When you use Juniper OS to process personal data about your own customers, you are the data controller and Juniper Enterprises Holdings Limited is your data processor under UK GDPR Article 28. This page summarises the terms; a counter-signed DPA is available on request for customers who need one on file.
Our commitments as processor
- Process personal data only on your documented instructions.
- Enforce tenant isolation at the database layer (Postgres Row-Level Security) so no customer can access another's data.
- Encrypt data at rest (AES-256) and in transit (TLS 1.3); integration credentials are encrypted with a separate key.
- Bind every sub-processor to equivalent obligations, and publish them on our sub-processors page.
- Assist you with data-subject requests, breach notification, and DPIAs.
- Notify you without undue delay (and within 72 hours of becoming aware) of any personal-data breach.
- Delete or return personal data on termination, subject to the documented retention schedule and legal hold requirements.
International transfers
Primary data residency is the UK (Supabase, eu-west-2). Where a sub-processor operates outside the UK/EU, transfers rely on Standard Contractual Clauses or an equivalent adequacy mechanism.
Requesting a signed DPA
Email privacy@juniperenterprises.co.uk with your legal entity name and we'll return a counter-signed agreement.