Legal
Data Processing Addendum
Last updated: 2026-09-23
Contents
This is Journey’s published standard-form Data Processing Addendum. It has effect only where an agreement between Journey and a customer expressly incorporates it.
1. Applicability
This Data Processing Addendum (“DPA”) applies only where an agreement between Journey Technologies Inc. (“Journey”) and a customer (“Customer”) expressly incorporates it. It supplements that agreement (the “Agreement”). If this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls for that subject matter. Except as modified by this DPA, the Agreement remains in effect.
2. Scope and roles
“Customer Personal Data” means personal information that Customer provides to Journey, or authorizes Journey to receive from Customer’s systems or providers, that Journey processes on Customer’s behalf in connection with the service.
Where Customer acts as a business or controller of Customer Personal Data under applicable privacy law, Journey acts as its service provider or processor. Where Customer itself acts as a processor or service provider, Journey will act as its subprocessor or subcontractor, as applicable. The parties acknowledge that their roles depend on the particular processing activity and applicable law.
Information an individual provides directly to Journey or connects personally — including personal financial accounts, personally connected equity accounts, private questions, personal goals, and household information — is not Customer Personal Data merely because the individual receives Journey through Customer. Journey handles that information under its Privacy Policy, and nothing in this DPA gives Customer rights to it.
3. Processing details
Customer instructs Journey to process Customer Personal Data as necessary to provide the services described in the Agreement, according to Customer’s configuration and use of the service and any other documented instructions consistent with the Agreement.
| Data subjects | Customer’s employees, former employees, administrators, and, where Customer provides the information, dependents or beneficiaries |
| Categories of data | Identity and contact information; employment information; compensation; benefits eligibility and elections; retirement plan information; equity grants and vesting information; HR and payroll information; and information an employee explicitly submits to Customer through Journey |
| Nature of processing | Collection, hosting, storage, organization, retrieval, analysis, transmission, integration, deletion, and other processing necessary to provide the service |
| Purposes | Providing compensation, benefits, equity, and related employee experiences; operating Customer-authorized integrations and workflows; support; security and fraud prevention; and improving the quality of the services provided to Customer as permitted by applicable law |
| Duration | For the term of the Agreement and any limited period afterward permitted or required by the Agreement, this DPA, or applicable law |
4. Journey’s processing commitments
For Customer Personal Data, Journey will process the information according to Customer’s documented instructions, the Agreement, and applicable law.
Journey will not sell Customer Personal Data or share it for cross-context behavioral advertising. Journey will not retain, use, or disclose Customer Personal Data outside the limited and specified purposes of the Agreement or outside the direct business relationship with Customer, except as permitted by applicable law.
Journey will not combine Customer Personal Data with personal information received from another customer or collected through Journey’s independent relationship with an individual, except where applicable law permits that processing.
Journey will provide the level of privacy protection required by applicable law and will notify Customer if Journey determines that it can no longer meet applicable obligations concerning Customer Personal Data.
Customer may take reasonable and appropriate steps, consistent with applicable law and the Agreement, to verify Journey’s compliance with this DPA and to stop and remediate unauthorized processing of Customer Personal Data.
5. Customer responsibilities
Customer represents that it has the rights and authority necessary to provide or make Customer Personal Data available to Journey and to instruct Journey to process it as contemplated by the Agreement.
Customer is responsible for providing legally required notices, obtaining required permissions or consents, and ensuring that its instructions to Journey comply with applicable law. Journey is not required to follow an instruction that it reasonably believes would violate applicable law and may notify Customer of that concern.
6. Confidentiality
Journey will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as necessary for their authorized responsibilities.
7. Security
Journey will maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data against unauthorized access, use, alteration, loss, or disclosure, taking into account the nature of the information and the risks presented by the processing.
A current overview of Journey’s security practices is available on our Security page. That page is informational and does not expand Journey’s contractual obligations unless the Agreement expressly provides otherwise.
8. Subprocessors
Customer generally authorizes Journey to engage subprocessors to process Customer Personal Data in connection with the service. Journey maintains its current subprocessor list at /legal/subprocessors.
Journey will require subprocessors that process Customer Personal Data on Journey’s behalf to enter into written agreements imposing data-protection obligations consistent with Journey’s obligations under this DPA, and Journey remains responsible for the performance of its subprocessors to the extent required by applicable law and the Agreement.
Where applicable law requires advance notice and an opportunity to object to a new subprocessor, Journey will provide that opportunity to Customer before the new subprocessor begins processing Customer Personal Data. Any objection must be based on reasonable grounds concerning the protection of Customer Personal Data, and the parties will work in good faith toward a reasonable resolution.
9. Individual rights and compliance assistance
Taking into account the nature of the processing and the information available to Journey, Journey will reasonably assist Customer with applicable obligations concerning Customer Personal Data, including responding to legally valid individual rights requests, security obligations, breach notifications, and data-protection assessments where required by applicable law.
If Journey receives a request directly concerning Customer Personal Data for which Customer is responsible, Journey may direct the individual to Customer or otherwise handle the request as applicable law requires. Requests concerning information that Journey handles independently under its Privacy Policy are not governed by Customer’s instructions under this DPA.
10. Verification and assessments
On reasonable request, Journey will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA and will cooperate with reasonable assessments to the extent required by applicable law.
Assessments are subject to reasonable confidentiality, security, scope, frequency, and non-disruption safeguards. Where an independent security or compliance report reasonably addresses the requested controls, Journey may provide that report instead of duplicative testing or access.
11. Deletion and return
At the end of services involving Customer Personal Data, Journey will, at Customer’s direction and as required by applicable law, delete or return Customer Personal Data unless applicable law requires or permits its retention. This section does not apply to information that is outside the definition of Customer Personal Data under Section 2.
Any continued availability to an individual of employer-sourced compensation, benefits, equity, or other records after the employment or Customer relationship ends must be expressly authorized by the Agreement and handled consistently with Journey’s Privacy Policy. Absent that authorization, Customer Personal Data remains subject to Customer’s applicable deletion or return instructions.
12. Security incidents
Journey will notify Customer without undue delay after becoming aware of a breach of Journey’s security resulting in unauthorized access to, acquisition of, use of, disclosure of, alteration of, or destruction of Customer Personal Data (a “Security Incident”).
Journey will provide information reasonably available to it concerning the nature of the Security Incident, the affected Customer Personal Data, remediation or mitigation steps, and other information reasonably necessary to assist Customer with applicable legal obligations. Journey will take reasonable steps to investigate, contain, mitigate, and remediate a Security Incident.
13. International processing
Journey currently provides the service primarily from the United States. If Journey will process Customer Personal Data subject to the GDPR, UK GDPR, or another privacy regime requiring additional contractual transfer mechanisms on Customer’s behalf, the parties will put appropriate supplemental terms in place where required.
14. Relationship to the Agreement and changes
This DPA remains in effect for as long as Journey processes Customer Personal Data on Customer’s behalf. Any limitations and exclusions of liability in the Agreement apply to this DPA to the fullest extent permitted by applicable law.
Journey may update the public form of this DPA as laws and services change. The version incorporated into an Agreement continues to govern that Agreement unless the parties agree otherwise or the Agreement expressly provides for updated versions to apply.
Questions: legal@usejourneywealth.com