AGREEMENTS

Data Processing Addendum


This addendum applies where Jewell handles personal information as part of delivering services to a client. It forms part of the Terms of Service or MSA.

Last updated: 15 July 2026

This Data Processing Addendum ("DPA") applies where, in delivering services, Jewell handles personal information provided by or on behalf of the client. It forms part of the Terms of Service or the Master Services Agreement between the parties.

Roles and responsibilities

  • The client determines the purposes and means of handling the personal information it provides; Jewell processes that personal information as needed to deliver the agreed services and on the client's documented instructions.
  • Each party is responsible for its own compliance with applicable privacy and data protection law.
  • Jewell will not use client personal information for its own purposes, other than as reasonably necessary to provide, secure and improve the services in a de-identified way.

Privacy Act and Australian Privacy Principles

Jewell handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and in line with its Privacy Policy. The client warrants that it has the authority and any consents required for Jewell to handle the personal information as contemplated by the engagement.

Where the client is subject to the GDPR

Where the client is subject to the EU or UK General Data Protection Regulation, Jewell acts as processor for client personal information and commits, in addition to the above, to:

  • Process personal data only on the client's documented instructions, including on transfers, unless required by law;
  • Ensure people authorised to process the data are bound by confidentiality;
  • Implement appropriate technical and organisational security measures;
  • Engage sub-processors only under written terms that flow down equivalent obligations, and remain responsible for their performance;
  • Assist the client, taking into account the nature of processing, with data-subject requests and with its security, breach-notification and impact-assessment obligations;
  • Notify the client of a personal data breach without undue delay, and in any event within 72 hours of becoming aware where the GDPR applies;
  • On termination, delete or return client personal data at the client's choice, unless retention is required by law.

Sub-processors

Jewell uses a small number of trusted providers to deliver its services. Current categories include:

CategoryProvider (example)Purpose
Cloud hosting & CDNCloudflareWebsite hosting, content delivery and security
Productivity & file storageGoogle Workspace / Google DriveClient asset libraries, documents and collaboration
CRMHubSpotContact, pipeline and campaign management
Transactional emailResendSystem and notification email delivery
AI model providerse.g. AnthropicAI-assisted delivery under human review

The full current list of sub-processors is available on request. On request, Jewell will give the client at least 14 days' notice of material changes to its sub-processors, so the client has a chance to raise any reasonable objection.

Security measures

Jewell maintains security measures appropriate to the risk, including encryption of data in transit, encrypted per-client portal rooms, access controls on a least-privilege basis, multi-factor authentication on core systems, vetting of sub-processors, and internal policies against using client confidential material to train publicly available AI models. More detail is in the Cyber Security & Liability policy.

Overseas disclosure

Delivering the services may involve storing or processing personal information overseas, primarily in the United States of America, through the providers listed above. Jewell takes reasonable steps to ensure those providers handle personal information consistently with this DPA and applicable law.

Audit and information rights

On reasonable written notice and no more than once a year (unless required by a regulator or following a breach), Jewell will provide the client with information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and to protecting other clients' information and Jewell's security.


Jewell Group Pty Ltd. These terms may change without notice; the current version lives here. Questions? hello@jewellai.com.


LEGAL LIBRARY

All of Jewell's terms, in one place.

Business details, policies, service terms by discipline and the agreements behind each engagement.