. If you upload something we never asked for, it is still Customer Data and this addendum still covers it.
7. What we commit to as your processor
- Documented instructions. We process Customer Data only on your instructions. Your instructions are the Terms of Service, this addendum, the settings and configuration your admins choose in the product, and the support requests you send us. We may also process where a law we are subject to requires it, and where we are allowed to say so, we will tell you first. If an instruction looks to us like it breaks data protection law, we will tell you rather than quietly carry it out.
- Confidentiality. Everyone who can reach Customer Data is bound to keep it confidential, by contract or by law, and that duty outlasts their involvement.
- Security. See section 8.
- Helping with data subject requests. If a crew member or client contact asks you to access, correct, export, or delete their record, most of it you can do yourself inside the workspace. Where you cannot, email privacy@jamcrew.io and we will help, within a reasonable time and at no charge for a reasonable volume of requests. If a request comes to us directly, we will not answer it on your behalf. We will point the person to you and let you know it happened.
- Helping with assessments. Taking into account what we know and what we can see, we will give you reasonable help with data protection impact assessments and with any prior consultation with a regulator, to the extent it concerns our processing.
- Breach notification. See section 9.
- Deletion or return. See section 11.
- Information and audit. See section 12.
8. Security measures
We keep technical and organizational measures appropriate to the risk. Concretely, today:
- Traffic between your browser and JamCrew, and between JamCrew and its subprocessors, runs over TLS.
- Each workspace is a separate tenant. Access control is enforced in the application layer, in TypeScript query and mutation functions that check the caller against the workspace on every read and every write. It is not enforced by database row policies, and we name the mechanism rather than the buzzword so you can assess it.
- Authentication is handled by Clerk. You can sign in with an email address or with Google, Apple, or Microsoft, and you can add an authenticator app as a second factor on your account.
- Production access is limited to the people who need it to operate and support the service.
- Diagnostic and analytics payloads pass through a sanitizer before they leave the browser. Email addresses are redacted, URLs are cut back to origin and path so query strings never travel, and keys carrying contact, identity, financial, location, or credential material are dropped. Session replay masks input fields and text by default and is switched off entirely on sign-in, settings, billing, payroll, payments, invoices, onboarding, and account routes.
- We review a subprocessor before it touches Customer Data, and we publish the list.
What we will not do is claim a certification we do not hold. JamCrew has no SOC 2 report and no ISO 27001 certificate today. If your procurement process requires one, tell us at legal@jamcrew.io so we know how much it matters and to whom. Several of our infrastructure subprocessors do hold those certifications, and we can point you at their reports, but that is their audit and not ours.
9. Personal data breaches
If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay. Notice goes to the admin contacts on your workspace and to any security contact you have given us.
The first notice will carry what we actually know at that point: what happened, which categories of data and roughly how many records are involved if we can tell, what we are doing about it, and who to talk to. We will keep updating you as we learn more. We would rather send you a short, true notice quickly than a complete one late.
We are deliberately not promising a fixed hour count here. A number we could miss is worth less to you than a commitment we will keep. Notifying the regulator and the affected people is your call as controller, and we will give you what you need to make it.
10. Subprocessors
General written authorization. You give us general written authorization to use subprocessors. The current list, with what each one does and where it is, lives at jamcrew.io/subprocessors. By agreeing to the Terms you approve every subprocessor on that list as of the date you sign up.
- Our duty to them. Before a subprocessor receives Customer Data, we put it under written terms that are no less protective than this addendum. If a subprocessor fails to meet its data protection obligations, we remain responsible to you for its performance.
- Notice of changes. When we intend to add or replace a subprocessor, we update the subprocessor page and notify subscribers at least 30 days before the new one starts processing Customer Data. To get those notices, email legal@jamcrew.io with the subject line Subprocessor updates and the address you want them sent to.
- Objection. You have 30 days from the notice to object, in writing, on reasonable data protection grounds. Tell us what the concern is. We will try to find a way to give you the service without the change, for example by turning off the feature that needs it. If we cannot, you may terminate the affected subscription by written notice before the change takes effect.
- Emergencies. If we have to replace a subprocessor urgently to keep the service running or to close a security problem, we will make the change and tell you as soon as we reasonably can, with the reason. Your objection right still applies afterward.
- Optional integrations. Some subprocessors only ever see your data because one of your admins connected them. Those are marked on the list. Connecting one is your instruction to send data to it.
Cancelling for any other reason follows the billing rules in Section 9 of the Terms of Service.
11. International transfers
JamCrew is a United States company. Our infrastructure and most of our subprocessors are in the United States. If you or the people in your workspace are in the European Economic Area, the United Kingdom, or Switzerland, Customer Data will be transferred to the United States. This section is the mechanism that covers it.
