Política de privacidad
Última actualización: 2026-09-11
El texto jurídico vinculante está en inglés. Las secciones siguientes se muestran en inglés para todas las versiones de idioma.
1. Who we are and scope
This Privacy Policy explains how David Lander, trading as “Jomioz” (“Jomioz,” “we,” “us,” or “our”), collects, uses, and shares personal information when you visit our website (such as jomioz.com), use our marketing pages, join a waitlist, contact us, or use the Jomioz product — including the web app, mobile app, Client Hub, and related services (together, the “Service”).
Controller for platform account, billing, security, and marketing-site data:
- David Lander, trading as “Jomioz”
- Tax ID (NIF/NIE): Y8422959M
- Address: Calle San Isidro, 2 - La Orotava - Tenerife - Spain
- Contact: info@jomioz.com
Jomioz is field-service operations software for service businesses. We serve customers in Europe and the Americas and design our privacy practices to meet applicable laws in those regions, including the EU/UK GDPR and US state privacy laws such as the CCPA/CPRA where they apply.
Full imprint details: https://www.jomioz.com/legal.
This Policy covers Jomioz as provider of the Service. It does not apply to the privacy practices of Account Owners (your business’s own notices to its customers) or of third parties we do not control.
2. Controller vs processor (B2B)
When an Account Owner uses Jomioz to manage its own customers (“End Users”), jobs, estimates, invoices, messages, and related content, that organization is typically the controller (or “business”) of that Customer Data, and Jomioz acts as a processor (or “service provider”) on the Account Owner’s documented instructions.
Jomioz is the controller of account, billing, security, and platform administration data (for example staff sign-in emails, subscription records, authentication logs, and audit logs we need to run the Service).
Account Owners are responsible for having a lawful basis and any required notices or consents to put End User personal data into Jomioz (including when sending email, SMS, or WhatsApp through the Service). End Users with privacy requests about data in a customer’s workspace should contact that Account Owner first.
B2B customers may review or request a Data Processing Agreement (DPA) at https://www.jomioz.com/dpa or info@jomioz.com.
3. Information we collect (tied to the product)
Account Owners and Employee Users: name, work email, company details, role/permissions, locale and timezone, plan and billing contact details, and content you create in the product (for example job notes, photos, attachments, checklists, time entries, and settings).
End Users (your customers): information you store or collect through the Service — for example name, phone, email, service addresses/properties, job history, estimate and invoice details, e-signatures, Client Hub activity (approvals, reschedules, messages), and payment status for charges you collect. We process this as a processor on your behalf.
Communications: transactional and customer messages you send or receive through enabled channels (email; SMS and WhatsApp where you connect those integrations), plus related delivery metadata.
Location and maps: if you use scheduling, routing, or “on my way” style features, we may process addresses and map/route-related data via our mapping provider. Approximate location derived from IP may be used for security and diagnostics.
Payments: subscription billing is processed by Stripe. Customer charges you collect (Jomioz Payments) are also processed by Stripe. We do not store full card numbers on Jomioz servers for independent reuse.
AI features (where enabled on your plan): prompts and content you submit to drafting or assistive features, and generated outputs, processed through our AI provider solely to deliver those features. We do not use Customer Data or those prompts to train third-party foundation models.
Logs and technical data: IP address, device and app/browser type, crash or diagnostic data, feature usage events (including PostHog product analytics), and authentication/security logs.
Marketing site and waitlists: form submissions and analytics as described in our Cookie Policy (https://www.jomioz.com/cookies).
4. How we use information and legal bases (Europe)
We use information to: provide and operate the Service (accounts, jobs, scheduling, documents, Client Hub, payments, messaging); authenticate users (including optional two-factor authentication); send technical, security, and support messages; bill subscriptions; detect and prevent fraud or abuse; meet legal obligations; improve reliability and product quality (including PostHog product-usage analytics); and generate aggregated, anonymized statistics that do not identify individuals.
Where the EU/UK GDPR applies, we rely on: (a) performance of a contract — to run your account, workspace, billing, and the features you use; (b) legitimate interests — security, fraud prevention, service communications, and product analytics that help us keep the Service reliable, balanced against your rights; (c) legal obligation — tax, accounting, and similar duties that apply to us as provider; and (d) consent where required — non-essential marketing-site cookies and optional marketing, which you may withdraw at any time without affecting prior lawful processing.
5. United States privacy (including California)
Categories we may collect as a business (depending on how you use the site or Service): identifiers (name, email, account ID, IP address); commercial information (plan, billing status, trial activity); internet or other electronic activity (pages viewed, feature-usage events, cookie/device identifiers); approximate location derived from IP; and inferences drawn from that activity (for example interest in a trial). Sources include you, your organization, cookies and similar technologies after consent, and our subprocessors. We use these categories to provide the Service, secure accounts, bill subscriptions, measure the marketing site, and improve reliability.
