Datenschutzerklärung
Zuletzt aktualisiert: July 27, 2026
Die verbindliche Fassung ist Englisch. Die folgenden Abschnitte sind auf allen Sprachversionen der Website in Englisch.
1. Who we are and scope
This Privacy Policy explains how the company operating Jomioz (“Jomioz,” “we,” “us,” or “our”) collects, uses, and shares personal information when you visit our website (such as jomioz.com), use our marketing pages, join a waitlist, contact us, or use the Jomioz product — including the web app, mobile app, Client Hub, and related services (together, the “Service”).
Jomioz is field-service operations software for service businesses: customers and properties, scheduling and jobs, estimates and invoices, payments, team messaging, and related workflows. We serve customers in Europe and the Americas and design our privacy practices to meet applicable laws in those regions, including the EU/UK GDPR and US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) where they apply.
Privacy contact: privacy@jomioz.com. For our full legal name, tax identification number (NIF/CIF), and registered office, email privacy@jomioz.com or legal@jomioz.com — we will provide these statutory details promptly.
This Policy covers Jomioz as provider of the Service. It does not apply to the privacy practices of Account Owners (your business’s own notices to its customers) or of third parties we do not control.
2. Controller vs processor (B2B)
When an Account Owner uses Jomioz to manage its own customers (“End Users”), jobs, estimates, invoices, messages, and related content, that organization is typically the controller (or “business”) of that Customer Data, and Jomioz acts as a processor (or “service provider”) on the Account Owner’s documented instructions.
Jomioz is the controller of account, billing, security, and platform administration data (for example staff sign-in emails, subscription records, authentication logs, and audit logs we need to run the Service).
Account Owners are responsible for having a lawful basis and any required notices or consents to put End User personal data into Jomioz (including when sending email, SMS, or WhatsApp through the Service). End Users with privacy requests about data in a customer’s workspace should contact that Account Owner first.
B2B customers may request a Data Processing Agreement (DPA) at privacy@jomioz.com.
3. Information we collect (tied to the product)
Account Owners and Employee Users: name, work email, company details, role/permissions, locale and timezone, plan and billing contact details, and content you create in the product (for example job notes, photos, attachments, checklists, time entries, and settings).
End Users (your customers): information you store or collect through the Service — for example name, phone, email, service addresses/properties, job history, estimate and invoice details, e-signatures, Client Hub activity (approvals, reschedules, messages), and payment status for charges you collect. We process this as a processor on your behalf.
Communications: transactional and customer messages you send or receive through enabled channels (email; SMS and WhatsApp where you connect those integrations), plus related delivery metadata.
Location and maps: if you use scheduling, routing, or “on my way” style features, we may process addresses and map/route-related data via our mapping provider. Approximate location derived from IP may be used for security and diagnostics.
Payments: subscription billing is processed by Stripe. Customer charges you collect (Jomioz Payments) are also processed by Stripe. We do not store full card numbers on Jomioz servers for independent reuse.
AI features (where enabled on your plan): prompts and content you submit to drafting or assistive features, and generated outputs, processed through our AI provider to deliver those features.
Fiscal features (Spain, where we enable them for your organization): invoice and tax-identification data needed for Verifactu / AEAT reporting through our fiscal partner.
Logs and technical data: IP address, device and app/browser type, crash or diagnostic data, feature usage events, and authentication/security logs.
Marketing site and waitlists: form submissions and basic analytics as described in the cookies section.
4. How we use information and legal bases (Europe)
We use information to: provide and operate the Service (accounts, jobs, scheduling, documents, Client Hub, payments, messaging); authenticate users (including optional two-factor authentication); send technical, security, and support messages; bill subscriptions; detect and prevent fraud or abuse; meet legal obligations; improve reliability and product quality; and generate aggregated, anonymized statistics that do not identify individuals.
Where the EU/UK GDPR applies, we rely on: (a) performance of a contract; (b) legitimate interests (security, fraud prevention, product improvement, service communications), balanced against your rights; (c) legal obligation; and (d) consent where required (for example non-essential cookies or optional marketing), which you may withdraw at any time without affecting prior lawful processing.
5. United States privacy (including California)
We do not sell personal information for money. If you accept analytics cookies on our marketing site, we may use Google Analytics, Google Ads, Meta Pixel (Facebook), and Meta’s Conversions API (server-side events) to measure visits, trial clicks, and ad performance. That may constitute “sharing” for cross-context behavioral advertising under the CCPA/CPRA. You can decline cookies on our banner, or use Google’s and Meta’s opt-out tools. If our practices change further, we will update this Policy and provide required opt-out mechanisms.
If you are a resident of California or another US state with similar privacy laws, you may have rights to know/access, correct, delete, and obtain a portable copy of certain personal information we hold as a business, and to appeal a denied request where the law provides. You will not be discriminated against for exercising those rights.
To exercise US privacy rights for data Jomioz controls (for example your own account email), contact privacy@jomioz.com. For Customer Data your employer or service provider stores about you as an End User inside a Jomioz workspace, contact that business first — we act as their service provider for that data.
Authorized agents may submit requests where state law allows; we may require proof of authority and identity verification.
8. International transfers (Europe ↔ Americas)
Because we serve customers in Europe and the Americas, personal data may be processed in the EEA, the United Kingdom, the United States, and other countries where we or our subprocessors operate.
Where we transfer personal data from the EEA/UK to a country without an adequacy decision, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and UK equivalents, plus supplementary measures where needed. Where US law requires disclosures about out-of-state or international processing, this section and our subprocessor list serve that purpose.
Contact privacy@jomioz.com for transfer details relevant to your workspace.
9. Retention
Retention depends on the data type: account data for the life of the account plus a limited wind-down period; Customer Data per the Account Owner’s configuration and deletion/export requests; billing and fiscal records for periods required by applicable tax and accounting law (including Spanish fiscal retention where Verifactu applies); messaging and support records for continuity and abuse prevention; and security logs for a limited investigation period.
When data is no longer needed, we delete or anonymize it, subject to backup copies that age out in the ordinary course.
10. Security
We implement technical and organizational measures designed to protect personal data, including TLS encryption in transit, encryption at rest where supported by our infrastructure, role-based access in the product, optional two-factor authentication, monitoring, and least-privilege access to production systems. See also our Security page at jomioz.com/security.
No online service is 100% secure. Use strong unique passwords, enable two-factor authentication where available, and report suspected issues to security@jomioz.com.
11. Your rights (Europe and elsewhere)
If the GDPR (or UK GDPR) applies, you may have rights to access, rectify, erase, restrict, or port personal data, to object to certain processing, and to lodge a complaint with a supervisory authority (in Spain, the Agencia Española de Protección de Datos — AEPD; in other EEA countries, your local authority).
For data your organization controls inside Jomioz, contact your workspace administrator first. For data Jomioz controls as provider (or if your admin cannot help), contact privacy@jomioz.com. We may need to verify your identity before responding.
US state rights are described in section 5.
12. Children
Jomioz is a business service and is not directed to children. You must be at least the age of majority in your jurisdiction to use the Service. We do not knowingly collect personal data from children under 16 (or under 13 in the United States, or the higher age required in your country). If you believe we have, contact privacy@jomioz.com and we will delete it.
13. Changes to this policy
We may update this Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated through the product or by email where appropriate.
14. Contact
Privacy requests (EU/UK and US): privacy@jomioz.com. Legal: legal@jomioz.com. Security: security@jomioz.com. See also our Terms of Service and Security page on jomioz.com.
Siehe auch Nutzungsbedingungen
