Jelto legal

Data Processing Agreement

Review how Jelto processes data on your behalf. Prepare a copy for your organization.

Last updated

Prepare your copy

Fill in your details to update the agreement below.

Stays in your browser
Customer and collection details

Opens your browser’s print dialog. Choose “Save as PDF” to download a copy.

Details stay on this page and are not sent to Jelto or saved in browser storage. Preparing a copy does not sign the agreement.

Customer legal nameNot provided
Proposed effective dateNot provided
Customer addressNot provided
Contact emailNot provided
CollectionCookieless website

1. Parties and relationship

This DPA is between the Customer identified above and Taha Bozdemir, operating as Jelto. Contact: [email protected]. This proposed copy is not an executed agreement; it takes effect when validly agreed by both parties.

The Customer is the controller, or an authorized processor; Jelto is its processor or subprocessor. Jelto separately controls account, billing and security data under the Privacy Policy.

This DPA supplements the Terms and prevails for customer personal-data processing. Binding transfer clauses prevail over conflicts. Data-protection terms have their legal meanings under applicable law, including the EU GDPR, UK GDPR and Data Protection Act 2018 where applicable.

2. Processing scope

Jelto collects, validates, stores, aggregates, reports, exports and deletes data to provide configured analytics. Processing continues while collection is enabled and while data is retained under this DPA. Annex A describes the data and people covered.

Cookieless website collection uses daily, product-scoped visitor hashes without cookies or browser storage. Salts expire within 48 hours. These hashes can be personal data.

Attribution memory is not selected for this agreement.

The Customer must match this selection and its notices to its actual settings. Preparing this copy does not change those settings.

3. Instructions

Jelto processes data only on documented instructions, including this DPA, service settings and authorized support requests. This includes transfers. We will notify the Customer if an instruction appears unlawful and may pause the affected processing while it is resolved.

Under GDPR Article 28(3)(a), processing without instructions requires EU or Member State law binding on Jelto, with advance notice unless that law prohibits it on important public-interest grounds. Other legal demands do not override data-protection or transfer safeguards. We assess demands, limit disclosure to what is required and notify the Customer where permitted.

The Customer is responsible for lawful collection, notices, consent and the data-use restrictions in the Terms. A Customer acting for another controller must have authority to appoint Jelto and relay its instructions.

4. Confidentiality and security

Access is limited to authorized people who need it and are bound by confidentiality. We maintain security appropriate to the data, processing risks and state of the art, as described in Annex B.

We do not sell customer data, build advertising profiles or train general-purpose AI models with it. Jelto’s application does not store or log IP addresses or link website visitors to desktop installations.

5. Subprocessors

When this DPA takes effect, the Customer gives general written authorization for the agreed Annex C providers. We bind them to equivalent data-protection duties through written contracts and remain responsible for their performance.

We email the Customer at least 30 days before adding or replacing a provider, specifying its identity, role and processing locations, and update the schedule. The Customer may object on reasonable data-protection grounds during that period. If no resolution is available before the change, it may end the affected service before that provider processes its data and receive unused prepaid fees for that service.

6. Requests and assistance

We forward requests about customer data to the Customer unless prohibited by law, without independently deciding the response. Considering the processing and information available, we assist with rights requests, security, impact assessments and required authority consultations.

Exports and erasure tools support these requests. App requests can use an install ID; cookieless website records may no longer identify a named visitor. We explain these limits and assess information provided to locate records.

Extra assistance charges must be reasonable, documented and agreed in writing beforehand. Fee disagreements cannot delay mandatory assistance, and we do not charge to remedy our own breach.

7. Personal data breaches

We notify the Customer without undue delay after becoming aware of a breach affecting its data, without waiting for a completed investigation. As available, we provide the breach’s nature, affected data and people, approximate numbers, likely consequences, mitigation and a contact. We provide updates, take reasonable steps to contain and remedy the breach, and cooperate on required notifications. The Customer decides its notices to authorities and people; Jelto’s independent legal duties remain. Notification alone does not admit liability.

8. Return and deletion

The Customer selects analytics retention from 30 days to three years on Starter or five years on Growth; the default is three years. Live cleanup can lag by approximately two days.

When processing services end, we will, at the Customer’s choice, return data and delete remaining copies, or delete it. Any legally required retention is limited to its required purpose, with its basis and scope explained where permitted. Under GDPR Article 28(3)(g), the storage exception is for EU or Member State law. This DPA protects data still held.

