| Owner | Jonny Allum (Data Protection Lead) |
| Version | 1.0 · Effective 13/07/2026 · Review annually (July) |
| Applies to | All personal data processed by JonnyAI, BizOS, HubSuite, JAIOS and agency engagements |
1. Our two roles
Controller. JonnyAI is the controller for: platform account data (tenant owners, staff logins, billing contacts), prospect and CRM data, marketing lists, agency client contact data, and website analytics.
Processor. For everything a tenant puts *inside* their BizOS workspace — customers, residents, staff records, medication charts, safeguarding concerns, payroll figures — the tenant is the controller and JonnyAI is the processor. This includes special category data (health data in the care vertical: care plans, MAR charts, NEWS2 observations, safeguarding records), so processor obligations are treated at the highest tier.
2. Lawful bases (as controller)
| Processing | Basis |
|---|---|
| Operating a customer's account and subscription | Contract |
| Platform security, fraud prevention, audit logs | Legitimate interests |
| Marketing to prospects and customers | Consent (see POL-12) — campaigns are consent-first with tokenised unsubscribe |
| Tax and accounting records | Legal obligation |
3. Processor commitments (what tenants can rely on)
- Tenant data is processed only to provide the service — never mined, never used to train models, never shared across tenants.
- Per-tenant RLS isolates every table; portal users see only their own slice.
- Subprocessors are limited to the register in POL-09 (Supabase, Google Cloud, Stripe, Resend, Anthropic, Twilio where enabled). New subprocessors require updating that register before first use.
- AI processing (JonnyAI ask/digest/actions) sends compact structured signals — counts, renewal bands, status maps, one named worst item — not row dumps, to the model backend. See POL-05 §4.
- On termination, tenant data is exported on request and then deleted per POL-10 / SOP-10.
- A data processing agreement (DPA) reflecting these terms is offered to every paying tenant; care-vertical tenants get it proactively at onboarding (SOP-01), since their data is special category.
4. Data subject rights
Requests (access, rectification, erasure, portability, restriction, objection) are handled within one calendar month:
- Where JonnyAI is controller: fulfil directly. Identity is verified against the account email before disclosure.
- Where JonnyAI is processor: the request is redirected to the tenant (their duty), and JonnyAI assists — exports, targeted deletion — within the same window. Never fulfil a data subject request against a tenant's workspace without the tenant's instruction.
5. Breach notification
Personal data breaches follow SOP-05. As processor, affected tenants are notified without undue delay after becoming aware. As controller, the ICO is notified within 72 hours where the breach is likely to risk individuals' rights, and affected individuals directly where the risk is high. Every breach, notifiable or not, is logged in the incident record.
6. DPIAs and privacy by design
A short DPIA is written before: a new vertical carrying a new category of sensitive data, a new AI capability that changes what data reaches a model backend, or a new public (no-login) surface. The existing product controls — RLS, role gating, consent-first comms, confirm-step AI actions, draft-only tax — are the baseline every new feature must meet, not aspirations.
7. International transfers
Primary processing is UK/EU-hosted where the provider allows region pinning (Supabase project region; GCP VM region). US-based providers (Stripe, Resend, Anthropic) are used under their standard contractual clauses / UK addendum as published in their DPAs. The subprocessor register (POL-09) records the transfer mechanism per vendor.
8. Records
Retention schedule lives in POL-10. The record of processing activities (ROPA) is this document plus the subprocessor register — reviewed together annually.