We do not sell personal information for money. If you accept analytics cookies on our marketing site, we may use Google Analytics, Google Ads, Meta Pixel (Facebook), and Meta’s Conversions API (server-side events) to measure visits, trial clicks, and ad performance. That may constitute “sharing” for cross-context behavioral advertising under the CCPA/CPRA.
You can opt out of that sharing by declining cookies on our banner, by emailing info@jomioz.com with the subject “Do Not Sell or Share,” or by using Google’s and Meta’s opt-out tools. We will honor a request that reasonably identifies you. If our practices change further, we will update this Policy.
If you are a resident of California or another US state with similar privacy laws, you may have rights to know/access, correct, delete, and obtain a portable copy of certain personal information we hold as a business, and to appeal a denied request where the law provides. You will not be discriminated against for exercising those rights.
To exercise US privacy rights for data Jomioz controls (for example your own account email), contact info@jomioz.com. For Customer Data your employer or service provider stores about you as an End User inside a Jomioz workspace, contact that business first — we act as their service provider for that data.
Authorized agents may submit requests where state law allows; we may require proof of authority and identity verification.
8. International transfers (Europe ↔ Americas)
Because we serve customers in Europe and the Americas, personal data may be processed in the EEA, the United Kingdom, the United States, and other countries where we or our subprocessors operate.
Where we transfer personal data from the EEA/UK to a country without an adequacy decision, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and UK equivalents, plus supplementary measures where needed. Where US law requires disclosures about out-of-state or international processing, this section and our subprocessor list serve that purpose.
Contact info@jomioz.com for transfer details relevant to your workspace.
9. Retention
We keep personal data only as long as needed for the purposes in this Policy, then delete or anonymize it, subject to backup copies that age out in the ordinary course.
Account and workspace administration data: for the life of the account, then typically up to 24 months after closure so we can complete offboarding, resolve disputes, and meet legal holds.
Customer Data (End User contacts, jobs, documents, messages, files): for as long as the Account Owner’s workspace retains it, and until that organization deletes it or we complete a deletion/export request we are instructed to run.
Billing, invoicing, and accounting records we hold as provider: for the period required by applicable tax and accounting law (often six to ten years, depending on the country).
Support and abuse-prevention records: typically up to 24 months after the last relevant ticket or incident.
Security and authentication logs: typically up to 12 months, unless a longer period is needed for an investigation or legal claim.
Marketing-site analytics after cookie consent (including PostHog on the marketing site, Google, and Meta): until you withdraw consent or the vendor’s retention period ends — you can decline or withdraw via the cookie banner or by emailing us.
10. Security
We implement technical and organizational measures designed to protect personal data, including TLS encryption in transit, encryption at rest where supported by our infrastructure, role-based access in the product, optional two-factor authentication, monitoring, and least-privilege access to production systems. See also our Security page at jomioz.com/security.
No online service is 100% secure. Use strong unique passwords, enable two-factor authentication where available, and report suspected issues to info@jomioz.com.
If we become aware of a personal-data breach affecting Customer Data we process for an Account Owner, we will notify that Account Owner without undue delay and provide information reasonably available to help them meet their own obligations.
11. Your rights (Europe and elsewhere)
If the GDPR (or UK GDPR) applies, you may have rights to access, rectify, erase, restrict, or port personal data, to object to certain processing, and to lodge a complaint with a supervisory authority (in Spain, the Agencia Española de Protección de Datos — AEPD; in other EEA countries, your local authority).
For data your organization controls inside Jomioz, contact your workspace administrator first. For data Jomioz controls as provider (or if your admin cannot help), contact info@jomioz.com. We aim to respond within 30 days (or sooner if law requires). We may need to verify your identity before responding. End Users should contact their Account Owner first for workspace Customer Data.
US state rights, including Do Not Sell or Share, are described in section 5.
12. Children
Jomioz is a business service and is not directed to children. You must be at least the age of majority in your jurisdiction to use the Service. We do not knowingly collect personal data from children under 16 (or under 13 in the United States, or the higher age required in your country). If you believe we have, contact info@jomioz.com and we will delete it.
13. Changes to this policy
We may update this Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated through the product or by email where appropriate.
14. Contact
Privacy, legal, and security requests: info@jomioz.com. See also our Terms of Service, Cookie Policy, Security page, Subprocessors list, and DPA on jomioz.com.
Ver también Términos de servicio · Política de cookies
