Roles and DPA
Jurono acts as controller for website visits, demo requests, marketing, billing, account administration, support, and platform security. For customer content inside a firm account, Jurono generally acts as processor under Art. 28 GDPR.
A data processing agreement is provided before production processing of firm or client data. The DPA covers subject matter, duration, data categories, data subject categories, instructions, confidentiality, subprocessors, deletion, return, and audit support.
- Controller for Jurono website, marketing, support, and billing operations
- Processor for customer content inside a firm account
- DPA and TOM overview available via privacy@jurono.eu or the contact form
TOM overview
Technical and organisational measures are maintained according to risk profile. Controls evidenced in the codebase today include Argon2id password hashing with bcrypt migration, JWT access control, CSRF checks for cookie requests, role and tenant guards, audit logs, consent logging, and PII redaction for structured logs.
Documented backup and restore evidence, production runtime proof for the ClamAV upload-scanning baseline, RLS hardening, complete encryption at rest for especially sensitive content, and SOC 2 reports are not presented as completed controls.
- Access control, roles, tenant context, and permission checks
- Audit, consent, and security-event logging
- PII redaction for logs and secrets
- Open baselines stay blockers instead of marketing claims
Subprocessors and transfers
The DPA appendix source of truth is the production subprocessor register maintained for procurement review. Current repository evidence and operator attestation name netcup for production hosting and Impossible Cloud for S3-compatible object storage. PostgreSQL, Redis, Typesense, Umami, ClamAV and the application runtime are operated by Jurono on the production infrastructure where applicable. SMTP/email, monitoring, support tooling, signed region evidence and transfer evidence remain incomplete.
| Service | Purpose | Location | Transfer mechanism | Status |
| --- | --- | --- | --- | --- |
| netcup production hosting | App operation, database, cache, search, and Jurono-operated services | Germany by operator attestation | EEA processing; signed DPA/region evidence required in the appendix | Operator-attested, evidence pack pending |
| Impossible Cloud S3-compatible storage | Documents, exports, audit, backup, and temporary upload buckets | `eu-central-2` by operator attestation | EEA processing; signed DPA/region evidence required in the appendix | Operator-attested, evidence pack pending |
| Jurono-operated Umami | Optional analytics after consent | Follows verified Jurono hosting evidence unless separately hosted | No sensitive mandate data; consent-gated analytics only | Repo-evidenced endpoint, hosting evidence pending |
| Microsoft Clarity | Optional website analytics after consent | Microsoft regions according to Microsoft privacy terms | Microsoft DPA, EU Standard Contractual Clauses, and applicable adequacy mechanisms | Optional marketing provider; signed appendix pending |
| To verify: SMTP/email | System and notification email | Must be named in the DPA appendix | Must be named before sensitive production use | Not verified |
| To verify: monitoring and support tooling | Error reporting, uptime/support workflows, and customer assistance | Must be named in the DPA appendix | Must be named before sensitive production use | Not verified |
- No hypothetical provider lists without names
- The production subprocessor register controls the signed DPA appendix
- Sensitive mandate data remains restricted until provider evidence is complete or the customer contract/product path explicitly excludes the affected processing
Retention, export and deletion
Jurono supports access, export, and deletion processes where Jurono acts as controller or assists the customer as processor under instruction. Contractual and statutory retention duties, security requirements, professional obligations, and third-party rights can limit immediate deletion.
The backup, restore, and retention evidence register is maintained for DPA/TOM review. It currently records a restricted state: production backup frequency, restore tests, backup lifecycle retention, and signed access-control evidence must be completed before backup or restore readiness is presented as an implemented control.
- Active data is retained while the contract, customer instruction, legal duty, security need, or statutory limitation period requires it
- Deleted active data is deleted or anonymised where no legal/security exception applies; backups age out under the verified lifecycle once that evidence exists
- Exports are provided for customer review or data-subject support and then deleted or restricted under the agreed export retention period
- Restores must happen in isolated, access-limited environments and be recorded before sensitive mandate data can rely on the backup baseline
Incidents and contact
Data protection and security requests go to privacy@jurono.eu. Security incidents are assessed, contained, documented, and reviewed against notification duties under Art. 33 and 34 GDPR.
Where Jurono acts as processor, affected customers are informed without undue delay after Jurono becomes aware of a relevant event.
- privacy@jurono.eu for DPA, TOMs, and privacy questions
- support@jurono.eu for operational support topics
- Incident assessment with customer notification for processor processing
Certifications and blockers
Jurono currently has no published SOC 2 report, ISO 27001 certification, or comparable external certification. SOC 2 is used as a control orientation, not as an existing attestation.
Before sensitive production mandate data is processed, production subprocessors (#126), backup/restore evidence (#127), production evidence for the ClamAV malware-scanning baseline (#128), and encryption/RLS baselines must be closed as blockers or explicitly restricted in the customer contract.
- No hidden certification claim
- Missing baselines are tracked as blockers
- Current review materials are provided through the DPA/TOM request flow