Cancelling a subscription does not end processing of retained history. Product deletion allows seven days to cancel, then live erasure is processed within 24 hours. Backups age out within 30 days and the recovery archive within 90 days; recovery must reapply deletions before data returns to service. Stop collection to prevent new data arriving after erasure.

Stored export files expire seven days after job creation. New downloads are denied at expiry; scheduled maintenance removes files and retries failures while retaining cleanup metadata. Installation erasure revokes and removes its specific exports and product-wide exports, including jobs in progress. Customers may generate new exports from remaining data after erasure completes. Product/account deletion removes all their exports. Copies already downloaded to external devices remain the customer’s responsibility. Deletion records also retain install identifiers without scheduled expiry. These limits do not waive erasure duties or mandatory deadlines. See the retention policy for separate account, financial and security periods.

9. Audits

We provide compliance information and allow and contribute to Customer or mandated-auditor inspections. Routine audits begin with documentation, require 30 days’ written notice and ordinarily occur once per 12 months during business hours, protecting confidentiality and other customers’ data.

Notice and frequency limits do not apply where a breach, credible material noncompliance, an authority’s request or law requires otherwise. Arrangements cannot obstruct mandatory audits. The Customer pays its auditor; extra Jelto assistance follows Section 6.

10. International transfers

The documented origin deployment is in the EU; network and other provider processing can occur elsewhere. Before restricted transfers, the parties must document and implement the safeguards and supplementary measures required by each applicable law. This DPA does not itself execute or replace required transfer contracts. Actual locations and transfer arrangements remain to be confirmed.

11. Liability and law

The Terms’ single liability cap and all its exceptions apply jointly to the Terms and this DPA. The Terms’ Turkish law and conditional Istanbul jurisdiction also apply. These provisions do not restrict statutory data-subject claims, regulators’ powers, mandatory processor duties, responsibility for subprocessors or binding transfer-clause rights.

Annex A. Data covered

People covered are website visitors, desktop users and people included in customer-authorized events, revenue records or integrations. Only enabled features apply:

  • Web: page/referrer hosts and paths, campaign labels, timestamps, daily hashes or same-host cookies, browser/device details, user agent, language, approximate location, engagement and permitted properties.
  • Desktop: install IDs, app/OS details, language, approximate location, activity and configured properties.
  • Revenue and crawlers: amounts, currencies, transaction digests, attribution labels or app install IDs; separately classified crawler requests with redacted paths.
  • Integrations: selected GitHub commit metadata, Search Console aggregates, report recipients and aggregate content.

IP addresses are handled transiently for delivery, location and daily web hashing. Identifiers, paths and properties may be personal data. Special-category and criminal-offence data are prohibited inputs.

Annex B. Security measures

  • Data minimization, transient IP handling and short-lived web hash salts.
  • Scoped access and credentials; time-limited, audited support access.
  • Hashed account tokens and keys; encrypted reusable integration credentials.
  • HTTPS, private database networking and restricted administration.
  • Encrypted backups, restricted recovery archives and deletion-aware recovery.
  • Application logs that exclude IP addresses, raw secrets and visitor identifiers.

These describe the service design; deployment and recovery controls require verification before execution.

Annex C. Providers

Hetzner Online GmbH
Hosting and live customer-data storage. Documented locations: Germany / Finland.
Cloudflare, Inc.
Global network transit, including connection addresses and request bodies; R2 recovery storage with documented EU jurisdiction. Jelto’s stored copies exclude IP addresses; provider network and security logging follows its terms and settings.
Resend, Inc.
US email provider for recipients and enabled aggregate reports; also delivers Jelto’s account email.

Lemon Squeezy handles Jelto’s subscription billing as merchant of record. Customer-authorized Google, GitHub and revenue connections are separate enabled relationships. DB-IP supplies an offline geolocation database and receives no visitor data.

Preparation and signatures

Prepared for Not provided by Not provided, Not provided. Entering details or saving a copy is not an electronic signature or acceptance.

For the Customer
Signature / date

Taha Bozdemir · Jelto
Signature / date

Before execution, complete the business address, confirm providers and transfers, resolve retention and erasure limits, and complete security verification and legal review. Contact [email protected].