Standard Contractual Clauses
Where the EU GDPR applies to a transfer, the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this addendum by reference. Incorporation by reference means the full text of those clauses is not reprinted here but is treated as though it were written out in this document, word for word, and binds both parties on that basis. You can read the official text on the Commission's website. Where the clauses and this addendum disagree, the clauses win.
- Module 2 applies where you are a controller and we are your processor. That is the usual case.
- Module 3 applies where you are a processor acting for someone else who is the controller, and we are your subprocessor.
- Clause 7, the docking clause, applies.
- Clause 9, Option 2, general written authorization, applies, with the 30 day notice period described in section 10.
- Clause 11: the optional independent dispute resolution body language does not apply.
- Clause 17, Option 1: the clauses are governed by the law of Ireland.
- Clause 18(b): disputes go to the courts of Ireland.
- Annex I is filled in by sections 3, 4, 5, and 6 of this addendum. You are the data exporter, Made by Jam LLC is the data importer, and the contact point for both is the address each party has given the other. Under Clause 13, the competent supervisory authority is the Irish Data Protection Commission unless the law that applies to you points somewhere else, in which case it points there.
- Annex II, the technical and organizational measures, is section 8.
- Annex III, the list of subprocessors, is the subprocessor page as it stands from time to time.
United Kingdom
Where the UK GDPR applies, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, is incorporated by reference and amends the clauses above for UK transfers. Its tables are completed by this addendum: Table 1 by the parties and details in sections 2 and 3, Table 2 by the Module 2 or Module 3 selection above, Table 3 by the annexes listed above, and in Table 4 the party that may end the addendum under Section 19 is the importer.
Switzerland
Where the Swiss Federal Act on Data Protection applies, the clauses above apply with these readings: the Federal Data Protection and Information Commissioner is the competent authority, references to the GDPR are read as references to the Swiss Act, references to a member state do not stop a data subject in Switzerland from suing where they live, and the clauses protect the data of legal entities until Swiss law says otherwise.
We do not rely on the EU-US Data Privacy Framework for transfers to JamCrew. We rely on the clauses above. Some of our subprocessors maintain their own transfer mechanisms, including framework certifications and their own contractual clauses. Those are their arrangements, published on their own sites, and they sit alongside ours rather than replacing it.
12. Deletion and return
You can export Customer Data from your workspace at any time while your subscription is active. Do that before you leave, because it is the fastest route and it does not need us.
When your workspace ends, we delete or return Customer Data according to the retention windows in the Terms of Service, unless a law requires us to keep something longer, which happens with financial and tax records. Copies may sit in routine backups for a short period until those backups cycle out. Until they are gone, they stay covered by this addendum and nobody works with them.
13. Information and audit
We will give you the information you reasonably need to show that we are meeting our obligations here. Start by asking. Most questions get answered in an email, and that is faster for both of us than an audit.
If that is not enough, you may audit our processing of your Customer Data no more than once in any twelve month period, on at least 30 days written notice, during business hours, at your own cost, under confidentiality, and in a way that does not disturb other customers or reach anyone else's data. A regulator with authority over you may audit whenever the law lets it. If a particular audit takes substantial time from us, we may charge for that time at a reasonable rate, agreed with you in advance.
14. California and other US state privacy laws
For Customer Data, JamCrew is a service provider or processor as those terms are used in the California Consumer Privacy Act and the comparable state laws. That means:
- We do not sell Customer Data and we do not share it for cross-context behavioral advertising. There is no version of the product where we do.
- We do not keep, use, or disclose Customer Data for any purpose other than performing the services for you, or as the law otherwise permits a service provider to act. We do not combine it with data from other sources except as the law allows on your behalf.
- We do not process it outside our direct relationship.
- We will tell you if we determine that we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorized use.
- You may take those same reasonable and appropriate steps to confirm that we use Customer Data in a way consistent with your obligations under those laws. Section 13 is how.
15. Order of precedence, liability, and changes
- Precedence. For the processing of Customer Data, this addendum controls over anything inconsistent in the Terms of Service. For transfers covered by them, the Standard Contractual Clauses control over this addendum.
- Liability. Each party's liability under this addendum is subject to the limits and exclusions in the Terms of Service, except where the law does not allow that. The Standard Contractual Clauses carry their own liability terms for the transfers they cover, and nothing here cuts those down.
- Changes. We may publish a new version of this addendum, for example when the law changes or when the product does. Material changes get at least 30 days notice by email or a prominent notice on the platform before they take effect. Each version carries a version number and an effective date, at the top of the page.
- Everything else. Governing law, venue, dispute resolution, and the rest of the general terms are in the Terms of Service and are not repeated here.
Contact
Made by Jam LLC, Gainesville, Georgia, United States.
- Contracts and countersignature: legal@jamcrew.io
- Privacy questions and data subject requests: privacy@jamcrew.io
- Related pages: Subprocessors, Privacy Policy, Your Privacy Choices, Terms of Service
Version 1.1 · Last updated: July 26, 2026