Skip to content
JanusSecurity & PrivacyData processing addendum

Janus / Security & Privacy

Data processing addendum

Instructions, confidentiality, provider obligations, and data return or deletion.

Last updated

On this page

This addendum applies when incorporated into the parties’ services agreement. Client and Provider are the parties identified in that agreement. Their data-protection roles follow the agreed processing activity.

Instructions and permitted purposes

Provider will process Client Personal Data only on documented instructions for the agreed Janus services, unless legally required otherwise. Those purposes include authorized transcription, organizing project information, drafting and refining deliverables, matching records, planning work, tracking delivery, reporting progress and contract usage, and approved feedback handling.

Information may concern staff, contractors, meeting participants, account users, and people referenced in permitted content. It may include business contact details, roles, meeting statements and metadata, approved documents, project and usage records, generated outputs, embeddings, and approved extension submissions. Voice or audio is included only when authorized. Patient information, credentials, and unapproved captures remain excluded.

Provider will flag instructions it believes infringe applicable data-protection law. Client is responsible for the lawfulness of its instructions and supplied data; Provider remains responsible for its own obligations.

Confidentiality and security

Authorized personnel will be subject to confidentiality duties and access limited to assigned responsibilities. Provider will maintain the measures expressly agreed for the engagement, including authenticated access, tenant and organization permissions, scoped client views, and private storage for confidential uploads.

The agreed security measures cover access controls, encryption, incident response, retention, and recovery. The applicable services agreement defines these obligations.

Client Personal Data will not be sold, used for behavioral advertising, or used to train general-purpose AI models. Selected provider accounts and terms must support these restrictions.

Providers and locations

Only providers authorized in writing may process Client Personal Data. The provider overview identifies the services supporting Janus. New or replacement providers require prior written agreement. Provider will impose applicable obligations in writing and remain responsible for their performance under this addendum.

The parties must agree processing locations and any required transfer safeguards before affected processing begins. Primary application or database regions do not establish every AI, support, log, or backup location.

Requests and incidents

Provider will promptly inform Client of individual requests concerning Client Personal Data and reasonably assist Client in responding. Provider will notify Client without undue delay after becoming aware of a breach affecting that data, provide available details, supplement them as facts become known, and cooperate in containment and remediation. Client controls its notifications unless Provider has an independent legal duty.

Provider will provide reasonable information and assistance for compliance reviews, impact assessments, and proportionate audits, with safeguards for other clients’ information. No independent certification is implied.

Return and deletion

At the end of processing, Provider will return or delete Client Personal Data according to Client’s instructions and the agreed retention schedule, subject to identified legal obligations. This must address source and processing copies, approved documents, project records, generated content, embeddings, extension drafts and submitted files, logs, backups, and provider-held copies.

Backup expiry, restoration handling, export format, deletion deadlines, and responsibilities must be agreed before processing begins. Provider will confirm completion on request under those agreed terms. Retained information remains protected and limited to its permitted purpose.

Duration and governing agreement

Before processing begins, the parties must document the operational security and retention schedules, approved providers and locations, instruction and incident contacts, and any required transfer terms. These obligations continue while Client Personal Data is retained. Liability and governing law follow the services agreement, subject to mandatory law.