
Data processing agreement.
This DPA is incorporated into the Just Arrived Terms of Service and applies to every customer — no separate signature is required.
Last updated 23 August 2026 · Version 1.0
Parties
The customer organization using Just Arrived acts as data controller. ReadyLive Technologies, CVR 35622594, Sundholmsvej 31, 4. tv, 2300 København S, Denmark acts as data processor.
Subject matter, duration, nature and purpose
Subject matter: visitor management at the controller's offices — visitor check-in data, the employee host directory, and the delivery of arrival and safety notifications. Duration: the term of the controller's subscription, plus the deletion period described below.
Nature and purpose: collecting visitor check-in details on kiosks, notifying hosts of arrivals, maintaining an on-site roll call for evacuation safety, and providing an administration workspace and visit history to the controller.
Data subjects and personal data
Categories of data subjects: visitors to the controller's offices, and the controller's employees and administrators.
Categories of personal data: visitor name, optional company, email, phone and license plate, host visited, and check-in and check-out timestamps; where the controller enables them, visitor photographs and agreement acceptance records (typed name and/or drawn signature, tied to the immutable agreement version shown); and for employees and administrators, name, work email, job title, office and the chat platform identifiers used to deliver notifications. Visitor photos and signatures are stored in encrypted private storage and are deleted automatically when the visit reaches the controller's retention window. The full list is described in the privacy policy.
Documented instructions
The processor processes personal data only on the controller's documented instructions, which comprise this DPA, the Terms of Service, and the configuration the controller makes in the product (check-in flow, retention window, connected notification channels). The processor informs the controller if an instruction appears to infringe the GDPR.
Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations and are granted access only to the extent required to operate and support the service.
Security measures
The processor maintains appropriate technical and organisational measures, including: encryption of personal data in transit and at rest; row-level security enforcing strict tenant isolation between customer organizations; role-based access controls and least-privilege administrative access; credentials and integration secrets stored server-only, never exposed to browsers; audit logging of administrative actions; automated anonymisation of visit records after the controller's retention window; and EU data residency for the primary database and backend.
Subprocessors
The controller gives general written authorisation for the subprocessors on the subprocessor list, which is kept current on this site. The processor imposes data protection obligations on each subprocessor no less protective than those in this DPA, and announces material changes — adding or replacing a subprocessor — by email with at least 30 days notice, so the controller has a reasonable opportunity to object.
International transfers
The primary database and backend are hosted in the EU. Personal data is not transferred to a third country except through the subprocessors on the list, and only under an appropriate transfer mechanism — an adequacy decision or the EU Standard Contractual Clauses. Notifications delivered through US-based chat platforms (Slack, Teams, Google Chat, Discord) take place under those providers' data processing terms and transfer mechanisms, and only when the controller has connected the channel.
Assistance and breach notification
Taking into account the nature of the processing, the processor assists the controller with responding to data subject requests, with security of processing, and with data protection impact assessments and prior consultation.
The processor notifies the controller of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, together with the information the controller needs to meet its own notification obligations.
Deletion or return
During the term, visit records are anonymised automatically once the controller's retention window passes. The controller may export a complete copy of its data at any time, self-service, from the admin console under Account → Billing → Data & privacy — a machine-readable archive including all stored media, delivered as a private, time-limited download link. The controller may likewise delete its entire workspace from the same place; deletion is immediate and permanent, covers every database record and stored file, cancels any subscription, and is recorded in a platform-level deletion log. Where the controller does not delete on termination, the processor deletes all personal data after a 30-day grace period, unless retention is required by EU or member state law. Assistance with export or deletion is available via privacy@justarrived.io.
Audit rights
The processor makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates, on reasonable notice, no more than once per year unless required by a supervisory authority, and subject to confidentiality.