Data Processing Agreement
Terms for personal data JustOnAir processes on behalf of customers.
Effective date: 6 October 2026
This Data Processing Agreement ("DPA") is part of the Terms of Service between JustOnAir (the "Processor") and the customer (the "Customer"). It applies to the personal data the Processor processes on the Customer's behalf under Article 28 GDPR and under KVKK.
1. Roles
The Customer is the controller, or a processor acting for its own client. JustOnAir is the processor.
2. Instructions
2.1 We process data only on the Customer's documented instructions. These are the Terms, this DPA, and the Customer's configuration of the Service. 2.2 We inform the Customer if we believe an instruction infringes the law.
3. Confidentiality
Everyone authorised to process the data is bound by confidentiality.
4. Security
We maintain appropriate technical and organisational measures (Annex II).
5. Sub-processors
5.1 The Customer gives general authorisation for the use of sub-processors. The current list is published on our Sub-processors page. 5.2 We give 30 days' notice of any new sub-processor. If the Customer objects on reasonable grounds and the objection cannot be resolved, the Customer may terminate and receive a refund of unused purchased credit. 5.3 Every sub-processor is bound by equivalent obligations. We remain liable for each of them.
6. Assistance
We assist the Customer, as reasonably required, with:
- data subject requests;
- security;
- breach notification;
- data protection impact assessments;
- consultations with supervisory authorities.
7. Breaches
We notify the Customer of a personal data breach without undue delay, and in any case within 48 hours of becoming aware of it.
8. Deletion
We delete Customer data within 30 days of the end of the Service, unless the law requires us to keep it. Backups expire on their regular cycle.
9. Audits
9.1 We provide the information needed to demonstrate compliance. 9.2 The Customer may also audit us, on these conditions:
- 30 days' written notice;
- no more than once a year;
- at the Customer's cost.
10. International transfers
10.1 Data is hosted in the EU and accessed from Türkiye. 10.2 Where required, the EU Standard Contractual Clauses (Decision (EU) 2021/914) are incorporated by reference, as follows:
- Module Two applies where the Customer is a controller. Module Three applies where the Customer is a processor.
- The Customer is the data exporter. JustOnAir is the data importer.
- Clause 7 applies.
- Clause 9(a): Option 2 applies, with 30 days' notice.
- Clause 11: the optional wording does not apply.
- Clause 13: the competent authority is that of the data exporter.
- Clause 17: the law of Ireland applies.
- Clause 18: the courts of Ireland have jurisdiction.
The Annexes below complete the Clauses.
10.3 For UK transfers, the UK International Data Transfer Addendum applies. For Swiss transfers, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection. 10.4 Transfers subject to KVKK rely on KVKK Article 9 safeguards.
11. Government access
We disclose data only under valid legal process, and only the minimum required. We notify the Customer unless the law prohibits it.
12. Precedence
For processing of personal data, this DPA prevails over the Terms. The Standard Contractual Clauses prevail over this DPA.
Annex I: Description of processing
A. Parties
- Data exporter: the Customer, as identified in its account. The Customer accepts this DPA by accepting the Terms.
- Data importer: JustOnAir, as identified in the Legal Notice. Contact: privacy@justonair.com.
B. Processing
| Data subjects | People who appear in the Customer's content; viewers; the Customer's end users |
| Personal data | Audio and video content; metadata supplied by the Customer; viewer IP addresses and technical request data |
| Sensitive data | Only as determined by the Customer's content. Protected by access restriction, encryption in transit and retention limits |
| Frequency | Continuous |
| Nature and purpose | Ingest, processing, storage and delivery of video, to provide the Service and enforce the Acceptable Use Policy |
| Retention | According to the Customer's settings and the Terms |
C. Competent supervisory authority: as determined under Clause 13 of the Standard Contractual Clauses.
Annex II: Security measures
- Encryption in transit.
- Hashed storage of credentials.
- Access control and tenant isolation.
- Restricted administrative access.
- Signed playback links.
- Backups and monitoring.
- Automated retention.
- An incident response process.
Annex III: Sub-processors
As published on our Sub-processors page.